Data Processing Agreement
Last updated: 3 September 2026
This Data Processing Agreement explains how Corevilla processes personal data on behalf of landlords, property managers and organisations using the Corevilla service.
1. Parties and application
This Data Processing Agreement, referred to as the “Agreement”, forms part of the agreement between Corevilla and the person or organisation that creates or operates a Corevilla landlord account, referred to as the “Customer”.
This Agreement applies where Corevilla processes personal data on behalf of the Customer through the Corevilla property-management service.
By creating an account, using the service or accepting the Corevilla Terms and Conditions, the Customer agrees to this Agreement.
2. Roles of the parties
For personal data entered into Corevilla and managed by the Customer, the Customer normally acts as the data controller and Corevilla acts as the data processor.
The Customer determines the purposes and means of processing tenant, tenancy, property-management, payment and maintenance information.
Corevilla processes this information to provide, maintain, secure and support the service in accordance with the Customer’s instructions and this Agreement.
Corevilla remains an independent data controller for information processed for its own purposes, including account registration, subscription management, billing, service security and compliance with legal obligations. Such processing is governed by the Corevilla Privacy Policy.
3. Customer instructions
Corevilla will process Customer personal data only:
- To provide and operate the Corevilla service.
- As necessary to fulfil the Customer’s use of the service and its available features.
- In accordance with this Agreement, the Terms and Conditions and documented instructions provided by the Customer.
- Where required by European Union or Maltese law.
If Corevilla is legally required to process personal data outside the Customer’s instructions, Corevilla will inform the Customer before processing unless the applicable law prohibits such notice.
Corevilla will inform the Customer if, in Corevilla’s reasonable opinion, an instruction infringes applicable data-protection law.
4. Details of processing
Subject matter
Processing personal data to provide an online property-management service.
Duration
Processing continues for the duration of the Customer’s use of Corevilla and for any subsequent retention period permitted under this Agreement, the Terms and Conditions or applicable law.
Nature and purpose
Corevilla may collect, store, organise, retrieve, display, transmit, update, secure, back up, restrict and delete personal data for the purpose of providing the service.
Categories of data subjects
- Landlords and property owners.
- Property managers and members of landlord organisations.
- Tenants and prospective tenants.
- Guarantors, occupants and tenant representatives.
- Contractors or other persons recorded in maintenance communications.
Types of personal data
- Name, email address and telephone number.
- Date of birth, nationality and postal address.
- Account and organisation information.
- Property, unit, occupancy and tenancy information.
- Contract dates, rent, deposit and payment information.
- Landlord bank and payment-instruction information.
- Maintenance requests, messages, photographs and attachments.
- Tenant documents uploaded to the service.
- Audit, access, authentication and security records.
- Other information entered by the Customer or its authorised users.
5. Customer responsibilities
The Customer is responsible for:
- Ensuring that personal data is collected and processed lawfully, fairly and transparently.
- Establishing and documenting an appropriate legal basis for processing.
- Providing appropriate privacy information to tenants and other affected persons.
- Entering only personal data that is adequate, relevant and reasonably necessary.
- Keeping personal data accurate and up to date.
- Establishing appropriate retention periods.
- Responding to requests made by data subjects.
- Managing the access granted to its users and promptly disabling access that is no longer required.
- Protecting account credentials and notifying Corevilla of suspected unauthorised access.
- Ensuring that its instructions to Corevilla comply with applicable law.
6. Confidentiality
Corevilla will ensure that persons authorised to process Customer personal data are subject to an appropriate duty of confidentiality.
Access to Customer personal data will be limited to persons who reasonably require access to operate, secure, maintain or support the service.
7. Security measures
Corevilla will implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Measures may include:
- Encrypted transmission using HTTPS.
- Authentication and role-based access controls.
- Organisation-level separation of customer data.
- Restricted administrative access.
- Security and audit logging.
- Password-protection and account-security controls.
- Backups and service-recovery measures.
- Software maintenance and security updates.
- Monitoring and investigation of suspected security incidents.
Security measures may be updated as the service develops, provided that the overall protection of personal data is not materially reduced.
8. Personal data breaches
Corevilla will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer’s behalf.
Where reasonably available, the notification will describe:
- The nature of the breach.
- The categories of data and persons affected.
- The likely consequences of the breach.
- The measures taken or proposed to address it.
Corevilla will provide reasonable cooperation to help the Customer investigate the incident and meet applicable notification obligations.
