Legal
Data Processing Agreement
Governs how LeaseOps processes personal data on a customer's behalf.
Last updated: August 2026 (draft)
1. Purpose and roles
This Data Processing Agreement ("DPA") supplements the Terms of Service between a property management company ("Customer," the data Controller for its tenants, owners, vendors, and applicants) and LeaseOps ("Processor"). It applies whenever LeaseOps processes personal data on Customer's behalf in the course of providing the Service.
2. Subject matter and duration
Processing covers the personal data Customer submits to or generates within LeaseOps about its tenants, prospective tenants/applicants, property owners, and vendors, for as long as Customer's account with LeaseOps remains active, plus any post- termination retention period described in the Privacy Policy.
3. Nature and purpose of processing
LeaseOps processes this data to provide the Service: storing and displaying property/ lease/tenant records, processing rent payments and owner payouts, routing e-signature requests, facilitating tenant screening, sending workflow notifications, and generating documents. LeaseOps does not process this data for its own independent purposes beyond operating and improving the Service.
4. Categories of data subjects and data
- Data subjects: tenants and household members, rental applicants, property owners, vendors, and Customer's own staff.
- Data categories: contact information, lease and financial terms, payment status, application and screening information (where tenant screening is used), maintenance and communication records, and documents uploaded or generated within the Service.
5. Processor obligations
LeaseOps will:
- Process personal data only on Customer's documented instructions, as reflected in the Service's normal operation and configuration.
- Ensure personnel with access to personal data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures, including per-organization data isolation at the database layer (row-level security) so no organization's data is visible to another.
- Assist Customer, to the extent reasonably possible, in responding to data subject requests (access, correction, deletion) it receives.
- Notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data.
- Delete or return personal data at the end of the engagement, subject to legal retention requirements, per the Privacy Policy.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
6. Subprocessors
Customer authorizes LeaseOps to engage the following subprocessors to provide the Service, each under its own data protection terms:
- Amazon Web Services (AWS) — cloud hosting and file storage (United States).
- Stripe — payment processing and owner payouts.
- DocuSign — electronic signature.
- Checkr — tenant screening (background/credit checks), engaged only when Customer or an applicant initiates screening.
- A transactional email provider — account and workflow notification delivery.
LeaseOps will provide reasonable notice before adding a new subprocessor that will process Customer's data, so Customer can object on reasonable data-protection grounds.
7. International transfers
Data is currently hosted in the United States. LeaseOps does not currently transfer personal data outside the United States other than as described above.
8. Customer obligations
Customer is responsible for having a lawful basis to collect and share the personal data it submits to LeaseOps, including obtaining any required consents (e.g. the FCRA authorization required before initiating tenant screening — see the FCRA Disclosure) and providing any required notices to its tenants, owners, vendors, and applicants.
9. Liability
Liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
10. Contact
Questions about this DPA, including subprocessor questions, can be sent through the contact page.