Data Processing Agreement
Last updated: May 29, 2026 — Araneo s.r.o. | Chalupkova 7981/4, Bratislava 811 09, Slovakia | IČO: 57 562 351
By accepting Araneo's Terms of Service, you (the "Controller") enter into this Data Processing Agreement ("DPA") with Araneo s.r.o. (the "Processor"). This DPA is incorporated by reference into the Terms of Service and takes effect from the date you create your Araneo account. No separate signature is required.
This DPA governs how Araneo processes personal data on your behalf in connection with the Services, pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR") and Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA").
1. Definitions
Terms defined in the GDPR — including "personal data", "processing", "data subject", "controller", "processor", "sub-processor", and "personal data breach" — have the meanings given to them there. Additionally:
- "Services" means the AI-powered lead qualification, CRM, and rental agent productivity platform provided by Araneo under the Terms of Service
- "Controller Personal Data" means personal data submitted to or generated through the Services by the Controller
- "Tenant Data" means personal data of tenant applicants collected through the AI screening conversation on behalf of the Controller
2. Roles of the Parties
With respect to Tenant Data and other personal data processed through the Services, Araneo acts as the data processor and you — the rental agent or agency subscribing to the Services — act as the data controller. You determine the purposes and means of the screening process; Araneo processes personal data only to deliver the Services as you direct.
Where Araneo processes your account and billing data for its own purposes (account management, billing, fraud prevention), Araneo acts as an independent data controller governed by the Privacy Policy.
3. What Araneo Processes on Your Behalf
Nature of processing
- Collection of tenant applicant responses through automated conversational AI screening via Facebook Messenger and WhatsApp
- Analysis and scoring of tenant responses using AI to generate HOT/WARM/COLD lead classifications
- Storage of lead profiles, scores, and full conversation transcripts in your dashboard
- Delivery of HOT lead alerts to you via WhatsApp
- Delivery of WARM lead summaries via email digest
- Display of tenant data and pipeline analytics in your CRM dashboard
- Export of tenant data at your direction — for example via PDF export
- Publication of listing posts to your Facebook Business Page via the Facebook Graph API
- Creation and management of Facebook ad campaigns on your behalf via the Facebook Marketing API
Categories of data subjects
- Tenant applicants who interact with your AI screening system through Facebook Messenger or WhatsApp
- Your authorised users and agents who access the Araneo platform
Categories of personal data
- Tenant applicants: name, email address, phone number, monthly income (self-reported), employment type, credit score range (self-reported), move-in date, number of occupants, guarantor availability, document readiness, rental history, pet ownership, smoking status (optional), full conversation transcript, AI-generated lead score and HOT/WARM/COLD classification, Facebook Page-Scoped User ID (Messenger users), WhatsApp phone number (WhatsApp users)
- Your authorised users: name, email address, WhatsApp phone number used for HOT alerts, Facebook Business Page credentials
4. How Araneo Processes Your Data
4.1 Araneo processes Controller Personal Data only to provide the Services and only in accordance with your documented instructions, as set out in the Terms of Service and this DPA. Araneo will not use Controller Personal Data for any other purpose.
4.2 Araneo will inform you immediately if it believes an instruction from you would infringe applicable data protection law.
4.3 Araneo ensures that all personnel with access to Controller Personal Data are subject to binding confidentiality obligations.
4.4 Araneo applies the principle of data minimisation — processing only personal data that is adequate, relevant, and limited to what is necessary to deliver the Services.
4.5 AI lead scoring and qualification is performed on Araneo's own self-hosted infrastructure. Tenant screening data is not transmitted to or processed by any third-party AI provider.
5. Sub-processors
By accepting the Terms of Service, you provide general authorisation for Araneo to engage the sub-processors listed in Schedule 1 below. Araneo will notify you of any intended changes to sub-processors — including additions or replacements — by updating Schedule 1 and posting a notice at araneo.io/dpa at least thirty (30) days before any new sub-processor begins processing your data. If you reasonably object to a new sub-processor on data protection grounds, please contact hello@araneo.io and we will work in good faith to address your concern.
Each sub-processor is required to process personal data only for the purposes for which they were engaged and is bound by appropriate data protection obligations.
6. Security Measures
Araneo implements the technical and organisational measures described in Schedule 2 below to protect Controller Personal Data against unauthorised or unlawful processing, accidental loss, destruction, or damage.
These measures are regularly reviewed and updated. Where a change to security measures would materially reduce the level of protection, Araneo will notify you in advance.
7. Data Subject Rights
7.1 Araneo will assist you in responding to data subject requests under applicable law — including rights of access, rectification, erasure, restriction, portability, and objection — within the timescales required. Where Araneo receives a data subject request directly, it will promptly forward it to you and not respond to the data subject except as you direct or as required by law.
7.2 Tenant applicants may opt out of automated screening at any time by replying STOP to a Messenger or WhatsApp message. Araneo will immediately cease processing that individual's screening conversation.
8. Personal Data Breaches
Araneo will notify you without undue delay, and where feasible within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will include the nature of the breach, approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it. Where full information is not available within 48 hours, Araneo will provide initial notification and follow up with additional details as they become available.
