Zum Hauptinhalt springen
Rentprime
Legal

Data processing agreement (DPA)

As of: May 2026

Payment method required · €0 for the first 7 days · cancel anytime
This translation is provided for convenience only. Only the German version is legally binding.

As of: May 2026 · Data processing per Art. 28 GDPR

Insofar as you use Rentprime as a customer to create utility bills for your tenants, you process your tenants' personal data as the responsible body under GDPR. For this a data processing agreement (DPA) between you and Rentprime is required, which we make available to you in electronic form on request.

Contracting parties

Controller: The customer (you as user of Rentprime)
Data processor: KRUPKA Concept GmbH, Monheim am Rhein

Subject and duration

The processor processes the controller's tenants' personal data exclusively for providing the agreed software features. This includes in particular: tenant master data, lease agreements, utility bills, consumption data, payment history and communication threads.

Type and purpose of processing

Collection, storage, processing and provision of tenant data for the purpose of creating utility bills, lease agreements, deadline tracking, communication and related rental workflows.

Categories of data subjects

  • Tenants of the controller
  • Authorised representatives and family members
  • Kontaktpersonen (Hausmeister, Handwerker etc.)

Categories of personal data

  • Stammdaten (Name, Anschrift, Geburtsdatum, Familienstand)
  • Contact details (phone, email)
  • Contract data (rent, commencement/end of contract)
  • Bank details (IBAN for SEPA direct debit)
  • Consumption data (heating, water, electricity)
  • Kommunikationsdaten (E-Mails, Anrufnotizen)

Technical and organizational measures (TOM)

The processor takes the following technical and organizational measures to secure data processing under Art. 32 GDPR:

  • Pseudonymization and encryption of personal data (AES-256, TLS 1.3)
  • Access control through strong passwords, optional 2FA
  • Hosting bei nach ISO 27001 zertifizierten EU-Anbietern (Anwendungs-Datenbank in Stockholm/Schweden, Compute in Frankfurt und Stockholm)
  • Daily encrypted backups with 30-day retention
  • Recoverability of personal data in the event of physical or technical incidents (Art. 32 (1) (c) GDPR)
  • Regular review of the effectiveness of the TOMs (Art. 32 (1) (d) GDPR)
  • Obligation of employees to maintain data confidentiality
  • Protokollierung sicherheitsrelevanter Ereignisse

Sub-processors

The processor is entitled to engage further processors (sub-processors). The controller grants its general authorisation for this. The processor informs the controller in advance of any intended change concerning the addition or replacement of sub-processors and grants the controller a right of objection. A complete current list is made available on request. Currently engaged sub-processors:

Transfer impact assessments (TIA) for third-country processors (Anthropic, Google, Stripe) in accordance with EDPB Recommendation 01/2020 are provided on request.

  • Vercel Inc., USA — Frontend- und Serverless-Function-Hosting; Compute in Frankfurt (fra1). Drittlandmechanismus: DPF + SCC.
  • Fly, Inc., USA — Betrieb der Anwendungs-API api.rentprime.de; Compute in Frankfurt (fra). Drittlandmechanismus: SCC (kein DPF).
  • Supabase Inc., USA — Anwendungs-Datenbank in der EU-Region Stockholm (eu-north-1, Schweden). Drittlandmechanismus: DPF + SCC.
  • Cloudflare Inc., USA — CDN, DDoS- und WAF-Schutz; Edge-Verarbeitung in der EU. Drittlandmechanismus: DPF + SCC.
  • Stripe Payments Europe Ltd., Dublin, Irland (Zahlungsabwicklung — Konzernanbindung an Stripe, Inc. USA; DPF + SCC).
  • Brevo (Sendinblue SAS), Paris, Frankreich — Newsletter- und Lead-Formular-Verwaltung; Verarbeitung innerhalb der EU (kein Drittland).
  • Resend, Inc., USA — Transaktions-Mail-Versand. Drittlandmechanismus: DPF + SCC.
  • Postmark (ActiveCampaign LLC), USA — Transaktions-Mail-Fallback. Drittlandmechanismus: DPF + SCC.
  • Twilio Inc., USA — SMS-/WhatsApp-Versand (nur bei aktivierter Mieterkommunikation). Drittlandmechanismus: DPF + SCC.
  • Anthropic PBC, USA — KI-Funktionen Lou-Chat/Vertrags-Check. Drittlandmechanismus: DPF + SCC.
  • Anthropic PBC, USA — Beleg-/OCR-Erkennung (Claude Vision). Drittlandmechanismus: DPF + SCC.
  • finAPI / Klarna Kosma — Bank-Sync nach PSD2 (nur bei aktivierter Kontoanbindung; Verarbeitung innerhalb der EU).

For all processors established in the USA (Vercel, Fly, Supabase, Cloudflare, Resend, Postmark, Twilio, Anthropic, Google) as well as for the Irish payment processor Stripe (parent company in the USA), a third-country transfer to the USA takes place. This is safeguarded by the EU-US Data Privacy Framework (adequacy decision of the EU Commission of 10.07.2023) and/or EU-Standardvertragsklauseln (SCC, Art. 46 UK GDPR + DPA 2018) as well as supplementary measures (encryption in transit and at rest, PII minimization, contractually guaranteed zero retention/no training with the AI providers). Fly, Inc. is not DPF-listed; the transfer here is based exclusively on the SCC.

Rights and obligations

The processor processes the data solely on the documented instructions of the controller. It supports the controller in fulfilling its obligations under Art. 32–36 GDPR as well as in responding to requests from data subjects — including the controller's tenants — exercising their rights (Art. 12–22 GDPR).

Notification of personal data breaches: The processor notifies the controller of any personal data breach without undue delay after becoming aware of it, in order to enable the controller to notify within the deadline under Art. 33 GDPR (within 72 hours), and supports the controller in notifying data subjects under Art. 34 GDPR.

Control and audit rights (Art. 28 (3) (h) GDPR): The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for and contributes to audits — including inspections — conducted by the controller or another auditor mandated by the controller.

Deletion and return (Art. 28 (3) (g) GDPR): After completion of the processing services, the processor, at the controller's choice, deletes or returns all personal data and deletes existing copies, unless a legal retention obligation prevents this.

Sign DPA agreement

The complete signed version of the data processing agreement will be sent to you upon informal request by email to contact@rentprime.de sent within 24 hours on weekdays. The contract is concluded in electronic form (DocuSign or qualified electronic signature).

Try it just looks like.

If Rentprime doesn't save you two weekends a year, you can cancel with a single click.

We use cookies and similar technologies so our site works and so we understand how it’s used. Necessary cookies are always on. Other categories are only enabled if you choose.