Skip to content
Legal

Data Processing Agreement

How Dwelon AI processes personal data as a data processor under GDPR Article 28 and CCPA requirements.

GDPR Art. 28CCPASCCs included
Version 1.0. Last updated: 1 January 2025.
Agreement parties
Data Controller

Customer (you)

Data Processor

Dwelon AI, Inc., Delaware, USA

DPO Contact

privacy@dwelon.com

Governing law

EU Member State / Delaware, USA

This Data Processing Agreement forms part of the Terms of Service between Dwelon AI (Processor) and the Customer (Controller) and governs all processing of Personal Data in connection with Dwelon's end-to-end autonomous property operations system. It is designed to meet the requirements of GDPR, CCPA, and other applicable data protection laws.

1. Definitions

Controller

The natural or legal person (Customer) who determines the purposes and means of processing Personal Data.

Processor

Dwelon AI, which processes Personal Data on behalf of the Controller.

Personal Data

Any information relating to an identified or identifiable natural person.

Processing

Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

Sub-processor

Any third party engaged by the Processor to process Personal Data.

Data Subject

The individual to whom the Personal Data relates.

2. Scope and Purpose

This DPA applies to all processing of Personal Data by Dwelon AI on behalf of the Customer in connection with the agentic property management platform.

Purpose of processing

  • Execute autonomous property operations workflows (rent collection, maintenance triage, leasing, renewals)

  • Route communications between tenants, vendors, and owners via email and SMS

  • Process approval queue decisions and enforce workspace policy rules

  • Generate operational analytics, audit trails, and compliance reports

  • Process AI-powered actions via language models for workflow execution

Categories of data subjects

  • Tenants and prospective tenants

  • Property owners and landlords

  • Property managers, operators, and team members

  • Vendors and service providers

Types of personal data

  • Contact information (name, email, phone number)

  • Property and tenancy details (unit, lease terms, rent amounts)

  • Financial information (payment history, balances, late fees)

  • Documents (leases, applications, maintenance photos)

  • Communication records (emails, SMS messages, in-app messages)

  • Workflow execution logs and approval history

3. Controller (Customer) Obligations

The Customer as Controller shall:

  • Ensure a lawful basis exists for all processing and obtain required consents from data subjects

  • Provide clear instructions to Dwelon AI regarding the processing of Personal Data

  • Ensure Personal Data provided is accurate and up-to-date

  • Comply with all applicable data protection laws (GDPR, CCPA, local regulations)

  • Respond to Data Subject requests within legally required timeframes

  • Notify Dwelon AI promptly of any changes affecting processing instructions

  • Use the platform in compliance with the Fair Housing Act and anti-discrimination laws

  • Configure appropriate approval thresholds and policy rules for autonomous actions

4. Processor (Dwelon AI) Obligations

Dwelon AI as Processor shall:

  • Process Personal Data only on documented instructions from the Customer, unless required by law

  • Ensure all personnel authorized to process Personal Data are bound by confidentiality obligations

  • Implement appropriate technical and organizational security measures (see Section 5)

  • Not engage additional sub-processors without prior written authorization from Customer

  • Assist the Customer in responding to Data Subject access, rectification, and erasure requests

  • Assist with security breach notifications, DPIAs, and prior consultations as required

  • Delete or return all Personal Data upon termination, at Customer's choice

  • Make all information necessary to demonstrate compliance available for audits

  • Log all autonomous AI actions in an immutable audit trail accessible to Customer

5. Security Measures

Dwelon AI implements the following measures to protect Personal Data:

Technical measures

  • Encryption in transit (TLS 1.3) and at rest
  • Firebase security rules for workspace-level data isolation
  • Role-based access control (RBAC) within workspaces
  • Multi-factor authentication for admin access
  • Automated backup and disaster recovery
  • Intrusion detection and rate limiting
  • Audit logging of all data access and mutations

Organizational measures

  • Security awareness training for all personnel
  • Incident response procedures with defined escalation
  • Access limited on need-to-know basis
  • Regular security policy reviews
  • Vendor and sub-processor security assessments
  • Human-in-the-loop controls for high-impact actions
  • Policy-based blocking of unsafe autonomous actions

6. Sub-processors

The Customer authorizes the following sub-processors. Dwelon AI will notify the Customer of any intended changes, allowing 30 days to object.

