Back to the homepage

Data Processing Agreement

Last updated: July 25, 2026

This Data Processing Agreement (DPA) forms part of the Terms of Service between moovit, s.r.o., trading as Renvia (Processor), and the Customer (Controller), where Renvia processes Customer Data on the Customer's behalf.

1. Scope, duration and instructions

This DPA applies for the duration of the Customer's use of the Service and to the processing described in Annex I. The Controller instructs the Processor to process Customer Data solely to provide, secure, maintain and support the Service, as configured by the Controller and its authorized Users, and as otherwise documented in this DPA or the Terms. The Processor will inform the Controller if it considers an instruction to infringe applicable data-protection law, unless prohibited by law.

2. Confidentiality and security

Renvia ensures that persons authorized to process Customer Data are bound by confidentiality obligations. Renvia implements measures appropriate to the risk under Article 32 GDPR. Current measures include encrypted transport, cloud-provider encryption at rest where configured, authenticated API access, portfolio isolation, role checks, restricted infrastructure permissions, rate limiting, passkey support, security logging and controlled software deployments.

The Controller acknowledges that no specific SLA, recovery point objective, recovery time objective, individual restore service or universal backup-retention period is included unless agreed separately in writing.

3. Subprocessors

The Controller gives general written authorization for the subprocessors listed on the Service Providers page. Renvia will impose equivalent data-protection obligations on subprocessors as required by Article 28(4) GDPR and remains responsible for their processing to the extent required by law.

For a material new or replacement subprocessor that processes Customer Data, Renvia will give the Controller advance notice at the registered account email where required by Article 28 GDPR. The Controller may object on reasonable data-protection grounds by writing to privacy@renvia.app. The parties will work in good faith on a reasonable solution; where none is available, the Controller may stop using the affected Service.

4. International transfers

Customer Data may be processed outside the EEA when a subprocessor or integration requires it. Renvia will use an adequacy decision, Standard Contractual Clauses or another lawful Chapter V transfer mechanism where required, and will provide reasonable information about the applicable mechanism upon request.

5. Assistance

Taking account of the nature of processing and information available, Renvia will provide reasonable assistance to the Controller with data subject requests and with the Controller's obligations under Articles 32–36 GDPR. Requests should be sent to privacy@renvia.app.

6. Personal data breaches

Renvia will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data. The notice will include information available to Renvia that is reasonably necessary for the Controller to assess and meet its obligations.

7. Compliance information and audits

Renvia will make available information reasonably necessary to demonstrate compliance with this DPA. Before an on-site audit, the Controller must give at least 30 days' written notice, use an independent auditor bound by confidentiality, limit an audit to once a year unless a material incident or law requires otherwise, and avoid unreasonable disruption. Renvia may first satisfy a request through written responses, security documentation or a remote review.

8. Return and deletion

The Controller can delete records through available Service controls and an owner can start portfolio deletion in Settings. Portfolio deletion removes the related active-system records and supported stored files by a background process. Before that action, the owner is offered information about requesting an export; Renvia does not currently promise an automatic self-service export of every data category.

On termination, Renvia will delete or anonymize Customer Data in its active systems on the Controller's instruction, unless retention is required by law or necessary for legal claims, security or fraud prevention. Infrastructure copies follow the applicable provider lifecycle; no unverified universal deletion period is promised.

9. Liability, term and contact

Liability is governed by the Terms and mandatory law. This DPA ends when the Service agreement ends and Customer Data has been deleted or anonymized in accordance with this DPA, subject to permitted retention. The governing law and jurisdiction are those stated in the Terms.

moovit, s.r.o.
Bobuľová 11/B, 900 28 Ivanka pri Dunaji, Slovakia
IČO: 45240639 · IČ DPH: SK2022919415
privacy@renvia.app

Annex I — Processing details

Subject matter and purposeProviding a SaaS platform for property, reservation, financial, document and service management.
DurationFor the Service term and permitted retention period.
Data subjectsCustomer's Users, guests, tenants, property owners, contractors and other individuals whose data the Controller enters.
Data categoriesIdentification and contact data, reservations, property data, financial records, documents, notes and access-related data entered by the Controller.
OperationsCollection, storage, retrieval, consultation, transmission, deletion and other operations needed to provide the Service.

Annex II — Authorized subprocessors

The current list, purposes and transfer information are maintained on the Service Providers page, which forms part of this DPA.