Legal
Data processing addendum
The terms on which Kwestra LLC processes personal information for agents, agencies and networks that use prop.forsale.
On this page
The short version
- Your agency decides how its clients’ information is used (controller). We process it only for you (processor).
- We keep it confidential and secure, use only the listed sub-processors, and tell you before adding one.
- We help you answer rights requests and tell you without undue delay about any security incident.
- Transfers out of the EU, UK and South Africa are covered by the Standard Contractual Clauses, the UK Addendum and POPIA section 72.
- This addendum forms part of our terms of service. You accept it by using the service; no signature is needed.
This summary helps you find your way. The full text below is what applies.
1. Scope and parties
This addendum is between the agent, agency or network that holds a prop.forsale workspace ("you") and Kwestra LLC, 14 NE 1st Ave, Ste 1403 #146, Miami, FL 33132, USA ("we"). It forms part of our terms of service (/terms) and applies whenever we process Agency Personal Data. If this addendum and the terms conflict on data protection, this addendum wins; if the Standard Contractual Clauses conflict with this addendum, the Clauses win.
2. Definitions
- Agency Personal Data
- Personal information you, or people using your website or deal rooms, put into the service, for which you are the controller (responsible party).
- Data Protection Law
- Every law that applies to that processing, including POPIA, the GDPR, the UK GDPR, US state privacy laws such as the CCPA, and the UAE Personal Data Protection Law.
- Sub-processor
- A provider we engage that may process Agency Personal Data.
- Security Incident
- A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Agency Personal Data (a "security compromise" under POPIA section 22).
- SCCs
- The standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- UK Addendum
- The International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
3. What we process
| Item | Detail |
|---|---|
| Subject matter | Hosting and operating the agency’s websites, enquiries, newsletters, alerts and deal rooms on prop.forsale. |
| Duration | For as long as the agency uses the service, then until deletion 30 days after the workspace is deleted, save records the law requires us to keep. |
| Nature and purpose | Storage, retrieval, display, transmission (including email delivery), organisation, encryption, backup and deletion, only to provide the service. |
| Data subjects | Enquirers, newsletter subscribers and alert recipients, deal room parties (buyers, sellers, landlords, tenants, attorneys, originators and others), and the agency’s own staff. |
| Personal information | Names, email addresses, phone numbers, messages, consent records, property interests, deal roles, and documents uploaded to deal rooms (which can include identity documents, proof of address and proof of funds). |
| Special categories | None intended. The agency must not upload special categories of data unless it is necessary and lawful. |
| Frequency | Continuous. |
| Where | Main database in the United States; documents and photos in the data region the agency chose (United States, European Union, Asia-Pacific or Oceania). |
4. What we promise
We will:
- process Agency Personal Data only on your documented instructions, which are these terms and your use of the service, and tell you if we believe an instruction breaks the law;
- not use it for our own purposes, not sell or share it, not combine it with other data except as the service requires, and not keep, use or disclose it outside our direct relationship with you (the CCPA service-provider promises; we understand and will comply with them);
- make sure everyone who can access it is bound by confidentiality;
- protect it with the measures in the security annex below, and keep them at least as protective;
- help you, through the service and on request, to answer requests from people exercising their rights, including the workspace export and the erasure tools;
- help you with security, breach notification, impact assessments and consultations with regulators, taking into account what we know;
- at the end of the service, delete Agency Personal Data 30 days after your workspace is deleted, save what the law requires us to keep, and let you export it before then;
- give you the information you reasonably need to show compliance, and allow audits as set out below.
5. What you promise
You will:
- have a lawful basis for the processing and give people the notices the law requires (your agency site shows a notice naming you);
- get any consent needed, including for direct marketing, and keep the evidence the service records;
- upload only the personal information you need, and only the identity and financial documents your legal checks require;
- make sure your instructions comply with Data Protection Law.
6. Sub-processors
You give us general authorisation to use the sub-processors listed at /subprocessors. We bind each by written terms at least as protective as this addendum and remain responsible for them. We will announce a new sub-processor on that page and by email to workspace owners at least 30 days before it starts. If you object on reasonable data protection grounds and we cannot resolve it, you may end the affected service and we will refund any prepaid fees for the unused period.
7. International transfers
Where Agency Personal Data from the EU or EEA reaches us or a sub-processor in a country without an adequacy decision, the SCCs apply and are incorporated into this addendum: Module 2 (controller to processor) between you and us, and Module 3 (processor to processor) with our sub-processors. For Module 2: clause 7 (docking) applies; under clause 9 option 2 (general authorisation) applies with the notice period above; the optional wording in clause 11 does not apply; clause 13 names the supervisory authority of your establishment or, if none, of your representative; clauses 17 and 18 choose the law and courts of Ireland. Annexes I and II are the tables in this addendum.
For UK data, the UK Addendum applies with the same details, and either party may end it as its section 19 allows. For Swiss data, the SCCs apply with references to the Swiss Federal Act on Data Protection. Where a sub-processor is certified under the EU-US Data Privacy Framework (and its UK and Swiss extensions), that certification may be relied on instead, with the SCCs as a fallback.
For South African data, every transfer meets POPIA section 72 through these binding terms, which give protection substantially similar to POPIA.
8. Security incidents
We will tell you without undue delay, and where feasible within 48 hours, after becoming aware of a Security Incident affecting Agency Personal Data. We will say what happened, what data and people are affected, what we are doing and whom to contact, and add detail as we learn it, so that you can meet your own deadlines (72 hours to a regulator under the GDPR; "as soon as reasonably possible" under POPIA section 22). Telling you is not an admission of fault.
9. Information and audits
On request we will answer reasonable security questionnaires and share summaries of our controls and our sub-processors’ certifications. If that is not enough to show compliance, or a regulator requires it, you may audit us once a year on at least 30 days’ written notice, during business hours, under confidentiality, at your cost. Send requests to privacy@pfs-stage.dev.
10. Security annex
| Area | What we do |
|---|---|
| Encryption | TLS for all traffic. Deal room documents uploaded to the vault are encrypted with AES-256-GCM using a key derived for each agency, on top of storage-level encryption. |
| Separation | Every query is scoped to one agency workspace; one agency cannot read another’s records. |
| Access control | Role-based access inside each workspace; deal room parties see only what the agent makes visible; least-privilege access for our staff. |
| Accountability | Administrative actions and every deal document view or download are logged. |
| Secrets | Sign-in, invitation and unsubscribe tokens are stored only as hashes. |
| Abuse protection | Bot checks on public forms, rate limits on sign-in, and no raw IP address stored with consent records. |
| Availability | Point-in-time database recovery for 30 days and backups before each release. |
| Deletion | Automated retention jobs, per-person erasure tools for enquiries and subscribers, and full deletion of a workspace 30 days after it is closed. |
11. Liability, term and signatures
Each party’s liability under this addendum is subject to the limits in the terms of service, except where Data Protection Law or the SCCs do not allow a limit. This addendum lasts as long as we process Agency Personal Data.
You accept this addendum by accepting the terms of service. If you need a signed copy for your records, email privacy@pfs-stage.dev.