In plain language
Landlord acts as your Data Processor under GDPR Article 28. We are a US entity, so EU/UK → US transfers are covered by the 2021 Standard Contractual Clauses, Module 2, embedded in this DPA. We retain conversation content only for the limited periods set out in Annex IIA, and never use it to train models for anyone but you. Sub-processors (listed below) handle voice, LLM inference, payments, and messaging under their own published DPAs, each explicitly incorporated into our commercial terms with them.
How customers accept this DPA.
Customers based in the European Economic Area, the United Kingdom, or Switzerland are presented with this DPA inside the Landlord app at first login. They must scroll through it and tick the acceptance checkbox to proceed. Landlord records each acceptance with timestamp, the accepting user’s email, the entity name, the IP address, the user agent, and a SHA-256 hash of the exact DPA text that was accepted. This satisfies GDPR Article 28(9), which requires the DPA to be “in writing, including in electronic form.” Every version of this DPA, including the exact text a customer accepted, stays published at uselandlord.com/dpa.
This Data Processing Agreement (DPA) is entered into between The Customer identified in the Order Form or signup record (the Controller) and DeepRent LLC, a Delaware limited liability company, DBA Landlord, having its registered office at 1207 Delaware Ave #3446, Wilmington, DE 19806, United States (the Processor). Each a Party and together the Parties.
This DPA forms part of, and is incorporated by reference into, the Commercial Terms or Master Subscription Agreement between the Parties (the Principal Agreement). By accepting the Principal Agreement, the Controller accepts this DPA. The Processor accepts this DPA by making the Service available to the Controller.
1. Background and purpose
1.1 In the course of providing the Landlord AI Sales Employee service (the Service), the Processor will Process Personal Data on behalf of the Controller. This DPA sets out the Parties’ rights and obligations under Article 28 of Regulation (EU) 2016/679 (GDPR), and, where applicable, the UK GDPR and the Data Protection Act 2018, and the relevant national implementing law of the Controller’s jurisdiction.
1.2 The European Commission’s 2021 Standard Contractual Clauses for the transfer of personal data to third countries, Module 2 (Controller to Processor) (SCCs), are incorporated into this DPA by reference and govern the transfer of Personal Data from the Controller in the EEA, the United Kingdom, or Switzerland to the Processor in the United States. Where the Controller is established in the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs applies. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
2. Definitions
Terms not defined in this DPA have the meaning given to them in the GDPR. Personal Data, Processing, Data Subject, Sub-processor, Supervisory Authority, and Personal Data Breach have the meanings in Articles 4 and 33 GDPR.
3. Scope and instructions
3.1 The Processor will Process Personal Data only on the documented instructions of the Controller, including with regard to transfers to a third country, unless required to do so by Union, Member State, or UK law.
3.2 The Controller’s initial instructions are set out in Annex I (Description of Processing) and the Principal Agreement. The Controller may issue further instructions in writing (including by email or through the Service’s administrative interface) during the term.
3.3 The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.
4. Subject matter, duration, nature and purpose, categories of data and Data Subjects
These are described in Annex I (Description of Processing).
5. Confidentiality
The Processor ensures that persons authorised to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives termination of the Principal Agreement.
6. Security
The Processor implements and maintains the technical and organisational measures described in Annex II (Technical and Organisational Measures) to ensure a level of security appropriate to the risk, pursuant to Article 32 GDPR.
6A. Use of Personal Data for model training
6A.1 Except as permitted by clause 6A.2, the Processor does not use Personal Data for: (a) training, fine-tuning, pre-training, reinforcement learning or any other development of any AI or machine learning model; (b) benchmarking, evaluation, testing, quality scoring or red-teaming of any model or service; or (c) human review, annotation, labelling or listening by any person other than Processor personnel bound by confidentiality and acting to deliver, support or secure the Service.
