1. What Is a Data Processing Agreement?
A Data Processing Agreement — or "DPA" — describes how a software provider processes customer information on behalf of its customers. Many organizations require one before adopting a new tool, particularly when regulated data or client information is involved.
Our Commitment
Most individual REI Compass™ users do not need to execute this agreement. This page is primarily intended for brokerages, investment firms, real estate teams, organizations, and enterprise customers.
2. Our Role
When REI Compass™ processes information on behalf of a business customer:
- The Business Customer acts as the Data Controller — the party that decides what information is uploaded and why.
- REI Compass™ acts as the Data Processor — processing that information only to deliver the services the customer has requested.
Customers decide what information they upload. REI Compass™ processes that information only to provide the services the customer has chosen to use, in accordance with the Terms of Service.
3. Information We Process
Depending on how the customer uses the platform, information processed on the customer's behalf may include:
- Account information (e.g. name, email, authentication data)
- Investment workspaces created inside the platform
- Property analysis, calculations, and modeling data
- Reports generated by the customer
- Journals and journal entries
- Notes attached to properties, deals, or contacts
- Power Team contacts
- AI prompts submitted by the customer
4. How We Protect Data
REI Compass™ maintains a layered set of technical and organizational safeguards designed to protect customer information, including:
- Encrypted connections (HTTPS/TLS) for data in transit
- Secure authentication with modern session management
- Password hashing using industry-standard algorithms
- Multi-factor authentication (MFA) support
- Row Level Security (RLS) enforced at the database layer
- Audit logging of sensitive administrative actions
- Reputable, secure cloud infrastructure
A more detailed description of our security posture is available on the Security & Trust page.
5. Trusted Service Providers
REI Compass™ uses a small number of carefully selected subprocessors to operate the platform — for example, to host the database, authenticate users, and power AI-assisted features. Each provider receives only the information necessary to perform its service.
The current list, along with each provider's purpose, is maintained on the Subprocessors page and is updated when a significant provider is added, replaced, or removed.
6. Customer Responsibilities
As the Data Controller, the customer remains responsible for:
- Obtaining any permissions or consents required to upload information to the platform
- Complying with all privacy and data protection laws applicable to the customer
- Ensuring they have the authority to upload information about third parties, including clients, partners, and other individuals
- Responding to data subject requests (such as access, correction, or deletion) where applicable
7. Requesting a Signed DPA
Requests can be sent to support@reicompass.com. Please include your organization name, the number of users involved, and any specific documentation or clauses your team requires.
9. Contact
For questions about this page, or to request a signed DPA for your organization, reach out using the contact information below.
Contact
Questions about this policy?
If you have questions about this policy or how REI Compass™ handles your information, please contact us.
Response Time
Typically within 2 business days
Revision Log
Version History
Version 1.0
Published July 2026
Initial publication.
