This Data Processing Addendum (“DPA”) forms part of the agreement governing a customer's use of AgentNook (the “Agreement”) between the customer identified by its AgentNook account, order form, or other ordering document (“Customer”) and Again LLC, doing business as AgentNook (“AgentNook”). It applies when AgentNook processes Customer Personal Data on Customer's behalf. Capitalized terms not defined here have the meanings in the Agreement.
1. Definitions
- Applicable Data Protection Law means privacy and data-protection law applicable to the processing under the Agreement, including, as applicable, the GDPR, UK GDPR, and U.S. state privacy laws.
- Customer Personal Data means personal data, personal information, or a similar regulated category contained in Customer Data that AgentNook processes on Customer's behalf.
- Controller, Processor, Data Subject, Personal Data Breach, process, and Supervisory Authority have the meanings given by Applicable Data Protection Law.
- GDPR means Regulation (EU) 2016/679, and UK GDPR means the GDPR as incorporated into United Kingdom law.
- Subprocessor means a third party engaged by AgentNook to process Customer Personal Data.
- SCCs means the European Commission's Standard Contractual Clauses adopted by Decision (EU) 2021/914.
2. Roles, scope, and instructions
Customer is a Controller or Processor, as applicable, and AgentNook is a Processor or Subprocessor. Customer appoints AgentNook to process Customer Personal Data to provide, secure, maintain, and support the Service; follow documented configuration and user instructions; and perform the processing described in Annex I. The Agreement, this DPA, product configuration, and Customer's lawful use of the Service are Customer's documented instructions.
AgentNook will process Customer Personal Data only on those instructions unless law requires otherwise. If legally permitted, AgentNook will notify Customer before legally required processing. AgentNook will promptly inform Customer if, in our opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing until the parties resolve the issue.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; providing required notices; obtaining required rights and consents; responding to Data Subjects; and ensuring its instructions comply with law. Customer will not provide data that the Service is not designed to handle, including full payment-card data, protected health information, account passwords, government identification numbers, or special-category data, unless AgentNook expressly agrees in writing.
3. Confidentiality and personnel
AgentNook will ensure that people authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as necessary to perform their responsibilities. AgentNook remains responsible for their compliance with this DPA.
4. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as risks to individuals, AgentNook will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures are summarized in Annex II. Customer is responsible for configuring permissions appropriately, safeguarding user accounts, and using available security controls.
5. Subprocessors
Customer grants general written authorization for AgentNook to use the Subprocessors listed in Annex III. AgentNook will impose data-protection obligations on each Subprocessor that are no less protective in substance than the obligations applicable to its processing under this DPA, and AgentNook remains responsible for each Subprocessor's performance to the extent required by Applicable Data Protection Law.
We may update the list as the Service changes. For a new Subprocessor that will materially process Customer Personal Data, we will provide notice by updating this DPA or through another reasonable channel before the new processing begins where practicable. Customer may object on reasonable data-protection grounds by emailing hello@agentnook.com within 15 days after notice. The parties will work in good faith on a reasonable solution. If none is available, Customer may stop using the affected feature or terminate the affected Service without penalty for its unused prepaid period.
6. Data Subject requests
Taking into account the nature of processing, AgentNook will provide reasonable assistance through product functionality and other appropriate measures so Customer can respond to Data Subject requests. If AgentNook receives a request relating to Customer Personal Data directly, we will direct the requester to Customer or forward the request when reasonably identifiable, unless law prohibits us from doing so. We will not independently respond except on Customer's instructions or as legally required.
7. Security incidents
AgentNook will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. As information becomes available, we will provide information reasonably necessary for Customer to meet its notification obligations, including the nature of the incident, categories of affected data and people, likely consequences, and mitigation taken or proposed. AgentNook will take reasonable steps to contain, investigate, and mitigate the incident. Notification is not an admission of fault or liability.
8. Assistance and compliance information
Taking into account the nature of processing and information available to us, AgentNook will provide reasonable assistance with Customer's security obligations, breach notifications, data-protection impact assessments, and prior consultations relating to the Service. We will make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
9. Audits
Customer may audit compliance with this DPA once per year and additionally after a Personal Data Breach or when required by a Supervisory Authority. Audits must be preceded by reasonable notice, occur during normal business hours, avoid unreasonable disruption, protect other customers and confidential information, and comply with reasonable security procedures. AgentNook may satisfy an audit request with current questionnaires, summaries, certifications, or independent reports where appropriate. Customer bears its audit costs; AgentNook may charge reasonable costs for unusually burdensome assistance. These limits do not restrict a Supervisory Authority's lawful powers.
10. Return and deletion
During the term, Customer may access and export Customer Data through available Service features. At Customer's choice and on written instruction or termination, AgentNook will delete or return Customer Personal Data and delete remaining copies, unless law requires retention. Data in restricted backups will be isolated from ordinary use and deleted according to the applicable backup lifecycle. Data in a shared workspace remains under the controlling Customer's instructions even if an individual user leaves.
11. International transfers
Customer authorizes AgentNook and its Subprocessors to process Customer Personal Data in the United States and other countries needed to provide the Service. Each party will comply with transfer restrictions under Applicable Data Protection Law.
