Data Processing Agreement

Last Updated: September 8, 2026
Effective Date: August 3, 2026

1. Introduction and Roles

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Abodient Terms of Service between Abodient Ltd ("Abodient", "we", "us") and the customer ("you", the "Customer"). It governs our processing of personal data on your behalf and sets out the commitments required by Article 28 of the UK GDPR and EU GDPR.

This DPA applies whenever you use Abodient to process personal data relating to other individuals — in particular your tenants and professional contacts (contractors, service providers). In respect of that data:

  • You are the data Controller — you decide why and how the data is used.
  • Abodient is the data Processor — we process it on your documented instructions to provide the service.

Separately, Abodient acts as Controller of your own account data; that processing is governed by our Privacy Policy, not this DPA. If there is any conflict between this DPA and the Terms of Service on data protection matters, this DPA prevails.

2. Scope of Processing

The subject matter, nature, purpose, duration, data types, and data subjects are set out in Annex A. In summary, we process the personal data only to provide the Abodient property-management platform and its features (AI assistance, maintenance coordination, document analysis, professional outreach, notifications) and for no other purpose.

This includes keeping the platform secure and diagnosing and correcting faults in the service we provide to you, which are part of providing it. It does not include developing our product from your tenants' personal data: where we want to learn from usage more generally, we work from anonymised or aggregated data. If we ever determined our own purpose for identifiable personal data, we would be a controller for that processing and would say so, rather than treat it as covered by your instructions — a party that decides its own purpose is not a processor for it, whatever the paperwork says.

3. Your Responsibilities as Controller

As the Controller, you warrant and undertake that, for all personal data you provide to or process through Abodient (including your tenants' and professional contacts' data):

  • Lawful basis. You have a valid lawful basis under UK/EU GDPR to provide that data to us and to have us process it on your behalf for the purposes set out in this DPA.
  • Transparency. You have given (or will give) the relevant data subjects the privacy information required by Articles 13–14 of the UK/EU GDPR — including that their personal data may be processed by Abodient and our sub-processors as described here and in our Privacy Policy.
  • Right to share. You are entitled to share the data with us and are not prohibited from doing so by any agreement, duty, or law.
  • Instructions. Your provision and use of the data constitutes your lawful, documented instructions to us to process it as described in this DPA.

You remain responsible, as Controller, for your data subjects' rights requests; we assist as set out below.

4. Our Obligations as Processor

We commit to the following (UK GDPR / GDPR Article 28(3)):

  • Documented instructions. We process personal data only on your documented instructions — including the Terms, this DPA, and your configuration and use of the platform — unless required to do otherwise by law (in which case we will inform you first, unless legally prohibited).
  • Unlawful instructions. We will inform you promptly if, in our opinion, an instruction from you infringes UK or EU data protection law.
  • Records of processing. We maintain records of the processing we carry out on your behalf, in accordance with Article 30(2).
  • Confidentiality. Personnel authorised to process the data are bound by appropriate obligations of confidentiality.
  • Security. We implement and maintain appropriate technical and organisational measures to protect the data, as described in Annex B (Article 32).
  • Sub-processors. We engage the sub-processors listed in Annex C under the conditions in Section 5 below.
  • Assistance with data subject rights. Taking into account the nature of the processing, we assist you with appropriate measures to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). The platform's built-in export and deletion tools are provided for this purpose; for anything they do not cover, contact privacy@abodient.ai.
  • Assistance with compliance. We assist you, taking into account the information available to us, with your obligations on security (Art. 32), personal data breach notification (Arts. 33–34), and data protection impact assessments and prior consultation (Arts. 35–36).
  • Personal data breach. We notify you without undue delay after becoming aware of a personal data breach affecting your data, so that you can meet your own notification obligations. Our notice will contain, as a minimum and so far as it is available to us: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures we have taken or propose to take, including to mitigate any adverse effects; and a contact point for further information. Where we do not have all of it at the outset, we will send what we have rather than wait, and follow up as we learn more.
  • Deletion or return. On termination of the service, at your choice, we will return and then delete, or delete, all personal data processed on your behalf, and delete existing copies, within thirty days of your instruction — unless retention is required by law (in which case we retain only what is legally required, for only as long as required). Where you have not told us your choice, we will ask before deleting. The platform's self-service export tools are available to you throughout that period.
  • Automated decision-making. The assistant supports your decisions; it does not take significant decisions about your tenants. It reads, classifies and summarises messages, drafts communications, and arranges contractor attendance within the limits you configure. It does not decide anything with legal or similarly significant effects on a tenant — it does not serve notice, end a tenancy, determine rent, or assess anyone's suitability — and those actions require you. Where you enable a setting that lets messages go out without your prior approval, the spend limit on your account still applies and a quote above it is returned to you for approval. If a tenant asks for a person to look at something the assistant has done, contact us at privacy@abodient.ai and a person will.
  • Demonstrating compliance. We make available to you the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in Section 6.

