Skip to content
The Quarters

Trust

GDPR, from the operator's side.

You are the one with the obligations to your tenants. This page is written to help you answer the questions you get asked, rather than to reassure you about ours.

Draft. Not yet in force

This summary is a working draft, written to be reviewed rather than relied on. It has not been checked by a lawyer and does not bind anyone. It must not go live before legal review.

Who is who

For your tenants' personal data you are the controller and we are your processor. You decide what is collected and why; we process it on your instructions and for no other purpose. That is set out in the data processing agreement, which is part of your contract from the moment you open an account. You do not have to request it or sign anything separate.

For your own account data (your name, your colleagues' logins, your billing details) we are the controller, and the privacy policy covers it.

The questions your clients ask

Corporate and relocation clients increasingly ask these in writing before signing. The answers, so you can give them:

  • Where is the data? In the European Union. Two sub-processors are established in the United States and those transfers rely on Standard Contractual Clauses; both are named on the sub-processors page with what they touch.
  • Is it used for anything else? No. Not sold, not analysed for our own purposes, not used to train machine-learning models.
  • Who can see it? The people in your organisation you have given access to, at the role you gave them. Our staff do not browse customer data; access for support is on request and by exception.
  • What happens at the end? Deleted or returned at your choice after the 90-day export window.

Subject requests

If a tenant asks you for a copy of their data, or asks you to delete it, that request is yours to answer, because you are the controller. What we provide is the means: export gives you everything held about a person, and deletion is available to you directly.

If a tenant writes to us instead, we will tell them we are a processor and point them at you, and let you know it happened. We will not action a request about your data without your instruction.

Retention

Two things pull in opposite directions and it is worth understanding both. Data protection pushes toward deleting what you no longer need; Dutch fiscal law requires financial records to be kept for seven years. Tenancy records with money attached fall under the second.

Two things are deliberately never pruned, and both are evidence rather than convenience: the log of automated email, because "did we send that?" gets asked about last year, and signing records, because that is the entire point of them.

Breaches

If we become aware of a personal data breach affecting your data we tell you without undue delay, with what we know and what we are doing. Notifying the Autoriteit Persoonsgegevens and, where required, the affected people, is the controller's duty. That is yours, and we give you what you need to do it inside the 72 hours.

Contact

privacy@thequarter.ai. There is no formally appointed Data Protection Officer; at this size one is not required, and the address reaches somebody who can actually answer.