PropEdge logoPropEdgeGrow
FeaturesPricingROI Calculator
Watch a Live DemoStart Free Trial

PropEdge LLC Data Processing Addendum

Last Updated: September 27, 2026

This Data Processing Addendum (this "DPA") forms part of, and is incorporated into, the PropEdge Terms of Service or other written agreement governing the Client's use of the Services (the "Agreement") between PropEdge LLC ("PropEdge") and the entity that has entered into the Agreement ("Client"). This DPA applies automatically to the Client's use of the Services, without the need for a separate signature. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Definitions

  • "Data Protection Laws" means all laws and regulations applicable to the processing of Client Personal Data under the Agreement, which may include, to the extent applicable: the GDPR; the UK GDPR and UK Data Protection Act 2018; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its regulations (the "CCPA"); other U.S. state comprehensive privacy laws; the Israeli Protection of Privacy Law, 5741-1981, and its regulations; and Canada's Personal Information Protection and Electronic Documents Act.
  • "GDPR" means Regulation (EU) 2016/679.
  • "Client Personal Data" means personal data, including Lead Data, that PropEdge processes on behalf of Client in providing the Services, as further described in Annex I.
  • "Controller," "processor," "data subject," "personal data," "processing," "business," "service provider," "sell," and "share" have the meanings given in the applicable Data Protection Laws, and "controller" includes "business" and "processor" includes "service provider" where applicable.
  • "Security Incident" means a breach of security of the Services leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data in PropEdge's possession or control. Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Client Personal Data, such as pings, port scans, denial-of-service attacks, or unsuccessful log-in attempts.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914, as amended or replaced.
  • "Sub-processor" means any third party engaged by PropEdge to process Client Personal Data.

2. Roles and Scope

2.1 Roles. With respect to Client Personal Data, Client is the controller (or business), and PropEdge is a processor (or service provider). Where Client acts as a processor on behalf of a third-party controller (for example, a brokerage on whose behalf an agent or team uses the Services), Client warrants that its instructions and actions, including the appointment of PropEdge as a sub-processor, have been authorized by the relevant controller, and PropEdge is a sub-processor.

2.2 PropEdge as controller. This DPA does not apply to personal data for which PropEdge is a controller, such as account, billing and contact information of Client's personnel, Usage Data, and personal data processed for PropEdge's own business, security, legal, and compliance purposes, all of which are governed by the PropEdge Privacy Policy.

2.3 Details of processing. The subject matter, duration, nature, and purpose of the processing, and the types of personal data and categories of data subjects, are described in Annex I.

3. Client Obligations

3.1 Instructions. The Agreement, this DPA, and Client's configuration and use of the Services constitute Client's complete and final documented instructions to PropEdge regarding the processing of Client Personal Data. Additional instructions require PropEdge's prior written agreement and may be subject to additional Fees.

3.2 Client warranties. Client represents, warrants, and covenants that:

(a) Client has, and will maintain throughout the term, a lawful basis under Data Protection Laws for the collection and processing of Client Personal Data and for disclosing it to PropEdge for processing under the Agreement;

(b) Client has provided, and will provide, all notices to data subjects required by Data Protection Laws and other applicable laws, including notice that personal data will be processed by service providers, that communications may be conducted using artificial intelligence and automated technologies, and that calls may be recorded;

(c) Client has obtained, and will maintain and document, all consents required by Data Protection Laws and other applicable laws, including consents for automated calls and messages, artificial or AI-generated voice calls, SMS, and call recording, and will promptly notify PropEdge of any withdrawal of consent;

(d) Client's instructions comply with Data Protection Laws and other applicable laws, including fair housing and anti-discrimination laws, and will not cause PropEdge to violate any law;

(e) Client will not provide, or cause PropEdge to process, Prohibited Data (as defined in the PropEdge Privacy Policy) or any personal data not necessary for the Services; and

(f) Client is solely responsible for the accuracy, quality, and legality of Client Personal Data and the means by which it was acquired.

3.3 Client responsibilities. Client is solely responsible for (a) responding to data subject requests and complaints relating to Client Personal Data; (b) determining whether the Services and PropEdge's security measures meet Client's requirements and legal obligations; (c) any data protection impact assessments, risk assessments, or registrations required of a controller; (d) notifying data subjects, regulators, and others of Security Incidents where Client is required to do so; and (e) the security of Client's own systems, accounts, credentials, and integrations, and of Client Personal Data once exported from the Services or transferred to Client's systems or Third-Party Services.

