Skip to content

Legal

Data Processing Addendum

Effective September 30, 2026 Operated by Frontier Global Technologies, Inc.

This Data Processing Addendum ("DPA") forms part of the Alto Inspect Terms of Service and is incorporated into them when the Customer accepts them. It governs the personal data that Frontier Global Technologies, Inc. ("FGT") processes on the Customer's behalf. Capitalised terms not defined here have the meaning given in the Terms.

1. Parties and roles

  • The Customer is the controller (responsable) of Customer Data: it decides how and why it is processed.
  • FGT is the processor (encargado): it processes Customer Data on the Customer's behalf, only to provide the Service.

2. Subject matter, duration, nature and purpose

  • Subject matter: providing the Alto Inspect Service — property records, move-in and move-out inspections, photos, signatures, tenant self-inspection links and PDF reports.
  • Duration: while the Customer uses the Service and until Customer Data is deleted under section 9.
  • Nature: hosting, storage, synchronisation, retrieval, report generation, sending to the recipients the Customer chooses, and deletion.
  • Purpose: to provide, secure and support the Service in line with the Customer's instructions.

3. Data and data subjects

  • Data subjects: tenants, landlords and owners, inspectors and other Customer users, and anyone who appears in photos or reports.
  • Data: names, email addresses, property addresses, photos, images of handwritten signatures, inspection grades and comments, and the IP address and browser used when signing or submitting a tenant link.
  • Sensitive data: the Service is not designed to collect it, but it may appear incidentally in photos or content the Customer uploads. FGT processes it only on the Customer's instructions.

4. FGT's obligations

FGT will:

  • process Customer Data only on the Customer's documented instructions, as set out in the Terms, this DPA and the Customer's use of the Service, and tell the Customer if it believes an instruction breaks the law;
  • not process Customer Data for its own purposes or any purpose other than those instructed, including its own marketing or training machine-learning models;
  • maintain appropriate administrative, technical and physical security measures to protect Customer Data;
  • keep Customer Data confidential and ensure that everyone authorised to process it is bound by confidentiality;
  • help the Customer, as far as reasonable, to answer ARCO and consent-revocation requests, and pass on without delay any such request it receives directly;
  • notify the Customer without undue delay of any security breach affecting Customer Data, with the information available to help the Customer meet its own obligations;
  • not transfer Customer Data except to subprocessors authorised under section 5, or where the law requires it at the request of a competent authority;
  • delete or return Customer Data when the Service ends, as set out in section 9.

5. Subprocessors

  • The Customer gives FGT general written authorisation to use the subprocessors on its subprocessor list.
  • FGT will impose on each subprocessor, by contract, data-protection obligations equivalent to those in this DPA, and remains responsible to the Customer for their performance.
  • FGT will tell the Customer by email at least 15 days before a new subprocessor starts processing Customer Data. If the Customer objects on reasonable data-protection grounds and FGT cannot address the objection, the Customer may terminate the affected Service without penalty.

6. International transfers

Customer Data may be processed outside Mexico, including in the United States, by FGT or its subprocessors. FGT will ensure that it receives the same protection as this DPA requires.

7. The Customer's obligations

The Customer will:

  • have a lawful basis for the processing and give data subjects its own privacy notice before their data is collected;
  • obtain any consent the law requires, including express consent for sensitive data where applicable;
  • give lawful instructions and make sure the data it enters is accurate and necessary.

8. Information and audits

On reasonable request, FGT will give the Customer the information needed to show compliance with this DPA. Any further audit or review will be agreed in writing, with reasonable prior notice, and at the Customer's cost unless it reveals a material breach.

9. Deletion and return at the end of the Service

When the Service ends, the Customer has 30 days to export its Customer Data or ask for it to be returned. After that, FGT will delete it from its live systems, except for copies it must keep by law, which will be restricted. Copies in backups are deleted through normal rotation within 35 days. If a team owner deletes a team while the Service continues, the same rule applies to that team's data.

10. Governing law and precedence

This DPA is governed by the same law and courts as the Terms. If this DPA and the Terms conflict on the processing of Customer Data, this DPA prevails.

Contact

Frontier Global Technologies, Inc.
PO Box 450948, Laredo, Texas 78045, United States
Privacy: [email protected]
Legal notices: [email protected]

← Back to Alto Inspect