Data Protection

Data Processing Addendum

Effective: September 15, 2026 · Last Updated: September 15, 2026

1N599 Inc (dba TheReelty)

Who this is for: brokerages, property management companies, teams and other business customers that put personal data about their own clients, leads, tenants, owners or staff into TheReelty. It applies automatically as part of your agreement with us — there is nothing to sign. If your organization needs a countersigned copy, email support@thereelty.com.

1. Parties and Incorporation

This Data Processing Addendum ("DPA") is between 1N599 Inc, doing business as TheReelty("TheReelty," "we," "us"), and the business customer that uses the TheReelty platform ("Customer," "you"). It forms part of the Master Services Agreement or, if you have not entered into one, the Terms of Service (either, the "Agreement"). It applies whenever we process Customer Personal Data on your behalf.

2. Definitions

  • Data Protection Laws means all privacy and data protection laws that apply to the processing, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), the Texas Data Privacy and Security Act, other US state privacy laws, and India's Digital Personal Data Protection Act 2023 where applicable.
  • Customer Personal Data means personal data that you or your authorized users submit to the platform, or that we collect on your behalf, and that we process as your processor or service provider.
  • Subprocessor means a third party we engage to process Customer Personal Data.
  • Security Incident means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • "Controller," "processor," "data subject," "processing," "business" and "service provider" have the meanings given in the Data Protection Laws.

3. Roles of the Parties

For Customer Personal Data, you are the controller (or "business") and we are your processor (or "service provider"). For account, billing, security and usage data about your authorized users, we act as an independent controller under our Privacy Policy.

You are responsible for having a lawful basis, and any notices and consents required, for the personal data you put into the platform — including consent for marketing emails and text messages sent through our marketing tools, and a permissible purpose under the Fair Credit Reporting Act for tenant or background screening.

4. Processing on Your Instructions

We process Customer Personal Data only to provide, secure and support the services under the Agreement, and otherwise only on your documented instructions. The Agreement, this DPA and your configuration of the platform are your complete instructions. If we believe an instruction breaks Data Protection Laws, we will tell you and may decline to follow it. If the law requires us to process Customer Personal Data for another purpose, we will tell you first unless the law forbids it.

5. Details of the Processing

ItemDescription
Subject matterProviding the TheReelty platform to Customer under the Agreement
DurationThe term of the Agreement, plus the return and deletion period in Section 13
Nature and purposeHosting, storage, organization, retrieval, transmission, analysis (including AI-assisted analysis), and deletion, to deliver the features Customer uses
Data subjectsCustomer’s clients, leads, buyers, sellers, tenants, applicants, property owners, vendors, and Customer’s employees and contractors
Categories of dataNames and contact details; property, listing, lease and transaction information; payment and rent status; maintenance requests; messages and call records; documents and media Customer uploads; identity verification and screening results where Customer uses those features
Sensitive dataNot intended. Government ID numbers, bank details and screening reports should be provided only through the platform features built to collect them.

6. US State Law Service Provider Terms

Where the CCPA or a similar US state law applies, we:

  • Do not sell or share Customer Personal Data, including for cross-context behavioral advertising
  • Do not retain, use or disclose it for any purpose other than the business purposes in the Agreement
  • Do not retain, use or disclose it outside our direct business relationship with you
  • Do not combine it with personal data we receive from other sources, except as those laws permit
  • Will comply with those laws, give the same level of privacy protection they require, and tell you if we can no longer meet these obligations

You may take reasonable steps to stop and remediate unauthorized use of Customer Personal Data. We certify that we understand and will comply with these restrictions.

7. Confidentiality

We limit access to Customer Personal Data to personnel who need it to provide the services and who are bound by written confidentiality obligations.

8. Security

We maintain technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit using TLS, and encryption at rest by our hosting and database providers
  • Role-based access control enforced on the server for every protected page and API, and data scoped to the account that owns it
  • Passwords stored only as salted hashes; rate limiting on sign-in and other sensitive endpoints
  • Least-privilege access to production systems for our personnel
  • Error monitoring and logging to detect and investigate abuse and failures
  • Managed backups through our database provider

We may update these measures as long as the overall level of protection is not reduced.