5. Sub-processors

  • Authorisation. You provide general authorisation for us to engage the sub-processors listed in Annex C to support the service.
  • Flow-down. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible to you for each sub-processor's performance.
  • Changes. We may add or replace sub-processors. We will update Annex C and give you at least fourteen days' notice (by email and in-app) before a new or replacement sub-processor begins processing your personal data, so that you can object on reasonable data-protection grounds. Where a change is required urgently for security, legal or service-continuity reasons, we may make it immediately and will notify you promptly afterwards. If you reasonably object and we cannot provide a comparable alternative, you may terminate the affected service.

6. Audits

On reasonable written request (no more than once per year, except after a breach or where required by a regulator), we will provide information reasonably necessary to demonstrate compliance with this DPA — including, where available, third-party certifications or reports for our infrastructure providers. Where these are insufficient, we will cooperate with a reasonable, proportionate audit, subject to confidentiality and reasonable notice.

7. International Transfers

Personal data may be transferred to and processed outside the UK/EEA (including the United States) by us and our sub-processors. Where it is, we ensure an appropriate transfer mechanism is in place — such as a UK adequacy decision, the UK Addendum to the EU Standard Contractual Clauses, or equivalent safeguards. Sub-processor locations are noted in Annex C.

8. Liability, Term and Governing Law

This DPA is effective for as long as we process personal data on your behalf. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with the Terms of Service.

Insurance. We carry professional indemnity insurance of £1,000,000 and cyber and data insurance of £500,000, underwritten by Hiscox. A certificate of insurance is available to customers on request.

Annex A — Details of Processing

Subject matter: Provision of the Abodient property-management platform.

Duration: For the term of the Customer's use of the service, plus any legally required retention period.

Nature and purpose: Storing, organising, analysing, and transmitting personal data to deliver property-management features — AI-assisted tenant support, maintenance coordination, document analysis, professional outreach, scheduling, and notifications.

Categories of data subjects:

  • The Customer's tenants
  • The Customer's professional contacts (contractors, service providers)

Categories of personal data:

  • Identity and contact details (names, email addresses, phone numbers)
  • Property and tenancy details associated with individuals
  • Tenant issue reports, messages, and uploaded photos
  • Lease, inventory, and related document content
  • Communication history with tenants and professionals

Special category data: We do not ask for it, and the platform has no feature that requires it — but in property management it arrives whether it is invited or not. A tenant reporting an issue may volunteer health, disability, vulnerability or safeguarding information in a message or a photograph, and we would rather describe that honestly than ask you to pretend it does not happen.

How it is handled: such data is processed only as part of the tenant communication it arrives in, for the purpose of resolving that issue. It is covered by the same technical and organisational measures set out in Annex B, and by the same property-level isolation as all other tenant data — the assistant can only search documents and messages belonging to the property in the conversation it is handling. We do not apply a separate special-category classification, and we do not claim one: we would rather tell you what we actually operate.

What this means for you: as controller, you need an Article 9 condition for that processing, and depending on the Schedule 1 condition you rely on, an appropriate policy document under the Data Protection Act 2018. Helping you get that right is on our roadmap rather than in this document today.

