Data Processing Agreement
Effective Date: September 7, 2026
Last Updated: September 7, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between AK COMPANY LLC, operator of KipoProp (“KipoProp,” “Processor,” “we,” “us,” or “our”), and the customer that uses the KipoProp Service (“Customer” or “Controller”).
This DPA applies where KipoProp processes Personal Data on behalf of Customer in connection with the KipoProp Service.
By agreeing to the KipoProp Terms of Service, or otherwise entering into an agreement governing use of KipoProp, Customer enters into and agrees to this DPA where applicable.
If Customer is itself processing Personal Data on behalf of another controller, Customer acts as a processor and KipoProp acts as Customer’s subprocessor for that processing.
This DPA is intended to address applicable requirements under privacy and data-protection laws, including where applicable the EU GDPR, UK GDPR, United States state privacy laws, and applicable Canadian privacy laws. It should be read together with our Privacy Policy and the Subprocessor List.
1. Definitions
“Applicable Data Protection Law” means privacy, data protection, and data security laws applicable to the processing of Customer Personal Data under this DPA.
“Customer Data” means data submitted to, stored in, transmitted through, or otherwise processed through KipoProp by or on behalf of Customer.
“Customer Personal Data” means Personal Data contained within Customer Data that KipoProp processes on behalf of Customer.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“Personal Data” includes personal data, personal information, or similar information protected by Applicable Data Protection Law.
“Processing” and “Process” have the meanings given under applicable data-protection law.
“Security Incident” means a confirmed unauthorized or unlawful access to, acquisition, alteration, disclosure, destruction, or loss of Customer Personal Data processed by KipoProp.
“Subprocessor” means a third party engaged by KipoProp to process Customer Personal Data on behalf of Customer.
2. Roles of the Parties
Customer determines the purposes and essential means of processing Customer Personal Data and generally acts as Controller or Business.
KipoProp processes Customer Personal Data on Customer’s behalf and generally acts as Processor, Service Provider, Contractor, or equivalent role under Applicable Data Protection Law.
Where Customer acts as a processor for another controller, KipoProp will act as Customer’s subprocessor.
Each party is responsible for complying with the legal obligations applicable to its own role.
3. Processing Instructions
KipoProp will process Customer Personal Data only:
- on Customer’s documented instructions;
- as necessary to provide, maintain, secure, and support the Service;
- as described in the applicable agreement and this DPA; or
- where required by applicable law.
Customer’s use and configuration of the Service, support requests, and other documented communications may constitute documented processing instructions.
If KipoProp reasonably believes an instruction violates Applicable Data Protection Law, KipoProp may notify Customer and suspend the affected processing until the parties resolve the issue, unless prohibited by law.
4. Customer Obligations
Customer represents that:
- it has the right and lawful basis to provide Customer Personal Data to KipoProp;
- its instructions comply with applicable law;
- it provides legally required privacy notices;
- it obtains required consents or other legal bases;
- it does not instruct KipoProp to process Personal Data unlawfully; and
- it uses reasonable measures to ensure authorized access to Customer Data.
Customer remains responsible for determining whether its collection and use of tenant, owner, vendor, employee, contractor, or other Personal Data is lawful.
5. Confidentiality
KipoProp will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Customer Personal Data will be limited to persons and service providers that require access for legitimate operational purposes associated with providing, securing, supporting, or maintaining the Service.
6. Security
KipoProp will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure.
Security measures will take into account:
- the nature and scope of processing;
- available technology;
- implementation costs; and
- the likelihood and severity of risks to individuals.
The measures applicable to the current KipoProp Service are described in Schedule 2 of this DPA.
KipoProp may update security measures as technology and threats evolve, provided that the overall level of protection is not materially reduced.
7. Data Subject Requests
Taking into account the nature of the processing, KipoProp will provide reasonable assistance to Customer with requests by Data Subjects to exercise rights available under Applicable Data Protection Law.
Such rights may include:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability; and
- other legally applicable rights.
