Data Processing Agreement
Civentry, a product of Daddisyn Labs, LLC, Moorpark, California
Effective date: June 17, 2026
Last updated: June 17, 2026
1. Introduction and Scope
This Data Processing Agreement ("DPA") supplements and is incorporated into the Civentry Terms of Service or other written agreement between Daddisyn Labs, LLC ("Civentry," "we," "us") and the customer that has accepted it ("Customer," "you") governing Customer's use of the Civentry service (the "Agreement"). This DPA applies whenever Civentry processes Customer Personal Data (defined below) on Customer's behalf in providing the Service.
This DPA takes effect on the earlier of the date Customer accepts it and the date Customer first uses the Service to upload or process personal data. For negotiated enterprise engagements, this DPA may also be executed by both parties using the signature block in Section 14.
If there is a conflict between this DPA and the rest of the Agreement regarding the processing of Customer Personal Data, this DPA controls.
2. Definitions
Capitalized terms not defined here have the meanings given in the Agreement.
- "Data Protection Laws" means all U.S. federal and state data privacy and protection laws applicable to the processing of Customer Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and comparable comprehensive consumer privacy laws of other U.S. states.
- "Customer Personal Data" means personal information, as defined under Data Protection Laws, that Civentry processes on Customer's behalf in providing the Service, including the contents of documents Customer uploads and any resident or member personal information contained in them.
- "Business," "Controller," "Service Provider," "Processor," "Sell," "Share," "Consumer," "Personal Information," and "Deidentified" have the meanings given under applicable Data Protection Laws.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Civentry or its Sub-Processors.
- "Sub-Processor" means a third party engaged by Civentry to process Customer Personal Data in providing the Service.
- "Sub-Processor List" means the list of Sub-Processors in Schedule 3, as updated from time to time.
3. Roles of the Parties
With respect to Customer Personal Data, Customer is the Business / Controller and Civentry is Customer's Service Provider / Processor. Customer determines the purposes and means of processing; Civentry processes Customer Personal Data only to provide the Service and only as described in this DPA and the Agreement.
For clarity, this DPA does not govern information for which Civentry is itself the business/controller (such as Customer's account, billing, and usage information); that information is governed by the Civentry Privacy Policy.
4. Civentry's Processing Obligations
4.1 Documented instructions. Civentry will process Customer Personal Data only (a) to provide, maintain, secure, and support the Service; (b) in accordance with the Agreement, this DPA, and Customer's reasonable documented instructions given through the Service's features and settings; and (c) as required by applicable law, in which case Civentry will inform Customer of the requirement before processing unless legally prohibited.
4.2 Notice of conflicting instructions. Civentry will inform Customer if, in its reasonable opinion, an instruction violates Data Protection Laws.
4.3 Confidentiality. Civentry will ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.
4.4 Security. Civentry will implement and maintain reasonable and appropriate technical and organizational security measures designed to protect Customer Personal Data, as described in Schedule 2 (Security Measures).
4.5 Assistance with individual rights requests. Taking into account the nature of the processing, Civentry will provide reasonable assistance (including through the Service's features) to enable Customer to respond to verified requests from residents, members, or other consumers to exercise their rights under Data Protection Laws. Civentry will not respond to such a request independently except as instructed by Customer or as required by law, and will, where permitted, redirect requests it receives directly to Customer.
4.6 Assistance with compliance. Taking into account the nature of the processing and the information available to Civentry, Civentry will provide reasonable assistance to Customer with data protection impact assessments and consultations with regulators, to the extent required by Data Protection Laws and relating to Civentry's processing.
4.7 Personal Data Breach. Civentry will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to Civentry to assist Customer in meeting its own breach-notification obligations. Civentry's notification is not an acknowledgment of fault or liability.
