Demo Environment Sample data only · No real emails or texts sent · Resets nightly
Legal

Data Processing Addendum

In plain terms: when OnlyHOA handles personal information in your Community, it does so on the Customer's behalf and under the Customer's instructions — as a service provider / processor, not as an owner of that data. This Addendum sets out how OnlyHOA protects that information and the limits on how it may be used, consistent with Nevada NRS 603A and the California Consumer Privacy Act as amended by the CPRA.

Effective August 26, 2026 · Last updated August 26, 2026
01

Scope, Roles & Incorporation

This Data Processing Addendum ("DPA") supplements and is incorporated into the Terms of Service and any subscription agreement, order form, or master services agreement between OnlyHOA LLC ("OnlyHOA," "Processor," "Service Provider") and the customer that subscribes to the OnlyHOA platform (the "Customer," "Controller," "Business"). It governs OnlyHOA's Processing of Personal Information contained in Customer Data when OnlyHOA provides the Platform.

Roles. As between the parties, the Customer is the controller / business that determines the purposes and means of Processing Customer Data, and OnlyHOA is the processor / service provider that Processes Personal Information only on the Customer's documented instructions and on its behalf. OnlyHOA does not sell or share Personal Information and does not process it for its own independent commercial purposes. Where the Customer is a management company acting for one or more associations, the Customer is responsible for its authority to instruct OnlyHOA with respect to each association's data.

02

Definitions

Capitalized terms not defined here have the meaning given in the Terms of Service or in applicable law. "Applicable Privacy Law" means Nevada Revised Statutes Chapter 603A and, to the extent it applies to a Customer's Processing, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act and its regulations ("CCPA/CPRA"), together with other U.S. state privacy laws that apply. "Personal Information" means information relating to an identified or identifiable individual that is Processed under this DPA. "Processing" means any operation performed on Personal Information. "Customer Data" has the meaning in the Terms of Service. "Subprocessor" means a third party engaged by OnlyHOA to Process Personal Information in providing the Platform. The terms business, service provider, contractor, sell, and share have the meanings given in the CCPA/CPRA.

03

Processing Details

The nature, purpose, and details of Processing are described in Annex A. In summary, OnlyHOA Processes Customer Data to provide, secure, support, and maintain the Platform for the Customer's Community, and for the limited additional purposes permitted by Section 5.

ElementDescription
Subject matterProvision of the OnlyHOA community-management software platform.
DurationThe term of the Customer's subscription, plus the return/deletion period in Section 10.
Nature & purposeHosting, storage, transmission, display, security, support, and configured features of the Platform, on the Customer's instructions.
Categories of individualsThe Customer's Authorized Users — e.g., board members, officers, community managers, staff, residents/homeowners, and vendors.
Categories of Personal InformationIdentifiers and contact details; account and role data; property/unit and community-membership data; communications and records the Customer places on the Platform; and, where the Customer enables payments, limited payment-related identifiers (see the Payment Terms — full card and bank-account numbers are handled by payment providers, not stored by OnlyHOA).
04

OnlyHOA's Obligations as Processor

  • Instruction-limited Processing. OnlyHOA Processes Personal Information only on the Customer's documented instructions, including as configured through the Platform, except where a law to which OnlyHOA is subject requires otherwise (in which case OnlyHOA will inform the Customer unless legally prohibited).
  • Confidentiality. OnlyHOA ensures that personnel authorized to Process Personal Information are bound by confidentiality obligations and access it only as needed to provide the Platform.
  • Security. OnlyHOA maintains the safeguards in Section 6.
  • Assistance. Taking into account the nature of the Processing, OnlyHOA assists the Customer, by appropriate technical and organizational measures, in responding to individual-rights requests and in meeting the Customer's security, breach-notification, and (where applicable) assessment obligations.
  • Notice of inability to comply. OnlyHOA will notify the Customer if it determines it can no longer meet its obligations under Applicable Privacy Law, and in that case the Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.
05

CCPA/CPRA Service-Provider & Contractor Restrictions

To the extent the CCPA/CPRA applies to a Customer's Processing, OnlyHOA acts as a service provider (or contractor) and certifies that it will:

  • Process Personal Information only for the specific business purpose(s) of providing the Platform as set out in this DPA and the Customer Agreement, and not for any other purpose;
  • Not sell and not share Personal Information within the meaning of the CCPA/CPRA;
  • Not retain, use, or disclose Personal Information outside the direct business relationship with the Customer, or for any commercial purpose other than the permitted business purpose(s), except as permitted by law;
  • Not combine Personal Information received from or on behalf of the Customer with Personal Information received from another source, except as the CCPA/CPRA permits a service provider or contractor to do;
  • Provide the same level of privacy protection as required of the Customer by the CCPA/CPRA;
  • Cooperate with and assist the Customer in responding to verifiable consumer requests to know, delete, correct, opt out, and limit the use of sensitive personal information;
  • Notify the Customer if OnlyHOA determines it can no longer meet its CCPA/CPRA obligations;
  • Grant the Customer the right to take reasonable and appropriate steps to help ensure that OnlyHOA uses Personal Information consistent with the Customer's CCPA/CPRA obligations, and to stop and remediate unauthorized use; and
  • Impose the restrictions in this Section on any Subprocessor by written contract, as described in Section 7.

