All policies
01

Purpose and scope

This Data Processing Agreement ("DPA") forms part of the agreement between OTHRS ("the Platform", "we", "us") and the organisation using the Platform ("the Customer", "you") wherever OTHRS processes personal data on the Customer's behalf in the course of providing the OTHRS platform (supported housing, care, and investment marketplace and workflow services).

This DPA applies whenever the Customer is the data controller and OTHRS is the data processor for personal data submitted to or generated within the Platform — for example, contact details of the Customer's staff, tenants, service users, or counterparties entered into Deal Rooms, Investment Rooms, Care Demand records, or messaging.

02

Definitions

Terms used in this DPA ("personal data", "processing", "controller", "processor", "data subject", "personal data breach") have the meanings given in the UK GDPR and the Data Protection Act 2018.

03

Roles of the parties

  • The Customer is the data controller for personal data it submits to, or causes to be generated within, the Platform relating to its own staff, service users, tenants, or business contacts.
  • OTHRS is the data processor, processing that personal data only on the Customer's documented instructions, as set out in this DPA and the Platform's Terms of Service, except where OTHRS is required to process it by UK law (in which case OTHRS will inform the Customer of that legal requirement before processing, unless the law prohibits this).
  • Where OTHRS determines the purposes and means of processing certain data independently (for example, platform account data, billing data, or aggregated/anonymised analytics used to operate and improve the Platform itself), OTHRS acts as an independent controller for that processing, as described in the Platform's Privacy Policy.
04

Scope of processing

4.1 Categories of data subjects: the Customer's employees and authorised users; individuals named or referenced in Care Demand records, Deal Room or Investment Room communications, property/opportunity listings, and messages exchanged through the Platform; contacts submitted through forms.

4.2 Categories of personal data: names, job titles, organisational affiliation, business contact details (email, phone); content of messages and documents uploaded to Deal Rooms/Investment Rooms/Care Demand records, which may incidentally include personal data about service users or tenants depending on what the Customer chooses to submit. Care Demand records are structured to stay at an aggregate/anonymised level (e.g. "12 units of extra care housing needed") and do not name an individual's health condition or care need. No special category data is processed by design. Customers should not submit special category data (health, care-need information tied to a named individual) through the Platform — see Section 10.

4.3 Nature and purpose of processing: storage, display, matching, search, and transmission of the above data as necessary to provide the Platform's core functionality — hosting listings, facilitating introductions and deal-room communication, running the matching/coverage features, and platform administration.

4.4 Duration: for as long as the Customer's account is active, plus any retention period set out in the Privacy Policy or required by law after account closure.

05

OTHRS's obligations as processor

OTHRS shall:

  1. Process personal data only on the Customer's documented instructions (including as set out in the Terms of Service and this DPA), unless required otherwise by law.
  2. Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including the following measures:
    • Encryption in transit — all traffic to and within the Platform is encrypted via TLS/HTTPS.
    • Encryption at rest — the underlying Postgres database (hosted on Supabase) encrypts stored data at rest.
    • Row-Level Security (RLS) based multi-tenant isolation — every table in the production database has RLS policies enforcing that one organisation's data is never visible to another organisation's users at the database layer, not just in the application UI.
    • Staff access restrictions / least-privilege admin access — administrative functions are gated behind role-based route guards (founder/admin-only access), and administrative actions are recorded to an audit log.
  4. Not engage a new sub-processor without giving the Customer at least 30 days' prior written notice (by email to the Customer's registered account contact, and/or by an update to the published sub-processor list referenced below), during which the Customer may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection, failing which the Customer may terminate the affected service. OTHRS's current sub-processors are:
    • Supabase — database, authentication, file storage, and edge functions; holds all application data.
    • Klaviyo — transactional and lifecycle email delivery (in-app notification emails, onboarding, billing communications).
    • Stripe — payment and subscription billing processing.
  5. Impose data-protection obligations on any sub-processor that are no less protective than those set out in this DPA, and remain fully liable to the Customer for that sub-processor's performance of its obligations.
  6. Assist the Customer, insofar as reasonably possible, in responding to requests from data subjects exercising their rights under UK GDPR.
  7. Assist the Customer in ensuring compliance with its security, breach-notification, DPIA, and prior-consultation obligations, taking into account the nature of processing and information available to OTHRS.
  8. Notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data — see Section 9 for the specific target window and notification method.
  9. At the Customer's written request following termination or expiry of the Terms of Service, and in any event within 30 days of that request, delete or return all personal data to the Customer (at the Customer's choice) and delete existing copies, unless UK law requires OTHRS to retain the data — in which case OTHRS will inform the Customer of that requirement and the retention period involved.
  10. Make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to at least 30 days' prior written notice, a limit of one such audit in any 12-month period (except where the audit follows a suspected or confirmed personal data breach, or is required by a supervisory authority), and the auditor's agreement to reasonable confidentiality terms. The Customer bears its own costs of an audit; OTHRS bears its own costs of reasonably co-operating with one.
06

