Legal
Data Processing Addendum
Last updated September 13, 2026
Contents
- 1. Purpose and structure of this Addendum
- 2. Roles of the parties
- 3. Details of the processing
- 4. PropertyStack's obligations as processor
- 5. Sub-processors
- 6. Security of processing
- 7. Personal-data breaches
- 8. International data transfers
- 9. Assisting with data-subject and consumer requests
- 10. Audits and information
- 11. Return and deletion on termination
- 12. CCPA/CPRA service-provider terms
- 13. Liability
- 14. How to execute the DPA
This page summarizes PropertyStack's Data Processing Addendum (the "DPA"), which governs how PropertyStack processes personal data on behalf of its customers when providing the PropertyStack property-management platform. It is written in plain language so that customers, their privacy teams and their own data subjects can understand our commitments before signing.
PropertyStack is operated by PropertyStack Software Pty Ltd (ABN 91 674 505 821) ("PropertyStack", "we", "us", "our"), an Australian private company located in Brisbane, Queensland, Australia. Correspondence relating to this Addendum should be directed to legal@propertystack.ai. In this Addendum, "you" and "Customer" mean the organization that has entered into a customer agreement with PropertyStack for use of the platform.
This is a summary only. The signable DPA — available on request from legal@propertystack.ai — sets out the full, legally binding terms, forms part of the customer agreement, and prevails over this page in the event of any conflict. The signable DPA also carries the authoritative, current list of sub-processors and the standard contractual clauses and transfer instruments referenced below.
This page is effective as of July 11, 2026 and was last updated on September 13, 2026.
1. Purpose and structure of this Addendum
This Addendum applies where, in the course of providing the PropertyStack platform, PropertyStack processes personal data for which the Customer is responsible. It supplements the customer agreement and does not vary any provision of that agreement except as expressly stated.
PropertyStack operates from Australia and serves customers in multiple jurisdictions. This Addendum is structured so that the terms applicable to the Customer depend on the data protection laws that apply to the Customer's processing. Our home jurisdiction is Australia, and the baseline regime is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (the "APPs"). Where the Customer or its data subjects are subject to other laws — including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), other US state privacy laws (including those of Virginia, Colorado, Connecticut and Utah), and Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA") — the corresponding module of the signable DPA applies in addition to the general terms.
PropertyStack does not currently offer or target its services to customers in the EU/EEA or the United Kingdom and has no EU or UK customers. Accordingly, PropertyStack has not appointed an EU or UK representative under Article 27 of the GDPR or the UK GDPR. If PropertyStack begins offering services in those regions, it will appoint the required representatives and update this page. The GDPR and UK GDPR modules of the signable DPA remain available for customers and data subjects to whom those laws may apply.
References in this Addendum to "controller", "processor", "business", "service provider", "personal data", "personal information", "data subject", "consumer", "processing" and "sub-processor" have the meanings given in the applicable data protection law. Where a term is defined differently across laws, the definition of the law applicable to the relevant processing controls.
This Addendum does not govern the marketing website at the PropertyStack domain, nor the personal information PropertyStack collects for its own purposes. Those are described in our Privacy Policy and Cookie Policy.
2. Roles of the parties
For personal data that PropertyStack processes on the Customer's behalf through the platform, the Customer is the controller (and, under the CCPA/CPRA, the "business") and PropertyStack is the processor (and, under the CCPA/CPRA, the "service provider"). Where the Customer is itself acting as a processor for a third party, PropertyStack acts as a sub-processor and the relevant terms flow down accordingly.
The Customer is responsible for establishing a lawful basis for the processing it instructs, for the accuracy and lawfulness of the personal data it or its users submit to the platform, and for providing any notices and obtaining any consents required from its guests, owners, contractors and staff.
Separately, PropertyStack acts as a controller (or "business") in respect of the account, administrative, billing and product-usage data it collects to establish and manage the customer relationship, to secure and improve the platform, and to meet its own legal obligations — for example administrator contact details, subscription and payment records, support interactions, and telemetry. That controller-side processing is described in our Privacy Policy, not in this Addendum.
