Dated: 8 October 2026
1.For the purposes of this Data Processing Addendum:
Customer Personal Datameans any personal data within the Customer Data and any personal data which the Supplier processes in connection with this Agreement, in the capacity of a processor on behalf of the Customer;
Data Protection Laws means (i) to the extent the UK GDPR applies, the law of the United Kingdom or of a part of the United Kingdom which relates to the protection of personal data; and/or (ii) to the extent the EU GDPR applies, the law of the European Union or any member state of the European Union to which The Supplier is subject, which relates to the protection of personal data;
EU GDPR means the General Data Protection Regulation ((EU) 2016/679);
Supplier Personal Data means any personal data which the Supplier processes in connection with this Agreement, in the capacity of a controller;
UK GDPRhas the meaning given to it in the Data Protection Act 2018;
and, for the purposes of this Data Processing Agreement, controller, processor, data subject, personal data, personal data breach and processing shall have the meaning given to them in the UK GDPR.
2.Both parties will comply with all applicable requirements of the Data Protection Laws. The provisions of this Data Processing Addendum are in addition to, and do not relieve, remove or replace, a party's obligations or rights under the Data Protection Laws.
3.The parties have determined that, for the purposes of the Data Protection Laws, the Supplier shall process the Customer Personal Data as a processor on behalf of the Customer.
4.If the determination in paragraph 3 changes, the parties shall work together in good faith to make any changes which are necessary to this Data Processing Agreement.
5.By entering into the Agreement, the Customer consents to (and shall procure all required consents, from its Representatives, in respect of) all actions taken by the Supplier in connection with the processing of the Supplier Personal Data, provided these are in compliance with the then-current version of the Supplier’s privacy policy available at https://www.askporter.com/privacy-policy (“Privacy Policy”). In the event of any inconsistency or conflict between the terms of the Privacy Policy and the Agreement, the Privacy Policy will take precedence.
6.Without prejudice to the generality of paragraph 2, the Customer will:
a)ensure that it has all necessary and appropriate consents and notices in place to enable lawful transfer of the Supplier Personal Data and the Customer Personal Data to the Supplier or lawful collection of the same by the Supplier for the Term and purposes of this Agreement; and
b)comply with the EU GDPR’s and UK GDPR’s Data Minimisation Principle by limiting the Customer Personal Data shared with the Supplier to only what is adequate, relevant and necessary for the Supplier to perform the Services.
7.Annex 1 sets out the scope, nature and purposes of the processing of Customer Personal Data by the Supplier, the duration of the processing and the types of personal data and categories of data subject.
8.Without prejudice to the generality of paragraph 2, the Supplier shall, in relation to Customer Personal Data:
a)process it only on the documented instructions of the Customer, which shall be to process the Customer Personal Data for the purposes set out in Annex 1, unless the Supplier is required by Applicable Laws to otherwise process it. Where the Supplier is relying on Applicable Laws as the basis for such processing, it shall notify the Customer of this before performing the processing required by the Applicable Laws unless those Applicable Laws prohibit it from so notifying the Customer. The Supplier shall inform the Customer if, in its respective opinion, the instructions of the Customer infringe Data Protection Laws;
b)implement appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Customer Personal Data and against accidental loss or destruction of, or damage to, Customer Personal Data, which the Customer has reviewed and confirms are appropriate to (i) the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage; and (ii) the nature of the data to be protected, in each case having regard to the state of technological development and the cost of implementing any measures;
c)ensure that any of its Representatives engaged and authorised by the Supplier to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory or common law obligation of confidentiality;
d)assist the Customer insofar as this is possible (taking into account the nature of the processing and the information available to the Supplier), and at the Customer’s cost and written request, in responding to any request from a data subject and in ensuring the Customer’s compliance with its obligations under Data Protection Laws with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
e)notify the Customer without undue delay on becoming aware of a personal data breach involving the Customer Personal Data;
f)at the written direction of the Customer, delete or return Customer Personal Data and copies of it to the Customer on termination of this Agreement unless the Supplier is required by Applicable Laws to continue to process that Customer Personal Data. For the purposes of this paragraph, Customer Personal Data shall be considered deleted where it is put beyond further use by the Supplier; and
g)maintain records to demonstrate its compliance with this paragraph and allow for reasonable access by the Customer or the Customer’s designated representative (at the Customer’s cost), for the purpose of auditing these records, at reasonable times and on reasonable notice.
9.The Customer hereby provides its prior, general authorisation for the Supplier to:
a)appoint sub-processors to process the Customer Personal Data, including the sub-processors set out in Annex 2 provided that the Supplier:
I.shall ensure that the terms on which it appoints such processors comply with Data Protection Laws, and are consistent with the obligations imposed on it in this Data Processing Addendum;
II.shall remain responsible for the acts and omissions of any such processor as if they were its acts and omissions; and
