Legal & Compliance

Data Processing Agreement

Version 1.2  |  Effective: 7 September 2026  |  Home Watch IT, LLC
Who this applies to: This Agreement applies to all customers of Home Watch IT, LLC who use the HWIT Services to process personal data of individuals located in the European Union, European Economic Area, or United Kingdom. It supplements and forms part of the HWIT Master Services Agreement.

1. Background and Purpose

Home Watch IT, LLC ("Processor") provides home watch management software (the "Services") to home watch professionals under the HWIT Master Services Agreement ("Service Agreement"). This Data Processing Agreement ("DPA") sets out the terms under which such processing takes place and satisfies the requirements of Article 28 of EU Regulation 2016/679 ("EU GDPR") and the equivalent United Kingdom legislation ("UK GDPR"). This DPA forms part of and supplements the Service Agreement. In the event of conflict, this DPA shall prevail in relation to all matters concerning personal data processing.

2. Definitions

TermMeaning
Applicable LawEU GDPR (Regulation 2016/679), UK GDPR, and all subordinate legislation and regulatory guidance thereunder.
ControllerThe HWIT customer who determines the purposes and means of processing End-User Personal Data.
Customer DataAll personal data submitted to or generated within the Services by or on behalf of the Controller.
Data SubjectAny identified or identifiable natural person whose personal data is processed under this DPA.
End-User Personal DataPersonal data relating to the Controller's customers, including names, postal addresses, contact details, property information, and security access information (including alarm codes).
Personal Data BreachA breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data.
ProcessorHome Watch IT, LLC, which processes Customer Data on behalf of and under the instruction of the Controller.
SCCsStandard Contractual Clauses approved by the European Commission under Decision (EU) 2021/914 of 4 June 2021.
ServicesThe HWIT software platform, including scheduling, visit reporting, AI-powered document search, AI-assisted report completion, automated email delivery, customer portal access, and related features.
Sub-ProcessorAny third party engaged by the Processor to process Customer Data in connection with the Services.
UK AddendumThe International Data Transfer Addendum to the SCCs issued by the UK ICO, Version B1.0, in force 21 March 2022.

3. Roles of the Parties

The Controller is the data controller for all End-User Personal Data processed through the Services. The Processor is the data processor, acting solely on the Controller's documented instructions. The Processor shall not process Customer Data for any purpose other than providing the Services, except where required to do so by applicable law. Each Party shall comply with its respective obligations under Applicable Law.

4. Details of Processing

Nature of ProcessingCollection, storage, organisation, retrieval, automated processing, AI-assisted search, AI-assisted report completion, automated email delivery, and secure deletion of Customer Data.
PurposesEnabling the Controller to manage home watch visit scheduling, field reporting, customer communications, invoicing support, AI document search, and AI-assisted report completion.
DurationFor the duration of the Service Agreement and until all Customer Data is deleted in accordance with clause 9 of this DPA.
Categories of Personal DataNames; postal addresses; email addresses; telephone numbers; property access and security information (including alarm codes); visit reports and visit records; scheduling information.
Categories of Data SubjectsThe Controller's end-user customers (homeowners and property owners); the Controller's employees and authorised field staff.
Special Categories of DataNone. The Services are not designed to process special category data as defined under Article 9 GDPR.

5. Processor Obligations

5.1 Instructions

The Processor shall process Customer Data only on the documented instructions of the Controller. If required by applicable law to process beyond those instructions, the Processor shall inform the Controller before such processing, unless legally prohibited from doing so.

5.2 Confidentiality

The Processor shall ensure that all personnel authorised to process Customer Data are subject to binding confidentiality obligations and are made aware of the requirements of this DPA.

5.3 Security

The Processor shall implement and maintain appropriate technical and organisational measures including: encryption of personal data in transit and at rest; measures to ensure ongoing confidentiality, integrity, and availability; role-based access controls; and secure deletion procedures upon account termination.

5.4 Sub-Processors

The Controller provides general written authorisation for the Processor to engage the Sub-Processors listed in Schedule B. The Processor shall impose equivalent data protection obligations on each Sub-Processor, provide at least 30 days' notice of any Sub-Processor change, and remain fully liable for their acts and omissions.

5.5 Data Subject Rights

The Processor shall, insofar as technically possible, assist the Controller in fulfilling obligations to respond to Data Subject requests. The Processor shall notify the Controller without undue delay if it receives a Data Subject request directly.

