Data Processing Addendum

Last Updated: July 29, 2026

1. Preamble

1.1. This Data Processing Addendum (“Addendum”) forms part of the agreement between Customer and REMLogics, LLC (“Service Provider”), together referred to as the “Parties,” governing Customer’s use of the REMLogics platform and related services (the “Agreement”) and applies where Service Provider will Process Customer Data when providing Services under the Agreement. All capitalized terms not defined in this Addendum shall have the meanings set forth in the Agreement.

2. Definitions

2.1. “Agreement” means the written or electronic agreement between Customer and Service Provider specific to the provision of the Services to Customer.

2.2. “Applicable Data Protection Laws” means all applicable federal, state, and provincial laws and regulations relating to the privacy, security, or Processing of Personal Information, including the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100 et seq.), the Texas Data Privacy and Security Act (Tex. Bus. & Com. Code Ch. 541), the Personal Information Protection and Electronic Documents Act (Canada), and comparable state comprehensive privacy laws, together with any final implementing regulations, regulating the collection, use, disclosure, storage, transfer, privacy, security, or other Processing of Personal Information and laws regulating notification in the event of a Security Incident.

2.3. “Controller” means the natural or legal person that determines the purposes and means of the Processing of Personal Information, including “controller,” “business,” or like term as defined by Applicable Data Protection Laws.

2.4. “Customer Data” means the data that Service Provider Processes for or on behalf of Customer through Service Provider’s provision of the Services.

2.5. “Data Subject” means an identified or identifiable natural person to whom Personal Information relates, including “data subject,” “consumer,” or like term as defined by Applicable Data Protection Laws.

2.6. “Personal Information” means any information relating to an identified or identifiable natural person, including “personal information” or analogous variations of such terminology within the meaning of Applicable Data Protection Laws. For the purposes of this Addendum, Personal Information is limited to such information that is contained in Customer Data.

2.7. “Processing” or “Process” means any operation or set of operations which is performed upon Customer Data, including “processing” or “process” as defined under Applicable Data Protection Laws.

2.8. “Processor” means the natural or legal person that Processes Personal Information on behalf of the Controller, including “processor,” “service provider,” or like term as defined by Applicable Data Protection Laws.

2.9. “Security Incident” means (a) the confirmed unauthorized access to, acquisition of, use of, disclosure of, alteration of, or loss of Customer Data; or (b) a “security breach” or similar term as defined by applicable law.

2.10. “Services” as used in this Addendum means the services or products that are specifically addressed in the Agreement, statement of work, or order form entered into between the Parties.

2.11. “Subprocessor” means any third party engaged by Service Provider to whom Service Provider delegates a Processing activity related to Customer Data.

3. Designation of the Parties; Data Ownership

3.1. The Parties agree that, for the purposes of compliance with Applicable Data Protection Laws, all Personal Information that is received by Service Provider from Customer in connection with the performance of Service Provider’s obligations under the Agreement and this Addendum, Customer will be the Controller and Service Provider will be the Processor.

3.2. Each Party will comply, and will take reasonable steps to ensure that its personnel comply, with Applicable Data Protection Laws in connection with the Agreement and this Addendum.

3.3. Customer is and shall remain the owner of any Customer Data. Service Provider acquires no rights in Customer Data except as necessary to perform the Services under the Agreement.

4. Processing of Customer Data

4.1. Customer Data will be Processed by Service Provider solely for purposes that are (a) strictly necessary for Service Provider to perform its obligations under the Agreement; (b) required by law so long as such Processing does not violate Applicable Data Protection Laws; and (c) other purposes permitted by Customer in writing or otherwise explicitly stated in this Addendum. Customer’s instructions for the Processing of Customer Data are set forth in the Agreement and this Addendum, which together constitute Customer’s documented instructions to Service Provider.

