Tentunit Privacy Policy — Business Supplement

Version 1.1 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business customers (landlords and property managers) and their tenants

1. Why This Supplement Exists

The general Tentunit Privacy Policy describes the consumer marketplace, where Tentunit decides how personal information is used. Tentunit Business works differently, and this Supplement explains how.

1.1 Purpose and Relationship to the Privacy Policy

The Tentunit Privacy Policy describes how Tentunit, Inc. handles personal information on the consumer marketplace, where Tentunit determines the purposes and means of processing (acting as the “controller”). When a landlord or property management company uses Tentunit Business to manage tenancies, the business customer controls the tenant data and Tentunit processes it on the customer’s instructions under a binding Data Processing Addendum (the “DPA”). This Supplement explains that split, who is responsible for what, and how individuals can exercise their rights.

1.2 Precedence

Where this Supplement conflicts with the general Privacy Policy in relation to Tentunit Business accounts, this Supplement controls. Where this Supplement conflicts with the DPA in relation to the processing of Tenant Data, the DPA controls.

2. The Controller / Processor Split — With Worked Examples

The same platform holds three different kinds of data, with three different legal owners. This section gives concrete examples so you can tell them apart.

2.1 Tenant Data — Customer Is the Controller; Tentunit Is the Processor

“Tenant Data” is personal information about tenants, applicants, and guarantors that a Business customer enters into or collects through the software. The Business customer is the controller (and decides why and how the data is used); Tentunit acts as a processor (or CCPA “service provider”) and processes it only per the customer’s instructions and the DPA. Worked examples of Tenant Data:

  • Maintenance records: a photo of a leaking radiator a tenant uploads with a repair request, the repair ticket history, and the contractor notes attached to it;
  • Chat logs: in-app messages between a tenant and the property manager about a late payment plan or a move-out inspection;
  • Guarantor information: the name, address, income declaration, and signed guarantee document of a parent co-signing a student tenant’s lease;
  • Lease and applicant files: rental applications, signed leases, government ID copies collected by the landlord, deposit itemizations, inspection reports;
  • Payment history within the ledger: rent charges, payment statuses, arrears notes, and late-fee records that the landlord maintains in the platform.

2.2 Business Account Data — Tentunit Is the Controller

“Business Account Data” is information about the Business customer itself and its authorized users, which Tentunit processes for its own purposes as controller under the general Privacy Policy. Worked examples:

  • the account holder’s identity and login credentials, and the names and emails of staff seats;
  • KYB/business-verification records submitted during onboarding;
  • billing and subscription data (plan, invoices, payment method reference);
  • support tickets and correspondence between the customer and Tentunit;
  • product usage analytics and security logs described in Section 6.

2.3 Payment Data — Tentunit and Stripe as Independent Controllers

Tentunit and Stripe act as independent controllers for payment data required to execute payment transactions — for example, the bank account or card details a tenant supplies to pay rent, and the transaction records Stripe must keep under financial regulation. This processing is described in the Payments Terms and in Stripe’s own privacy policy. The rent ledger entries the landlord sees remain Tenant Data under Section 2.1.

2.4 Edge Cases

Some records touch more than one category: for example, a chargeback dispute involves Tenant Data (the ledger), payment data (the Stripe transaction), and Business Account Data (the customer’s support ticket). In such cases, each element is governed by the rules for its category.

3. Tenant Rights — How Requests Are Routed

If your landlord manages your tenancy through Tentunit Business, your landlord — not Tentunit — is legally responsible for answering your privacy requests about Tenant Data. Here is exactly what happens when you contact us.

3.1 Who Answers What

Your landlord is responsible for the lawful basis of processing your Tenant Data and for responding to your requests to access, correct, delete, restrict, or port that data, or to object to its processing. Tentunit answers requests concerning data it controls (for example, if you also hold a Tentunit consumer marketplace account, or for payment data Tentunit controls under Section 2.3).

3.2 Step-by-Step Routing Flow

  1. You submit a request — to your landlord directly, or to [email protected] if you are unsure who is responsible.
  2. Tentunit triages the request: if it concerns Tenant Data, Tentunit does not respond substantively but identifies the responsible Business customer.
  3. Tentunit forwards the request to that customer within the timeframe committed in the DPA and tells you it has done so, with the landlord’s contact point where available.
  4. The landlord responds to you within the deadline that applies to it under law (e.g., one month under the GDPR, extendable as the law allows).
  5. Tentunit assists the landlord behind the scenes — via the platform’s search, correction, export, and deletion tools — as required by the DPA.
  6. If the request concerns data Tentunit controls, Tentunit handles it directly under the general Privacy Policy and confirms the outcome to you.

