Handback

Handback Data Processing Addendum

Effective: 1 August 2026

This Data Processing Addendum (“DPA”) forms part of the Handback Terms of Service between the customer (“Customer”) and the individual operator of Handback (“Handback”), who is based in the United States. The operator's legal name and address are available on request from support@tryhandback.com and will be published here once a business entity is registered. This DPA applies when Handback processes Customer Personal Data on Customer's behalf.

1. Definitions

“Applicable Privacy Law” means a privacy, data-protection, or data-security law that applies to Handback's processing of Customer Personal Data under the agreement.

“Customer Personal Data” means personal information or personal data contained in Customer Content that Handback processes on Customer's behalf, including information about tenants, occupants, vendors, or other individuals. It does not include information for which Handback independently determines the purposes and means of processing, such as account administration, service security, or direct support communications.

“process,” “processor,” “controller,” “business,” “service provider,” “contractor,” “sell,” “share,” and related terms have the meanings given by Applicable Privacy Law.

“Security Incident” means unauthorized access to, acquisition, destruction, loss, alteration, or disclosure of Customer Personal Data in Handback's custody or control. It does not include unsuccessful attempts that do not compromise Customer Personal Data.

“Subprocessor” means a third party engaged by Handback to process Customer Personal Data on Customer's behalf.

2. Roles and instructions

Customer determines the purpose and means of processing Customer Personal Data and acts as controller or business to the extent those terms apply. Handback acts as processor, service provider, or contractor on Customer's behalf to the extent those terms apply.

Handback will process Customer Personal Data only:

If Handback believes an instruction violates Applicable Privacy Law, it may suspend the relevant processing and inform Customer, unless legally prohibited.

Customer is responsible for the lawfulness, accuracy, and minimization of Customer Personal Data and for giving required notices, obtaining required permissions, responding to individuals, and issuing lawful instructions.

3. Processing details

4. Confidentiality and security

Handback will ensure that people authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access it only as necessary for assigned responsibilities.

Handback will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and the size and context of the service. The controls actually in place are listed in Section 7 of the Privacy Notice.

Handback may update safeguards as technology and risks change, provided that it does not materially reduce the overall protection of Customer Personal Data during the account term.

5. Security incidents

Handback will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. The notice will provide information reasonably available to Handback about the nature of the incident, affected information, likely consequences, containment or remediation steps, and a contact for follow-up.

Handback's notification or response is not an admission of fault or liability. Customer is responsible for determining whether it must notify tenants, regulators, or others, and Handback will provide reasonable assistance based on information available to it.

6. Subprocessors

Customer gives Handback general authorization to use Subprocessors necessary to provide the service. Handback will:

If Customer reasonably objects to a new Subprocessor on data-protection grounds, Customer may contact Handback within 15 days of notice. The parties will try to resolve the concern. If no reasonable alternative is available, Customer may stop using the affected feature or close the account.

7. Assistance with individual requests

Taking into account the nature of the processing, Handback will provide functionality or reasonable assistance enabling Customer to respond to verified requests to access, correct, obtain, or delete Customer Personal Data.

If Handback receives a request directly from a person concerning Customer Personal Data, Handback will, as appropriate and legally permitted:

Handback will not independently respond on Customer's behalf unless Customer instructs it to do so or law requires it.

8. Compliance assistance and information

Taking into account the nature of processing and information available to Handback, Handback will provide reasonable assistance with Customer's legally required privacy impact assessments, security assessments, consultations, and responses to regulators relating to Handback's processing of Customer Personal Data.

On reasonable written request, Handback will provide information reasonably necessary to demonstrate compliance with this DPA. Any review must protect other customers, security, confidential information, and trade secrets; avoid unreasonable disruption; and ordinarily rely first on existing documentation, questionnaires, or independent reports. On-site audits are available only when required by Applicable Privacy Law and after reasonable notice, scope, confidentiality, and security arrangements.

9. Return and deletion

During the account term, Customer may export Customer Personal Data at any time as a complete archive, and may delete individual records or the entire account from within the application. Account closure performed in the application erases Customer Personal Data, including uploaded files, from active systems immediately. Where closure is requested by email instead, Handback will act within 30 days of verifying the request, unless law permits or requires retention.

Customer Personal Data in Handback's disaster-recovery backups, which are held on encrypted storage and are accessible only to the operator, ages out within approximately 14 further days. If backup data is restored, the deletion is reapplied. Handback retains a record of each deletion — its date, the volume removed, and a one-way hash of the account email — together with any limited information necessary to protect security, comply with law, or establish, exercise, or defend legal claims.

10. California terms

To the extent the California Consumer Privacy Act (“CCPA”) applies to Customer Personal Data, the parties acknowledge and agree that:

  1. Customer discloses Customer Personal Data to Handback only for the limited and specified business purposes in Sections 2 and 3.
  2. Handback will not sell or share Customer Personal Data.
  3. Handback will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than the limited and specified purposes in this DPA, except as permitted by the CCPA.
  4. Handback will not combine Customer Personal Data with personal information received from or on behalf of another person or collected from Handback's own interaction with an individual, except as permitted by the CCPA.
  5. Handback will comply with applicable CCPA obligations and provide the same level of privacy protection required of businesses with respect to Customer Personal Data.
  6. Customer may take reasonable and appropriate steps to help ensure that Handback uses Customer Personal Data consistently with Customer's CCPA obligations.
  7. Handback will notify Customer if Handback determines it can no longer meet its CCPA obligations.
  8. After notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
  9. Handback will enable Customer to comply with applicable consumer requests or will comply with requests forwarded by Customer when Customer provides the information reasonably necessary to do so.
  10. Handback will require a Subprocessor processing Customer Personal Data to enter a written contract containing applicable CCPA protections.

The parties certify that they understand and will comply with these restrictions.

11. International processing

Handback is currently designed for U.S. rental-property use and does not represent that it complies with the laws of every country. Customer will not use Handback to process personal data governed by non-U.S. transfer restrictions unless the parties have implemented legally required transfer terms and safeguards.

12. Conflict, changes, and contact

If this DPA conflicts with the Terms concerning processing of Customer Personal Data, this DPA controls. All other provisions of the Terms remain in effect.

Handback may update this DPA as the service or Applicable Privacy Law changes. Material reductions in Customer's data-protection rights will be handled under the change-notice process in the Terms.

Privacy contact: support@tryhandback.com Security contact: support@tryhandback.com A postal address for legal notices is available on request from support@tryhandback.com.

HomeTermsPrivacy Data Processing AddendumSubprocessors Contact