If KipoProp receives a request relating primarily to Customer Personal Data for which Customer acts as Controller, KipoProp may direct the individual to Customer and will not independently respond to the substance of the request unless legally required or instructed by Customer.
8. Compliance Assistance
Taking into account the nature of processing and information available to KipoProp, KipoProp will provide reasonable assistance to Customer with applicable obligations concerning:
- security of processing;
- Personal Data breaches;
- data protection impact assessments;
- consultations with supervisory authorities; and
- other processor-assistance obligations required by Applicable Data Protection Law.
9. Security Incident Notification
KipoProp will notify Customer without undue delay after becoming aware of a Security Incident involving Customer Personal Data.
Where reasonably available, notice may include:
- the nature of the incident;
- categories of affected information;
- categories or approximate number of affected Data Subjects;
- likely consequences;
- measures taken or proposed to address the incident; and
- a point of contact for additional information.
Information may be provided in phases as investigation continues.
Notification of a Security Incident does not constitute an admission of fault or liability.
Customer remains responsible for determining whether notification to regulators, individuals, customers, or other parties is legally required.
10. Subprocessors
Customer grants KipoProp general authorization to engage Subprocessors to support the Service.
KipoProp will maintain a current list of Subprocessors at /subprocessors.
KipoProp will require Subprocessors that process Customer Personal Data to be subject to written data-protection obligations appropriate to the services they provide.
KipoProp remains responsible for its Subprocessors’ processing of Customer Personal Data to the extent required by Applicable Data Protection Law.
Before adding or replacing a Subprocessor that will materially process Customer Personal Data, KipoProp will provide reasonable advance notice where required by applicable law.
Customer may object to a new Subprocessor on reasonable and documented data-protection grounds by contacting privacy@kipoprop.com.
Customer should submit an objection within 15 days after receiving applicable notice.
The parties will work in good faith to address a reasonable objection.
If the parties cannot reasonably resolve the objection, KipoProp may provide an alternative configuration where commercially reasonable or Customer may stop using the affected Service functionality.
11. International Data Transfers
AK COMPANY LLC is established in the United States.
Customer Personal Data may therefore be transferred to and processed in the United States and other countries where KipoProp or its authorized Subprocessors operate.
Where Applicable Data Protection Law requires a transfer safeguard, KipoProp will use an applicable lawful transfer mechanism.
For transfers of Personal Data governed by the EU GDPR to a country that does not benefit from an applicable adequacy decision, the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914 are incorporated into this DPA where required.
Where Customer acts as Controller and KipoProp acts as Processor, Module Two (Controller to Processor) applies.
Where Customer acts as Processor and KipoProp acts as Subprocessor, Module Three (Processor to Processor) applies.
For purposes of the EU Standard Contractual Clauses:
- the data exporter is Customer;
- the data importer is AK COMPANY LLC;
- Annex I processing details are set out in Schedule 1;
- Annex II security measures are set out in Schedule 2;
- the list of approved Subprocessors is available at /subprocessors;
- general written authorization for Subprocessors applies;
- the optional independent dispute-resolution mechanism in Clause 11 does not apply unless otherwise legally required;
- where a governing EU Member State law must be selected and Customer’s establishment does not supply an applicable choice, the laws of Ireland apply;
- disputes under the SCCs may be brought before the courts of Ireland where the SCCs require selection of an EU Member State forum.
Nothing in the KipoProp Terms limits rights or obligations under the Standard Contractual Clauses where such limitation would be prohibited.
For transfers governed by UK data-protection law, the then-applicable UK International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner is incorporated where required, using the information contained in this DPA and its Schedules to complete the applicable tables.
If an applicable transfer mechanism is invalidated or becomes unavailable, the parties will cooperate in good faith to implement another valid mechanism.
12. United States Privacy Laws
Where applicable United States privacy law treats KipoProp as a Service Provider, Contractor, Processor, or equivalent entity, KipoProp will process Customer Personal Data only for the limited and specified purposes described in the parties’ agreement.
