Data Processing Agreement
How Dwelon AI processes personal data as a data processor under GDPR Article 28 and CCPA requirements.
Customer (you)
Dwelon AI, Inc., Delaware, USA
privacy@dwelon.com
EU Member State / Delaware, USA
This Data Processing Agreement forms part of the Terms of Service between Dwelon AI (Processor) and the Customer (Controller) and governs all processing of Personal Data in connection with Dwelon's end-to-end autonomous property operations system. It is designed to meet the requirements of GDPR, CCPA, and other applicable data protection laws.
1. Definitions
The natural or legal person (Customer) who determines the purposes and means of processing Personal Data.
Dwelon AI, which processes Personal Data on behalf of the Controller.
Any information relating to an identified or identifiable natural person.
Any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
Any third party engaged by the Processor to process Personal Data.
The individual to whom the Personal Data relates.
2. Scope and Purpose
This DPA applies to all processing of Personal Data by Dwelon AI on behalf of the Customer in connection with the agentic property management platform.
Purpose of processing
Execute autonomous property operations workflows (rent collection, maintenance triage, leasing, renewals)
Route communications between tenants, vendors, and owners via email and SMS
Process approval queue decisions and enforce workspace policy rules
Generate operational analytics, audit trails, and compliance reports
Process AI-powered actions via language models for workflow execution
Categories of data subjects
Tenants and prospective tenants
Property owners and landlords
Property managers, operators, and team members
Vendors and service providers
Types of personal data
Contact information (name, email, phone number)
Property and tenancy details (unit, lease terms, rent amounts)
Financial information (payment history, balances, late fees)
Documents (leases, applications, maintenance photos)
Communication records (emails, SMS messages, in-app messages)
Workflow execution logs and approval history
3. Controller (Customer) Obligations
The Customer as Controller shall:
Ensure a lawful basis exists for all processing and obtain required consents from data subjects
Provide clear instructions to Dwelon AI regarding the processing of Personal Data
Ensure Personal Data provided is accurate and up-to-date
Comply with all applicable data protection laws (GDPR, CCPA, local regulations)
Respond to Data Subject requests within legally required timeframes
Notify Dwelon AI promptly of any changes affecting processing instructions
Use the platform in compliance with the Fair Housing Act and anti-discrimination laws
Configure appropriate approval thresholds and policy rules for autonomous actions
4. Processor (Dwelon AI) Obligations
Dwelon AI as Processor shall:
Process Personal Data only on documented instructions from the Customer, unless required by law
Ensure all personnel authorized to process Personal Data are bound by confidentiality obligations
Implement appropriate technical and organizational security measures (see Section 5)
Not engage additional sub-processors without prior written authorization from Customer
Assist the Customer in responding to Data Subject access, rectification, and erasure requests
Assist with security breach notifications, DPIAs, and prior consultations as required
Delete or return all Personal Data upon termination, at Customer's choice
Make all information necessary to demonstrate compliance available for audits
Log all autonomous AI actions in an immutable audit trail accessible to Customer
5. Security Measures
Dwelon AI implements the following measures to protect Personal Data:
Technical measures
- Encryption in transit (TLS 1.3) and at rest
- Firebase security rules for workspace-level data isolation
- Role-based access control (RBAC) within workspaces
- Multi-factor authentication for admin access
- Automated backup and disaster recovery
- Intrusion detection and rate limiting
- Audit logging of all data access and mutations
Organizational measures
- Security awareness training for all personnel
- Incident response procedures with defined escalation
- Access limited on need-to-know basis
- Regular security policy reviews
- Vendor and sub-processor security assessments
- Human-in-the-loop controls for high-impact actions
- Policy-based blocking of unsafe autonomous actions
6. Sub-processors
The Customer authorizes the following sub-processors. Dwelon AI will notify the Customer of any intended changes, allowing 30 days to object.
