ParcelDossier

Data Processing Addendum

Version: v1.0 | Effective: 2026-08-30

This Data Processing Addendum (“Addendum”) forms part of the End User License Agreement and Terms of Service at legal/EULA.md between Cheppers Zrt. (“the Provider”) and the Customer that subscribes to ParcelDossier through AWS Marketplace. It applies to the processing of personal data carried out in connection with the Service. To the extent of any conflict between this Addendum and the End User License Agreement and Terms of Service concerning the processing of personal data, this Addendum prevails. Nothing in this Addendum varies clause 2.3 of the End User License Agreement and Terms of Service, under which a mandatory AWS Marketplace term prevails.

1. Definitions and roles

1.1 The terms “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given to them in Regulation (EU) 2016/679 (the “GDPR”), which are adopted into this Addendum by reference. “Submitted Data”, “Assessment Context”, “Output”, and “Service” have the meanings given to them in the End User License Agreement and Terms of Service.

1.2 For Submitted Data, the Customer is the controller and the Provider is the processor. The Customer determines the purposes and means of that processing by deciding what to submit and why. The Provider processes it only on the Customer’s documented instructions, of which this Addendum and the End User License Agreement and Terms of Service are the initial and complete set.

1.3 For the Customer’s own account data, the Provider is the controller. That processing is described in the Provider’s Privacy Policy at legal/PRIVACY-POLICY.md and is not governed by the processor obligations in clause 4 of this Addendum.

1.4 The role allocation in clauses 1.2 and 1.3 is stated in both directions deliberately, so that neither party is left to infer its capacity from context.

1.5 The Service is designed to key on the parcel rather than on the person. An assessment is anchored to a property, a parcel identifier, and public records about that parcel, and the Provider does not seek property-owner names. Any personal data contained in Submitted Data is present because the Customer chose to include it, and the Customer remains responsible for that choice under clause 5.1 of the End User License Agreement and Terms of Service.

2. Subject matter, duration, nature, and purpose of processing

2.1 Subject matter. The processing of personal data contained in Submitted Data that the Customer transmits to the Service, and in the Output, evidence records, and processing logs derived from it.

2.2 Duration. The processing continues for the duration of the Customer’s AWS Marketplace subscription and, following its termination or expiry, for the deletion window of 30 calendar days provided in clause 8 of this Addendum. Processing of the categories expressly retained under clause 8.3 continues for the periods stated there.

2.3 Nature. Collection by receipt of the Customer’s API request, storage, organization, enrichment against public records and free federal data sources about the subject parcel, automated analysis including inference performed through a sub-processor, structuring into an assessment with per-dimension coverage and confidence values, retrieval by the Customer, and erasure.

2.4 Purpose. To perform the Service for the Customer that submitted the data, and for no other purpose. The Provider does not use Submitted Data to perform the Service for any other customer, maintains no cross-customer cache, index, or memory written from one Customer’s Submitted Data and read while serving another, and does not use Submitted Data to train, fine-tune, or otherwise adapt any general-purpose model.

3. Categories of data subjects and personal data

3.1 Categories of data subjects:

3.1.1 the Customer’s personnel who hold API credentials or tenant console access; and

3.1.2 any individual who is identifiable from a Submitted Data payload the Customer chooses to send, including from content the Service retrieves from a “Media[]” URL the Customer supplies.

3.2 Categories of personal data:

3.2.1 contact and account identifiers, being the registration email, the AWS account identifier, and the licence identifier;

3.2.2 authentication metadata, being an API key prefix and a hash of the key, together with console login and session records;

3.2.3 usage and billing records, being per-assessment processing records, metered quantities, and the security audit log entries that relate to an identifiable user; and

3.2.4 any personal data the Customer embeds in an Assessment Context or that appears in content fetched from a “Media[]” URL the Customer supplies.

3.3 The Provider does not require and does not solicit special-category personal data within the meaning of Article 9 of the GDPR, or personal data relating to criminal convictions and offences within the meaning of Article 10. The Customer must not submit such data, and warrants under clause 5.1.5 of the End User License Agreement and Terms of Service that it has not done so. The Service does not accept demographic attributes as inputs and does not produce them as Output.

