1. Definitions and application
“Applicable Data Protection Law” means privacy, data-protection, and data-security law applicable to Provider’s processing of Customer Personal Data under the Agreement. “Customer Personal Data” means personal data, personal information, or a similar protected category contained in Customer Data and processed by Provider on Customer’s behalf. “Data Subject,” “Controller,” “Processor,” “Business,” “Service Provider,” “Sell,” and “Supervisory Authority” have the meanings given by Applicable Data Protection Law.
This DPA applies only to Customer Personal Data processed by Provider as a Processor or Service Provider. It does not govern information for which Provider independently determines the purposes and means of processing, such as Provider’s own account administration, security, billing, and business-contact records, which are addressed in the Privacy Policy.
2. Roles and documented instructions
Customer is the Controller or Business, and Provider is the Processor or Service Provider, for Customer Personal Data. Customer is responsible for its instructions and for providing all notices, rights, permissions, and lawful bases required for the processing. Provider will process Customer Personal Data only:
- to provide, secure, maintain, and support the Service under the Agreement;
- as configured or initiated by Customer and its authorized users;
- as further documented in an Order Form or written instruction from Customer; or
- as required by law, in which case Provider will notify Customer before processing unless the law prohibits notice.
Provider will promptly inform Customer if, in Provider’s reasonable opinion, an instruction violates Applicable Data Protection Law. Provider may suspend the affected processing while the parties work in good faith to resolve the issue.
Provider will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain or use it outside the business relationship with Customer, or combine it with personal information obtained from another source except as permitted to provide the Service or by Applicable Data Protection Law. Provider will not use Customer Personal Data to train a general-purpose AI model unless Customer gives an explicit instruction under separately approved terms.
3. Processing details
Subject matter and purpose
Hosting and operating a multi-tenant real-estate wholesaling CRM, authenticating users, enforcing company membership and permissions, storing protected documents, supporting Customer, sending transactional email, and providing a read-only AI Help Assistant.
Duration
For the term of the Agreement and any limited period afterward needed for Customer’s authorized export, deletion, backups, security, legal compliance, or dispute resolution, subject to Section 11.
Nature of processing
Collection, recording, organization, structuring, hosting, storage, retrieval, consultation, display, transmission, import, export, versioning, restriction, support, security analysis, deletion, and other processing initiated by authorized use of the Service.
Categories of Data Subjects
Customer personnel and authorized users; prospective and actual property sellers, owners, buyers, investors, vendors, contractors, and business contacts; and other individuals whose information Customer lawfully submits to the Service.
Types of Customer Personal Data
Names, business and personal contact details, account and role information, property and lead information, appointment and task details, communications metadata, notes, offer and transaction information, contract and document contents, import data, buyer criteria, audit events, and other fields or files Customer chooses to submit.
Sensitive or regulated data
The Service is not designed for protected health information, payment-card data subject to PCI DSS storage requirements, government identification numbers, account passwords, biometric identifiers, or other special-category or highly sensitive data unless an Order Form expressly authorizes the data type and the parties approve appropriate safeguards. Customer will not submit such data without that written authorization.
4. Confidentiality and personnel
Provider will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed for their responsibilities. Provider will provide appropriate privacy and security guidance to personnel with such access and will remain responsible for their compliance with this DPA.
5. Security measures
Provider will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures in the current product architecture include:
- verified-account authentication and protected password-reset and session flows managed through Supabase Auth;
- company identifiers on tenant records, application-layer company scoping, and Postgres row-level security to reinforce tenant isolation;
- server-side authorization using company membership, roles, and permission keys rather than relying on interface visibility;
- company-scoped storage paths and protected document access and download flows;
- input validation, parameterized database access, and server-side secret handling;
- audit logging for implemented sensitive events and minimized operational logging designed to avoid unnecessary personal data;
- cross-tenant tests for protected product surfaces and security review of changes affecting authentication, authorization, tenancy, or documents; and
- a read-only AI capability boundary with no write tools and minimized provider-bound context.
Deployment-dependent measures, including backup scope, recovery objectives, monitoring, retention automation, and incident operations, will be described in the Agreement or security materials only after verification. No SOC 2, ISO, HIPAA, GDPR, or other certification is represented by this DPA.