6A.2 Training the Controller’s own AI — part of the Service. As part of providing the Service, the Processor uses Personal Data, including call audio, call transcripts and the content of messages and emails handled by the AI employee, to train, fine-tune, adapt, test and evaluate the AI employee and any AI model operated for the Controller. The Controller’s acceptance of this DPA is its documented instruction under clause 3 to do so, and to that extent, and to that extent only, it displaces clause 6A.1(a), 6A.1(b) and, for the review described in clause 6A.2(d), clause 6A.1(c). It is subject to each of the following:
- (a) the resulting model, and every training dataset, weight, adapter, embedding and other derived artefact, is dedicated to the Controller alone, held logically separated from other customers’ data, and used only to deliver the Service to the Controller;
- (b) nothing derived from the Personal Data is used to train, tune, evaluate or improve any model, product or service made available to the Processor’s other customers or to anyone else;
- (c) where the training is carried out with a sub-processor, the Processor engages that sub-processor on terms under which the data is used solely to produce the Controller’s dedicated model, is not used to train, tune, evaluate or improve that sub-processor’s own models or services, and is not subject to that sub-processor’s human review;
- (d) any human review, correction, transcription or labelling of Personal Data for the purposes of that training is carried out only by Processor personnel bound by confidentiality or by the Controller’s own personnel;
- (e) the Controller confirms that it has a lawful basis for the training, that its privacy information tells data subjects that call and message content may be used to train and improve the Controller’s AI, and that any notice or consent required for the recording and for that further use has been given or obtained; and
- (f) Personal Data retained as training data is held for the period stated in Annex IIA, and on termination that training data and any model trained on it are deleted or returned under clause 11.
7. Sub-processors
7.1 The Controller grants the Processor a general authorisation to engage the Sub-processors listed in Annex III (Sub-processors) as updated from time to time at https://uselandlord.com/dpa.
7.2 The Processor will inform the Controller of any intended addition or replacement of Sub-processors at least 30 days in advance, giving the Controller the opportunity to object. If the Controller objects on reasonable data-protection grounds, the Parties will discuss in good faith; if no resolution is reached, the Controller may terminate the Principal Agreement without penalty pro rata to the unused term.
7.3 Each Sub-processor’s own Data Processing Agreement is explicitly incorporated into the commercial terms between the Processor and that Sub-processor, and includes the SCCs where applicable. Links to each Sub-processor’s DPA are provided in Annex III.
7.4 The Processor imposes on each Sub-processor data-protection obligations no less protective than those in this DPA.
8. Assistance with Data Subject rights
The Processor will, taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to requests for exercising Data Subject rights under Chapter III GDPR.
9. Assistance with Controller obligations
The Processor will assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of the Processing and the information available to the Processor.
10. Personal Data Breach notification
The Processor will notify the Controller without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach. The notification will contain the information required by Article 33(3) GDPR to the extent then known, with updates as further information becomes available.
11. Deletion or return of Personal Data
At the choice of the Controller, the Processor will delete or return all the Personal Data to the Controller after the end of the provision of services relating to Processing, and delete existing copies, unless Union, Member State, or UK law requires storage of the Personal Data.
12. Audit
12.1 The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.
12.2 The Processor will allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, on reasonable prior notice (at least 30 days), no more than once per year (except where required by a Supervisory Authority or following a Personal Data Breach), at the Controller’s cost, subject to reasonable confidentiality safeguards.
12.3 The Processor may satisfy the audit obligation by providing relevant third-party certifications when available.
13. International transfers - SCCs
13.1 The Parties incorporate the 2021 SCCs Module 2 (Controller to Processor) into this DPA. The Controller is the data exporter; the Processor is the data importer.
13.2 The following optional SCC choices apply:
- Docking clause (Clause 7): applicable.
- Sub-processor authorisation (Clause 9): Option 2 (general written authorisation), 30 days’ notice.
- Redress (Clause 11): independent dispute-resolution body option not selected.
- Governing law (Clause 17): the law of the EU Member State of the Controller’s establishment, or, where the Controller is established outside the EU, the law of Ireland.
- Forum (Clause 18): the courts of the same jurisdiction.
