Data Processing Agreement
Last updated: 28 September 2026
This data processing agreement applies between the customer and Rentoutbase when the customer uses Rentoutbase to process personal data about tenants and others. It forms part of the customer agreement and applies together with our terms of service, without a separate signature. A customer who wants a signed copy can request one at support@rentoutbase.com.
1. Background and roles
The customer is the landlord or company that has an agreement with Rentoutbase to use the service. The customer is the controller of the personal data it enters or collects through the service about tenants and others.
Rentoutbase is operated by Embrik Skrindo (sole proprietor), Norway, and is the processor of that data.
Personal data about the customer as a customer of Rentoutbase, such as account and billing details, is processed by Rentoutbase as controller. That is described in the privacy policy and is not covered by this agreement.
This agreement is intended to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).
2. Purpose, nature and duration
Purpose. Rentoutbase processes the personal data to provide the service to the customer: managing properties and buildings, tenants, digital leases with e-signing, rent tracking, damage reports and maintenance, messages and announcements to tenants, finances, the customer’s public listing site and the tenant app.
Nature. The processing consists of collection (data the customer enters, and data tenants and applicants submit through the tenant app, the tenant portal or the customer’s listing site), storage, organisation, retrieval, display and transmission (emails and push notifications the customer triggers or has set up). When the customer uses an AI feature or has switched on Rob AI, it also includes analysis and drafting with artificial intelligence. It further includes export and deletion.
Rentoutbase does not process the personal data for its own purposes, does not sell it and does not use it for marketing.
Duration. The processing lasts for as long as the customer agreement is in force, and after that until the personal data has been deleted or returned under section 13.
3. Data subjects and personal data
This agreement covers personal data about these categories of data subjects:
- tenants and co-tenants, including former and upcoming tenants
- other parties to or signatories of a lease
- applicants and others who send an enquiry through the customer’s listing site
- the customer’s employees and other users the customer gives access to the service
- other people named in messages, damage reports or documents, such as contractors
This agreement covers these categories of personal data:
- names and contact details, such as email, phone and address
- identity details included in a lease, such as date of birth or national identity number
- tenancies and contracts: property, lease period, rent, deposit, contract documents, signatures and signing times
- rent records: amounts due, amounts recorded as received, and reminders
- messages between the customer and tenants, and announcements to tenants
- damage reports with descriptions, photos, status and notes
- access codes and push tokens for the tenant app
- enquiries from applicants: name, contact details and message
- for the customer’s users: name, email, role and permissions
The service is not designed for special categories of personal data (Article 9) or data relating to criminal convictions and offences (Article 10). The customer shall not enter such data unless it is necessary.
4. The customer’s obligations
- The customer is responsible for having a legal basis for the processing, for informing data subjects about it, and for the instructions it gives being lawful.
- The customer decides what data is entered and how long it is kept in the service, and shall not enter more data than necessary.
- The customer is responsible for its own users: who has access, what permissions they have, and keeping sign-in details secret.
5. Instructions and confidentiality
Rentoutbase processes the personal data only on documented instructions from the customer. The instructions are this agreement, the customer agreement and the customer’s use and settings of the service, including actions the customer requests or approves in Rob AI.
If EEA or Norwegian law requires Rentoutbase to process the data otherwise, Rentoutbase informs the customer before the processing starts, unless that law prohibits it. If Rentoutbase considers that an instruction infringes data protection law, it informs the customer immediately.
Everyone who processes the personal data on behalf of Rentoutbase is bound by confidentiality, by agreement or by law.
6. Rob AI and integrations
- Rob AI is switched off until the customer switches him on. When Rob is paused, all of Rob’s processing stops.
- The AI features send personal data to OpenAI (API) only when the customer uses an AI feature or has switched on Rob AI, and only the data relevant to the request.
- Rob never writes and sends a message to a tenant on his own. A message Rob has drafted is sent only once the customer has approved the exact text. Standard rent reminder emails are sent automatically only where they have been switched on for the account; they are off when Rob is first activated.
- Rob changes data in the customer’s account, such as recording a rent payment or adding a calendar event, only when the customer explicitly asks. If the customer asks for an action after Rob has read text written by a tenant or applicant, the action is placed in the approval queue instead of being performed. Every action Rob takes is logged.
- Rob remembers facts only from the customer’s own messages, never from text written by tenants.
- Integrations the customer connects with an API key can read data within that key’s scope but cannot change anything directly. They can only submit proposals that the customer must approve.
- Rentoutbase does not train its own AI models on the customer’s personal data.
7. Security
Rentoutbase implements technical and organisational measures under Article 32. At present these are:
- All traffic to and from the service uses HTTPS.