4. Processor obligations

4.1 Documented instructions. The Provider processes personal data contained in Submitted Data only on the Customer’s documented instructions, including as to any transfer to a third country, unless required to do otherwise by European Union or Member State law to which the Provider is subject. Where such a requirement applies, the Provider informs the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. The Provider informs the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

4.2 Confidentiality. The Provider ensures that every person authorized to process personal data under this Addendum is bound by an obligation of confidentiality, whether contractual or statutory, and that access is limited to those personnel who need it to perform the Service.

4.3 Security. The Provider implements the technical and organisational measures set out in Annex II, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects.

4.4 Sub-processors. The Provider engages sub-processors only in accordance with clause 5.

4.5 Data-subject requests. Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise a data subject’s rights. Where the Provider receives such a request directly and the request concerns Submitted Data, the Provider does not respond to it on its own initiative but refers it to the Customer without undue delay.

4.6 Assistance with security, breaches, and assessments. Taking into account the nature of the processing and the information available to it, the Provider assists the Customer in ensuring compliance with the obligations in Articles 32 to 36 of the GDPR, covering security of processing, notification of a personal data breach to the supervisory authority and communication to data subjects, data protection impact assessments, and prior consultation.

4.7 Deletion or return. At the end of the provision of the Service, the Provider deletes or returns personal data contained in Submitted Data in accordance with clause 8.

4.8 Demonstrating compliance. The Provider makes available to the Customer the information necessary to demonstrate compliance with the obligations in this clause 4 and allows for and contributes to audits in accordance with clause 9.

5. Sub-processors

5.1 The Customer gives the Provider a general written authorisation to engage sub-processors for the processing described in clause 2.

5.2 The sub-processors engaged as at the effective date of this Addendum are listed in Annex III.

5.3 The Provider gives the Customer at least 30 calendar days’ prior notice of the addition or replacement of a sub-processor. Notice is given to the contact details the Customer supplies on registration or through AWS Marketplace.

5.4 The Customer may object to a proposed addition or replacement on reasonable data protection grounds within the notice period. The parties will discuss the objection in good faith. If the objection cannot be resolved, the Customer may terminate its subscription in accordance with the cancellation mechanism AWS Marketplace provides, without that termination being treated as a breach of the End User License Agreement and Terms of Service.

5.5 The Provider imposes on each sub-processor, by written contract, data protection obligations no less protective than those imposed on the Provider by this Addendum, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

6. International transfers

6.1 The Provider processes personal data under this Addendum in the AWS us-east-1 region in the United States. The Provider does not process personal data under this Addendum in any other region.

6.2 The transfer mechanism is the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into this Addendum by reference.

6.3 Module Two (controller to processor) applies to the transfer of personal data contained in Submitted Data from the Customer as controller to the Provider as processor. Module Three (processor to sub-processor) applies where the Provider makes an onward transfer to a sub-processor listed in Annex III.

6.4 The annexes of this Addendum populate the annexes of the Standard Contractual Clauses: Annex I of this Addendum populates Annex I of the Standard Contractual Clauses, Annex II of this Addendum populates Annex II of the Standard Contractual Clauses, and Annex III of this Addendum populates the sub-processor list.

6.5 Where the Standard Contractual Clauses require a party to make a choice among options, the parties select the option that gives effect to clause 6.1 to clause 6.4, and the docking clause applies so that a further party may accede.

6.6 The governing law and the choice of forum required by the Standard Contractual Clauses are those stated in clause 10, subject to any mandatory requirement of the Standard Contractual Clauses themselves.

7. Personal data breach

7.1 The Provider notifies the Customer of a personal data breach affecting personal data processed under this Addendum without undue delay and in any event within 48 hours of the Provider becoming aware of it.

7.2 The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed to address it, in each case with the information available at the time. Where the information is not all available at once, the Provider provides it in phases without further undue delay as it emerges.

7.3 The Provider does not notify a supervisory authority or any data subject on the Customer’s behalf in respect of Submitted Data unless the Customer instructs it in writing to do so.

