Data Processing Agreement

Data Processing Agreement

Version 1.0, 4 September 2026. Our Terms of Use and Privacy Policy both say that where we process personal data on your behalf, “our data processing terms govern that processing”. These are those terms.

They apply automatically to every customer, with no need to sign anything, from the moment you put personal data into the Platform. Most vendors make you request a DPA and then negotiate it. We publish ours and it is already in force, because a protection you have to ask for is one most customers never get. If your legal team needs a countersigned copy on your paper, ask through our contact page and we will sign.

This agreement forms part of the Terms of Use. Where it conflicts with the Terms, this agreement controls for the processing of personal data.

1. Who is who

You are the controller. We are the processor. You decide what personal data goes into the Platform and why. We hold it and act on it only as you instruct. BrokerDIY LLC is the processor; the entity that holds the account is the controller.

This does not cover information we decide about for our own purposes — your account and billing records, website visitors, and marketing contacts. For those we are the controller and the Privacy Policy governs, not this agreement.

“Personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” carry the meanings given in the GDPR. “Data protection law” means the EU GDPR, the UK GDPR and Data Protection Act 2018, and the US state privacy laws listed in section 11, each as they apply to you.

2. What we are processing, and for how long

Subject matterProviding the BrokerDIY platform to you under the Terms of Use.
DurationFor as long as your account is active, plus the 30-day window in section 8.
Nature and purposeHosting, storing, transmitting, displaying, indexing, backing up and processing your data so the Platform works; sending the calls, texts, emails and documents you instruct it to send; generating AI output you ask for; supporting and securing the service.
Types of personal dataNames, postal and email addresses, telephone numbers, transaction and property details, document contents and signatures, communications content and metadata, call audio and transcripts where a feature records them, and any other personal data you choose to put into the Platform.
Categories of data subjectYour agents and staff; your clients — buyers, sellers, landlords and tenants; co-operating agents, and other parties to a transaction such as lenders, closing attorneys and inspectors.
Special category dataNot requested and not required by the Platform. If you choose to upload it, you are responsible for having a lawful basis and a condition for doing so.

3. What we will and will not do with it

  • We process personal data only on your documented instructions. Your instructions are the Terms of Use, this agreement, and your use of the Platform’s features. If we are required by law to process it otherwise, we will tell you first unless the law forbids that.
  • We will tell you if, in our opinion, an instruction you give us infringes data protection law.
  • We do not sell it. We do not share it for cross-context behavioural advertising, and we do not use it for our own purposes.
  • We do not combine it with personal data we receive from anyone else, or collect ourselves, except as permitted for a business purpose you have engaged us for.
  • We do not use one customer’s personal data to train systems that serve another customer, and our AI providers are contractually barred from training their general models on it.
  • Everyone we let near it is bound by confidentiality obligations that survive their engagement.
  • The only thing we derive and keep for ourselves is Aggregate Data as defined in section 8 of the Terms — statistics carrying no names, addresses, document contents or client information, unattributed and non-reversible. That is not personal data, and we do not attempt to re-identify it.

4. Security

We maintain technical and organisational measures appropriate to the risk, including:

  • Encryption of personal data in transit and at rest.
  • Logical isolation of each customer’s data by tenant, enforced in the application rather than by convention.
  • Role-based access control, with staff access limited to what a task requires, granted by you for support, logged, and revoked when the work is done.
  • Hash-chained integrity records on executed documents, so tampering is detectable without relying on us.
  • Patching, backup, and restoration testing; backups roll off within 35 days.
  • Logging of administrative actions, retained for up to 24 months.

We may change these measures as technology moves, but not in a way that materially reduces the protection.

5. Sub-processors

You give us general authorisation to engage sub-processors. The current list is published at brokerdiy.com/sub-processors and is incorporated into this agreement.

  • We update that page before a new sub-processor starts processing, and we give you 30 days’ notice by email of an addition or replacement.
  • You may object on reasonable data-protection grounds within those 30 days. We will work with you to find an alternative; if we cannot, you may cancel the affected part of the service and we will refund fees paid for the period after cancellation.
  • Each sub-processor is bound by written terms no less protective than these, and we remain fully liable to you for their performance.
  • Where a sub-processor must be added immediately to keep the service running or secure, we may do so and will tell you as soon as we have.