5. CCPA and U.S. Privacy Law Covenants
To the extent Data Protection Laws apply, Civentry, as Customer's Service Provider/Processor, agrees that it will:
(a) process Customer Personal Data only to perform the Service and the business purposes specified in the Agreement and this DPA, and not for any other purpose;
(b) not Sell or Share Customer Personal Data;
(c) not retain, use, or disclose Customer Personal Data outside the direct business relationship between Civentry and Customer, or for any purpose other than providing the Service, except as permitted by Data Protection Laws;
(d) not combine Customer Personal Data with personal information Civentry receives from, or on behalf of, any other party, or collects from its own interactions with individuals, except as permitted by Data Protection Laws to perform the Service;
(e) comply with the applicable obligations of Data Protection Laws and provide Customer Personal Data the level of protection those laws require of a service provider/processor;
(f) notify Customer without undue delay if Civentry determines it can no longer meet its obligations under applicable Data Protection Laws; and
(g) where Civentry creates deidentified information from Customer Personal Data, (i) take reasonable measures to ensure the information cannot be associated with or reasonably linked to an individual, household, or Organization; (ii) publicly commit to maintain and use it only in deidentified form and not attempt to re-identify it, except as permitted by law; and (iii) contractually require any recipient to comply with clauses (i)–(iii).
The parties acknowledge that Customer's provision of Customer Personal Data to Civentry under the Agreement does not constitute a Sale or Share and is made solely so that Civentry can perform the Service.
6. Sub-Processors
6.1 General authorization. Customer authorizes Civentry to engage the Sub-Processors listed in Schedule 3 to process Customer Personal Data in providing the Service.
6.2 Sub-Processor obligations. Civentry will impose on each Sub-Processor data protection obligations substantially as protective as those in this DPA, and will remain responsible for each Sub-Processor's performance of those obligations to the same extent Civentry would be responsible if performing the services itself, subject to the limitations of liability in the Agreement.
6.3 Changes and objection. Civentry will provide notice (by updating the Sub-Processor List, in-Service notice, email to subscribers of the list, or other reasonable means) before adding or replacing a Sub-Processor that processes Customer Personal Data. Customer may object on reasonable data-protection grounds within 30 days of notice by contacting hello@civentry.com. If Customer objects, the parties will work in good faith to find a reasonable solution; if none is feasible, Customer may terminate the affected portion of the Service and receive a pro-rated refund of any prepaid, unused fees for that portion.
7. Customer's Obligations
7.1 Authority and notices. Customer represents and warrants that, for all Customer Personal Data it uploads or enters (including resident or member personal information), it has and will maintain all rights, consents, authority, and a lawful basis required under Data Protection Laws to provide that data to Civentry and to authorize Civentry's processing under the Agreement, and that it has provided all notices required of a business/controller to the individuals whose data it uploads.
7.2 Lawful instructions. Customer's instructions to Civentry will comply with Data Protection Laws. Customer is responsible for the accuracy and legality of the Customer Personal Data and the means by which it acquired it.
7.3 Configuration responsibility. Customer is responsible for its own configuration and use of the Service's controls (for example, role assignments, transparency settings, retention choices, and approvals) in a manner that complies with Data Protection Laws.
8. Data Subject / Consumer Requests
If Civentry receives a request from a resident, member, or other consumer to exercise rights under Data Protection Laws with respect to Customer Personal Data, Civentry will, where permitted by law, advise the individual to submit the request to Customer and will reasonably assist Customer in responding as described in Section 4.5.
9. Return and Deletion of Customer Personal Data
On expiration or termination of the Agreement, Civentry will, consistent with the Agreement and Privacy Policy, retain Customer Personal Data for 90 days and then permanently delete it, except where retention is required by law (including a litigation hold), in which case Civentry will isolate and protect the data and delete it when the obligation ends. Customer may request earlier deletion of specific documents through the Service; deletion is permanent and not reversible. Deletion from routine backups occurs in the ordinary course of backup rotation. A change in who administers an association does not, by itself, cause Civentry to return, delete, or relocate that association's data; the association's tenant and data remain in place, and any transition is handled as set out in the Commercial Terms.
10. Audit and Compliance
On Customer's reasonable written request, no more than once per year, and subject to confidentiality obligations, Civentry will make available information reasonably necessary to demonstrate its compliance with this DPA, for example, its current security and privacy documentation and any available third-party audit summaries or security certifications of its infrastructure providers. The parties agree that this information satisfies Customer's audit rights, unless Data Protection Laws require more.