9. Subprocessors

You authorize us to engage the Subprocessors below. We impose data protection obligations on each Subprocessor that are no less protective than this DPA, and we remain responsible for their performance. Not every Subprocessor processes data for every customer — several are used only when you turn on the related feature.

SubprocessorPurposeLocation
Vercel Inc.Application hosting, file storage and content deliveryUnited States
Neon Inc.Managed PostgreSQL databaseUnited States
Upstash Inc.Rate limiting and short-lived cacheUnited States
Stripe Inc.Payment processing and billingUnited States
Razorpay Software Pvt. Ltd.Payment processing (India region only)India
Resend Inc.Transactional and marketing email deliveryUnited States
Twilio Inc.SMS, voice and video communicationsUnited States
Telnyx LLCTelephony and SMSUnited States
Daily.co (Pluot Communications Inc.)Video callsUnited States
Anthropic PBCAI text generation and analysisUnited States
Groq Inc.AI text generationUnited States
Features & Labels Inc. (fal.ai)AI image and video generationUnited States
HeyGen Technology Inc.AI avatar and narrated video generationUnited States
Persona Identities Inc.Identity verificationUnited States
ID.me Inc.Identity verificationUnited States
Checkr Inc.Background and tenant screeningUnited States
Plaid Inc.Bank account and income verificationUnited States
DocuSign Inc.Electronic signaturesUnited States
Google LLC (Google Maps Platform)Address autocomplete and mapsUnited States
ATTOM Data Solutions, RentCast, RealieProperty records and valuation data (property addresses only)United States
Functional Software Inc. (Sentry)Error monitoringUnited States
PostHog Inc.Product analyticsUnited States

We will update this list at least 30 days before a new Subprocessor begins processing Customer Personal Data. To be told by email, write to support@thereelty.com with the subject "Subprocessor Updates." You may object on reasonable data protection grounds within that 30-day period. If we cannot address the objection, you may terminate the affected services without penalty.

10. Data Subject Requests

The platform lets you access, correct, export and delete most Customer Personal Data yourself. If we receive a request from one of your data subjects, we will forward it to you without undue delay and will not respond ourselves except to redirect them to you. We will give you reasonable help with requests you cannot fulfil through the platform.

11. Security Incidents

We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting your Customer Personal Data. The notice will describe what happened, the data affected, the likely consequences and what we are doing about it, and we will update you as we learn more. Notifying you is not an admission of fault.

12. Assistance, Records and Audits

We will give you reasonable information and help with data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing.

On written request, no more than once a year (or after a Security Incident or a regulator's request), we will answer reasonable security questionnaires and provide the information needed to show we comply with this DPA. Any on-site audit must be agreed in advance, conducted with at least 30 days' notice during business hours by an auditor bound by confidentiality, and is at your cost.

13. Return and Deletion

When the Agreement ends, you may export your Customer Personal Data for 30 days. We will then delete it from our active systems within 90 days, and from backups as they expire in the normal cycle, except where the law requires us to keep it. Anything we must keep stays protected by this DPA.

14. International Transfers

We are based in the United States and process Customer Personal Data there and in the locations listed in Section 9. Where GDPR, UK GDPR or Swiss law restricts a transfer, the EU Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable) are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and the amendments required by Swiss law. For the Clauses: the optional docking clause applies; Clause 9 option 2 (general authorization) applies under Section 9 above; the optional language in Clause 11 does not apply; Clauses 17 and 18 are governed by the laws and courts of Ireland; and Annexes I and II are completed by Sections 1, 5 and 8 of this DPA.

15. Liability and Precedence

Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where the Data Protection Laws or the Standard Contractual Clauses do not allow it. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls; if it conflicts with the Standard Contractual Clauses, the Clauses control.

16. Contact

Data Protection — 1N599 Inc (dba TheReelty)

5900 Balcones Drive # 8394, Austin, TX 78731

support@thereelty.com