Scout - Legal

Data Processing Agreement (DPA)

Effective 08.07.2026

This Data Processing Agreement (the “DPA”) forms part of the agreement between Epic House SIA (SIA), registration number 40203716958, with registered office at Duntes iela 6, Riga, LV-1013, Latvia, Latvia (the “Processor”) and the customer organisation that has subscribed to the Scout service (the “Controller”), for the processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of the Service (the “Principal Agreement”).

It is concluded pursuant to Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Latvian Fizisko personu datu apstrādes likums (Personal Data Processing Law), and where applicable the United Kingdom GDPR.

By accepting the Principal Agreement, by clicking “I accept” on a DPA acceptance flow, or by using the Service, the Controller enters into this DPA.


1. Definitions

Capitalised terms have the meaning given in the Principal Agreement or in the GDPR. In addition:

2. Roles, scope and duration

The categories of data subjects, categories of personal data, nature and purpose of the processing, and the duration are set out in Annex I.

3. Processor obligations

The Processor will:

4. Controller obligations

The Controller represents and warrants that:

5. Security

The Processor implements the technical and organisational measures described in Annex II, which include in particular:

6. Sub-processors

7. International transfers

Where the Processor or a Sub-processor processes Customer Personal Data outside the European Economic Area:

The Processor has carried out a transfer impact assessment for transfers to the United States and considers that, taken with its technical measures, the transfers offer a level of protection essentially equivalent to that within the EEA. A copy is available on request.

8. Personal-data breach

The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will include the information required by Art. 33(3) GDPR insofar as available, and will be supplemented as the investigation progresses. The Processor will support the Controller in any onward notification to a supervisory authority or affected data subjects.

9. Audits

10. Liability

The liability of the parties under this DPA is governed by the limitation-of-liability provisions of the Principal Agreement. Where this DPA references the SCCs, the liability provisions of the SCCs apply between the parties to the SCCs.

11. Term and termination

This DPA terminates automatically when the Principal Agreement terminates, except for clauses that by their nature survive (e.g., deletion of data, audit cooperation for breaches discovered after termination, liability).

After termination, the Processor will, at the Controller’s choice, return or delete Customer Personal Data within 30 days, except that the Processor may retain Customer Personal Data to the extent (and for as long as) required by law (e.g., billing records).

12. Order of precedence

In case of conflict between this DPA and the Principal Agreement, this DPA prevails as to data-protection matters. In case of conflict between this DPA and the SCCs, the SCCs prevail.


Annex I - Description of the processing

Categories of data subjects

Categories of personal data

Special categories

Not intended; only if voluntarily provided in free text.

Frequency of processing

Continuous, for as long as the Service is provided.

Nature and purpose of the processing

Providing the Scout lead-orchestration service - receiving leads, translating lead messages with AI assistance, searching property databases, coordinating viewings, generating property listing descriptions and documents, and notifying the Controller’s personnel.

Duration

For the term of the Principal Agreement, plus retention periods set out in the Privacy Policy.


Annex II - Technical and organisational measures

The Processor implements the following measures:

1. Confidentiality

2. Integrity

3. Availability and resilience

4. Procedures for testing and evaluating effectiveness

5. User and access management

6. Data-subject rights support


Annex III - Authorised Sub-processors

The categories of authorised Sub-processors are published at https://www.scoutgo.app/sub-processors. The itemised list naming each Sub-processor is maintained by the Processor and provided to the Controller on request; it is updated on at least 30 days’ notice under §6(b). This Annex forms part of this DPA.