DealStrand Data Processing Addendum
Effective August 29, 2026 · Version 1.1
Effective date: August 29, 2026
This Data Processing Addendum ("DPA") forms part of the DealStrand Terms of Service (the "Agreement") between Kerja Group LLC dba DealStrand ("DealStrand", "Processor") and the Customer ("Controller"). It applies to the extent DealStrand processes Personal Data on behalf of the Customer in providing the Service. It is accepted automatically when the Customer accepts the Agreement; no signature is required. Customers who need a countersigned copy or the EU Standard Contractual Clauses executed separately may request them at privacy@dealstrand.com.
1. Definitions
"Personal Data", "processing", "controller", "processor", "data subject", "supervisory authority", and "personal data breach" have the meanings given in the GDPR. "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU GDPR, UK GDPR, Swiss FADP, the California Consumer Privacy Act as amended, and other US state privacy laws. "Customer Data" has the meaning in the Agreement. "Sub-processor" means a third party engaged by DealStrand to process Customer Data.
2. Roles and scope
2.1 For Customer Data, the Customer is the controller (or "business") and DealStrand is the processor (or "service provider" / "contractor"). Where the Customer is itself a processor for its own clients, DealStrand is a sub-processor, and the Customer warrants that its instructions are authorized by the relevant controller.
2.2 For account, billing, and usage data described in the Privacy Notice, DealStrand is an independent controller and this DPA does not apply.
3. Details of processing (Annex I)
- Subject matter: provision of the DealStrand hosted deal-flow platform.
- Duration: the term of the Agreement plus the retention period in Section 9.
- Nature and purpose: hosting, storage, organization, document generation, electronic signature, communication, AI-assisted analysis, and related support, as instructed through the Service.
- Categories of data subjects: the Customer's team members; the Customer's clients, prospects, and counterparties, including buyers, sellers, property owners, investors, lenders, borrowers, contractors and vendors, referral partners, attorneys, notaries, and their representatives; Portal Users.
- Categories of Personal Data: identification and contact data (name, email, phone, structured address); professional data (company, role, license number and status); deal and property data; financial data (loan requests, financial statements, bids, invoices, fee arrangements, bank details supplied by the Customer's contacts); identity documents and tax forms uploaded to secure vaults; signatures and audit trails; communications and activity logs; portal credentials.
- Special categories: none intended. The Customer must not upload special-category data (for example health data or criminal-offense data) unless it has a lawful basis and has notified DealStrand.
- Frequency: continuous.
4. Processor obligations
DealStrand will:
(a) process Customer Data only on the Customer's documented instructions, which are the Agreement, this DPA, and the Customer's use of the Service's features and settings, unless required by law, in which case DealStrand will inform the Customer before processing unless legally prohibited; (b) inform the Customer if it believes an instruction violates Data Protection Laws; (c) ensure persons authorized to process Customer Data are bound by confidentiality; (d) implement the technical and organizational measures in Annex II; (e) respect the conditions in Section 6 for engaging Sub-processors; (f) taking into account the nature of processing, assist the Customer by appropriate technical and organizational measures in responding to data-subject requests; (g) assist the Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to DealStrand; (h) at the Customer's choice, delete or return Customer Data at the end of the Service as set out in Section 9; (i) make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as set out in Section 8; (j) not sell or share Customer Data, not retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes specified in the Agreement, and not combine it with Personal Data from other sources except as permitted by Data Protection Laws (CCPA service-provider terms). DealStrand certifies that it understands and will comply with these restrictions.
5. Customer obligations
The Customer will: (a) comply with Data Protection Laws in its collection and use of Customer Data, including providing all required notices to data subjects and obtaining any required consents; (b) ensure it has a lawful basis for each category of Personal Data it processes through the Service, in particular identity documents, tax forms, and financial information; (c) issue only lawful instructions; (d) configure the Service's access controls, portal grants, and retention settings appropriately; and (e) respond to data-subject requests relating to Customer Data.
6. Sub-processors
6.1 The Customer gives general authorization for DealStrand to engage the Sub-processors listed in Annex III and to add or replace Sub-processors.
6.2 DealStrand will notify the Customer of an intended new Sub-processor at least 15 days before it processes Customer Data, by email or in-product notice. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected subscription and receive a pro-rated refund of prepaid fees for the unused term.
6.3 DealStrand imposes on each Sub-processor data-protection obligations no less protective than this DPA and remains liable for its Sub-processors' performance.
