Data Processing Agreement

Effective Date: April 20, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tisacrest LLC, doing business as HOA Base ("Processor" or "we"), and the community manager or HOA entity subscribing to the Service ("Controller" or "you"). This DPA governs the processing of personal data that you entrust to us in connection with your use of the HOA Base platform at hoabase.io.

This DPA is automatically accepted by the Controller upon creating a subscription to the Service. It applies when HOA Base processes personal data on behalf of the Controller as part of providing the Service. For the purposes of this DPA, "personal data," "processing," "data subject," "controller," and "processor" have the meanings given in applicable data protection laws, including the Nevada Privacy of Information Collected on the Internet from Consumers Act (NRS 603A) and other applicable U.S. data protection laws.

2. Roles and Responsibilities

2.1 Controller

The community manager or HOA entity is the Controller of the personal data of its community residents, board members, and household members. The Controller determines the purposes and means of processing personal data through its use of the Service.

2.2 Processor

HOA Base acts as the Processor, processing personal data only on behalf of and in accordance with the Controller's documented instructions, which are defined by the Controller's configuration and use of the Service.

3. Scope of Processing

3.1 Categories of Data Subjects

  • HOA community residents and homeowners.
  • Household members associated with a home.
  • Board members and community managers.
  • Guests registered through the platform.

3.2 Types of Personal Data

  • Identity Data: Names, email addresses, phone numbers, profile images.
  • Property Data: Home addresses, lot numbers, property details.
  • Financial Data: Subscription billing records and transaction history for community managers (payment card details are processed directly by Stripe and are not stored by HOA Base). HOA Base does not process resident HOA dues payments.
  • Communications: Messages, maintenance requests, ARC requests, violation records.
  • Registration Data: Vehicle registrations, pet registrations, guest registrations.
  • Documents: Uploaded files including governance documents, meeting minutes, and attachments.
  • Usage Data: Authentication logs, activity records, audit trails.

3.3 Purposes of Processing

Personal data is processed solely for the following purposes:

  • Providing and maintaining the Service as configured by the Controller.
  • Processing community manager subscription billing.
  • Sending transactional communications (invitations, notifications, alerts).
  • Generating reports and analytics for the Controller.
  • AI-assisted document processing when initiated by authorized users.
  • Maintaining security, audit logs, and compliance records.

4. Controller Obligations

The Controller shall:

  • Ensure a lawful basis exists for the processing of personal data, including obtaining any necessary consents from data subjects.
  • Provide clear and accurate instructions to the Processor regarding the processing of personal data.
  • Ensure that the personal data provided is accurate and up to date.
  • Inform data subjects about the processing of their personal data, including directing them to HOA Base's Privacy Policy.
  • Comply with applicable data protection laws in its use of the Service.

5. Processor Obligations

HOA Base shall:

  • Process personal data only in accordance with the Controller's documented instructions, except where required by applicable law.
  • Ensure that persons authorized to process personal data have committed to confidentiality obligations.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Section 7.
  • Not engage sub-processors without the Controller's prior authorization, as described in Section 6.
  • Assist the Controller in responding to data subject requests, including access, correction, and deletion requests.
  • Notify the Controller without unreasonable delay upon becoming aware of a personal data breach.
  • Delete or return all personal data upon termination of the Service, subject to legal retention obligations and the data retention practices described in the Privacy Policy.
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA.

6. Sub-Processors

The Controller authorizes HOA Base to engage the following sub-processors for the purposes described:

Sub-ProcessorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure, data storage (DynamoDB, S3), email delivery (SES), authentication (Cognito), AI processing (Bedrock), compute (Lambda)United States
Stripe, Inc.Payment processing, subscription billing, and financial transactionsUnited States
Google LLCSocial sign-in authentication (Google Sign-In)United States
Apple Inc.Social sign-in authentication (Sign in with Apple)United States

HOA Base will notify the Controller before adding or replacing any sub-processor, giving the Controller an opportunity to object. If the Controller reasonably objects, HOA Basewill make commercially reasonable efforts to provide an alternative or the Controller may terminate the affected Service.

7. Security Measures

HOA Base implements the following technical and organizational measures to protect personal data:

7.1 Encryption

  • All data in transit is encrypted using TLS/HTTPS.
  • Data at rest is encrypted using AWS-managed encryption keys.

7.2 Access Controls

  • JWT-based authentication with AWS Cognito.
  • Role-based access controls (Resident, Manager, Board, Admin).
  • Automatic session timeout after 20 minutes of inactivity.
  • Invitation-only account creation (no self-registration).

7.3 Infrastructure Security

  • Serverless architecture (AWS Lambda) reducing attack surface.
  • Private S3 storage with CloudFront Origin Access Control.
  • Presigned URLs for secure, time-limited file access.
  • No direct database access from the public internet.

7.4 Monitoring and Auditing

  • Comprehensive audit logging of significant actions.
  • CloudWatch monitoring and alerting.
  • Automated scheduled cleanup and integrity checks.

8. Data Subject Rights

HOA Base will assist the Controller in fulfilling its obligations to respond to data subject requests, including:

  • Right of Access: Providing the data subject's personal data held within the Service.
  • Right to Rectification: Correcting inaccurate personal data.
  • Right to Erasure: Deleting personal data upon request, subject to legal retention requirements.
  • Right to Data Portability: Exporting personal data in a structured, commonly used format.
  • Right to Restriction: Restricting processing of personal data in certain circumstances.

The Controller should direct data subject requests to hello@hoabase.io, and HOA Base will respond within 30 days.

9. Data Breach Notification

In the event of a personal data breach, HOA Base will:

  • Notify the Controller without unreasonable delay after becoming aware of the breach.
  • Provide sufficient information to enable the Controller to meet its own breach notification obligations, including:
    • The nature of the breach, including categories and approximate number of data subjects affected.
    • The likely consequences of the breach.
    • The measures taken or proposed to address the breach.
  • Cooperate with the Controller in investigating and remediating the breach.

10. Data Transfers

All personal data is processed and stored within the United States on AWS infrastructure. The Service is currently available only to communities located in the United States.HOA Base relies on AWS's compliance certifications and data protection measures for the security of stored data.

11. Data Retention and Deletion

Personal data is retained for the duration of the Controller's subscription. Upon termination:

  • The Controller may export their data before the end of the grace period.
  • After the 30-day grace period, personal data will be scheduled for deletion.
  • Subscription billing and financial records are retained by Stripe in accordance with Stripe's own data retention policies. Audit logs may be retained for legitimate business purposes.
  • Soft-deleted records are permanently removed after their grace period expires through automated cleanup processes.

12. Audits

HOA Base will make available to the Controller, upon reasonable request, information necessary to demonstrate compliance with this DPA. The Controller may conduct an audit, or appoint a third-party auditor, subject to reasonable advance notice (at least 30 days) and confidentiality obligations. Audits shall be conducted during normal business hours and shall not unreasonably interfere with HOA Base's operations.

13. Term and Termination

This DPA is effective as long as HOA Base processes personal data on behalf of the Controller. Upon termination of the underlying Service agreement, this DPA will automatically terminate, subject to the data retention and deletion provisions in Section 11.

14. Governing Law

This DPA is governed by the same governing law as the Terms of Service (the laws of the State of Nevada), unless overridden by mandatory data protection laws applicable to the Controller.

15. Contact

For questions about this DPA or to exercise any rights under it, contact us at:

Tisacrest LLC (d/b/a HOA Base)
Email: owner@tisacrest.com