Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between SimpleAgentRE, LLC (“SimpleAgentRE,” the Processor) and the subscribing agent or brokerage (“Customer,” the Controller). It governs SimpleAgentRE’s processing of personal information that the Customer submits to the portal about their clients and transactions (“Customer Personal Data”).
1. Roles of the parties
The Customer is the data controller and determines the purposes and means of processing Customer Personal Data. SimpleAgentRE acts solely as the data processor (or “service provider” under U.S. state law), processing Customer Personal Data only on the Customer’s documented instructions, which include the Terms of Service, this DPA, and the Customer’s use of the portal’s features.
2. Scope & nature of processing
- Subject matter: providing the SimpleAgentRE portal and its features (client database, CMA/valuations, transaction sheets, forms, document storage, reminders).
- Categories of data subjects: the Customer’s real estate clients (buyers, sellers, prospects) and their related contacts.
- Categories of data: identification and contact details, property and transaction details, documents, and similar information the Customer chooses to enter.
- Duration: for the term of the subscription plus the retention period in §8.
3. Our obligations as processor
SimpleAgentRE will:
- Process Customer Personal Data only on the Customer’s documented instructions, including for international transfers, unless required by law (in which case we will notify the Customer unless legally prohibited);
- Not sell Customer Personal Data and not use it for our own marketing, advertising, or to build profiles unrelated to providing the service;
- Not combine Customer Personal Data with data from other sources except to provide the service or as permitted by law;
- Ensure personnel authorized to process the data are bound by confidentiality;
- Implement and maintain the security measures described in §5;
- Assist the Customer, taking into account the nature of processing, in meeting its own obligations under applicable privacy laws.
4. Customer obligations
- The Customer is responsible for the accuracy and lawfulness of the data it enters and for having a lawful basis and any required notices/consents to collect and share it with us.
- The Customer’s instructions must comply with applicable law.
- The Customer is responsible for managing user access within its account and for the confidentiality of its login credentials.
5. Security measures
SimpleAgentRE maintains technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit (TLS/HTTPS);
- Access controls, role/owner-scoping of records, and hashed credentials;
- Logical separation of customer accounts;
- Regular, secured backups and tested restore procedures;
- Monitoring, logging, and patching of the hosting environment.
6. Sub-processors
The Customer authorizes SimpleAgentRE to engage sub-processors to deliver the service. We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. Current sub-processors are listed in §9. We will give notice of intended changes and allow the Customer a reasonable opportunity to object on reasonable data-protection grounds.
7. Consumer rights requests (access, correction, deletion / “right to be forgotten”)
Because the Customer is the controller, requests from the Customer’s clients to access, correct, port, or delete their data are handled by the Customer. SimpleAgentRE provides in-portal tools to view, export, and permanently delete an individual client’s records so the Customer can fulfill these requests. Where the Customer cannot do so through those tools, we will provide reasonable assistance, taking into account the nature of processing. If we receive such a request directly from a consumer, we will not respond substantively except to confirm the request relates to a Customer and, where appropriate, forward it to the Customer.
8. Retention & deletion on termination
On termination or cancellation, the Customer may export its data through the portal. We retain Customer Personal Data for [RETENTION DAYS] days after termination to allow reactivation and export, after which we permanently delete or anonymize it from active systems. Backup copies are deleted on their normal expiry cycle. We will delete data sooner upon the Customer’s written request, subject to any legal retention requirement.
9. Breach notification
If SimpleAgentRE becomes aware of a personal-data breach affecting Customer Personal Data, we will notify the affected Customer without undue delay and in any event within [BREACH NOTICE HOURS] hours of confirming the breach, with the information reasonably available to help the Customer meet its own notification obligations, and we will take reasonable steps to mitigate.
Current sub-processors
| Sub-processor | Service | Data involved |
|---|---|---|
| Hostinger | Application hosting & storage | All stored data |
| Card Point | Subscription billing | Subscriber billing data |
| Hostinger | Transactional email | Contact data in emails |
| Anthropic | CMA / automated analysis | Property & comparable data |
10. Audits
On reasonable prior written request, no more than once per year (unless required by a supervisory authority or following a breach), SimpleAgentRE will make available information reasonably necessary to demonstrate compliance with this DPA.
11. General
This DPA is governed by the laws of the State of [STATE]. In case of conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA controls. Questions: Information@SimpleAgentRE.com.