Data Processing Agreement

Last updated: May 29, 2026 — Araneo s.r.o. | Chalupkova 7981/4, Bratislava 811 09, Slovakia | IČO: 57 562 351

By accepting Araneo's Terms of Service, you (the "Controller") enter into this Data Processing Agreement ("DPA") with Araneo s.r.o. (the "Processor"). This DPA is incorporated by reference into the Terms of Service and takes effect from the date you create your Araneo account. No separate signature is required.

This DPA governs how Araneo processes personal data on your behalf in connection with the Services, pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR") and Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA").

1. Definitions

Terms defined in the GDPR — including "personal data", "processing", "data subject", "controller", "processor", "sub-processor", and "personal data breach" — have the meanings given to them there. Additionally:

2. Roles of the Parties

With respect to Tenant Data and other personal data processed through the Services, Araneo acts as the data processor and you — the rental agent or agency subscribing to the Services — act as the data controller. You determine the purposes and means of the screening process; Araneo processes personal data only to deliver the Services as you direct.

Where Araneo processes your account and billing data for its own purposes (account management, billing, fraud prevention), Araneo acts as an independent data controller governed by the Privacy Policy.

3. What Araneo Processes on Your Behalf

Nature of processing

Categories of data subjects

Categories of personal data

4. How Araneo Processes Your Data

4.1  Araneo processes Controller Personal Data only to provide the Services and only in accordance with your documented instructions, as set out in the Terms of Service and this DPA. Araneo will not use Controller Personal Data for any other purpose.

4.2  Araneo will inform you immediately if it believes an instruction from you would infringe applicable data protection law.

4.3  Araneo ensures that all personnel with access to Controller Personal Data are subject to binding confidentiality obligations.

4.4  Araneo applies the principle of data minimisation — processing only personal data that is adequate, relevant, and limited to what is necessary to deliver the Services.

4.5  AI lead scoring and qualification is performed on Araneo's own self-hosted infrastructure. Tenant screening data is not transmitted to or processed by any third-party AI provider.

5. Sub-processors

By accepting the Terms of Service, you provide general authorisation for Araneo to engage the sub-processors listed in Schedule 1 below. Araneo will notify you of any intended changes to sub-processors — including additions or replacements — by updating Schedule 1 and posting a notice at araneo.io/dpa at least thirty (30) days before any new sub-processor begins processing your data. If you reasonably object to a new sub-processor on data protection grounds, please contact hello@araneo.io and we will work in good faith to address your concern.

Each sub-processor is required to process personal data only for the purposes for which they were engaged and is bound by appropriate data protection obligations.

6. Security Measures

Araneo implements the technical and organisational measures described in Schedule 2 below to protect Controller Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage.

These measures are regularly reviewed and updated. Where a change to security measures would materially reduce the level of protection, Araneo will notify you in advance.

7. Data Subject Rights

7.1  Araneo will assist you in responding to data subject requests under applicable law — including rights of access, rectification, erasure, restriction, portability, and objection — within the timescales required. Where Araneo receives a data subject request directly, it will promptly forward it to you and not respond to the data subject except as you direct or as required by law.

7.2  Tenant applicants may opt out of automated screening at any time by replying STOP to a Messenger or WhatsApp message. Araneo will immediately cease processing that individual's screening conversation.

8. Personal Data Breaches

Araneo will notify you without undue delay, and where feasible within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will include the nature of the breach, approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it. Where full information is not available within 48 hours, Araneo will provide initial notification and follow up with additional details as they become available.

Araneo will cooperate fully with you in investigating and remedying any breach and in making any required notifications to supervisory authorities or data subjects.

9. International Data Transfers

Araneo's primary data storage is in Canada (Supabase ca-central-1), which benefits from an EU adequacy decision under GDPR Article 45. Workflow automation processing occurs within Germany (Hetzner VPS, Frankfurt), which is within the EEA and subject to GDPR directly.

Where personal data is processed by sub-processors in the United States — specifically Meta and Stripe — Araneo relies on those providers' data processing agreements and applicable transfer safeguards. See Schedule 1 for details. Araneo will promptly notify you if any transfer safeguard it relies upon becomes invalid or unenforceable.

10. Retention and Deletion

10.1  Araneo retains Controller Personal Data only for as long as necessary to provide the Services or as required by applicable law. Specific retention periods are described in the Privacy Policy.

10.2  You may delete individual tenant lead records at any time through the Araneo dashboard. Araneo will remove those records from primary systems within 72 hours.

10.3  Upon termination of your account, Araneo will delete or return all Controller Personal Data within 30 days at your election, except:

10.4  Araneo cannot delete data held independently by sub-processors. You must contact those sub-processors directly to exercise deletion rights against data they hold independently.

11. Your Responsibilities as Controller

11.1  You confirm that you have and will maintain a valid legal basis for directing Araneo to process Controller Personal Data under this DPA.

11.2  You are responsible for ensuring that tenant applicants are informed that they are interacting with an automated AI system, that their responses will be used to generate a qualification score, and that their responses are processed by Araneo's automated AI scoring system. Where required by law, you must obtain explicit informed consent from tenants before directing them to interact with Araneo's screening system.

11.3  You are solely responsible for ensuring that your use of AI lead scoring complies with applicable human rights legislation, including the Canadian Human Rights Act, the Ontario Human Rights Code, and equivalent provincial legislation. You must not use AI outputs to make rental decisions that discriminate on any protected ground.

11.4  You must not instruct Araneo to process personal data in a manner that would cause Araneo to violate applicable data protection law.

12. Audit Rights

Araneo will make available to you all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections conducted by you or your appointed auditor. Audit requests must be submitted in writing with at least 30 days notice. Audits may be conducted no more than once per calendar year, at your expense, and subject to reasonable confidentiality obligations.

13. Liability and Governing Law

This DPA is governed by the laws of the Slovak Republic and forms part of the Terms of Service. Liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Where both Parties are responsible for a data protection breach, liability shall be apportioned in accordance with their respective responsibilities.

14. Updates to This DPA

Araneo may update this DPA from time to time to reflect changes in applicable law, our processing activities, or sub-processors. We will provide at least 30 days notice of any material changes by posting an updated version at araneo.io/dpa and notifying you by email. Continued use of the Services after the effective date of any update constitutes acceptance of the updated DPA.

Schedule 1 — Authorised Sub-processors

The following sub-processors are authorised as of the date shown above. Araneo will notify you of any changes at least 30 days in advance.

Sub-processorLocationPurposeSafeguard
SupabaseCanada (ca-central-1)Primary database storageCanada has EU adequacy decision under GDPR Article 45
n8n / Hetzner VPSFrankfurt, Germany (EEA)Workflow automationProcessing within EEA — GDPR applies directly
Meta (Facebook/WhatsApp)United StatesMessenger and WhatsApp messaging; Facebook Graph APIMeta Business Data Processing Terms
StripeUnited StatesPayment processing (Controller billing data only)Stripe Data Processing Agreement

The full Privacy Policy including current processor details is available at araneo.io/privacy-policy.

Schedule 2 — Technical and Organisational Security Measures

Araneo implements the following measures pursuant to Article 32 GDPR:

Encryption

Access controls

Infrastructure

Incident response

Organisational measures

Contact

Araneo s.r.o.
Chalupkova 7981/4, Bratislava 811 09, Slovakia
hello@araneo.io