Legal · United States · Archived version

Propty Data Processing Addendum

Version:
2026.08.31
Published:
2026-08-31
SHA-256:
f55300810ca06b08516a1dfc26abb102b5d4cbdd160102b34d77373e96d647f6
Counsel-delivered text, version 2026.08.31. This published source is immutable; later changes require a new version and URL.
PROPTY DATA PROCESSING ADDENDUM Version: 2026.08.31 Effective Date: The effective date of the applicable Propty Operator Agreement or Order Form. This Data Processing Addendum ("DPA") forms part of the Propty Operator Agreement between Propty, Inc. ("Propty") and the entity identified as Operator in an applicable Order Form ("Operator"). Capitalized terms not defined in this DPA have the meanings given in the Operator Agreement. 1. Scope This DPA governs Propty's Processing of Personal Data in connection with the Services. For purposes of this DPA: "Personal Data" means information relating to an identified or reasonably identifiable individual and includes equivalent concepts such as personal information or personal data under Applicable Data Protection Law. "Applicable Data Protection Law" means privacy, data-protection and security laws applicable to the Processing. "Process" or "Processing" has the meaning assigned by Applicable Data Protection Law. "Subprocessor" means a third party engaged by Propty to Process Personal Data on Operator's behalf. 2. Roles 2.1 Processor / Service Provider Role To the extent Propty Processes Personal Data solely to provide the Services according to Operator's documented instructions, Operator acts as the relevant controller/business and Propty acts as processor/ service provider or equivalent. This generally includes: • tenant or customer PII; • account information; • payment-status data; • contact information; • call recordings used to provide the Operator's service; • call transcripts used to provide the Operator's service; • communications content; • lease and rental information; • operator account records. 2.2 Independent Processing Propty may Process limited Personal Data for its own legitimate and legally permitted purposes where Propty independently determines the purposes and means of that Processing, including: • security; • fraud prevention; • abuse prevention; • authentication; • system integrity; • regulatory compliance; • licensing; • legal holds; • establishment, exercise or defense of legal claims; • mandatory compliance records; • audit evidence. For those limited purposes, Propty acts in the role assigned to it by Applicable Data Protection Law. 2.3 Mixed-Purpose Records Certain records may serve both Operator service purposes and Propty's independent compliance purposes. These include: • consent records; • revocation records; • presentation events; • refusal or suppression records; • statutory workflow records; • access and security logs. Propty will limit any independent use of these records to the applicable compliance, security, audit or legal purpose. 3. Operator Instructions Operator instructs Propty to Process Personal Data as necessary to: • provide the Services; • perform configured workflows; • transmit communications; • maintain accounts; • support Operator users; • provide reporting; • maintain and secure the Services; • perform contractual obligations; • comply with Applicable Law. Additional documented instructions may be provided through: • the Operator Agreement; • an Order Form; • platform configuration; • an authorized API request; • written instructions accepted by Propty. Propty will notify Operator if, in Propty's reasonable judgment, an instruction violates Applicable Data Protection Law, and may suspend that instruction. 4. Purpose Limitation Propty will not: • sell Operator Personal Data; • use Operator Personal Data for unrelated advertising; • use identifiable Operator Personal Data to create tenant-level profiles for another customer; • disclose Operator Personal Data to another Propty customer; • use Operator Personal Data beyond the purposes permitted by this DPA and the Operator Agreement. 5. Cross-Customer Prohibition Propty will not use identifiable Personal Data from one Operator to provide another Operator with: • tenant-level intelligence; • customer-level intelligence; • targeting; • behavioral profiles; • collection scores; • payment propensity information; • individualized recommendations concerning another Operator's tenants. This restriction does not prohibit use of properly aggregated or deidentified data that cannot reasonably identify an individual, Operator or Location. 6. AI Training Prohibition Propty will not use identifiable: • Operator Data; • tenant Personal Data; • call recordings; • call transcripts; • collection communications; • account information; • consent records; • statutory notice records to train or fine-tune a general-purpose artificial intelligence model for Propty, another customer or a third- party model provider unless: 1. Operator separately authorizes that use in writing; and 2. any legally required authorization from affected individuals has been obtained. This prohibition does not prevent: • inference necessary to provide the Services; • transient processing by an AI model necessary to generate an Operator-requested output; • retrieval-augmented generation that does not train the underlying general model; • security and safety testing; • deidentified analytics; • customer-specific configuration that does not train a shared or general-purpose model. Propty will contractually restrict its Subprocessors consistently with this Section to the extent applicable to their Processing. 7. Confidentiality Propty will ensure that persons authorized to Process Personal Data: • are subject to appropriate confidentiality obligations; and • access Personal Data only as necessary for their authorized duties. 