Proposed agreement · Not yet in effect
Status & application
This is a draft for the future ListingGTM customer service. It is not yet an executed agreement and does not authorize uploading CRM contacts or running campaigns. Before it applies, a service agreement must identify the customer and the ListingGTM operating legal entity, attach a completed processing schedule, identify approved subprocessors, and establish any required transfer safeguards. The website waitlist is covered by the Privacy Notice instead.
1. Roles & instructions
For personal data that a customer provides for ListingGTM to process on that customer’s behalf, the customer acts as controller and the identified ListingGTM provider acts as processor, unless applicable law establishes another role. The provider processes that data only on documented lawful instructions, including the service agreement and authorized workspace settings, except where required by law. Where permitted, the provider informs the customer of such a legal requirement before processing.
Provider-sourced data and independently determined processing require a separate role assessment. This addendum must not be used to label all prospect sourcing as processing on a customer’s behalf. The provider will inform the customer if an instruction appears to infringe applicable data-protection law.
2. Confidentiality & access
The provider limits access to authorized personnel who need it for the services, binds those personnel to confidentiality obligations, and maintains appropriate access controls. Those obligations continue after access ends.
3. Security
The provider implements technical and organizational measures appropriate to the nature, scope, context, and risks of the agreed processing. The executed security schedule will describe access management, isolation, encryption in transit, provider storage protections, logging, incident response, backup arrangements, and deletion procedures. Measures may evolve without materially reducing the agreed protection.
4. Subprocessors
The customer grants general written authorization only for subprocessors identified in the executed provider list. The provider gives at least 30 days’ prior notice of a proposed addition or replacement and an opportunity to object on reasonable data-protection grounds. The parties will work in good faith on an alternative; if none is reasonably available, the customer may stop the affected processing and terminate the affected service under the service agreement. Subprocessors must be bound to equivalent applicable obligations, and the provider remains responsible for their performance of those obligations.
5. Assistance
Taking account of the processing and information available, the provider will reasonably assist with individual-rights requests, security obligations, breach assessment and notices, data-protection impact assessments, and required regulator consultation. The provider will forward requests relating to customer data rather than independently deciding their outcome, unless required by law.
6. Personal data incidents
The provider will notify the customer without undue delay after becoming aware of a personal data breach affecting customer data. Notices will include the available nature and scope of the breach, affected categories and approximate volumes where known, likely consequences, mitigation, and a contact for follow-up. Missing information may be provided in phases. The parties will cooperate in investigation and containment. Notification is not an admission of liability.
7. Return & deletion
At the end of the affected services, the provider will, at the customer’s choice, return or delete customer personal data and delete existing copies unless law requires retention. The executed service schedule must state export availability, deletion timing, and backup expiration periods. Retained data remains protected and may be processed only for the permitted retention purpose.
8. Demonstrating compliance
The provider will make information reasonably necessary to demonstrate compliance available to the customer and permit appropriate audits or inspections by the customer or its mandated auditor. Reasonable confidentiality, security, and scheduling arrangements apply without preventing legally required oversight. The service agreement will address reasonable audit costs without limiting mandatory rights.
9. International transfers
Restricted transfers may take place only when the required legal mechanism and supplementary measures are in place. The parties must complete the applicable EU standard contractual clauses, UK addendum or other valid mechanism where required; this draft does not claim that those instruments have already been executed.
Schedule A — Processing description
- Subject matter & duration
- Customer-authorized real estate workflows for the term of the service and the documented return/deletion period.
- Nature & purpose
- Storage, organization, enrichment where authorized, message preparation, permitted outreach coordination, appointment handling, and reporting, limited to purchased and enabled features.
- Data subjects
- Customer personnel and their authorized prospects, sellers, buyers, buyer agents, and business contacts.
- Data categories
- Business contact details, customer-provided preferences, property and transaction context, communications, scheduling details, and consent or suppression records as applicable.
- Excluded data
- Do not upload payment-card details, government identifiers, health information, or other sensitive categories unless an expressly agreed workflow lawfully requires them and appropriate safeguards are in place.
- Customer responsibilities
- Lawful instructions, required notices and permissions, appropriate contact selection, and honoring individual rights.
Schedule B — Required before activation
Identify the contracting entities, privacy and incident contacts, hosting regions, actual subprocessors, applicable laws, transfer instruments, security commitments, and exact export/deletion/backup timelines. Review and finalize this addendum with qualified counsel before processing customer data under it.