Data Processing Agreement
Last updated: September 2026
1. Parties and scope
This Data Processing Agreement (“DPA”) is between Propelos Technology S.L., a Spanish limited company with its registered office at The Pool Marbella, El Corte Inglés El Capricho, 1 planta Avda. Bulevar Príncipe Alfonso de Hohenlohe 2, Marbella, 29602, Spain (“Propelos”, “we”), and the business that has accepted our Terms of Service or signed a contract with Propelos for the Services (the “Customer”).
It applies whenever Propelos processes personal data on the Customer’s behalf while providing the AI Property Finder and related services (the “Services”): the chat and search widgets on the Customer’s website, the hosted search page, and the capture of enquiries and their delivery to the Customer. It forms part of the Terms of Service and sets out the terms required by Article 28 GDPR and Article 33 LOPDGDD. If the Customer has signed a separate data processing agreement with Propelos, that agreement prevails.
2. Definitions
“GDPR” means Regulation (EU) 2016/679. “LOPDGDD” means Spanish Organic Law 3/2018 of 5 December on the Protection of Personal Data and the Guarantee of Digital Rights. “Controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in the GDPR. A “Buyer” is a person who uses the Finder on the Customer’s website or hosted search page.
3. Roles
For the personal data described in this DPA, the Customer is the controller and Propelos is the processor. Propelos is a controller in its own right only for the Customer’s account data, such as the login details of the Customer’s staff and billing information, which our Privacy Policy covers.
4. Subject matter and duration
The subject matter is the processing of Buyers’ personal data so that Propelos can provide the Services to the Customer. The processing lasts as long as the Customer uses the Services, plus the period after the end of the Services described in section 15, until the data is deleted.
5. Nature and purpose of the processing
Propelos processes the personal data only to:
- understand what Buyers search for and answer them with listings from the Customer’s portfolio, using AI models;
- transcribe a Buyer’s voice input, when the Customer has voice search switched on;
- collect enquiries through the Finder’s enquiry form, with any consents the Buyer gives;
- deliver enquiries to the Customer by email and, where the Customer sets them up, to its CRM, webhooks or API;
- keep enquiries and conversations for the Customer, and produce usage statistics for the Customer;
- keep the Services secure, prevent abuse and fix faults.
6. Data subjects and categories of personal data
Data subjects: Buyers (prospective purchasers and tenants who use the Finder), people who send an enquiry through it, and the Customer’s staff whose details the Customer adds to the Services (for example, the agent who receives enquiries).
Personal data:
- identity and contact details: name, email address and phone number;
- messages: what Buyers write or say to the Finder, and the summary of the conversation attached to an enquiry;
- search behaviour: searches, the properties viewed and clicked, budget, preferred areas and other preferences;
- consent records: whether the Buyer agreed to marketing and to the Customer’s privacy policy, and the address of the policy shown;
- technical data: a session identifier, the country derived from the IP address, device and browser type, the referring page, the landing page and campaign parameters.
The Services are not designed to collect special categories of personal data. A Buyer may still volunteer such data in a message; Propelos then processes it only as part of that message.
7. The Customer’s obligations
- The Customer is responsible for having a lawful basis for the processing and for informing Buyers about it, in particular in its own privacy policy. The Finder can link to the Customer’s privacy policy and ask for consent in its enquiry form; setting this up is the Customer’s responsibility.
- The Customer’s instructions must comply with data protection law.
- The Customer is responsible for the systems it asks Propelos to send enquiries to, such as its CRM, email addresses and webhook endpoints.
8. Processing on documented instructions
Propelos processes the personal data only on the Customer’s documented instructions. The Terms of Service, this DPA and the Customer’s settings in the Services are those instructions. If EU or Member State law requires Propelos to process the data otherwise, Propelos will tell the Customer before doing so, unless that law prohibits it. Propelos will tell the Customer if, in its opinion, an instruction infringes data protection law.
9. Confidentiality
Propelos ensures that everyone it authorises to process the personal data is bound by confidentiality, by contract or by law, and has access only to what their work requires.