- Annex I, II, III of the SCCs: as set out in this DPA’s Annexes I, II, IIA and III.
- Supervisory authority (Annex I.C): the Supervisory Authority of the Controller’s establishment.
13.3 Where the Controller is established in the United Kingdom, the UK International Data Transfer Addendum (issued by the ICO under section 119A of the Data Protection Act 2018) is incorporated by reference and supplements the SCCs.
13.4 The Parties acknowledge the Transfer Impact Assessment summary at Annex IV.
14. Acceptance and form
14.1 In accordance with Article 28(9) GDPR, this DPA is in writing in electronic form.
14.2 Controllers established in the European Economic Area, the United Kingdom, or Switzerland accept this DPA inside the Landlord application at first login. The Processor records each acceptance with timestamp, accepting user, entity name, IP address, user agent, and a SHA-256 hash of the exact DPA text accepted. The Controller can retrieve the exact text it accepted, and any version it has previously accepted, at any time from uselandlord.com/dpa.
15. Term and termination
This DPA enters into force on the date the Controller accepts the Principal Agreement and continues until the Principal Agreement is terminated, except for clauses which by their nature survive (confidentiality, deletion, audit for the relevant retention period).
16. Governing law and disputes
16.1 This DPA is governed by the laws of the State of Delaware, USA, save that the incorporated Standard Contractual Clauses and the UK International Data Transfer Addendum are governed as those instruments provide under clause 13, and nothing in this clause deprives a data subject of any right or remedy under applicable data protection law, including the right to bring proceedings in their country of habitual residence.
16.2 Except as provided in clause 16.3, any dispute, claim or controversy arising out of or relating to this DPA, or to its breach, termination, enforcement, interpretation or validity, is finally and exclusively resolved by binding arbitration and not in court. The arbitration is administered by the American Arbitration Association under its Commercial Arbitration Rules (or, where the dispute is international, its International Arbitration Rules), before a single arbitrator, seated in Wilmington, Delaware, USA, and conducted in English. The award is final and binding and judgment on it may be entered in any court of competent jurisdiction. Each Party waives any right to a trial by jury and, to the fullest extent permitted by law, any right to bring or take part in a class, collective, consolidated or representative action, and the arbitrator may not consolidate the claims of more than one party. The existence, content and outcome of any arbitration are confidential, except as required by law or to enforce or challenge the award. Each Party bears its own legal costs; the fees of the arbitrator and the administering institution are shared equally, subject to the arbitrator’s power to reallocate them in the award.
16.3 Either Party may apply to a court of competent jurisdiction for interim or permanent injunctive or other equitable relief to prevent or restrain an actual or threatened breach of the confidentiality or intellectual property provisions of this DPA. Doing so is not a waiver of clause 16.2.
17. Liability
Liability under this DPA is governed by the limitation-of-liability provisions of the Principal Agreement.
18. Order of precedence
In the event of conflict: (1) the SCCs prevail over this DPA in relation to international transfers; (2) this DPA prevails over the Principal Agreement on data-protection matters.
19. Updates to this DPA
The Processor may update this DPA from time to time. Material changes will be notified to active Controllers through the Landlord application, and by email to the account’s administrative contact, within 30 days of taking effect. Continued use of the Service after that notice constitutes acceptance of the updated DPA. A Controller that does not accept a material change may terminate the Principal Agreement without penalty, pro rata to the unused term, by written notice within 30 days of receiving the notice of change. Every version of this DPA, including each version a Controller has previously accepted, remains available at uselandlord.com/dpa.
Annex I - Description of Processing (and SCC Annex I)
A. List of Parties
- Data exporter (Controller): the legal entity identified in the Order Form or signup record.
- Data importer (Processor): DeepRent LLC, USA. Contact: Hunter Webb, support@uselandlord.com.