Customer's obligations

The Customer shall:

  1. Ensure it has, and will maintain, a valid lawful basis under UK GDPR for all personal data it submits to, or causes to be generated within, the Platform, and that it has given any data subjects concerned the information required by UK GDPR (including, where relevant, that their data will be processed using the Platform).
  2. Not submit special category data to the Platform, consistent with Section 10 below, and be responsible for the consequences of doing so where it occurs despite this.
  3. Ensure its own instructions to OTHRS regarding the processing of personal data comply with UK GDPR, and that OTHRS acting on those instructions will not cause OTHRS to be in breach of UK GDPR.
  4. Be solely responsible for the accuracy, quality, and legality of the personal data it submits to the Platform, and for the means by which it acquired that data.
07

International transfers

All processing and storage stays within the UK. None of OTHRS's current sub-processors (Supabase, Klaviyo, Stripe) are configured to process or store OTHRS customer personal data outside the UK. No international transfer mechanism is therefore required at this time. If this changes in future (e.g. a new sub-processor with non-UK hosting), this section will need updating with the transfer mechanism used (the UK's International Data Transfer Addendum to the EU SCCs, or an adequacy decision) before that processing begins, and the new sub-processor notice process in Section 5.4 will apply.

08

Data subject rights

OTHRS shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, for the fulfilment of the Customer's obligation to respond to requests for exercising a data subject's rights (access, rectification, erasure, restriction, portability, objection) under UK GDPR.

09

Personal data breach notification

OTHRS shall notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Customer's personal data, by email to the Customer's registered account contact, providing information to assist the Customer in meeting its own obligations to notify the ICO and affected data subjects where required. The Customer shall co-operate with OTHRS as reasonably necessary to investigate and remediate the breach.

10

Special category data

Per Section 4.2 above, the Platform is not designed to process special category data. Care Demand records and other Platform content are structured to stay at an aggregate/anonymised level and should not include health-related or other special category information tied to a named individual. Customers should not submit special category data through the Platform. If a Customer does submit such data despite this, OTHRS's standard security measures (Section 5.3) apply, but the Platform has not been designed or assessed for special-category-data handling and Customers do so at their own risk pending any future change to this position.

11

Liability and indemnity

  1. Each party's total aggregate liability to the other arising out of or in connection with this DPA, whether in contract, tort (including negligence), or otherwise, shall not exceed the total fees paid or payable by the Customer under the Terms of Service in the 12 months preceding the event giving rise to the claim.
  2. Nothing in this DPA limits or excludes either party's liability for: death or personal injury caused by its negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be limited or excluded under UK law.
  3. Subject to Section 11.2, the cap in Section 11.1 does not apply to: a party's breach of Section 5 (OTHRS's obligations as processor) or Section 6 (Customer's obligations) resulting in a regulatory fine, penalty, or third-party claim against the other party; or a party's breach of confidentiality obligations under the Terms of Service.
  4. Each party shall indemnify the other against all liabilities, costs, and losses (including reasonable legal fees) arising from the indemnifying party's breach of its obligations under this DPA, to the extent that breach caused the loss.
  5. Neither party is liable for any indirect or consequential loss, or loss of profits, revenue, or anticipated savings, arising out of or in connection with this DPA.
12

Term and termination

This DPA remains in effect for as long as OTHRS processes personal data on the Customer's behalf under the Terms of Service, and terminates automatically on termination of that agreement, subject to Section 5.9 (return/deletion of data).

13

General

  1. Entire agreement. This DPA, together with the Terms of Service, constitutes the entire agreement between the parties in relation to the processing of personal data under the Terms of Service, and supersedes all prior agreements or understandings on that subject.
  2. Order of precedence. If there is a conflict between this DPA and the Terms of Service on a matter of personal data processing, this DPA prevails; on all other matters, the Terms of Service prevails.
  3. Variation. No variation of this DPA is effective unless made in writing and agreed by both parties, save that OTHRS may update the sub-processor list under Section 5.4 by the notice process described there.
  4. Assignment. Neither party may assign or transfer this DPA without the other's prior written consent, except that OTHRS may assign it in connection with a merger, acquisition, or sale of substantially all of its relevant assets, provided the assignee agrees to be bound by its terms.
  5. Notices. Notices under this DPA shall be given in writing to the recipient's registered account contact (for the Customer) or to OTHRS's published legal/compliance contact address.
  6. Severability. If any provision of this DPA is held unenforceable, the remaining provisions continue in full force and effect.
14

Governing law

This DPA is governed by the laws of England and Wales, matching the governing law clause already used in the Platform's other legal documents.