| Sub-processor | Service | Location | Purpose |
|---|---|---|---|
| Firebase (Google) | Authentication & Database | US | User auth, Firestore data storage, real-time sync |
| Google Gemini | AI Language Model | US | Workflow execution, communication drafting, triage decisions |
| Stripe | Payment Processing | US | Subscription billing, tenant rent payments |
| SendGrid (Twilio) | Email Delivery | US | Transactional emails, notifications, tenant communications |
| Twilio | SMS | US | SMS notifications, verification messages |
| Render | Infrastructure | US | Backend hosting, API serving, worker execution |
7. Data Retention
Personal Data is retained according to the following schedule. Customers can request earlier deletion subject to legal retention requirements.
| Data category | Retention period |
|---|---|
| Active workspace data | Duration of service agreement |
| Tenant records | 7 years post-tenancy (legal requirement) |
| Payment & financial data | 7 years (regulatory compliance) |
| Maintenance records | 5 years |
| Audit trail / workflow logs | 3 years |
| Deleted account data | Purged within 30 days of request |
| Backup copies | Rotated within 90 days |
8. Data Subject Rights
Dwelon AI will assist the Customer in fulfilling Data Subject requests:
Full data export available from workspace dashboard in JSON/CSV format
Customers can update all records directly through the platform
One-click data deletion with automated cascade across all sub-processors
Machine-readable export (JSON/CSV) of all personal data
Processing can be halted on Customer instruction per workflow category
Specific data subjects can be excluded from autonomous workflows
Response timeline: Dwelon AI responds to Customer requests within 5 business days to support the Customer's 30-day GDPR obligation.
9. Data Breach Notification
In the event of a Personal Data breach, Dwelon AI will notify the Customer without undue delay and within 48 hours of becoming aware. The notification will include:
Description of the nature of the breach
Categories and approximate number of Data Subjects affected
Categories and approximate number of records affected
Likely consequences of the breach
Measures taken or proposed to address the breach and mitigate effects
The Customer remains responsible for notifying supervisory authorities (72 hours under GDPR) and affected Data Subjects where required by law.
10. International Data Transfers
For transfers of Personal Data outside the European Economic Area, the following mechanisms apply:
Standard Contractual Clauses (SCCs) as approved by the European Commission, incorporated by reference into this DPA
EU-US Data Privacy Framework where applicable
Supplementary measures: encryption in transit and at rest, access controls, regular security assessments
11. AI and Autonomous Processing
Dwelon AI uses Google Gemini language models to execute autonomous workflows. The following safeguards apply:
Personal Data is sent to Google's API only as needed to execute specific workflow actions, and never for model training
Processing occurs under Google's data processing terms with equivalent protections
All AI-generated actions are logged in the Customer's audit trail with full input/output records
Defined High-Impact Actions always require qualified human review and explicit approval under the Terms; eligible work outside that category can run autonomously within configured authority
Customers can disable AI processing for specific workflow categories or data subjects
Rate limits and spending caps prevent runaway autonomous execution
12. Term and Termination
This DPA remains in effect for the duration of the Services agreement. Upon termination:
At Customer's choice, Dwelon AI will either return all Personal Data (JSON/CSV) or delete it and certify deletion in writing
Deletion completed within 30 days unless legal retention is required
Backup copies rotated and purged within 90 days
Sub-processors instructed to delete Customer data on the same schedule
13. Liability
Each party's liability under this DPA is subject to the limitations in the main Services Agreement
Dwelon AI is liable only for damages caused by processing that violates GDPR processor obligations or Customer's lawful instructions
The Customer indemnifies Dwelon AI for claims arising from Customer's breach of data protection laws or unlawful processing instructions
14. Governing Law
For EU/EEA Data Subjects: the laws of the EU Member State in which the Customer is established
For all other Data Subjects: the laws of the State of Delaware, USA
Disputes resolved per the dispute resolution provisions in the main Services Agreement
Need a signed copy?
Enterprise customers can request a countersigned Data Processing Agreement tailored to specific compliance requirements.
Request signed DPA