11. International Data Transfers
The Service is operated from the United States and is intended for U.S.-based community associations and management firms. This DPA does not address transfers of personal data subject to the laws of the EEA, UK, or Switzerland. If the parties agree that Civentry will process the personal data of individuals in those jurisdictions, they will execute appropriate additional terms (including the EU Standard Contractual Clauses and any UK addendum) before such processing begins.
12. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
13. Term, Conflicts, and Miscellaneous
This DPA is effective for as long as Civentry processes Customer Personal Data under the Agreement. In the event of a conflict regarding the processing of Customer Personal Data, the order of precedence is: (1) this DPA; (2) the rest of the Agreement. Except as amended by this DPA, the Agreement remains in full force. This DPA is governed by the same governing law and dispute-resolution terms as the Agreement.
14. Signatures (for negotiated engagements)
For engagements where the parties execute this DPA, it is agreed and accepted as of the date last signed below.
| Daddisyn Labs, LLC | Customer |
|---|---|
| Signature: ________________ | Signature: ________________ |
| Name: ________________ | Name: ________________ |
| Title: ________________ | Title: ________________ |
| Date: ________________ | Date: ________________ |
Schedule 1: Details of Processing
Roles. Customer = Business/Controller. Civentry = Service Provider/Processor.
Subject matter. Provision of the Civentry service (document organization, AI-assisted financial analysis, resident-transparency controls, and vendor-bid workflows).
Nature and purpose of processing. Receiving, storing, parsing, extracting structured data from, analyzing (including via AI to generate drafts for human review), organizing, transmitting, and displaying Customer Personal Data to deliver the Service; securing the Service; and providing support.
Duration. For the term of the Agreement, plus the retention period in Section 9.
Categories of data subjects. Customer's authorized users (e.g., treasurers, board members); residents and members of the community association(s) whose information appears in uploaded documents; and vendors/contractors who participate in bid workflows.
Categories of Customer Personal Data. Names, email addresses, roles, and association affiliation; information contained in uploaded financial and governing documents, which may include resident names, contact details, unit information, delinquency status, and payment information appearing in those documents; and data derived from such documents.
Sensitive data. Civentry does not request sensitive categories of data (such as Social Security numbers, full financial account numbers, or health information) and instructs Customers not to upload them; such data may nonetheless appear in documents a Customer chooses to upload. Customer is responsible for what it uploads.
Schedule 2: Security Measures
Civentry maintains technical and organizational measures designed to protect Customer Personal Data, including:
- Access control: role-based access (Treasurer/Administrator, Board Member, Resident) enforced through application- and database-level controls, not solely in the interface.
- Tenant isolation: each association is isolated from every other through tenant-based access controls designed to prevent cross-Organization access.
- Encryption: in transit using modern TLS (1.3 preferred, 1.2 minimum); at rest using AES-256 via infrastructure providers.
- Document storage: private storage (no public buckets or public links); access via short-lived, time-limited signed URLs; direct storage locations not exposed in the interface; upload validation and file type/size limits.
- Authentication: multi-factor authentication available for administrative roles.
- Human review gate: AI-generated outputs are drafts until an authorized user reviews and approves them.
- Audit logging: security-relevant events recorded in an audit log that is append-only in normal application use and retained for at least 12 months.
- Sub-processor diligence: reliance on established infrastructure providers with recognized security certifications, each bound by a data processing agreement.
A current description of Civentry's practices is maintained on its Security & Data Handling page. Civentry may update these measures provided the updates do not materially reduce the overall security of the Service.
Schedule 3: Sub-Processor List
| Sub-Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and document storage | United States |
| Anthropic | AI analysis of documents | United States |
| LlamaIndex / LlamaParse | Document parsing and text extraction | United States |
| Stripe | Payment processing | United States |
| Vercel | Application hosting | United States |
| Resend | Transactional email delivery | United States |