5.6 Assistance with Controller Obligations

Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of processing, breach notification to supervisory authorities and Data Subjects, data protection impact assessments, and prior consultation with supervisory authorities.

5.7 Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, upon reasonable written request (no more than once per 12-month period, unless required by a supervisory authority or following a Personal Data Breach).

6. Personal Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach, including a description of the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken to address it.

7. International Data Transfers

Customer Data is stored and processed in the United States of America. The Controller hereby authorises such transfer on the basis of the following safeguards:

Sub-ProcessorEU Transfer MechanismUK Transfer Mechanism
AWSEU–US Data Privacy FrameworkUK–US Data Bridge
CloudflareEU–US Data Privacy Framework; SCCsUK Extension to the DPF (UK–US Data Bridge)
SupabaseEU–US DPF; SCCsUK Addendum to SCCs
Google CloudEU–US Data Privacy FrameworkUK–US Data Bridge
OpenAI Ireland Ltd.EEA entity; SCCs for onward transfersUK Addendum to SCCs
SMTP2GOSCCs, EU Commission Decision (EU) 2021/914, Module 2UK IDTA, ICO Version B1.0
Make.com / CelonisEU entity (Czechia) — no transfer requiredUK Addendum for UK-originating data
PDFShiftEU entity (France) — no transfer requiredUK Addendum for UK-originating data
MonitorQASCCs (EU Commission Decision 2021/914, Module 2)SCCs + UK Addendum

The Standard Contractual Clauses (Controller to Processor, Module 2) under Commission Decision (EU) 2021/914 are hereby incorporated into this DPA by reference. Governing law: Ireland. Competent supervisory authority: determined in accordance with Clause 13 of the SCCs — the supervisory authority of the EU Member State in which the Controller (data exporter) is established. For UK data, the UK Addendum (ICO Version B1.0) is incorporated alongside the SCCs.

8. Controller Obligations

The Controller warrants that it has a lawful basis for all processing; has provided Data Subjects with all required privacy notices; shall not instruct the Processor to process data in a manner that would violate Applicable Law; and shall not submit special category personal data without prior written agreement.

9. Data Return and Deletion

Return of data. At the Controller's choice, the Processor shall return and/or delete all Customer Data at the end of the provision of the Services. Upon written request received before the effective date of termination, the Processor shall provide the Controller with a complete export of Customer Data — including customer and contact records, properties, visit reports, notes, and scheduling data in a structured, commonly used, machine-readable format (CSV or JSON), together with photographs and document files in their original formats — at no additional charge.

Deletion. Upon termination, the Processor shall delete all live Customer Data immediately or, where an export has been requested under this clause, upon delivery of the export or 30 days after termination, whichever occurs first. Residual copies in encrypted backups are purged within 15 days thereafter. The Processor shall confirm deletion in writing upon request.

10. Liability

Each Party shall be liable to the other for damages caused by its breach of this DPA or Applicable Law. For the avoidance of doubt, the general limitation of liability in §9 of the Service Agreement does not apply to breaches of this DPA or of Applicable Law. Liability for such breaches is subject only to the separate limit for data protection claims expressly stated in §9 of the Service Agreement.

11. Term and Termination

This DPA shall remain in force for the duration of the Service Agreement and shall automatically terminate upon its termination. Obligations relating to deletion of Customer Data survive termination.

12. EU Representative (Article 27 GDPR)

The Processor is established outside the European Union. Pursuant to Article 27 GDPR, the Processor has designated Home Watch IT d.o.o., Pod Jeseni 16, 1000 Ljubljana, Slovenia (email: info@homewatchit.com), as its representative in the European Union. Data Subjects and supervisory authorities may contact the EU representative, in addition to or instead of the Processor, on all issues related to the processing of personal data under this DPA.

The Services are not currently offered to customers established in the United Kingdom; accordingly, no separate representative has been appointed under Article 27 of the UK GDPR. The UK transfer mechanisms in this DPA remain available where a Controller established in the EU processes personal data of Data Subjects located in the UK.

13. General Provisions

This DPA is governed by the laws of Ireland (other than SCCs/UK Addendum). It constitutes the entire agreement between the Parties regarding personal data processing and supersedes all prior agreements on such subject matter.