6. Subprocessors
Customer generally authorizes Provider to engage subprocessors to provide the Service. Current service categories include Supabase services for authentication, managed Postgres database infrastructure, and protected object storage; hosting infrastructure; and a transactional email provider for account, invitation, security, import, and billing messages. When the AI Help Assistant uses external inference, an AI service provider may process assistant prompts, approved Help Center content, and minimized safe context. Provider will maintain a current list of material subprocessors on the Subprocessors page before this DPA becomes effective.
Provider will impose data-protection obligations on each subprocessor that are no less protective in material respects than the obligations applicable to Provider under this DPA, to the extent relevant to the services performed. Provider remains responsible for each subprocessor’s performance of those obligations.
Provider will give reasonable advance notice of a new material subprocessor when required by the Agreement. Customer may object on reasonable data-protection grounds by written notice within the stated notice period. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate only the affected Service, and Provider will refund prepaid fees for the terminated period.
7. Personal Data Breach
Provider will notify Customer without undue delay after becoming aware of a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Provider’s possession or control (a “Personal Data Breach”). Notice is not an admission of fault or liability.
Provider may give an initial notice with the information then available and supplement it as the investigation develops. The notice will describe, as reasonably available, the nature of the incident, affected data and Data Subjects, likely consequences, containment or remediation measures, and a contact for follow-up. Provider will take reasonable steps to contain, investigate, and mitigate the incident and will provide information reasonably needed for Customer to meet its legal notification duties. Customer is responsible for notifying regulators and Data Subjects unless law assigns that duty to Provider.
8. Data Subject requests
Taking into account the nature of the processing, Provider will provide reasonable assistance through available Service functionality and appropriate technical measures so Customer can respond to verified requests to exercise privacy rights. If Provider receives a request directly concerning Customer Personal Data, Provider will refer the requester to Customer and will not independently respond except as Customer authorizes or law requires.
Customer is responsible for determining whether a request is valid and for instructing Provider. If assistance requires material work beyond standard Service functionality, Provider may charge reasonable costs after giving Customer an estimate, unless Applicable Data Protection Law prohibits a charge.
9. Compliance assistance
Taking into account the nature of processing and information available to Provider, Provider will reasonably assist Customer with data-protection impact assessments, prior consultations, security inquiries, and records needed to demonstrate compliance. Customer remains responsible for its assessment of the Service, its processing instructions, and its regulatory obligations.
10. International transfers
Customer authorizes processing in the countries where Provider and approved subprocessors operate, subject to Applicable Data Protection Law. If Customer Personal Data is transferred from a jurisdiction that restricts international transfers, the parties will use the applicable approved transfer mechanism, such as then-current standard contractual clauses or another lawful safeguard. Any required transfer addendum must be executed before the restricted transfer begins.
11. Return and deletion
During the subscription term, Customer may access and export Customer Data through the Service’s available features. After termination or expiration and on Customer’s written request, Provider will delete or return Customer Personal Data in accordance with the Agreement and Provider’s documented deletion process, unless law requires retention.
To the extent backup copies exist, Customer Personal Data in them will remain protected and isolated from ordinary use. Any backup-expiration schedule or retention commitment will be documented and operationally verified before this DPA becomes effective. Provider may retain limited security, audit, billing, and legal records where required or reasonably necessary, subject to continued confidentiality and use restrictions. De-identified data may be retained only if Provider takes reasonable measures to prevent re-identification and does not attempt to re-identify it.
12. Information and audits
On reasonable written request, Provider will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant security summaries, policies, questionnaires, and independent reports if and when available. The absence of an independent certification or report does not reduce Provider’s obligations under an executed DPA and must not be represented as a certification.
If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may conduct one audit per year through an independent qualified auditor, with at least 30 days’ notice, during normal business hours, under confidentiality obligations, and without accessing another customer’s data or unreasonably disrupting operations. More frequent audits are permitted following a confirmed Personal Data Breach or regulator request. Customer bears its audit costs unless the audit identifies a material breach by Provider.
13. Order of precedence and liability
If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls. The Agreement’s liability limitations apply to this DPA to the extent permitted by Applicable Data Protection Law. If the parties execute jurisdiction-specific terms, those terms control for the covered processing.
14. DPA requests and privacy contact
Contact us to request an execution-ready DPA or raise a processing question. Do not include Customer Personal Data in the initial request.
A&A Development LLC
Email: sales@aadealflow.com
5900 Balcones Drive STE 100, Austin, TX 78731