Legal
Data Processing Agreement
Last updated: May 26, 2026
Non-binding procurement draft
This public draft is for discussion only and does not create a processing, security, incident, transfer, retention, audit, subprocessor, or notice commitment. Only a fully executed agreement signed by authorized representatives can create contractual obligations.
How to use this document
This is Aptoria's public DPA discussion draft for procurement review. Enterprise procurement teams may request a reviewed version; response timing and final terms depend on the request, workflow scope, and contracting process. To start that review, email legal@aptoria.ai with your company name and the email of the signatory.
1. Definitions
"Aptoria" means Aptoria LLC, a limited-liability company that operates the Aptoria platform and acts as the data processor under this Agreement. "Customer" means the entity that has signed up for an Aptoria account. "Personal Data" has the meaning given in applicable data-protection law (GDPR, CCPA/CPRA, UK GDPR). "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, and erasure. "Subprocessor" means a third party engaged by Aptoria to process Personal Data on Customer's behalf (listed in Schedule A below).
2. Scope and roles in an executed DPA
The expected executed agreement treats Customer as the Controller of Personal Data submitted to the Service and Aptoria as the Processor. Processing instructions, permitted product functionality, and any customer-specific limitations are established only by the signed agreement and enabled service configuration.
3. Customer obligations
A signed agreement is expected to require Customer to confirm an appropriate lawful basis, notices, and consents for Personal Data it provides to Aptoria, including tenant or applicant data uploaded to the Service where applicable.
4. Security measures for review
Aptoria's current security posture includes encryption in transit and at rest, role-based access controls, workspace-scoped database access paths, staff production-access controls, centralized logging, least-privilege service credentials, access reviews, and incident-response procedures. This draft is not an external audit report, security certification, or guarantee that every workflow, provider, or deployment path has identical controls.
5. Subprocessors
Schedule A lists current subprocessors for procurement review. Notice periods, objection rights, and any termination remedy are commitments only in the executed DPA or governing agreement signed by authorized representatives.
6. International data transfers
Aptoria's current public subprocessor list is U.S.-centered, with some providers operating global infrastructure. Transfer mechanisms, SCCs, UK addenda, and customer-specific transfer terms should be reviewed in the signed agreement and relevant provider documentation.
7. Data subject rights
Aptoria provides account-export and account-deletion features intended to help with access, correction, deletion, and portability workflows. Assistance scope, timelines, fees, and exceptions are governed by the executed agreement, product configuration, and applicable law.
8. Personal Data breach notification
Incident-notification timing, content, and escalation contacts are set in the executed agreement. This public draft previews the topic for procurement review but does not create a 72-hour notification commitment unless those terms are signed.
9. Audits
Security questionnaires, audit reports, and any on-site or remote audit rights are handled through procurement and the executed agreement. This public page does not grant an audit right or represent that a third-party audit report is currently available.
10. Return or deletion
Return, deletion, retention, backup, and legal-hold terms are governed by the signed agreement, enabled product features, provider limits, and applicable law. The Service includes export and deletion workflows, but this draft does not create a 30-day production-deletion or 90-day backup-overwrite commitment.
11. Liability
Liability terms are not established by this public draft. They are controlled by the signed customer agreement, Terms of Service, and any executed DPA or order form.
Schedule A — Subprocessors (current)
Supabase, Inc.
Purpose: Application database, authentication, file storage
Data: Account, tenant, lease, payment, message, document
Region: United States (US-East)
Provider DPA / privacy policy ↗
Stripe, Inc.
Purpose: Payment processing (rent collection), owner ACH payouts, subscription billing
Data: Payment instrument tokens, transaction metadata
Region: United States
Provider DPA / privacy policy ↗
Plaid, Inc.
Purpose: Bank account verification + ACH transactions
Data: Bank account details (tokenized), institution metadata
Region: United States
Provider DPA / privacy policy ↗
OpenAI, L.L.C.
Purpose: AI assistant + agent drafting + document classification
Data: Lease text, message content, property metadata (sent to inference API; not used for model training per OpenAI API terms)
Region: United States
Provider DPA / privacy policy ↗
Resend (Resend, Inc.)
Purpose: Transactional email delivery
Data: Email addresses, message subject + body, delivery status
Region: United States
Provider DPA / privacy policy ↗
Twilio Inc.
Purpose: SMS notifications + 2FA codes
Data: Phone numbers, message content, delivery status
Region: United States
Provider DPA / privacy policy ↗
DocuSign, Inc.
Purpose: Optional electronic signature on lease documents (when configured by landlord)
Data: Lease document, signer name + email, signature audit trail
Region: United States
Provider DPA / privacy policy ↗
Vercel Inc.
Purpose: Web application hosting + edge function execution
Data: Request logs (IP, user-agent, route, response code), no payload bodies
Region: Global edge network; US primary
Provider DPA / privacy policy ↗
This template is provided for procurement review. Contractual obligations exist only in the agreement signed by an authorized representative of Aptoria. Subprocessor-change notice, audit, incident, deletion, and assistance commitments exist only where they are included in the executed agreement.