Data Processing Agreement
Last updated: August 2026
The binding version of this agreement is the Spanish one. This English text is provided for convenience.
This Data Processing Agreement (the “Agreement” or “DPA”) forms part of the contractual relationship between ALIVIO Asset Management, S.L., registered office at [pending], NIF [pending] (“ALIVIO” or the “Processor”); and the legal entity or professional identified as the client in the relevant commercial proposal, order or contract (the “Client” or the “Controller”). Both parties agree to govern the processing of personal data carried out by ALIVIO on behalf of the Client in accordance with Regulation (EU) 2016/679 (GDPR) and other applicable data protection law.
1. Purpose
This Agreement governs ALIVIO’s access to and processing of the personal data for which the Client acts as controller and which is necessary to provide the contracted services. Processing is carried out solely to provide ALIVIO’s services and execute the Client’s documented instructions. ALIVIO’s access to such data is not a communication or transfer of data, but access necessary to provide a service on behalf of the Controller.
2. Services that may involve processing
Depending on the modules and services contracted, ALIVIO may process personal data in relation to: pre-sale management; pre-handover and handover of properties; after-sales management; dwelling reviews; recording and monitoring of issues; coordination of actions; supplier assignment and management; visit management; documentation of actions; addition of photographs; signatures and sign-offs; report generation; communications between project participants; support and maintenance of the Platform; and other expressly contracted functionalities.
3. Duration
This Agreement remains in force while ALIVIO processes personal data on behalf of the Client. Once the service ends, data is returned or deleted in accordance with this Agreement, without prejudice to data that must be kept duly blocked to address possible legal liabilities.
4. Nature and purpose of the processing
Depending on the functionalities used, ALIVIO may carry out operations of collection; recording; structuring; organisation; storage; consultation; communication between authorised users; modification; classification; linking; documentation generation; retention; extraction or export; and deletion. The purpose is solely to enable the provision of the contracted services and the operation of the corresponding ALIVIO functionalities. ALIVIO will not use data processed on behalf of the Client for its own purposes incompatible with that purpose.
5. Categories of data subjects
Depending on the Client’s use of the Platform, data may relate to buyers or prospective buyers; owners; owners’ representatives; the Client’s employees and collaborators; managers; technicians; developer or builder representatives; suppliers; suppliers’ employees or collaborators; participating professionals; authorised Platform users; and other people whose data is necessary to manage an issue or action.
6. Categories of data
A. Identification: name and surname; user identification; company or organisation; position or function.
B. Contact: email; phone; business address; other data necessary for communication.
C. Property-related: property address; identification of dwelling, premises or element; the data subject’s relationship with the property; information associated with its handover or use.
D. Issue-related: issue descriptions; observations; communications; dates; statuses; actions taken; identification of participating users.
E. Photographs and documentation: photographs of the property, construction elements, installations, defects, repairs and actions; work orders; reports; quotes; records; signed documents; technical documentation; and other documents necessary for managing the service.
F. Signature and sign-off data: signer identification; signature added to the Platform; date and time; associated document or action; evidence of acceptance or sign-off; and other technical data necessary to evidence the action.
G. Technical data: user identifier; date and time of access; actions performed; status changes; activity logs; information necessary to ensure security and traceability.
7. Special categories of data
The Platform is not designed for the ordinary processing of the special categories of personal data referred to in Article 9 GDPR. The Client must avoid entering data relating to health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data intended to uniquely identify a person, or information about sex life or orientation, unless strictly necessary, with a sufficient legal basis and having previously informed ALIVIO where specific measures may be required. Authorised Users must likewise avoid including in photographs, comments or documentation personal information unnecessary to manage the relevant issue or action.
8. Controller’s instructions
ALIVIO processes personal data only following the Client’s documented instructions. Documented instructions include those set out in the contract; these conditions; the applicable General and Particular Conditions; the configuration made by the Client; and instructions transmitted by duly authorised persons. If ALIVIO considers that an instruction infringes the GDPR or other applicable data protection law, it will inform the Client.
