Data Processing Agreement
Version: 2026-09-06
*Translation for convenience. The Spanish original prevails in case of discrepancy.*
This agreement forms part of the Mansaria Terms of Use and is accepted together with them. Without it, the Agency cannot process personal data of its clients through the platform (art. 28 GDPR).
1. Parties and roles
- Controller: the Agency that subscribes to Mansaria. It decides what data it enters, for what purpose and for how long.
- Processor: Myroslav Podryhulia, tax ID Y9837838Q (NIE), domiciled at calle La Laja, 7, 38678 Adeje, Santa Cruz de Tenerife, Spain (“Mansaria”). Processes data only on documented instructions from the Controller.
The documented instructions are these Terms and the ordinary use of the product’s features.
2. Subject matter, duration and nature
Provision of a cloud service for real estate management: clients, properties, demands, deals, viewings, documents and communications; and, for agencies that use them, holiday rentals with booking and stay management, cleanings, payouts to providers, invoicing and bank reconciliation, electronic signature, and submission of the guest report to the authorities.
Processing lasts as long as the service contract is in force.
3. Categories of data subjects and data
- Data subjects: clients and prospective clients of the Agency; property owners; guarantors and document signatories, who are not always clients; guests and travellers staying at a property, including minors; employees of the Agency as users of the CRM.
- Identification data: name, surname, email, phone, language, nationality, address.
- Document data: NIE, passport, tax ID, document type, number and support number, and documents provided by the client (contracts, receipts).
- Stay data: date of birth, sex, nationality and, for minors, relationship. These are collected because the guest report requires them (RD 933/2021) and are submitted to the Ministry of the Interior.
- Financial data: deal amounts, commissions, expenses, financing details and bank transactions imported by the Agency.
- Communications: notes, emails sent, consents and their evidence.
- Handwritten signature: the image of the stroke used to sign a document.
- Technical data tied to an action: IP address and user agent on forms, consents and signatures. They are kept because they are the evidence of who acted and when; under the GDPR they are personal data, which is why they are declared here.
- Use of the selection sent to the client: whether it was opened and what the client answered.
No special categories under art. 9 GDPR are collected in dedicated fields. The system allows documents to be attached and has free-text fields, so this statement rests on the instruction given to the Agency and not on a technical restriction: if the Agency enters such data, it does so under its sole responsibility.
4. Mansaria’s obligations
- Process data only on the Controller’s instruction, never for its own purposes nor to build commercial profiles.
- Maintain confidentiality, also after the contract ends, and require it from its personnel.
- Apply the art. 32 GDPR measures described in Annex I.
- Assist the Controller in responding to data subject rights (access, rectification, erasure, portability, objection).
- Notify the Controller without undue delay and within 48 hours at the latest of any security breach affecting its data, with the information needed for notification to the supervisory authority.
- Make available the information needed to demonstrate compliance and allow audits with reasonable notice.
- On termination, at the Controller’s choice, return or delete the data. Export is available inside the product itself.
5. Subprocessors
The Controller generally authorises the engagement of the subprocessors listed in SUBENCARGADOS.md, published on the website.
Mansaria will give 30 days’ notice of any addition or replacement. If the Controller objects on reasoned grounds within that period and no solution is found, it may terminate the contract without penalty.
6. International transfers
Some subprocessors are outside the European Economic Area. In those cases the transfer relies on the European Commission’s Standard Contractual Clauses or on a valid adequacy decision, as detailed in the subprocessor list.
7. Retention
Mansaria keeps the data for as long as the Agency maintains the account.
Express warning: the Agency may be required by Spanish Law 10/2010 on the prevention of money laundering to keep client documentation for ten years. A data subject’s right to erasure does not override that legal obligation of the Controller, and it is the Controller who decides what is deleted and when.
8. Liability
Each party is liable for its own breaches. Mansaria is not liable for the content the Agency enters nor for the lawfulness of the legal basis the Agency invokes towards its clients.
Annex I — Security measures
- Encryption in transit (TLS) and at rest in the database.
- Isolation between agencies through row-level policies in the database: one agency cannot read another’s rows even if the application fails.
- Role-based access control and configurable client visibility.
- Two-step verification available for every account.
- Change log for deals, properties, clients and consents.
- Document storage in a private bucket with time-limited signed links.
- Own daily encrypted backups. Every night the complete database — including the access accounts — and all stored files are copied. The copy is encrypted with an asymmetric key whose private half is kept offline, so the storage provider cannot read it. The system that performs the backup does handle the data in the clear while creating and verifying it — a copy that is never verified is not a copy: it runs in the European Union (Scaleway, Paris), in memory where it fits, and the plaintext is deleted as soon as the copy is encrypted and never leaves that machine. It is kept for thirty days in object storage located in the European Union, at two separate providers.
- Backup verification. Each copy is checked automatically when created (that the dump reads through in full and contains the access accounts) and compared against the history to catch a copy that is readable yet incomplete. Quarterly, a test restore is performed onto a separate database and the restored content is compared with the original.
- Mutual monitoring. The system that runs the backups and the application watch each other and send an email alert if either stops, because missing backups produce no visible symptom on their own.