3. Details of the processing
The signable DPA sets out the details of the processing in a schedule (equivalent to Annex I of the EU Standard Contractual Clauses). In summary:
- Subject-matter: PropertyStack's processing of personal data on the Customer's behalf in order to provide and support the platform.
- Duration: for the term of the customer agreement, followed by the return or deletion of personal data as described in section 11.
- Nature and purpose: hosting, storing, transmitting, organizing and otherwise processing personal data as necessary to deliver the platform's functionality — including guest messaging and the unified inbox, multi-calendar and channel management, tasks and maintenance, trust accounting, owner statements and disbursements, owner, guest and contractor portals, the direct booking site, PS Pay card payments, PS Verify guest identity and booking verification, smart-lock access, analytics, upsells, and related AI-agent features — in accordance with the Customer's documented instructions.
- Types of personal data: guest and owner contact details (such as name, email, phone and address); booking and stay information (such as reservation dates, property and channel, guest counts and preferences); guest and owner messages and communications; payment-related data processed in connection with PS Pay — cardholder data is handled by Kovena, our third-party payments provider, is not stored on PropertyStack servers, and is also subject to Kovena's own terms and privacy policy; identity and verification data processed in connection with PS Verify; property access codes and smart-lock credentials; contractor details; and Customer staff login and profile data. The Customer controls what personal data it submits.
- Special categories and sensitive information: apart from the identity-verification data described in the next bullet, the platform is not designed to process special-category data (as defined in Article 9 of the GDPR and UK GDPR) or sensitive information (as defined in section 6 of the Privacy Act 1988 (Cth)), and the Customer should not submit such data except where strictly necessary and permitted by applicable law.
- Identity verification (PS Verify): PS Verify processes guest identity and booking verification data on the Customer's behalf. This may include government-identifier information (such as passport or driver-license details), which is sensitive information under the Privacy Act 1988 (Cth). PropertyStack treats identity-verification data accordingly — it is used only for the restricted purpose of verifying guest identity and bookings, is subject to heightened security controls (including access restriction and encryption in transit and at rest), and is retained only for as long as necessary for that purpose. The Customer, as controller, is responsible for establishing a lawful basis for this processing before instructing it — including, where the Privacy Act 1988 (Cth) applies, obtaining consent or relying on another basis permitted under Australian Privacy Principle 3 — and for providing any required notices to its guests.
- Categories of data subjects: the Customer's guests and prospective guests; property owners; contractors and service providers; and the Customer's own staff and authorized users.
- Frequency: continuous, for the duration of the customer agreement.
4. PropertyStack's obligations as processor
Consistent with Article 28(3) of the GDPR and UK GDPR, and with equivalent obligations under the APPs and other applicable laws, PropertyStack undertakes that it will:
- Process the Customer's personal data only on the Customer's documented instructions — including the customer agreement, this Addendum, and the configuration and use of the platform — unless required to do otherwise by law, in which case (where legally permitted) PropertyStack will inform the Customer of that requirement before processing.
- Ensure that personnel authorized to process the personal data are bound by appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures as described in section 6.
- Respect the conditions for engaging sub-processors set out in section 5.
- Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (see section 9).
- Assist the Customer in ensuring compliance with its obligations relating to security of processing, notification of personal-data breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to PropertyStack.
- At the Customer's choice, delete or return the personal data on termination as described in section 11.
- Make available to the Customer the information necessary to demonstrate compliance with these obligations and allow for and contribute to audits, as described in section 10.
- Promptly inform the Customer if, in PropertyStack's opinion, an instruction infringes applicable data protection law.
5. Sub-processors
The Customer provides a general authorization for PropertyStack to engage sub-processors to process personal data in connection with the platform. PropertyStack imposes on each sub-processor data protection obligations that are, in substance, equivalent to those in this Addendum, and remains responsible to the Customer for the performance of its sub-processors' obligations.