7. Personal data breach
DealStrand will notify the Customer without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting Customer Data, providing available information about the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. DealStrand will cooperate with the Customer's own notification obligations. Notification is not an admission of fault.
8. Audits
On written request no more than once per year (or following a breach or a supervisory-authority request), DealStrand will provide documentation of its security measures and responses to reasonable security questionnaires. If this is insufficient to demonstrate compliance, the Customer or an independent auditor bound by confidentiality may conduct an audit at the Customer's cost, on 30 days' notice, during business hours, without unreasonable disruption, and excluding other customers' data.
9. Return and deletion
During the term the Customer can export Customer Data using the Service's export tools. After a trial expires without conversion, Customer Data is retained 14 days; after a paid subscription ends, 30 days; then it is permanently deleted from production systems, and residual copies are purged from encrypted backups within 90 days of deletion from production. DealStrand may retain Customer Data as required by law, protecting its confidentiality until deletion.
10. International transfers
10.1 DealStrand processes Customer Data in the United States (and, where offered and selected by the Customer, an EU region).
10.2 For transfers of Personal Data from the EU/EEA, the parties incorporate the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor), or Module Three (processor to processor) where the Customer is a processor, with: Clause 7 (docking) included; Clause 9 Option 2 with the notice period in Section 6.2; Clause 11 optional language not included; Clause 13 and Clause 17 governed by the law of Ireland; Clause 18 courts of Ireland; Annexes I and II completed by Sections 3 and Annex II; Annex III by Annex III of this DPA.
10.3 For transfers from the UK, the UK International Data Transfer Addendum to the SCCs applies with the parties' details from the Agreement and this DPA. For Switzerland, the SCCs apply with the adaptations required by the Swiss FADP and the Federal Data Protection and Information Commissioner as the competent authority.
10.4 Where a Sub-processor is certified under the EU-US Data Privacy Framework, DealStrand may rely on that certification for onward transfers to that Sub-processor.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Agreement. In the event of conflict, the Standard Contractual Clauses prevail, then this DPA, then the Agreement.
Annex II — Technical and organizational measures
- Tenant isolation: each Customer workspace runs as a separate application with its own database and file storage on the hosting platform; no shared database between customers.
- Encryption: TLS 1.2+ for all traffic; encrypted backups at rest; sensitive vault documents stored outside the web root with restricted file permissions and served only through authenticated, nonce-checked handlers.
- Access control: role-based permissions in the product (operator, team member, portal user by category); administrative access to servers restricted to named personnel with key-based authentication; least privilege.
- Authentication: hashed passwords, rate limiting, bot protection (Cloudflare Turnstile), session management; single-method login gate.
- Logging and monitoring: audit logs of sensitive actions (document access, signature events, legal-document decisions), uptime and health monitoring, error monitoring.
- Backups and resilience: scheduled off-site encrypted backups; documented restore procedure; backup retention not exceeding 90 days as in Section 9.
- Network protection: CDN, DDoS mitigation, web application firewall, DNS hosted at Cloudflare; server firewall limited to required ports.
- Secure development: versioned releases, integrity-checked deployments, code review, dependency updates and patching.
- Personnel: confidentiality obligations; access limited to support, security, and maintenance purposes.
- Data minimization and retention: deletion schedule in Section 9; export tools for Customers.
- AI providers: contractual no-training terms; data sent only when a feature is invoked; option for Customer-managed provider keys.
- Incident response: documented breach procedure with the notification commitment in Section 7.
Annex III — Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| IONOS | VPS hosting of Customer workspaces | United States (EU region where offered) |
| Ploi (a WebBuilds B.V. product) | Server provisioning, management, and deployment control plane | Europe (exact country not published); account and server-management data is processed by Ploi |
| Cloudflare, Inc. | CDN, DNS, TLS, WAF, bot protection | Global / United States |
| Resend | Transactional email delivery | United States |
| Anthropic, PBC | AI features (when invoked) | United States |
| Paddle.com Market Limited | Merchant of Record — billing data only (not Customer Data) | UK / EU / US |
| [to be completed] | Encrypted off-site backups | United States |
| [to be completed] | Support desk and diagnostics | United States |
Contact for this DPA: Kerja Group LLC dba DealStrand, 386 South Atlantic, 59, Ormond Beach, Florida 32176, USA · privacy@dealstrand.com