Legal

Data Processing Addendum

Effective date: August 1, 2026

This Data Processing Addendum, including its schedules and annexes, is referred to as the “DPA.”

This DPA is entered into between:

Rize Technologies, LLC, a Wyoming limited liability company doing business as Rize Ink, referred to as “Rize Ink,” “Rize,” “Processor,” “Service Provider,” “Contractor,” or “we”; and the broker, brokerage, real estate team, individual agent, company, or other person or entity that has entered into an agreement to use the Rize Ink Service, referred to as “Customer,” “Controller,” “Business,” or “you.”

This DPA supplements and forms part of the Rize Ink Terms of Service, an order form, subscription agreement, enterprise agreement, or other agreement governing Customer’s use of the Rize Ink Service, collectively referred to as the “Agreement.”

By accepting the Agreement or using the Service to process Customer Personal Data, Customer and Rize Ink agree to this DPA.

1. Order of precedence

If there is a conflict concerning the processing of Customer Personal Data:

  1. Applicable Standard Contractual Clauses control first.
  2. This DPA controls second.
  3. The Agreement controls third.
  4. The Privacy Policy and other policies control after the Agreement.

Except as modified by this DPA, the Agreement remains in effect.

2. Definitions

2.1 Applicable Data Protection Law

“Applicable Data Protection Law” means any privacy, data protection, or data security law that applies to Rize Ink’s processing of Customer Personal Data under the Agreement, including, where applicable:

  1. The California Consumer Privacy Act, as amended.
  2. Other United States state comprehensive privacy laws.
  3. State data breach notification laws.
  4. The European Union General Data Protection Regulation.
  5. The United Kingdom General Data Protection Regulation.
  6. Other applicable privacy or data protection laws.

2.2 Customer Personal Data

“Customer Personal Data” means Personal Data that Rize Ink processes on behalf of Customer through the Service.

Customer Personal Data includes Personal Data contained in:

  1. Forms and document libraries.
  2. Real estate transaction records.
  3. Contracts, disclosures, addenda, riders, and notices.
  4. Electronic-signature envelopes.
  5. Signer and recipient records.
  6. Customer contact and transaction-management records.
  7. Documents and information uploaded by or for Customer.
  8. Audit trails and authentication records associated with Customer transactions.

Customer Personal Data does not include Personal Data that Rize Ink independently controls for its own account administration, billing, fraud prevention, security, legal compliance, or direct business relationship with Customer, except where Applicable Data Protection Law provides otherwise.

2.3 Data Subject

“Data Subject” means an identified or identifiable person whose Personal Data is processed, including a consumer as defined by applicable United States state privacy law.

2.4 Personal Data

“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a person or household.

“Personal Data” includes “personal information,” “personal data,” and substantially similar terms defined under Applicable Data Protection Law.

2.5 Process or Processing

“Process” or “Processing” means any operation performed on Personal Data, including collecting, accessing, recording, organizing, storing, modifying, retrieving, viewing, using, transmitting, disclosing, restricting, deleting, or destroying it.

2.6 Security Incident

“Security Incident” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data processed by Rize Ink.

Security Incident does not include:

  1. Unsuccessful attempts to access systems.
  2. Port scans.
  3. Denial-of-service attempts that do not compromise Customer Personal Data.
  4. Blocked malware.
  5. Unsuccessful login attempts.
  6. Events caused solely by Customer’s systems, users, credentials, or instructions, unless Rize Ink contributed to the event.

2.7 Subprocessor

“Subprocessor” means a third party engaged by Rize Ink to process Customer Personal Data to provide the Service.

2.8 State privacy terms

“Business,” “Consumer,” “Contractor,” “Controller,” “Processor,” “Sale,” “Service Provider,” “Share,” and “Targeted Advertising” have the meanings provided by Applicable Data Protection Law.

