Data processing addendum
How Calden handles personal information for the property management companies it works for, as their service provider.
Last updated October 11, 2026
1This addendum
This addendum forms part of the agreement between Calden (“we”) and the customer (“you”) under our Terms of service and any order. It applies whenever we process personal information for you (“customer personal data”), and wins over the terms where they differ on data protection.
“Privacy laws” means the US federal and state laws that apply to that processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and similar state laws.
2Roles and the processing
You are the controller (the “business” under the CCPA). We are your processor, service provider and contractor.
- Purpose
- Coordinating maintenance at the properties you manage, as the agreement describes.
- People
- Your tenants, property owners, vendors and their staff, and your own team.
- Data
- Names and contact details, property and lease details, messages, call recordings and transcripts, job records, consent records, facts about properties (access codes encrypted), and vendor business and insurance details.
- Not requested
- Social Security or full taxpayer numbers, dates of birth, bank or payment details and driver's licence numbers: never asked for, and never read from property management software. Opinions and protected characteristics are never kept in the coordinator's memory. Messages and calls contain what people choose to say.
- Duration
- The term of the agreement, then until deletion under section 10.
3Your instructions
We process customer personal data only on your documented instructions: the agreement, the rules and settings you choose in the console, and what you ask in writing. We will tell you if we believe an instruction breaks privacy laws.
You are responsible for the lawfulness of your instructions and for having the notices and consents privacy and telephone laws require for the people we contact for you.
4US state privacy law terms
We will not:
- sell or share customer personal data, as the CCPA defines those words;
- keep, use or disclose it for any purpose other than providing the service to you, or outside our direct business relationship with you;
- combine it with personal information from other sources, except as privacy laws allow a service provider to.
We will comply with privacy laws and give customer personal data the level of protection they require, and tell you if we can no longer meet them. You may take reasonable steps to stop and remedy any use that breaks this addendum. We understand and will comply with these restrictions.
5Our people
Only staff who need customer personal data to run or support the service may access it, and each is bound to keep it confidential.
6Security measures
We keep technical and organisational measures appropriate to the risk, including:
- encryption in transit, and AES-256-GCM encryption at rest for access codes and the keys to property management software, in addition to the database host’s encryption;
- every customer’s data kept apart in the application: each request is limited to the signed-in person’s company;
- sign-in by emailed link with no passwords, and roles that limit who can see access codes, approve spending, change rules or export data;
- connections to property management software that only read, never write;
- a record of every message, call, decision by the coordinator, and change by your team;
- no secrets in code or logs, and checks on the signatures of incoming provider requests.
We hold no security certifications today and do not claim any.
7Subprocessors
You authorise us to use the subprocessors below. Each is bound in writing to protect customer personal data at least as this addendum requires, and we remain responsible for them. Customer personal data is stored and processed in the United States.
- Anthropic
- The AI model that reads each job and writes the coordinator's messages, picks out facts worth keeping, and summarises closed jobs. Receives the job's conversation and the details it needs.
- Retell AI
- Runs phone calls with an AI voice agent, records them and transcribes them. Receives phone numbers, call audio, and the job details the call needs.
- Resend
- Sends email: sign-in links, invitations, notices, morning summaries and pilot request emails. Receives email addresses and the message.
- Inngest
- Runs background work and timers, such as the next step of a job or a follow-up. Receives job and contact identifiers and step results, which can include message text.
- Neon
- Hosts the database where all customer data is stored.
- Vercel Inc.
- Runs the application and this website. Customer data passes through it, and it keeps request logs.
- Twilio (planned)
- Will send and receive text messages. Not in use yet; we will give notice before it handles customer data.
We will email you 30 days before a new subprocessor handles customer personal data. If you object on reasonable data protection grounds and we cannot address it, you may end the affected service and receive a refund of fees prepaid for the time after it ends.
8Helping with requests
If someone asks us to see, correct or delete their information, we will pass the request to you and not answer it ourselves unless you tell us to. We will help you respond, and help with assessments and consultations privacy laws require, as far as is reasonable given what we hold. People can stop texts and calls by replying STOP, which the service records and honours at once.
9Security incidents
If we confirm a breach of security that leads to unauthorised access to, or loss or disclosure of, customer personal data, we will notify you without undue delay and within 72 hours, with what we know about what happened, the data and people affected, and what we are doing. We will update you as we learn more and help you meet your own notice duties. Notifying you is not an admission of fault.
10Deletion and return
While the agreement lasts, owners and admins can download job lists and reports as CSV in the console, and we will export everything else on request in a common format. Records are not deleted automatically on a schedule today.
When the agreement ends, or when you ask, we will delete customer personal data from our systems within 30 days, and confirm it in writing. Copies in database backups expire on the host’s backup schedule and are not used meanwhile. We keep only what the law requires us to keep.
11Audits
We will give you the information reasonably needed to show we meet this addendum, and answer a reasonable security questionnaire once a year. If that is not enough, you or an independent auditor bound by confidentiality may audit our compliance once a year, with 30 days’ notice, during business hours and at your cost, or after a security incident.
12Liability and contact
Each party’s liability under this addendum is subject to the limits in the Terms of service. Questions, requests and incident reports: hello@getcalden.com.