This Data Processing Agreement ("DPA") governs the processing carried out by SFV S.R.L. on behalf of the agencies that use the Domusify platform, within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR").
The DPA supplements the platform's Terms of service. It forms part of the contractual relationship between SFV and the Agency and applies whenever SFV processes personal data on behalf of the Agency.
1. Parties and roles
Data controller ("Agency")
The real estate agency, business or professional who enters into the Terms of service and uses the platform for their business. The Agency is identified by the data provided in the contractual relationship and configured in its workspace.
Data processor ("SFV")
SFV S.R.L., with registered office at Via Terra di Santa Lucia 56, 95030 Mascalucia (CT), Italy, tax code and VAT number 05881360878.
The Agency determines the purposes and the essential means of the processing carried out within its real estate business. SFV provides the platform and processes the Agency's personal data in accordance with the documented instructions received.
This DPA concerns exclusively the activities in which SFV acts as data processor.
Processing for which SFV acts as an autonomous controller is outside the scope of this DPA, including the management of users' authentication identities, the general security of accounts and the platform, the direct relationship with SFV and the marketing website. Such processing is described in the platform Privacy policy.
Where the same person is affected by both types of processing, the respective roles remain distinct. For example, SFV may process as controller the email and credentials needed for the account and, at the same time, process on behalf of the Agency the professional profile, the association with the workspace and the authorisations granted by the Agency.
2. Effectiveness, form and precedence
The DPA takes effect together with the Terms of service, or at the time the parties accept it or refer to it through another written or electronic agreement.
The DPA constitutes a written agreement even when entered into in electronic form.
In the event of a conflict between this DPA and the Terms of service, the DPA prevails as regards the obligations relating to the processing of personal data on behalf of the Agency.
For all matters not concerning the protection of personal data, the Terms of service continue to apply.
3. Subject matter, nature and purposes of the processing
SFV processes personal data only to the extent necessary to provide, maintain, protect and make usable the platform features requested by the Agency.
Depending on the features used, the activities may include:
- storage, organisation, modification, consultation and deletion of the data entered by the Agency;
- publication and distribution of the content of the Agency's website;
- technical management of properties, offices, agents, staff, media, pages and settings;
- management of the associations between users and the Agency's workspace, of the access profiles, roles and permissions decided by the Agency;
- technical management of the invitations issued by the Agency to its staff;
- storage and distribution of photographs, floor plans and other media;
- transmission of the enquiries sent by visitors to the agencies' websites to the recipients identified by the Agency;
- sending of the relevant service and confirmation emails;
- hosting, database, backup, restoration, maintenance and technical management of the infrastructure;
- prevention of spam, abuse and unauthorised access;
- production of aggregated statistics for the Agency's website, where the relevant feature is enabled and the visitor has given the necessary consent;
- technical support and troubleshooting, limited to the data that needs to be consulted for the specific activity;
- any further operations requested by the Agency through platform features consistent with this DPA.
SFV does not autonomously determine further purposes for the data processed on behalf of the Agency and does not use that data for its own advertising campaigns, commercial profiling or sale to third parties.
4. Documented instructions of the Agency
SFV processes personal data only on the basis of the Agency's documented instructions.
Documented instructions include, among others:
- the Terms of service and this DPA;
- the configurations made in the panel;
- the creation, modification, publication or deletion of content;
- the enabling or disabling of the available features;
- the choice of recipients and settings of a service;
- the assignment of roles, permissions and access;
- the requests sent to support through the channels made available by SFV;
- further written instructions agreed between the parties.
The Agency warrants that its instructions are lawful and that the data has been collected and made available to the platform in compliance with the applicable legislation.
If SFV considers that an instruction infringes the GDPR or other applicable data protection provisions, it informs the Agency without undue delay and may suspend performance of the specific instruction until its lawfulness is clarified.
Where European Union or Italian law requires SFV to carry out processing other than the instructions received, SFV informs the Agency in advance of the legal obligation, unless the law prohibits such communication on important grounds of public interest.