3. Scope and roles

3.1 Customer as Controller or Business

For Customer Personal Data, Customer is generally the Controller or Business and determines:

  1. Why the information is processed.
  2. Which information is collected.
  3. Which documents are uploaded.
  4. Who receives documents.
  5. Which forms and fields are used.
  6. How long Customer requires the information.
  7. Which users may access the information.
  8. Whether Customer has a lawful basis to process it.

3.2 Rize Ink as Processor or Service Provider

Rize Ink acts as Customer’s Processor, Service Provider, or Contractor when it processes Customer Personal Data to provide the Service.

Rize Ink will process Customer Personal Data only:

  1. On Customer’s documented instructions.
  2. To provide the Service.
  3. As described in the Agreement and this DPA.
  4. As required by law.
  5. As otherwise permitted by Applicable Data Protection Law.

3.3 Customer instructions

Customer instructs Rize Ink to process Customer Personal Data as necessary to:

  1. Create and administer Customer accounts.
  2. Maintain broker, team, and individual-agent workspaces.
  3. Upload, store, organize, and retrieve forms.
  4. Create and maintain forms libraries and templates.
  5. Populate and prepare documents.
  6. Send documents to recipients and signers.
  7. Authenticate users and signers.
  8. Collect electronic consent, signatures, and initials.
  9. Create completion certificates and audit trails.
  10. Deliver and store completed documents.
  11. Provide transaction-management and client-portal functionality.
  12. Provide support requested by Customer.
  13. Maintain backups and disaster-recovery systems.
  14. Detect fraud, misuse, and security threats.
  15. Comply with Customer’s documented configuration and instructions.
  16. Perform other processing initiated through the Service by an authorized Customer user.

Additional documented instructions may be agreed through an order form, support request, product configuration, or written agreement.

3.4 Rize Ink as independent Controller

Rize Ink may act as an independent Controller or Business for limited purposes including:

  1. Subscription billing.
  2. Customer-account administration.
  3. Direct communications with Customer.
  4. Service security.
  5. Fraud and abuse prevention.
  6. Legal compliance.
  7. Enforcement of the Agreement.
  8. Internal business records.
  9. Privacy, copyright, and legal requests.
  10. Deidentified or aggregated service analytics.

Rize Ink’s processing in that independent capacity is governed by the Rize Ink Privacy Policy and Applicable Data Protection Law.

4. Processing instructions

Rize Ink will:

  1. Process Customer Personal Data only for the limited and specified purposes described in this DPA.
  2. Not materially expand the purposes of processing without Customer’s instructions or legally required notice.
  3. Inform Customer if Rize Ink reasonably believes an instruction violates Applicable Data Protection Law.
  4. Suspend an unlawful instruction until the parties resolve the issue.
  5. Inform Customer before processing Customer Personal Data under a legal requirement unless the law prohibits that notice.

Rize Ink is not required to follow an instruction that:

  1. Violates law.
  2. Violates another person’s rights.
  3. Creates a material security risk.
  4. Is technically impossible.
  5. Requires Rize Ink to provide legal advice.
  6. Conflicts with a valid court order or government requirement.

5. Customer obligations

Customer represents and warrants that:

  1. Customer has the right to collect and provide Customer Personal Data to Rize Ink.
  2. Customer’s instructions comply with Applicable Data Protection Law.
  3. Customer has provided required notices.
  4. Customer has obtained required permissions and consents.
  5. Customer has a lawful basis for the processing.
  6. Customer will respond appropriately to Data Subject requests.
  7. Customer will use appropriate account permissions.
  8. Customer will not instruct Rize Ink to process information unlawfully.
  9. Customer will not upload unnecessary sensitive information.
  10. Customer will use stronger authentication when appropriate for higher-risk transactions.
  11. Customer will comply with brokerage, licensing, professional, and record-retention requirements.
  12. Customer is responsible for the conduct of its users and administrators.

Customer is responsible for determining whether any information or document may legally be stored, delivered, signed, or processed electronically.

