Data Processing & Security
How we process personal data on your behalf and the security measures we apply.
Purpose & Scope
This Data Processing Agreement and Security Overview ("DPA") describes how PropertyMeasure Inc., a Delaware corporation ("Processor," "we") processes personal data on behalf of a business Customer ("Controller," "you") when you use the Service, and the security measures we apply. This DPA supplements our Terms of Service and applies to the extent we process personal data subject to applicable data protection laws (including the GDPR and CCPA/CPRA).
Definitions
- "Controller," "Processor," "Data Subject," "Personal Data," and "Processing" have the meanings given under applicable data protection law.
- "Sub-processor" — a third party engaged by us to process personal data on your behalf.
- "Applicable Law" — data protection and privacy laws applicable to the processing.
Roles of the Parties
As between the parties, you are the Controller (or processor acting on behalf of a controller) of the personal data you submit, and we are the Processor. Each party will comply with its obligations under Applicable Law.
Details of Processing
- Subject matter: provision of the measurement, estimating, and proposal Service.
- Duration: for the term of your use of the Service and as needed to fulfill the Terms.
- Nature & purpose: hosting, storing, and processing account and Customer Data to deliver the Service.
- Categories of data subjects: your authorized users and individuals referenced in your Customer Data.
- Categories of personal data: names, contact and account details, billing metadata, property addresses, and usage data.
Processor Obligations
- Process personal data only on your documented instructions, including via the Service, unless required by law.
- Ensure personnel authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (below).
- Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations.
- Make available information reasonably necessary to demonstrate compliance.
Security Measures
We maintain a security program that includes, at minimum:
- Encryption of data in transit (HTTPS/TLS) and encryption at rest via our infrastructure providers.
- Access controls, authentication, and least-privilege principles for systems and data.
- Use of reputable, security-certified infrastructure (Google Cloud/Firebase) and payment processing (Stripe, PCI-DSS).
- Logging, monitoring, and separation of production environments.
- Regular review of our practices and vendors.
Sub-processors
You authorize us to engage sub-processors to provide the Service. We impose data-protection obligations on sub-processors that are consistent with this DPA. We will provide notice of new sub-processors and remain responsible for their performance. Our current sub-processors include:
- Google LLC (Firebase / Google Cloud) — authentication, database, hosting, serverless functions, and map imagery tiles.
- Stripe, Inc. — payment processing and billing (PCI-DSS compliant; full card details are handled by Stripe, not by us).
- EmailJS — delivery of transactional email (e.g., password-reset messages).
- Esri and imagery/basemap providers — aerial and satellite imagery displayed in the measurement tools.
- ReportAll USA / parcel-data providers — parcel boundary lookups by address or location.
- OpenStreetMap / Photon — address search and geocoding.
Data Subject Requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights under Applicable Law. If we receive such a request directly, we will advise the data subject to contact you.
Personal Data Breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and provide information reasonably available to help you meet your notification obligations.
International Transfers
Where personal data is transferred across borders, we rely on appropriate safeguards recognized under Applicable Law (such as the EU Standard Contractual Clauses), where required.
Return & Deletion of Data
Upon termination of the Service, and at your written request, we will delete or return personal data processed on your behalf, except where retention is required by law. Deletion may be subject to reasonable timelines and backup cycles.
Audits
Upon reasonable written request and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA. Audits, if any, will be conducted with reasonable notice, during business hours, and without unreasonably disrupting our operations.
Order of Precedence & Contact
In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls. For DPA or security inquiries, contact legal@propertymeasure.ai.
