Tentunit Business — Data Processing Addendum (DPA)
Version 1.1 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business
1. Scope, Parties & Roles
This section explains who this DPA binds, what data it covers, and who acts as controller and processor. In short: your tenants’ data is yours; Tentunit only processes it to run the service for you.
1.1 Incorporation and Parties
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Tentunit Business Terms of Service (the “Agreement”) between Tentunit, Inc., a Delaware corporation (“Tentunit”), and the landlord, property manager, or other entity subscribing to Tentunit Business (“Customer”). Each of Tentunit and Customer is a “party.” This DPA takes effect on the earlier of the Effective Date stated above and the date Customer first submits Tenant Data to the Services, and remains in force for as long as Tentunit processes Tenant Data on Customer’s behalf.
1.2 Covered Processing
This DPA applies whenever Tentunit processes personal data relating to Customer’s tenants, rental applicants, guarantors, and related individuals (“Tenant Data”) on Customer’s behalf in the course of providing Tentunit Business (the “Services”), including rent collection, tenant screening support, lease and document management, and tenant communications.
1.3 Allocation of Roles
For Tenant Data, the parties agree that:
- Customer is the controller of Tenant Data (or, where Customer processes Tenant Data on behalf of another property owner or principal, Customer acts as a processor instructing Tentunit as its sub-processor);
- Tentunit is the processor, acting only on Customer’s documented instructions as described in Section 4; and
- for the purposes of the CCPA, Tentunit acts as Customer’s “service provider” as further described in Section 13.
1.4 Excluded Processing
This DPA does not apply to personal data that Tentunit processes as an independent controller for its own purposes, including: (a) Customer’s own account, registration, billing, and subscription data; (b) data processed for Tentunit’s security, fraud prevention, service integrity, and legal compliance; and (c) payment data processed by Tentunit and its payment processor as independent controllers under the Payments Terms. Such processing is governed by the Tentunit Privacy Policy and, where applicable, the Privacy Policy Business Supplement.
2. Definitions
This section defines the technical terms used throughout the DPA. Terms drawn from the GDPR carry the meanings European regulators and courts give them.
2.1 Defined Terms
- “Data Protection Laws” means all laws and regulations applicable to the processing of personal data under this DPA, including (i) Regulation (EU) 2016/679 (the “GDPR”); (ii) the UK GDPR and the UK Data Protection Act 2018; (iii) the California Consumer Privacy Act, as amended, and its regulations (the “CCPA”); and (iv) any other applicable US state, federal, or member-state data protection law, in each case as amended or replaced.
- “personal data,” “controller,” “processor,” “processing” (and “process”), “data subject,” “personal data breach,” “supervisory authority,” and “special categories of personal data” have the meanings given to them in Article 4 GDPR (and, for processing subject to the UK GDPR, the corresponding meanings under the UK GDPR). “Personal data” includes “personal information” as defined in the CCPA, and “data subject” includes “consumer” as defined in the CCPA, in each case to the extent the CCPA applies.
- “sell,” “share,” “business purpose,” “commercial purpose,” “service provider,” and “deidentified” have the meanings given in the CCPA.
- “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner’s Office.
- “Sub-processor” means any third party engaged by Tentunit (or by another Sub-processor) to process Tenant Data on Customer’s behalf.
- “Business ToS” means the Tentunit Business Terms of Service.
2.2 Interpretation
Capitalized terms not defined in this DPA have the meanings given in the Agreement. References to laws include their regulations and successors; “including” means “including without limitation.”
3. Details of Processing
This section summarizes what data Tentunit processes for you, about whom, and for how long. The full Annex I-style description required by the SCCs appears in Schedule 3.
3.1 Subject Matter, Duration, Nature and Purpose
The subject matter of the processing is the provision of the Services described in the Agreement. The duration is the term of Customer’s subscription, plus the post-termination export and deletion window described in Section 12. The nature and purpose of the processing comprise the hosting, storage, transmission, organization, structuring, retrieval, analysis, and display of Tenant Data as necessary to operate the Services, provide technical support, and comply with Customer’s documented instructions. Tentunit does not process Tenant Data for its own advertising purposes.