6. Specific business purposes

Rize Ink processes Customer Personal Data only for the following specific business purposes:

  1. Providing document-upload and document-storage services.
  2. Providing customer-controlled forms libraries.
  3. Preparing, formatting, and populating documents.
  4. Providing electronic-record and electronic-signature services.
  5. Authenticating account users and document signers.
  6. Sending transaction-related email and text communications.
  7. Providing transaction workspaces and client portals.
  8. Generating audit trails, event logs, document hashes, and completion certificates.
  9. Providing account, permission, and organization administration.
  10. Delivering completed documents to authorized recipients.
  11. Maintaining backups, availability, and disaster recovery.
  12. Providing customer-requested support.
  13. Detecting, preventing, and investigating security incidents, fraud, and unlawful activity.
  14. Maintaining and improving the quality and reliability of the Service as permitted by law.
  15. Complying with law and valid legal process.

Customer discloses Customer Personal Data to Rize Ink only for those limited and specified purposes.

7. United States state privacy requirements

To the extent Rize Ink processes Customer Personal Data as a Service Provider, Contractor, or Processor under United States state privacy law, Rize Ink agrees that it will:

  1. Not sell Customer Personal Data.
  2. Not share Customer Personal Data for cross-context behavioral advertising.
  3. Not process Customer Personal Data for targeted advertising.
  4. Not retain, use, or disclose Customer Personal Data for purposes outside the specific business purposes stated in this DPA, except as permitted by law.
  5. Not retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and Rize Ink, except as permitted by law.
  6. Not use Customer Personal Data for Rize Ink’s independent commercial purposes except as permitted by law.
  7. Not combine Customer Personal Data received from Customer with Personal Data received from another person or collected from Rize Ink’s independent interaction with a Data Subject, except as permitted by law.
  8. Provide the level of privacy protection required of a Service Provider, Contractor, or Processor.
  9. Comply with applicable obligations imposed on Service Providers, Contractors, and Processors.
  10. Notify Customer if Rize Ink determines it can no longer meet its obligations under Applicable Data Protection Law.
  11. Allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use.
  12. Assist Customer in responding to applicable Consumer requests.
  13. Assist Customer with legally required privacy assessments, risk assessments, cybersecurity audits, and regulatory inquiries to the extent the relevant information is within Rize Ink’s possession.
  14. Require applicable Subprocessors to agree to appropriate data protection restrictions.
  15. Process sensitive Personal Data only to provide the Service, maintain security, prevent fraud, comply with law, or as otherwise permitted by Applicable Data Protection Law.

8. Confidentiality

Rize Ink will ensure that personnel authorized to process Customer Personal Data:

  1. Are subject to confidentiality obligations.
  2. Receive access only where reasonably necessary.
  3. Receive appropriate privacy and security guidance.
  4. Are subject to disciplinary or contractual consequences for unauthorized access.
  5. Process Customer Personal Data only as required for their duties.

Confidentiality obligations will survive termination of employment, engagement, or access where appropriate.

9. Security measures

Rize Ink will implement and maintain reasonable administrative, technical, and organizational safeguards appropriate to:

  1. The nature of Customer Personal Data.
  2. The sensitivity of the information.
  3. The risks presented by the processing.
  4. The cost and feasibility of available safeguards.
  5. Applicable legal requirements.

The minimum security measures are described in Annex 2.

Rize Ink may update its security measures as technology and risks change, provided that the overall level of protection is not materially reduced.

Rize Ink does not promise that unauthorized access or Security Incidents will never occur.

10. Security incidents

10.1 Notification

Rize Ink will notify Customer without undue delay after confirming a Security Incident involving Customer Personal Data.

Where reasonably practicable, Rize Ink will provide the initial notification within 72 hours after confirmation.

Notification may be delayed where:

  1. Law enforcement or another government authority requires delay.
  2. Disclosure is prohibited by law.
  3. Additional time is reasonably needed to determine whether Customer Personal Data was involved.

