Effective: 1 August 2026
This Data Processing Addendum (“DPA”) forms part of the Handback Terms of Service between the customer (“Customer”) and the individual operator of Handback (“Handback”), who is based in the United States. The operator's legal name and address are available on request from support@tryhandback.com and will be published here once a business entity is registered. This DPA applies when Handback processes Customer Personal Data on Customer's behalf.
“Applicable Privacy Law” means a privacy, data-protection, or data-security law that applies to Handback's processing of Customer Personal Data under the agreement.
“Customer Personal Data” means personal information or personal data contained in Customer Content that Handback processes on Customer's behalf, including information about tenants, occupants, vendors, or other individuals. It does not include information for which Handback independently determines the purposes and means of processing, such as account administration, service security, or direct support communications.
“process,” “processor,” “controller,” “business,” “service provider,” “contractor,” “sell,” “share,” and related terms have the meanings given by Applicable Privacy Law.
“Security Incident” means unauthorized access to, acquisition, destruction, loss, alteration, or disclosure of Customer Personal Data in Handback's custody or control. It does not include unsuccessful attempts that do not compromise Customer Personal Data.
“Subprocessor” means a third party engaged by Handback to process Customer Personal Data on Customer's behalf.
Customer determines the purpose and means of processing Customer Personal Data and acts as controller or business to the extent those terms apply. Handback acts as processor, service provider, or contractor on Customer's behalf to the extent those terms apply.
Handback will process Customer Personal Data only:
If Handback believes an instruction violates Applicable Privacy Law, it may suspend the relevant processing and inform Customer, unless legally prohibited.
Customer is responsible for the lawfulness, accuracy, and minimization of Customer Personal Data and for giving required notices, obtaining required permissions, responding to individuals, and issuing lawful instructions.
Handback will ensure that people authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access it only as necessary for assigned responsibilities.
Handback will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and the size and context of the service. The controls actually in place are listed in Section 7 of the Privacy Notice.
Handback may update safeguards as technology and risks change, provided that it does not materially reduce the overall protection of Customer Personal Data during the account term.
Handback will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will provide information reasonably available to Handback about the nature of the incident, affected information, likely consequences, containment or remediation steps, and a contact for follow-up.
Handback's notification or response is not an admission of fault or liability. Customer is responsible for determining whether it must notify tenants, regulators, or others, and Handback will provide reasonable assistance based on information available to it.
Customer gives Handback general authorization to use Subprocessors necessary to provide the service. Handback will:
If Customer reasonably objects to a new Subprocessor on data-protection grounds, Customer may contact Handback within 15 days of notice. The parties will try to resolve the concern. If no reasonable alternative is available, Customer may stop using the affected feature or close the account.
Taking into account the nature of the processing, Handback will provide functionality or reasonable assistance enabling Customer to respond to verified requests to access, correct, obtain, or delete Customer Personal Data.
If Handback receives a request directly from a person concerning Customer Personal Data, Handback will, as appropriate and legally permitted:
Handback will not independently respond on Customer's behalf unless Customer instructs it to do so or law requires it.
Taking into account the nature of processing and information available to Handback, Handback will provide reasonable assistance with Customer's legally required privacy impact assessments, security assessments, consultations, and responses to regulators relating to Handback's processing of Customer Personal Data.
On reasonable written request, Handback will provide information reasonably necessary to demonstrate compliance with this DPA. Any review must protect other customers, security, confidential information, and trade secrets; avoid unreasonable disruption; and ordinarily rely first on existing documentation, questionnaires, or independent reports. On-site audits are available only when required by Applicable Privacy Law and after reasonable notice, scope, confidentiality, and security arrangements.
During the account term, Customer may export Customer Personal Data at any time as a complete archive, and may delete individual records or the entire account from within the application. Account closure performed in the application erases Customer Personal Data, including uploaded files, from active systems immediately. Where closure is requested by email instead, Handback will act within 30 days of verifying the request, unless law permits or requires retention.
Customer Personal Data in Handback's disaster-recovery backups, which are held on encrypted storage and are accessible only to the operator, ages out within approximately 14 further days. If backup data is restored, the deletion is reapplied. Handback retains a record of each deletion — its date, the volume removed, and a one-way hash of the account email — together with any limited information necessary to protect security, comply with law, or establish, exercise, or defend legal claims.
To the extent the California Consumer Privacy Act (“CCPA”) applies to Customer Personal Data, the parties acknowledge and agree that:
The parties certify that they understand and will comply with these restrictions.
Handback is currently designed for U.S. rental-property use and does not represent that it complies with the laws of every country. Customer will not use Handback to process personal data governed by non-U.S. transfer restrictions unless the parties have implemented legally required transfer terms and safeguards.
If this DPA conflicts with the Terms concerning processing of Customer Personal Data, this DPA controls. All other provisions of the Terms remain in effect.
Handback may update this DPA as the service or Applicable Privacy Law changes. Material reductions in Customer's data-protection rights will be handled under the change-notice process in the Terms.
Privacy contact: support@tryhandback.com Security contact: support@tryhandback.com A postal address for legal notices is available on request from support@tryhandback.com.