Notification of an incident does not constitute an acknowledgement of fault or liability by Corevilla.
9. Data-subject requests
Taking into account the nature of the processing, Corevilla will provide reasonable assistance to enable the Customer to respond to valid requests concerning access, correction, deletion, restriction, objection or data portability.
If Corevilla receives a request relating primarily to data controlled by the Customer, Corevilla may direct the person to the Customer or forward the request to the Customer.
Corevilla will not independently respond on behalf of the Customer unless authorised by the Customer or required by law.
10. Compliance assistance
Taking into account the nature of the processing and information reasonably available to Corevilla, Corevilla will provide reasonable assistance concerning:
- Security of processing.
- Personal data breach investigations and notifications.
- Data-protection impact assessments.
- Consultation with supervisory authorities where required.
- Responding to data-subject requests.
Assistance requiring substantial custom work may be subject to reasonable charges, provided that the Customer is informed before such charges are incurred.
11. Subprocessors
The Customer gives Corevilla general authorisation to use third-party service providers, referred to as subprocessors, where reasonably necessary to provide and support the service.
Subprocessors may provide services including:
- Application and database hosting.
- Email delivery.
- Payment and subscription processing.
- Mapping and address-search services.
- Monitoring, diagnostics and analytics.
- Backup, security and infrastructure services.
Corevilla will require subprocessors that process Customer personal data to provide data-protection commitments appropriate to the services they perform.
Corevilla remains responsible for the performance of its data-protection obligations where processing is delegated to a subprocessor, as required by applicable law.
Corevilla may update its subprocessors as the service develops. Where a new subprocessor is expected to materially affect the processing of Customer personal data, Corevilla will provide reasonable notice through the service, by email or by updating the relevant public information.
A Customer with a reasonable data-protection objection to a new subprocessor should contact Corevilla promptly at contact@corevilla.com .
12. International transfers
Corevilla may use service providers that process personal data outside Malta or the European Economic Area.
Where required, Corevilla will ensure that an appropriate transfer mechanism is in place, such as:
- An adequacy decision adopted by the European Commission.
- Approved Standard Contractual Clauses.
- Binding corporate rules.
- Another lawful safeguard recognised under the GDPR.
Corevilla will take supplementary measures where reasonably necessary in light of the transfer and associated risks.
13. Return and deletion of data
During an active subscription, the Customer may access, update and, where the service provides the relevant functionality, export or delete its information.
Following account closure or subscription expiry, Corevilla may restrict access to the account.
At the Customer’s request, Corevilla will delete or return Customer personal data where reasonably possible, unless applicable law requires or permits continued retention.
Data may remain temporarily within backups, security records or disaster-recovery systems until those records are overwritten or securely deleted through the normal retention cycle.
Corevilla may retain limited information where necessary to meet legal obligations, establish or defend legal claims, prevent fraud, resolve disputes or maintain service security.
Inactive or unpaid accounts are not necessarily deleted automatically after 30 days. They may subsequently be reviewed and deleted by a Corevilla administrator.
14. Information and audits
Corevilla will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable under data-protection law.
Where the information provided is insufficient, the Customer may request a reasonable audit concerning processing performed on its behalf.
Audits must:
- Be requested with reasonable advance notice.
- Take place during normal business hours.
- Minimise disruption to Corevilla and other customers.
- Protect confidential information and other customers’ data.
- Be limited to information relevant to the Customer’s processing.
The Customer will bear reasonable costs associated with an audit unless the audit identifies a material breach by Corevilla.
15. Liability
Each party is responsible for complying with the data-protection obligations that apply to it.
The Customer is responsible for the lawfulness, quality, accuracy and content of personal data entered into Corevilla and for the instructions it gives to Corevilla.
Liability arising under this Agreement is subject to the limitations and exclusions contained in the Corevilla Terms and Conditions, except where such limitation is prohibited by applicable law.
16. Order of precedence
If there is a conflict between this Agreement and the Corevilla Terms and Conditions concerning the processing of Customer personal data, this Data Processing Agreement will take precedence to the extent of that conflict.
17. Changes to this Agreement
Corevilla may update this Agreement to reflect changes to the service, subprocessors, security measures or applicable law.
The updated version will be published on this page with a revised effective date. Corevilla will provide reasonable notice where a change materially affects the processing of Customer personal data.
18. Contact
Questions concerning this Data Processing Agreement may be sent to: