Tentunit Business — Data Processing Addendum (DPA)

Version 1.1 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business

1. Scope, Parties & Roles

This section explains who this DPA binds, what data it covers, and who acts as controller and processor. In short: your tenants’ data is yours; Tentunit only processes it to run the service for you.

1.1 Incorporation and Parties

This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Tentunit Business Terms of Service (the “Agreement”) between Tentunit, Inc., a Delaware corporation (“Tentunit”), and the landlord, property manager, or other entity subscribing to Tentunit Business (“Customer”). Each of Tentunit and Customer is a “party.” This DPA takes effect on the earlier of the Effective Date stated above and the date Customer first submits Tenant Data to the Services, and remains in force for as long as Tentunit processes Tenant Data on Customer’s behalf.

1.2 Covered Processing

This DPA applies whenever Tentunit processes personal data relating to Customer’s tenants, rental applicants, guarantors, and related individuals (“Tenant Data”) on Customer’s behalf in the course of providing Tentunit Business (the “Services”), including rent collection, tenant screening support, lease and document management, and tenant communications.

1.3 Allocation of Roles

For Tenant Data, the parties agree that:

  • Customer is the controller of Tenant Data (or, where Customer processes Tenant Data on behalf of another property owner or principal, Customer acts as a processor instructing Tentunit as its sub-processor);
  • Tentunit is the processor, acting only on Customer’s documented instructions as described in Section 4; and
  • for the purposes of the CCPA, Tentunit acts as Customer’s “service provider” as further described in Section 13.

1.4 Excluded Processing

This DPA does not apply to personal data that Tentunit processes as an independent controller for its own purposes, including: (a) Customer’s own account, registration, billing, and subscription data; (b) data processed for Tentunit’s security, fraud prevention, service integrity, and legal compliance; and (c) payment data processed by Tentunit and its payment processor as independent controllers under the Payments Terms. Such processing is governed by the Tentunit Privacy Policy and, where applicable, the Privacy Policy Business Supplement.

2. Definitions

This section defines the technical terms used throughout the DPA. Terms drawn from the GDPR carry the meanings European regulators and courts give them.

2.1 Defined Terms

  • “Data Protection Laws” means all laws and regulations applicable to the processing of personal data under this DPA, including (i) Regulation (EU) 2016/679 (the “GDPR”); (ii) the UK GDPR and the UK Data Protection Act 2018; (iii) the California Consumer Privacy Act, as amended, and its regulations (the “CCPA”); and (iv) any other applicable US state, federal, or member-state data protection law, in each case as amended or replaced.
  • “personal data,” “controller,” “processor,” “processing” (and “process”), “data subject,” “personal data breach,” “supervisory authority,” and “special categories of personal data” have the meanings given to them in Article 4 GDPR (and, for processing subject to the UK GDPR, the corresponding meanings under the UK GDPR). “Personal data” includes “personal information” as defined in the CCPA, and “data subject” includes “consumer” as defined in the CCPA, in each case to the extent the CCPA applies.
  • “sell,” “share,” “business purpose,” “commercial purpose,” “service provider,” and “deidentified” have the meanings given in the CCPA.
  • “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
  • “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner’s Office.
  • “Sub-processor” means any third party engaged by Tentunit (or by another Sub-processor) to process Tenant Data on Customer’s behalf.
  • “Business ToS” means the Tentunit Business Terms of Service.

2.2 Interpretation

Capitalized terms not defined in this DPA have the meanings given in the Agreement. References to laws include their regulations and successors; “including” means “including without limitation.”

3. Details of Processing

This section summarizes what data Tentunit processes for you, about whom, and for how long. The full Annex I-style description required by the SCCs appears in Schedule 3.

3.1 Subject Matter, Duration, Nature and Purpose

The subject matter of the processing is the provision of the Services described in the Agreement. The duration is the term of Customer’s subscription, plus the post-termination export and deletion window described in Section 12. The nature and purpose of the processing comprise the hosting, storage, transmission, organization, structuring, retrieval, analysis, and display of Tenant Data as necessary to operate the Services, provide technical support, and comply with Customer’s documented instructions. Tentunit does not process Tenant Data for its own advertising purposes.

3.2 Categories of Personal Data and Data Subjects

The categories of personal data (identity, contact, lease, payment-record, communications, and document data) and the categories of data subjects (tenants, rental applicants, guarantors and co-signers, and other individuals whose data Customer submits to the Services) are described in full in Schedule 3, which serves as the Annex I-style description of processing for the SCCs.

3.3 Special Categories

The Services are not designed or intended for special categories of personal data under GDPR Article 9, data relating to criminal convictions and offences under GDPR Article 10 (except lawful screening outputs Customer obtains through properly licensed screening features), or sensitive personal information under the CCPA beyond what is inherent in the categories above. Customer must not submit such data except where strictly necessary and lawful, and bears sole responsibility for any such submission.

4. Processing on Documented Instructions

This section is the core processor promise: Tentunit only does with Tenant Data what you tell it to do, and will warn you if an instruction appears unlawful.

4.1 Documented Instructions

Tentunit shall process Tenant Data only on Customer’s documented instructions, including with regard to transfers of Tenant Data to a third country or an international organisation, unless required to do so by applicable law to which Tentunit is subject; in such a case, Tentunit shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Customer’s documented instructions consist of: (a) the Agreement and this DPA (including the SCCs where applicable); (b) Customer’s configuration and use of the Services and their features; and (c) any further written instructions agreed by the parties. Instructions outside the scope of the Agreement require prior written agreement.

4.2 Infringing Instructions

Tentunit shall inform Customer without undue delay if, in Tentunit’s opinion, an instruction infringes Data Protection Laws. Pending resolution, Tentunit may suspend performance of the affected instruction. Tentunit is not obliged to perform a comprehensive legal review of Customer’s instructions, and Customer remains responsible for the lawfulness of its instructions.

4.3 Customer Responsibilities

Customer warrants that: (a) it has, and will maintain, a lawful basis and all legally required notices and consents for the Tenant Data it submits to the Services; (b) its instructions comply with Data Protection Laws; and (c) where Customer acts as a processor for another controller, it is authorized to appoint Tentunit as a sub-processor on the terms of this DPA.

4.4 Article 28(3) Obligation Mapping

For clarity, the parties record how this DPA satisfies each element of GDPR Article 28(3):

GDPR Art. 28(3) requirement Where addressed
(a) Processing only on documented instructions, incl. transfers Sections 4.1, 10
(b) Confidentiality commitments of authorized persons Section 5
(c) Security measures under Article 32 Section 6; Schedule 2
(d) Conditions for engaging sub-processors (Art. 28(2), (4)) Section 9; Schedule 1
(e) Assistance with data subject rights (Chapter III) Section 7.1
(f) Assistance with Articles 32–36 obligations Sections 7.2–7.5, 8
(g) Return or deletion at end of services Section 12
(h) Information to demonstrate compliance; audits Section 11

5. Confidentiality & Personnel

Plainly: everyone at Tentunit who can touch Tenant Data is bound to keep it confidential and is trained to handle it properly.

5.1 Confidentiality Commitments

Tentunit shall ensure that persons authorized to process Tenant Data have committed themselves to confidentiality under written contractual obligations or are under an appropriate statutory obligation of confidentiality. These obligations survive the end of the person’s engagement.

5.2 Access Limitation and Training

Tentunit shall limit access to Tenant Data to personnel who require such access to perform the Services or Tentunit’s obligations under this DPA, and shall ensure that such personnel receive appropriate and regular data protection and security training as described in Schedule 2.

6. Security of Processing

This section commits Tentunit to concrete safeguards — encryption, access controls, and logging — sized to the risks of the data.

6.1 Technical and Organizational Measures

Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to data subjects, Tentunit shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32, including at minimum:

  • encryption of Tenant Data in transit and at rest;
  • role-based access controls (RBAC) limiting access to personnel with a need to know; and
  • audit logging of access to and material actions on Tenant Data.

The full set of measures is described in Schedule 2.

6.2 Updates to Measures

Tentunit may update the measures in Schedule 2 to reflect technical progress and evolving threats, provided updates do not materially reduce the overall level of protection of Tenant Data.

7. Assistance Obligations

Because tenants exercise their privacy rights against Customer (the controller), this section obliges Tentunit to give Customer the practical help it needs to respond — and to help with security, breach, and impact-assessment duties.

7.1 Data Subject Requests (GDPR Chapter III)

Taking into account the nature of the processing, Tentunit shall assist Customer, by appropriate technical and organizational measures and insofar as this is possible, in fulfilling Customer’s obligation to respond to data subject requests under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection) and analogous rights under other Data Protection Laws, including through the Services’ self-service search, correction, export, and deletion features. If Tentunit receives a request directly from a data subject relating to Tenant Data, Tentunit will not respond substantively (except to direct the individual to Customer) and will forward the request to Customer within 5 business days of receipt.

7.2 Security Assistance (Article 32)

Tentunit shall assist Customer in ensuring compliance with Customer’s own security obligations under GDPR Article 32 by implementing the measures in Section 6 and Schedule 2 and by providing the compliance information described in Section 11.

7.3 Breach Notification Assistance (Articles 33–34)

Tentunit shall assist Customer in complying with Customer’s obligations to notify personal data breaches to supervisory authorities and to communicate them to data subjects, by providing the notifications, information, and cooperation described in Section 8.

7.4 Data Protection Impact Assessments (Article 35)

Tentunit shall provide reasonable assistance to Customer with data protection impact assessments relating to Customer’s use of the Services, to the extent the required information is available to Tentunit and Customer does not otherwise have access to it.

7.5 Prior Consultation (Article 36)

Tentunit shall provide reasonable assistance to Customer with prior consultations with supervisory authorities under GDPR Article 36 arising from Customer’s use of the Services, to the extent the required information is available to Tentunit.

8. Personal Data Breach

If something goes wrong with Tenant Data, this section requires Tentunit to tell Customer quickly and give it the facts needed to meet its own regulatory deadlines.

8.1 Notification

Tentunit shall notify Customer without undue delay, and in any event no later than 72 hours after becoming aware of a personal data breach affecting Tenant Data. Notification will be made to Customer’s account administrator email and, where designated, Customer’s privacy contact.

8.2 Content of Notification

The notification will describe, to the extent then known: (a) the nature of the breach, including where possible the categories and approximate volumes of Tenant Data and data subjects affected; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (d) a contact point for further information ([email protected]). Where all information is not available at once, it may be provided in phases without undue further delay.

8.3 Cooperation and Remediation

Tentunit shall provide timely updates as its investigation progresses, take reasonable steps to contain and remediate the breach, and reasonably cooperate with Customer’s own notification obligations. Tentunit’s notification is not an admission of fault or liability; Customer remains responsible for deciding whether and how to notify supervisory authorities and data subjects in respect of Tenant Data.

9. Sub-processors

Tentunit relies on a short list of vetted vendors (like Stripe for payments). This section sets the rules for adding or changing them and preserves Customer’s right to object.

9.1 General Authorization

Customer provides a general authorization for Tentunit to engage Sub-processors to process Tenant Data, including those listed in Schedule 1 — currently the Stripe entities (payments and identity verification). Any additional sub-processors (for example, hosting, email delivery, analytics, or AI model providers) will be added to Schedule 1 with 30 days’ notice per Section 9.3.

9.2 Flow-Down Obligations

Before permitting any Sub-processor to process Tenant Data, Tentunit shall carry out reasonable due diligence and impose on the Sub-processor, by written contract, data protection obligations materially no less protective than those set out in this DPA. Tentunit remains fully liable to Customer for the performance of each Sub-processor’s obligations.

9.3 Changes and Objection Right

Tentunit will give Customer at least 30 days’ advance notice of any intended addition or replacement of a Sub-processor (via email or an in-product subscription mechanism). Customer may object on reasonable, documented data protection grounds within the notice period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees for those Services. If Customer does not object within the notice period, the change is deemed accepted.

10. International Transfers

Tenant Data protected by EU or UK law may be processed in the United States; this section puts the legally required transfer mechanisms and safeguards in place automatically.

10.1 EU Transfers — SCCs

Where Tenant Data protected by the GDPR is transferred to Tentunit in the United States (or another country not benefiting from an adequacy decision), the parties incorporate the EU SCCs, Module Two (controller → processor) into this DPA by reference, with Customer as data exporter and Tentunit as data importer. The SCCs are completed as follows: Clause 7 (docking clause) is included; Clause 9(a), Option 2 applies with a 30-day notice period (general authorization); the optional language in Clause 11(a) is not included; Clause 17 is governed by the law of Ireland; and Clause 18 designates the courts of Ireland. Annexes I, II, and III of the SCCs are deemed completed by the details in Section 3 and Schedule 3 (Annex I), Schedule 2 (Annex II), and Schedule 1 (Annex III) of this DPA, respectively.

10.2 UK Transfers — UK Addendum

For transfers subject to the UK GDPR, the UK Addendum applies and amends the SCCs as set out therein. Tables 1–3 of the UK Addendum are deemed completed with the corresponding details in this DPA and its Schedules, and for Table 4 either party may end the UK Addendum as set out in its Section 19.

10.3 Supplementary Measures and Transfer Impact Assessments

Tentunit applies supplementary measures to protect transferred Tenant Data, including encryption in transit and at rest, access minimization, and the organizational safeguards in Schedule 2. On Customer’s reasonable request, Tentunit will provide information reasonably available to it to assist Customer in conducting and documenting a transfer impact assessment, including about the legal regimes applicable to Tentunit and its Sub-processors and the safeguards applied.

10.4 Government Access Requests

If Tentunit receives a legally binding request from a public authority for access to or disclosure of Tenant Data, Tentunit will, unless legally prohibited from doing so: (a) promptly notify Customer of the request; (b) review the legality of the request and challenge it where it lacks a valid legal basis or where a challenge is otherwise reasonably available under applicable law; (c) disclose only the minimum data necessary to comply with a valid, binding request; and (d) document each request and its outcome. Where notification is prohibited, Tentunit will use reasonable efforts to obtain a waiver of the prohibition.

11. Audits & Demonstration of Compliance

Customer is entitled to verify that Tentunit keeps its promises, through the audit rights set out in this Section.

11.1 Compliance Information

Tentunit shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and GDPR Article 28, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, in each case as set out in this Section 11.

11.2 Audit Rights

Customer (or an independent auditor bound by confidentiality obligations reasonably acceptable to Tentunit) may audit Tentunit’s compliance with this DPA once per 12-month period, on at least 30 days’ written notice, during normal business hours, without unreasonably disrupting Tentunit’s operations or compromising other customers’ data. If Tentunit obtains third-party security attestations (e.g., SOC 2) in the future, Tentunit may offer such reports in satisfaction of audit requests. Audit findings are Tentunit’s confidential information. Each party bears its own audit costs. Nothing in this Section limits any non-waivable audit right under the SCCs.

12. Return & Deletion of Tenant Data

When the relationship ends, Customer gets a window to take its data out; after that, Tentunit deletes it — except the narrow records the law forces Tentunit to keep.

12.1 Export Window

For 60 days following termination or expiration of the Agreement, Customer may export Tenant Data via the Services’ export tools or by written request to [email protected]. During this window, Tentunit will continue to protect Tenant Data under this DPA but is not obliged to provide the full Services.

12.2 Deletion

After the export window, Tentunit will delete Tenant Data within a further 30 days, including deletion from backups in the ordinary course of backup rotation. Until expired, backup copies remain protected by the measures in Schedule 2.

12.3 Certification of Deletion

Upon Customer’s written request made within a reasonable period after the deletion deadline, Tentunit will certify in writing that Tenant Data has been deleted in accordance with this Section 12, subject to the carve-out in Section 12.4.

Tentunit may retain Tenant Data to the extent and for the period required by applicable law (for example, financial, tax, or anti-money-laundering record-keeping). Retained data remains subject to the confidentiality, security, and use-limitation obligations of this DPA, is isolated from further active processing, and is deleted when the legal retention obligation ends.

13. CCPA Service-Provider Terms

For California residents’ data, this section makes the legally required “service provider” commitments: Tentunit does not sell tenants’ data or use it for anything beyond running the service for Customer.

13.1 Service-Provider Restrictions

To the extent Tenant Data includes personal information of California residents, Customer discloses it to Tentunit only for the limited and specified business purposes described in Section 3 and Schedule 3, and Tentunit acts as Customer’s service provider. Tentunit:

  • will not sell or share (for cross-context behavioral advertising) Tenant Data;
  • will not retain, use, or disclose Tenant Data for any purpose other than performing the Services under the Agreement, or outside the direct business relationship with Customer, except as permitted by the CCPA and its regulations;
  • will not retain, use, or disclose Tenant Data for any commercial purpose other than the business purposes specified in the Agreement, except as permitted by the CCPA; and
  • will not combine Tenant Data with personal information received from other sources, except as permitted for the CCPA’s enumerated business purposes (for example, security, fraud prevention, and service improvement to the extent permitted).

13.2 Certification and Compliance Notice

Tentunit certifies that it understands the restrictions in Section 13.1 and will comply with them. Tentunit will notify Customer promptly if it makes a determination that it can no longer meet its obligations under the CCPA, in which case Customer may, upon notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Tenant Data. Customer may exercise the monitoring rights contemplated by the CCPA through the audit and information rights in Section 11.

13.3 Consumer Requests and Deidentification

Tentunit will assist Customer in responding to verifiable consumer requests under the CCPA in the manner described in Section 7.1. Where Tentunit creates or receives deidentified data derived from Tenant Data, Tentunit will: (a) take reasonable measures to ensure it cannot be associated with a consumer or household; (b) maintain and use it only in deidentified form and not attempt to reidentify it, except as the CCPA permits to test deidentification; and (c) contractually require recipients to do the same.

14. Liability

Liability under this DPA follows the cap the parties already negotiated in the Business ToS — with the exceptions the law itself requires.

Each party’s liability, taken together in the aggregate, arising out of or relating to this DPA (including, to the maximum extent permitted, the SCCs and UK Addendum) is subject to the limitations and exclusions of liability in the Business ToS, applied in the aggregate across the Agreement and this DPA and not separately for each. Nothing in this Section 14 limits: (a) either party’s liability to data subjects under Data Protection Laws or under Clause 12 of the SCCs; or (b) any liability that cannot be limited or excluded under applicable law.

15. Precedence, Governing Law & General

This section resolves conflicts between documents (this DPA wins on data protection matters) and covers housekeeping.

15.1 Order of Precedence

If this DPA conflicts with the Agreement or any other agreement between the parties, this DPA controls with respect to the processing of Tenant Data and the parties’ data protection obligations. If the SCCs or the UK Addendum conflict with this DPA, the SCCs or the UK Addendum control for the transfers they govern; nothing in this DPA or the Agreement modifies the SCCs or prejudices the fundamental rights of data subjects.

15.2 Governing Law and Severability

Except where the SCCs or UK Addendum mandate otherwise, this DPA is governed by the governing law and venue specified in the Business ToS. If any provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the parties will replace the affected provision with a valid one that most closely reflects its intent.

15.3 Updates and Contact

Tentunit may update this DPA where required to maintain compliance with Data Protection Laws, and will notify Customer of material updates. Questions about this DPA: [email protected] (or [email protected] for legal notices).

Schedule 1 — Sub-processors

This Schedule serves as Annex III to the SCCs (list of sub-processors).

Sub-processor Function Location
Stripe, Inc. Payment processing; identity verification (Stripe Identity) United States
Stripe Payments Europe, Ltd. Payment processing (EEA) Ireland
Stripe Payments UK, Ltd. Payment processing (UK) United Kingdom

Tentunit will update this Schedule with 30 days’ notice before engaging any additional sub-processor (for example, hosting, email delivery, analytics, or AI model providers).

The current, complete list is maintained at the sub-processor page linked in Customer’s account and is updated per Section 9.3.

Schedule 2 — Technical & Organizational Measures

This Schedule serves as Annex II to the SCCs and describes the measures implemented under Section 6.

2.1 Access Control

  • Role-based access controls (RBAC) and least-privilege provisioning for all systems processing Tenant Data;
  • multi-factor authentication for personnel access to production systems;
  • unique, individually attributable accounts; prompt access revocation on role change or departure; periodic access reviews;
  • audit logging of administrative access and material actions on Tenant Data, with log review and retention procedures.

2.2 Encryption

  • TLS 1.2+ for Tenant Data in transit over public networks;
  • industry-standard encryption (e.g., AES-256) for Tenant Data at rest;
  • managed key storage with restricted access and key rotation practices.

2.3 Availability & Backups

  • Redundant infrastructure across availability zones;
  • routine encrypted backups with defined rotation schedules;
  • documented disaster recovery and business continuity procedures with periodic testing of restore capability.

2.4 Testing & Secure Development (DevSecOps)

  • Firewalls, network segmentation, and vulnerability management with risk-based remediation timelines;
  • periodic penetration testing by qualified testers;
  • mandatory code review, dependency and static analysis scanning in the build pipeline;
  • separation of production and non-production environments; no Tenant Data in non-production environments without equivalent safeguards.

2.5 Incident Management

  • Documented, tested incident response plan with defined roles, escalation paths, and severity classification, supporting the 72-hour notification commitment in Section 8;
  • post-incident reviews and corrective-action tracking.

2.6 Vendor Management

  • Security and privacy due diligence before onboarding Sub-processors;
  • contractual flow-down of data protection and security obligations per Section 9.2;
  • periodic reassessment of Sub-processors’ compliance posture.

2.7 Personnel Security & Training

  • Written confidentiality undertakings for all personnel with access to Tenant Data;
  • background checks where lawful and proportionate;
  • regular, role-appropriate security and privacy training, including onboarding and refresher training.

2.8 Physical Security

  • Data centers operated by leading cloud providers with certified physical access controls (badged entry, surveillance, environmental protections);
  • Tentunit office controls restricting physical access to systems and media.

Schedule 3 — Description of Processing (Annex I to the SCCs)

Item Description
Data exporter Customer (landlord, property manager, or other subscribing entity) — controller (or processor acting for a property owner)
Data importer Tentunit, Inc. — processor; contact: [email protected]
Categories of data subjects Tenants; rental applicants; guarantors and co-signers; other individuals whose data Customer submits (e.g., emergency contacts, occupants)
Categories of personal data Identity data (name, date of birth, government ID details where collected); contact data (email, phone, postal address); lease data (unit, lease terms, rent amounts, move-in/move-out dates); payment records (transaction history, payment status, bank/card tokens held by the payment processor); communications (messages, notices, support correspondence); uploaded documents (leases, applications, inspection reports, deposit itemizations)
Special categories of data Not intended. The Services are not designed for GDPR Article 9 data; Customer must not submit such data except where strictly necessary and lawful (Section 3.3)
Frequency of transfer Continuous, for the duration of the Services
Nature of processing Hosting, storage, transmission, organization, structuring, retrieval, analysis, and display
Purpose of processing Provision of the Services (rent collection, tenant screening support, lease and document management, tenant communications), support, and compliance with Customer’s documented instructions
Duration of processing / retention Term of Customer’s subscription, plus 60-day post-termination export window and deletion within a further 30 days (Section 12), subject to the legal retention carve-out
Transfers to sub-processors As listed in Schedule 1; same subject matter, nature, and duration as above
Competent supervisory authority Determined in accordance with Clause 13 of the SCCs