5. Obligations of the Agency
As data controller, the Agency is responsible for the lawfulness of the processing carried out through the platform.
In particular, the Agency undertakes to:
- have a valid legal basis for the processing carried out;
- provide data subjects with the information required by Articles 13 and 14 GDPR;
- obtain consent where the processing requires it;
- give SFV lawful, relevant and proportionate instructions;
- process only data that is adequate, relevant and limited to what is necessary;
- keep authorised users up to date and promptly remove access that is no longer necessary;
- configure roles and permissions according to the principle of least privilege;
- use the forms, statistics and any external content in compliance with its own policies and the choices of data subjects;
- not use the platform for purposes incompatible with the service or with the applicable legislation;
- inform SFV when a data subject request, an authority measure or an incident requires technical work on the service.
The platform is designed for managing real estate websites and content and does not require, in ordinary use, the intentional processing of special categories of data under Article 9 GDPR or of data relating to criminal convictions and offences under Article 10 GDPR.
The Agency must not intentionally enter such data into the platform, free-text fields, documents or media, unless the relevant feature is expressly provided for and the parties have agreed on any necessary measures.
6. Authorised persons and confidentiality
SFV ensures that the persons authorised to process personal data on behalf of the Agency:
- access the data only when necessary for their respective duties;
- are bound by contractual or legal confidentiality obligations;
- receive adequate instructions in relation to the activities carried out;
- are subject to access control measures consistent with their respective functions.
The confidentiality obligations continue to apply after the authorisation or the relationship with SFV ends.
7. Security of processing
SFV adopts technical and organisational measures appropriate to the risk within the meaning of Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.
The main categories of measures applied are described in Annex B.
The measures are reviewed and may be updated over time in order to maintain an adequate level of security. Updating the measures must not result in a substantial reduction of the overall level of protection during the relationship.
The Agency acknowledges that the security of processing also depends on its own correct configuration of access, on the safekeeping of credentials and on the lawfulness and quality of the data uploaded.
8. Personal data breaches
SFV informs the Agency without undue delay after becoming aware of a personal data breach concerning data processed on behalf of the Agency.
The notification contains, to the extent that the information is available:
- the nature of the breach;
- the categories of data subjects involved;
- the categories and approximate amount of data or records concerned, where determinable;
- the likely consequences of the breach;
- the measures taken or proposed to contain it and mitigate its effects;
- the contact details or channel through which available updates can be obtained.
Where it is not possible to provide all the information at the same time, SFV communicates it progressively without further undue delay.
SFV's notification does not constitute an acknowledgement of liability.
The Agency remains responsible for assessing the breach and for any notifications to the Authority or communications to data subjects required by Articles 33 and 34 GDPR. SFV provides the assistance reasonably necessary on the basis of the information available to it.
9. Data subject rights
Taking into account the nature of the processing, SFV assists the Agency, by means of appropriate technical and organisational measures, to the extent possible, in enabling it to respond to data subject requests under Chapter III GDPR.
Depending on the case, the assistance may concern:
- identification of the data;
- access to and export of the available information;
- rectification;
- erasure;
- restriction;
- portability in the applicable cases;
- handling of objections or withdrawal of consent for the features concerned.
If SFV receives a request directly concerning data processed exclusively on behalf of an Agency, it does not decide on the request autonomously and, unless contrary legal obligations apply:
- informs the data subject that the controller is the Agency, or
- forwards the request to the Agency where it can reasonably be identified.
SFV does not respond on the merits on behalf of the Agency without instructions, unless required to do so by law.
10. Assistance for Articles 32-36 GDPR
Taking into account the nature of the processing and the information available to it, SFV provides reasonable assistance to the Agency with the obligations concerning:
- security of processing;
- management of personal data breaches;
- data protection impact assessments;
- any prior consultation of the supervisory authority.
The Agency remains responsible for assessing whether a DPIA is needed and for the decisions that fall to the controller.
11. Sub-processors
The Agency grants SFV general written authorisation to use the sub-processors listed in Annex C for the activities needed to provide the service.