Sub-processorServiceLocationPurpose
Firebase (Google)Authentication & DatabaseUSUser auth, Firestore data storage, real-time sync
Google GeminiAI Language ModelUSWorkflow execution, communication drafting, triage decisions
StripePayment ProcessingUSSubscription billing, tenant rent payments
SendGrid (Twilio)Email DeliveryUSTransactional emails, notifications, tenant communications
TwilioSMSUSSMS notifications, verification messages
RenderInfrastructureUSBackend hosting, API serving, worker execution

7. Data Retention

Personal Data is retained according to the following schedule. Customers can request earlier deletion subject to legal retention requirements.

Data categoryRetention period
Active workspace dataDuration of service agreement
Tenant records7 years post-tenancy (legal requirement)
Payment & financial data7 years (regulatory compliance)
Maintenance records5 years
Audit trail / workflow logs3 years
Deleted account dataPurged within 30 days of request
Backup copiesRotated within 90 days

8. Data Subject Rights

Dwelon AI will assist the Customer in fulfilling Data Subject requests:

Access (Art. 15)

Full data export available from workspace dashboard in JSON/CSV format

Rectification (Art. 16)

Customers can update all records directly through the platform

Erasure (Art. 17)

One-click data deletion with automated cascade across all sub-processors

Portability (Art. 20)

Machine-readable export (JSON/CSV) of all personal data

Object (Art. 21)

Processing can be halted on Customer instruction per workflow category

Restrict processing (Art. 18)

Specific data subjects can be excluded from autonomous workflows

Response timeline: Dwelon AI responds to Customer requests within 5 business days to support the Customer's 30-day GDPR obligation.

9. Data Breach Notification

In the event of a Personal Data breach, Dwelon AI will notify the Customer without undue delay and within 48 hours of becoming aware. The notification will include:

  • Description of the nature of the breach

  • Categories and approximate number of Data Subjects affected

  • Categories and approximate number of records affected

  • Likely consequences of the breach

  • Measures taken or proposed to address the breach and mitigate effects

The Customer remains responsible for notifying supervisory authorities (72 hours under GDPR) and affected Data Subjects where required by law.

10. International Data Transfers

For transfers of Personal Data outside the European Economic Area, the following mechanisms apply:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission, incorporated by reference into this DPA

  • EU-US Data Privacy Framework where applicable

  • Supplementary measures: encryption in transit and at rest, access controls, regular security assessments

11. AI and Autonomous Processing

Dwelon AI uses Google Gemini language models to execute autonomous workflows. The following safeguards apply:

  • Personal Data is sent to Google's API only as needed to execute specific workflow actions, and never for model training

  • Processing occurs under Google's data processing terms with equivalent protections

  • All AI-generated actions are logged in the Customer's audit trail with full input/output records

  • Defined High-Impact Actions always require qualified human review and explicit approval under the Terms; eligible work outside that category can run autonomously within configured authority

  • Customers can disable AI processing for specific workflow categories or data subjects

  • Rate limits and spending caps prevent runaway autonomous execution

12. Term and Termination

This DPA remains in effect for the duration of the Services agreement. Upon termination:

  • At Customer's choice, Dwelon AI will either return all Personal Data (JSON/CSV) or delete it and certify deletion in writing

  • Deletion completed within 30 days unless legal retention is required

  • Backup copies rotated and purged within 90 days

  • Sub-processors instructed to delete Customer data on the same schedule

13. Liability

  • Each party's liability under this DPA is subject to the limitations in the main Services Agreement

  • Dwelon AI is liable only for damages caused by processing that violates GDPR processor obligations or Customer's lawful instructions

  • The Customer indemnifies Dwelon AI for claims arising from Customer's breach of data protection laws or unlawful processing instructions

14. Governing Law

  • For EU/EEA Data Subjects: the laws of the EU Member State in which the Customer is established

  • For all other Data Subjects: the laws of the State of Delaware, USA

  • Disputes resolved per the dispute resolution provisions in the main Services Agreement

Need a signed copy?

Enterprise customers can request a countersigned Data Processing Agreement tailored to specific compliance requirements.

Request signed DPA
Related documents
Privacy PolicyTerms of ServiceCookie Policy