1. Application and roles
This Data Processing Addendum (DPA) forms part of the B2B Terms of Service or other agreement between AZ Technologies SRL (processor) and the customer (controller) when Renovae processes personal data in customer content on the customer's behalf. Terms such as controller, processor, personal data, processing, and supervisory authority have the meanings given in the GDPR.
For business-contact, billing, security, and service-management data that AZ Technologies SRL determines independently, it acts as controller under the Privacy and Retention Policy rather than as processor under this DPA.
2. Processing instructions
AZ Technologies SRL will process customer personal data only on documented instructions in the agreement, the customer's configured actions, and support requests, including transfers needed to provide the service. If an instruction appears to violate data-protection law, we will inform the customer unless prohibited by law and may pause the affected processing.
3. Processing details
- Subject and purpose: hosting, transforming, generating, organizing, displaying, publishing, exporting, securing, supporting, and deleting property-project content.
- Duration: the applicable trial or subscription plus the deletion periods in the Privacy and Retention Policy.
- Nature: collection, storage, retrieval, consultation, transmission to subprocessors, image transformation, organization, display, restriction, and deletion.
- Data subjects: property owners, occupants, visitors, photographers, agents, customer staff, and other persons incidentally visible or identifiable in customer content.
- Data types: images, panoramas, visual property details, prompts, project labels, contact details, account/access data, device/network data, and any personal data the customer chooses to include.
- Special-category data: not intended or required. The customer must not upload it unless expressly agreed and lawfully supported by appropriate safeguards.
4. Confidentiality and security
Persons authorized to process customer personal data are bound by confidentiality. AZ Technologies SRL will maintain measures appropriate to the risk, including access controls, secret and token protection, transmission encryption, provider controls, logging, recovery arrangements, and periodic review. The customer is responsible for secure sharing of invitation, workspace, embed, and publication links.
5. Subprocessors
The customer gives general authorization to use subprocessors needed for the service. Current categories and providers include Vercel (hosting), Neon (PostgreSQL database), Cloudflare (R2 object storage and Turnstile security), Clerk (administrator authentication), Resend (email delivery), and OpenAI (AI image processing). Their role depends on the enabled feature.
We will provide reasonable advance notice of a material new subprocessor by updating this page or notifying the customer's business contact. The customer may object on reasonable data-protection grounds before the change takes effect. The parties will work in good faith on an alternative; if none is reasonably available, either party may terminate the affected feature.
We impose data-protection obligations on subprocessors appropriate to their role. For restricted international transfers, we use a valid transfer mechanism such as adequacy or standard contractual clauses where required.
6. Assistance
Taking account of the nature of processing and available information, we will reasonably assist the customer with data-subject requests, security, breach assessment and notification, impact assessments, and supervisory-authority consultations. Additional work beyond ordinary product controls may be charged at an agreed professional-services rate where legally permitted.
7. Personal-data breaches
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data and provide information reasonably available about its nature, likely consequences, affected records, and mitigation. Notification is not an admission of fault. The customer remains responsible for notifications required of it as controller.
8. Return, deletion, and audit information
At the end of the service, and subject to the Privacy and Retention Policy, we will delete or return customer personal data at the customer's choice where the product supports export, unless law requires retention. Residual encrypted backups are isolated from ordinary use and overwritten through the normal backup cycle.
We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR, initially through documentation and written responses. On reasonable notice, the customer may request an audit where documentation is insufficient. Audits must protect other customers, security, and confidentiality, avoid unreasonable disruption, and be paid by the customer unless they reveal a material breach by AZ Technologies SRL.
9. Order of precedence and contact
This DPA prevails over conflicting general service terms for its subject matter. The standard contractual clauses, where applicable, prevail over this DPA. Data-protection questions and requests should be sent to hello@aztechnologies.be.