Legal Center
Data Processing Agreement.
A GDPR-style Data Processing Agreement template between your organization and Keystone IQ, for your legal or procurement team's records. Last updated July 2026.
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between the customer organization using Keystone IQ ("Controller") and Certix Consulting LLC, doing business as Keystone IQ ("Processor"), governing the Processor's processing of personal data on the Controller's behalf. Where this DPA and the Terms of Service conflict on data-protection matters, this DPA controls.
1. Parties & definitions
"Controller" means the customer organization that has created a Keystone IQ account and determines the purposes and means of processing the personal data it uploads to, or generates within, the Keystone IQ platform.
"Processor" means Certix Consulting LLC, doing business as Keystone IQ, which processes personal data on the Controller's behalf solely to provide the Keystone IQ service.
2. Subject matter and duration
The subject matter of this DPA is the Processor's processing of personal data in connection with the Controller's use of the Keystone IQ platform to manage its real estate portfolio. Processing occurs for the duration of the Controller's underlying Keystone IQ subscription, and continues only as long as necessary to fulfill the data-retention and deletion obligations described in Section 9 after the subscription ends.
3. Nature and purpose of processing
The Processor processes personal data for the purpose of providing property management and real estate portfolio software, including: financial tracking and ledger management for the Controller's properties; tenant and lease record-keeping; AI-assisted extraction of data from documents the Controller uploads (invoices, mortgage statements, owner packets); and, where the Controller opts in, connecting to the Controller's bank and mortgage accounts to import transactions and balances.
4. Categories of data subjects and categories of personal data
Categories of data subjects whose personal data may be processed under this DPA include: (a) the Controller's own users (its owners, employees, or contractors with a Keystone IQ login); (b) the Controller's tenants; and (c) the Controller's property staff, vendors, and contacts recorded in the platform (e.g. property managers, maintenance vendors).
Categories of personal data processed may include: contact information (name, email, phone, mailing address); lease and financial records (rent amounts, payment history, lease terms, security deposits); and, only where the Controller chooses to connect a bank or mortgage account via Plaid, bank-linked transaction and account-balance data. Keystone IQ does not intentionally collect special categories of data (e.g. health or biometric data) and the Controller should not upload such data to the platform.
5. Processor obligations
Confidentiality. The Processor ensures that any personnel authorized to process personal data on its behalf are bound by an obligation of confidentiality, whether contractual or statutory.
Security measures. The Processor maintains the technical and organizational security measures described in its Privacy Policy, including encryption of data in transit and at rest. On operator access specifically, the Privacy Policy states: "Keystone IQ operators have administrative access limited to the metadata required to support your account — organization name, member emails, subscription plan, aggregate usage counts, and property names. They do not see individual transactions, tenant details, or document contents. Every operator access is recorded in an audit log with a typed reason." This DPA does not create any security commitment beyond what the Privacy Policy already describes.
Sub-processor authorization. The Controller provides general authorization for the Processor to engage the sub-processors listed at keystoneiq.app/subprocessors to assist in providing the service. The Processor will provide notice of any material change to that list (such as adding a new sub-processor) by updating the page linked above; the Controller may object on reasonable data-protection grounds by contacting support@keystoneiq.app.
6. Assistance with data subject rights requests
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller in responding to requests from data subjects exercising their rights (such as access, correction, or deletion requests) to the extent such requests relate to personal data the Processor holds on the Controller's behalf. Requests for assistance can be directed to support@keystoneiq.app.
7. Breach notification
The Processor will notify the Controller without undue delay and within 72 hours of confirmation of any personal data breach affecting the Controller's data, and will provide the information reasonably available to it at that time to help the Controller meet its own notification obligations, with further detail provided as the Processor's investigation progresses.
8. Audit rights
The Controller may request reasonable evidence of the Processor's compliance with this DPA (such as a description of the security measures in place) no more than once per year, absent a specific concern. The Processor will provide relevant documentation in response to such a request.
Keystone IQ does not currently hold a SOC 2 or ISO 27001 certification, and does not offer on-site audits. We believe documentation-based review is the right fit at our current stage, and we're glad to answer specific questions about our practices at support@keystoneiq.app.
9. Data deletion and return on termination
Upon termination of the underlying subscription, the Processor retains the Controller's data for a 30-day grace period so the Controller can reactivate without losing anything, after which it is permanently deleted across all Processor systems — including transactions, properties, tenants, documents in the Document Vault, and any connected bank or mortgage account tokens (access to connected financial institutions is revoked and the associated tokens are destroyed). The subscription is cancelled and the Controller's contact details held by the payment sub-processor are scrubbed; invoices and payment records that tax and accounting law require the sub-processor to retain are kept for the mandated period.
The Controller may request deletion of its account and data at any time, before the 30-day grace period elapses, from its account settings or by emailing support@keystoneiq.app. A Controller that needs an export of its data before deletion should request one through the same channel prior to the grace period ending.
EU representative
Not applicable — Keystone IQ has no EU establishment and has not appointed an EU representative.
This is a template for reference. For an executed, counter-signed copy of this Data Processing Agreement, contact support@keystoneiq.app.
Not legal advice. Consult a qualified attorney for your jurisdiction.