4. PropEdge Obligations

4.1 Processing on instructions. PropEdge will process Client Personal Data only on Client's documented instructions as set out in Section 3.1, unless required to do so by applicable law, in which case PropEdge will, where legally permitted, inform Client of that legal requirement before processing. PropEdge will inform Client if, in its opinion, an instruction infringes Data Protection Laws, provided that PropEdge has no obligation to monitor or assess the lawfulness of Client's instructions or to provide legal advice. PropEdge may decline to follow any instruction it reasonably believes to be unlawful, without liability.

4.2 Confidentiality. PropEdge will ensure that its personnel authorized to process Client Personal Data are subject to appropriate obligations of confidentiality.

4.3 Security. PropEdge will implement and maintain appropriate technical and organizational measures designed to protect Client Personal Data, as described in Annex II. Client acknowledges that the security measures are subject to technical progress and development, and PropEdge may update them from time to time, provided that the updates do not materially decrease the overall security of the Services.

4.4 Permitted uses. In addition to processing on Client's instructions, PropEdge may process Client Personal Data as permitted for a processor or service provider under Data Protection Laws, including to (a) detect, prevent, and respond to security incidents, fraud, and illegal activity; (b) maintain, repair, improve, and develop the Services, provided that PropEdge does not build or modify a profile of a data subject for use in providing services to another client; (c) comply with applicable law and legal process; and (d) create De-identified Data, which is not Client Personal Data.

4.5 CCPA service provider terms. To the extent the CCPA applies, PropEdge will not: (a) sell or share Client Personal Data; (b) retain, use, or disclose Client Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted by the CCPA; (c) retain, use, or disclose Client Personal Data outside the direct business relationship between PropEdge and Client; or (d) combine Client Personal Data with personal information PropEdge receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by the CCPA. PropEdge will comply with applicable obligations under the CCPA, provide the same level of privacy protection as required of businesses by the CCPA, and notify Client if PropEdge determines it can no longer meet its obligations under the CCPA. Client may, upon reasonable written notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Client Personal Data by PropEdge. PropEdge certifies that it understands and will comply with the restrictions in this Section 4.5.

4.6 AI model training. PropEdge will not use Client Personal Data to build, train, or configure AI agents or models for any other client. PropEdge will use AI Sub-processors under terms that, to PropEdge's knowledge, restrict the AI Sub-processor from using Client Personal Data to train its general-purpose models, where such terms are reasonably available.

5. Sub-processors

5.1 General authorization. Client grants PropEdge general authorization to engage Sub-processors to process Client Personal Data, including the Sub-processors listed in Annex III (as updated from time to time). PropEdge will impose on each Sub-processor data protection obligations that are substantially similar to, or no less protective of Client Personal Data in substance than, those in this DPA, to the extent applicable to the nature of the services provided by the Sub-processor. Client acknowledges that certain Sub-processors (such as major cloud, AI, communications, and payment providers) offer only their standard terms, and that such terms satisfy this Section 5.1.

5.2 Changes. PropEdge may add or replace Sub-processors by updating the Sub-processor list at propedge.biz/dpa or by otherwise notifying Client (which may be by email or in-app notice). Client may object to a new Sub-processor on reasonable, documented data protection grounds by notifying PropEdge in writing within ten (10) days after notice. If Client does not object within that period, Client is deemed to have authorized the new Sub-processor. If Client objects, the parties will discuss the objection in good faith. If they cannot resolve it within thirty (30) days, Client's sole and exclusive remedy is to terminate the affected Services upon written notice, and PropEdge will refund any prepaid Fees for the terminated Services covering the period after termination. PropEdge may engage a Sub-processor without prior notice where urgently required to maintain the security, availability, or integrity of the Services, and will then provide notice as soon as reasonably practicable.

5.3 Client-directed services. Third-Party Services that Client selects, connects, or instructs PropEdge to use (such as Client's CRM, calendar, listing portals, lead sources, telephony or messaging accounts, and any AI provider or integration Client specifies) are not Sub-processors of PropEdge. Client is solely responsible for its relationship with such providers, and PropEdge is not responsible for their processing of personal data.

6. Data Subject Requests

PropEdge will, taking into account the nature of the processing, provide Client with reasonable assistance, through the functionality of the Services or otherwise, to enable Client to respond to requests from data subjects to exercise their rights under Data Protection Laws. If PropEdge receives a request directly from a data subject that identifies Client, PropEdge will, where legally permitted, promptly forward the request to Client or direct the data subject to Client, and will not respond to the request except to confirm that it has been forwarded, unless instructed by Client or required by law. Client will reimburse PropEdge for its reasonable costs of assistance beyond making available the functionality of the Services.

