Data Processing Addendum

This Data Processing Addendum sets out the terms on which Property Management Network processes personal data on behalf of Customers of Property Management Network.

Effective date: July 1, 2026 · Last updated: July 1, 2026

This DPA forms part of the Terms of Service between you and Property Management Networkand applies wherever we process personal data on the Customer’s behalf (for example, Tenant personal data managed through the Service). Where there is a conflict between this DPA and the Terms in respect of the processing of personal data, this DPA prevails.

1. Introduction and roles

In this DPA, Customer (also you) means the account holder using Property Management Network. We, us, and our mean Property Management Network. A Tenant means a data subject whose personal data the Customer manages through the Service.

With respect to Tenant personal data and other personal data that the Customer submits to the Service, the Customer acts as the data controller and we act as the data processor, processing that personal data solely on the Customer’s behalf. With respect to the Customer’s own account data (for example, the name and contact details of the account holder and billing information), we act as a controller in our own right, as described in our Privacy Policy.

2. Definitions

Unless otherwise defined here, the following terms have the meanings given below:

  • Controller means the entity that determines the purposes and means of the processing of personal data.
  • Processor means the entity that processes personal data on behalf of the controller.
  • Personal Data means any information relating to an identified or identifiable natural person that is processed under this DPA.
  • Data Subject means the identified or identifiable natural person to whom Personal Data relates.
  • Processing means any operation performed on Personal Data, whether or not by automated means, including collection, storage, use, and deletion.
  • Sub-processor means any third party engaged by us to process Personal Data on behalf of the Customer.
  • Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the GDPR) and the United Kingdom General Data Protection Regulation (the UK GDPR).
  • Standard Contractual Clauses means the standard data protection clauses approved by the European Commission (or the equivalent UK transfer mechanism) for the transfer of Personal Data to processors established in third countries.

3. Details of the processing

The subject matter, duration, nature, and purpose of the processing, and the types of Personal Data and categories of Data Subjects, are as follows:

  • Subject matter: the provision of the Service to the Customer.
  • Duration: the term of the agreement between the Customer and us, plus the deletion window described in Section 11.
  • Nature and purpose: hosting, storage, and processing of Personal Data as necessary to operate the property-management features of the Service.
  • Types of Personal Data: names, contact details, tenancy information, lease information, and payment-status data.
  • Categories of Data Subjects:the Customer’s Tenants and contacts.

4. Our obligations as processor

When acting as a processor on the Customer’s behalf, we shall:

  • process Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case we shall inform the Customer of that legal requirement before processing, unless prohibited from doing so);
  • ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR;
  • taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures in responding to requests from Data Subjects seeking to exercise their rights;
  • assist the Customer in ensuring compliance with its obligations relating to the security of processing, personal-data breach notification, data-protection impact assessments (DPIAs), and prior consultations with supervisory authorities;
  • make available to the Customer the information necessary to demonstrate compliance with the obligations set out in this DPA.

5. Sub-processors

The Customer provides a general authorization for us to engage Sub-processors to process Personal Data in connection with the Service. Our current Sub-processors are listed on our Sub-processors page.

Where we engage a Sub-processor, we impose data-protection obligations that are substantially equivalent to those set out in this DPA. We give the Customer prior notice of any intended addition or replacement of a Sub-processor, and the Customer may object to the change on legitimate data-protection grounds. We remain responsible for the performance of each Sub-processor’s obligations.

6. International transfers

Where processing of Personal Data involves a transfer to a country outside the European Economic Area or the United Kingdom that has not been recognized as providing an adequate level of protection, we implement an appropriate transfer mechanism, such as the Standard Contractual Clauses or another lawful mechanism recognized under Applicable Data Protection Law.

7. Data-subject rights

Taking into account the nature of the processing, we assist the Customer, as controller, by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law. Where we receive a request directly from a Data Subject in respect of Personal Data processed on the Customer’s behalf, we shall, unless legally required to respond, forward that request to the Customer without undue delay.

8. Personal-data breach

We shall notify the Customer without undue delay after becoming aware of a personal-data breach affecting Personal Data processed on the Customer’s behalf. That notification shall, to the extent available, describe the nature of the breach, its likely consequences, and the measures taken or proposed to address it, so that the Customer can meet its own notification obligations.

9. Audit

We make available to the Customer the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are subject to reasonable prior written notice, are conducted during normal business hours in a manner that does not disrupt our operations, and are subject to appropriate confidentiality obligations.

10. Return and deletion

Upon termination or expiry of the agreement, we shall, at the Customer’s choice, delete or return all Personal Data processed on the Customer’s behalf, and delete existing copies, within 30 days, save where retention of the Personal Data is required by Applicable Data Protection Law or other law, in which case we shall protect that Personal Data and process it only as necessary for the purpose that requires its retention.

11. Liability

Each party’s liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service.

12. Execution

This DPA is incorporated into, and forms part of, the Terms of Service and takes effect upon the Customer’s acceptance of the Terms and use of the Service. A countersigned copy of this DPA is available on request by contacting dpo@propertymanagement.network.

Contact us

If you have questions about this policy, contact us at dpo@propertymanagement.network.

Property Management Network