9. ALIVIO’s obligations as Processor
ALIVIO undertakes to:
- process data only in accordance with the Client’s documented instructions;
- not use data for its own purposes incompatible with the contracted service;
- ensure that persons authorised to process personal data have committed to confidentiality;
- apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk;
- assist the Client, taking into account the nature of the processing, in handling data-subject rights requests;
- cooperate with the Client in fulfilling its obligations relating to security, data breaches, impact assessments and prior consultations where applicable;
- maintain the documentation legally required regarding the processing carried out as processor;
- make available to the Client the information reasonably necessary to demonstrate compliance with Article 28 GDPR;
- notify the Client of personal data breaches as set out in this Agreement;
- return or delete the data at the end of the service under the agreed terms.
10. Confidentiality
ALIVIO ensures that persons who may access personal data processed on behalf of the Client are subject to adequate confidentiality obligations. These obligations remain in force even after their professional relationship with ALIVIO ends. Authorised Users external to ALIVIO are subject to the corresponding Conditions of Use and confidentiality obligations applicable to their access.
11. Role-based access
ALIVIO applies a role- and permission-based access model. In the Pre-sale/After-sales module there may be, among others, Administrator; Manager/Technician; Owner; and Supplier profiles. Each user accesses only the information necessary for their assigned functions. In particular, suppliers must limit their access and use of data to the issues and actions assigned to them. The Client is responsible for determining who must have access to its projects and for reporting registrations, deregistrations or permission changes. ALIVIO is responsible for technically applying the permissions configured according to the contracted service.
12. Client’s obligations
As Controller, the Client must: determine the essential purposes and means of the processing; ensure it has a valid legal basis to process the data; provide the information required by Articles 13 and 14 GDPR where applicable; determine who must have access; ensure the data entered is adequate, relevant and limited to what is necessary; provide ALIVIO with the necessary instructions; carry out impact assessments where required; and fulfil the obligations that legally correspond to the controller. The Client must not use ALIVIO for processing incompatible with the purpose of the contracted service.
13. Data-subject rights
If ALIVIO directly receives a data-subject rights request relating to data processed on behalf of the Client, it will inform the Client without undue delay and will not substantively respond unless instructed by the Client or where there is a legal obligation. ALIVIO provides reasonable assistance to the Client through available technical measures to handle requests relating to access; rectification; erasure; objection; restriction; portability; and other legally recognised rights.
14. Security
ALIVIO adopts appropriate technical and organisational measures taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of individuals. Measures may include, as applicable: authentication mechanisms; user and permission management; role-based access control; activity logging; communication protection measures; backups; recovery mechanisms; infrastructure protection measures; vulnerability management; incident response procedures; and measures to ensure confidentiality, integrity and availability. Specific technical measures are described in Annex III.
15. Personal data breaches
ALIVIO notifies the Client, without undue delay, of any personal data breach it becomes aware of affecting data processed on behalf of the Client. The notification includes, where available: the nature of the incident; categories of affected data subjects; categories of affected data; approximate volume; possible consequences; measures adopted or proposed; and contact details for follow-up. Where it is not possible to provide all information at once, it may be provided progressively. It is for the Client to determine whether to notify the supervisory authority or the data subjects, unless the law provides otherwise.
16. Sub-processors
The Client generally authorises ALIVIO to use third-party providers where necessary to provide the service, including providers of hosting and cloud infrastructure; storage; databases; communications; email; monitoring; technical support; security; backups; and other necessary technology services.
ALIVIO keeps an up-to-date list of the sub-processors that materially take part in processing data on behalf of the Client. ALIVIO imposes on such sub-processors data-protection obligations substantially equivalent to those in this Agreement, and remains liable to the Client for the sub-processor’s compliance under applicable law.
Sub-processor changes. ALIVIO informs the Client of the addition or replacement of sub-processors where required, allowing it to raise reasoned objections related to data protection.
17. International transfers
ALIVIO endeavours to ensure that personal data is processed within the European Economic Area (EEA). Where any of its providers involves an international transfer of data outside the EEA, ALIVIO ensures a valid mechanism under the GDPR, including, where applicable: an adequacy decision; standard contractual clauses approved by the European Commission; or any other legally recognised mechanism. Where necessary, ALIVIO adopts appropriate supplementary measures based on the risk of the transfer.
18. Subcontracting of professional services
Where ALIVIO uses technicians, collaborators or other professionals to carry out services associated with the project and they need to access personal data on behalf of the Client, ALIVIO ensures their access is subject to adequate confidentiality and data-protection obligations. Where such professionals are contracted directly by the Client and only use ALIVIO as Authorised Users, their data-protection relationship is determined according to the Client’s instructions and responsibilities.