The sub-processors currently engaged to deliver the PropertyStack product platform are: Kovena (Australia) — payment processing for PS Pay; Twilio Inc. (United States) — SMS and telephony; Twilio SendGrid (United States) — transactional email; ElevenLabs Inc. (United States) — AI voice and conversation features; Google LLC (United States) — analytics; and Vercel Inc. (United States) — web hosting; together with cloud infrastructure providers located in Australia and the United States. The authoritative, current sub-processor list for the product accompanies the signable DPA and may be requested at any time from legal@propertystack.ai.
Our AI providers process customer and visitor data solely to provide the service to us; we do not permit them to use that data to train their general-purpose models, and human oversight is retained for consequential actions.
PropertyStack will give the Customer at least 30 days' advance notice of any intended addition or replacement of a sub-processor, so as to give the Customer a reasonable opportunity to object on reasonable data-protection grounds. If the Customer objects and the parties cannot resolve the concern, the Customer may, as its remedy, terminate the affected part of the platform in accordance with the customer agreement.
For completeness, the separate marketing website relies on the sub-processors described under "How we share information" in our Privacy Policy — namely Vercel Inc. (hosting and content delivery), Google LLC (Google Analytics 4, only after consent), HYROS Inc. (advertising-attribution measurement for our own marketing campaigns, only after consent), ElevenLabs Inc. (the on-site assistant), Slack Technologies LLC (lead delivery to our team), HubSpot, Inc. (our customer relationship management system, which receives contact and resource submissions so our team can follow up) and Twilio Inc. (an SMS notification of your inquiry to our team so we can call you back promptly). Those relate to the website, not to the product platform governed by this Addendum, and are distinct from the product sub-processors listed above.
6. Security of processing
PropertyStack maintains appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 of the GDPR and UK GDPR and by Australian Privacy Principle 11.
Personal data is encrypted in transit using TLS, and data at rest is encrypted using industry-standard algorithms. PropertyStack applies least-privilege and role-based access controls and requires strong authentication for internal systems. Further detail is set out on our Security page.
No method of transmission or storage is completely secure, and the measures described here are those in effect from time to time; PropertyStack may update them provided the level of protection is not materially reduced.
7. Personal-data breaches
PropertyStack will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer's personal data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
PropertyStack will take reasonable steps to contain and remediate the breach and will cooperate with and assist the Customer so that the Customer can meet its own notification obligations to supervisory authorities and affected individuals — including, where applicable, under the GDPR/UK GDPR, the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), and other applicable laws. Notification is not, and will not be construed as, an acknowledgment of fault or liability.
In addition to assisting the Customer, where PropertyStack itself experiences an eligible data breach of personal data it holds and is subject to its own direct notification obligations — including under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), or under the GDPR, UK GDPR or other applicable law — PropertyStack will comply with those obligations, including any required notification to the Office of the Australian Information Commissioner (OAIC) or other competent authority.
8. International data transfers
The platform, and personal data processed through it, may be processed in countries other than the country in which the Customer or its data subjects are located — principally Australia and the United States, where our providers operate.
Where personal data subject to the GDPR is transferred to a country not covered by an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses ("SCCs") — Module Two (controller to processor) or Module Three (processor to processor), as applicable — which are incorporated into the signable DPA. Where personal data is subject to the UK GDPR, the parties rely on the UK International Data Transfer Agreement or the UK Addendum to the SCCs. Where required, transfer risk assessments and supplementary measures are addressed in the signable DPA.
For personal data subject to the Privacy Act 1988 (Cth), PropertyStack takes reasonable steps consistent with Australian Privacy Principle 8 in relation to overseas disclosure and remains accountable for the handling of that data by its overseas recipients. For personal data subject to PIPEDA, PropertyStack uses contractual means to ensure a comparable level of protection and remains accountable for that data when it is transferred to and processed by its recipients.
The signable DPA identifies the transfer mechanism applicable to each recipient and prevails as to the operative clauses.
9. Assisting with data-subject and consumer requests
If PropertyStack receives a request from a data subject or consumer to exercise rights under applicable law — such as access, correction, deletion, portability, restriction, objection, or opt-out — that relates to personal data processed on the Customer's behalf, PropertyStack will not respond directly except to confirm that the request should be directed to the Customer, unless legally required or instructed otherwise by the Customer.
