Legal

Data Processing Addendum

This addendum describes how Rentyn processes customer personal information for landlord and property-operator accounts.

Last updated: June 19, 2026

This customer-facing DPA is a practical starting point. Enterprise customers may require a signed version, subprocessors list, security exhibit, and jurisdiction-specific clauses.

1. Scope

This Data Processing Addendum applies when Rentyn processes personal information on behalf of a landlord, property operator, or other business customer under the Rentyn Terms of Service or another written agreement.

Rentyn's mailing address is 265 rue Hymus, Pointe-Claire, QC H9R 0G2, Canada. Rentyn serves customers in Canada and the United States. This DPA is designed to assist customers in meeting obligations under PIPEDA, Quebec Law 25, and applicable United States privacy laws.

2. Roles

The customer is the controller, business, or equivalent decision-maker for tenant, resident, vendor, property, and staff personal information submitted to Rentyn. Rentyn acts as a processor, service provider, or equivalent vendor when processing that information to provide the service.

3. Processing Instructions

Rentyn will process customer personal information according to the customer's documented instructions, including the service agreement, product configuration, account settings, support requests, and lawful use of the Rentyn service.

4. Categories of Information

5. Purpose of Processing

Rentyn processes customer personal information to provide, secure, support, maintain, improve, and troubleshoot the service; route tenant communications; manage AI-assisted workflows; produce summaries; support billing; and comply with legal obligations.

6. Confidentiality and Security

Rentyn will use reasonable administrative, technical, and organizational safeguards designed to protect customer personal information. Personnel and service providers with access to customer personal information must use it only for authorized purposes and are subject to confidentiality obligations.

7. Subprocessors

Rentyn may use subprocessors to provide hosting, database, authentication, communications, transcription, email, payment, AI, analytics, security, and support functions. Current or expected subprocessors may include Clerk, Supabase, Twilio, Stripe, Brevo, Meta, Deepgram, Anthropic, infrastructure providers, and similar vendors.

Rentyn remains responsible for subprocessors' processing of customer personal information as required by applicable law and the governing agreement.

Rentyn will notify customers of material changes to its subprocessors by updating this DPA or by email notice at least 14 days before the change takes effect where reasonably practicable. Customers who object to a new subprocessor on reasonable privacy grounds may contact us at support@rentyn.ca to discuss the concern before the change takes effect.

8. Breach Notification and Security Incidents

If Rentyn becomes aware of a confirmed security breach affecting customer personal information, Rentyn will notify the affected customer without unreasonable delay and in any event within 72 hours of becoming aware of the breach where practicable. The notification will describe: (a) the nature of the breach; (b) the categories and approximate number of individuals and records affected; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach.

Rentyn will also notify applicable regulatory authorities as required by law, including the Office of the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec (CAI) where required under PIPEDA and Quebec Law 25.

Customers are responsible for notifying their own tenants, residents, or other affected individuals where required by law, based on information provided by Rentyn.

9. Audit Rights

Rentyn will make available to customers, upon reasonable written request, information necessary to demonstrate compliance with Rentyn's obligations under this DPA. This may include security documentation, certifications, or summaries of relevant security controls.

Enterprise customers requiring additional audit rights or on-site assessments may request a signed DPA with expanded audit provisions by contacting support@rentyn.ca.

10. Customer Responsibilities

The customer is responsible for lawful collection and use of customer personal information, including notices, consents, tenant communications, call recording consent, SMS consent, emergency policies, data accuracy, user permissions, and account configuration.

11. Assistance

Rentyn will provide reasonable assistance, taking into account the nature of the service, for privacy requests, security incidents, and compliance obligations relating to customer personal information.

12. Return or Deletion

Upon account termination or written request, Rentyn will delete or return customer personal information where reasonably available and legally permitted. Unless a different account setting, plan, legal requirement, or written agreement applies, Rentyn generally aims to delete or anonymize tenant records, SMS logs, call recordings, transcripts, summaries, and maintenance history within 24 months after account closure. Rentyn may retain copies as needed for legal compliance, security, fraud prevention, dispute resolution, unpaid invoices, backups, and legitimate business records. Backups and system logs are deleted on normal rotation schedules.

13. International Processing

Customer personal information may be processed in Canada, the United States, and other locations where Rentyn or its subprocessors operate. Rentyn takes appropriate contractual and organizational measures to protect personal information transferred across borders. Customers are responsible for ensuring that their use of Rentyn is lawful for their tenant, resident, and property locations.

14. Contact

Privacy and data processing questions may be sent to support@rentyn.ca.