1. Who is responsible for what
Your agency remains the data controller for its clients' data. It decides what is collected, why, and for how long. Tramontane acts as a processor under Article 28 GDPR: we process that data solely on your instruction and solely for the purposes we have written down together.
This split is formalised in writing before anything goes live, in a processing agreement annexed to the installation contract.
2. No parallel database
We do not build a database alongside yours. The automations we install work on your tools and your access, and the data stays inside your agency software and your systems. We do not export your buyer register, we do not duplicate your listing portfolio.
3. Record of the processing entrusted to us
Before each go-live, we document in writing which data is processed, by which automation or agent, for what purpose, and how long it transits. That document is yours and feeds directly into your own record of processing activities.
4. Sub-processors
Some of the components we install rely on third-party providers, in particular for language models. We give you the named list of those providers before go-live, together with where the processing takes place. No provider is added mid-engagement without your prior written agreement.
Where a transfer outside the European Union is necessary, it is covered by the European Commission's standard contractual clauses.
5. What we never do with your data
Your clients' data is never used to train a model, never reused for another Tramontane client, and never transferred, sold or rented to a third party. We require the same contractually from our providers.
6. Minimisation
An automation receives only the fields it needs. An agent writing a listing has no access to a tenant's bank details. This restriction is defined at assessment and verified before go-live.
7. A human at the end of the loop
No decision producing a legal or similarly significant effect on a person is taken by a machine alone. Text produced by our agents is read and approved by a member of your team before publication or sending. A tenant application is never rejected automatically.
8. Technical security
The access you grant us is named, limited to the installed scope, and revocable at any time. Exchanges between your tools and the components we install are encrypted in transit. Our access is removed at the end of the engagement, and we confirm that to you in writing.
9. End of engagement
At the end of the engagement, the automations stay in place and keep running for you. We remove our access and any residual technical data within 30 days, and we hand over the documentation of what was installed.
10. Data subject rights
Requests for access, rectification, erasure, objection, restriction and portability are exercised with your agency as controller. We commit to assisting you in answering them within the statutory deadlines. The detail of those rights is in our Privacy policy.