III.shall inform the Customer of any intended changes concerning the addition or replacement of the processors, giving the Customer the opportunity to object to such changes provided that if the Customer objects to the changes and cannot demonstrate, to the Supplier’s reasonable satisfaction, that the objection is due to an actual or likely breach of Data Protection Law, the Customer shall indemnify the Supplier for any losses, damages, costs (including legal fees) and expenses suffered by them in accommodating the objection.
b)transfer Customer Personal Data cross-borders where such transfer is necessary for the purpose set out in Annex 1, provided that the Supplier shall ensure that all such transfers are effected in accordance with Data Protection Laws. For these purposes, the Customer shall promptly comply with any reasonable request of the Supplier, including any request to enter into standard data protection clauses adopted by the EU Commission from time to time (where the EU GDPR applies to the transfer) or adopted by the UK Information Commissioner from time to time (where the UK GDPR applies to the transfer). Where personal data transfers are made to a restricted country, the Customer is responsible for carrying out any transfer risk assessment, and the Supplier shall provide reasonable assistance that the Customer requests.
10.The Supplier may update or modify the Data Processing Addendum from time to time where necessary to comply with applicable Data Protection Laws, to reflect changes in security measures, or to add new sub-processors. Supplier will provide the Customer with prior notice of any material updates (via email or through the platform). If the Customer objects to any material modification that adversely affects its data protection rights, it may terminate the affected services upon written notice. The Supplier may also, at any time by giving not less than 30 days' notice, revise this Data Processing Addendum by replacing it (in whole or part) with any applicable standard clauses approved by the EU Commission or the UK Information Commissioner's Office or forming part of an applicable certification scheme or code of conduct (“Amended Terms”). Such Amended Terms shall apply when replaced by an attachment to an Order Form, but only in respect of such matters which are within the scope of the Amended Terms.
Processing of the Customer Personal Data by the Supplier under this Agreement shall be for the subject-matter, duration, nature and purposes and involve the types of personal data and categories of data subjects set out in this Annex 1.
The provision and use of the Services in accordance with the terms of this Agreement, including the Supplier’s provision of cloud hosted services to the Customer to provide access and use of the Supplier’s platform(s). This includes allowing the Customer to upload information and facilitate the exchange of information between it, its Authorised Users and End Users, including handling incoming phone calls, making calls, recording and analysing the conversation and data within these activities.
The duration of this Agreement and thereafter to the extent necessary to perform any post-expiry or termination obligations under this Agreement.
Such processing as is necessary for the Supplier to provide, and the Customer and its Authorised Users and End Users to use, the Services in accordance with the terms of this Agreement, including: Collection, Recording, Hosting, Organisation, Structuring, Storage, Adaptation or alteration, Retrieval, Consultation, Use, Disclosure by transmission, dissemination or otherwise making available, Alignment or combination, Restriction, Erasure or destruction.
Personal data required to be processed by the Supplier in order for the Customer and its Authorised Users and End Users to use the Services, including:
About Authorised Users:
Name, role/job title and contact details.
About End Users:
Name, address, contact details, and information about accessibility needs or vulnerabilities relevant to the use of the Services (which may include Special Category Data depending on the responses provided by End Users).
Technical Data:
Internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device identifiers, and other technology on the devices used to access the Services.
Property and Tenancy-Related Data:
Information relating to the End User’s property or tenancy where relevant to the Services, such as property type, size, layout, and features (for example, the presence of utilities or systems such as boilers or heating systems), as well as tenancy information (for example, tenancy status, occupancy details, and tenancy history where relevant).
Categories required to be processed by the Supplier in order for the Customer and its Authorised Users and End Users to use the Services, including:
Customers, Employees, contractors and suppliers of the Customer, its Authorised Users, its End Users and the Tenants.
Twilio Inc.
+1 415 390 2337
375 Beale St, San Francisco, CA 94105, United States
Purpose:Voice and SMS services provider.
Google LLC
+1 650 253 0000
1600 Amphitheatre Parkway Mountain View, CA 94043, United States
Purpose: Hosting specialist data services and natural language processing.
Amazon
+1 206 266 1000
410 Terry Avenue North, Seattle, WA 98109, United States
Purpose:Cloud hosting services.
Microsoft
+1 888-725-1047
One Microsoft Way, Redmond, WA, 98052, United States
Purpose: Natural language processing and assistant related services.
Datadog, Inc.
20 8th Avenue, New York, NY, 10018, United States
Purpose: System monitoring and alerting.
LangChain, Inc.
42 Decatur Street, San Francisco, California 94103
Purpose: System monitoring
OpenAI, L.L.C
www.openai.com
1960 Bryant Street, San Francisco, CA 94110, United States
Purpose: Natural language processing.
Atlassian Pty Ltd
www.atlassian.com
Level 6, 341 George Street, Sydney, NSW 2000, Australia
Purpose: Third-party service provider of customer support and task management tools.
Slack Technologies Limited
www.slack.com
Salesforce Tower, 60 R801, North Dock, Dublin, Ireland
Purpose: Provision of a cloud-based communication and collaboration platform.

Best FM & Housing AI Platform

PropTech Innovation

Best Repairs & Maintenance

UK government-backed · externally audited
UK data residency by default
Documented data processing · DPA on request
AI governance framework · 2024 legislation

Best FM & Housing AI Platform

PropTech Innovation

Best Repairs & Maintenance

UK government-backed · externally audited
UK data residency by default
Documented data processing · DPA on request
AI governance framework · 2024 legislation