Taking into account the nature of the processing, PropertyStack will provide reasonable assistance, including appropriate technical and organizational measures and platform functionality, to enable the Customer to respond to and fulfill such requests within the timeframes required by applicable law.
10. Audits and information
PropertyStack will make available to the Customer the information reasonably necessary to demonstrate compliance with its obligations under this Addendum and applicable data protection law, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer.
To minimize disruption and protect the confidentiality and security of PropertyStack's systems and other customers' data, the Customer will ordinarily satisfy its audit rights by reviewing PropertyStack's then-current third-party audit reports and certifications, where any are available. Any on-site or more detailed audit will be conducted on reasonable prior notice, during business hours, no more than once per year (except where required by a supervisory authority or following a personal-data breach), subject to confidentiality, and at the Customer's cost, as further set out in the signable DPA.
11. Return and deletion on termination
On termination or expiry of the customer agreement, the Customer may export its data from the platform for 30 days. After that export window, PropertyStack will, at the Customer's choice, delete or return the personal data processed on the Customer's behalf, and will delete or de-identify remaining copies within a reasonable period, unless applicable law requires continued storage.
PropertyStack may retain personal data to the extent, and for the period, required by applicable law. In particular, customer account records are retained for the life of the account and for up to seven years after closure where required by Australian tax, GST, trust-accounting and financial-reporting law. PropertyStack will continue to protect any retained data in accordance with this Addendum for as long as it is held.
12. CCPA/CPRA service-provider terms
Where the CCPA/CPRA applies, PropertyStack acts as a "service provider" and processes personal information only on the Customer's behalf. PropertyStack certifies that it understands and will comply with the following restrictions:
- PropertyStack does not sell, and does not share (for cross-context behavioral advertising), the personal information disclosed by the Customer.
- PropertyStack does not retain, use or disclose that personal information for any purpose other than the specific business purpose of performing the services under the customer agreement, or as otherwise permitted by the CCPA/CPRA.
- PropertyStack does not retain, use or disclose that personal information outside the direct business relationship between PropertyStack and the Customer.
- PropertyStack does not combine that personal information with personal information it receives from, or on behalf of, other persons, or collects from its own interactions with the consumer, except as permitted by the CCPA/CPRA.
- The Customer may take reasonable and appropriate steps to ensure that PropertyStack uses the personal information it discloses in a manner consistent with the Customer's obligations under the CCPA/CPRA, and to stop and remediate any unauthorized use of that personal information.
- PropertyStack grants the Customer the right to monitor PropertyStack's compliance with these service-provider obligations, including through the audit, assurance and information-provision mechanisms described in section 10.
- PropertyStack will comply with applicable obligations under the CCPA/CPRA, provide the same level of privacy protection as required of a business, and enable the Customer to respond to verifiable consumer requests. PropertyStack will notify the Customer if it determines it can no longer meet these obligations. Comparable service-provider or processor terms apply under the Virginia, Colorado, Connecticut and Utah privacy laws.
13. Liability
Each party's liability arising out of or related to this Addendum, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the customer agreement, and any reference in that agreement to the liability of a party means the aggregate liability of that party under the agreement and this Addendum together.
Nothing in this Addendum limits or excludes any liability that cannot be limited or excluded under applicable law. In particular, the consumer guarantees under the Australian Consumer Law are not excluded.
14. How to execute the DPA
Customers that require a signed DPA — for example to meet obligations under the GDPR, UK GDPR, the Privacy Act 1988 (Cth) or other applicable laws — should contact legal@propertystack.ai to request the current signable version.
The signable DPA, once executed by both parties, forms part of and is governed by the customer agreement, including its governing-law and dispute-resolution terms. Unless the customer agreement states otherwise, it is governed by the laws of Queensland, Australia, and the parties submit to the jurisdiction of the courts of Queensland and the Federal Court of Australia.
For privacy questions generally, contact our Privacy Officer, who can be reached at privacy@propertystack.ai; for security questions, contact security@propertystack.ai.