14. Artificial Intelligence Features and Model Training

14.1 Where the Services include features that use third-party artificial intelligence models, Customer Data submitted to those features is processed solely to generate the output requested by the Controller's authorised user, and for no other purpose.

14.2 The Processor does not use Customer Data, or any other content processed through the Services, to train, fine-tune, develop or improve any machine learning or artificial intelligence model.

14.3 The Processor contracts with each Sub-Processor that provides artificial intelligence model services on terms that prohibit the use of Customer Data for model training or model improvement, and will not opt in to any model-improvement, feedback-sharing or fine-tuning programme offered by such a Sub-Processor in respect of Customer Data.

14.4 Any new Sub-Processor providing artificial intelligence model services will be introduced only in accordance with clause 5.4 and will be subject to the same prohibition.

Schedule A — Annex I: Description of Processing

Data Exporter (Controller)The HWIT customer identified in the Service Agreement: a home watch services company using the HWIT platform.
Data Importer (Processor)Home Watch IT, LLC, 12895 Josey Ln #124-1155, Dallas TX 75234, USA. Contact: info@homewatchit.com
Categories of Data SubjectsEnd-user customers of the Controller (homeowners and property owners); employees and field staff of the Controller.
Categories of Personal DataNames; postal addresses; email addresses; telephone numbers; property-specific notes and access/security information (including alarm codes); visit reports; scheduling information.
Special CategoriesNone intended.
Frequency of TransferContinuous, for the duration of the Service Agreement.
Retention PeriodDuration of the Service Agreement. At the Controller's choice, data is returned (machine-readable export) and/or deleted at termination in accordance with clause 9; residual backup copies purged within 15 days.
Supervisory Authority (EU)The supervisory authority of the EU Member State in which the data exporter is established, in accordance with Clause 13(a) of the SCCs. Where the data exporter is not established in an EU Member State but has designated a representative under Article 27 GDPR, the supervisory authority of the Member State in which that representative is established.
Supervisory Authority (UK)UK Information Commissioner's Office (ICO) — ico.org.uk
AI-assisted report completion ("AI Fill")Voice dictation is transcribed by the operating system keyboard on the authorised user's own device, under the device vendor's terms and outside the Services. No audio is transmitted to the Processor or to any Sub-Processor. The transcribed text and the applicable report template are transmitted to the AI Sub-Processor solely to populate the report. No client names, property addresses, property notes, photographs or other Customer Data are transmitted.

Schedule B — Approved Sub-Processors

Sub-ProcessorCountryRoleTransfer MechanismModel training
Amazon Web Services (AWS)USACloud infrastructure & hostingEU–US DPF; UK–US Data Bridge; SCCsNot applicable
Cloudflare, Inc.USAHosting, content delivery network (CDN), DNS & security servicesEU–US DPF; UK–US Data Bridge; SCCsNot applicable
Supabase Inc.USADatabase (PostgreSQL)EU–US DPF; SCCs; UK AddendumNot applicable
Google Cloud PlatformUSACloud infrastructureEU–US DPF; UK–US Data Bridge; SCCsNot applicable
OpenAI Ireland Ltd.Ireland (EEA)AI-assisted report completion (AI Fill) and document searchEEA entity; SCCs for onward transfers; UK AddendumCustomer content is not used for model training or model improvement. HWIT has not opted in to any data-sharing or model-improvement programme.
SMTP2GO (Sand Dune Mail Ltd.)New ZealandTransactional email deliverySCCs Module 2 (EU 2021/914); UK IDTA (ICO v. B1.0)Not applicable
Make.com (Celonis)Czechia (EEA)Workflow automationEEA entity; UK Addendum for UK dataNot applicable
PDFShiftFrance (EEA)PDF document generationEEA entity; UK Addendum for UK dataNot applicable
MonitorQAUSAField reporting software (HWIT master account; client accounts managed under it; data accessed via API)Data Processing Agreement; SCCsNot applicable
Data Protection Contact

Home Watch IT, LLC
12895 Josey Ln, #124-1155, Dallas TX 75234, USA
Email: info@homewatchit.com
Phone: +1 (214) 461-0166

Home Watch IT d.o.o. — EU Representative under Article 27 GDPR
Pod Jeseni 16, 1000 Ljubljana, Slovenia
Email: info@homewatchit.com