SFV:
- selects sub-processors that offer adequate guarantees;
- enters into written agreements with them imposing, for the processing carried out on behalf of the Agency, data protection obligations substantially equivalent to those applicable to SFV under this DPA;
- remains liable to the Agency for the performance of the sub-processor's obligations within the limits provided for by Article 28 GDPR.
Changes to the list
SFV informs the Agency of its intention to add or replace a sub-processor processing personal data on behalf of the Agency with reasonable notice and, where possible, at least 30 days before the relevant processing begins.
The communication may take place by email, through the panel or through another electronic channel used for contractual communications.
The Agency may object within the period indicated in the communication, exclusively on documented and reasonable grounds relating to the protection of personal data.
The parties cooperate in good faith to assess a reasonable solution. If the objection cannot be resolved, SFV may propose an alternative configuration or the discontinuation of the feature concerned; where the change substantially affects the overall use of the service, the remedies and termination arrangements provided for by the Terms of service and by the applicable legislation continue to apply.
The sub-processors of the providers listed in Annex C may in turn be used within the limits provided for by their respective DPAs and by the authorisation mechanisms governed therein.
12. Third-party services that do not act as sub-processors
Some features may involve the use of parties that, for the specific activities indicated, do not assume the role of SFV's sub-processor.
Such services are described in Annex D to avoid their being confused with the sub-processors authorised under Article 28 GDPR.
Where the feature is optional, the Agency's use of the relevant feature constitutes an instruction to SFV to carry out the technical operations necessary to enable it, without prejudice to the liability of the third parties for the processing they carry out as autonomous controllers.
SFV limits the disclosure to the data needed for the feature and configures the service, where technically possible, according to data minimisation criteria.
13. International transfers
SFV configures the main hosting, database and media storage infrastructure using European regions.
This does not exclude that some sub-processors, companies in their group, support systems or further sub-processors may process or make accessible personal data from countries outside the European Economic Area.
SFV carries out or permits international transfers of data processed on behalf of the Agency only:
- on the basis of the Agency's documented instructions incorporated into the service and this DPA;
- where the transfer complies with Chapter V GDPR;
- by means of an applicable adequacy decision, or
- by means of standard contractual clauses and any necessary supplementary measures, or
- by means of another valid mechanism provided for by the applicable legislation.
Where applicable, SFV benefits from and relies on the transfer mechanisms provided for in the sub-processors' DPAs.
Any consent collected from visitors for an optional tool does not replace the safeguards required by Chapter V GDPR.
14. Return and deletion of data
On termination of the services relating to the processing, at the Agency's choice, SFV returns or deletes the personal data processed on its behalf, unless European Union or Italian law requires it to be retained.
Before definitive deletion, the Agency may request the return of the data within the limits of the available export features or, where reasonably necessary, in a technically usable format agreed with SFV.
After the return, or where the Agency chooses deletion:
- the data is removed from the active systems according to the applicable technical procedures;
- copies that are no longer necessary are deleted;
- any data in backup copies remains isolated and is not used for ordinary purposes, being overwritten or deleted according to the normal rotation cycle;
- if a backup is restored, the deletions already requested are applied again where technically necessary.
The obligation to delete does not apply to data that SFV must retain for a legal obligation or to data that SFV processes autonomously as controller on the basis of a separate purpose and legal basis.
15. Information, checks and audits
SFV makes available to the Agency the information reasonably necessary to demonstrate compliance with the obligations under Article 28 GDPR and this DPA.
The Agency may request relevant documentation on the security measures, the sub-processors and the processing methods.
Where the available documentation is not sufficient to verify a relevant obligation, the Agency may carry out, or appoint an independent auditor to carry out, a check, subject to the following conditions:
- the check must have a proportionate scope directly connected to the processing carried out on behalf of the Agency;
- it must be agreed with reasonable notice, except in the case of incidents or urgent requests from an authority;
- it must avoid unnecessary interference with the security and continuity of the service;
- the auditor must be bound by adequate confidentiality obligations;
- the check must not involve access to the data of other agencies, to confidential information of other clients or to information whose disclosure would compromise the security of the platform.
