Data Processing Addendum

Effective date: August 20, 2026

This addendum forms part of the service agreement between CMJPEJ, LLC (“we”, the service provider) and the community, association or management company that has engaged us (the customer). It describes how we handle personal information on the customer’s behalf.

Plainly: the customer decides, we execute. The customer determines why and how resident and visitor information is used. We process it only to provide the service and only on the customer’s documented instructions, which include the settings chosen in the platform. We do not sell it, we do not share it for cross-context behavioural advertising, and we do not use it for our own purposes.

What we process

  • Residents and household members: name, unit, contact details, vehicles, notification preferences, and account activity.
  • Visitors and guests: name, the resident expecting them, expected times, vehicle and plate where given, and entry and exit records.
  • Access and security records: gate and door events, licence-plate reads where the customer operates cameras, guard activity, incidents and shift notes.
  • Communications: messages sent through the platform, SMS and email delivery records, and call recordings where the customer has that feature enabled.
  • Staff and guards: account details and the actions taken under their account.

Retention is set by the customer per category. We delete records on the customer’s instruction. Where a retention period is configured, deletion is carried out on request rather than automatically — we will tell the customer if that changes.

How we protect it

  • Transport encryption for all traffic between apps, browsers and our servers.
  • Encryption of stored secrets and credentials — including door-system and telephony credentials, and SMTP settings — using AES-256-GCM.
  • Role-based access, enforced per community. A community’s records are reachable only through that community’s authorised roles.
  • Audit logging of sensitive actions, retained for the customer to review.
  • Application attestation on our mobile apps, so requests from a modified or impersonating client are rejected.
  • Access to production systems limited to personnel who need it, under confidentiality obligations.

We do not represent that the underlying database storage is encrypted at rest, or that backups are replicated to a separate site. We will not claim a control we have not implemented, and we will update this section when either changes.

Subprocessors

We use the following to provide the service. Each is bound to protect information consistently with this addendum.

  • Vultr Holdings — cloud hosting and database (United States).
  • Cloudflare — network protection, DNS and content delivery (United States).
  • VoIP Innovations — SMS and voice carriage (United States).
  • SMTP2GO — transactional email delivery (United States).
  • Stripe — payment processing for communities that pay by card (United States).
  • ProdataKey (PDK) — door and access-control systems, for communities using that hardware (United States).
  • Apple and Google — push-notification delivery to their own devices.

We will give the customer notice before adding a subprocessor that processes resident or visitor personal information, and the customer may object on reasonable data-protection grounds.

Assisting the customer

Residents and visitors ask their community, not us, and that is the correct route: the community holds the relationship. We will help the customer respond to a request to access, correct, export or delete personal information, and we provide the tools in the platform to do so.

Security incidents

If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to personal information we process for the customer, we will notify the customer without undue delay, and will provide the information the customer reasonably needs to meet its own notification obligations. We will not delay telling the customer while we investigate.

Return and deletion

On the end of the service agreement, the customer may request an export of its records. We will delete or return them on the customer’s instruction, other than copies we are required to keep by law or that persist in routine backups until those backups age out.

Audits

On reasonable notice, and no more than once a year unless there has been a security incident, we will answer the customer’s reasonable questions about our handling of its information and provide the documentation we hold.

Scope

We operate in the United States and this addendum is written for United States law, including the state privacy laws that apply to service providers. We are not a HIPAA business associate and the service is not intended for protected health information. If the customer has obligations we are not addressing here, tell us before signing.

Contact

CMJPEJ, LLC, 709 W Jericho Tpke, Huntington, NY 11743 — [email protected]

See also our Privacy Policy and Terms of Service.