10. Security measures
Propelos applies appropriate technical and organisational measures under Article 32 GDPR, including:
- encryption in transit: the Services are served over HTTPS, and connections to our database are encrypted with TLS;
- CRM credentials and webhook signing secrets are encrypted at rest with AES-256-GCM, under a key kept apart from the database;
- passwords are stored only as bcrypt hashes, and login sessions only as hashes of the session token; sessions expire after 24 hours;
- access control: each customer’s users can reach only that customer’s data, because the account is taken from the login session on our server and never from the request; administrative access is limited to authorised Propelos staff;
- the widget’s access tokens are signed, tied to the Customer’s website address and expire after 24 hours;
- rate limits on the public endpoints and on login;
- error reports are filtered to remove contact details and message content before they leave our servers.
Propelos may update these measures as long as the overall level of security does not decrease.
11. Sub-processors
The Customer gives Propelos general authorisation to use sub-processors. Propelos uses these sub-processors for the Services:
- Replit (United States): hosts the application on Google Cloud and relays our requests to OpenAI and OpenRouter
- Neon (United States): runs our database, provided through Replit on Amazon Web Services (us-east-1)
- OpenAI (United States): AI models that understand searches, write answers and enquiry summaries, transcribe voice input and look up places a buyer mentions; also used for AI Visibility reports
- OpenRouter (United States): routes some AI requests to Google’s Gemini models and to TypeSafe AI’s Jev model
- Google (United States): Gemini AI models, reached through OpenRouter (and directly for AI Visibility reports), and Google Maps Platform, which receives only the name of a place a buyer mentions
- TypeSafe AI (United States): the Jev AI model, reached through OpenRouter, which ranks and classifies search results
- Resend (United States): sends our emails, including account emails and enquiry notifications to agencies
- Sentry (Germany, EU): error monitoring; contact details and message content are filtered out before an error report is sent
Propelos will tell the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Customer may cancel its subscription before the change takes effect. Propelos imposes on each sub-processor, by written contract, the same data protection obligations as this DPA, and remains responsible to the Customer for their performance.
12. International transfers
Some sub-processors process personal data outside the European Economic Area, mainly in the United States. Propelos makes these transfers only with a safeguard recognised by the GDPR: the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914) or, where the recipient is certified, the EU-US Data Privacy Framework. The Customer authorises these transfers.
13. Assistance to the Customer
- Taking into account the nature of the processing, Propelos helps the Customer answer requests from Buyers who exercise their rights (access, rectification, erasure, restriction, portability and objection). If a Buyer contacts Propelos directly, we pass the request to the Customer without undue delay and do not answer it ourselves unless the Customer asks us to.
- Propelos helps the Customer meet its obligations on security, breach notification, data protection impact assessments and prior consultation with the supervisory authority, taking into account the information available to Propelos.
14. Personal data breaches
Propelos notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, and aims to do so within 72 hours. The notice describes, as far as is known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Propelos adds information as it becomes available.
15. Deletion or return at the end of the Services
When the Customer’s subscription ends, Propelos keeps the personal data for 90 days, so that the Customer can restart the Services or ask for a copy, and then deletes it, unless EU or Spanish law requires Propelos to keep it. During those 90 days the Customer may ask us to return its enquiries in a common format (CSV) or to delete the data sooner. Copies in our providers’ backup systems are deleted as those backups expire.
16. Audits and information
Propelos makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allows for audits, including inspections, by the Customer or an auditor it appoints. The Customer gives at least 30 days’ written notice, and audits take place during business hours, no more than once a year (unless a supervisory authority requires it or there has been a personal data breach), under confidentiality and at the Customer’s cost. Propelos may first answer by providing documentation, where that is enough to demonstrate compliance.
17. Liability and order of precedence
Each party’s liability under this DPA is subject to the limitations in the Terms of Service, except where the law does not allow liability to be limited. If this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.
18. Governing law and jurisdiction
This DPA is governed by the laws of Spain. Any dispute arising from or in connection with it is subject to the exclusive jurisdiction of the courts of Málaga, Spain.
19. Contact
For questions about this DPA, or to exercise the Customer’s rights under it: privacy@propelos.com
Address: Propelos Technology S.L., The Pool Marbella, El Corte Inglés El Capricho, 1 planta Avda. Bulevar Príncipe Alfonso de Hohenlohe 2, Marbella, 29602, Spain
Tax ID (NIF): B27624980
Registered in the Mercantile Registry of Málaga, sheet MA-197845 (electronic volume and folio), IRUS 1000471597682
See also: Terms of Service · Privacy Policy