3.2 Categories of Personal Data and Data Subjects
The categories of personal data (identity, contact, lease, payment-record, communications, and document data) and the categories of data subjects (tenants, rental applicants, guarantors and co-signers, and other individuals whose data Customer submits to the Services) are described in full in Schedule 3, which serves as the Annex I-style description of processing for the SCCs.
3.3 Special Categories
The Services are not designed or intended for special categories of personal data under GDPR Article 9, data relating to criminal convictions and offences under GDPR Article 10 (except lawful screening outputs Customer obtains through properly licensed screening features), or sensitive personal information under the CCPA beyond what is inherent in the categories above. Customer must not submit such data except where strictly necessary and lawful, and bears sole responsibility for any such submission.
4. Processing on Documented Instructions
This section is the core processor promise: Tentunit only does with Tenant Data what you tell it to do, and will warn you if an instruction appears unlawful.
4.1 Documented Instructions
Tentunit shall process Tenant Data only on Customer’s documented instructions, including with regard to transfers of Tenant Data to a third country or an international organisation, unless required to do so by applicable law to which Tentunit is subject; in such a case, Tentunit shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Customer’s documented instructions consist of: (a) the Agreement and this DPA (including the SCCs where applicable); (b) Customer’s configuration and use of the Services and their features; and (c) any further written instructions agreed by the parties. Instructions outside the scope of the Agreement require prior written agreement.
4.2 Infringing Instructions
Tentunit shall inform Customer without undue delay if, in Tentunit’s opinion, an instruction infringes Data Protection Laws. Pending resolution, Tentunit may suspend performance of the affected instruction. Tentunit is not obliged to perform a comprehensive legal review of Customer’s instructions, and Customer remains responsible for the lawfulness of its instructions.
4.3 Customer Responsibilities
Customer warrants that: (a) it has, and will maintain, a lawful basis and all legally required notices and consents for the Tenant Data it submits to the Services; (b) its instructions comply with Data Protection Laws; and (c) where Customer acts as a processor for another controller, it is authorized to appoint Tentunit as a sub-processor on the terms of this DPA.
4.4 Article 28(3) Obligation Mapping
For clarity, the parties record how this DPA satisfies each element of GDPR Article 28(3):
| GDPR Art. 28(3) requirement | Where addressed |
|---|---|
| (a) Processing only on documented instructions, incl. transfers | Sections 4.1, 10 |
| (b) Confidentiality commitments of authorized persons | Section 5 |
| (c) Security measures under Article 32 | Section 6; Schedule 2 |
| (d) Conditions for engaging sub-processors (Art. 28(2), (4)) | Section 9; Schedule 1 |
| (e) Assistance with data subject rights (Chapter III) | Section 7.1 |
| (f) Assistance with Articles 32–36 obligations | Sections 7.2–7.5, 8 |
| (g) Return or deletion at end of services | Section 12 |
| (h) Information to demonstrate compliance; audits | Section 11 |
5. Confidentiality & Personnel
Plainly: everyone at Tentunit who can touch Tenant Data is bound to keep it confidential and is trained to handle it properly.
5.1 Confidentiality Commitments
Tentunit shall ensure that persons authorized to process Tenant Data have committed themselves to confidentiality under written contractual obligations or are under an appropriate statutory obligation of confidentiality. These obligations survive the end of the person’s engagement.
5.2 Access Limitation and Training
Tentunit shall limit access to Tenant Data to personnel who require such access to perform the Services or Tentunit’s obligations under this DPA, and shall ensure that such personnel receive appropriate and regular data protection and security training as described in Schedule 2.
6. Security of Processing
This section commits Tentunit to concrete safeguards — encryption, access controls, and logging — sized to the risks of the data.
6.1 Technical and Organizational Measures
Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to data subjects, Tentunit shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32, including at minimum:
- encryption of Tenant Data in transit and at rest;
- role-based access controls (RBAC) limiting access to personnel with a need to know; and
- audit logging of access to and material actions on Tenant Data.
The full set of measures is described in Schedule 2.
6.2 Updates to Measures
Tentunit may update the measures in Schedule 2 to reflect technical progress and evolving threats, provided updates do not materially reduce the overall level of protection of Tenant Data.
7. Assistance Obligations
Because tenants exercise their privacy rights against Customer (the controller), this section obliges Tentunit to give Customer the practical help it needs to respond — and to help with security, breach, and impact-assessment duties.
7.1 Data Subject Requests (GDPR Chapter III)
Taking into account the nature of the processing, Tentunit shall assist Customer, by appropriate technical and organizational measures and insofar as this is possible, in fulfilling Customer’s obligation to respond to data subject requests under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection) and analogous rights under other Data Protection Laws, including through the Services’ self-service search, correction, export, and deletion features. If Tentunit receives a request directly from a data subject relating to Tenant Data, Tentunit will not respond substantively (except to direct the individual to Customer) and will forward the request to Customer within 5 business days of receipt.
7.2 Security Assistance (Article 32)
Tentunit shall assist Customer in ensuring compliance with Customer’s own security obligations under GDPR Article 32 by implementing the measures in Section 6 and Schedule 2 and by providing the compliance information described in Section 11.
7.3 Breach Notification Assistance (Articles 33–34)
Tentunit shall assist Customer in complying with Customer’s obligations to notify personal data breaches to supervisory authorities and to communicate them to data subjects, by providing the notifications, information, and cooperation described in Section 8.
7.4 Data Protection Impact Assessments (Article 35)
Tentunit shall provide reasonable assistance to Customer with data protection impact assessments relating to Customer’s use of the Services, to the extent the required information is available to Tentunit and Customer does not otherwise have access to it.
7.5 Prior Consultation (Article 36)
Tentunit shall provide reasonable assistance to Customer with prior consultations with supervisory authorities under GDPR Article 36 arising from Customer’s use of the Services, to the extent the required information is available to Tentunit.
8. Personal Data Breach
If something goes wrong with Tenant Data, this section requires Tentunit to tell Customer quickly and give it the facts needed to meet its own regulatory deadlines.
8.1 Notification
Tentunit shall notify Customer without undue delay, and in any event no later than 72 hours after becoming aware of a personal data breach affecting Tenant Data. Notification will be made to Customer’s account administrator email and, where designated, Customer’s privacy contact.
8.2 Content of Notification
The notification will describe, to the extent then known: (a) the nature of the breach, including where possible the categories and approximate volumes of Tenant Data and data subjects affected; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (d) a contact point for further information ([email protected]). Where all information is not available at once, it may be provided in phases without undue further delay.
8.3 Cooperation and Remediation
Tentunit shall provide timely updates as its investigation progresses, take reasonable steps to contain and remediate the breach, and reasonably cooperate with Customer’s own notification obligations. Tentunit’s notification is not an admission of fault or liability; Customer remains responsible for deciding whether and how to notify supervisory authorities and data subjects in respect of Tenant Data.
9. Sub-processors
Tentunit relies on a short list of vetted vendors (like Stripe for payments). This section sets the rules for adding or changing them and preserves Customer’s right to object.
9.1 General Authorization
Customer provides a general authorization for Tentunit to engage Sub-processors to process Tenant Data, including those listed in Schedule 1 — currently the Stripe entities (payments and identity verification). Any additional sub-processors (for example, hosting, email delivery, analytics, or AI model providers) will be added to Schedule 1 with 30 days’ notice per Section 9.3.
9.2 Flow-Down Obligations
Before permitting any Sub-processor to process Tenant Data, Tentunit shall carry out reasonable due diligence and impose on the Sub-processor, by written contract, data protection obligations materially no less protective than those set out in this DPA. Tentunit remains fully liable to Customer for the performance of each Sub-processor’s obligations.
9.3 Changes and Objection Right
Tentunit will give Customer at least 30 days’ advance notice of any intended addition or replacement of a Sub-processor (via email or an in-product subscription mechanism). Customer may object on reasonable, documented data protection grounds within the notice period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees for those Services. If Customer does not object within the notice period, the change is deemed accepted.
