Data Processing Addendum
This Addendum forms part of the agreement between the property-management customer (“Controller”) and BoroDesk (“Processor”) for the Unified Resident & Board Portal. It governs Processor’s handling of resident personal information on Controller’s behalf. This is a customer-facing template for the demo build.
1. Roles
Controller determines the purposes and means of processing resident data. Processor processes that data only on Controller’s documented instructions, including as configured through the Portal.
2. Scope of processing
- Categories of data: resident contact and household details, ledger balances and payment references, service records (maintenance, amenities, packages, visitors), communications and consents, and — for boards — governance records.
- Data subjects: residents, owners, board members, and building staff.
- Purpose: operating the resident & board portal and its integrations.
3. Security measures (NY SHIELD reasonable safeguards)
- Encryption in transit (TLS) and at rest.
- Row-level security enforcing per-unit and per-org isolation in the database.
- Least-privilege, role-based access control.
- Immutable audit logging of sensitive actions (payments, votes, document access, permission changes, data exports).
- Breach-detection hooks and a documented incident-response path.
4. Sub-processors
Processor engages: Supabase (hosting, database, auth, storage), Stripe (payments; PCI-DSS), Anthropic (assistant model; no training on customer data), and email/SMS/push delivery providers. Processor maintains data-processing terms with each and remains responsible for their performance. Processor will give notice of new sub-processors.
5. Confidentiality & personnel
Personnel authorized to process data are bound by confidentiality and access only on a need-to-know basis.
6. Data subject requests
Processor provides Portal tooling for Controller to fulfill access, correction, export (CSV/JSON), and deletion requests, and will assist Controller in responding to resident requests, subject to legal retention.
7. Breach notification
Processor will notify Controller without undue delay after becoming aware of a personal-data breach affecting Controller’s data, with information reasonably needed for Controller to meet its obligations (including under NY GBL §899-aa/§899-bb).
8. Return & deletion
On termination, Processor will, at Controller’s choice, return or delete resident data, except where retention is required by law (e.g., governance/financial records).
9. Audits
Processor will make available information necessary to demonstrate compliance and will cooperate with reasonable audits, subject to confidentiality.
10. Contact
Data protection: dpo@borodesk.com.