Scout - Legal
Data Processing Agreement (DPA)
Effective 08.07.2026
This Data Processing Agreement (the “DPA”) forms part of the agreement between Epic House SIA (SIA), registration number 40203716958, with registered office at Duntes iela 6, Riga, LV-1013, Latvia, Latvia (the “Processor”) and the customer organisation that has subscribed to the Scout service (the “Controller”), for the processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of the Service (the “Principal Agreement”).
It is concluded pursuant to Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Latvian Fizisko personu datu apstrādes likums (Personal Data Processing Law), and where applicable the United Kingdom GDPR.
By accepting the Principal Agreement, by clicking “I accept” on a DPA acceptance flow, or by using the Service, the Controller enters into this DPA.
1. Definitions
Capitalised terms have the meaning given in the Principal Agreement or in the GDPR. In addition:
- “Customer Personal Data” means personal data that the Processor processes on behalf of the Controller under the Principal Agreement, including (without limitation) lead contact details, lead messages, property notes and viewing history.
- “Sub-processor” means a third party engaged by the Processor to process Customer Personal Data on behalf of the Controller.
- “Standard Contractual Clauses” or “SCCs” means the European Commission’s Implementing Decision (EU) 2021/914 of 4 June 2021.
2. Roles, scope and duration
- The Controller is the data controller and the Processor is the data processor for Customer Personal Data.
- The Processor processes Customer Personal Data only to provide the Service, in accordance with the documented instructions of the Controller, which are set out in the Principal Agreement, this DPA, and any further written instruction the Controller gives via the Service or by email.
- This DPA applies for as long as the Processor processes Customer Personal Data on behalf of the Controller.
The categories of data subjects, categories of personal data, nature and purpose of the processing, and the duration are set out in Annex I.
3. Processor obligations
The Processor will:
- (a) Process Customer Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by EU or Member State law (in which case the Processor will inform the Controller before processing, unless the law prohibits this on important public-interest grounds).
- (b) Ensure that persons authorised to process Customer Personal Data have committed to confidentiality or are under a statutory duty of confidentiality.
- (c) Implement the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk.
- (d) Engage Sub-processors only under §6 below.
- (e) Taking into account the nature of the processing, assist the Controller by appropriate measures, insofar as possible, in fulfilling its obligation to respond to data-subject rights requests under Chapter III GDPR.
- (f) Assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data-protection impact assessments, prior consultation), taking into account the nature of processing and the information available to the Processor.
- (g) At the choice of the Controller, delete or return all Customer Personal Data after the end of the provision of services, and delete existing copies, unless retention is required by EU or Member State law.
- (h) Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits under §9 below.
4. Controller obligations
The Controller represents and warrants that:
- (a) it has a lawful basis for the processing it asks the Processor to carry out;
- (b) it has provided all required notices to data subjects (including leads and listing agents);
- (c) the instructions it gives to the Processor comply with applicable data-protection law; and
- (d) it will not include in Customer Personal Data any special categories of data within the meaning of GDPR Art. 9 unless strictly necessary and lawful, and in any case will inform the Processor in advance.
5. Security
The Processor implements the technical and organisational measures described in Annex II, which include in particular:
- TLS in transit and AES-256 (or equivalent) encryption of data at rest;
- application-level encryption of secrets (e.g., bot tokens);
- role-based access controls; multi-factor authentication for personnel accessing production systems;
- secure software-development practices; code review; dependency scanning;
- daily encrypted backups with tested restoration;
- logging and monitoring of access to Customer Personal Data;
- regular security reviews of code that touches personal data.
6. Sub-processors
- (a) The Controller authorises the Processor to engage the Sub-processors in the categories published at https://www.scoutgo.app/sub-processors as of the effective date; the current itemised list naming each Sub-processor, with its purpose, location and transfer safeguard, is provided to the Controller on request.
- (b) The Processor will give the Controller at least 30 days’ prior written notice of any planned addition or replacement of a Sub-processor, by email or in-app notice. The Controller may object on reasonable data-protection grounds. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the Service for the unused part of the prepaid term.
- (c) The Processor will impose on each Sub-processor data-protection obligations no less protective than those in this DPA and remains fully liable to the Controller for the Sub-processor’s performance.
7. International transfers
Where the Processor or a Sub-processor processes Customer Personal Data outside the European Economic Area:
- Where the European Commission has issued an adequacy decision for the destination country, the parties rely on it.
- Otherwise the parties rely on the EU Standard Contractual Clauses (Module 2 - controller to processor), which are hereby deemed incorporated by reference into this DPA. Annex I of this DPA serves as Annex I.A and I.B of the SCCs; Annex II serves as Annex II of the SCCs; Annex III serves as the SCC list of Sub-processors.
