Data Processing Agreement

Last Updated: July 5, 2026

This Data Processing Agreement ("DPA") is entered into between ReGild LLC, a Georgia limited liability company doing business as GnomeOwner, of 1445 Woodmont Ln NW #1769, Atlanta, GA 30318 ("GnomeOwner," "we," "us"), and the homeowners association, condominium owners association, or property owners association that subscribes to the GnomeOwner Services ("Association," "you").

This DPA forms part of, and is incorporated by reference into, the GnomeOwner Terms of Service (the "Terms"). It governs GnomeOwner's processing of Personal Information on the Association's behalf. If this DPA conflicts with the Terms or the Privacy Policy on a matter of data processing, this DPA controls; on all other matters, the Terms control.

1. Roles of the Parties

1.1 The Association is the controller. The Association collects its members' and residents' Personal Information and decides why and how it is used. Under the California Consumer Privacy Act as amended ("CCPA") the Association is the "business," and under comparable state privacy laws it is the "controller."

1.2 GnomeOwner is the processor. GnomeOwner processes Personal Information only on the Association's behalf and at its documented instructions, as a "service provider" under the CCPA and a "processor" under comparable state privacy laws. The Association's documented instructions are: these Terms, this DPA, the Association's configuration of the Services, and the actions its authorized users take within the Services.

1.3 Nothing in this DPA makes GnomeOwner a "managing agent," fiduciary, property manager, or custodian of the Association's funds or records (see Terms Sections 1.2, 4.3).

2. Definitions

3. Scope and Details of Processing

3.1 Business Purpose (defined and limited). GnomeOwner processes Personal Information solely to provide, secure, support, and improve the HOA-management platform for the Association, on the Association's instructions. By feature category, this means: association record-keeping and ledgers; dues, assessment, and payment tracking and collection facilitation; bank-feed reconciliation; document storage, search, and analysis; meeting recording, transcription, and summarization; compliance-calendar and reminder features; board- and resident-facing communications (including routing, classifying, and storing resident-to-board correspondence as part of the Association's records); the resident portal; and AI-assisted versions of the foregoing. This categorical description is intended to cover like-for-like evolution of these features without amendment; a genuinely new category of processing requires an update to this DPA or the Privacy Policy with notice.

3.2 Categories of data subjects. Association board members, officers, and authorized administrators; unit owners and residents; portal users and their authorized helpers; and vendors or other individuals whose information the Association enters into the Services.

3.3 Categories of Personal Information. Names, email addresses, phone numbers, mailing and property addresses, unit numbers; dues, assessment, and payment history; ledger and financial records; meeting audio recordings and transcripts; uploaded governing documents and other association documents (including any personal information they contain); resident-to-board correspondence and communication records; portal account and sign-in records; and technical/usage data generated by use of the Services.

3.4 Duration. The subscription term plus any retention period under Section 11, until deletion in accordance with Section 11.

3.5 Location. All processing under this DPA takes place in the United States, by GnomeOwner and by the Sub-processors listed under Section 8. GnomeOwner will not move processing of Personal Information outside the United States without advance notice to the Association as a material change under Section 8.4.

4. GnomeOwner's Core Restrictions

GnomeOwner will:

(a) No selling. Not Sell the Personal Information.

(b) No sharing. Not Share the Personal Information (including for cross-context behavioral advertising or targeted advertising).

(c) No use outside the relationship. Not retain, use, or disclose the Personal Information for any purpose other than the Business Purpose, or outside the direct business relationship between GnomeOwner and the Association, except as Applicable Privacy Law permits a service provider or processor to do (for example, to detect and defend against security incidents or fraud, to comply with law, or for internal operations consistent with the Business Purpose and the Association's reasonable expectations).

(d) No combining. Not combine the Personal Information it receives from the Association with Personal Information it receives from another association or from any other source, except as the CCPA and its regulations expressly permit a service provider to do. In plain terms: one association's data is never blended into another's, and it is never used to build cross-customer profiles. (Tenant isolation is also enforced technically — see Section 7.)

(e) No training AI models. Not use Personal Information, uploaded documents, audio recordings, or the Association's financial data to train AI models, and engage only AI Sub-processors whose terms prohibit training on data submitted through their APIs (see Privacy Policy Section 2). Data sent to AI Sub-processors is processed per-request to generate the requested output.

(f) Same protection. Provide the same level of privacy protection as Applicable Privacy Law requires of the Association with respect to the Personal Information, and comply with the obligations Applicable Privacy Law places on service providers and processors.

GnomeOwner certifies that it understands the restrictions in this Section 4 and will comply with them.