You can always contact [email protected] and we will route your request; contacting us first never invalidates your request.

4. Geographic Scope & International Transfers

Tentunit Business is offered on both sides of the Atlantic, and the protections that apply depend on where you are.

4.1 Where the Service Operates

Tentunit Business is offered in the United States and the European Union/UK.

4.2 United States (including CCPA)

Tentunit acts as a “service provider” under the California Consumer Privacy Act (CCPA/CPRA) with respect to Tenant Data, and does not sell or share Tenant Data for cross-context behavioral advertising. California residents’ requests concerning Tenant Data are routed to the responsible Business customer as described in Section 3.

4.3 EU/UK and Transfer Mechanisms

For processing subject to the GDPR or UK GDPR, the DPA governs Tenant Data and incorporates the European Commission’s Standard Contractual Clauses (Module 2: controller → processor) for transfers to the United States, supplemented by the UK Addendum for UK-governed transfers. Tentunit applies supplementary safeguards (encryption in transit and at rest, access minimization) as described in the DPA.

4.4 EU and UK Representatives

Tentunit has no EU or UK establishment. Before actively offering the Service to EU/UK customers, Tentunit will appoint an EU representative under GDPR Article 27 and a UK representative as required, and will publish their details here and in the general Privacy Policy.

5. Sub-processors

Tentunit does not build everything itself; it uses a short, vetted list of vendors — and Business customers are told before that list changes.

5.1 Current Sub-processors

Tentunit uses vetted sub-processors to deliver the service, currently: Stripe, Inc. (payments and identity verification, United States), Stripe Payments Europe, Ltd. (EEA), and Stripe Payments UK, Ltd. (UK). Tentunit will update this list with 30 days’ notice before engaging any additional sub-processor (for example, hosting, email delivery, analytics, or AI model providers). The current, authoritative list is maintained in Schedule 1 of the DPA and at the sub-processor page linked in the customer’s account.

5.2 Change Notice and Objection

Business customers are notified of sub-processor additions or replacements at least 30 days in advance and may object on reasonable data protection grounds as described in the DPA. Each sub-processor is bound by written terms materially no less protective than the DPA.

6. Business Account Data: Analytics, Telemetry & Marketing

This section explains what Tentunit collects about how Business customers use the product, why, on what legal basis, and how to opt out. It applies to Business Account Data, not Tenant Data.

6.1 What Telemetry We Collect

For Business customer users (landlord and property-manager accounts), Tentunit collects: feature-usage events (which screens and tools are used, and how often); performance and diagnostic data (error reports, load times, device/browser type); security logs (login events, IP addresses, authentication outcomes); and support interaction records. Telemetry is keyed to the business user’s account, and is pseudonymized where feasible before analysis. Tentunit does not use Tenant Data for its own analytics beyond what the DPA permits for providing and securing the service.

We use this telemetry to: operate, secure, and troubleshoot the service (legal basis: performance of our contract with the Business customer, and legitimate interests in security and fraud prevention); understand aggregate feature adoption to improve the product (legal basis: legitimate interests, balanced against users’ rights via pseudonymization and aggregation); and meet legal and accounting obligations (legal basis: legal obligation).

6.3 Opt-Outs

Business users may object to analytics processing based on legitimate interests by emailing [email protected] or using in-product analytics settings where available. Security logging and telemetry strictly necessary to deliver the contracted service cannot be disabled while the account remains active.

6.4 Marketing to Business Contacts

Tentunit may send product news, feature announcements, and commercial offers to Business customer contacts on the legal basis of legitimate interests in business-to-business marketing (or consent where local law requires it, for example under EU/UK e-privacy rules for electronic marketing). Every marketing message includes a working unsubscribe link, and opt-outs are honored promptly and do not affect transactional or service messages (such as billing notices, security alerts, or breach notifications). Tentunit does not use Tenant Data for marketing.

6.5 Cookies

Cookies and similar technologies used on Tentunit websites and in the product — including any analytics cookies — are described in the Tentunit Cookie Notice, which explains categories, durations, and consent choices. Where consent is required (EU/UK), non-essential cookies are set only after consent.

7. Security and Breach Notification

Tenant Data is protected with strong technical controls, and Business customers hear about incidents fast enough to meet their own legal deadlines.

7.1 Security Measures

Tenant Data is encrypted in transit and at rest, with role-based access controls and audit logging. The full set of technical and organizational measures — covering access control, encryption, backups, testing, incident response, vendor management, personnel training, and physical security — is set out in Schedule 2 of the DPA.