10.2 Information provided

Rize Ink will provide information reasonably available concerning:

  1. The nature of the Security Incident.
  2. The approximate date or period.
  3. The categories of information involved.
  4. The categories or approximate number of affected Data Subjects, where known.
  5. The likely consequences.
  6. Measures taken or proposed.
  7. A contact for follow-up.
  8. Information reasonably necessary for Customer’s legal assessment.

Rize Ink may provide information in phases as it becomes available.

10.3 Cooperation

Rize Ink will:

  1. Take reasonable steps to contain and investigate the Security Incident.
  2. Preserve relevant evidence.
  3. Remediate identified vulnerabilities where reasonably appropriate.
  4. Cooperate with Customer’s reasonable investigation.
  5. Provide reasonable information needed for legally required notices.

Customer is responsible for determining whether Customer must notify Data Subjects, regulators, insurance carriers, clients, or other parties.

Rize Ink will not notify Customer’s clients or transaction participants directly unless:

  1. Customer instructs Rize Ink to do so.
  2. Applicable law requires Rize Ink to do so.
  3. Immediate notice is reasonably necessary to reduce imminent harm.

10.4 No admission

A Security Incident notification is not an admission of fault or liability.

11. Data Subject and Consumer requests

If Rize Ink receives a request directly from a Data Subject concerning Customer Personal Data, Rize Ink will, unless legally required otherwise:

  1. Inform the requester that Rize Ink processes the information for Customer.
  2. Direct the requester to Customer.
  3. Notify Customer where appropriate.
  4. Not substantively respond without Customer’s authorization.

Taking into account the nature of the processing, Rize Ink will provide reasonable assistance enabling Customer to respond to requests involving:

  1. Access.
  2. Correction.
  3. Deletion.
  4. Portability.
  5. Restriction.
  6. Objection.
  7. Opt-out rights.
  8. Withdrawal of consent.
  9. Other applicable privacy rights.

Customer is responsible for:

  1. Verifying the requester’s identity.
  2. Determining whether the request is valid.
  3. Identifying applicable exceptions.
  4. Communicating with the Data Subject.
  5. Providing legally required responses.

Rize Ink may charge reasonable fees for unusually burdensome or repetitive assistance that goes beyond ordinary Service functionality, provided Rize Ink gives Customer advance notice.

12. Data protection assessments and regulatory assistance

Taking into account the nature of the processing and information available, Rize Ink will reasonably assist Customer with:

  1. Privacy impact assessments.
  2. Data protection impact assessments.
  3. Risk assessments.
  4. Cybersecurity audits.
  5. Prior consultation with regulators.
  6. Investigations by supervisory authorities.
  7. Information reasonably needed to demonstrate Customer’s compliance.

Rize Ink is not required to:

  1. Disclose another customer’s information.
  2. Disclose privileged legal advice.
  3. Disclose information that would materially compromise security.
  4. Provide Customer with direct access to production systems.
  5. Create reports or certifications that do not exist.
  6. Bear unreasonable third-party costs requested solely for Customer’s benefit.

13. Subprocessors

13.1 General authorization

Customer grants Rize Ink general written authorization to use Subprocessors to provide the Service.

Rize Ink will maintain an accurate list of material Subprocessors on the Rize Ink website or in Annex 3.

13.2 Subprocessor requirements

Before allowing a Subprocessor to process Customer Personal Data, Rize Ink will enter into a written agreement requiring the Subprocessor to:

  1. Process the information only for authorized purposes.
  2. Maintain confidentiality.
  3. Implement appropriate security safeguards.
  4. Comply with applicable privacy obligations.
  5. Assist with Security Incidents and Data Subject requests where appropriate.
  6. Delete or return information as required.
  7. Not sell or share Customer Personal Data.
  8. Meet applicable international-transfer requirements.

Rize Ink remains responsible for the Subprocessor’s performance of its data processing obligations to the extent required by Applicable Data Protection Law.

13.3 Notice of new Subprocessors

Rize Ink will provide at least 15 days’ advance notice before a new material Subprocessor begins processing Customer Personal Data.

