Back to the legal center

Your information

Data processing

Responsibilities between customers and AlquilaOS for rental-management data.

Effective September 8, 2026 · Revision 3

01Scope and instructions

This addendum forms part of the agreement with J.R.SOSA & CO. LLC, 2125 Biscayne Blvd, Ste 204 #24427, Miami, Florida 33137 US, and supplements the Terms of service when we process personal data for a business customer. The customer is a controller, or acts for an authorized controller, and AlquilaOS is a processor for that processing. It does not cover information we process as an independent controller for our billing, security, or compliance.

The purpose is to provide supported property, rental-relationship, document, maintenance, communication, and payment management functions. Processing may include collection, recording, organization, storage, access, authorized transmission, backup, and deletion during the contractual relationship and applicable retention periods. Instructions consist of this agreement, authorized configuration, and written requests consistent with the service.

02Data and individuals covered

Individuals may include customer users, owners, tenants, contacts, and vendors. Data may include identifiers, contact information, addresses, units, lease terms and dates, documents, photos, maintenance requests, communication records, and limited transaction information.

The customer decides which documents to provide and must avoid unnecessary sensitive information. Full card numbers, security codes, complete medical records, and other categories unrelated to the service are not authorized. If a use requires additional legal safeguards, the parties must agree to them before that processing.

03Responsibilities of the parties

The customer provides required notices and has valid legal bases, permissions, and instructions; verifies accuracy, minimization, and recipients; and determines lawful retention requirements. AlquilaOS processes data under documented instructions unless legally required otherwise, restricts access to authorized persons under confidentiality duties, and does not use the data for incompatible independent purposes.

If an instruction appears to violate applicable law, we will inform you unless prohibited and may suspend that instruction while it is clarified. We will disclose legal disclosure requirements where permitted. Each party remains responsible for its applicable compliance duties; this addendum does not transfer duties exclusive to the customer.

04Security, incidents, and assistance

We will maintain technical and organizational measures appropriate to risk, including access controls and logical account separation, protected communications, and operational records consistent with the service architecture. No measure removes every risk. The customer must protect its users, email, devices, and exported copies.

We will notify the customer without undue delay after becoming aware of a personal-data breach under this addendum and provide available information needed to assess and meet obligations. Information may be supplied in stages. We will reasonably assist with rights requests, impact assessments, and authority consultations, considering the processing and available information. This does not override stricter notices or deadlines required by law.

05Subprocessors and transfers

The customer authorizes providers identified in Subprocessors for the listed services. We will impose protections appropriate to the processing and remain responsible for their performance to the extent required by law and this agreement. Stripe may also act independently under its own agreements.

Before adding a subprocessor that materially changes processing, we will publish the update and give reasonable notice to affected customers. Customers may object on substantiated data-protection grounds, and we will work to resolve the objection or allow termination of the affected function. If an international transfer requires specific clauses or another mechanism, the necessary safeguards must be documented and in effect before transfer.

06Compliance information and termination

On reasonable request, we will provide information sufficient to demonstrate compliance with applicable obligations. Reviews must protect trade secrets, security, and others’ data. If law requires an additional audit, we will coordinate proportionate scope, notice, and access; nothing limits authorities’ statutory powers. We may agree on reasonable charges for extraordinary assistance where lawful, without charging to remedy our own breach.

At termination, we will follow lawful instructions to return or delete data through available functions or support, except for legally required retention. Backups expire through their lifecycle and remain protected while retained. Confidentiality and protection obligations continue while we retain data. Coordinate requests through soporte@alquilaos.com.