SFV may satisfy a request for a check also by means of documentation, attestations, independent reports or remote audits, where such instruments reasonably allow the required compliance to be established.
The powers of the supervisory authorities remain unaffected.
16. Liability of the roles and unlawful instructions
Each party is responsible for the obligations that the GDPR assigns to it on the basis of its role.
Nothing in this DPA transfers to SFV the responsibilities that belong to the Agency as controller, nor limits SFV's mandatory obligations as processor.
Where SFV autonomously determines, in breach of this DPA, the purposes and means of processing carried out on behalf of the Agency, the consequences provided for by Article 28(10) GDPR apply.
The provisions of the Terms of service on liability apply to the extent that they do not conflict with mandatory rules of the GDPR or with the rights of data subjects and supervisory authorities.
17. Duration
This DPA remains in force for the entire period during which SFV processes personal data on behalf of the Agency.
Obligations that by their nature must survive termination, including confidentiality, deletion, return, cooperation on previous incidents and documentation obligations, continue to apply for as long as necessary.
18. Governing law
This DPA is governed by the law indicated in the Terms of service, without prejudice to the application of the GDPR, to the competences of the supervisory authorities and to the other mandatory provisions applicable to the protection of personal data.
Annex A — Description of the processing
A.1 Subject matter
Provision of the Domusify platform as a SaaS service for creating and managing the Agency's website, its content and the related technical features.
A.2 Duration
For the duration of the service relationship and, after termination, only for the period technically necessary for the return, deletion and normal rotation of backup copies, without prejudice to legal obligations.
A.3 Nature of the operations
The operations may include:
- technical collection;
- receipt;
- recording;
- organisation;
- structuring;
- storage;
- consultation;
- modification;
- extraction;
- transmission;
- publication at the Agency's instruction;
- restriction;
- deletion;
- backup and restoration.
A.4 Purposes
The purposes are limited to providing the features requested by the Agency, including:
- management and publication of the real estate website;
- management of properties, offices, agents, staff and content;
- management of the access decided by the Agency;
- storage and distribution of media;
- technical management of the enquiries coming from visitors;
- sending of service emails;
- security, maintenance, backup and support;
- statistics for the Agency's website when enabled under the conditions provided for;
- further features used by the Agency in accordance with the service.
A.5 Categories of data subjects
The processing may concern:
- the Agency's clients and potential clients;
- owners, sellers, landlords and other parties who offer or entrust properties to the Agency;
- buyers, tenants and people requesting information;
- visitors to the Agency's websites;
- real estate agents, staff, employees, consultants and other members of the Agency's organisation;
- contacts at the Agency's offices;
- people who may be represented or mentioned in the content uploaded by the Agency;
- third parties whose data is incidentally present in photographs, floor plans, communications or other content, to the extent that the Agency is legitimately entitled to process it.
A.6 Categories of personal data
Depending on the use of the platform, the following may be processed:
Identifying and contact data
- first and last name;
- business name;
- email;
- telephone number;
- professional contact details;
- any further contact details entered by the Agency.
Professional and organisational data
- office or branch of affiliation;
- professional role;
- qualification;
- professional photograph;
- association with an agency;
- access profiles, roles and permissions assigned by the Agency;
- professional and social links.
Property data
- addresses and locations;
- geographical coordinates;
- descriptions;
- technical features;
- prices and commercial information relating to the property;
- photographs;
- floor plans;
- other media and content connected with the listing.
This information constitutes personal data only when it can be linked, directly or indirectly, to an identified or identifiable natural person.
Data from visitor enquiries
- name;
- email;
- telephone;
- message;
- reason for the enquiry;
- reference to the property concerned;
- technical data needed for delivery and security.
Visitor enquiries are not stored by the platform in a leads database; they pass through the application and the email service to be delivered to the recipients identified by the Agency.
Technical data
- IP addresses;
- technical identifiers;
- connection data;
- application and security logs;
- information about browser and device;
- technical data needed for the protection, diagnosis and operation of the service.