Notice may be provided:

  1. By email.
  2. Through the Service.
  3. Through the Subprocessor webpage.
  4. Through another agreed method.

13.4 Customer objections

Customer may object to a new Subprocessor on reasonable and documented data protection grounds by notifying Rize Ink within 15 days after notice.

The parties will attempt in good faith to resolve the objection.

Possible resolutions may include:

  1. Additional safeguards.
  2. A commercially reasonable configuration avoiding the Subprocessor.
  3. Discontinuation of the affected feature.
  4. Termination of the affected Service without penalty.

Customer may not object solely for competitive, commercial, or unrelated reasons.

14. Government and legal requests

If Rize Ink receives a subpoena, warrant, court order, or government request seeking Customer Personal Data, Rize Ink will, unless prohibited by law:

  1. Notify Customer before disclosure.
  2. Direct the requesting authority to Customer where appropriate.
  3. Disclose only information reasonably required.
  4. Challenge an unlawful or facially invalid request where reasonably appropriate.
  5. Document the request and response.

Rize Ink is not required to take legal action at its own expense beyond what Applicable Data Protection Law requires.

15. Return, export, and deletion

15.1 During the Subscription

Customer may access, export, or delete Customer Personal Data through available Service controls, subject to:

  1. Account permissions.
  2. Brokerage record-retention requirements.
  3. Legal holds.
  4. Security investigations.
  5. Applicable law.
  6. The integrity of executed documents and audit trails.

15.2 Following termination

Following termination:

  1. Customer will ordinarily have 30 days to export available Customer Personal Data.
  2. Rize Ink may remove Customer Personal Data from active systems within 90 days after the export period.
  3. Residual backup copies may remain for up to an additional 180 days.
  4. Backup information will remain protected and will not ordinarily be restored except for disaster recovery, security, or legal purposes.
  5. Rize Ink may retain information required by law, legal hold, fraud prevention, billing, security, or dispute resolution.

15.3 Certification

Upon reasonable written request, Rize Ink will provide written confirmation that Customer Personal Data has been deleted or placed beyond ordinary use, subject to legal and backup-retention exceptions.

15.4 Executed records

Customer acknowledges that deleting an executed document may affect legally required transaction records and signature evidence.

Rize Ink may require organizational administrator approval before deleting:

  1. Executed contracts.
  2. Audit trails.
  3. Completion certificates.
  4. Brokerage transaction files.
  5. Records subject to retention requirements.

16. Audits and compliance information

16.1 Compliance materials

Upon reasonable request, Rize Ink will make available information reasonably necessary to demonstrate compliance with this DPA, which may include:

  1. Security documentation.
  2. Privacy documentation.
  3. Subprocessor information.
  4. Data-flow descriptions.
  5. Penetration-test summaries, where available.
  6. Independent audit or certification reports, where available.
  7. Responses to reasonable security questionnaires.

Rize Ink must not represent that it holds a certification, such as SOC 2 or ISO 27001, unless that certification has actually been obtained and remains current.

16.2 Customer audits

Customer may audit Rize Ink’s compliance:

  1. No more than once in a 12-month period.
  2. On at least 30 days’ written notice.
  3. During normal business hours.
  4. In a manner that does not unreasonably disrupt operations.
  5. Subject to reasonable confidentiality and security requirements.

The annual limitation does not apply when:

  1. A Security Incident materially affects Customer Personal Data.
  2. A regulator requires an audit.
  3. Customer has reasonable evidence of material noncompliance.

16.3 Audit method

Rize Ink may first satisfy an audit request through:

  1. Existing independent reports.
  2. Certifications.
  3. Written responses.
  4. Remote interviews.
  5. Documentation review.

An onsite inspection may occur only when those methods are reasonably insufficient.

An auditor must:

  1. Be independent.
  2. Not be a direct competitor of Rize Ink.
  3. Sign appropriate confidentiality obligations.
  4. Avoid access to other customers’ information.
  5. Follow Rize Ink’s security rules.

