DealWise AI – Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms and Conditions between DealWise AI, LLC (“DealWise,” “we,” “our,” or “us”) and the customer who accepts them (“Customer,” “you”). It governs how DealWise processes personal data on your behalf when you use the DealWise AI platform (the “Platform”).
This DPA applies automatically from the date above; nothing needs to be signed for it to take effect. If your own compliance process requires a countersigned copy, or the Standard Contractual Clauses on a separate executed document, write to support@dealwiseai.com and we will provide one.
1. Roles of the Parties
You are the controller of the personal data you put into the Platform. DealWise is your processor and processes that data only to provide the Platform to you and only on your documented instructions.
For the narrow set of data DealWise handles for its own purposes — your account and billing details, and the technical records it keeps in order to run and secure the service — DealWise acts as a controller. That processing is governed by the Privacy Policy rather than by this DPA.
“Controller,” “processor,” “personal data,” “processing,” “data subject” and “personal data breach” carry the meanings given to them in the EU General Data Protection Regulation and, for United Kingdom data, in the UK GDPR and the Data Protection Act 2018.
2. Subject Matter, Nature, Purpose and Duration
The subject matter of the processing is the provision of commercial real estate underwriting software.
The nature and purpose of the processing is to:
- store the deal inputs you enter and the documents you upload
- read those documents so that the terms in them can be proposed to you for review
- compute underwriting outputs from the rent roll you have accepted
- produce written analysis of those outputs
- deliver your documents and results back to you, and to nobody else
Processing continues for as long as your account exists, and ends as described in clause 10.
3. Categories of Personal Data and of Data Subjects
Two very different populations appear in the Platform, and the second is the one a vendor review is usually asking about.
The first is you. As the account holder, the personal data DealWise holds about you is:
- your name, email address and company name
- the sign-in credentials held by the authentication provider on DealWise's behalf
- your billing contact details, held by the payment processor
- records of your activity in the Platform, including which documents were delivered to you and when
The second is third parties who have no relationship with DealWise at all, and who appear because they are named in a document you upload:
- tenants, and the guarantors who stand behind their leases
- individual landlords, sellers and buyers
- brokers, agents and property managers
- signatories, contacts and principals named in an offering memorandum, an operating statement or a comparable-sale sheet
The categories of personal data are whatever those documents happen to contain, which in practice usually includes:
- names, business addresses and sometimes home addresses
- telephone numbers and email addresses
- signatures
- commercial terms attributable to a named individual, such as rent, deposits, options and guarantees
- financial information about a named guarantor or a sole trader
DealWise does not ask for special category data, government identifiers or payment card numbers, and no feature requires them. Documents are uploaded whole, so DealWise cannot prevent such data appearing inside one; what you upload is yours to control.
The third parties above did not agree to anything with DealWise and in most cases will not know the Platform exists. Having a lawful basis for putting their information into it, and giving them whatever notice their own law requires, is your responsibility as controller — it is the representation you make in clause 6 of the Terms and Conditions.
4. Instructions
DealWise processes personal data only on your documented instructions. Your instructions are the Terms and Conditions, this DPA, and the operations you carry out in the Platform.
DealWise will not:
- process your content for its own purposes beyond what is needed to provide, secure and support the Platform
- sell your content, or share it for cross-context behavioural advertising
- use your content to train artificial intelligence models, or permit the artificial intelligence provider described in clause 7 to do so
If DealWise believes an instruction infringes data protection law, it will tell you and may suspend that processing until the point is resolved. If DealWise is required by law to process personal data other than on your instructions, it will tell you before doing so unless that law forbids it.
5. Confidentiality
DealWise is operated by a small team. Everyone with access to production systems is bound by a duty of confidentiality that survives the end of their engagement, and that access is limited to the people who need it to run and support the Platform.
DealWise personnel do not read your documents as a matter of routine. Access happens for a stated reason — investigating a fault you have reported, or a security incident — and any document delivered through the Platform is recorded against the account that received it.
Administrative access to the underlying database and file storage is not itself reported to you. That limit is stated on the Security page rather than left for you to discover.
6. Security Measures
DealWise implements technical and organisational measures appropriate to the risk of the processing described above.
The measures actually in place — private document storage with no public or shareable download link, delivery only to an authenticated session, row-level isolation enforced by the database rather than by application code, credential scrubbing before any error report leaves the service, and encryption in transit and at rest — are described on the Security page. That page is the description of measures for the purposes of this DPA, and it is written to be read by someone deciding whether to trust it.
The same page states what is not in place, including the absence of multi-factor authentication and of a SOC 2 or ISO 27001 report. Read it before deciding whether DealWise is an appropriate processor for the data you intend to upload.
Measures may change as the Platform changes. They will not be reduced in a way that materially lowers the protection of your content during your subscription term.
7. Sub-processors
You give DealWise general authorisation to engage sub-processors. The current list, described by function, is on the Sub-processors page. The providers are named individually on request to support@dealwiseai.com, which is how a sub-processor schedule for your own vendor review is obtained.
DealWise imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains liable to you for their performance as if it were its own.
