DPA
Data processing
These terms govern how Heimster processes personal data that commercial customers manage on the platform. They form part of the terms of use and constitute the data processing agreement within the meaning of Art. 9 FADP and Art. 28 GDPR - no separate signature is required.
1. Subject matter and roles
Where a company uses Heimster commercially - a brokerage, a property manager or a developer, for example - to manage its own contact, prospect, applicant, owner or tenant data, that company remains the controller for that data. Heimster processes it on their behalf. These terms govern that processing; they form part of the terms of use and are agreed upon acceptance of those terms.
These terms do not cover processing for which Heimster is itself the controller - such as accounts and credentials, the operation and security of the platform, billing, and the matching of search profiles with properties. What Heimster is responsible for itself is described in the privacy policy.
Nature and purpose of the processing: provision of the functions you have booked - storing, structuring, evaluating, communicating and sharing data in the context of letting, selling, managing and marketing real estate. Duration: for the term of the user relationship.
Categories of data subjects: prospective tenants and buyers, applicants, tenants and purchasers, owners, business contacts and the customer's employees. Categories of personal data: contact and master data, information on housing and household circumstances, application documents, contract and property data, correspondence, appointments and activity histories. Application documents may contain particularly sensitive personal data.
2. Bound by instructions
Heimster processes this data solely to provide the agreed services and in accordance with the customer's instructions. Operating the platform - what is recorded, shared, sent, exported or deleted - constitutes an instruction. Any further instructions are given in text form.
Heimster does not sell this data, does not use it for its own advertising and does not use it to train generalised AI models. If Heimster considers an instruction unlawful, the customer is informed; execution may be suspended until the matter is clarified. Where Heimster is required to process data by mandatory law, we give prior notice unless the law prohibits this.
3. Confidentiality
Everyone at Heimster with access to this data is bound to confidentiality and trained accordingly. Access is limited to what is necessary for operation, support and security, and is logged. The Heimster team has no access to the contents of connected mailboxes.
4. Technical and organisational measures
Heimster takes appropriate measures to protect this data, in particular:
- operation and storage in Switzerland; exceptions are listed exhaustively in the privacy policy
- encryption in transit (TLS) and encryption of data at rest
- storage of access tokens and keys in a key vault, separate from the application
- tenant separation: one organisation's data is not accessible to other organisations
- a roles and permissions model, two-factor or passkey sign-in, logging of security-relevant events
- regular backups, held separately from the production system, and tested restoration
- monitoring of availability and misuse, and prompt installation of security updates
The measures are continuously adapted to the state of the art, maintaining an equivalent or higher level of protection.
5. Sub-processors
The customer authorises Heimster to engage sub-processors to provide the services - in particular for hosting and storage, email dispatch, AI-supported functions, map services, payment processing and security and infrastructure services. The categories and the countries data reaches are described in the privacy policy; we provide the current list of the companies engaged on request.
Heimster binds every sub-processor to a level of protection corresponding to these terms and is liable for their performance as for its own. We give at least 30 days' advance notice in text form before engaging a new sub-processor or replacing an existing one. Within that period the customer may object on important data protection grounds; if the objection cannot be resolved, the customer may end the affected services with effect from the close of the current billing month.
Where data is disclosed to a country without an adequate level of data protection, Heimster relies on standard contractual clauses or another permissible safeguard and takes supplementary technical measures.
6. Assistance to the customer
Heimster supports the customer with suitable technical means in fulfilling data subjects' requests for access, rectification, erasure, restriction and portability. The functions needed for this - search, inspection, correction, export and deletion - are available in the product; if a data subject approaches us directly, we refer them to the customer and inform the customer.
If Heimster becomes aware of a data security breach affecting the customer's data, we inform the customer without delay, as a rule within 48 hours of becoming aware, with the available information on the nature, scope, likely consequences and measures taken. Notification to a supervisory authority or to data subjects is the customer's responsibility; we support them in this.
On request, Heimster provides reasonable support to the customer for a data protection impact assessment and for prior consultation of the supervisory authority, insofar as these relate to the processing governed here.
7. Deletion and return
The customer's data remains the customer's data. During the user relationship the product's export functions are available to them. If they request an export after termination, we provide the data within 30 days in a common format; we then delete it, including copies in backups, within the usual retention cycles. Excepted is data we are required to retain by law - invoicing records, for example; this remains stored under restricted access until the retention period expires.
8. Evidence and audits
On request, Heimster demonstrates compliance with these terms, primarily by providing information, current documentation of the technical and organisational measures and, where available, audit reports or certificates. Where that is not sufficient in an individual case, the customer may, with reasonable advance notice and at most once a year, carry out an audit or have one carried out by an independent expert bound to confidentiality, in a manner that does not unreasonably disrupt operations. Where there are concrete indications of a breach, an audit is permissible at any time. The cost of an audit initiated by the customer is borne by the customer, unless a material breach of contract comes to light.
9. Term, precedence and final provisions
These terms apply for the duration of the user relationship; the obligations on confidentiality, deletion and evidence continue beyond it. For the processing governed here they take precedence over the terms of use. In all other respects the terms of use apply, in particular on liability, governing law and place of jurisdiction.
Please direct questions on these terms and requests about sub-processors to privacy@heimster.ch.