Customer is responsible for its audit costs and Rize Ink’s reasonable costs caused by an unusually burdensome audit, unless the audit reveals material noncompliance by Rize Ink.

17. Sensitive and regulated information

Rize Ink is not designed to process the following categories unless Rize Ink expressly supports the processing and agrees in writing:

  1. Protected health information regulated by HIPAA.
  2. Full payment-card information subject to PCI DSS.
  3. Biometric identifiers used for unique identification.
  4. Criminal justice information subject to specialized access requirements.
  5. Classified government information.
  6. Information subject to export-control restrictions.
  7. Information concerning children collected in violation of applicable law.

Customer should not upload:

  1. Passwords.
  2. Authentication secrets.
  3. Complete payment-card numbers.
  4. Bank-account login credentials.
  5. Unnecessary Social Security numbers.
  6. Unnecessary government identification records.
  7. Medical records unrelated to a lawful transaction purpose.

If Customer uploads sensitive information, Rize Ink will process it only to provide the Service, maintain security, comply with law, or follow Customer’s lawful instructions.

18. Artificial intelligence and Customer Personal Data

Unless Customer separately provides affirmative written authorization:

  1. Rize Ink will not use private Customer Personal Data to train a general-purpose artificial-intelligence model.
  2. Rize Ink will not authorize a third-party AI provider to use Customer Personal Data to train its general models.
  3. AI providers may process Customer Personal Data only to provide the customer-requested feature.
  4. Rize Ink will apply appropriate contractual and security restrictions to AI Subprocessors.
  5. Customer remains responsible for reviewing AI-generated or extracted information.
  6. Customer Personal Data will not be used to create advertising profiles.

Rize Ink may use aggregated or deidentified information to improve the Service where the information cannot reasonably be associated with Customer, a transaction, or an individual.

19. International transfers

19.1 General requirement

Rize Ink will not transfer Customer Personal Data internationally except:

  1. As instructed by Customer.
  2. As needed to use an approved Subprocessor.
  3. Under a legally recognized transfer mechanism.
  4. As otherwise permitted by Applicable Data Protection Law.

19.2 European Economic Area

Where Customer transfers Personal Data protected by the GDPR to Rize Ink in a country not covered by an adequacy decision, the European Commission Standard Contractual Clauses adopted under Decision 2021/914 are incorporated by reference.

The applicable module is:

  1. Module Two when Customer is a Controller and Rize Ink is a Processor.
  2. Module Three when Customer is a Processor and Rize Ink is a Subprocessor.

The information in Annexes 1, 2, and 3 of this DPA completes the corresponding annexes to the Standard Contractual Clauses.

The parties must identify in Annex 4:

  1. The applicable module.
  2. The competent supervisory authority.
  3. The governing Member State law.
  4. The competent courts.
  5. Any optional clauses selected.
  6. The data exporter’s contact information.

19.3 United Kingdom and Switzerland

Where required, the parties will enter into:

  1. The applicable United Kingdom international data transfer addendum or agreement.
  2. Necessary Swiss adaptations to the Standard Contractual Clauses.
  3. Another legally valid transfer mechanism.

No international-transfer schedule is required merely because a United States real estate transaction involves a foreign citizen. The schedule becomes relevant when Applicable Data Protection Law governs the transfer.

20. Liability

The liability limitations, exclusions, and indemnification provisions in the Agreement apply to this DPA.

Nothing in this DPA limits liability that cannot legally be limited.

The Standard Contractual Clauses control to the extent their mandatory liability terms conflict with the Agreement.

21. Term

This DPA begins when Customer accepts the Agreement or first submits Customer Personal Data to the Service.

It continues until Rize Ink no longer processes Customer Personal Data.

Provisions concerning confidentiality, security, deletion, legal holds, audits, liability, and international transfers survive as necessary.