19. Audits
ALIVIO makes available to the Client the information reasonably necessary to demonstrate compliance with its obligations as processor. Where reasonably necessary, the Client may request additional information or carry out an audit, directly or through an independent auditor subject to confidentiality. Audits must: be notified with reasonable notice; take place during business hours; not unjustifiably interfere with ALIVIO’s activity; be limited to systems and processing related to the Client; and respect the confidentiality and security of other clients. Where an audit generates extraordinary costs for ALIVIO not arising from an attributable breach, the parties may agree in advance who bears such costs.
20. Fate of data at the end of the service
Once the service ends, the Client may request, within the term and conditions set contractually, the return or export of its data in the available formats. ALIVIO then deletes the personal data processed on behalf of the Client, unless there is a legal retention obligation; it is necessary to keep it blocked to address liabilities; or another legal basis legitimises its retention. Copies in backup systems may be kept during their ordinary retention cycles, remaining protected and not used for other purposes.
21. Data for which ALIVIO acts as controller
This Agreement governs only the processing carried out by ALIVIO on behalf of the Client. ALIVIO may act as an independent controller for certain processing necessary for its own legitimate purposes, including management of the contractual relationship; account administration; billing; financial management; compliance with legal obligations; Platform security; fraud or abuse prevention; handling queries; and defence against claims. Such processing is governed by ALIVIO’s Privacy Policy and not by this Agreement.
22. Liability
Each party is liable for its obligations under the GDPR and other applicable law. ALIVIO is not liable for processing carried out following the Client’s lawful instructions where liability arises exclusively from the determination of purposes, legal bases or decisions that correspond to the Client. The above is without prejudice to the liabilities that legally correspond to ALIVIO for breach of its own obligations as processor.
23. Cooperation
The parties cooperate reasonably to ensure compliance with data-protection obligations. Where a supervisory authority requests information relating to the processing governed by this Agreement, both parties cooperate within the scope of their respective responsibilities.
24. Applicable law and supervisory authority
This Agreement is governed by Regulation (EU) 2016/679, Spanish Organic Law 3/2018 and other applicable Spanish and European data-protection law. The competent supervisory authority in Spain is the Spanish Data Protection Agency, without prejudice to the powers of other authorities under the GDPR.
Annex I — Description of the processing
- Controller: Client identified in the proposal or contract.
- Processor: ALIVIO Asset Management, S.L.
- Subject matter: provision of the ALIVIO Platform and contracted services.
- Duration: during the contractual relationship and the subsequent applicable retention periods.
- Main purposes: technical and operational management of pre-sale, handover and after-sales real estate processes.
- Data subjects: owners, buyers, prospective buyers, representatives, technicians, managers, suppliers, employees, collaborators and other authorised participants.
- Data: identification, contact, property, issues, photographs, documentation, communications, actions, signatures, sign-offs and technical records.
- Operations: collection, recording, organisation, storage, consultation, authorised communication, modification, retrieval, export, retention and deletion.
Annex II — Sub-processors
ALIVIO keeps an up-to-date list of providers acting as sub-processors. At least the following is documented for each provider: provider; service; main processing location; possible international transfers; and transfer mechanism, where applicable. List pending completion following the technical review of providers.
| Provider | Service | Location | Intl. transfers | Mechanism |
|---|---|---|---|---|
| [pending] | [pending] | [pending] | [pending] | [pending] |
Annex III — Technical and organisational measures
ALIVIO maintains technical and organisational measures appropriate to the risk, including, as applicable: access control via individual users; role-based permission management; restriction of access to projects and assets; authentication mechanisms; logging and traceability of relevant actions; communication protection; backups; recovery mechanisms; system updates and maintenance; vulnerability management; incident-management procedures; confidentiality measures applicable to staff and collaborators; user onboarding and offboarding procedures; periodic review of accesses and permissions; continuity and availability measures; and procedures for deleting or blocking information. Specific measures are adapted to the technology architecture ultimately used by ALIVIO.
Formalisation
This Agreement is an integral part of contracting the ALIVIO service. Its acceptance through the signature of the relevant proposal, contract or service order incorporating it by reference has the same effect as its independent signature, without prejudice to the parties formalising it separately.
Version: August 2026.