Progressa

Legal

Data Processing Agreement.

Last updated 12th Aug 2026.

This is the Article 28 agreement between your agency and us. It applies from the moment you open your first case, and accepting the Terms of Service accepts this with them — there is one gate, at first sign-in, and it covers both.

Who is who

Your agency is the controller. The case record is about your clients and their transaction; you decide what goes in it and why. We are the processor. We hold it and act on your instructions, and we do not use it for our own purposes.

The waitlist and any research notes are different — those are ours as controller, and the Privacy Notice covers them. A DPA is the wrong instrument for them.

What we process, and on what instructions

Subject matter: coordinating a sale-agreed property transaction. Duration: for as long as your account is open, plus the retention period below. Categories of data subject: your vendors, your buyers, and the solicitors on both sides. Categories of data: names, email addresses, the property address, milestone dates, the messages we sent on your behalf, and the replies that came back.

Your documented instructions are the product itself: opening a case, recording a milestone, adding a party, sending an update. We do nothing with the data that the product does not do on your instruction, and we will tell you if we think an instruction breaches data protection law.

Sub-processors

Six, listed with what each does, where it is and what covers the transfer, in the Privacy Notice. That table is the annex to this agreement. You consent to those six by accepting these terms, and we will give you notice before adding or replacing one so you can object.

One of them reads the text of solicitors’ written replies to suggest a status. It is named, and what it sees is described, in the Privacy Notice under “How the AI reading works”. If your firm’s policy does not permit that, tell us and we will turn it off for your account — the product works without it.

What we do about security

  • Everything is encrypted in transit, and the database connection pins its TLS mode.
  • A link we email is a random token, stored only as a hash, scoped to one person, expiring, and reissued with each message.
  • One agency can never see another’s cases. Every query is scoped by account.
  • Error reports have email addresses and link tokens removed before they leave us.
  • The case ledger is append-only at the database level, so a record cannot be altered after the fact — by us or by anyone.

Breaches, audits and your own duties

If there is a personal data breach we will tell you without undue delay and give you what you need for your own notification. You may audit our compliance with this agreement on reasonable notice, and we will answer a security questionnaire without one.

We help you meet requests from data subjects and, where it applies, with your DPIA. In practice most requests reach us through you, because you are the controller.

What happens at the end — and the six years

On termination we return or delete the personal data, at your choice, except the case ledger of a closed sale, which is kept for six years.

That exception is deliberate and it is the one term worth reading twice. The dated record is the artefact the product exists to produce; you may need it years later for the PSRA, for a client, or in a dispute, and so may we. It is retained under Article 17(3)(e) — the establishment, exercise or defence of legal claims — and it is append-only, so neither of us can quietly edit it. If you would rather it were destroyed at termination, say so before you open your first case and we will tell you honestly whether we can sell you the product on that basis.

During our research this week

We deliberately keep ourselves out of processor territory while researching. We ask agents not to show us real client or transaction data, we do not ask for exports or logins, and if something identifying appears on a shared screen we do not record it or write it down. That way there is nothing to govern, which is simpler for both of us than papering it.

If your agency’s own policy requires something signed before you will even talk to us, a mutual NDA is the appropriate document at this stage rather than a DPA. Ask and we will send one.

What the agreement will cover

When Progressa opens, the DPA will be part of the terms, and will set out:

  • the subject matter, duration, nature and purpose of the processing
  • the categories of personal data and of data subjects
  • that we act only on your documented instructions, and tell you if an instruction appears unlawful
  • confidentiality obligations binding anyone with access
  • the technical and organisational security measures in place, described specifically rather than as a gesture
  • the sub-processors we use, and advance notice before that list changes, with a right to object
  • how we assist you with access, correction and erasure requests from your clients
  • breach notification, and the period within which you will hear from us
  • deletion or return of data when the agreement ends, and by when
  • audit and information rights
  • where data is hosted, any international transfer, and the lawful basis for it

Where data will sit

Worth flagging early because it tends to matter to agencies: the waitlist database is currently hosted in London, in the United Kingdom, which is outside the EU but covered by a European Commission adequacy decision. Before the product handles any agency’s client data we intend to be in an EU region, and the agreement will state the location plainly.

If you need something sooner

If your agency needs an executed agreement, or a security questionnaire completed, before Progressa opens, email hello@progressa.ie and it will be dealt with directly by a person rather than routed into a process.

True Home Properties Limited, registered in Ireland, company number 811518.