B. Description of transfer
| Categories of Data Subjects | Prospective and existing customers of the Controller; individuals contacting the Controller via phone, WhatsApp, SMS, iMessage, or email |
|---|---|
| Categories of Personal Data | Name; phone number; email address; content of inbound communications; unit-rental inquiry data (size, location, dates); transactional payment-link metadata (not card data) |
| Special-category data | None |
| Frequency of transfer | Continuous (real-time per interaction) |
| Nature of processing | Receiving inbound communications; generating responses via LLM; booking units; sending payment links; following up on stale leads; writing back to Controller’s PMS/CRM; training and evaluating the AI employee and models operated for the Controller (clause 6A) |
| Purpose | Provision of the Landlord AI Sales Employee service to the Controller, including training and evaluating the AI employee and models operated for the Controller under clause 6A. No other purpose is authorised. |
| Retention | As set out in Annex IIA (Retention periods) |
| Transfers to (sub-)processors | See Annex III |
C. Competent Supervisory Authority
The Supervisory Authority of the Controller’s place of establishment (for example, Datatilsynet for Norway, the Information Commissioner’s Office for the United Kingdom, the CNIL for France, the Data Protection Commission for Ireland).
Annex II - Technical and Organisational Measures (and SCC Annex II)
The Processor implements the following measures:
- Encryption in transit - TLS 1.2+ on all API endpoints and channel integrations.
- Encryption at rest - AES-256 on all Personal Data held at rest in managed cloud datastores, including conversation content, call recordings and operational metadata.
- Access control - Role-based access control; least privilege; MFA mandatory on all administrative and engineering accounts.
- Personnel security - All employees and contractors bound by written confidentiality obligations; background checks where local law permits.
- Time-limited conversation storage - conversation content is retained only for the periods in Annex IIA and deleted automatically on expiry; the agent otherwise retrieves data from authorised Controller systems on demand.
- Sub-processor due diligence - Sub-processors must publish a GDPR-compliant DPA and offer the 2021 SCCs.
- Logging and monitoring - Application and access logs retained for incident investigation only.
- Backup - Encrypted, on a rolling 35-day cycle, restored only for disaster recovery.
- Incident response - Documented procedure; 48-hour Controller notification on confirmed Personal Data Breach.
- Vulnerability management - Patching of managed services per vendor cadence; dependency scanning on application code.
- Business continuity - Multi-region failover for production sub-processors where available.
- Physical security - All Processor infrastructure is hosted on managed cloud (Sub-processors); no Processor-operated data centres.
Annex IIA - Retention periods
Periods are maximums and run from creation of the record unless stated otherwise. Deletion happens in the ordinary course on expiry, without the Controller having to request it.
| Category | Retention |
|---|---|
| Prompts, model outputs and conversation transcripts (chat, email, SMS, WhatsApp) | 90 days |
| Call audio recordings | 30 days |
| Call transcripts | 90 days |
| Derived embeddings, indexes and caches | Deleted with the source record, and within 30 days at the latest |
| Controller knowledge base, configuration and operational records | For the term of the Principal Agreement, then 30 days |
| System, access, security and audit logs | 365 days |
| Abuse and safety monitoring data held by a model provider | 30 days, automated review only |
| Personal Data retained as training data, and any model trained on it, under clause 6A | For the term of the Principal Agreement, then 30 days |
| Encrypted backups (rolling cycle) | 35 days |
| Account and billing records held by Landlord as controller | 7 years, as required by law |
Where a model provider offers a zero-retention option, Landlord uses it, and the prompt and output retention above is then held only by Landlord and not by the model provider.
Annex III - Sub-processors (and SCC Annex III)
Each Sub-processor’s own Data Processing Agreement is explicitly incorporated into the commercial terms between Landlord and that Sub-processor, and includes the 2021 SCCs where the Sub-processor is established outside the EEA. The list below is current as of the Effective Date and is updated at https://uselandlord.com/dpa. Additions or replacements are notified at least 30 days in advance.
