Data Processing Addendum
Effective date: June 7, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Terms and Conditions or other written agreement (the "Agreement") between HOA in a Box and the customer that uses the HOA in a Box platform ("Customer"). It applies whenever HOA in a Box processes Personal Data on Customer's behalf in connection with the Services. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls. Records processed through the Services on Customer's behalf are confidential and are handled in accordance with this DPA and the Privacy Policy.
1. Definitions
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including U.S. state privacy laws (such as the California Consumer Privacy Act, as amended by the CPRA) and, to the extent applicable, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
- "Personal Data" means information relating to an identified or identifiable individual that HOA in a Box processes on Customer's behalf under the Agreement.
- "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given under Applicable Data Protection Law. For U.S. state laws, "Controller" includes "business," and "Processor" includes "service provider" or "processor."
- "Subprocessor" means a third party engaged by HOA in a Box to process Personal Data.
2. Roles of the parties
With respect to Personal Data processed under the Agreement, Customer is the Controller and HOA in a Box is the Processor acting on Customer's documented instructions. Customer is responsible for the lawfulness of the Personal Data it provides and of Customer's instructions, including having a valid legal basis and providing required notices and obtaining required consents from Data Subjects (for example, the residents and owners whose records it enters).
3. Scope and instructions
HOA in a Box will process Personal Data only: (a) to provide and support the Services; (b) in accordance with Customer's documented instructions, including those set out in the Agreement and this DPA and as configured by Customer through the Platform; and (c) as required by applicable law, in which case HOA in a Box will inform Customer of the legal requirement before processing unless prohibited by law. The subject matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A. HOA in a Box will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Confidentiality
HOA in a Box ensures that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and are trained on their data protection responsibilities. Access to Personal Data is limited to personnel who need it to provide the Services.
5. Security measures
HOA in a Box implements and maintains the technical and organizational measures described in Annex B to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing. HOA in a Box may update these measures provided that the updates do not materially reduce the overall level of security.
6. Subprocessing
Customer provides general authorization for HOA in a Box to engage Subprocessors to process Personal Data. HOA in a Box will: (a) enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA; (b) remain responsible for each Subprocessor's performance of its obligations; and (c) maintain a list of the categories of Subprocessors in Annex C. HOA in a Box will provide notice of intended changes to its Subprocessors (for example, by updating Annex C or by email to Customer's designated contact) and Customer may object on reasonable data protection grounds by notifying [email protected]; the parties will work in good faith to resolve the objection.
7. Assistance with Data Subject rights
Taking into account the nature of the processing, HOA in a Box will provide reasonable assistance, including appropriate technical and organizational measures, to help Customer respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law. If HOA in a Box receives such a request directly, it will, unless legally prohibited, promptly forward the request to Customer and not respond except on Customer's instruction.
8. Personal Data Breach notification
HOA in a Box will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and HOA in a Box will provide reasonable cooperation to support Customer's own notification obligations. Report suspected incidents to [email protected].
9. Data protection impact assessments
Taking into account the nature of processing and information available to HOA in a Box, HOA in a Box will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, where required by Applicable Data Protection Law.
10. International data transfers
HOA in a Box processes Personal Data in the United States. Where Customer's use of the Services involves the transfer of Personal Data subject to a law that restricts cross-border transfers (such as the GDPR or UK GDPR), the parties will put in place an appropriate transfer mechanism — including, where applicable, the European Commission Standard Contractual Clauses or the UK International Data Transfer Addendum — which are incorporated by reference upon execution by the parties. HOA in a Box is currently focused on the U.S. market; Customers requiring such mechanisms should contact [email protected].
11. Return and deletion
On termination or expiry of the Agreement, HOA in a Box will, at Customer's choice, make Customer Personal Data available for export and then delete or return it, except to the extent retention is required by applicable law (including the retention schedules that apply to the association) or for the establishment, exercise, or defense of legal claims. Backup copies are deleted in the ordinary course of HOA in a Box's backup cycle.
12. Audits and information
HOA in a Box will make available to Customer information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, no more than once per year (unless required by a supervisory authority or following a Personal Data Breach), and subject to confidentiality obligations, HOA in a Box will allow for and contribute to audits conducted by Customer or an independent auditor, which may be satisfied through HOA in a Box's then-current security documentation and third-party reports where available.
13. U.S. state privacy law terms
With respect to Personal Data subject to U.S. state privacy laws, HOA in a Box acts as a service provider or processor and certifies that it will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or as otherwise permitted by law; (c) retain, use, or disclose Personal Data outside the direct business relationship with Customer; or (d) combine Personal Data with information received from other sources, except as permitted by applicable law. HOA in a Box will comply with applicable obligations and provide the same level of privacy protection as required of Customer. Customer may take reasonable steps to ensure HOA in a Box's use of Personal Data is consistent with these obligations.
14. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
15. Term and governing law
This DPA takes effect on the Effective Date and continues for as long as HOA in a Box processes Personal Data on Customer's behalf. This DPA is governed by the governing law of the Agreement (the State of Oklahoma, United States) except where Applicable Data Protection Law requires otherwise for a specific provision.
Annex A — Details of processing
- Subject matter: Provision of the community association management Services.
- Duration: The term of the Agreement, plus any retention period required by law or configured by Customer.
- Nature and purpose: Hosting, storing, transmitting, organizing and displaying Personal Data to enable an association to maintain its member and property records, bill and collect assessments, correspond with residents, record violations, architectural requests and complaints, issue and evidence official notices, run meetings and ballots, publish its own website, and keep the records behind all of that.
- Types of Personal Data: Identifiers (name, postal address, email address, telephone number); the property or unit a person owns or occupies and their role in it; financial records relating to the association (assessments, payments, payment plans, balances); correspondence with the board; records of requests, architectural applications, violations and complaints — including the identity of a person who files a complaint, which the Platform withholds from the wider board; official notices and evidence of their delivery; amenity reservations; and the fact that a member voted in an association ballot.
- Categories of Data Subjects: Customer's Authorized Users — the board members and any managing agent it appoints — and the owners, residents and other occupants of the properties within the association, together with anyone who corresponds with the board through the Services.
Annex B — Technical and organizational security measures
- Encryption of Personal Data in transit (TLS) and at rest.
- Role-based access control with least-privilege access and authentication controls for administrative and production access.
- Logging, monitoring, and auditing of access to production systems and data.
- Network and application security controls, including hardened HTTP security headers, bot mitigation, and rate limiting on public endpoints.
- Dependency and vulnerability review as part of the deployment process, and a documented vulnerability disclosure process.
- Segregation of customer data in a multi-tenant environment and environment separation between development and production.
- Regular backups and a documented incident response process.
- Personnel confidentiality obligations and security awareness practices.
See the Trust Center for the current description of our security posture.
Annex C — Subprocessors
HOA in a Box engages the following categories of Subprocessors to provide the Services. A current list naming specific Subprocessors is available on request to [email protected].
- Cloud infrastructure hosting and content delivery (United States).
- Transactional email delivery for notifications and form submissions.
- Security, bot-mitigation, and DDoS-protection services.
- First-party, privacy-respecting product and website analytics.
- Payment processing.
- Transactional email delivery.
- Where Customer chooses to post an official notice through the Services, the print-and-post provider engaged at Customer's direction to print and mail it.
Contact
To request the current Subprocessor list, raise a data protection question, or request a countersigned copy of this DPA, contact [email protected].
Last updated: June 7, 2026