5. Compliance Notification and Remediation

5.1 Duty to flag. GnomeOwner will notify the Association without undue delay if it determines that it can no longer meet its obligations under this DPA or Applicable Privacy Law.

5.2 Remediation. Upon such notice — or upon the Association's reasonable, good-faith belief that GnomeOwner is using Personal Information in an unauthorized manner — the Association may take reasonable and appropriate steps to stop and remediate the unauthorized use, and GnomeOwner will cooperate, including by suspending the affected processing while the issue is addressed.

6. Verification

6.1 The Association may take reasonable steps to confirm that GnomeOwner uses the Personal Information consistently with this DPA. On written request no more than once per twelve (12) months (or following a Personal Information breach affecting the Association, or where a regulator requires it), GnomeOwner will make available information reasonably necessary to demonstrate compliance — such as a summary of its security practices, its current Sub-processor list and the status of Sub-processor data-processing terms, and responses to a reasonable written security questionnaire.

6.2 This verification right is exercised through documentation and written responses in the first instance. It is not a right to unrestricted on-site inspection of GnomeOwner's (or its Sub-processors') infrastructure, and any further verification must be reasonable in scope, conducted so as not to compromise the security or confidentiality of other associations' data, at the requesting Association's expense, and subject to reasonable scheduling and confidentiality terms.

7. Security

GnomeOwner implements and maintains reasonable and appropriate technical and organizational measures to protect Personal Information, consistent with Privacy Policy Section 5, including:

GnomeOwner may update these measures over time, provided the updates do not materially reduce the overall protection of Personal Information.

8. Sub-processors

8.1 Authorization and disclosure. The Association gives GnomeOwner general authorization to engage Sub-processors to deliver the Services, within the following disclosed categories: cloud hosting and infrastructure (database, authentication, file storage, content delivery — currently Supabase and Vercel); AI / large-language-model providers (document search, board assistant, transcription and related AI features — currently including Google (Gemini) and Groq, on per-request, no-training API terms); bank connectivity (currently Plaid, read-only, solely to reconcile the Association's accounts, with no authority to move funds); payment processing (currently Stripe); and email delivery (currently Resend). All current Sub-processors process data in the United States.

8.2 Maintained list. A current, complete list of Sub-processors is maintained at gnomeowner.com/subprocessors, showing each vendor's purpose, a link to its privacy policy, and whether it is bound by its own signed data-processing agreement or data-processing terms with GnomeOwner.

8.3 Flow-down. GnomeOwner engages each Sub-processor under written terms that impose data-protection obligations at least as protective as those in this DPA with respect to the Personal Information the Sub-processor handles — including the restrictions in Section 4. GnomeOwner remains responsible to the Association for each Sub-processor's performance of those obligations.

8.4 Changes. GnomeOwner will post any new Sub-processor to the maintained list before it begins processing Personal Information. For a material change — a new category of processing, a Sub-processor gaining access to a new type of data (particularly financial, ledger, or banking data), processing moving outside the United States, or a vendor gaining rights to use data for its own purposes — GnomeOwner will additionally notify Association account holders by email or in-app notice before the change takes effect, and the Association may object in writing within thirty (30) days. If the objection cannot be resolved, the Association may terminate its subscription and this DPA without penalty (other than fees already accrued) and exercise its export and deletion rights under Section 11. A routine, like-for-like swap — replacing a vendor within an already-disclosed category performing the same function on materially equivalent terms (for example, one no-training API-only AI provider for another, or one U.S.-based hosting provider for another), or adding a redundant or backup vendor within a disclosed category on the same terms — is not a material change and requires only the list update.

9. Assistance with Consumer Rights Requests and Association Compliance

9.1 Taking into account the nature of the processing, GnomeOwner will assist the Association in responding to verifiable requests from consumers (members, residents, portal users) to exercise rights under Applicable Privacy Law — including access/know, deletion, and correction — by appropriate technical and organizational means. In most cases the Services themselves are the means: board administrators can view, export, correct, and delete member records directly.

9.2 If GnomeOwner receives a rights request directly from an individual that relates to Personal Information it processes on the Association's behalf, GnomeOwner will forward the request to the Association without undue delay and will not respond substantively on the Association's behalf except at the Association's direction or where Applicable Privacy Law requires. (Deletion requests by individual portal users for their own portal account are handled per Section 11.4.)

9.3 GnomeOwner will provide reasonable assistance, with information available to it, for the Association's own compliance obligations under Applicable Privacy Law relating to the processing — such as security, breach notification, and data-protection assessments — to the extent the Association cannot obtain the information itself through the Services.