7. Security Incidents

7.1 Notification. PropEdge will notify Client without undue delay after becoming aware of and confirming a Security Incident. PropEdge will provide available information reasonably requested by Client to meet Client's obligations under Data Protection Laws, and may provide such information in phases as it becomes available. PropEdge will take reasonable steps designed to contain and mitigate the effects of the Security Incident.

7.2 No admission. PropEdge's notification of or response to a Security Incident is not an acknowledgement by PropEdge of any fault or liability.

7.3 Third-party notifications. Except where required by law, PropEdge will not notify regulators or data subjects of a Security Incident affecting Client Personal Data without Client's consent. Client is responsible for any notifications to regulators, data subjects, and others that Client is required to make, and, except to the extent the Security Incident was caused by PropEdge's breach of this DPA, for the costs of such notifications.

8. Assistance and Audits

8.1 Assistance. Taking into account the nature of the processing and the information available to PropEdge, PropEdge will provide reasonable assistance to Client, at Client's expense, with any data protection impact assessments and prior consultations with supervisory authorities that Client is required to carry out under Data Protection Laws, solely in relation to PropEdge's processing of Client Personal Data.

8.2 Information. Upon Client's written request, not more than once in any twelve (12) month period, PropEdge will make available to Client information reasonably necessary to demonstrate PropEdge's compliance with this DPA, which may include responses to a reasonable security questionnaire, summaries of PropEdge's security measures, and any third-party certifications or reports PropEdge may have. All such information is PropEdge's Confidential Information.

8.3 Audits. If the information provided under Section 8.2 is insufficient to demonstrate compliance, or if an audit is required by a supervisory authority or Data Protection Laws, Client may, at its sole expense and not more than once in any twelve (12) month period (except as required by a supervisory authority or following a Security Incident), conduct an audit of PropEdge's compliance with this DPA, subject to: (a) at least thirty (30) days' prior written notice and a mutually agreed scope, timing, and duration; (b) the audit being conducted during normal business hours, remotely where reasonably possible, and without unreasonably interfering with PropEdge's operations; (c) the auditor being an independent professional that is not a competitor of PropEdge and is bound by confidentiality obligations acceptable to PropEdge; (d) no access being granted to data of other clients, PropEdge's Sub-processors' facilities, or information subject to legal privilege or confidentiality obligations to third parties; and (e) Client reimbursing PropEdge for its time spent at PropEdge's then-current professional services rates. Client will provide PropEdge with a copy of any audit report, which will be PropEdge's Confidential Information.

9. International Data Transfers

9.1 Locations. Client authorizes PropEdge and its Sub-processors to transfer and process Client Personal Data in the United States, Israel, the European Union, and any other country in which PropEdge or its Sub-processors operate, subject to this Section 9.

9.2 Transfer mechanisms. To the extent Client Personal Data subject to the GDPR, UK GDPR, or Swiss law is transferred to PropEdge in a country that has not received an adequacy decision (and is not covered by another valid transfer mechanism), the parties agree that the SCCs are incorporated into this DPA by reference and apply as follows: (a) Module Two (controller to processor) applies where Client is a controller, and Module Three (processor to processor) applies where Client is a processor; (b) Clause 7 (docking clause) does not apply; (c) under Clause 9, Option 2 (general written authorization) applies, with the notice period described in Section 5.2; (d) the optional language in Clause 11 does not apply; (e) under Clause 13, the competent supervisory authority is the one determined in accordance with that Clause; (f) under Clauses 17 and 18, the SCCs are governed by the law of, and disputes will be resolved by the courts of, Ireland; and (g) Annexes I, II, and III of the SCCs are completed by Annexes I, II, and III of this DPA. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner (Version B1.0) applies, with Tables 1 through 3 completed by the information in this DPA and its Annexes, and neither party may terminate the Addendum under Section 19 of the Addendum. For transfers subject to Swiss law, the SCCs apply with the necessary adaptations, with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority. Where Israel or another country has an adequacy decision, the parties may rely on that decision instead of the SCCs.

9.3 Precedence. In the event of a conflict between this DPA and the SCCs, the SCCs prevail to the extent of the conflict and solely with respect to the transfers they govern. Nothing in this DPA is intended to limit the rights of data subjects under the SCCs to the extent such rights cannot be limited by law.