DealWise will give at least thirty days' notice — by email to your account address, and by updating the Sub-processors page — before a new sub-processor begins processing your content.
If you object within that period on reasonable data protection grounds, tell us and we will try to offer an alternative. If we cannot, you may terminate your subscription and receive a pro-rata refund of the fees you have paid for the unused remainder of the term.
8. Assisting with Data Subject Requests
If a data subject contacts DealWise directly about content held in your account, DealWise will not answer them substantively. It will direct them to you and tell you they made contact, unless the law requires otherwise.
Most requests you can satisfy yourself, inside the Platform:
- deal inputs and uploaded documents can be viewed, corrected and deleted from the deal they belong to
- deleting a deal deletes its stored files as well as its records
- deal data can be exported as CSV, as an Excel workbook, or as a PDF summary
For anything the Platform cannot do on its own — closing an entire account, or locating every place one person is named across your deals — write to support@dealwiseai.com. DealWise will assist within ten business days, or sooner where your own statutory deadline is shorter and you say so.
There is no search across the contents of stored documents today. Finding one individual inside a large document set is therefore a manual exercise for both of us, and it is more useful to say that here than when the request arrives.
9. Personal Data Breach
DealWise will notify you without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting personal data it processes on your behalf.
The notification will describe, so far as it is known at the time:
- what happened, and when it happened and was discovered
- the categories and approximate number of data subjects and records concerned
- the likely consequences
- what has been done to address it and to limit the harm
DealWise will not notify a supervisory authority or the affected data subjects on your behalf. As controller that judgement and that duty are yours; DealWise's job is to give you what you need to make it, and to keep giving it as more becomes known.
10. Deletion and Return on Termination
While your subscription lasts you can export your deal data at any time, in the formats named in clause 8. Do that before closing the account: DealWise does not undertake to reconstruct an export afterwards.
On termination, DealWise will delete your content within thirty days of a written request to support@dealwiseai.com, except where it must keep something to comply with a legal obligation — billing records being the ordinary case.
Deletion removes the database records and the stored files, and DealWise keeps no separate archive of customer content. Copies held inside the infrastructure providers' own routine backups are removed on those providers' cycles rather than on ours, and DealWise cannot pull a single record out of one ahead of that schedule.
11. Audit
DealWise will make available the information reasonably necessary to demonstrate compliance with this DPA, and will complete a written security questionnaire.
There is no SOC 2 report and no ISO 27001 certificate to send you, and no third-party penetration test report. If your vendor review requires one of those, DealWise does not meet that bar today. You should know that before you buy rather than at renewal.
DealWise will allow and contribute to audits, including inspections, conducted by you or by an auditor you mandate: on reasonable written notice, subject to confidentiality, no more than once in any twelve-month period unless a supervisory authority requires otherwise, and at your cost.
12. International Transfers
DealWise AI, LLC is a United States company and the Platform is operated from the United States. Personal data you put into the Platform is processed there.
Where you transfer personal data subject to the GDPR, the UK GDPR or the Swiss FADP, the European Commission's Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), are incorporated into this DPA and take effect between us.
The Clauses are completed as follows:
- you are the data exporter and DealWise is the data importer
- clause 7, the docking clause, applies
- clause 9 uses option 2, general written authorisation, with the notice period set in clause 7 of this DPA
- clause 11 does not use the optional independent dispute resolution body
- clause 17 selects the law of Ireland, and clause 18(b) the courts of Ireland
- Annexes I, II and III are populated by clauses 2, 3, 6 and 7 of this DPA together with the Sub-processors page
For United Kingdom transfers, the Information Commissioner's International Data Transfer Addendum (version B1.0) applies to those Clauses, with tables 1 to 3 completed by this DPA and table 4 selecting the importer. For Switzerland, references to the GDPR are read as references to the FADP and the Federal Data Protection and Information Commissioner is the competent authority.
This choice of law governs transfer disputes under the Clauses. It does not displace the governing law and dispute resolution provisions of the Terms and Conditions for anything else.
13. United States State Privacy Laws
Where the California Consumer Privacy Act applies, DealWise is a “service provider” and you are the “business.” DealWise does not sell or share personal information, does not retain, use or disclose it for any purpose other than performing the services, and does not combine it with personal information obtained from another source except as that Act permits.
Equivalent commitments apply where the processing is governed instead by the privacy law of Virginia, Colorado, Connecticut, Utah, Texas or another United States state.
14. Precedence, Liability and Changes
This DPA forms part of the Terms and Conditions. Where the two conflict on a matter of data protection, this DPA prevails; on every other matter the Terms prevail.
The limitation of liability in clause 15 of the Terms and Conditions applies to claims under this DPA, except to the extent the law does not permit it to.
DealWise may update this DPA. Where a change materially reduces your rights or DealWise's obligations, it will be notified by email to your account address at least thirty days before it takes effect, and the date at the top of this page will move with it.
15. Contact Information
DealWise AI, LLC
See also the Security page it refers to, the Sub-processors list, the Privacy Policy, and the Terms & Conditions this addendum forms part of.