Content and communications
- texts entered by the Agency;
- content of the communications handled through the platform features;
- photographs, files and media uploaded.
A.7 Special categories and judicial data
The standard service does not require the intentional processing of:
- special categories of personal data under Article 9 GDPR;
- data relating to criminal convictions and offences under Article 10 GDPR.
The Agency is instructed not to enter them intentionally into the service unless it has first verified the necessity, the legal basis and the applicable measures.
A.8 Frequency
Processing takes place continuously or occasionally, depending on the Agency's and the relevant website visitors' use of the service.
Annex B — Technical and organisational measures
The measures set out below describe the main categories of protection adopted in the current architecture. They may evolve over time, provided that the overall level of protection is not substantially reduced.
B.1 Tenant separation
- each Agency has a logically separate workspace;
- the data of the main resources is associated with its
tenant_key; - the PostgreSQL database uses Row-Level Security (RLS) policies for the main tenant-owned tables;
- the policies are configured to prevent access when the tenant context is not correctly set;
- database-level controls complement application-level controls and do not replace them.
B.2 Access control
- individual authentication of users;
- separation between authentication identity and the Agency's professional profile;
- email address verification;
- management of access profiles, roles and permissions;
- application authorisations to the tenant's resources;
- ability for the Agency to remove or change staff access;
- personal credentials not intended for sharing.
B.3 Protection of credentials and tokens
- passwords stored as hashes and not in plain text;
- invitation tokens stored in the database as hashes;
- tokens and sessions subject to expiry or invalidation;
- application secrets and third-party service credentials kept separate from the application's public content.
B.4 Communication security
- use of HTTPS/TLS for public connections;
- application protections against forged requests;
- traffic distribution and protection infrastructure;
- anti-bot controls on public forms where provided for.
B.5 Data minimisation
- separation between SaaS account data and the Agency's professional data;
- no leads archive for enquiries coming from public forms;
- enquiries sent to the indicated recipients without ordinary persistence of the content in a contacts database;
- limitation of integrations to the data needed for the relevant feature;
- operational prohibition on sending identifying personal data to the AI photo processing feature.
B.6 Infrastructure and availability
- main infrastructure configured in European regions;
- managed database;
- object storage for media;
- backup copies and restoration mechanisms according to the configuration of the infrastructure services;
- separation between application data, media and technical configurations where appropriate.
B.7 Monitoring, maintenance and incidents
- collection of technical logs needed for diagnosis and security;
- management of application updates and dependencies;
- technical procedures for analysing malfunctions and incidents;
- limitation of technical access to data to the activities necessary for providing, maintaining or supporting the service.
B.8 Restoration and deletion
- backup and restoration procedures for service continuity;
- deletion of data from active systems on termination in accordance with the DPA and the Terms;
- normal rotation of backup copies;
- reapplication of deletions where a restoration makes previously deleted data available again, where necessary.
Annex C — Authorised sub-processors
The following list concerns the parties used by SFV as processors or sub-processors to process personal data on behalf of the Agencies.
Inclusion concerns only the activities in which the provider effectively acts as processor or sub-processor; any activities carried out by the same provider as an autonomous controller fall outside that qualification.
| Provider | Function | Data involved | Documentation |
|---|---|---|---|
| DigitalOcean | Hosting of the application and managed database | Application data, database, logs and technical data needed for provision | Data Processing Agreement |
| Amazon Web Services (AWS) — S3 | Storage and distribution of media | Photographs, floor plans, files and related technical data | AWS GDPR Data Processing Addendum |
| Elastic Email | Sending of the emails generated by the service, including enquiries coming from the Agencies' websites | Email addresses, message content and technical delivery data | Data Processing Addendum |
| Cloudflare | CDN, traffic protection and security controls | IP, connection information and technical security signals | Cloudflare Data Processing Addendum |
| Google — reCAPTCHA, for the protection of the public forms on the Agencies' websites | Anti-bot verification: distinguishes human requests from automated ones | Verification token, IP address, user agent, website hostname and technical request signals | Google Cloud Data Processing Addendum |
| Google — Google Analytics 4, when enabled for the Agency's website | Statistical processing of traffic according to the configuration provided by the platform | Online identifiers, device data and browsing events | Google Ads Data Processing Terms |
Google Analytics 4
Where GA4 is used for the Agencies' websites, SFV configures the service according to the model provided for processing on behalf of the Agency:
- activation only after the visitor's consent;
- no advertising features;
- no Google Signals;
- no transmission of the data entered in forms;
- no use by SFV of the Agencies' data for its own advertising purposes;
- use of the settings needed so that the processing of Analytics data falls, as far as applicable, within the Google terms provided for services as processor.