10. Return and Deletion

Following termination or expiration of the Services, and subject to Section 7.5 of the Agreement, PropEdge will delete Client Personal Data within ninety (90) days, unless Client instructs earlier deletion in writing or PropEdge is required or permitted by applicable law to retain it. Client Personal Data residing in backups will be deleted in accordance with PropEdge's standard backup rotation. PropEdge may retain Client Personal Data to the extent required or permitted by law, or where it is subject to a legal hold or reasonably necessary to establish, exercise, or defend legal claims, in each case subject to the confidentiality and security obligations of this DPA. Upon written request, PropEdge will confirm deletion in writing. Client is responsible for exporting any Client Personal Data it wishes to retain before termination.

11. Limitation of Liability

11.1 Cap applies. Each party's liability, taken together in the aggregate, arising out of or relating to this DPA (including the SCCs, to the maximum extent permitted by law), whether in contract, tort, or under any other theory of liability, is subject to the exclusions and limitations of liability in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.

11.2 No liability for Client's obligations. To the maximum extent permitted by law, PropEdge is not liable for any claim, fine, penalty, or damage to the extent arising from (a) Client's breach of this DPA, the Agreement, or Data Protection Laws; (b) Client's instructions, configurations, scripts, or criteria; (c) Client's failure to provide notices or obtain consents; or (d) any processing by Client or by Third-Party Services selected by Client.

11.3 Indemnity. Client will defend, indemnify, and hold harmless the PropEdge Parties from and against all Claims and related losses, damages, fines, penalties, costs, and expenses (including reasonable attorneys' fees) arising out of or relating to Client's breach of Section 3 of this DPA or of Data Protection Laws, in accordance with the procedure in Section 15.2 of the Agreement.

11.4 Data subjects. Nothing in this Section 11 limits any rights of data subjects that cannot be limited by law. To the extent PropEdge pays compensation to a data subject or regulator that is attributable to Client's acts or omissions, Client will reimburse PropEdge for that amount.

12. General

12.1 Term. This DPA remains in effect for as long as PropEdge processes Client Personal Data on behalf of Client.

12.2 Conflict. In the event of a conflict between the Agreement and this DPA regarding the processing of Client Personal Data, this DPA prevails, except as provided in Section 11 and except that Section 9.3 governs conflicts with the SCCs.

12.3 Changes. PropEdge may update this DPA from time to time (a) as required by changes in Data Protection Laws or guidance, or to reflect updated SCCs; (b) to reflect changes in the Services or Sub-processors; or (c) in any manner that does not materially diminish the protection of Client Personal Data. Updates take effect upon posting or notice, as described in the Agreement.

12.4 Governing law. Except as required by the SCCs or Data Protection Laws, this DPA is governed by the law and dispute resolution provisions of the Agreement.

Annex I: Details of Processing

Parties. Data exporter: Client (as identified in the Agreement or Order Form), acting as controller (or processor on behalf of a controller). Data importer: PropEdge LLC, acting as processor (or sub-processor). Contact: daniel@propedge.biz.

Categories of data subjects.

  • Leads, including prospective buyers, sellers, renters, landlords, and investors who inquire with or are contacted on behalf of Client;
  • Client's personnel, agents, and Authorized Users whose data is included in calendars, routing rules, and communications; and
  • Other individuals whose personal data is included in Client Materials or communications (for example, individuals appearing in property photos).

Categories of personal data.

  • Contact data: name, phone number, email address, messaging handles;
  • Inquiry and qualification data: buying, selling or renting interest, property type and listing of interest, budget and price range, timeline, preferences, financing or pre-approval status as described by the Lead;
  • Location data: property addresses, current city or area, areas of interest, and precise location if provided;
  • Appointment and calendar data: availability, scheduled meetings and showings, assigned agent;
  • Communications data: SMS, chat, WhatsApp, and email content; voice recordings; transcripts; summaries; AI-generated notes, scores, and classifications; and
  • Technical data: phone number metadata, timestamps, call duration, delivery status, lead source, IP address, and device information for web chat.

Sensitive data. None intended. Client must not submit Prohibited Data, including special categories of personal data under the GDPR. Voice recordings are not processed to uniquely identify individuals.

Frequency of transfer. Continuous for the duration of the Services.

Nature and purpose of processing. Collection, recording, organization, storage, retrieval, transcription, analysis, generation of AI responses, communication with data subjects by voice, SMS, messaging, chat, and email, qualification and scoring according to Client's criteria, appointment scheduling on Client's calendars, transfer to Client and Client's connected systems, quality assurance, support, and deletion, in each case to provide the Services to Client under the Agreement.