To the extent required by applicable law, KipoProp will not:
- sell Customer Personal Data;
- share Customer Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data outside the direct business relationship except as legally permitted;
- use Customer Personal Data for purposes unrelated to providing the Service; or
- combine Customer Personal Data with Personal Data obtained from unrelated sources except where permitted by applicable law.
KipoProp will notify Customer if KipoProp determines that it can no longer meet applicable obligations imposed on it as a service provider, contractor, or processor.
13. Canadian Privacy Requirements
Where Canadian privacy law applies, KipoProp will process Customer Personal Data only for purposes authorized by Customer and will use appropriate safeguards considering the sensitivity of the information.
Customer acknowledges that authorized processing may occur outside Canada, including in the United States, subject to applicable legal safeguards.
14. Return and Deletion of Data
Upon termination of the applicable Service and subject to available product functionality, Customer should export Customer Data it wishes to retain.
Following termination or a valid deletion instruction, KipoProp will delete or return Customer Personal Data as required by applicable law and the applicable agreement.
Limited information may remain temporarily in:
- backups;
- disaster-recovery systems;
- security logs;
- fraud-prevention records; or
- legally required records.
Any retained Customer Personal Data will remain subject to applicable protections and will not be used for unrelated purposes.
15. Audits and Compliance Information
KipoProp will make available information reasonably necessary to demonstrate compliance with processor obligations under Applicable Data Protection Law.
Where appropriate, KipoProp may satisfy audit requests by providing:
- security documentation;
- policies;
- independent assessments;
- certifications, if available;
- relevant questionnaire responses; or
- other reasonable compliance information.
If applicable law requires an additional audit or inspection, Customer may request one on reasonable advance written notice.
Audits must:
- occur no more than once per 12-month period unless required because of a confirmed Security Incident, regulator request, or reasonable evidence of material non-compliance;
- avoid unreasonable disruption;
- protect other customers’ confidential information;
- comply with reasonable security requirements; and
- be performed by Customer or an independent auditor subject to appropriate confidentiality obligations.
Customer bears its own audit costs unless applicable law requires otherwise.
16. Sensitive Personal Data
KipoProp is not designed to require special-category or highly sensitive Personal Data unless specific KipoProp functionality clearly supports and requires that information.
Customer should not submit highly sensitive Personal Data unless:
- it is reasonably necessary for Customer’s lawful use of the Service;
- Customer has an appropriate lawful basis;
- applicable notices and permissions have been provided; and
- processing is permitted by applicable law.
Customer must not use KipoProp to unlawfully process protected characteristics, medical information, biometric data, authentication secrets, or government identification information.
17. Liability
Liability arising from this DPA is subject to the liability provisions of the KipoProp Terms of Service to the maximum extent permitted by applicable law.
However, nothing in the Terms or this DPA limits:
- rights of Data Subjects that cannot legally be limited;
- liability that Applicable Data Protection Law prohibits the parties from limiting; or
- obligations imposed by applicable Standard Contractual Clauses.
18. Duration
This DPA becomes effective when the parties’ agreement requires KipoProp to process Customer Personal Data.
It remains in effect for as long as KipoProp processes Customer Personal Data on Customer’s behalf.
19. Order of Precedence
If this DPA conflicts with the KipoProp Terms of Service regarding processing of Customer Personal Data, this DPA controls.
If the EU Standard Contractual Clauses or applicable UK international transfer terms conflict with this DPA regarding an international transfer, the applicable mandatory transfer terms control.
20. Contact
Questions or requests concerning this DPA may be directed to:
AK COMPANY LLC
Operator of KipoProp
2105 Vista Oeste St NW, Suite E-1300
Albuquerque, NM 87120
United States
Privacy Email: privacy@kipoprop.com
Website: kipoprop.com
Schedule 1 — Details of Processing
A. Parties
Data Exporter / Controller: the KipoProp Customer identified through the Customer’s account or applicable agreement.