7.2 Breach Notification

If a personal data breach affects Tenant Data, Tentunit notifies the affected Business customer without undue delay and no later than 72 hours after becoming aware, with the information the customer needs for its own regulatory notifications (nature of the breach, categories and approximate volumes affected, likely consequences, and remediation measures), supplemented in phases as the investigation progresses. The Business customer remains responsible for any notifications it owes to supervisory authorities and tenants.

8. Retention and Deletion

Data lives only as long as the business relationship requires — plus a window to take it with you.

8.1 During the Subscription

Tenant Data is retained for as long as the Business customer’s subscription is active and per its instructions; customers can delete individual records at any time through the product.

8.2 After Cancellation

After cancellation, Tenant Data is available for export for 60 calendar days, then deleted within a further 30 days, except records Tentunit must retain by law (e.g., financial transaction records retained under tax and anti-money-laundering rules). Legally retained records are isolated, remain protected under the DPA’s security terms, and are deleted when the retention obligation ends. Deletion certification is available on written request as described in the DPA.

8.3 Business Account Data

Business Account Data is retained per the general Privacy Policy (typically for the life of the account plus applicable limitation and record-keeping periods).

9. What Business Customers Must Do

Because the Business customer is the controller of Tenant Data, several compliance duties sit with the customer, not with Tentunit. The most important ones are set out here.

9.1 Lawful Basis, Notices, and Rights Handling

Business customers must: (a) have a lawful basis (and, where needed, provide notices or obtain consents) for the Tenant Data they process through Tentunit; (b) respond to tenant privacy rights requests within the legally required deadlines, using Tentunit’s assistance under the DPA; and (c) keep Tenant Data accurate and limited to what the tenancy relationship requires.

9.2 Screening and Background Checks

Tentunit does not currently offer screening or background-check features; if you collect such data outside the platform, do not upload consumer reports into the Service. Customers who conduct tenant screening outside the platform must comply with all applicable law, in particular:

  • FCRA permissible purpose: obtain consumer reports only with a permissible purpose (tenant screening), provide required disclosures, and obtain the applicant’s authorization where required;
  • Adverse action: where a customer declines an applicant, requires a higher deposit, or imposes other adverse terms based in whole or in part on a consumer report, the customer must follow the FCRA adverse-action process (pre-adverse and adverse action notices, the reporting agency’s contact details, and the applicant’s dispute rights);
  • State and local limits: honor state and local restrictions on the use of criminal history, eviction records, and credit information in housing decisions (including “fair chance” and lookback-period rules), which may be stricter than federal law;
  • Fair housing / disparate impact: apply screening criteria consistently and be aware that facially neutral criteria (such as blanket criminal-record bans) can create unlawful disparate impact under the Fair Housing Act and equivalent state laws. Customers should document individualized assessments where appropriate.

9.3 Prohibited Data — Special Categories and Children

The service is not designed for special categories of personal data (GDPR Article 9 — e.g., health records, biometric identifiers, data revealing race, religion, or sexual orientation) or comparable “sensitive data” beyond what is inherent in tenancy records; customers must not upload such data without Tentunit’s prior written agreement. The service is not directed to children, and customers must not create tenant profiles designed to collect personal data directly from children; where a household includes minors, customers should record only the minimum occupancy information the tenancy lawfully requires.

10. Changes to This Supplement

We may need to update this Supplement, but material changes will not take effect silently.

Tentunit may update this Supplement from time to time, for example to reflect new features, legal developments, or the designation of the EU/UK representatives. For material changes, Tentunit will give Business customers at least 30 days’ advance notice (by email or in-product notice) before the change takes effect; continued use of Tentunit Business after the effective date constitutes acceptance. Non-material changes (such as clarifications or contact-detail updates) may take effect on posting, with the version number and effective date updated above.

11. Contact and Complaint Escalation

Questions and complaints follow a simple ladder: support first, then the privacy team, then — for EU/UK individuals — your data protection regulator.

11.1 Layered Contact Points

  1. Support (first line): general account or product questions — [email protected].
  2. Privacy team: privacy questions, rights requests, and requests to be routed to a landlord — [email protected].
  3. Legal notices: formal legal correspondence — [email protected].

11.2 Escalation and Supervisory Authorities

If you are not satisfied with the response, you may escalate in writing to [email protected] marked “Escalation,” and Tentunit will have the matter reviewed by staff responsible for privacy compliance. Individuals in the EU or UK also have the right, at any time, to lodge a complaint with a supervisory authority — in the EU, the data protection authority of your habitual residence, place of work, or the place of the alleged infringement; in the UK, the Information Commissioner’s Office (ICO). For Tenant Data, complaints about the landlord’s processing decisions should be directed to the landlord as controller, but nothing prevents you from contacting a supervisory authority directly.