Data Processing Addendum
Last updated: September 11, 2026
This DPA is provided as a template for reference. It is not legal advice — please have it reviewed and adapted by qualified counsel before you rely on it or share it with a customer.
This Data Processing Addendum ("DPA") forms part of the Ask Redline Terms of Service (the "Agreement") between the customer ("Customer") and Redline Monitoring Services Inc. ("Redline", "we", "us"). It governs Redline's Processing of Personal Data in connection with the Ask Redline service (the "Services"). Where there is a conflict between the Agreement and this DPA with respect to the Processing of Personal Data, this DPA prevails to the extent of that conflict.
For the purposes of this DPA, Customer (the HOA or management company) is the "Data Controller" that determines the purposes and means for which Personal Data is Processed, and Redline acts as the "Data Processor" that Processes Personal Data on the Controller's behalf and in accordance with its documented instructions. "Personal Data" means information relating to an identified or identifiable individual (such as a resident's name, unit, mobile number and message content) that Redline Processes on Customer's behalf. "Processing" means any operation performed on Personal Data. The terms "Data Controller", "Data Processor", and "Data Subject" have the meaning given under applicable Data Protection Laws, including the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other applicable U.S. state privacy laws.
01 Scope & processing details
- Subject matter: provision of the Ask Redline resident-concierge Services. Duration: for the term of the Agreement and until all Personal Data is returned or deleted per Section 9.
- Nature & purpose: receiving and answering resident messages and calls from a community's governing documents; capturing and routing requests (e.g., maintenance, RSVPs); identity verification; sending confirmations, updates and community/safety alerts; and maintaining records for the Customer.
- Categories of Data Subjects: the Customer's residents, homeowners, household members, guests and authorized administrators.
- Categories of Personal Data: mobile phone number, name, unit/address, message and call content (including any photos or voicemails), request and conversation records, and administrator account details. Redline does not intentionally collect special-category data.
02 Redline's processing obligations
- Redline will Process Personal Data solely to provide the Services and only on the Customer's documented instructions (including as set out in the Agreement and this DPA), unless required by law — in which case Redline will notify the Customer in advance where legally permitted.
- As a service provider/processor, Redline will NOT: (i) sell or share Personal Data; (ii) retain, use, or disclose it for any purpose other than providing the Services or as permitted by the CCPA; (iii) use it outside the direct business relationship with the Customer; or (iv) combine it with data from other sources except as permitted by applicable law.
- Personal Data and community documents are provided to vetted AI subprocessors only to generate responses, and are NOT used to train those providers' models. Redline may use aggregated or de-identified data to operate and improve the Services and will not attempt to re-identify it.
03 Subprocessors
- Customer authorizes Redline to engage subprocessors to deliver the Services. Redline binds each subprocessor by contract to data-protection obligations no less protective than this DPA, and remains responsible for their performance.
- Current subprocessors include: Twilio (SMS/MMS, WhatsApp and voice telephony); OpenAI and Anthropic (AI language and voice model responses — no training on Customer data); Resend (transactional email); Google (administrator authentication); and Redline's cloud hosting and database provider (application hosting and data storage).
- Redline will make available an up-to-date list of subprocessors on request and will give the Customer reasonable notice of any intended addition or replacement, allowing the Customer to object on reasonable data-protection grounds.
04 Confidentiality & personnel
- Redline ensures that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and access it only on a need-to-know basis to perform the Services.
05 Security
- Redline maintains reasonable and appropriate technical and organizational measures designed to protect Personal Data against unauthorized or accidental access, loss, alteration, disclosure or destruction, appropriate to the risk.
- Measures include strict per-community tenant isolation (one community can never access another's data), encryption in transit, access controls and least-privilege administration, identity verification before disclosing account-specific information, and monitoring and logging.
06 Security-incident notification
- Redline will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own breach-notification obligations, together with a description of the incident and remediation steps taken.
07 Data-subject requests
- Taking into account the nature of the Processing, Redline will provide reasonable assistance to enable the Customer to respond to requests from Data Subjects to exercise their rights (access, correction, deletion, restriction, portability or objection).
- If a Data Subject contacts Redline directly with such a request, Redline will (where permitted) direct them to the Customer or notify the Customer, and will not respond substantively without the Customer's authorization, except to confirm the request relates to the Customer.
08 Assistance, audits & assessments
- Redline will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, will allow for and contribute to audits, including by providing a third-party certification or report where available in lieu of an on-site audit.
- Redline will provide commercially reasonable assistance with data-protection impact assessments and prior consultations with a supervisory authority where required by Data Protection Laws.
09 International transfers
- Where the Customer is subject to EU or UK Data Protection Laws and a transfer of Personal Data to Redline would otherwise be restricted, the parties agree that the applicable EU Standard Contractual Clauses (Module Two, Controller-to-Processor) and the UK International Data Transfer Addendum are incorporated into this DPA by reference, with the Customer as data exporter and Redline as data importer, and the processing details in Section 1 completing the relevant annexes.
10 Return & deletion
- On termination or expiry of the Agreement, Redline will, at the Customer's election, return or delete Personal Data (and instruct its subprocessors to do so) within thirty (30) days, unless retention is required by law. If the Customer makes no election within that period, Redline may delete the Personal Data.
11 Customer obligations
- The Customer represents that it has all necessary rights, consents and lawful bases (including any SMS/TCPA opt-in consent) for Redline to Process Personal Data as contemplated by the Agreement, that its processing instructions comply with applicable law, and that it is responsible for its own configuration decisions (such as which features it enables).
12 General
- This DPA is governed by the same law and jurisdiction as the Agreement. Each party's liability under this DPA is subject to the limitations of liability in the Agreement. If any provision is held invalid, the remainder stays in effect. This DPA remains in effect for as long as Redline Processes Personal Data on the Customer's behalf.
Contact
Redline Monitoring Services Inc., Austin, TX 78705 · (512) 363-6584 · mike@redlinemonitoring.com
See also our Privacy Policy and Terms of Service.