Araneo will cooperate fully with you in investigating and remedying any breach and in making any required notifications to supervisory authorities or data subjects.
9. International Data Transfers
Araneo's primary data storage is in Canada (Supabase ca-central-1), which benefits from an EU adequacy decision under GDPR Article 45. Workflow automation processing occurs within Germany (Hetzner VPS, Frankfurt), which is within the EEA and subject to GDPR directly.
Where personal data is processed by sub-processors in the United States — specifically Meta and Stripe — Araneo relies on those providers' data processing agreements and applicable transfer safeguards. See Schedule 1 for details. Araneo will promptly notify you if any transfer safeguard it relies upon becomes invalid or unenforceable.
10. Retention and Deletion
10.1 Araneo retains Controller Personal Data only for as long as necessary to provide the Services or as required by applicable law. Specific retention periods are described in the Privacy Policy.
10.2 You may delete individual tenant lead records at any time through the Araneo dashboard. Araneo will remove those records from primary systems within 72 hours.
10.3 Upon termination of your account, Araneo will delete or return all Controller Personal Data within 30 days at your election, except:
- Billing and transaction records retained for up to 7 years under applicable accounting law
- Data in system backups, which may persist for up to 90 days and which is not accessible or used for any purpose during that period
10.4 Araneo cannot delete data held independently by sub-processors. You must contact those sub-processors directly to exercise deletion rights against data they hold independently.
11. Your Responsibilities as Controller
11.1 You confirm that you have and will maintain a valid legal basis for directing Araneo to process Controller Personal Data under this DPA.
11.2 You are responsible for ensuring that tenant applicants are informed that they are interacting with an automated AI system, that their responses will be used to generate a qualification score, and that their responses are processed by Araneo's automated AI scoring system. Where required by law, you must obtain explicit informed consent from tenants before directing them to interact with Araneo's screening system.
11.3 You are solely responsible for ensuring that your use of AI lead scoring complies with applicable human rights legislation, including the Canadian Human Rights Act, the Ontario Human Rights Code, and equivalent provincial legislation. You must not use AI outputs to make rental decisions that discriminate on any protected ground.
11.4 You must not instruct Araneo to process personal data in a manner that would cause Araneo to violate applicable data protection law.
12. Audit Rights
Araneo will make available to you all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections conducted by you or your appointed auditor. Audit requests must be submitted in writing with at least 30 days notice. Audits may be conducted no more than once per calendar year, at your expense, and subject to reasonable confidentiality obligations.
13. Liability and Governing Law
This DPA is governed by the laws of the Slovak Republic and forms part of the Terms of Service. Liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Where both Parties are responsible for a data protection breach, liability shall be apportioned in accordance with their respective responsibilities.
14. Updates to This DPA
Araneo may update this DPA from time to time to reflect changes in applicable law, our processing activities, or sub-processors. We will provide at least 30 days notice of any material changes by posting an updated version at araneo.io/dpa and notifying you by email. Continued use of the Services after the effective date of any update constitutes acceptance of the updated DPA.
Schedule 1 — Authorised Sub-processors
The following sub-processors are authorised as of the date shown above. Araneo will notify you of any changes at least 30 days in advance.
| Sub-processor | Location | Purpose | Safeguard |
|---|---|---|---|
| Supabase | Canada (ca-central-1) | Primary database storage | Canada has EU adequacy decision under GDPR Article 45 |
| n8n / Hetzner VPS | Frankfurt, Germany (EEA) | Workflow automation | Processing within EEA — GDPR applies directly |
| Meta (Facebook/WhatsApp) | United States | Messenger and WhatsApp messaging; Facebook Graph API | Meta Business Data Processing Terms |
| Stripe | United States | Payment processing (Controller billing data only) | Stripe Data Processing Agreement |
The full Privacy Policy including current processor details is available at araneo.io/privacy-policy.
Schedule 2 — Technical and Organisational Security Measures
Araneo implements the following measures pursuant to Article 32 GDPR:
Encryption
- All data at rest encrypted using AES-256
- All data in transit encrypted using TLS 1.2 or higher (HTTPS)
- API keys and credentials stored as encrypted environment variables, never in source code
Access controls
- Role-based access control — users access only data relevant to their account
- Multi-factor authentication available for all dashboard accounts
- API access restricted by scoped authentication tokens
- Internal system access limited to authorised Araneo personnel on a need-to-know basis
Infrastructure
- Primary database on Supabase Canada (ca-central-1) — ISO 27001 certified infrastructure
- Workflow automation on self-hosted n8n (Hetzner VPS, Frankfurt) — ISO 27001 certified
- Automated encrypted backups with defined retention schedules
Incident response
- Documented internal incident response procedure
- Personnel trained on personal data breach identification and reporting
- Internal breach register maintained regardless of whether regulatory notification is required
Organisational measures
- Confidentiality obligations on all personnel with access to personal data
- Data minimisation applied throughout — only data necessary to deliver the Services is processed
- Regular review and testing of security measures
Contact
Araneo s.r.o.
Chalupkova 7981/4, Bratislava 811 09, Slovakia
hello@araneo.io