Privacy Policy

Nesore

Last updated: 13 August 2026

NESORE

Operated by Zofte s. r. o.

DATA PROCESSING AGREEMENT

Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)

This is an English translation of the original Slovak-language Data Processing Agreement, provided for the convenience of users. In the event of any discrepancy between this translation and the Slovak original, the Slovak version shall prevail. The contractual aspects of this Agreement are governed by the laws of the Slovak Republic.


Parties

Controller: the Landlord – the user who, through the Platform, manages the personal data of their tenants (hereinafter the "Controller")

Processor: Zofte s. r. o. (hereinafter the "Processor")

This Data Processing Agreement (hereinafter the "Agreement") is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 (GDPR) and forms an integral part of the Platform's Terms and Conditions. It is concluded at the moment the Controller first enters the personal data of their tenants or other data subjects into the Platform.


Article I – Subject Matter and Duration of Processing

The subject matter is the processing of personal data of data subjects entered or managed by the Controller through the Platform, carried out by the Processor on the Controller's behalf for the purpose of providing the Platform's functionalities related to managing the tenancy relationship. Processing continues for the duration of the contractual relationship between the parties under the Terms and Conditions and ends in accordance with Article VII of this Agreement.


Article II – Nature, Purpose and Scope of Processing

ItemDescription
Nature of processingHosting, storage, organisation, disclosure, backup and deletion of data through the Platform
Purpose of processingManagement of the tenancy relationship by the landlord: recording of tenants, payments and invoices, communication, issue reports
Categories of data subjectsTenants and prospective tenants, and possibly other persons named by the landlord (e.g. co-occupants)
Categories of personal dataIdentification and contact details, data on the tenancy relationship, payment data, content of communications, content of issue reports
Special categoriesGenerally not processed; should the Controller enter such data, they undertake to ensure a valid legal basis pursuant to Art. 9 GDPR

Article III – Obligations of the Processor

The Processor undertakes to:

  1. process personal data only on the documented instructions of the Controller, except where required to do so by EU or Slovak law; in such a case, it shall inform the Controller of that legal requirement before processing, unless that law prohibits such information;
  2. ensure that persons authorised to process the data have committed themselves to confidentiality;
  3. take appropriate technical and organisational measures pursuant to Article 32 GDPR, further specified in Annex 2;
  4. comply with the conditions for engaging a further processor set out in Article IV;
  5. assist the Controller in responding to requests from data subjects exercising their rights;
  6. assist in complying with the obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessment);
  7. at the end of the provision of services, at the Controller's choice, delete or return all personal data and delete existing copies, unless their retention is required by EU or Slovak law;
  8. make available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allow for audits, including inspections.

Article IV – Sub-processors

The Controller grants the Processor general authorisation to engage further processors to ensure the technical functions of the Platform (hosting, storage, e-mail, payment gateway). The Processor maintains an up-to-date list in Annex 1, informs the Controller of any changes in advance, and gives the Controller the opportunity to object. It shall impose the same data protection obligations on each sub-processor and remains liable to the Controller for their performance.


Article V – International Transfers

Where processing involves a transfer outside the EEA, the Processor shall ensure appropriate safeguards under Chapter V GDPR, in particular standard contractual clauses (Commission Implementing Decision (EU) 2021/914) or an adequacy decision. The specific mechanism and sub-processor concerned are set out in Annex 1.


Article VI – Notification of Personal Data Breaches

The Processor shall notify the Controller of any personal data breach without undue delay after becoming aware of it, describing the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures taken, so that the Controller may fulfil its obligations under Articles 33 and 34 GDPR.


Article VII – Duration and Termination

This Agreement takes effect upon the first entry of personal data into the Platform and remains in effect for the duration of the Terms and Conditions. It ends upon termination of the Terms and Conditions. Upon termination, the Processor shall deal with the data in accordance with Article III(7).

Notwithstanding termination, the obligations of confidentiality, the obligation to delete or return data, and liability for any breach arising before termination remain in effect.


Article VIII – Records and Audit

The Processor keeps records of processing activities carried out on behalf of the Controller pursuant to Article 30(2) GDPR and shall make them available upon request. An audit is carried out on the basis of at least 14 days' prior notice, no more than once every 12 months, except for an audit triggered by a breach; the costs of a routine audit are borne by the Controller, and the costs of an audit triggered by a proven breach are borne by the Processor.


Article IX – Governing Law

The contractual aspects of this Agreement are governed by the laws of the Slovak Republic. This does not affect the direct applicability of the GDPR.


Annexes

  • Annex 1 – List of approved sub-processors and the mechanism for international transfers;
  • Annex 2 – Technical and organisational security measures (TOMs) pursuant to Article 32 GDPR.

Annex 1 – List of Approved Sub-processors

Sub-processor (e.g.)PurposeLocationTransfer mechanism
Vercel Inc.Hosting / application deploymentUSAStandard Contractual Clauses (SCC)
SupabaseData storageEU / Zofte s. r. o.within the EEA / SCC if outside
ResendDelivery of transactional e-mailsEU / Zofte s. r. o.within the EEA / SCC if outside

Annex 2 – Technical and Organisational Measures (TOMs)

A. Encryption and transmission

  • encryption of transmission via TLS 1.2/1.3 (HTTPS);
  • passwords stored as a cryptographic hash (bcrypt).
  • properly configured CORS
  • encryption of data at rest is provided by the hosting provider (Supabase) — AES-256 at rest, TLS in transit

B. Access control

  • principle of least privilege and role-based access control;
  • Sanctum tokens — access/refresh with rotation
  • thorough input validation

C. Resilience and incidents

  • regular backups and restore testing;
  • monitoring of security events (error monitoring);
  • incident management process, including breach notification.
  • SQL injection protection

D. Organisational measures

  • confidentiality commitment for all persons with access;
  • regular data protection training;
  • contractual data protection safeguards with sub-processors.

Signatures of the Parties

The Agreement is deemed concluded at the moment described in the introduction. The following signature block is provided for confirmation in paper or electronically signed form, where applicable.

For the Controller (Landlord):

Name / business name: ______________________________

Date: ______________________________

Signature: ______________________________

For the Processor (Zofte s. r. o.):

Name and position: ______________________________

Date: ______________________________

Signature: ______________________________