Data Processing Agreement
For Enterprise Customers
Last updated: January 16, 2026
1. Purpose and Scope
This Data Processing Agreement ("DPA") forms part of the service agreement between PROPMETRIK ("Processor") and our Enterprise customers ("Controller") regarding the processing of personal data in compliance with:
- Ghana Data Protection Act, 2012 (Act 843)
- EU General Data Protection Regulation (GDPR) where applicable
- Other applicable data protection laws
2. Definitions
- Controller: The Enterprise customer determining purposes and means of processing
- Processor: PROPMETRIK processing personal data on behalf of Controller
- Personal Data: Information relating to identified or identifiable individuals
- Processing: Any operation performed on personal data
- Sub-processor: Third-party engaged by Processor to process personal data
3. Processing Details
3.1 Nature and Purpose
PROPMETRIK processes personal data to provide:
- Property valuation and advisory services
- Real estate data intelligence and analytics
- Deal management and CRM functionality
- Market research and reporting
3.2 Types of Personal Data
- Contact information (names, emails, phone numbers)
- Professional details (company, job title)
- Property information (addresses, valuations, transactions)
- Usage data (platform interactions, preferences)
- Financial information (for transactions)
3.3 Categories of Data Subjects
- Enterprise customer employees and users
- Property owners and tenants
- Real estate agents and brokers
- Prospective buyers and investors
3.4 Duration
Processing continues for the duration of the service agreement, plus retention periods required by law or as specified in the agreement.
4. Processor Obligations
PROPMETRIK commits to:
- Process personal data only on documented instructions from the Controller
- Ensure personnel processing data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Engage sub-processors only with prior written authorization
- Assist Controller in responding to data subject rights requests
- Assist Controller with data protection impact assessments
- Delete or return data upon termination (unless retention required by law)
- Make available information demonstrating compliance
5. Security Measures
5.1 Technical Measures
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Multi-factor authentication for user access
- Regular security patches and updates
- Intrusion detection and prevention systems
- Regular vulnerability scanning and penetration testing
5.2 Organizational Measures
- Access controls based on principle of least privilege
- Employee training on data protection
- Background checks for personnel with data access
- Incident response and business continuity plans
- Regular security audits and certifications
6. Sub-processors
6.1 Authorized Sub-processors
PROPMETRIK engages the following sub-processors:
| Entity | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting | EU/US |
| Google Cloud | Analytics & Storage | EU/US |
| Stripe | Payment processing | Global |
6.2 Sub-processor Changes
PROPMETRIK will notify Controller of any intended changes to sub-processors at least 30 days in advance. Controller may object to changes on reasonable grounds.
7. Data Breach Notification
In the event of a personal data breach, PROPMETRIK will:
- Notify Controller without undue delay (within 72 hours where feasible)
- Provide description of the breach and affected data
- Detail likely consequences and mitigation measures taken
- Provide contact point for further information
- Cooperate with Controller's incident response
8. International Transfers
Where personal data is transferred outside Ghana, PROPMETRIK ensures adequate safeguards through:
- Standard Contractual Clauses (SCCs) approved by regulatory authorities
- Adequacy decisions recognizing equivalent data protection
- Binding Corporate Rules where applicable
- Specific consent for certain transfers
9. Audit Rights
Controller has the right to:
- Request and review audit reports (SOC 2, ISO 27001)
- Conduct audits or inspections with reasonable notice (once per year)
- Engage third-party auditors (subject to confidentiality agreements)
PROPMETRIK will provide reasonable cooperation for audits, subject to confidentiality and operational constraints.
10. Return and Deletion of Data
Upon termination or expiry of services, PROPMETRIK will:
- Return all personal data to Controller in standard format (within 30 days)
- Delete all copies of personal data from systems
- Certify deletion upon Controller request
- Retain data only where required by applicable law
11. Liability and Indemnification
Each party's liability under this DPA is subject to limitations in the main service agreement. PROPMETRIK indemnifies Controller for damages arising from PROPMETRIK's breach of data protection obligations, subject to applicable limitations.
12. Duration and Termination
This DPA remains in effect for the duration of the service agreement and any retention periods required for data deletion or return. Termination of the service agreement automatically terminates this DPA, subject to data return/deletion obligations.
13. Contact for DPA Matters
For DPA-related inquiries or data protection concerns:
Email: [email protected]
Address: PROPMETRIK, Data Protection Officer, Accra, Ghana