8. Security Propty will maintain reasonable and appropriate administrative, technical and organizational safeguards considering the nature of the Personal Data and Services. These safeguards will include, as appropriate: • encryption in transit; • encryption at rest; • logical access controls; • least-privilege access; • authentication; • logging and monitoring; • vulnerability management; • backup and recovery; • incident-response procedures; • employee security controls; • separation of customer data; • secrets-management practices. 9. Security Incidents Propty will notify Operator without undue delay after confirming a Security Incident involving Operator Personal Data. The notice will include information reasonably available concerning: • nature of the incident; • categories of Personal Data involved; • known or reasonably estimated scope; • mitigation measures; • remediation measures; and • information reasonably necessary for Operator to assess legally required notifications. Notification does not constitute an admission of fault or liability. Propty may provide information in phases as an investigation continues. Nothing requires Propty to disclose information that would: • compromise security; • violate Applicable Law; • compromise legal privilege; or • violate a binding governmental restriction. 10. Subprocessors Operator authorizes Propty to use Subprocessors necessary to provide the Services. Propty will: • maintain a current Subprocessor list; • impose written data-protection obligations appropriate to the Processing; • remain responsible for the performance of its Subprocessors to the extent required by Applicable Law and the Operator Agreement. Where legally or contractually required, Propty will provide advance notice of material new Subprocessors. 11. Data-Subject Requests Where Propty acts as processor/service provider, Propty will provide reasonable assistance enabling Operator to respond to valid requests concerning: • access; • deletion; • correction; • portability; • restriction; • objection; • opt-out rights. Propty may direct a request received from an individual to Operator where Operator is responsible for responding. Where Propty independently Processes limited information for compliance, security, fraud prevention or legal claims, Propty will evaluate the request under Applicable Law applicable to that Processing. 12. Deletion and Return Following termination of the Services, Propty will delete or return Operator Personal Data in accordance with: • the Operator Agreement; • this DPA; • Operator's documented instructions; • Propty's applicable retention schedule. Propty may retain Personal Data where reasonably necessary for: • Applicable Law; • regulatory obligations; • licensing; • legal holds; • security; • fraud prevention; • establishment, exercise or defense of legal claims; • documented compliance evidence. Retained Personal Data will be restricted to those purposes and deleted when the applicable retention basis expires. 13. Legal Holds A valid legal hold suspends ordinary deletion for the affected records. Propty's legal-hold system will identify, as appropriate: • matter; • scope; • affected records or accounts; • relevant record classes; • hold start date; • authorized person; • release date or event. After release, applicable ordinary retention rules resume. 14. Compliance Evidence Operator acknowledges that Propty may independently retain narrowly scoped Compliance Evidence necessary to demonstrate: • consent; • revocation; • compliance-control operation; • suppressed actions; • statutory workflow execution; • legal or regulatory compliance; • communications history; • audit history. Deletion of an operational tenant profile does not necessarily require immediate deletion of lawfully retained Compliance Evidence. 15. Audits and Information Upon reasonable written request, Propty will provide information reasonably sufficient to demonstrate compliance with its processor/service-provider obligations. Where legally required, Propty will permit a reasonable audit subject to: • reasonable advance notice; • appropriate confidentiality; • protection of other customers' information; • protection of privileged information; • reasonable scope and frequency; • protection of security-sensitive information. Propty may satisfy an audit request through current independent certifications, reports or questionnaires where legally sufficient. 16. International Transfers Where Propty Processes Personal Data across national borders, Propty will implement any legally required transfer mechanism. Operator will not instruct Propty to Process Personal Data in a manner that violates applicable cross-border transfer requirements. 17. Operator Obligations Operator represents that: • it has a lawful basis to provide Personal Data to Propty; • its instructions comply with Applicable Law; • its privacy notices accurately describe its use of Propty where required; • it will not instruct Propty to unlawfully Process Personal Data; • Operator Data supplied to Propty is lawfully obtained. 18. Order of Precedence If this DPA conflicts with the Operator Agreement regarding Processing of Personal Data, this DPA controls. An applicable jurisdiction-specific data-protection addendum may control for its stated subject matter. 19. Liability Liability arising from this DPA is governed by the indemnification and limitation-of-liability provisions of the Operator Agreement unless Applicable Law prohibits such limitation. 20. Survival This DPA survives termination for so long as Propty retains Personal Data subject to its terms.