Tentunit Business — Third-Party Services Policy
Version 1.0 (Draft — pending legal review) · Effective Date: July 11, 2026 · Applies to: Tentunit Business
This page is informational. It explains, but does not override, the Platform Terms of Service, the Payment & Financial Services Terms, and the Data Processing Addendum, which control.
1. Overview
Tentunit Business is built on a foundation of carefully selected third-party services — payment processors, cloud infrastructure, AI model providers, and communications platforms. This page explains who those providers are, what they do, and where responsibility sits.
1.1 Purpose and Scope
This Third-Party Services Policy describes the categories of third-party services that Tentunit uses to deliver Tentunit Business, and the boundaries of control and responsibility between you, Tentunit, and those providers. It is a plain-language companion to the binding terms: sub-processing commitments live in the Data Processing Addendum, payment terms in the Payment & Financial Services Terms, and availability commitments in the Platform Availability, Support & SLA.
1.2 Vetting and Oversight
Tentunit selects providers through a security, privacy, and reliability review appropriate to the sensitivity of the data and functions involved, and binds providers that process personal data to contractual obligations consistent with the Data Processing Addendum. Providers are reviewed on an ongoing basis and replaced where they no longer meet Tentunit’s standards.
1.3 Authoritative Sub-Processor List
Schedule 1 of the Data Processing Addendum is the authoritative, current list of Tentunit’s sub-processors. This page describes categories and prominent examples; if this page and Schedule 1 ever differ, Schedule 1 controls. Changes to sub-processors are announced with 30 days’ notice as described in the Data Processing Addendum.
2. Stripe Services Scope
All payment functionality in Tentunit Business runs on Stripe. This section explains which Stripe entities are involved and what that means for you.
2.1 The Stripe Entities
Depending on your region, payment services are provided by: Stripe, Inc. (United States); Stripe Payments Europe, Ltd., regulated by the Central Bank of Ireland (EU); and Stripe Payments UK, Ltd., authorized by the Financial Conduct Authority (UK). Rent collection uses Stripe Connect, with landlords holding Stripe Connected Accounts; identity verification before first payout uses Stripe Identity, as described in the KYC & Identity Verification Policy.
2.2 Tentunit’s Role
Tentunit acts as a limited payment collection agent (agent of payee) for landlords, as set out in the Payment & Financial Services Terms. Tentunit is not a bank, money transmitter, or e-money issuer; funds flow is executed by the applicable Stripe entity.
2.3 Stripe Terms Flow Down
By using payment features, you also agree to the Stripe Services Agreement (including the Stripe Connected Account Agreement) applicable to your region. Stripe may decline, hold, or reverse transactions, and may require additional verification, under its own terms and its regulatory obligations. Where Stripe’s requirements affect your account — for example, a payout hold — Tentunit will notify you within 5 business days where legally permitted, as described in the Payment & Financial Services Terms.
2.4 Stripe Outages
Availability of Stripe’s services is outside Tentunit’s control. Downtime or degradation attributable to Stripe is excluded from Tentunit’s uptime calculation and does not accrue service credits, as set out in the exclusions of the Platform Availability, Support & SLA. Tentunit will nonetheless communicate known payment-provider disruptions through its status page.
3. Cloud Provider Scope
Tentunit Business is hosted on established cloud infrastructure rather than on servers Tentunit owns. This section explains what that covers.
3.1 Hosting and Infrastructure
Tentunit’s application, databases, storage, and networking run on third-party cloud infrastructure providers; these categories of providers will be added to Schedule 1 of the DPA with 30 days’ notice before they process Tenant Data. These providers supply the physical data centers, hardware, and foundational services; Tentunit configures, secures, and operates the application layer on top.
3.2 Encryption and Security
Customer Data and Tenant Data are encrypted at rest on cloud provider infrastructure and in transit between your devices and Tentunit’s services. Broader security measures, and Tentunit’s incident-response process, are described in the Data Processing Addendum and the Security & Incident Response Policy.
