Draft — not yet reviewed by an attorney. This text is a working draft for legal review before launch. It is not legal advice and is not yet in effect.

Rental Institute CRM · Legal

Data Processing Addendum

Last updated September 30, 2026 · Version 2026-09-30-draft.2

1. What this addendum is

This Data Processing Addendum (“DPA”) is part of the Terms of Service between Sound Properties Group LLC (“we”) and the Customer. It applies when we process Customer Personal Data to provide Rental Institute CRM. Where this DPA and the Terms conflict about Customer Personal Data, this DPA controls. Words defined in the Terms mean the same here.

2. Definitions

  • Customer Personal Data: personal information within Customer Data — for example property owners’ names, addresses, phone numbers, emails, call recordings and messages — that we process on the Customer’s behalf.
  • Privacy Laws: U.S. federal and state privacy laws that apply to that processing, including the California Consumer Privacy Act as amended (“CCPA”) and other state comprehensive privacy laws, where they apply.
  • Security Incident: a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.

3. Roles

The Customer decides why and how Customer Personal Data is processed and is the “business” or “controller.” We process it on the Customer’s behalf as its “service provider” or “processor.” The Customer is responsible for having a lawful basis, giving any notices, and obtaining any consents needed — including consent to be called, texted or recorded — for the data it puts into the Service and how it uses it.

4. How we process it

We process Customer Personal Data only to provide, secure and support the Service under the Terms, on the Customer’s documented instructions (the Terms, this DPA, and the Customer’s settings and actions in the Service), and as the law requires. We will tell the Customer if we believe an instruction breaks Privacy Laws.

The processing covers:

  • Subject matter: operating a CRM, dialer and texting platform for real-estate investors.
  • People involved: property owners, their relatives or contacts as returned by skip tracing, buyers, agents, sellers and other contacts of the Customer.
  • Types of data: contact details, property and ownership details, call and message content and logs, recordings, transcripts, consent and opt-out records, signatures and signing records.
  • Duration: the term of the Customer’s subscription, plus the deletion period in section 10.

5. Service provider commitments (CCPA)

Where the CCPA applies, we will not:

  • sell or share Customer Personal Data (as those words are defined in the CCPA);
  • keep, use or disclose it for any purpose other than the business purposes in the Terms, including any commercial purpose of our own, or outside our direct business relationship with the Customer;
  • combine it with personal information we get from anyone else, except as the CCPA permits.

We will comply with the CCPA’s obligations that apply to service providers, give Customer Personal Data the same level of privacy protection the CCPA requires, and tell the Customer if we can no longer meet these obligations. The Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use. We certify that we understand and will comply with these restrictions.

6. Our people

Only people who need access to provide or support the Service may access Customer Personal Data, and they are bound to keep it confidential.

7. Security measures

We maintain reasonable administrative, technical and physical safeguards, including:

  • Encryption of data in transit (HTTPS/TLS), and hosting and database providers that encrypt data at rest.
  • Sign-in through a dedicated identity provider; access inside each account limited by role and permission.
  • Separation of each customer’s data so one customer cannot read another’s.
  • Verification of the signature on every webhook from our telephony provider before acting on it.
  • Signature links built from long random tokens, stored only as hashes, and expiring.
  • Rate limits on actions that spend money or pull data, and usage metering.
  • Error monitoring configured not to capture session recordings or default personal data.
  • [Encryption at rest of each customer’s connected third-party credentials.]
  • [Backups and a tested restore procedure, with stated recovery targets.]
  • [Limiting our own staff’s access to what is needed for support, with an audit trail.]

We may update these measures as long as the overall level of protection does not go down.

8. Subprocessors

The Customer authorizes us to use the service providers listed below. We have written terms with each that protect Customer Personal Data at least as much as this DPA does, as far as their standard terms allow, and we are responsible for their work under this DPA.

We will give the Customer at least [15] days’ notice (by email or in the Service) before adding or replacing a provider that receives Customer Personal Data. If the Customer reasonably objects on data-protection grounds and we cannot resolve the objection, the Customer may end the affected part of the Service and get a refund of prepaid fees for the unused period.

Hosting, storage and accounts

ProviderWhat it doesWhat it receives
VercelHosts the application and runs its server code.All data passing through the application; request logs.
NeonPrimary database.Account data and Customer Data stored in the product.
ClerkSign-in and user identity.Users' names, email addresses, sign-in activity.
SentryError monitoring.Error reports with a user ID and role; no session replays.
Stripe(when billing launches)Subscription billing and payments.Billing contact, payment details (held by Stripe, not us), invoices.

Calls, texts, email and notifications

ProviderWhat it doesWhat it receives
TwilioPhone numbers, calls, texts, voicemail, call recordings and the spoken recording notice.Phone numbers, message content, call audio and recordings (stored by Twilio), call metadata.
ResendSends email: signature requests, portal and handoff emails, reports.Recipient names and email addresses, email content.
Browser push services (Google, Apple, Mozilla)Deliver notifications Users switch on.Encrypted notification payloads.

AI

ProviderWhat it doesWhat it receives
OpenAITranscribes call recordings and voicemails (Whisper).Recording audio.
AnthropicSummarizes calls and voicemails; writes deal reads.Transcripts, lead and property details, notes.

Maps

ProviderWhat it doesWhat it receives
Google Maps PlatformMap, satellite and Street View images of a property.Property addresses.
OpenStreetMap tile serversBackground map tiles on comps and deal maps.The map area viewed and the viewer's IP address.

Property and contact data sources

ProviderWhat it doesWhat it receives
DealMachineSkip tracing, comparable sales, property details and photos.Property addresses and owner names sent to look up; results returned.
RentCastRent estimates, comparable sales, listings and listing agents.Property addresses.
U.S. Department of Housing and Urban Development (HUD USER)Fair Market Rents for Section 8 underwriting.ZIP code or county.
FEMA National Flood Hazard Layer; USGS elevation serviceFlood zone and elevation for a property.Map coordinates.
County property appraiser and GIS services (currently Sarasota and Manatee counties, City of Bradenton)Public property records, sales and code-enforcement data for lists and comps.Addresses or parcel IDs queried; public records downloaded.

9. Helping with requests from individuals

If a person asks us directly about their data in the Customer’s records, we will pass the request to the Customer within [10] business days and will not answer it ourselves unless the law requires it. Taking into account what the Service can do, we will give the Customer reasonable help to answer requests to access, correct, delete or copy personal information, mostly through the Service’s own tools.

10. Security incidents

We will notify the Customer without undue delay, and within [72 hours], after confirming a Security Incident affecting its Customer Personal Data. The notice will describe what happened, the data affected so far as known, what we are doing about it, and a contact. We will update it as we learn more and cooperate reasonably with the Customer’s own legal notices. Our notice is not an admission of fault.

11. Return and deletion

The Customer can export its data through the Service while the subscription is active and for [30] days after it ends. After that period we delete Customer Personal Data from the live Service within [30] days, and from backups as they roll off within [backup retention period], unless the law requires us to keep it. Call recordings held by our telephony provider are deleted in the same window. On written request we will confirm deletion.

12. Information and audits

Once a year, or after a Security Incident, the Customer may ask in writing for information reasonably needed to show that we meet this DPA. We will answer written questions and share available summaries of our providers’ security certifications. Any on-site audit needs mutual agreement on scope, timing, cost and confidentiality.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms.

14. Contact

Privacy questions and notices under this DPA: sales@soundpropertiesgroup.com.