| # | Sub-processor | Entity & location | Service | Provider DPA / SCCs |
|---|---|---|---|---|
| 1 | Anthropic, PBC | San Francisco, USA | LLM inference (Claude API) - agent reasoning, email and chat generation | privacy.claude.com DPA auto-incorporated into commercial terms; SCCs Module 2 included; no model training on inputs by default; zero-retention available. |
| 2 | OpenAI, L.L.C. (when their models are used) | San Francisco, USA | LLM inference (OpenAI API) - agent reasoning, email and chat generation | openai.com/policies/data-processing-addendum SCCs Module 2 included; no training on API inputs by default; zero data retention available. |
| 3 | Google LLC (when their models are used) | Mountain View, USA | LLM inference (Gemini API) - agent reasoning, email and chat generation | cloud.google.com/terms/data-processing-addendum Cloud DPA with SCCs Module 2 included; customer data not used to train models. |
| 4 | ElevenLabs Inc. | Delaware, USA | Voice synthesis and telephony agent | elevenlabs.io/dpa |
| 5 | Stripe Payments Europe Ltd. | Dublin, Ireland | Payment links | stripe.com/legal/dpa |
| 6 | Twilio Ireland Ltd. (when SMS is used) | Dublin, Ireland | SMS routing | twilio.com/legal/data-protection-addendum |
| 7 | Meta Platforms Ireland Ltd. | Dublin, Ireland | WhatsApp Business API transport | facebook.com/legal/terms/dataprocessingterms |
| 8 | Amazon Web Services EMEA SARL (eu-west-1) | Luxembourg | Hosting of operational metadata | aws.amazon.com/compliance/gdpr-center/ |
| 9 | Supabase, Inc. | San Francisco, USA (data hosted in AWS us-east-1, United States) | Primary application database and file storage - the system of record for conversation transcripts, call recordings, Controller configuration and operational records | supabase.com/legal/dpa DPA incorporating the 2021 SCCs |
Sub-processor change log
- 9 September 2026 - v1.1 published - added clause 6A (training of the Controller's own AI as part of the Service), clause 16 (governing law and arbitration) and Annex IIA (retention periods); former clauses 16-18 (Liability, Order of precedence, Updates) are now 17-19. Supabase (row 9) added to Annex III: already in use as the system of record, so this corrects the disclosure rather than engaging a new sub-processor. AWS (row 8) widened to describe the infrastructure it actually provides. No sub-processor removed or replaced.
Annex IV - Transfer Impact Assessment summary
- Transfer route: EEA / UK / Switzerland → United States (Delaware).
- Mechanism: 2021 SCCs Module 2 (and, for UK exporters, the UK International Data Transfer Addendum).
- Nature of data: contact and inquiry data of self-storage prospects, and the content of their calls and messages for the periods in Annex IIA; no special-category data; no children’s data; no public-figure or activist exposure.
- US surveillance risk under FISA 702 / EO 12333: The Processor is not an “electronic communications service provider” within the meaning of 50 U.S.C. § 1881(b)(4) for the purposes of bulk collection. No requests under FISA 702 or National Security Letters received to date.
Supplementary measures:
- End-to-end TLS on all transport.
- Short, fixed retention periods for conversation content (data-minimisation by retention, see Annex IIA).
- Training data and models under clause 6A are dedicated to the Controller, logically separated from other customers’ data, and held only for the term of the Principal Agreement (clause 6A.2(a), Annex IIA).
- Sub-processor short-retention and zero-retention configurations where supported.
- Contractual obligations under SCC Clauses 14 and 15 (challenge government access; transparency).
Conclusion: The Parties conclude that the transfer offers a level of protection essentially equivalent to that guaranteed by the GDPR.
How customers accept this DPA.
Customers based in the European Economic Area, the United Kingdom, or Switzerland are presented with this DPA inside the Landlord app at first login. They must scroll through it and tick the acceptance checkbox to proceed. Landlord records each acceptance with timestamp, the accepting user’s email, the entity name, the IP address, the user agent, and a SHA-256 hash of the exact DPA text that was accepted. This satisfies GDPR Article 28(9), which requires the DPA to be “in writing, including in electronic form.” Every version of this DPA, including the exact text a customer accepted, stays published at uselandlord.com/dpa.