6. Helping you meet your own obligations

  • Data subject requests. The Platform’s own export, correction and deletion tools are the fastest route, and you can run them yourself. Where a request needs us, we will assist you, and we will not respond to a data subject directly about your data except to tell them to contact you.
  • Impact assessments. We will give you the information you reasonably need for a DPIA or a prior consultation with a regulator, to the extent only we hold it.
  • Personal data breach. If we become aware of a breach affecting your personal data we will tell you without undue delay, with what we know about its nature, the categories and approximate numbers affected, the likely consequences and the measures taken. We will keep you updated as we learn more, and we will not delay the first notice in order to make it complete.

7. Audit

We will make available the information needed to show we are meeting this agreement. You may audit us, or appoint an independent auditor who is not our competitor, once in any twelve months on 30 days’ written notice, during business hours, without unreasonably disrupting the service, and subject to confidentiality. Where we hold a current third-party report or certification that answers your question, we will provide that instead and you agree it satisfies the request. You bear your own audit costs; we bear ours. A regulator’s lawful demand is not limited by this section.

8. Return and deletion

When your account ends, the published retention policy at Your data and leaving BrokerDIY applies and forms part of this agreement: we hold everything intact for 30 days, we package and send it to you on request at no charge during that window, we email you seven days and one day before deletion, and then we delete it. Backups roll off within a further 35 days.

We keep personal data past that point only where a law requires it, and only for as long as that law requires, and it stays subject to this agreement while we hold it. We will certify deletion in writing on request.

9. International transfers

We are established in the United States and our sub-processors are principally in the United States, so personal data will be transferred there.

Where you transfer personal data subject to the EU GDPR to us, the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two, controller to processor, are incorporated into this agreement and apply. Clause 7 (docking) applies; the optional Clause 9(a) wording is Option 2, general written authorisation, with the 30-day notice period in section 5; the Clause 11 independent-dispute option does not apply; the governing law under Clause 17 is the law of Ireland; and the forum under Clause 18 is the courts of Ireland. Annex I is section 2 and section 5 of this agreement, Annex II is section 4, and Annex III is the published sub-processor list.

Where the UK GDPR applies, the UK International Data Transfer Addendum (version B1.0) is incorporated, with the tables completed by the equivalent sections of this agreement, and the Addendum’s Part 2 Mandatory Clauses apply. For Switzerland, references to the GDPR are read as references to the Swiss FADP and the supervisory authority is the FDPIC.

If a transfer mechanism we rely on is invalidated, we will adopt a lawful alternative without undue delay, and until we do we will suspend the affected transfer rather than continue it.

10. Government and law-enforcement requests

If we receive a demand for your personal data we will tell you before we disclose anything, so you can seek to challenge it, unless we are legally prohibited from telling you. Where we are prohibited, we will use reasonable efforts to have the prohibition lifted and to tell you as much as we lawfully can, as soon as we lawfully can. We disclose only the narrowest set of data the demand actually requires, and we challenge demands that appear unlawful or overbroad.

11. United States state privacy law

Where the California Consumer Privacy Act applies, we are a service provider and you are a business. Personal information is disclosed to us only for the limited and specified business purposes in section 2, and we are prohibited from, and will not:

  • sell or share it;
  • retain, use or disclose it for any purpose other than performing the services, including for a commercial purpose of our own;
  • retain, use or disclose it outside our direct business relationship with you; or
  • combine it with personal information from another source, except as the CCPA permits a service provider to do.

We understand and will comply with these restrictions, and we will tell you if we determine we can no longer meet them. You may take reasonable and appropriate steps to stop and remediate unauthorised use. Where Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida or a comparable state law applies, we act as a processor on the same terms, and this section is read to give effect to the equivalent requirements.

12. Your side of it

You are responsible for having a lawful basis for the personal data you put into the Platform, for giving the notices and holding the consents your clients and contacts are entitled to, for the accuracy of what you upload, and for the lawfulness of the calls, texts and emails you instruct the Platform to send — which is dealt with more fully in section 4 of the Terms. You confirm your instructions to us are lawful.

13. Liability, changes and term

Liability under this agreement is subject to the limitations in section 17 of the Terms of Use, except where data protection law does not permit that. Nothing here limits a data subject’s rights against either of us under the Standard Contractual Clauses.

This agreement starts when you first give us personal data and lasts until we have deleted it under section 8. Sections 3, 6, 8, 9, 10 and 11 survive its end for as long as we hold any of your personal data. We may update it to reflect a change in law or in our sub-processors; if a change materially reduces your protection we will tell you first, and you may cancel the affected service if you do not accept it.