7.4 The Customer may report a suspected security incident relating to the Service through the process published as legal/SECURITY-INCIDENT.md, which is the reporting channel in the other direction.

8. Deletion and return

8.1 On termination or expiry of the Customer’s subscription, or on the Customer’s written request, the Provider deletes personal data contained in Submitted Data within 30 calendar days of the later of those two events. This is the same timeframe as clause 12.1 of the End User License Agreement and Terms of Service and the same timeframe stated in the Privacy Policy. Where the Customer requests return rather than deletion, the Provider returns the data through the documented API before deleting it.

8.2 Deletion under clause 8.1 covers the submitted Assessment Contexts, the generated Output, the evidence records, and the per-assessment processing logs.

8.3 Two categories are expressly retained, and the reason for each is stated so the Customer is not misled:

8.3.1 security audit records, retained for at least 1 year under Annex II and for any longer period applicable law requires, because a security log that can be erased on request is not an audit log; and

8.3.2 De-identified Aggregate Data as defined in clause 10.2 of the End User License Agreement and Terms of Service, which contains no personal data, is no longer associated with the Customer, cannot be located by reference to the Customer, and is therefore outside the scope of this clause 8.

8.4 Billing and metering records required for tax, accounting, statutory bookkeeping, or AWS Marketplace reconciliation are retained for the period applicable law requires and are not deleted under clause 8.1 before that period ends.

8.5 Backup copies containing data deleted under clause 8.1 are not individually purged. They age out of the backup set as the backup retention window elapses, and the data is not restored into the live Service in the interim. The backup retention window is 30 days.

9. Audit

9.1 The Provider makes available to the Customer, on written request, the information reasonably necessary to demonstrate compliance with this Addendum, including a description of the measures in Annex II as implemented.

9.2 The Customer may exercise the right in clause 9.1 no more than once in any twelve-month period, except following a personal data breach affecting the Customer, where it may be exercised additionally.

9.3 A request under clause 9.1 requires at least 30 calendar days’ written notice, is subject to the confidentiality obligations in clause 15 of the End User License Agreement and Terms of Service, must not unreasonably disrupt the Provider’s business, and must not require the Provider to disclose another customer’s data or information that would compromise the security of the Service.

9.4 The Provider does not control the infrastructure operated by the sub-processors listed in Annex III and does not offer on-site inspection of that infrastructure. Where an audit right of that kind is required, the Customer is referred to the compliance materials the relevant sub-processor publishes.

9.5 The Provider holds no third-party audit report or certification under SOC 2, ISO 27001, or any equivalent scheme, and this Addendum is not to be read as stating or implying that one exists.

10. Governing law and order of precedence

10.1 This Addendum is governed by, and construed in accordance with, the laws of the State of Delaware, United States of America, without regard to its conflict-of-laws principles, and the state and federal courts located in the State of Delaware have exclusive jurisdiction over any dispute arising out of or relating to it, subject to any mandatory requirement of the Standard Contractual Clauses.

10.2 The order of precedence is: first, a mandatory AWS Marketplace seller or buyer term; second, the Standard Contractual Clauses incorporated by clause 6; third, this Addendum; fourth, the End User License Agreement and Terms of Service; fifth, the Provider’s published documentation.

10.3 Except as varied by this Addendum, the End User License Agreement and Terms of Service continues in full force.

Annex I - Description of processing

Item Description
Controller The Customer, in respect of Submitted Data
Processor Cheppers Zrt., a company incorporated in Hungary
Categories of data subjects The Customer’s personnel holding API credentials or tenant console access; any individual identifiable from a Submitted Data payload the Customer chooses to send (clause 3.1)
Categories of personal data Contact and account identifiers; authentication metadata; usage and billing records; any personal data embedded in an Assessment Context or in content fetched from a “Media[]” URL (clause 3.2)
Special-category data None. Not required, not solicited, and must not be submitted (clause 3.3)
Nature of processing Receipt, storage, organization, public-records enrichment about the subject parcel, automated analysis including inference through a sub-processor, structuring into an assessment with coverage and confidence values, retrieval, and erasure (clause 2.3)
Purpose of processing To perform the Service for the Customer that submitted the data, and for no other purpose (clause 2.4)
Duration The subscription term plus the 30 calendar days deletion window, save for the categories expressly retained under clause 8.3 and clause 8.4 (clause 2.2)
Processing location AWS us-east-1, United States (clause 6.1)
Frequency of transfer Continuous, on each API request the Customer makes

Annex II - Technical and organisational measures

Each measure below names the v3.0 requirement that delivers it. No measure is stated here that is not backed by such a requirement.

