Data Processing Addendum
Last updated: September 14, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service(the "Terms") between Future Condos Inc., which operates TripleTick ("we," "us," or the "Processor"), and the customer that has accepted the Terms ("you" or the "Controller"). It applies whenever we process Customer Personal Data on your behalf in providing the TripleTick platform.
This DPA is incorporated into the Terms by reference and takes effect when you accept the Terms. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA controls.
1. Definitions
- Customer Personal Data: personal data that you or your users submit to TripleTick, or that TripleTick receives on your behalf through a connected channel, and that we process as your processor.
- Data Protection Laws:all privacy and data protection laws that apply to the processing, which may include Canada's Personal Information Protection and Electronic Documents Act, the EU and UK General Data Protection Regulation, and similar laws elsewhere.
- Sub-processor: a third party we engage to process Customer Personal Data.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
Terms such as "controller," "processor," "data subject," and "processing" have the meanings given in the applicable Data Protection Laws.
2. Roles of the Parties
You are the controller of Customer Personal Data and decide why and how it is processed. We are your processor and process Customer Personal Data only on your behalf. Where you act as a processor for a third party, we act as your sub-processor, and you are responsible for obtaining any authorizations that third party requires.
We act as an independent controller only for the limited data we need to run our own business, such as account, billing, and support records, which our Privacy Policy covers.
3. Scope and Details of Processing
Subject matter and duration: providing the TripleTick platform under the Terms, for as long as the Terms remain in effect and until Customer Personal Data is deleted under section 11.
Nature and purpose: storing, organizing, transmitting, and analyzing messages and contact records so you can manage WhatsApp and Instagram conversations, run broadcasts and automations, operate AI agents, and manage your sales pipeline.
Categories of data subjects:
- Your contacts, leads, and customers who message you or whom you message
- Your employees and team members who use TripleTick
Categories of personal data:
- Names, phone numbers, email addresses, and social profile identifiers
- Message content, including text, images, documents, voice notes, and shared locations
- Conversation metadata, such as timestamps and delivery and read receipts
- Tags, notes, pipeline stages, custom fields, and other CRM data you create
- Documents and content you upload to a knowledge base or inventory
- Usage data about how team members use the platform
You should not submit special categories of personal data, or data about children, unless the processing is lawful and you have told us in writing.
4. Processing Instructions
We process Customer Personal Data only on your documented instructions. The Terms, this DPA, and your use and configuration of the platform are your complete instructions. We will tell you if we believe an instruction breaks Data Protection Laws, and we may suspend that processing until you confirm or change the instruction.
We may process Customer Personal Data outside your instructions only where the law requires it, and we will tell you first unless the law forbids it.
You are responsible for having a lawful basis for the processing, including any consent your contacts must give to receive messages, as required by section 5 of the Terms.
5. Confidentiality
We ensure that every person we authorize to process Customer Personal Data is bound by a duty of confidentiality, whether by contract or by law, and has access only to the extent needed to provide the service or support you.
6. Security Measures
We maintain technical and organizational measures designed to protect Customer Personal Data, including:
- Encryption of data at rest in our database provider and encryption in transit using TLS 1.2 or higher
- Row-level security policies in the database that isolate each organization's data from every other organization
- Access controls that limit access to Customer Personal Data to authorized personnel
- An audit log that records actions taken within each organization
- Rate limiting on application interfaces to reduce abuse
- Regular automated backups
- API keys and secrets stored as environment variables, never in source code
- Session recording disabled in our product analytics
We may update these measures over time, provided the update does not materially reduce the overall protection of Customer Personal Data.
7. Sub-processors
You give us general authorization to engage Sub-processors. Our current Sub-processors are listed on our Sub-processors page.
We will notify you of any new Sub-processor by email or by updating that page before it begins processing Customer Personal Data. You may object on reasonable data protection grounds by contacting us within 30 days of the notice. If we cannot reasonably address the objection, you may stop using the affected part of the service or terminate the Terms, which is your sole remedy for the objection.
We impose data protection obligations on each Sub-processor that are substantially similar to those in this DPA, and we remain responsible for each Sub-processor's performance of those obligations.
8. Data Subject Requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. Much of this you can do yourself in the app, including deleting individual contacts and conversations.
If we receive a request directly from one of your data subjects, we will refer the request to you and will not respond to it ourselves, unless the law requires otherwise.
9. Security Incident Notification
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will describe, to the extent then known, the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the steps we have taken or propose to take.
We will take reasonable steps to contain and investigate the incident and will provide further information as it becomes available. Our notice is not an acknowledgment of fault or liability.
10. International Transfers
Customer Personal Data may be processed in countries other than the one in which you or your data subjects are located, including where our Sub-processors operate, as listed on our Sub-processors page.
Where Data Protection Laws require a transfer mechanism, the parties agree that the Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum where applicable, are incorporated into this DPA by reference, with you as data exporter and us as data importer. We will ensure that onward transfers to Sub-processors are subject to an appropriate safeguard.
11. Deletion and Return of Data
You can export or delete Customer Personal Data using the platform at any time while the Terms are in effect.
After the Terms end, we retain Customer Personal Data for 90 days, during which you may ask us for a copy, and then delete it, as set out in section 11 of the Terms. Deletion requests are handled as described in our Data Deletion Policy, including completion within 30 days of verification and the purge of encrypted backups within 90 days as backups rotate.
We may keep Customer Personal Data where the law requires it, and data that has been anonymized so that it can no longer be linked to an individual. Any data we keep remains protected by this DPA.
12. Audits
On written request, and no more than once in any 12-month period, we will make available the information reasonably necessary to demonstrate our compliance with this DPA, such as written responses to a security questionnaire.
If that information is not enough to demonstrate compliance, or a supervisory authority requires it, you may conduct an audit at your own cost, on at least 30 days' written notice, during business hours, in a way that does not disrupt our operations or compromise the security or confidentiality of other customers' data. Any auditor must be bound by confidentiality obligations.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms.
14. Term and Governing Law
This DPA remains in effect for as long as we process Customer Personal Data on your behalf. It is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, except where Data Protection Laws or the Standard Contractual Clauses require a different governing law for a particular transfer.
15. Contact Us
For questions about this DPA or to exercise any right under it, contact us:
- Entity: Future Condos Inc.
- Email: security@tripletick.ai
- Website: tripletick.ai