Duration and retention. For the term of the Agreement, and thereafter until deletion under Section 10. Call recordings and full transcripts are retained for up to twelve (12) months from creation unless otherwise agreed in writing.

Sub-processor transfers. As described in Annex III, for the same nature, purpose, and duration as above, to the extent necessary for each Sub-processor's function.

Annex II: Technical and Organizational Security Measures

PropEdge maintains the following measures, as appropriate to the nature of the Services and the risks involved:

  1. Access control: access to Client Personal Data is limited to personnel and contractors who need it to provide the Services; unique accounts; multi-factor authentication where supported by the relevant systems; prompt removal of access upon role change or departure.
  2. Confidentiality: personnel and contractors with access to Client Personal Data are bound by written confidentiality obligations and receive guidance on data protection.
  3. Encryption: use of hosting and Service Providers that encrypt data in transit (TLS) and at rest, as supported by those providers.
  4. Vendor management: use of reputable Sub-processors with appropriate security practices; review of Sub-processor terms and security documentation before engagement.
  5. Credential and integration security: storage of API keys and OAuth tokens in the credential stores of PropEdge's platforms; use of least-privilege scopes for integrations where available.
  6. Data minimization: configuration of AI agents to collect only information needed for qualification and scheduling; prohibition on collection of Prohibited Data.
  7. Environment separation: separation of each Client's agents, workflows, and data within PropEdge's systems.
  8. Availability and recovery: reliance on the redundancy and backup capabilities of PropEdge's hosting and Service Providers.
  9. Incident response: procedures to investigate, contain, and notify Clients of Security Incidents.
  10. Deletion: procedures for deleting Client Personal Data at the end of the retention period or upon termination.

Annex III: Sub-processors

Sub-processorServiceLocation of processing
n8n GmbHWorkflow automation and data processingEuropean Union (Germany)
Lovable [CONFIRM LEGAL ENTITY NAME]Application development, hosting and database[CONFIRM LOCATION]
monday.com Ltd.CRM and data managementUnited States / European Union / Israel
Google LLC (Google Workspace)Email, calendar, productivity and storageUnited States and other locations
Microsoft Corporation (Microsoft 365 / Excel)Spreadsheets and productivityUnited States and other locations
OpenAI, L.L.C. / OpenAI Ireland Ltd.AI language modelsUnited States
Anthropic, PBCAI language modelsUnited States
Twilio Inc. [CONFIRM IF USED]Telephony, SMS and messagingUnited States
[VOICE AI PROVIDER]Voice agent, speech-to-text and text-to-speech[LOCATION]
Meta Platforms / WhatsApp (where WhatsApp is used)MessagingUnited States and other locations
Stripe, Inc.Payment processing (Client billing only)United States

PropEdge may update this list in accordance with Section 5.2.

Annex IV: Sample Notice and Consent Language for Client Forms

The following sample language is provided for convenience only, is not legal advice, and does not guarantee compliance with any law. Client is solely responsible for reviewing it with its own counsel, adapting it to its business and jurisdictions, and presenting it clearly and conspicuously, next to the submit button, before a Lead submits an inquiry. Consent should be a separate, unchecked checkbox and should not be a condition of any purchase.

Sample consent checkbox (web forms):

☐ By checking this box and submitting this form, I agree that [BROKERAGE NAME] and its service providers may contact me at the phone number and email address I provided, including by calls, text messages and WhatsApp messages using automated technology and artificial or AI-generated voices, about my real estate inquiry and related real estate services. I understand that calls may be recorded, and that I may be communicating with an AI assistant. Consent is not a condition of any purchase. Message frequency varies. Message and data rates may apply. Reply STOP to opt out and HELP for help. See our [Privacy Policy] and [Terms].

Sample opening disclosure (voice calls):

"Hi, this is [AGENT NAME], a virtual assistant for [BROKERAGE NAME]. This call may be recorded. How can I help you today?"

Sample first message (SMS):

"Hi [First Name], this is [AGENT NAME], the virtual assistant for [BROKERAGE NAME], following up on your inquiry about [PROPERTY]. Reply STOP to opt out."

↑ Back to top
PropEdge logoPropEdge

The growth platform for real estate teams that never stop supporting their clients.

Product
  • Features
  • Demo
  • Pricing
  • FAQ
Legal
  • Privacy
  • Terms
  • DPA
  • Cookies
© 2026 PropEdge LLC. All rights reserved.
Made for agents who close.
Edit with