- The supervisory authority for the SCCs is the Latvian Datu valsts inspekcija (DVI) as the Processor’s lead supervisory authority under the GDPR one-stop-shop.
- For transfers from the UK, the parties incorporate the UK International Data Transfer Addendum (IDTA) issued by the UK ICO.
The Processor has carried out a transfer impact assessment for transfers to the United States and considers that, taken with its technical measures, the transfers offer a level of protection essentially equivalent to that within the EEA. A copy is available on request.
8. Personal-data breach
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will include the information required by Art. 33(3) GDPR insofar as available, and will be supplemented as the investigation progresses. The Processor will support the Controller in any onward notification to a supervisory authority or affected data subjects.
9. Audits
- (a) The Controller may, no more than once every 12 months and on at least 30 days’ written notice, audit the Processor’s compliance with this DPA. The audit will be carried out during business hours, in a way that does not unreasonably interfere with the Processor’s business, and is subject to confidentiality.
- (b) The Controller’s audit right is satisfied by the Processor providing its most recent third-party audit reports (e.g., SOC 2, ISO 27001) where available, plus written answers to a reasonable list of questions.
- (c) The Controller bears its own costs and the reasonable costs of the Processor for the audit, except where the audit reveals a material non-compliance.
10. Liability
The liability of the parties under this DPA is governed by the limitation-of-liability provisions of the Principal Agreement. Where this DPA references the SCCs, the liability provisions of the SCCs apply between the parties to the SCCs.
11. Term and termination
This DPA terminates automatically when the Principal Agreement terminates, except for clauses that by their nature survive (e.g., deletion of data, audit cooperation for breaches discovered after termination, liability).
After termination, the Processor will, at the Controller’s choice, return or delete Customer Personal Data within 30 days, except that the Processor may retain Customer Personal Data to the extent (and for as long as) required by law (e.g., billing records).
12. Order of precedence
In case of conflict between this DPA and the Principal Agreement, this DPA prevails as to data-protection matters. In case of conflict between this DPA and the SCCs, the SCCs prevail.
Annex I - Description of the processing
Categories of data subjects
- The Controller’s personnel (agents, agency staff) using the Service.
- Property leads / buyers who contact the Controller via WhatsApp or other supported channels.
- Listing agents whose professional contact details the Controller asks the Processor to use to coordinate viewings.
Categories of personal data
- Identifiers: name, email, phone number, WhatsApp number.
- Contact and conversation content: messages, attachments, voice notes (audio; not transcribed), translations.
- Search and preference data: budget, location, property type, viewing schedule.
- Property and viewing data: viewing offers, outcomes, agent notes.
- Technical data: device tokens (for push), IP addresses, session identifiers.
- Billing data of the Controller’s account holders (handled by our payment provider).
Special categories
Not intended; only if voluntarily provided in free text.
Frequency of processing
Continuous, for as long as the Service is provided.
Nature and purpose of the processing
Providing the Scout lead-orchestration service - receiving leads, translating lead messages with AI assistance, searching property databases, coordinating viewings, generating property listing descriptions and documents, and notifying the Controller’s personnel.
Duration
For the term of the Principal Agreement, plus retention periods set out in the Privacy Policy.
Annex II - Technical and organisational measures
The Processor implements the following measures:
1. Confidentiality
- Role-based access; least-privilege; just-in-time admin elevation.
- Multi-factor authentication for all production systems.
- Pseudonymisation / encryption where appropriate.
- Encryption of secrets (third-party tokens) at the application layer.
2. Integrity
- TLS 1.2+ in transit; AES-256 at rest.
- Code review; dependency scanning; CI checks.
- Logged, audited writes to production data.
3. Availability and resilience
- Daily encrypted backups; tested restoration procedure.
- Multi-region hosting where supported by Sub-processors.
- Rate limiting and abuse-prevention controls.
4. Procedures for testing and evaluating effectiveness
- Documented incident-response plan.
- Periodic security reviews; annual third-party penetration test (planned).
5. User and access management
- Onboarding / off-boarding checklist; access reviews quarterly.
6. Data-subject rights support
- Self-service export and deletion endpoints.
- SLA: respond to Controller-initiated rights requests within 14 days.
Annex III - Authorised Sub-processors
The categories of authorised Sub-processors are published at https://www.scoutgo.app/sub-processors. The itemised list naming each Sub-processor is maintained by the Processor and provided to the Controller on request; it is updated on at least 30 days’ notice under §6(b). This Annex forms part of this DPA.