4.2. Service Provider shall not Process Customer Data for the purpose of providing targeted advertising.

4.3. With respect to any Personal Information that is subject to Applicable Data Protection Laws:

  • (a) Service Provider will not retain, use, combine, or disclose Personal Information for any purpose or timeline other than for the limited and specific purposes or timelines outlined in Annex 1, except as otherwise explicitly agreed to in writing by Service Provider and Customer;
  • (b) Service Provider shall not “sell” or “share” Personal Information, as such terms are defined by Applicable Data Protection Laws, or retain, use, combine, or disclose the Personal Information outside of the direct business relationship with Customer, including not combining Personal Information received from Customer with Personal Information that Service Provider receives from or on behalf of another person or collects from its own interactions with Data Subjects, except as expressly permitted by Applicable Data Protection Laws;
  • (c) Service Provider will only retain, use, or disclose the Personal Information for “business purposes,” as defined by Applicable Data Protection Laws, as authorized by the Agreement or this Addendum;
  • (d) Service Provider will not retain, use, or disclose the Personal Information for any “commercial purposes” other than the “business purposes” (as these terms are defined by Applicable Data Protection Laws) specified in the Agreement;
  • (e) Service Provider will provide the same level of privacy protection for Personal Information as required by Applicable Data Protection Laws;
  • (f) Customer has the right to take reasonable and appropriate steps to help ensure that Service Provider uses Personal Information in a manner consistent with Customer’s obligations under Applicable Data Protection Laws;
  • (g) Service Provider will notify Customer if Service Provider makes a determination that it can no longer meet its obligations under Applicable Data Protection Laws;
  • (h) Customer will have the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information by Service Provider;
  • (i) Service Provider shall ensure that each person Processing Personal Information in connection with the Services is subject to a duty of confidentiality with respect to the Personal Information; and
  • (j) Service Provider shall make available to Customer such readily accessible information in its possession necessary to demonstrate compliance with the obligations under Applicable Data Protection Laws.

4.4. If the Services include the Processing of Customer Data in or through any artificial intelligence algorithms or similar platforms (“AI Platform”), Service Provider may only use Customer Data to provide the Services and, for purposes of clarity, may not use any Customer Data to train any AI Platform or for the general betterment of any AI Platform without Customer’s prior written consent.

4.5. To the extent that Service Provider Processes Personal Information subject to the California Consumer Privacy Act, Service Provider certifies that it understands the restrictions in Section 4.3 of this Addendum and will comply with them.

4.6. Service Provider may create and use de-identified or aggregated data derived from Customer Data, provided that (a) such data cannot reasonably be used to identify any Data Subject; (b) Service Provider commits not to attempt to re-identify such data; and (c) Service Provider implements reasonable technical safeguards to prevent re-identification. De-identified or aggregated data is not Customer Data for purposes of this Addendum.

5. Information Security Measures

5.1. Service Provider will implement and maintain, at its own cost and expense, and in accordance with Applicable Data Protection Laws and industry standards, reasonable and appropriate technical, organizational, and physical security measures designed to protect the privacy and security of Customer Data it Processes in connection with the Agreement and this Addendum.

5.2. Without limiting the generality of Section 5.1, Service Provider shall:

  • (a) Implement access controls to limit access to Customer Data to personnel who require such access to perform the Services;
  • (b) Use encryption for Customer Data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent);
  • (c) Maintain network security controls, including firewalls, intrusion detection, and monitoring appropriate to the Services;
  • (d) Conduct periodic vulnerability assessments of the systems used to Process Customer Data;
  • (e) Maintain a written information security program appropriate to the nature of the Customer Data Processed; and
  • (f) Take reasonable steps to ensure that Service Provider’s personnel who Process Customer Data in connection with the Agreement are subject to appropriate supervision and binding confidentiality obligations in respect of such Processing.

5.3. Customer Data is hosted on Microsoft Azure infrastructure in the Central US region. Service Provider shall not relocate Customer Data to a different hosting region without prior written notice to Customer.

5.4. The Services are hosted on Microsoft Azure infrastructure, which maintains independent security certifications including SOC 1 Type II, SOC 2 Type II, and ISO 27001. Information regarding Azure’s compliance certifications is available at https://learn.microsoft.com/en-us/azure/compliance/. Service Provider leverages these infrastructure-level controls as part of its overall security program.

6. Subprocessors

6.1. Customer authorizes Service Provider to engage third-party Subprocessors to perform Processing activities involving Customer Data on Customer’s behalf. Service Provider will require such Subprocessors to agree in writing to comply with materially similar obligations as those contained in this Addendum. The current list of Subprocessors is set forth in Annex 2. Upon Customer’s request, Service Provider shall provide a complete and current list of Subprocessors that Process Customer Data.

6.2. Service Provider shall notify Customer of any intended addition or replacement of Subprocessors by updating Annex 2 and providing Customer with notice at least thirty (30) days before the new Subprocessor begins Processing Customer Data.

6.3. If Customer objects to a new Subprocessor on reasonable grounds relating to data protection, the Parties shall discuss Customer’s concerns in good faith with a view to achieving a commercially reasonable resolution. If the Parties are unable to reach a resolution within thirty (30) days of Customer’s objection, Customer may terminate the Agreement on written notice without penalty.

6.4. Service Provider shall remain liable for the acts and omissions of its Subprocessors to the same extent as if Service Provider were performing the Processing directly.

7. Cooperation and Audits

7.1. Service Provider will provide reasonable assistance, information, and cooperation to Customer to help Customer comply with Customer’s obligations under Applicable Data Protection Laws with respect to Customer Data.

