Data Processing Addendum
Last updated: July 6, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Atrium Elite ("Atrium Elite," "we," "us") and the customer ("Customer," "you") and applies to our processing of Personal Data on your behalf in connection with the Service. If there is a conflict between this DPA and the Agreement, this DPA controls as to the subject matter of data protection. Capitalized terms not defined here have the meaning in the Agreement.
Draft — pending legal review. This DPA is a good-faith draft; final terms (including the Standard Contractual Clauses and any region-specific annexes) will be confirmed by counsel. Business customers who need a signed DPA should contact privacy@atriumelite.com.
1. Roles and scope
For Personal Data contained in Customer Data, you are the controller (or processor acting for a third-party controller) and we are the processor (or sub-processor). We process such Personal Data only to provide, secure, and support the Service and only on your documented instructions (including the Agreement and your use of the Service), unless legally required otherwise (in which case we will inform you where permitted).
2. Definitions
"Personal Data," "processing," "controller," "processor," "data subject," and "personal data breach" have the meanings given under applicable data-protection law (including the GDPR/UK GDPR and the CCPA/CPRA). "Customer Data" has the meaning in the Agreement.
3. Details of processing
- Subject matter & duration: processing of Customer Data for the term of the Agreement plus the retrieval/deletion periods in Section 9.
- Nature & purpose: hosting, storage, computation, transmission, and display of Customer Data to operate the property-operations, accounting, and investor- administration features of the Service.
- Categories of data subjects: your personnel and authorized users, and the tenants, owners, investors, guarantors, and vendors whose information you enter.
- Categories of Personal Data: contact and identity details, financial and transaction records, lease and tenancy information, and account/usage data. You will not enter special-category data except as necessary and lawful.
4. Our obligations
We will: (a) process Personal Data only on your instructions; (b) ensure personnel authorized to process it are bound by confidentiality; (c) implement appropriate technical and organizational measures (Section 6); (d) assist you, taking into account the nature of processing, with data-subject requests (Section 7), security, breach notification, and data-protection impact assessments; and (e) make available information reasonably necessary to demonstrate compliance (Section 10).
5. Sub-processors
You authorize us to engage sub-processors to provide the Service. Our current sub-processors are Amazon Web Services (cloud hosting, database, authentication, email, and document storage) and Stripe (payment processing); a current list is available on request and on our Subprocessors page. We impose data-protection obligations on sub-processors no less protective than this DPA and remain responsible for their performance. We will give you reasonable notice of a new or replacement sub-processor and a chance to object on reasonable data-protection grounds.
6. Security
We maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access — including encryption in transit and at rest, access controls and least-privilege, tenant isolation, audit logging, an immutable financial ledger, and continuous integrity checks. A summary is on our Security Overview page. We may update these measures provided the level of protection is not materially reduced.
7. Data-subject requests
Taking into account the nature of processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to data- subject requests. Because you control Customer Data, you can access, correct, export, or delete it through the Service; where a data subject contacts us directly, we will refer the request to you.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your Personal Data, and provide information reasonably available to help you meet your notification obligations.
9. Return and deletion
On termination, and as described in the Agreement, you may retrieve a complete, machine-readable export of your Customer Data for at least ninety (90) days. After the retrieval period we will delete or destroy our copies of Personal Data — and certify destruction on request — subject to backups and any legal retention requirements, after which residual copies are deleted in the ordinary course.
10. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable prior notice, during business hours, subject to confidentiality, and no more than once per year unless required by a supervisory authority or following a breach. Third-party attestations or reports (where available) may be provided to satisfy audit requests.
11. International transfers
Where processing involves a transfer of Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism, including the applicable Standard Contractual Clauses (and the UK Addendum / Swiss amendments as relevant), which are incorporated by reference and will be completed and attached by the parties. [SCCs and region-specific annexes to be attached on counsel review.]
12. Aggregated and de-identified data
Notwithstanding anything to the contrary, we may create aggregated and de-identified data derived from Customer Data and from use of the Service — data that no longer identifies, and cannot reasonably be used to re-identify, you, your users, or any data subject. Such data is not Personal Data or Customer Data, and our use of it falls outside the processor relationship. We may use aggregated and de-identified data for any lawful business purpose, including to operate, secure, improve, and develop the Service and our analytical and machine-learning models and to produce anonymized, statistical benchmarks and market insights. We will not disclose Customer Data to other customers; any benchmark or insight is presented only in aggregated, anonymized form, computed across a minimum number of contributors, that does not reveal your non-public information or single you out; and we do not use such data to set, recommend, or coordinate rents or other prices among customers. You may opt out of the use of your data to produce cross-customer benchmarks at any time through your account settings or by contacting privacy@atriumelite.com, without affecting your use of the Service. This Section mirrors the "Aggregated and De-Identified Data" provision of the Terms of Service.
13. CCPA/CPRA
When we process Personal Data governed by the CCPA/CPRA on your behalf, we act as a service provider. We do not sell or share (as those terms are defined in the CCPA/CPRA) Personal Data, do not retain, use, or disclose it except as necessary to provide the Service or as permitted by the CCPA/CPRA, and do not combine it with data from other sources except as permitted for a service provider.
14. General
This DPA is governed by the law of the Agreement ([State/Country]). Each party's liability under this DPA is subject to the limitations of liability in the Agreement. Except as amended here, the Agreement remains in full force.
15. Contact
Data-protection questions or to request a signed DPA: privacy@atriumelite.com.