Annex B — Security Measures

We maintain appropriate technical and organisational measures, including:

  • Encryption in transit (HTTPS/TLS) for all data exchanged with the platform and sub-processors; encryption at rest at the database and storage layer.
  • Access controls: authentication via Supabase (asymmetric JWT validation), with database-level Row-Level Security enforcing isolation between customers and role-based access (landlord, tenant, agent, admin).
  • Tenant/property data isolation, including scoping of document search to the relevant property.
  • Secrets management: credentials held in secured environment configuration, never in source code.
  • Monitoring: error tracking configured to exclude personal data by default, and application/infrastructure logging.
  • Backups of the primary datastore, securely stored and rotated.

We review and update these measures over time as the service and threat landscape evolve.

Annex C — Approved Sub-processors

Sub-processorPurposeRegionTransfer mechanism
SupabaseDatabase, authentication, file storageEU (Ireland)No restricted transfer (EU)
Microsoft Azure OpenAI ServiceAI processing (chat, vision, reasoning)US / configured regionUK Addendum to the EU SCCs
OpenAIDocument embeddings for semantic searchUSUK Addendum to the EU SCCs
AnthropicAI processing (document reading and classification)USUK Addendum to the EU SCCs
RenderBackend application hostingEU (Frankfurt)No restricted transfer (EU)
VercelFrontend application hostingUS / EUUK Addendum to the EU SCCs
Google (Gmail, Drive, Places)Professional email, document storage, contractor lookupUS / EUUK Addendum to the EU SCCs
Meta (WhatsApp)Tenant messaging where enabledUS / EUUK Addendum to the EU SCCs
PerplexityContractor searchUSUK Addendum to the EU SCCs
SentryError and crash monitoring (no PII)EU (Germany)No restricted transfer (EU)
LangSmithAI request logging and quality (logs content)USUK Addendum to the EU SCCs
Google Analytics 4Usage analytics across the platform, including tenant-facing pagesUSUK Addendum to the EU SCCs
PostHogProduct-usage analytics across the platform, including tenant-facing pagesEUNo restricted transfer (EU)
ResendTransactional email delivery (invitations, notices, updates)USUK Addendum to the EU SCCs
TwilioSMS and voice call delivery to professionalsUSUK Addendum to the EU SCCs
ElevenLabsAutomated voice calls to professionalsUSUK Addendum to the EU SCCs
StripeSubscription billing (no tenant data)US / EUUK Addendum to the EU SCCs
XeroAccounting sync where enabled (no tenant names)US / NZUK Addendum to the EU SCCs

Where a sub-processor is shown as "No restricted transfer", the data stays within the UK/EEA and no transfer mechanism is needed. Where the UK Addendum to the EU Standard Contractual Clauses is shown, we rely on the Addendum as incorporated in that supplier's data processing terms. Some of these suppliers additionally hold certification under the UK Extension to the EU–US Data Privacy Framework; where we rely on that instead, we verify the certification covers the relevant data category at onboarding and re-check it annually.

We have data processing terms in place with every sub-processor listed above. Our AI providers (Microsoft Azure OpenAI Service, OpenAI and Anthropic) do not use API content to train their models. They may retain content for a limited period (up to 30 days) solely for abuse and misuse monitoring, after which it is deleted; we do not currently hold a zero-retention exemption with either provider.

LangSmith is a separate case and we state it plainly: it logs the content of AI requests, including message and document text, in order to let us diagnose and improve the assistant's behaviour. Our LangSmith projects are configured on the short-lived trace tier, under which traces are retained for 14 days and then deleted. LangSmith processes this data in the United States.

Contact

For any questions about this DPA or to exercise data-protection rights on behalf of your data subjects:

Email: privacy@abodient.ai

Provider: Abodient Ltd, company no. 16783207 (registered in England and Wales)

Registered office: Flat 36 Kimpton Court, 2 Murrain Road, London, N4 2BN, United Kingdom

ICO registration: ZC037453

This DPA is designed to meet the requirements of Article 28 of the UK GDPR and EU GDPR as of June 2026. We recommend you have it reviewed by a legal professional before relying on it in a regulated engagement.