Processing terms for business users
Last updated 10 October 2026
When these terms apply
These terms apply when you use CheckMyRental in the course of your business or profession, including when you let out homes for income, and a lease or your answers hold personal data of other people, for example your tenants. You are then the controller of that data and we are your processor (Article 28 of the GDPR). You accept these terms together with the Terms when you order.
When you use CheckMyRental as a consumer, we are the controller of your data and these terms do not apply. The privacy notice then describes what we do.
The clauses
Between you and us, the standard contractual clauses between controllers and processors in Commission Implementing Decision (EU) 2021/915 apply, unchanged. Annexes I to IV below are part of them. The decision is published at https://eur-lex.europa.eu/eli/dec_impl/2021/915/oj.
Where the clauses leave a choice: for sub-processors, the general written authorisation applies, and we change the list in Annex IV on this page at least 10 days before a new sub-processor starts, and tell you by email at the address of your order or account if it still exists then. If you object, you can stop using the service and delete your data. The competent supervisory authority is the Autoriteit Persoonsgegevens, the Dutch data protection authority.
Annex I: the parties
Controller: you, the person or business that placed the order or holds the account, identified by the email address you gave.
Processor: Neurova AI (sole proprietorship), Heideveldstraat 6, 5643 CH Eindhoven, Netherlands, KvK 94328900, VAT NL005076610B08. Contact for data protection: support@checkmyrental.nl, +31 6 19919544. No data protection officer has been appointed.
Annex II: the processing
- Item
- Purpose
- Description
- To check the masked text of a lease against 12 rules and to produce your report, on your instruction: you send the text and ask for the report. We process the data for nothing else.
- Item
- People concerned
- Description
- People named in the leases and answers you send, for example your tenants, co-tenants and agents, and you.
- Item
- Personal data
- Description
- The masked lease text (names, addresses, bank account numbers, phone numbers, email addresses, birth dates and ID numbers are masked in your browser before it is sent; masking can miss a detail), your answers to the questions, and your email address.
- Item
- Sensitive data
- Description
- None is asked for or intended. Do not send documents that hold such data.
- Item
- What we do with it
- Description
- Reading and masking happen in your browser. On our server: receiving, checking again, analysis by software and by an AI model that finds and quotes clauses, storage, producing the report, deletion.
- Item
- How long
- Description
- Contract text: 24 hours after upload. Findings: 7 days after the analysis, or with their report. Report: 7 days after delivery. The order with your answers and email address: 7 days, the end of the 14th day after a payment, or 8 days after a re-check if that is later. Earlier with Delete my data now. When the processing ends we delete the data. We keep only the minimal payment record that tax rules require, for which we are an independent controller.
| Item | Description |
|---|---|
| Purpose | To check the masked text of a lease against 12 rules and to produce your report, on your instruction: you send the text and ask for the report. We process the data for nothing else. |
| People concerned | People named in the leases and answers you send, for example your tenants, co-tenants and agents, and you. |
| Personal data | The masked lease text (names, addresses, bank account numbers, phone numbers, email addresses, birth dates and ID numbers are masked in your browser before it is sent; masking can miss a detail), your answers to the questions, and your email address. |
| Sensitive data | None is asked for or intended. Do not send documents that hold such data. |
| What we do with it | Reading and masking happen in your browser. On our server: receiving, checking again, analysis by software and by an AI model that finds and quotes clauses, storage, producing the report, deletion. |
| How long | Contract text: 24 hours after upload. Findings: 7 days after the analysis, or with their report. Report: 7 days after delivery. The order with your answers and email address: 7 days, the end of the 14th day after a payment, or 8 days after a re-check if that is later. Earlier with Delete my data now. When the processing ends we delete the data. We keep only the minimal payment record that tax rules require, for which we are an independent controller. |
Annex III: technical and organisational measures
- Area
- Masking
- What we do
- Personal details are masked in your browser before anything is sent. Our server checks again and refuses unmasked bank account numbers, email addresses, phone numbers, ID numbers and birth dates.
- Area
- AI provider
- What we do
- Only the masked text goes to the AI provider. A type in the code enforces this.
- Area
- Access
- What we do
- Report links are random 256-bit codes kept only as one-way hashes. Accounts have no password: a sign-in link works once for 15 minutes and a session lasts 12 hours. The owner's tools need a secret.