22. Changes

Rize Ink may update this DPA to:

  1. Comply with law.
  2. Address new privacy requirements.
  3. Reflect changes to the Service.
  4. Improve privacy or security protections.
  5. Replace obsolete legal mechanisms.

Rize Ink will provide reasonable advance notice of a material change that reduces Customer’s contractual data protection.

A change required by law may become effective sooner.

23. Electronic acceptance

This DPA may be accepted electronically.

Electronic acceptance has the same effect as a handwritten signature.

A separately signed copy is not required when the DPA is validly incorporated into the Agreement, although enterprise customers may request signature blocks.

24. Contact information

Rize Technologies, LLC
Doing business as Rize Ink
169 Madison Ave STE 2322, New York, NY 10016
Privacy inquiries: support@rizeink.com
Security inquiries: support@rizeink.com
Legal inquiries: legal@rizeink.com
Telephone: 352-234-3389

Annex 1 — Details of processing

A. Subject matter

Provision of Rize Ink’s document preparation, forms-library, transaction-management, electronic-signature, client-portal, storage, authentication, audit-trail, and related services.

B. Duration

Processing continues for the term of the Agreement and applicable retention and deletion periods.

C. Nature of processing

The processing may include:

  1. Collection.
  2. Receipt.
  3. Upload.
  4. Recording.
  5. Organization.
  6. Storage.
  7. Structuring.
  8. Viewing.
  9. Retrieval.
  10. Population of document fields.
  11. Electronic signing.
  12. Authentication.
  13. Transmission.
  14. Disclosure to Customer-authorized recipients.
  15. Backup.
  16. Restriction.
  17. Export.
  18. Deletion.

D. Purposes

The purposes are limited to:

  1. Providing the Service.
  2. Following Customer instructions.
  3. Maintaining security and availability.
  4. Providing support.
  5. Preventing fraud and illegal activity.
  6. Maintaining legally useful signature evidence.
  7. Complying with law.

E. Categories of Data Subjects

Data Subjects may include:

  1. Brokers.
  2. Real estate agents.
  3. Team members.
  4. Employees.
  5. Independent contractors.
  6. Transaction coordinators.
  7. Buyers.
  8. Sellers.
  9. Landlords.
  10. Tenants.
  11. Prospective customers.
  12. Signers.
  13. Document recipients.
  14. Attorneys.
  15. Title and escrow personnel.
  16. Lenders.
  17. Inspectors.
  18. Vendors.
  19. Property managers.
  20. Representatives of legal entities.
  21. Trustees, personal representatives, or authorized signers.

F. Categories of Personal Data

Customer Personal Data may include:

  1. Names.
  2. Email addresses.
  3. Telephone numbers.
  4. Mailing addresses.
  5. Property addresses.
  6. License and professional information.
  7. Brokerage and team affiliation.
  8. Contract and transaction information.
  9. Offer and purchase information.
  10. Lease information.
  11. Property information.
  12. Financial information included in documents.
  13. Electronic signatures and initials.
  14. Signer-consent records.
  15. IP addresses.
  16. Device and browser information.
  17. Authentication events.
  18. Audit trails.
  19. Communications.
  20. Uploaded documents.
  21. Document metadata.
  22. Transaction dates and deadlines.
  23. Legal representative or entity-signing information.

G. Sensitive Personal Data

The Service does not ordinarily require sensitive Personal Data, but Customer-uploaded documents may contain:

  1. Government identification information.
  2. Social Security numbers.
  3. Financial-account information.
  4. Information about familial or marital status.
  5. Information concerning disability or accommodation.
  6. Other information treated as sensitive under applicable law.

Customer is responsible for limiting sensitive information to what is reasonably necessary.

H. Processing frequency

Processing occurs on a continuous or transaction-initiated basis during Customer’s use of the Service.

I. Retention

Retention is governed by:

  1. Customer instructions.
  2. The Agreement.
  3. The Data Retention and Deletion Policy.
  4. Legal holds.
  5. Applicable law.

