Rental Institute CRM · Legal
Data Processing Addendum
Last updated September 30, 2026 · Version 2026-09-30-draft.2
1. What this addendum is
This Data Processing Addendum (“DPA”) is part of the Terms of Service between Sound Properties Group LLC (“we”) and the Customer. It applies when we process Customer Personal Data to provide Rental Institute CRM. Where this DPA and the Terms conflict about Customer Personal Data, this DPA controls. Words defined in the Terms mean the same here.
2. Definitions
- Customer Personal Data: personal information within Customer Data — for example property owners’ names, addresses, phone numbers, emails, call recordings and messages — that we process on the Customer’s behalf.
- Privacy Laws: U.S. federal and state privacy laws that apply to that processing, including the California Consumer Privacy Act as amended (“CCPA”) and other state comprehensive privacy laws, where they apply.
- Security Incident: a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
3. Roles
The Customer decides why and how Customer Personal Data is processed and is the “business” or “controller.” We process it on the Customer’s behalf as its “service provider” or “processor.” The Customer is responsible for having a lawful basis, giving any notices, and obtaining any consents needed — including consent to be called, texted or recorded — for the data it puts into the Service and how it uses it.
4. How we process it
We process Customer Personal Data only to provide, secure and support the Service under the Terms, on the Customer’s documented instructions (the Terms, this DPA, and the Customer’s settings and actions in the Service), and as the law requires. We will tell the Customer if we believe an instruction breaks Privacy Laws.
The processing covers:
- Subject matter: operating a CRM, dialer and texting platform for real-estate investors.
- People involved: property owners, their relatives or contacts as returned by skip tracing, buyers, agents, sellers and other contacts of the Customer.
- Types of data: contact details, property and ownership details, call and message content and logs, recordings, transcripts, consent and opt-out records, signatures and signing records.
- Duration: the term of the Customer’s subscription, plus the deletion period in section 10.
5. Service provider commitments (CCPA)
Where the CCPA applies, we will not:
- sell or share Customer Personal Data (as those words are defined in the CCPA);
- keep, use or disclose it for any purpose other than the business purposes in the Terms, including any commercial purpose of our own, or outside our direct business relationship with the Customer;
- combine it with personal information we get from anyone else, except as the CCPA permits.
We will comply with the CCPA’s obligations that apply to service providers, give Customer Personal Data the same level of privacy protection the CCPA requires, and tell the Customer if we can no longer meet these obligations. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use. We certify that we understand and will comply with these restrictions.
6. Our people
Only people who need access to provide or support the Service may access Customer Personal Data, and they are bound to keep it confidential.
7. Security measures
We maintain reasonable administrative, technical and physical safeguards, including:
- Encryption of data in transit (HTTPS/TLS), and hosting and database providers that encrypt data at rest.
- Sign-in through a dedicated identity provider; access inside each account limited by role and permission.
- Separation of each customer’s data so one customer cannot read another’s.
- Verification of the signature on every webhook from our telephony provider before acting on it.
- Signature links built from long random tokens, stored only as hashes, and expiring.
- Rate limits on actions that spend money or pull data, and usage metering.
- Error monitoring configured not to capture session recordings or default personal data.
- [Encryption at rest of each customer’s connected third-party credentials.]
- [Backups and a tested restore procedure, with stated recovery targets.]
- [Limiting our own staff’s access to what is needed for support, with an audit trail.]
We may update these measures as long as the overall level of protection does not go down.
8. Subprocessors
The Customer authorizes us to use the service providers listed below. We have written terms with each that protect Customer Personal Data at least as much as this DPA does, as far as their standard terms allow, and we are responsible for their work under this DPA.
We will give the Customer at least [15] days’ notice (by email or in the Service) before adding or replacing a provider that receives Customer Personal Data. If the Customer reasonably objects on data-protection grounds and we cannot resolve the objection, the Customer may end the affected part of the Service and get a refund of prepaid fees for the unused period.
Hosting, storage and accounts
| Provider | What it does | What it receives |
|---|---|---|
| Vercel | Hosts the application and runs its server code. | All data passing through the application; request logs. |
| Neon | Primary database. | Account data and Customer Data stored in the product. |
| Clerk | Sign-in and user identity. | Users' names, email addresses, sign-in activity. |
| Sentry | Error monitoring. | Error reports with a user ID and role; no session replays. |
| Stripe(when billing launches) | Subscription billing and payments. | Billing contact, payment details (held by Stripe, not us), invoices. |
Calls, texts, email and notifications
| Provider | What it does | What it receives |
|---|---|---|
| Twilio | Phone numbers, calls, texts, voicemail, call recordings and the spoken recording notice. | Phone numbers, message content, call audio and recordings (stored by Twilio), call metadata. |
| Resend | Sends email: signature requests, portal and handoff emails, reports. | Recipient names and email addresses, email content. |
| Browser push services (Google, Apple, Mozilla) | Deliver notifications Users switch on. | Encrypted notification payloads. |
AI
| Provider | What it does | What it receives |
|---|---|---|
| OpenAI | Transcribes call recordings and voicemails (Whisper). | Recording audio. |
| Anthropic | Summarizes calls and voicemails; writes deal reads. | Transcripts, lead and property details, notes. |
Maps
| Provider | What it does | What it receives |
|---|---|---|
| Google Maps Platform | Map, satellite and Street View images of a property. | Property addresses. |
| OpenStreetMap tile servers | Background map tiles on comps and deal maps. | The map area viewed and the viewer's IP address. |
Property and contact data sources
| Provider | What it does | What it receives |
|---|---|---|
| DealMachine | Skip tracing, comparable sales, property details and photos. | Property addresses and owner names sent to look up; results returned. |
| RentCast | Rent estimates, comparable sales, listings and listing agents. | Property addresses. |
| U.S. Department of Housing and Urban Development (HUD USER) | Fair Market Rents for Section 8 underwriting. | ZIP code or county. |
| FEMA National Flood Hazard Layer; USGS elevation service | Flood zone and elevation for a property. | Map coordinates. |
| County property appraiser and GIS services (currently Sarasota and Manatee counties, City of Bradenton) | Public property records, sales and code-enforcement data for lists and comps. | Addresses or parcel IDs queried; public records downloaded. |
9. Helping with requests from individuals
If a person asks us directly about their data in the Customer’s records, we will pass the request to the Customer within [10] business days and will not answer it ourselves unless the law requires it. Taking into account what the Service can do, we will give the Customer reasonable help to answer requests to access, correct, delete or copy personal information, mostly through the Service’s own tools.
10. Security incidents
We will notify the Customer without undue delay, and within [72 hours], after confirming a Security Incident affecting its Customer Personal Data. The notice will describe what happened, the data affected so far as known, what we are doing about it, and a contact. We will update it as we learn more and cooperate reasonably with the Customer’s own legal notices. Our notice is not an admission of fault.
11. Return and deletion
The Customer can export its data through the Service while the subscription is active and for [30] days after it ends. After that period we delete Customer Personal Data from the live Service within [30] days, and from backups as they roll off within [backup retention period], unless the law requires us to keep it. Call recordings held by our telephony provider are deleted in the same window. On written request we will confirm deletion.
12. Information and audits
Once a year, or after a Security Incident, the Customer may ask in writing for information reasonably needed to show that we meet this DPA. We will answer written questions and share available summaries of our providers’ security certifications. Any on-site audit needs mutual agreement on scope, timing, cost and confidentiality.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms.
14. Contact
Privacy questions and notices under this DPA: sales@soundpropertiesgroup.com.