Legal
Data processing agreement
Version 2026-09-11. Forms part of the terms of service and applies automatically to every customer. No signature is needed. If your own procurement requires a signed copy, email hello@sentiracrm.com and we will sign this text.
1. The parties and their roles
Controller: you, the agency with an account. Processor: Nicki Price Real Estate, S.L., VAT ESB21803580, Calle Úbeda 6B, 03193 San Miguel de Salinas (Alicante), Spain.
You decide what personal data goes into the service and why. We process it only to provide the service to you, on your documented instructions, which are these terms plus whatever you do inside the software. If we ever think an instruction breaks data protection law, we will tell you and not act on it.
2. What is processed
| Subject matter | Providing a customer relationship system, an AI assistant, a public website and portal feeds to an estate agency. |
|---|---|
| Duration | For as long as your account is open, plus the 30 day deletion window. |
| Nature and purpose | Storing, organising, retrieving, transmitting, translating, summarising and erasing data so that you can run your agency. |
| Types of personal data | Name, email, phone, language, country, budget, property interest, the content of enquiries and messages, viewing and appointment records, notes your staff write, deal and commission records, documents you upload, and for your own staff: name, work email, role and sign-in records. |
| Categories of data subject | Your clients and prospective clients, property owners and sellers, your own staff, and collaborating agents. |
| Special category data | Not required by the service and not requested by it. If you choose to type it into a free-text field it will be processed as ordinary content, and that is your decision as controller. |
3. Confidentiality
Everyone we allow near customer data is bound to confidentiality, and access is limited to the people who need it to run the service or to answer a support request.
4. Security
We keep appropriate technical and organisational measures, described in full and without embellishment on the trust page. The main ones: per-company scoping of every query in the application, HTTPS on every hostname, hashed passwords, session cookies that are HttpOnly and Secure, origin checks on state-changing requests, rate limits on public endpoints, restricted and neutralised file uploads, hosting in the EU, and daily backups in the same region.
We do not currently hold ISO 27001 or SOC 2 certification and we do not claim it.
5. Sub-processors
You give general authorisation for us to use sub-processors. The current list, with what each one receives and where it is, is on the trust page and is part of this agreement. If we intend to add or replace one we will email your account administrators at least 30 days beforehand. If you object on reasonable data protection grounds within that period and we cannot offer an alternative, you may cancel the affected part of the service and we will refund the unused part of any prepayment.
Every sub-processor is bound by terms no less protective than these.
6. International transfers
Your data is stored in Germany. Where a sub-processor outside the EEA receives personal data, the transfer is made under the European Commission's standard contractual clauses together with the measures on the trust page. We will give you the relevant details on request.
7. Helping you meet your own obligations
- Data subject requests. The software lets you find, correct, export and erase an individual's record yourself, without asking us. If a request reaches us instead, we will forward it to you promptly and will not answer it ourselves.
- Impact assessments and consultation. We will give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority.
- Breach. If we become aware of a personal data breach affecting your data we will tell you without undue delay and in any case within 48 hours, with what we know, what we are doing and what you may need to do. Notifying a supervisory authority or your clients is your decision as controller, and we will help you make it.
8. Deletion and return
You can export your data yourself, in a machine-readable form, at any time while the account is open and for 30 days after it closes. At the end of that window everything is erased from the live system, and it rolls out of backups within the same period. We keep only what the law requires us to keep, which is the invoices we raised to you.
9. Audit
We will make available the information needed to demonstrate that we meet this agreement, and will answer a reasonable security questionnaire once a year at no charge. Where you need more than that, an audit may be carried out once a year, with 30 days' notice, during working hours, by you or an independent auditor bound to confidentiality, in a way that does not disturb other customers, and at your cost unless it finds a material failure by us.
10. Liability and precedence
The liability provisions of the terms of service apply to this agreement. Where this agreement and the terms of service disagree about the processing of personal data, this agreement wins.
11. Contact
Nicki Price Real Estate, S.L., VAT ESB21803580, Calle Úbeda 6B, 03193 San Miguel de Salinas (Alicante), Spain. Email hello@sentiracrm.com.