For a restricted transfer of EEA personal data to AgentNook that is not otherwise covered by an adequate transfer mechanism, the SCCs are incorporated by reference and apply as follows: Module Two applies when Customer is a Controller and AgentNook is a Processor; Module Three applies when Customer is a Processor and AgentNook is a Subprocessor; Clause 7 (docking) applies; Option 2 and the authorization period in Section 5 apply to Clause 9; the optional language in Clause 11 does not apply; and the governing law and courts are those of Ireland. Annexes I–III of this DPA complete the corresponding SCC annexes. If the UK GDPR applies, the then-current International Data Transfer Addendum issued by the UK Information Commissioner is incorporated and modifies the SCCs as needed. The SCCs or UK Addendum control over conflicting terms in this DPA.
12. U.S. state privacy terms
To the extent Customer Personal Data is “personal information” subject to the California Consumer Privacy Act, AgentNook is a service provider or contractor. AgentNook will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or for purposes other than the business purposes specified in the Agreement and this DPA; or combine it with personal information received from another person or from AgentNook's own consumer interactions, except as permitted by law.
AgentNook will provide the same level of privacy protection required by applicable law, notify Customer if we determine we can no longer meet an applicable obligation, and allow Customer to take reasonable and appropriate steps to help ensure compliant processing and stop and remediate unauthorized use. These commitments also apply under other U.S. state privacy laws to the extent they impose equivalent processor, service-provider, or contractor duties.
13. Liability, order of precedence, and term
The Agreement's liability limits and exclusions apply to this DPA to the maximum extent permitted by law. If documents conflict regarding personal-data processing, the order of precedence is: SCCs or UK Addendum, this DPA, an applicable order form, then the Agreement. This DPA continues while AgentNook processes Customer Personal Data. Provisions intended to protect personal data survive termination for as long as AgentNook retains that data.
Annex I — Processing details
Parties: Customer is the Controller or Processor and data exporter. Again LLC, doing business as AgentNook, is the Processor or Subprocessor and data importer. The parties' account, order, and contact records supply their business and contact details.
Subject matter: Provision, security, maintenance, and support of the AgentNook real estate CRM and related features.
Duration: The Agreement's term and any limited period afterward during which deletion, return, legal retention, or backup expiration occurs.
Nature, purpose, and frequency: Hosting, organizing, retrieving, modifying, transmitting, analyzing, securing, supporting, and deleting Customer Personal Data as initiated by Customer's ongoing use of CRM, property, deal, task, document, referral, communication, reporting, AI, voice, and notification features.
Data Subjects: Customer's users, agents, staff, contractors, clients, prospects, leads, transaction participants, referral partners, vendors, and other people whose information Customer submits.
Personal data: Names; contact and professional information; authentication and workspace identifiers; property and transaction information; notes, tasks, communications, documents, photos, and attachments; financial and commission information entered into the CRM; referral information; prompts, relevant workspace context, AI outputs, transcripts, and voice content; and technical, usage, security, and support information.
Sensitive or special-category data: The Service is not designed to require special-category data. Customer must not submit it unless expressly agreed in writing. Customer may elect to enter financial details about transactions and commissions, which are not payment-card data.
Competent Supervisory Authority: Determined under Clause 13 of the SCCs based on the applicable exporter and Data Subjects.
Annex II — Technical and organizational measures
- TLS for data transmitted between supported clients and the Service.
- Managed database encryption and designated field-level encryption for sensitive contact fields.
- Private object storage with authenticated, time-limited access paths for protected files.
- Tenant, role, and membership authorization controls designed to separate workspace data.
- Server-side storage of service credentials and production secrets, with access limited by operational need.
- Authentication, session controls, validation, rate limiting, and safeguards for sensitive actions.
- Application logging and audit records for designated security-relevant or workspace actions.
- Managed infrastructure backup and recovery capabilities, subject to provider configuration and lifecycle.
- Code review, automated testing, dependency review, and restricted production deployment practices.
- Data minimization, account-deletion workflows, retention controls, and incident-response procedures.
Annex III — Authorized Subprocessors and providers
The providers below process information depending on the features, authentication method, billing channel, and deployment used. Some payment or platform providers may act as independent controllers for portions of their processing under their own terms.
- Supabase — managed database, authentication, object storage, and related infrastructure.
- Vercel — web application hosting, server execution, and content delivery.
- OpenAI — AI generation, transcription, and text-to-speech processing.
- Resend — transactional and service email delivery.
- Stripe — web subscription, payment, tax, and billing processing.
- Google — optional sign-in, Google Places address search, Google Play billing, push delivery, and public-site analytics.
- Apple — optional sign-in, App Store billing, and push-notification delivery.
- RevenueCat — mobile subscription and entitlement management.
- Expo — mobile build, update, and push-notification infrastructure.
- Open-Meteo — weather data for a user's saved service area.
- RentCast — optional property-data enrichment.
- Microsoft Clarity — public marketing-site analytics when enabled; not intentionally used in the authenticated CRM.
Acceptance and contact
This DPA is executed when Customer accepts the Agreement electronically, signs an order form incorporating it, or otherwise agrees to it. For DPA questions or a countersigned copy, contact hello@agentnook.com.
Again LLC, doing business as AgentNook