10. International Transfers
Tenant Data protected by EU or UK law may be processed in the United States; this section puts the legally required transfer mechanisms and safeguards in place automatically.
10.1 EU Transfers — SCCs
Where Tenant Data protected by the GDPR is transferred to Tentunit in the United States (or another country not benefiting from an adequacy decision), the parties incorporate the EU SCCs, Module Two (controller → processor) into this DPA by reference, with Customer as data exporter and Tentunit as data importer. The SCCs are completed as follows: Clause 7 (docking clause) is included; Clause 9(a), Option 2 applies with a 30-day notice period (general authorization); the optional language in Clause 11(a) is not included; Clause 17 is governed by the law of Ireland; and Clause 18 designates the courts of Ireland. Annexes I, II, and III of the SCCs are deemed completed by the details in Section 3 and Schedule 3 (Annex I), Schedule 2 (Annex II), and Schedule 1 (Annex III) of this DPA, respectively.
10.2 UK Transfers — UK Addendum
For transfers subject to the UK GDPR, the UK Addendum applies and amends the SCCs as set out therein. Tables 1–3 of the UK Addendum are deemed completed with the corresponding details in this DPA and its Schedules, and for Table 4 either party may end the UK Addendum as set out in its Section 19.
10.3 Supplementary Measures and Transfer Impact Assessments
Tentunit applies supplementary measures to protect transferred Tenant Data, including encryption in transit and at rest, access minimization, and the organizational safeguards in Schedule 2. On Customer’s reasonable request, Tentunit will provide information reasonably available to it to assist Customer in conducting and documenting a transfer impact assessment, including about the legal regimes applicable to Tentunit and its Sub-processors and the safeguards applied.
10.4 Government Access Requests
If Tentunit receives a legally binding request from a public authority for access to or disclosure of Tenant Data, Tentunit will, unless legally prohibited from doing so: (a) promptly notify Customer of the request; (b) review the legality of the request and challenge it where it lacks a valid legal basis or where a challenge is otherwise reasonably available under applicable law; (c) disclose only the minimum data necessary to comply with a valid, binding request; and (d) document each request and its outcome. Where notification is prohibited, Tentunit will use reasonable efforts to obtain a waiver of the prohibition.
11. Audits & Demonstration of Compliance
Customer is entitled to verify that Tentunit keeps its promises, through the audit rights set out in this Section.
11.1 Compliance Information
Tentunit shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and GDPR Article 28, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, in each case as set out in this Section 11.
11.2 Audit Rights
Customer (or an independent auditor bound by confidentiality obligations reasonably acceptable to Tentunit) may audit Tentunit’s compliance with this DPA once per 12-month period, on at least 30 days’ written notice, during normal business hours, without unreasonably disrupting Tentunit’s operations or compromising other customers’ data. If Tentunit obtains third-party security attestations (e.g., SOC 2) in the future, Tentunit may offer such reports in satisfaction of audit requests. Audit findings are Tentunit’s confidential information. Each party bears its own audit costs. Nothing in this Section limits any non-waivable audit right under the SCCs.
12. Return & Deletion of Tenant Data
When the relationship ends, Customer gets a window to take its data out; after that, Tentunit deletes it — except the narrow records the law forces Tentunit to keep.
12.1 Export Window
For 60 days following termination or expiration of the Agreement, Customer may export Tenant Data via the Services’ export tools or by written request to [email protected]. During this window, Tentunit will continue to protect Tenant Data under this DPA but is not obliged to provide the full Services.
12.2 Deletion
After the export window, Tentunit will delete Tenant Data within a further 30 days, including deletion from backups in the ordinary course of backup rotation. Until expired, backup copies remain protected by the measures in Schedule 2.
12.3 Certification of Deletion
Upon Customer’s written request made within a reasonable period after the deletion deadline, Tentunit will certify in writing that Tenant Data has been deleted in accordance with this Section 12, subject to the carve-out in Section 12.4.
