Effective: September 15, 2026 · Last Updated: September 15, 2026
1N599 Inc (dba TheReelty)
Who this is for: brokerages, property management companies, teams and other business customers that put personal data about their own clients, leads, tenants, owners or staff into TheReelty. It applies automatically as part of your agreement with us — there is nothing to sign. If your organization needs a countersigned copy, email support@thereelty.com.
This Data Processing Addendum ("DPA") is between 1N599 Inc, doing business as TheReelty("TheReelty," "we," "us"), and the business customer that uses the TheReelty platform ("Customer," "you"). It forms part of the Master Services Agreement or, if you have not entered into one, the Terms of Service (either, the "Agreement"). It applies whenever we process Customer Personal Data on your behalf.
For Customer Personal Data, you are the controller (or "business") and we are your processor (or "service provider"). For account, billing, security and usage data about your authorized users, we act as an independent controller under our Privacy Policy.
You are responsible for having a lawful basis, and any notices and consents required, for the personal data you put into the platform — including consent for marketing emails and text messages sent through our marketing tools, and a permissible purpose under the Fair Credit Reporting Act for tenant or background screening.
We process Customer Personal Data only to provide, secure and support the services under the Agreement, and otherwise only on your documented instructions. The Agreement, this DPA and your configuration of the platform are your complete instructions. If we believe an instruction breaks Data Protection Laws, we will tell you and may decline to follow it. If the law requires us to process Customer Personal Data for another purpose, we will tell you first unless the law forbids it.
| Item | Description |
|---|---|
| Subject matter | Providing the TheReelty platform to Customer under the Agreement |
| Duration | The term of the Agreement, plus the return and deletion period in Section 13 |
| Nature and purpose | Hosting, storage, organization, retrieval, transmission, analysis (including AI-assisted analysis), and deletion, to deliver the features Customer uses |
| Data subjects | Customer’s clients, leads, buyers, sellers, tenants, applicants, property owners, vendors, and Customer’s employees and contractors |
| Categories of data | Names and contact details; property, listing, lease and transaction information; payment and rent status; maintenance requests; messages and call records; documents and media Customer uploads; identity verification and screening results where Customer uses those features |
| Sensitive data | Not intended. Government ID numbers, bank details and screening reports should be provided only through the platform features built to collect them. |
Where the CCPA or a similar US state law applies, we:
You may take reasonable steps to stop and remediate unauthorized use of Customer Personal Data. We certify that we understand and will comply with these restrictions.
We limit access to Customer Personal Data to personnel who need it to provide the services and who are bound by written confidentiality obligations.
We maintain technical and organizational measures appropriate to the risk, including:
We may update these measures as long as the overall level of protection is not reduced.
You authorize us to engage the Subprocessors below. We impose data protection obligations on each Subprocessor that are no less protective than this DPA, and we remain responsible for their performance. Not every Subprocessor processes data for every customer — several are used only when you turn on the related feature.
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, file storage and content delivery | United States |
| Neon Inc. | Managed PostgreSQL database | United States |
| Upstash Inc. | Rate limiting and short-lived cache | United States |
| Stripe Inc. | Payment processing and billing | United States |
| Razorpay Software Pvt. Ltd. | Payment processing (India region only) | India |
| Resend Inc. | Transactional and marketing email delivery | United States |
| Twilio Inc. | SMS, voice and video communications | United States |
| Telnyx LLC | Telephony and SMS | United States |
| Daily.co (Pluot Communications Inc.) | Video calls | United States |
| Anthropic PBC | AI text generation and analysis | United States |
| Groq Inc. | AI text generation | United States |
| Features & Labels Inc. (fal.ai) | AI image and video generation | United States |
| HeyGen Technology Inc. | AI avatar and narrated video generation | United States |
| Persona Identities Inc. | Identity verification | United States |
| ID.me Inc. | Identity verification | United States |
| Checkr Inc. | Background and tenant screening | United States |
| Plaid Inc. | Bank account and income verification | United States |
| DocuSign Inc. | Electronic signatures | United States |
| Google LLC (Google Maps Platform) | Address autocomplete and maps | United States |
| ATTOM Data Solutions, RentCast, Realie | Property records and valuation data (property addresses only) | United States |
| Functional Software Inc. (Sentry) | Error monitoring | United States |
| PostHog Inc. | Product analytics | United States |
We will update this list at least 30 days before a new Subprocessor begins processing Customer Personal Data. To be told by email, write to support@thereelty.com with the subject "Subprocessor Updates." You may object on reasonable data protection grounds within that 30-day period. If we cannot address the objection, you may terminate the affected services without penalty.
The platform lets you access, correct, export and delete most Customer Personal Data yourself. If we receive a request from one of your data subjects, we will forward it to you without undue delay and will not respond ourselves except to redirect them to you. We will give you reasonable help with requests you cannot fulfil through the platform.
We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting your Customer Personal Data. The notice will describe what happened, the data affected, the likely consequences and what we are doing about it, and we will update you as we learn more. Notifying you is not an admission of fault.
We will give you reasonable information and help with data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing.
On written request, no more than once a year (or after a Security Incident or a regulator's request), we will answer reasonable security questionnaires and provide the information needed to show we comply with this DPA. Any on-site audit must be agreed in advance, conducted with at least 30 days' notice during business hours by an auditor bound by confidentiality, and is at your cost.
When the Agreement ends, you may export your Customer Personal Data for 30 days. We will then delete it from our active systems within 90 days, and from backups as they expire in the normal cycle, except where the law requires us to keep it. Anything we must keep stays protected by this DPA.
We are based in the United States and process Customer Personal Data there and in the locations listed in Section 9. Where GDPR, UK GDPR or Swiss law restricts a transfer, the EU Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable) are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and the amendments required by Swiss law. For the Clauses: the optional docking clause applies; Clause 9 option 2 (general authorization) applies under Section 9 above; the optional language in Clause 11 does not apply; Clauses 17 and 18 are governed by the laws and courts of Ireland; and Annexes I and II are completed by Sections 1, 5 and 8 of this DPA.
Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where the Data Protection Laws or the Standard Contractual Clauses do not allow it. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls; if it conflicts with the Standard Contractual Clauses, the Clauses control.
Data Protection — 1N599 Inc (dba TheReelty)
5900 Balcones Drive # 8394, Austin, TX 78731