Annex 2 — Technical and organizational security measures

Rize Ink will implement the following measures before processing production Customer Personal Data.

1. Governance

  1. Written information-security policies.
  2. Assigned security responsibility.
  3. Periodic security-risk reviews.
  4. Privacy and security training for authorized personnel.
  5. Confidentiality obligations.
  6. Incident-response procedures.
  7. Vendor-risk management.

2. Access control

  1. Unique user accounts.
  2. Role-based access.
  3. Least-privilege principles.
  4. Strong password requirements.
  5. Multifactor authentication for privileged administrative access.
  6. Prompt removal of terminated users.
  7. Periodic review of privileged access.
  8. Logging of administrative access to customer information.
  9. Prohibition on shared administrator credentials.

3. Authentication

  1. Secure session management.
  2. Expiring authentication tokens.
  3. Rate limiting.
  4. Protection against credential stuffing.
  5. Password-reset safeguards.
  6. Optional or required multifactor authentication based on role.
  7. Strong random signing links.
  8. One-time code controls where used.

4. Encryption

  1. Encryption of Customer Personal Data in transit using current transport encryption.
  2. Encryption of stored production Customer Personal Data.
  3. Secure management of encryption keys.
  4. Encryption of backups containing Customer Personal Data.
  5. Prohibition on transmitting credentials in plaintext.

5. Application security

  1. Secure development practices.
  2. Code review for material changes.
  3. Separation of development and production environments.
  4. Dependency and vulnerability monitoring.
  5. Input validation.
  6. Protection against common web application vulnerabilities.
  7. Controlled deployment procedures.
  8. Testing before production release.
  9. Secure secret management.

6. Infrastructure security

  1. Firewalls and network access controls.
  2. Restricted production access.
  3. System patching.
  4. Malware protection where appropriate.
  5. Centralized logging.
  6. Monitoring for suspicious activity.
  7. Secure system configuration.
  8. Backup and recovery processes.
  9. Environmental and physical controls provided by approved hosting facilities.

7. Data separation

  1. Logical separation of customer accounts.
  2. Account-level authorization checks.
  3. Restriction of cross-customer document access.
  4. Separate production and test environments.
  5. No use of production Customer Personal Data in development except where necessary and protected.

8. Logging

  1. Authentication logs.
  2. Administrative access logs.
  3. Electronic-signature event logs.
  4. Document-processing events.
  5. Security events.
  6. Reliable timestamps.
  7. Protection against ordinary alteration of completed audit trails.
  8. Defined retention periods.

9. Electronic-signature integrity

  1. Unique envelope identifiers.
  2. Cryptographic document hashes.
  3. Version controls.
  4. Audit trails.
  5. Signer-consent records.
  6. Authentication records.
  7. Locked completed documents.
  8. Completion certificates.
  9. Prevention of silent alteration of executed documents.

10. Availability and recovery

  1. Regular backups.
  2. Backup restoration testing.
  3. Disaster-recovery procedures.
  4. Incident-response procedures.
  5. Business-continuity planning.
  6. Monitoring of critical systems.
  7. Redundancy appropriate to the Service.

11. Vendor security

  1. Security and privacy review before engaging material Subprocessors.
  2. Written data protection obligations.
  3. Restrictions on use of Customer Personal Data.
  4. Security Incident notification requirements.
  5. Deletion and return obligations.
  6. Periodic review based on risk.

12. Secure deletion

  1. Deletion from active systems according to approved procedures.
  2. Expiration of backup copies according to backup cycles.
  3. Secure disposal of storage media.
  4. Revocation of access and credentials.
  5. Preservation when subject to legal hold.

Annex 3 — Subprocessor list

The subprocessor list is being finalized. For the current list of material Subprocessors, contact legal@rizeink.com.

Annex 4 — International transfer details

Completed only where Applicable Data Protection Law governs an international transfer, as described in Section 19. Enterprise customers requiring Standard Contractual Clauses should contact legal@rizeink.com.