- Area
- Transport and browser
- What we do
- HTTPS with HSTS, a strict content security policy and strict security headers.
- Area
- Logs
- What we do
- Contract text, names and addresses are never written to logs. A test fails if they are.
- Area
- Deletion
- What we do
- Deletion runs every 15 minutes and removes deleted text from the database file (secure delete, log truncation and VACUUM). Volume backups are off so that deleted data is not copied elsewhere.
- Area
- Hosting
- What we do
- Our servers and database run in Railway's Amsterdam region.
- Area
- Abuse and failures
- What we do
- Rate limits, a daily AI budget, a bot check, a kill switch for every rule, and alerts to the owner when something fails.
- Area
- Your help from us
- What we do
- The people concerned can use Download my data and Delete my data now, or write to us; we help with their requests, with impact assessments and with consultations as the clauses require. We tell you without undue delay after we become aware of a breach that affects your data.
| Area | What we do |
|---|---|
| Masking | Personal details are masked in your browser before anything is sent. Our server checks again and refuses unmasked bank account numbers, email addresses, phone numbers, ID numbers and birth dates. |
| AI provider | Only the masked text goes to the AI provider. A type in the code enforces this. |
| Access | Report links are random 256-bit codes kept only as one-way hashes. Accounts have no password: a sign-in link works once for 15 minutes and a session lasts 12 hours. The owner's tools need a secret. |
| Transport and browser | HTTPS with HSTS, a strict content security policy and strict security headers. |
| Logs | Contract text, names and addresses are never written to logs. A test fails if they are. |
| Deletion | Deletion runs every 15 minutes and removes deleted text from the database file (secure delete, log truncation and VACUUM). Volume backups are off so that deleted data is not copied elsewhere. |
| Hosting | Our servers and database run in Railway's Amsterdam region. |
| Abuse and failures | Rate limits, a daily AI budget, a bot check, a kill switch for every rule, and alerts to the owner when something fails. |
| Your help from us | The people concerned can use Download my data and Delete my data now, or write to us; we help with their requests, with impact assessments and with consultations as the clauses require. We tell you without undue delay after we become aware of a breach that affects your data. |
Annex IV: sub-processors
- Sub-processor
- Anthropic (Anthropic Ireland Limited for customers in the EEA)
- What it does
- AI model that finds and quotes clauses. Receives only the masked text.
- Where
- United States or worldwide (no EU-only option)
- Safeguard
- EU Standard Contractual Clauses in its data processing addendum
- Sub-processor
- Railway (Railway Corporation)
- What it does
- Hosting of the app and the database
- Where
- Amsterdam region; United States parent company
- Safeguard
- EU Standard Contractual Clauses or the EU-US Data Privacy Framework, in its data processing addendum
- Sub-processor
- Resend (Plus Five Five, Inc.)
- What it does
- Sending email: your link, your report, confirmations
- Where
- United States
- Safeguard
- EU Standard Contractual Clauses; certified under the EU-US Data Privacy Framework
- Sub-processor
- Cloudflare, Inc. (Turnstile)
- What it does
- Bot check
- Where
- United States
- Safeguard
- EU Standard Contractual Clauses and the EU-US Data Privacy Framework
| Sub-processor | What it does | Where | Safeguard |
|---|---|---|---|
| Anthropic (Anthropic Ireland Limited for customers in the EEA) | AI model that finds and quotes clauses. Receives only the masked text. | United States or worldwide (no EU-only option) | EU Standard Contractual Clauses in its data processing addendum |
| Railway (Railway Corporation) | Hosting of the app and the database | Amsterdam region; United States parent company | EU Standard Contractual Clauses or the EU-US Data Privacy Framework, in its data processing addendum |
| Resend (Plus Five Five, Inc.) | Sending email: your link, your report, confirmations | United States | EU Standard Contractual Clauses; certified under the EU-US Data Privacy Framework |
| Cloudflare, Inc. (Turnstile) | Bot check | United States | EU Standard Contractual Clauses and the EU-US Data Privacy Framework |
Payments
Stripe handles payments. It receives no lease text and no answers, so it is not a sub-processor of your lease data. What Stripe does with payment data and your email address is described in the privacy notice.