The Agency receives in the panel only the reports relating to its own website, according to the features made available by the platform.
Cloudflare
Cloudflare acts as a sub-processor for the activities carried out to provide SFV with network and security services on behalf of the Agency.
Cloudflare may also carry out specific activities under its own responsibility, as stated in its own documentation, for example in connection with the improvement of certain security and automated detection systems. Such autonomous activities do not turn the entire Cloudflare service into processing carried out on behalf of the Agency.
Chains of sub-processors
The providers listed above may use their own sub-processors in accordance with their respective DPAs.
The lists and notification mechanisms of the respective providers form part of the contractual guarantees assessed by SFV. By way of information:
Annex D — Third-party services not qualifying as sub-processors
The integrations indicated in this Annex are not presented as sub-processors under Article 28 where the relevant provider autonomously determines the purposes or essential means of its own processing, or expressly states that it does not act as processor for the feature concerned.
D.1 OpenStreetMap Foundation — OpenStreetMap and Nominatim
The platform may use OpenStreetMap and Nominatim for map display and address geocoding.
The OpenStreetMap Foundation states that the use of its services, including Nominatim and the OSM tiles it provides, does not create a controller–processor relationship, and that it does not enter into DPAs for such use.
When the feature is used, the technically necessary data may be communicated to the OpenStreetMap Foundation in accordance with its Privacy Policy and the documentation on services and tile users.
SFV and the Agency must limit the data communicated to what is necessary for the feature.
D.2 Google Maps
Where the Agency uses Google Maps as an alternative to OpenStreetMap, the content intended for visitors is loaded only under the consent conditions provided for by the Cookie policy of the Agency's website.
For the Google Maps APIs services, Google governs certain activities within a relationship between autonomous controllers. The processing carried out directly by Google is therefore distinct from the processing carried out by SFV on behalf of the Agency.
The Google Privacy Policy and the data protection terms relevant to the service apply.
D.3 Black Forest Labs — FLUX
The platform may make available a feature for processing real estate photographs through the FLUX API of Black Forest Labs.
The feature is designed for property photographs and must not be used to transmit identifying personal data that is not necessary to Black Forest Labs.
Before processing, the Agency must check the image and remove or obscure, where present:
- faces or identifiable people;
- documents;
- licence plates or other personal identifiers where not necessary;
- personal photographs;
- written information referable to natural persons;
- any other personal element not necessary for the work on the image.
Under the standard terms of the API service, Black Forest Labs autonomously governs certain uses of the inputs and outputs, including activities for developing or improving its services. For this reason, Black Forest Labs is not qualified in this DPA as a sub-processor for the processing of the Agencies' personal data.
The feature must therefore be used in compliance with the minimisation rule set out above. The API terms for the European Union and the Black Forest Labs Privacy Policy apply.
If SFV should in future activate a contractual arrangement with Black Forest Labs providing for the processing of personal data exclusively on behalf of SFV and allowing appointment under Article 28 GDPR, the provider may be reclassified and included in Annex C, following the procedure provided for new sub-processors.
This DPA is drafted to meet the requirements of Article 28(3) and (4) GDPR and takes into account the structure of the standard contractual clauses between controllers and processors adopted by the European Commission by Implementing Decision (EU) 2021/915.
Last updated: 20 September 2026