3.3 Regional Hosting
Tentunit hosts data in regions appropriate to its customer base in the US, EU, and UK, and applies the cross-border transfer safeguards described in the Data Processing Addendum where data moves between regions. Enterprise customers with specific residency requirements should raise them during contracting.
4. AI Provider Scope
The AI Features described in the AI Usage & Content Policy are delivered in part through third-party foundation-model providers. This section explains how your data is handled in that flow.
4.1 Transient Processing of Prompts
When you use an AI Feature, your Inputs (prompts and associated context) may be transmitted to a third-party foundation-model provider for processing and the generation of Outputs. This processing is transient in nature — performed to generate the response — and is subject to contractual restrictions on the provider’s use and retention of the data.
4.2 No Training Without Consent
Tentunit does not use Customer Data or Tenant Data to train AI models without your express consent, and Tentunit’s agreements with AI providers restrict those providers consistently with this commitment. This is a binding commitment stated in the AI Usage & Content Policy and reflected in the Data Processing Addendum.
4.3 Provider List and Changes
AI model providers acting as sub-processors will be added to Schedule 1 of the DPA with 30 days’ notice before they process Tenant Data. Tentunit may change model providers over time; such changes follow the 30-day sub-processor notice process, and material effects on AI Feature behavior are handled as described in the AI Usage & Content Policy.
5. Other Services
Beyond payments, hosting, and AI, Tentunit relies on a small set of additional providers for communications, verification, and product analytics.
5.1 Email and SMS Delivery
Notifications, reminders, and transactional messages are delivered through third-party email and SMS providers. Delivery depends on carriers, spam filtering, and recipient settings, and is not guaranteed, as explained in the Automation & System Actions Policy. Providers handling message content that includes personal data will be added to Schedule 1 of the DPA with 30 days’ notice before they process Tenant Data.
5.2 SheerID Student Verification
Where student-status verification is offered (for example, in connection with Tentunit’s student-housing marketplace features), verification is performed by SheerID. SheerID processes the verification data an individual submits under its own privacy terms presented at the point of verification, in addition to Tentunit’s.
5.3 Analytics
Tentunit uses third-party analytics services to understand product usage, improve reliability, and prioritize development. Analytics processing is described in the Privacy Policy — Business Supplement; applicable providers will be added to Schedule 1 of the DPA with 30 days’ notice before they process Tenant Data.
6. Control & Liability Boundaries
Third-party services make the platform possible, but they also draw lines of responsibility. This section explains where Tentunit’s responsibility ends and someone else’s begins.
6.1 Independent Providers
Third-party providers are independent businesses. They are not Tentunit’s employees, partners, or joint venturers, and Tentunit does not control their internal operations, terms, or availability.
6.2 Responsibility for Sub-Processors
Where a provider processes personal data as Tentunit’s sub-processor, Tentunit remains responsible for that sub-processor’s performance of data protection obligations to the standard set in the Data Processing Addendum. This is the core protection you should rely on: your data protection recourse for sub-processor failures is against Tentunit under the Data Processing Addendum, not against the sub-processor directly.
6.3 Services You Contract Directly
Tentunit is not responsible for services you contract with directly, even where they interact with Tentunit Business — for example, your own bank (including payout receipt, holds, or fees your bank imposes), your accounting software connected by API, your email provider, or advisors you engage. Your Stripe Connected Account relationship is governed by the Stripe agreements described in Section 2.3 in addition to Tentunit’s terms.
6.4 Outages and Service Credits
Responsibility for outages follows the exclusions in the Platform Availability, Support & SLA: downtime caused by third-party providers outside Tentunit’s control (including Stripe and telecom carriers) is excluded from the 99.9% uptime commitment and does not accrue credits. Tentunit’s overall liability remains limited as set out in the Platform Terms of Service.
6.5 Changes and Notice
Tentunit may add, remove, or replace providers. Where the provider is a sub-processor of personal data, changes are announced at least 30 days in advance per the Data Processing Addendum, giving you the objection rights described there. Other provider changes are made without notice where they do not materially affect the Services.
6.6 Questions
Questions about this page may be directed to [email protected]; data protection questions to [email protected].