12.4 Legal Retention Carve-Out
Tentunit may retain Tenant Data to the extent and for the period required by applicable law (for example, financial, tax, or anti-money-laundering record-keeping). Retained data remains subject to the confidentiality, security, and use-limitation obligations of this DPA, is isolated from further active processing, and is deleted when the legal retention obligation ends.
13. CCPA Service-Provider Terms
For California residents’ data, this section makes the legally required “service provider” commitments: Tentunit does not sell tenants’ data or use it for anything beyond running the service for Customer.
13.1 Service-Provider Restrictions
To the extent Tenant Data includes personal information of California residents, Customer discloses it to Tentunit only for the limited and specified business purposes described in Section 3 and Schedule 3, and Tentunit acts as Customer’s service provider. Tentunit:
- will not sell or share (for cross-context behavioral advertising) Tenant Data;
- will not retain, use, or disclose Tenant Data for any purpose other than performing the Services under the Agreement, or outside the direct business relationship with Customer, except as permitted by the CCPA and its regulations;
- will not retain, use, or disclose Tenant Data for any commercial purpose other than the business purposes specified in the Agreement, except as permitted by the CCPA; and
- will not combine Tenant Data with personal information received from other sources, except as permitted for the CCPA’s enumerated business purposes (for example, security, fraud prevention, and service improvement to the extent permitted).
13.2 Certification and Compliance Notice
Tentunit certifies that it understands the restrictions in Section 13.1 and will comply with them. Tentunit will notify Customer promptly if it makes a determination that it can no longer meet its obligations under the CCPA, in which case Customer may, upon notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Tenant Data. Customer may exercise the monitoring rights contemplated by the CCPA through the audit and information rights in Section 11.
13.3 Consumer Requests and Deidentification
Tentunit will assist Customer in responding to verifiable consumer requests under the CCPA in the manner described in Section 7.1. Where Tentunit creates or receives deidentified data derived from Tenant Data, Tentunit will: (a) take reasonable measures to ensure it cannot be associated with a consumer or household; (b) maintain and use it only in deidentified form and not attempt to reidentify it, except as the CCPA permits to test deidentification; and (c) contractually require recipients to do the same.
14. Liability
Liability under this DPA follows the cap the parties already negotiated in the Business ToS — with the exceptions the law itself requires.
Each party’s liability, taken together in the aggregate, arising out of or relating to this DPA (including, to the maximum extent permitted, the SCCs and UK Addendum) is subject to the limitations and exclusions of liability in the Business ToS, applied in the aggregate across the Agreement and this DPA and not separately for each. Nothing in this Section 14 limits: (a) either party’s liability to data subjects under Data Protection Laws or under Clause 12 of the SCCs; or (b) any liability that cannot be limited or excluded under applicable law.
15. Precedence, Governing Law & General
This section resolves conflicts between documents (this DPA wins on data protection matters) and covers housekeeping.
15.1 Order of Precedence
If this DPA conflicts with the Agreement or any other agreement between the parties, this DPA controls with respect to the processing of Tenant Data and the parties’ data protection obligations. If the SCCs or the UK Addendum conflict with this DPA, the SCCs or the UK Addendum control for the transfers they govern; nothing in this DPA or the Agreement modifies the SCCs or prejudices the fundamental rights of data subjects.
15.2 Governing Law and Severability
Except where the SCCs or UK Addendum mandate otherwise, this DPA is governed by the governing law and venue specified in the Business ToS. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the parties will replace the affected provision with a valid one that most closely reflects its intent.
15.3 Updates and Contact
Tentunit may update this DPA where required to maintain compliance with Data Protection Laws, and will notify Customer of material updates. Questions about this DPA: [email protected] (or [email protected] for legal notices).
Schedule 1 — Sub-processors
This Schedule serves as Annex III to the SCCs (list of sub-processors).
| Sub-processor | Function | Location |
|---|---|---|
| Stripe, Inc. | Payment processing; identity verification (Stripe Identity) | United States |
| Stripe Payments Europe, Ltd. | Payment processing (EEA) | Ireland |
| Stripe Payments UK, Ltd. | Payment processing (UK) | United Kingdom |
Tentunit will update this Schedule with 30 days’ notice before engaging any additional sub-processor (for example, hosting, email delivery, analytics, or AI model providers).