7.2. If Service Provider is requested or required (by oral questions, interrogatories, requests for information or documents in legal proceedings, subpoenas, civil investigative demands, or similar processes) to disclose any Customer Data to a third party, Service Provider shall promptly notify Customer of any such disclosure request (except to the extent that Service Provider is precluded by applicable law or legal process) so that Customer may seek a protective order or other appropriate remedy.

7.3. Subject to the terms of this Section 7, Service Provider shall permit Customer, its auditors, and designated audit representatives to audit and inspect, at Customer’s expense, and no more often than once per twelve (12) month period, upon no less than thirty (30) days’ advance written notice, and with controls to maintain the confidentiality and security of Service Provider’s own security infrastructure and confidential information: (a) Service Provider’s security practices and procedures related to Customer Data; and (b) all books, notices, and administrative records required to be retained by Service Provider under this Addendum. Such audit and inspection rights shall be limited to the purpose of verifying Service Provider’s compliance with this Addendum and the Agreement. If any audit or inspection conducted pursuant to this Addendum reveals a material noncompliance, Service Provider will propose an appropriate written remediation plan within the time reasonably requested by Customer and will remedy the identified issues according to such plan upon Customer’s approval.

7.4. In the event of a Security Incident caused by Service Provider or its Subprocessor, Customer may conduct one additional audit within thirty (30) days following the Security Incident, focused on the circumstances and remediation of the Security Incident.

7.5. Customer or its auditors and designated audit representatives shall (a) execute and deliver confidentiality and nondisclosure agreements reasonably acceptable to Service Provider, (b) observe Service Provider’s reasonable confidentiality and security arrangements, and (c) conduct any and all audits in a manner that results in minimal inconvenience and disruption to Service Provider’s business operations. The Parties agree that Customer or its auditors and designated audit representatives shall not be entitled to audit (w) Service Provider’s technical systems beyond the scope of Customer Data Processing, (x) data or information of other customers of Service Provider, (y) any Service Provider proprietary data, or (z) any other Service Provider confidential information that is not relevant for the purposes of the audit. All information learned or exchanged in connection with the conduct of an audit, as well as the results of any audit, constitute Service Provider’s confidential information for the purposes of the Agreement.

7.6. Upon notice to Service Provider, Service Provider shall take commercially reasonable steps to assist and support Customer in the event of an investigation by any regulator, including a data protection regulator or similar authority, if and to the extent that such investigation relates to Customer Data handled by Service Provider. Such assistance and support shall be at Customer’s expense, except where such investigation was required due to Service Provider’s or its Subprocessors’ acts or omissions, in which case such assistance and support shall be at Service Provider’s expense.

8. Security Incidents

8.1. Service Provider shall without undue delay, and in no event longer than seventy-two (72) hours of confirming a Security Incident, notify Customer in writing at Customer’s designated contact address. Such notice shall include, to the extent reasonably available:

  • (a) A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects affected;
  • (b) The name and contact information of Service Provider’s point of contact for further information;
  • (c) A description of the likely consequences of the Security Incident; and
  • (d) A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.

8.2. If Service Provider is unable to provide all information required under Section 8.1 at the time of initial notification, Service Provider shall provide such information in phases as it becomes available, without undue delay.

8.3. Service Provider agrees to take commercially reasonable efforts to contain, investigate, mitigate, and remediate any Security Incident that impacts Customer Data. Service Provider also agrees to provide reasonable assistance to Customer in Customer’s provision of notice of the Security Incident to impacted Data Subjects or other third parties, including regulators.

8.4. Service Provider shall reimburse Customer for all reasonable and documented costs actually incurred by Customer as a direct result of a Security Incident caused by Service Provider’s breach of this Addendum.

8.5. Service Provider’s notification of a Security Incident under this Section shall not be construed as an acknowledgment of fault or liability.

9. Data Subject Rights

9.1. Service Provider will reasonably assist Customer, taking into account the nature of the Processing, by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligations to respond to requests from Data Subjects to access, delete, correct, or object to the Processing of Personal Information, or any similar Data Subject right under Applicable Data Protection Laws (collectively, “Data Subject Request”).

9.2. If Service Provider receives a Data Subject Request directly from a Data Subject regarding Customer Data, Service Provider shall promptly redirect the Data Subject to Customer and notify Customer of the request, unless prohibited by applicable law.

9.3. Customer should submit Data Subject Requests requiring Service Provider’s assistance to privacy@remlogics.com, and Service Provider will respond to Customer within the timeframes outlined in Applicable Data Protection Laws.

