Beta notice
This DPA is written for HAPSecure's private beta and current customer-facing use. Limited-scope counsel review is still required before broad self-serve launch, paid advertising, or live certified-mail spend.
Data Processing Addendum
Effective date: June 29, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (the “Controller”) and UNFETTEREDMIND LLC (“HAPSecure” or the “Processor”) for use of the HAPSecure service. It governs the processing of personal data that HAPSecure carries out on the Controller's behalf and supplements the Terms of Service and Privacy Policy.
1. Parties and roles
The Controller is the customer organization that determines the purposes and means of processing tenant, applicant, household, unit, and PHA-document personal data. HAPSecure acts as the Processor, processing that personal data only on behalf of and on the documented instructions of the Controller.
2. Subject matter and duration
The subject matter of processing is operation of the HAPSecure compliance-ledger service. Processing continues for the duration of the agreement and until return or deletion of personal data as described in Section 10, subject to legal and record-retention obligations.
3. Nature and purpose of processing
HAPSecure ingests PHA correspondence and documents, classifies and extracts structured compliance data, records append-only events on a hash-chained ledger, runs cure-countdown timers, sends configured reminders, supports proof-submission workflows, displays HAP reconciliation and rent-reasonableness records, and stores supporting documents. Processing operations include collection, recording, organization, structuring, storage, retrieval, transmission, and erasure as needed to provide these functions.
4. Categories of data subjects and personal data
Data subjects: tenants, applicants, household members, customer staff, field contacts, PHA contacts where provided, and other people whose information appears in customer-provided records.
Categories of personal data: names, email addresses, phone numbers, residential addresses, unit identifiers, household and tenancy details, government housing-compliance records, inspection records, deficiency records, cure-proof photos and metadata, HAP/rent records, account identifiers, and audit-log metadata. The Controller remains responsible for the content and lawfulness of uploaded documents.
5. Processing on documented instructions
HAPSecure will process personal data only on the Controller's documented instructions, including those set out in the agreement and through use of the service, unless required to act by applicable law. HAPSecure will inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
6. Confidentiality
HAPSecure ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and access personal data only as necessary to perform their duties.
7. Security measures
HAPSecure maintains technical and organizational measures designed to protect personal data, including:
- Postgres Row-Level Security for per-organization isolation;
- private document storage gated by authorization checks;
- encryption in transit and provider-managed encryption at rest;
- append-only SHA-256 hash-chained ledger events that make tampering with past records detectable;
- MFA support and AAL2 enforcement;
- server-side validation for tenant-scoped writes and risky actions.
HAPSecure does not claim SOC 2, ISO 27001, or any other certification or third-party audit. This DPA describes actual controls only.
8. Sub-processing
The Controller authorizes HAPSecure to engage sub-processors to provide the service. Current core sub-processors include:
- Supabase - database, authentication, and document storage;
- Stripe - subscription billing and payment processing;
- Resend - outbound operational email sent by the application;
- Cloudflare - DNS, email routing, Worker processing, and edge security;
- Vercel - application hosting and content delivery;
- Anthropic - large language model services for document extraction;
- Lob - certified-mail letter creation when explicitly used;
- Google - public-page analytics and advertising attribution.
Supabase Auth currently sends authentication emails unless and until a custom SMTP provider is configured. HAPSecure will impose data-protection obligations on sub-processors and remains responsible for their performance as required by applicable law.
9. Assistance with data subject requests
Taking into account the nature of processing, HAPSecure will assist the Controller by appropriate technical and organizational measures, so far as possible, in responding to requests from data subjects to exercise their rights, and will promptly forward any such request it receives directly to the Controller.
10. Return, deletion, and retention
On termination of the service, HAPSecure will, at the Controller's choice where feasible, return or delete personal data, except to the extent retention is required by law, security, billing, dispute, or HUD/PHA record-retention obligations. Compliance records and supporting documents may persist on an immutable basis for the applicable retention period and audit purpose.
11. Personal data breach notification
HAPSecure will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's personal data and will provide information reasonably available to help the Controller meet its own notification obligations to authorities and data subjects.
12. Audit and information rights
HAPSecure will make available information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, notice, frequency, and security conditions to protect other customers and the service.
13. International transfers
Where processing involves transfer of personal data to a country subject to data-transfer law, the parties rely on appropriate safeguards such as contractual data-protection terms and Standard Contractual Clauses where applicable.
14. Governing law
This DPA is governed by the laws of the State of Texas and, where applicable, by the data-protection law governing the relevant processing. In the event of a conflict between this DPA and the Terms regarding processing of personal data, this DPA controls.
15. Contact
Questions or notices under this DPA may be sent to support@hapsecure.app, UNFETTEREDMIND LLC.