Data Processing Agreement
Version 1.0 — June 7, 2026 — DRAFT, pending attorney review.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Propveo ("Processor"). It governs Propveo's processing of personal data on the Controller's behalf.
1. Scope & Roles
The Controller determines the purposes and means of processing personal data of tenants, property owners, vendors, and team members uploaded to the Service. The Processor processes that data only on documented instructions from the Controller, including these Terms and the Service configuration.
2. Subject & Duration
The subject of processing is the data Controller submits to the Service. Duration: for the term of the agreement plus the retention period set out in the Privacy Policy.
3. Categories of Data
- Identification: name, email, phone, language.
- Lease/tenancy info: unit, dates, rent, deposit, payment history.
- Communications: messages sent and received via the Service.
- Property & ticket data: addresses, photos, notes, status, costs.
4. Sub-Processors
- Supabase — database, auth, storage (US/EU).
- Vercel — hosting and edge (Global).
- Stripe — payments (US/EU).
- Anthropic — AI assistance (US).
- Meta WhatsApp Business — messaging (US/EU).
- Google — Maps, Geocoding (US).
We will notify the Controller of changes to this list with reasonable notice; the Controller may object on reasonable data-protection grounds.
5. Security
The Processor maintains: TLS 1.2+ in transit; AES-256 at rest; least-privilege access; Postgres row-level security between organizations; signed-URL access to storage; audit logging of admin actions; incident response procedures.
6. Data Subject Requests
The Processor will assist the Controller in responding to data-subject requests (access, deletion, correction, portability) through self-service export and admin tools, and via support where automation is not possible.
7. Breach Notification
The Processor will notify the Controller of a personal data breach without undue delay and in any event within 72 hours of becoming aware of it, providing the information needed for the Controller to comply with its own notification obligations.
8. International Transfers
Where transfers occur outside the EEA/UK or Mexico, they are made under appropriate safeguards (Standard Contractual Clauses, adequacy decisions, or equivalent).
9. Audits
The Controller may, on reasonable notice and at its expense, audit the Processor's compliance with this DPA once per year. The Processor may provide third-party audit reports (SOC 2 / ISO 27001) in lieu of on-site audits when available.
10. Deletion / Return
Upon termination, the Processor will, at the Controller's option, return or delete all Customer Data within 30 days, except where retention is required by law.
11. Liability
Each party's liability under this DPA is subject to the limitation-of-liability section in the Terms of Service.
12. Order of Precedence
In case of conflict between this DPA and the Terms of Service, this DPA controls in respect of data-protection matters.