- Passwords are handled by Supabase Auth and never stored in plain text.
- The database is closed to Supabase’s public Data API: row level security is enabled on every table, with no public access.
- Sign-in is protected by limits on the number of attempts, and each user can turn on two-step sign-in with a one-time code by text message.
- Documents and photos from damage reports and inspections are stored privately and opened only through links that cannot be guessed.
- The customer’s employees get role-based permissions, which can be limited to specific buildings or apartments.
- API keys are shown once, stored only as hashes, limited to specific data categories and optionally buildings or apartments, rate limited, revocable at any time, and every call is logged.
- A message Rob has drafted is not sent to a tenant until the customer has approved the exact text, and Rob’s actions are logged.
- Administrative actions taken by Rentoutbase are logged.
Rentoutbase holds no security certifications. The customer should assess whether these measures give a level of security appropriate to its processing. Rentoutbase may change the measures, but not in a way that lowers the level of security.
8. Sub-processors
The customer gives general prior authorisation for Rentoutbase to use the sub-processors on the list of sub-processors.
Rentoutbase uses only sub-processors bound by written data protection obligations that meet Article 28(4), and remains responsible to the customer for their performance of those obligations.
Before a new or replacement sub-processor starts processing personal data on the customer’s behalf, Rentoutbase updates the list and notifies the customer by email at least 30 days in advance.
Within that period the customer may object in writing on reasonable data protection grounds. The parties shall then try to find a solution. If they cannot, the customer may terminate the customer agreement with effect before the change takes effect.
9. Transfers outside the EEA
The service’s database and file storage are in the EU (Ireland), and its server functions run in Ireland. Some sub-processors are US companies or may process data outside the EEA, as shown on the list of sub-processors. Such transfers take place under the sub-processor’s data processing terms.
Rentoutbase does not transfer the personal data outside the EEA other than through the sub-processors on the list, and shall ensure that those transfers have a valid basis under Chapter V of the GDPR.
10. Assistance to the customer
In the service, the customer can itself view, correct and delete data about tenants and others. If the customer needs more to answer a request from a data subject, such as for access, rectification, erasure or data portability, Rentoutbase assists on request.
If Rentoutbase receives such a request directly, it forwards it to the customer without undue delay. Rentoutbase does not answer the data subject on the customer’s behalf, other than to refer them to the customer.
Rentoutbase also assists the customer with its obligations under Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation with the supervisory authority), taking into account the nature of the processing and the information available to Rentoutbase.
11. Personal data breaches
Rentoutbase notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer’s personal data.
The notice is sent to the email address of the account owner and describes, as far as known: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information not available at first is provided as it becomes available.
Rentoutbase takes reasonable steps to limit the harm. As controller, the customer notifies the Norwegian Data Protection Authority (Datatilsynet) and, where required, the data subjects.
12. Audits and documentation
Rentoutbase makes available all information necessary to demonstrate compliance with this agreement and Article 28, and keeps a record of processing activities under Article 30(2).
The customer, or an independent auditor it appoints, may carry out audits, including inspections. An audit is notified in writing at least 30 days in advance, is carried out during normal working hours without disrupting operations more than necessary, and the auditor is bound by confidentiality. Rentoutbase may first respond with written documentation; if that is not sufficient, the audit goes ahead. Each party bears its own costs.
Sub-processors are audited through the documentation and rights they provide under their own terms.
13. Deletion and return
While the agreement is in force, the customer can correct and delete data in the service and download account data under Settings → Download your data. The customer can also request a complete copy of the personal data in a machine-readable format.
When the customer agreement ends, the customer may within 30 days request the return of the personal data in a machine-readable format. No later than 60 days after the agreement ended, Rentoutbase deletes the personal data processed on the customer’s behalf, including uploaded files, unless EEA or Norwegian law requires it to be kept. Rentoutbase confirms the deletion in writing on request.
Data held by sub-processors is deleted in accordance with their terms.
14. Term, precedence, changes and governing law
- This agreement applies for as long as Rentoutbase processes personal data on the customer’s behalf.
- If this agreement and the customer agreement conflict, this agreement prevails as regards the processing of personal data.
- Liability under this agreement is governed by the limitation of liability in the terms of service, unless mandatory law provides otherwise.
- Changes to this agreement are notified in the same way as changes to the terms of service. Changes to sub-processors follow section 8.
- This agreement is governed by Norwegian law, with the same venue as the terms of service.
- This agreement is available in Norwegian and English. If they differ, the Norwegian text prevails.
15. Contact
Questions about this agreement or data protection: support@rentoutbase.com. Rentoutbase is not required to appoint a Data Protection Officer; Embrik Skrindo is the point of contact for data protection.