Data Importer / Processor:
AK COMPANY LLC
2105 Vista Oeste St NW, Suite E-1300
Albuquerque, NM 87120
United States
Contact: privacy@kipoprop.com
B. Subject Matter
Provision and operation of the KipoProp property-management SaaS platform.
C. Duration
For the duration of Customer’s use of KipoProp and applicable post-termination retention periods.
D. Nature of Processing
Depending on Customer’s use of the Service, processing may include:
- collection;
- receipt;
- recording;
- organization;
- structuring;
- storage;
- retrieval;
- consultation;
- display;
- transmission;
- modification;
- backup;
- support access;
- deletion; and
- other operations required to provide KipoProp.
E. Purpose
To provide, maintain, secure, support, troubleshoot, and operate KipoProp and functionality requested by Customer.
F. Categories of Data Subjects
Depending on Customer’s use of KipoProp:
- Customer account users;
- landlords;
- property managers;
- property owners;
- tenants;
- occupants;
- vendors;
- contractors;
- maintenance providers;
- authorized team members; and
- other persons whose information Customer lawfully enters into KipoProp.
G. Categories of Personal Data
Depending on Customer’s use of the Service:
- names;
- contact information;
- internal identifiers;
- user roles;
- property and unit associations;
- tenant and occupant information;
- lease information;
- rent and transaction records;
- payment-status information;
- owner information;
- vendor and contractor information;
- maintenance information;
- communications;
- notes;
- tasks;
- documents;
- account and access information;
- support information;
- security and technical logs; and
- other Customer-provided property-management information.
H. Sensitive Data
KipoProp does not require special-category Personal Data as a general condition of using the Service.
Customer is responsible for determining whether any information it submits is sensitive and whether processing is lawful.
I. Processing Frequency
Continuous or as initiated by Customer during use of the Service.
Schedule 2 — Technical and Organizational Measures
The following measures describe controls that are actually implemented in the current KipoProp Service. KipoProp does not claim certifications, audit reports, defined recovery objectives, or testing programs that it has not completed.
1. Access Control
- protected application functionality requires an authenticated account session;
- role-based authorization controls determine what an authenticated user may access and change;
- administrative and team-management functions are restricted to users holding the applicable role;
- access is granted according to the role assigned within the customer’s workspace.
2. Tenant / Workspace Segregation
- each customer’s records are logically separated by organization;
- database row-level security policies are enabled on application tables and scope access to the requesting user’s organization and role.
3. Transmission Security
- production web, API, and database traffic is served over HTTPS/TLS.
4. Secrets
- production secrets and server-side keys are stored in the platform’s protected secret-management mechanism and read server-side, rather than hard-coded into frontend source code;
- privileged server credentials are never exposed to the browser.
5. Payment Information
- card details are entered and handled by Stripe’s hosted payment flows; KipoProp does not store full payment-card numbers.
6. Monitoring
- technical error and security monitoring is provided through Sentry;
- the Sentry implementation strips request bodies, cookies, headers, and query strings, redacts sensitive keys, disables Session Replay, and attaches only opaque identifiers rather than names, emails, or tenant content.
7. Analytics Privacy
- GA4 and PostHog are loaded only after the visitor grants Analytics consent;
- the PostHog property allowlist remains active and blocks non-approved custom properties;
- PostHog Session Replay, autocapture, heatmaps, and surveys remain disabled.
8. Security Development Practices
- TypeScript type checking and production build validation are run before releases;
- production releases are deployed through a controlled publish step;
- application and dependency updates are applied as part of ongoing maintenance.
9. Data Availability and Recovery
KipoProp relies on the managed database and hosting infrastructure described in the Subprocessor List for storage durability and platform-level availability. KipoProp does not publish backup frequency, recovery-point or recovery-time objectives, encryption-at-rest guarantees, penetration-test schedules, or compliance certifications, because those have not been independently verified for the current Service.