10. Personal Information Breach Notification

GnomeOwner will notify the Association without undue delay after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information processed under this DPA. The notice will describe, to the extent known: the nature of the breach, the categories and approximate volume of data and individuals affected, the likely consequences, and the measures taken or proposed to address it — supplemented as more information becomes available. GnomeOwner will reasonably cooperate with the Association's own notification obligations. GnomeOwner's notice is not an admission of fault. The Association remains responsible for determining and making any legally required notifications to its members or regulators, with GnomeOwner's reasonable assistance.

11. Data Retention, Return, and Deletion

This Section mirrors Terms of Service Section 6 and Privacy Policy Section 6; those mechanics apply to Personal Information under this DPA.

11.1 Cancellation does not delete. Cancelling or downgrading a subscription does not delete the Association's data. Records remain stored so the Association can resume service and pick up where it left off.

11.2 Deletion is a separate, deliberate act. Deleting the Association's account or organization is a distinct action from cancelling a subscription. Before deletion, GnomeOwner offers the ability to export the Association's data in a commonly used format — this export constitutes the "return" of Personal Information. Following a deletion request, the data enters a thirty (30) day recovery window, during which any authorized administrator of the Association may reverse the deletion. After the recovery window expires, the data is permanently deleted from GnomeOwner's systems.

11.3 Legally required retention. As an exception to Section 11.2, financial and tax-related records are retained in a minimized or anonymized form as required to satisfy applicable record-retention obligations, and GnomeOwner may retain Personal Information to the limited extent and for the limited duration Applicable Privacy Law or other law requires.

11.4 Individual portal users. A resident portal user may request deletion of their individual portal account. Because correspondence and records belonging to the Association remain the Association's own governance and financial records (Terms Section 4.3), those records are anonymized rather than destroyed.

11.5 No warranty after deletion. GnomeOwner makes no representation or warranty regarding recovery of data after the recovery window has expired. The Association is responsible for exporting records it is legally required to retain (Terms Section 4.3).

12. Funds and Payment Data Acknowledgment

The parties acknowledge, consistent with Terms Sections 3 and 11.3:

(a) GnomeOwner never receives, holds, or controls dues, assessments, or other member payments. Payments are processed by GnomeOwner's payment Sub-processor directly into the Association's own connected account (direct charges to the Association's account); the Association — not GnomeOwner — is the recipient of the funds.

(b) Bank connectivity is read-only: neither GnomeOwner nor its bank-connectivity Sub-processor is authorized to move, transfer, or withdraw funds, and bank data is accessed solely to reconcile the Association's ledger.

(c) GnomeOwner does not store card numbers or banking credentials; those are handled entirely by the respective Sub-processors under their own terms, which the Association or its members accept at the point of use (including the bank-connection consent screen presented at the moment an account is connected).

Nothing in this DPA makes GnomeOwner a money transmitter, payment processor of record, or custodian of Association funds.

13. Term, Termination, and Survival

13.1 This DPA takes effect when the Association accepts it (at onboarding or otherwise) and continues for as long as GnomeOwner processes Personal Information on the Association's behalf — through the subscription term, any period on the free tier, and any retention period under Section 11.

13.2 Termination of the Terms terminates this DPA, except that this DPA continues to govern any Personal Information GnomeOwner retains until it is deleted or anonymized under Section 11.

13.3 Sections 4 (restrictions), 10 (breach notice, as to data still held), 11 (retention/deletion), 12 (funds acknowledgment), and 14 (general) survive termination as to retained data.

14. General

14.1 Liability. The liability of each party under this DPA is subject to the exclusions and limitations of liability in the Terms (Sections 7–8). This DPA does not create a separate or additional liability cap, and nothing in it enlarges either party's liability beyond what the Terms provide.

14.2 Governing law and disputes. This DPA is governed by the laws of the State of Georgia, and disputes are resolved as provided in the Terms (Section 10).

14.3 Changes. GnomeOwner may update this DPA as the Services or Applicable Privacy Law evolve. Material changes will be notified as provided in the Terms (Section 12.2), and the then-current version will be maintained at a stable URL on gnomeowner.com.

14.4 Order of precedence. For data-processing matters: this DPA, then the Privacy Policy, then the Terms. For all other matters, the Terms control.

14.5 Severability. If any provision of this DPA is held unenforceable, the rest remains in force, modified to the minimum extent necessary.

14.6 Entire agreement (data processing). This DPA, together with the Terms and Privacy Policy, is the parties' entire agreement on the processing of Personal Information and supersedes prior data-processing understandings.

Accepted by the Association through its authorized administrator as part of GnomeOwner onboarding.