Skip to content
startitagents
PlatformTemplatesPlansQuestionsSign inCreate my account ↗

TRUST CENTER · STARTIT AGENTS

Data processing agreement

Conditions governing personal data Startit processes under the agent's instructions.

EspañolEnglish
Version 2026-10-06.1Effective from 06/10/2026 17:05 UTCStartit Services LLC
Public version history

Included documents

Terms of serviceCookie policyPrivacy policyAI and MCP connectionsContent and intellectual property complaintsAccessibilityProviders and connected servicesAcceptable use policyData processing agreementPublication policy and agent responsibilitiesElectronic acceptance, versions and notices

In this document

1. Parties, scope and priority2. Description of processing3. Instructions and Client obligations4. Restrictions and confidentiality5. Technical and organizational measures6. Providers and chosen connections7. Rights, incidents and cooperation8. Information and review9. Location, transfers and terminationEvidence of instructions and limited retention

1. Parties, scope and priority

This agreement supplements the Terms of Service between Startit Services LLC ("Provider") and the account holder ("Client"). It applies to personal data entered or collected in the account to manage the Client's activity. The Client acts as controller or business and the Provider as processor, service provider or contractor, depending on applicable law. Data Startit needs for its own billing, security and contractual relationship are governed by the Privacy Policy.

If provisions conflict regarding processing on the Client's behalf, this agreement prevails. It does not establish a relationship between Startit and the Client's brokerage or make Startit responsible for the commercial purposes the Client determines.

2. Description of processing

Subject and durationSoftware delivery during the contract and the period needed for closure, export, deletion and legal obligations.
OperationsCollection through forms and imports, storage, organization, consultation, updating, authorized sending, portal availability, export, backup and deletion.
PurposesManagement of contacts, inquiries, properties, tasks, deals, appointments, documents, events and communications requested by the Client.
PeopleContacts, prospective buyers or sellers, event attendees, clients and people legitimately included in documents.
CategoriesIdentity and contact details, real estate preferences, notes, correspondence, appointments, attendance, activity and documents needed for the relationship.
Restricted dataProcessing of special categories, criminal data, medical histories, financial credentials or children's data is not requested. These must not be uploaded without a specific agreement and appropriate controls.

3. Instructions and Client obligations

Documented instructions consist of the contract, configuration, the Client's legitimate actions and expressly approved proposals. The Client warrants a valid basis for supplying data and directing processing, provides required notices and keeps data and permissions current. The Client will not instruct unlawful actions or use the platform to evade people's rights.

The Provider processes data only to deliver the service and according to those instructions, except where legally required; in that case it will give notice when law permits. It will notify the Client if it considers an instruction contrary to applicable regulations and may suspend execution while the issue is clarified.

4. Restrictions and confidentiality

The Provider does not sell or share these data for cross-site behavioral advertising, use them for business purposes unrelated to the service or combine them with other sources to profile consumers beyond what the contract and law permit. It does not use CRM data to train its own AI models.

Access is limited to authorized people under confidentiality duties. The Provider will notify the Client if it determines it can no longer meet its obligations and allow reasonable measures to stop and correct unauthorized use. These restrictions include obligations applicable to service providers or contractors under state privacy laws.

5. Technical and organizational measures

Measures include account separation in queries and operations, authentication, plan and permission checks, session controls, input validation, CSRF protection, abuse limits, sensitive-action logging, private secret configuration and backup. The public service uses transport encryption and private documents require authorized access.

Security review considers product changes and reasonable risks. Measures may evolve without substantially reducing the overall protection level. The Client maintains the security of its devices, credentials, integrations and sharing decisions. No measure eliminates every risk.

6. Providers and chosen connections

The Client authorizes necessary providers identified in the provider register, subject to appropriate protective obligations. Startit will give reasonable advance notice of material additions, normally at least 15 days where possible, to allow a substantiated data-protection objection. If unresolved, the parties may agree on an alternative or end the affected function.

AI clients, registrars and other services connected directly by the Client may be the Client's own providers. Their authorization does not allow Startit to expand processing. The Client must review their terms and the lawfulness of transfers it directs.

7. Rights, incidents and cooperation

Taking the nature of processing into account, Startit will provide reasonable assistance with requests for access, correction, portability, deletion, objection or restriction. If it receives a request relating to the Client's data, it will forward or coordinate it with the Client unless legally prohibited. It will not independently decide matters belonging to the controller.

Upon confirming a security breach affecting the Client's personal data, Startit will notify the Client without undue delay using available information and provide relevant updates: nature, affected categories when known, likely consequences, measures and contact. Initial notice need not wait for a complete investigation and is not an admission of fault. The Client determines and makes its required notifications to people or authorities with reasonable Provider assistance.

Startit will cooperate with service-related impact assessments and regulatory consultations when legally necessary, proportionately to the information it controls.

8. Information and review

On reasonable request, Startit will provide information needed to demonstrate compliance with this agreement. Reviews will observe confidentiality, sufficient notice and a service-related scope without accessing secrets or other accounts' data. When necessary and documentation is insufficient, the parties will agree to a proportionate review. An audit clause does not authorize uncoordinated penetration testing.

9. Location, transfers and termination

The service initially targets US professionals. If the Client intends to transfer data subject to mandatory international mechanisms, it must communicate this beforehand so necessary safeguards can be established. This document does not replace standard contractual clauses, territorial addenda or legally required agreements; it does not assert certification under a transfer framework.

When service ends, the Provider will return or delete data according to the Client's valid instruction and available export capabilities, except where retention is legally required. It will agree to the closure period and notify retention exceptions. Backups will remain restricted and be deleted through rotation. Confidentiality and protection obligations survive while data are retained.

Evidence of instructions and limited retention

Contract versions, acceptances and publication receipts document instructions and obligations. Data strictly necessary for Startit’s own contractual relationship, security and defense of claims is governed by the Privacy policy and is not reused for incompatible purposes. Termination does not require destruction of evidence whose retention is mandatory or necessary and proportionate; access is restricted and applicable rights are honored. Copies of Customer content retained on the Customer’s instructions remain protected by this agreement.

Document fingerprint (SHA-256): 1a2fc14ba3838343046b75a198c18f6083a4172ea938312861d2f114f6847824

We are here to help.

Startit Services LLC · Florida, United States.
11851 Southwest 179th Terrace, Miami, FL 33177, United States

info@startitservices.com

startitagents

Your brand, your way of working.
A place to help it grow.

info@startitservices.com ↗

Discover

PlatformTemplatesPlans and pricingYour office

Trust

PrivacyTerms of serviceCookiesAccessibilityElectronic acceptanceVersion history

Responsible use

Acceptable useAI and MCP connectionsData processingProvidersPublication policyContent complaints
© 2026 Startit Services LLC. All rights reserved.Built for independent agents.