Permitted uses. OnlyHOA may Process Personal Information to detect security incidents and protect against fraudulent, malicious, or illegal activity; to maintain and improve the quality and safety of the Platform; and to comply with law — each only to the extent permitted for a service provider or contractor under the CCPA/CPRA, and consistent with generating aggregated or de-identified data as described in the Terms of Service.

06

Security Safeguards (NRS 603A)

Consistent with Nevada NRS 603A and applicable law, OnlyHOA maintains reasonable administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, acquisition, destruction, use, modification, or disclosure, appropriate to the nature of the information. These safeguards include:

  • Encryption of Personal Information in transit and at rest, with keys managed under access controls;
  • Per-tenant data isolation, so a Community's data is scoped to that Community;
  • Role-based access controls and least-privilege access for personnel and Authorized Users;
  • Multi-factor authentication for privileged access, and strong, salted password hashing;
  • Tamper-evident audit logging of security-relevant actions;
  • Monitoring, logging, and incident-response processes; and
  • Periodic review of safeguards as risks and the Platform evolve.

The Customer is responsible for configuring its Community, assigning roles and permissions, and managing its Authorized Users' access appropriately.

07

Subprocessors

The Customer authorizes OnlyHOA to engage Subprocessors — including hosting, communications, payment, and analytics providers — to Process Personal Information in providing the Platform. OnlyHOA imposes on each Subprocessor data-protection and security obligations that are substantially the same as, and no less protective than, those in this DPA, and remains responsible for a Subprocessor's performance of those obligations. A current, itemized list of the categories and identities of Subprocessors is maintained on our Subprocessor List. OnlyHOA will provide a mechanism for the Customer to be informed of material changes to its Subprocessors and to object on reasonable data-protection grounds.

08

Individual-Rights Requests

If OnlyHOA receives a request from an individual to exercise rights under Applicable Privacy Law with respect to Customer Data (such as access, deletion, correction, or opt-out), OnlyHOA will, to the extent legally permitted, route the request to the relevant Customer rather than respond directly, because the Customer determines the purposes of Processing. OnlyHOA provides tools and reasonable assistance to help the Customer fulfill such requests within the timeframe required by Applicable Privacy Law. OnlyHOA also operates a designated intake at /legal/dsar and legal@onlyhoa.com for requests directed to OnlyHOA.

09

Security-Incident Notification

OnlyHOA will notify the affected Customer without undue delay after becoming aware of a breach of security affecting Personal Information Processed under this DPA, and will provide information reasonably available to it to help the Customer meet its own notification obligations under NRS 603A.220 and other applicable law. The Customer, as the party with the relationship to the affected individuals and regulators, is responsible for determining and making any legally required notifications, unless the parties agree otherwise in writing. OnlyHOA will take reasonable steps to mitigate and remediate the incident.

10

Return & Deletion of Customer Data

Upon expiration or termination of the Customer's subscription, and on the Customer's request, OnlyHOA will make Customer Data available for export for the transition period stated in the Customer Agreement (ordinarily at least thirty (30) days). After that period, OnlyHOA will delete or de-identify Customer Data in its production systems within a commercially reasonable time, except where retention is required by law or for OnlyHOA's exercise or defense of legal claims, in which case the data remains protected by this DPA until deleted. Residual copies in routine backups are deleted on OnlyHOA's ordinary backup cycle. The Customer is responsible for retaining its own copies of records it is legally required to keep, including association books and records.

11

Records, Audits & International Transfers

OnlyHOA maintains records of its Processing sufficient to demonstrate compliance with this DPA and will make available to the Customer information reasonably necessary to demonstrate that compliance, subject to confidentiality and the protection of other customers' data. The Platform is operated from the United States; Personal Information is Processed in the United States.

12

Precedence, Term & Contact

This DPA forms part of, and is subject to, the Customer Agreement and the Terms of Service. For the Processing of Personal Information, this DPA controls over a conflicting provision of the Terms of Service; a signed Customer Agreement controls over this DPA to the extent it expressly addresses the same subject. This DPA remains in effect for as long as OnlyHOA Processes Personal Information under the Customer Agreement.

Contact: OnlyHOA LLC · 732 S 6th St, Ste N, Las Vegas, NV 89101 · legal@onlyhoa.com.