1. Parties, scope and priority
This agreement supplements the Terms of Service between Startit Services LLC ("Provider") and the account holder ("Client"). It applies to personal data entered or collected in the account to manage the Client's activity. The Client acts as controller or business and the Provider as processor, service provider or contractor, depending on applicable law. Data Startit needs for its own billing, security and contractual relationship are governed by the Privacy Policy.
If provisions conflict regarding processing on the Client's behalf, this agreement prevails. It does not establish a relationship between Startit and the Client's brokerage or make Startit responsible for the commercial purposes the Client determines.
2. Description of processing
| Subject and duration | Software delivery during the contract and the period needed for closure, export, deletion and legal obligations. |
|---|---|
| Operations | Collection through forms and imports, storage, organization, consultation, updating, authorized sending, portal availability, export, backup and deletion. |
| Purposes | Management of contacts, inquiries, properties, tasks, deals, appointments, documents, events and communications requested by the Client. |
| People | Contacts, prospective buyers or sellers, event attendees, clients and people legitimately included in documents. |
| Categories | Identity and contact details, real estate preferences, notes, correspondence, appointments, attendance, activity and documents needed for the relationship. |
| Restricted data | Processing of special categories, criminal data, medical histories, financial credentials or children's data is not requested. These must not be uploaded without a specific agreement and appropriate controls. |
3. Instructions and Client obligations
Documented instructions consist of the contract, configuration, the Client's legitimate actions and expressly approved proposals. The Client warrants a valid basis for supplying data and directing processing, provides required notices and keeps data and permissions current. The Client will not instruct unlawful actions or use the platform to evade people's rights.
The Provider processes data only to deliver the service and according to those instructions, except where legally required; in that case it will give notice when law permits. It will notify the Client if it considers an instruction contrary to applicable regulations and may suspend execution while the issue is clarified.
4. Restrictions and confidentiality
The Provider does not sell or share these data for cross-site behavioral advertising, use them for business purposes unrelated to the service or combine them with other sources to profile consumers beyond what the contract and law permit. It does not use CRM data to train its own AI models.
Access is limited to authorized people under confidentiality duties. The Provider will notify the Client if it determines it can no longer meet its obligations and allow reasonable measures to stop and correct unauthorized use. These restrictions include obligations applicable to service providers or contractors under state privacy laws.
5. Technical and organizational measures
Measures include account separation in queries and operations, authentication, plan and permission checks, session controls, input validation, CSRF protection, abuse limits, sensitive-action logging, private secret configuration and backup. The public service uses transport encryption and private documents require authorized access.
Security review considers product changes and reasonable risks. Measures may evolve without substantially reducing the overall protection level. The Client maintains the security of its devices, credentials, integrations and sharing decisions. No measure eliminates every risk.
6. Providers and chosen connections
The Client authorizes necessary providers identified in the provider register, subject to appropriate protective obligations. Startit will give reasonable advance notice of material additions, normally at least 15 days where possible, to allow a substantiated data-protection objection. If unresolved, the parties may agree on an alternative or end the affected function.
AI clients, registrars and other services connected directly by the Client may be the Client's own providers. Their authorization does not allow Startit to expand processing. The Client must review their terms and the lawfulness of transfers it directs.
7. Rights, incidents and cooperation
Taking the nature of processing into account, Startit will provide reasonable assistance with requests for access, correction, portability, deletion, objection or restriction. If it receives a request relating to the Client's data, it will forward or coordinate it with the Client unless legally prohibited. It will not independently decide matters belonging to the controller.
Upon confirming a security breach affecting the Client's personal data, Startit will notify the Client without undue delay using available information and provide relevant updates: nature, affected categories when known, likely consequences, measures and contact. Initial notice need not wait for a complete investigation and is not an admission of fault. The Client determines and makes its required notifications to people or authorities with reasonable Provider assistance.
Startit will cooperate with service-related impact assessments and regulatory consultations when legally necessary, proportionately to the information it controls.
8. Information and review
On reasonable request, Startit will provide information needed to demonstrate compliance with this agreement. Reviews will observe confidentiality, sufficient notice and a service-related scope without accessing secrets or other accounts' data. When necessary and documentation is insufficient, the parties will agree to a proportionate review. An audit clause does not authorize uncoordinated penetration testing.
9. Location, transfers and termination
The service initially targets US professionals. If the Client intends to transfer data subject to mandatory international mechanisms, it must communicate this beforehand so necessary safeguards can be established. This document does not replace standard contractual clauses, territorial addenda or legally required agreements; it does not assert certification under a transfer framework.
When service ends, the Provider will return or delete data according to the Client's valid instruction and available export capabilities, except where retention is legally required. It will agree to the closure period and notify retention exceptions. Backups will remain restricted and be deleted through rotation. Confidentiality and protection obligations survive while data are retained.
Evidence of instructions and limited retention
Contract versions, acceptances and publication receipts document instructions and obligations. Data strictly necessary for Startit’s own contractual relationship, security and defense of claims is governed by the Privacy policy and is not reused for incompatible purposes. Termination does not require destruction of evidence whose retention is mandatory or necessary and proportionate; access is restricted and applicable rights are honored. Copies of Customer content retained on the Customer’s instructions remain protected by this agreement.
Document fingerprint (SHA-256): 1a2fc14ba3838343046b75a198c18f6083a4172ea938312861d2f114f6847824
We are here to help.
Startit Services LLC · Florida, United States.
11851 Southwest 179th Terrace, Miami, FL 33177, United States