Beta
Real EstateMediaBooking
Slovenia flag Slovenia
GBP
English flagEnglish
About UsFAQ

Investra

Beta
Real Estate Media Booking
Real Estate Media Booking
About UsFAQ
Back to Legal Hub
Doc 06GDPR Art.28

Data Processing Agreement

Updated: August 5, 2026v1.0Investra International Ltd

1. Background and Scope

This Data Processing Agreement (“DPA”) forms part of the agreement between Investra International Ltd (“Processor”) and the partner identified in the relevant order (“Controller”) whenever Investra processes personal data on the Controller's behalf in connection with the Platform, for example when hosting a partner's customer enquiries or managing bookings on the partner's instructions.

This DPA is drafted to satisfy Article 28(3) of Regulation (EU) 2016/679 (GDPR).

2. Subject Matter, Duration and Nature of Processing

The subject matter of processing is the operation of Platform features for the Controller. Processing lasts for the term of the underlying agreement. The nature of processing comprises collection, storage, structuring, disclosure by transmission and erasure of the data categories described in Annex 1 of the order (typically prospect and customer contact data, enquiry content and booking records) concerning the Controller's prospects, customers and staff.

3. Instructions

The Processor processes personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do otherwise by Union or member-state law; in that case the Processor informs the Controller of the legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Processor informs the Controller immediately if, in its opinion, an instruction infringes data protection law.

4. Confidentiality and Security

The Processor ensures that persons authorised to process the data are bound by confidentiality and implements the technical and organisational measures described in Annex 2, taking into account the state of the art, in accordance with Article 32 GDPR. Measures include encryption in transit, access control, logging, environment segregation, backups and regular testing of effectiveness.

5. Sub-Processors

The Controller grants a general authorisation for the engagement of sub-processors. The current list is available in the partner portal; the Processor gives at least 30 days' notice of intended changes, during which the Controller may object on reasonable data-protection grounds. The Processor imposes on each sub-processor the same data-protection obligations as set out in this DPA and remains fully liable for their performance.

6. Data Subject Rights and Assistance

Taking into account the nature of processing, the Processor assists the Controller with appropriate technical and organisational measures in fulfilling data-subject requests under Chapter III GDPR, and assists with the Controller's obligations under Articles 32 to 36 GDPR, including breach notification, data-protection impact assessments and prior consultation.

The Processor forwards without undue delay any data-subject request it receives directly and does not respond to it except on the Controller's instruction, unless required by law.

7. Personal Data Breaches

The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller's notification obligations.

8. International Transfers

Processing takes place within the EEA and the United Kingdom. Transfers to third countries, including the TRNC where required for the performance of the Controller's bookings, occur only with appropriate safeguards under Chapter V GDPR, as documented in Annex 3.

9. Audits

The Processor makes available all information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, on at least 30 days' notice, no more than once per year except following a personal data breach, and subject to reasonable confidentiality undertakings.

10. Return and Deletion

At the end of the provision of services, the Processor, at the choice of the Controller, deletes or returns all personal data and deletes existing copies unless Union or member-state law requires storage. Deletion from backups occurs in the ordinary backup rotation cycle, no later than 90 days after the deletion request.

11. Liability and Order of Precedence

Liability under this DPA is subject to the limitations agreed in the underlying agreement, except where mandatory law provides otherwise. In case of conflict between this DPA and the underlying agreement, this DPA prevails with respect to the processing of personal data.

Legal Enquiries

General legallegal@investra.io
Data protection (DPO)dpo@investra.io
DSAR requestsdsar@investra.io
logo
Investra
Beta
Enterprises
Investra properties for saleInvestra apartments for saleInvestra Villas for sale
For ClientsFor AgentsFor AgenciesFor DevelopersFor Affiliates
ProjectsAbout
FAQ
Legal Hub

© 2026 INVESTRA INTERNATIONAL LTD. All rights reserved.

Legal HubTerms of usePrivacy policyCookie PolicyImpressumPropertiesAboutFAQ