10. Data Retention and Deletion

10.1. Service Provider shall either securely delete or securely return any Customer Data to Customer once Processing by Service Provider of any Customer Data is no longer required for Service Provider’s performance of its obligations under the Agreement or this Addendum, unless retention of any Customer Data is required by applicable law, in which case Service Provider will continue to retain the Customer Data subject to the requirements of this Addendum and may only Process such Customer Data for the purposes that make return or deletion infeasible.

10.2. Upon termination or expiration of the Agreement, or upon Customer’s written request, Service Provider shall complete the return or secure deletion of Customer Data within sixty (60) days. Where Customer elects return of Customer Data, Service Provider shall make such data available for export in a structured, commonly used, and machine-readable format. Service Provider shall certify such deletion in writing upon Customer’s request.

10.3. Service Provider shall ensure that its Subprocessors comply with the data return and deletion obligations of this Section.

11. Cross-Border Processing

11.1. Customer Data may be Processed in the United States. Where Customer Data originates from a jurisdiction outside the United States, Service Provider shall ensure that any cross-border transfer of Customer Data complies with Applicable Data Protection Laws.

11.2. Service Provider shall cooperate with Customer to implement any additional transfer mechanisms required by Applicable Data Protection Laws upon Customer’s reasonable request.

11.3. Customer acknowledges that Customer Data hosted in the United States may be subject to access by United States courts, law enforcement, or national security authorities under applicable United States law. Service Provider shall notify Customer of any such access request in accordance with Section 7.2, to the extent permitted by law.

12. Interpretation and Updates

12.1. This Addendum will be interpreted in a manner that allows Customer and Service Provider to comply with their respective obligations under Applicable Data Protection Laws.

12.2. Service Provider may update this Addendum from time to time in a manner that complies in all material respects with Applicable Data Protection Laws and will not otherwise materially lessen the protections to Customer Data as described under this Addendum. Material changes shall be communicated to Customer with at least thirty (30) days’ advance notice. To the extent that the terms of this Addendum conflict with the terms of the Agreement, the terms of this Addendum will control.

13. General Provisions

13.1. Limitation of Liability. The Parties’ liability under this Addendum shall be subject to the limitations and exclusions of liability set forth in the Agreement. Nothing in this Addendum or the Agreement shall relieve either Party of its responsibilities imposed under Applicable Data Protection Laws by virtue of its role in the Processing relationship.

13.2. Governing Law. This Addendum shall be governed by the laws of the State of Texas, without regard to conflict of laws principles.

13.3. Severability. If any provision of this Addendum is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

Annex 1: Personal Information Processing Terms

Element Description
Categories of Data Subjects Customer’s employees; tenants of Customer’s managed properties; business contacts and vendors of Customer
Categories of Personal Information Contact information (name, address, email address, phone number); employment information; financial and lease-related information, including payment and account data; commercial information related to tenancy and business operations
Categories of Sensitive Personal Information N/A. The REMLogics platform does not process sensitive personal information (e.g., Social Security numbers, government-issued identifiers, financial account numbers, health data, biometric data, or precise geolocation).
Frequency of Transfer Continuous
Purpose of Processing Providing the REMLogics platform and related services as described in the Agreement, including property management, lease administration, work order management, tenant billing, and related operational functions
Duration of Processing Until the termination of the Services under the Agreement or as otherwise required or permitted by law

Annex 2: Subprocessor List

Subprocessor Processing Activity Location
Microsoft Azure Cloud infrastructure and hosting Central US
App Service (API) Tenant, lease, and financial data on every API request Central US
App Service (Web) Renders tenant portal, applicant portal, lease/billing views Central US
SQL Database Leases, tenant ledgers, rent roll, billing, GL Central US
SQL Server Hosts all SQL Database instances above Central US
Container App Lease documents during PDF generation/processing Central US
Document Intelligence OCR/parsing of uploaded lease or tenant documents Central US
Azure OpenAI Tenant/lease context passed as prompts to the AI Assistant Central US
Storage Account Uploaded documents, function app data, file shares tied to tenant records Central US
Application Insights Request/exception telemetry; may capture PII if not scrubbed Central US
Log Analytics Workspace Aggregates telemetry from Application Insights and platform logs Central US
Key Vault Secrets, keys, certificates only Central US
Managed Identity Authentication only Central US
Container Registry Container images only Central US
Container Apps Environment Compute environment only Central US
Virtual Network / VPN Gateway Network transport only Central US
Private Endpoint / Private DNS Network routing only Central US
Public IP Address Network addressing only Central US
App Service Plan Compute/hosting tier only Central US
Action Group / Alert Rule Alert configuration/routing only Central US
Azure Load Testing Synthetic test traffic only Central US
Azure Workbook Dashboard configuration only Central US
Proptech OS AB Asset Data EU

Version History

Version Effective Date Summary of Changes
1.0 7/23/26 Initial publication