The current, complete list is maintained at the sub-processor page linked in Customer’s account and is updated per Section 9.3.
Schedule 2 — Technical & Organizational Measures
This Schedule serves as Annex II to the SCCs and describes the measures implemented under Section 6.
2.1 Access Control
- Role-based access controls (RBAC) and least-privilege provisioning for all systems processing Tenant Data;
- multi-factor authentication for personnel access to production systems;
- unique, individually attributable accounts; prompt access revocation on role change or departure; periodic access reviews;
- audit logging of administrative access and material actions on Tenant Data, with log review and retention procedures.
2.2 Encryption
- TLS 1.2+ for Tenant Data in transit over public networks;
- industry-standard encryption (e.g., AES-256) for Tenant Data at rest;
- managed key storage with restricted access and key rotation practices.
2.3 Availability & Backups
- Redundant infrastructure across availability zones;
- routine encrypted backups with defined rotation schedules;
- documented disaster recovery and business continuity procedures with periodic testing of restore capability.
2.4 Testing & Secure Development (DevSecOps)
- Firewalls, network segmentation, and vulnerability management with risk-based remediation timelines;
- periodic penetration testing by qualified testers;
- mandatory code review, dependency and static analysis scanning in the build pipeline;
- separation of production and non-production environments; no Tenant Data in non-production environments without equivalent safeguards.
2.5 Incident Management
- Documented, tested incident response plan with defined roles, escalation paths, and severity classification, supporting the 72-hour notification commitment in Section 8;
- post-incident reviews and corrective-action tracking.
2.6 Vendor Management
- Security and privacy due diligence before onboarding Sub-processors;
- contractual flow-down of data protection and security obligations per Section 9.2;
- periodic reassessment of Sub-processors’ compliance posture.
2.7 Personnel Security & Training
- Written confidentiality undertakings for all personnel with access to Tenant Data;
- background checks where lawful and proportionate;
- regular, role-appropriate security and privacy training, including onboarding and refresher training.
2.8 Physical Security
- Data centers operated by leading cloud providers with certified physical access controls (badged entry, surveillance, environmental protections);
- Tentunit office controls restricting physical access to systems and media.
Schedule 3 — Description of Processing (Annex I to the SCCs)
| Item | Description |
|---|---|
| Data exporter | Customer (landlord, property manager, or other subscribing entity) — controller (or processor acting for a property owner) |
| Data importer | Tentunit, Inc. — processor; contact: [email protected] |
| Categories of data subjects | Tenants; rental applicants; guarantors and co-signers; other individuals whose data Customer submits (e.g., emergency contacts, occupants) |
| Categories of personal data | Identity data (name, date of birth, government ID details where collected); contact data (email, phone, postal address); lease data (unit, lease terms, rent amounts, move-in/move-out dates); payment records (transaction history, payment status, bank/card tokens held by the payment processor); communications (messages, notices, support correspondence); uploaded documents (leases, applications, inspection reports, deposit itemizations) |
| Special categories of data | Not intended. The Services are not designed for GDPR Article 9 data; Customer must not submit such data except where strictly necessary and lawful (Section 3.3) |
| Frequency of transfer | Continuous, for the duration of the Services |
| Nature of processing | Hosting, storage, transmission, organization, structuring, retrieval, analysis, and display |
| Purpose of processing | Provision of the Services (rent collection, tenant screening support, lease and document management, tenant communications), support, and compliance with Customer’s documented instructions |
| Duration of processing / retention | Term of Customer’s subscription, plus 60-day post-termination export window and deletion within a further 30 days (Section 12), subject to the legal retention carve-out |
| Transfers to sub-processors | As listed in Schedule 1; same subject matter, nature, and duration as above |
| Competent supervisory authority | Determined in accordance with Clause 13 of the SCCs |