Measure Requirement
Access to the Service is granted only against a per-tenant API key. The key is stored as a non-secret prefix plus a hash and is never stored in recoverable form. The Customer can rotate the key on a self-service basis, and the Provider invalidates it when the subscription ends. TEN-02, TEN-03
Each Customer’s data and processing are isolated. Tenant identity is derived from the API key presented on the request rather than from any request parameter, and every commercial record carries an explicit tenant identifier, so a Customer’s request is structurally unable to reach another Customer’s data. CTX-03, TEN-03
Personal data is encrypted in transit using TLS and encrypted at rest by industry-standard means. INFRA-04
Security-relevant events are written to an append-only audit log, scoped per Customer and retained for at least 1 year. OBS-01
Content is fetched from a customer-supplied “Media[]” URL only through server-side request forgery guards that restrict which network destinations may be reached, and the affected dimension degrades to a stated coverage of none where a fetch is not permitted or not possible. SEV-04
Per-tenant rate limits and concurrency limits bound the request volume any single tenant can place on the Service. TEN-04

The measures listed above are the whole of the Provider’s technical and organisational commitment under this Addendum. No control beyond them is committed, and none is to be inferred from the Provider’s marketing or documentation.

The Provider claims no certification or attestation under SOC 2, ISO 27001, or any equivalent scheme, and none exists as at the effective date of this Addendum.

Annex III - Sub-processors

Sub-processor Role Location
Amazon Web Services, Inc. Infrastructure hosting: compute, managed database, storage, and backup for the Service us-east-1, United States
Amazon Bedrock, a service of Amazon Web Services, Inc. Model inference performed on the Assessment Context and the compiled evidence us-east-1, United States
AWS Marketplace, a service of Amazon Web Services, Inc. Subscription, entitlement, and metering. Receives pricing dimension, quantity, usage hour, and the AWS-issued customer and licence identifiers only; receives no property content and no assessment Output United States
RentCast (RentCast API, a third-party rental-data aggregator) Receives the subject property address to produce the long-term rent estimate with its range and comparable count United States
Esri (ArcGIS Living Atlas), serving the FEMA National Flood Hazard Layer Receives the subject property coordinate for the flood-zone and Special Flood Hazard Area lookup United States
United States Geological Survey (3DEP Elevation Point Query Service) Receives the subject property coordinate for the ground-elevation lookup United States
Federal Communications Commission (Broadband Data Collection) Receives the subject census block group for the fixed-broadband availability lookup United States
School District of Palm Beach County (attendance-zone feature service) Receives the subject property coordinate for the school-attendance-zone lookup within Palm Beach County United States
National Center for Education Statistics (School Attendance Boundary Survey, 2015-16) Source of the attendance-boundary dataset used for the school-attendance-zone lookup outside Palm Beach County United States
US Environmental Protection Agency (Envirofacts Toxics Release Inventory registry) Source of the Florida-wide facility registry used for the environmental proximity dimension United States
Overpass API (community-operated OpenStreetMap query service) Receives the subject property coordinate for the points-of-interest lookup Community-operated mirrors, principally in the European Union (Germany)

This Annex lists every sub-processor engaged as at the effective date of this Addendum, drawn from the Provider’s published coverage statement. Changes to this Annex are notified in accordance with clause 5.3.

Signature

Agreed by the Customer:

Name: ______________________________

Title: ______________________________

Entity: ______________________________

Date: ______________________________

Signature: ______________________________

Agreed by the Provider, Cheppers Zrt.:

Name: ______________________________

Title: ______________________________

Date: ______________________________

Signature: ______________________________

A countersigned PDF of this Addendum is available on request through the contact channel identified in the Contact section of legal/EULA.md.