Data Processing Addendum

Last updated July 26, 2026

This Data Processing Addendum (the “DPA”) governs how neighbors.fyi processes personal data on behalf of the community that subscribes to it. It forms part of the Terms of Service between Loomfield Labs, LLC and the Customer.

If you are a resident rather than a community administrator, the document that describes your personal data and your rights is the Privacy Policy. This page is the contract between us and your community.

1. Scope & how this binds

This DPA is entered into between Loomfield Labs, LLC, a Florida limited liability company doing business as neighbors.fyi (“neighbors.fyi”, “we”, “us”), and the community association, cooperative, management company, or other entity that subscribes to the Service (the “Customer”, “you”).

You do not need to sign or request this DPA. It becomes legally binding on the Customer upon acceptance of the Terms of Service, and it is incorporated into them by reference. A signature block is provided in Section 16 for customers whose internal records require a countersigned copy, but executing it is optional and adds no obligation that is not already in force.

Where this DPA conflicts with the Terms of Service or any other agreement between the parties, this DPA controls, but only as to the processing of Community Data. Everything else in the Terms of Service remains in effect.

2. Definitions

Terms not defined here have the meaning given in the Terms of Service or in applicable Data Protection Laws.

  • “Community Data” means personal data that you or your residents submit to, or generate within, your community on the Service. It includes resident names, email addresses, residential addresses and unit designations, profile content, messages and posts, request and violation records, documents you upload, and dues and assessment records.
  • “Account Data” means personal data relating to our commercial relationship with you: the names and contact details of the administrators authorized to manage the subscription, and billing contact information.
  • “Usage Data” means service telemetry we generate in operating the platform, including request logs, security and rate-limit logs, error reports, and aggregate feature-usage counts.
  • “Data Protection Laws” means all privacy and data protection laws applicable to a party’s processing under this DPA, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and U.S. state privacy laws including the California Consumer Privacy Act as amended (“CCPA”).
  • “Sub-processor” means a third party engaged by us that processes Community Data in order to provide the Service.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Community Data.

3. Roles of the parties

The parties occupy different roles depending on the data in question. Both are true at the same time.

  • Community Data: you are the controller, we are the processor. You decide who joins your community, what records your community keeps, how long you keep them, and what your community rules are. We process that data on your documented instructions. Under the CCPA we act as your service provider and not as a third party, and we do not sell or share Community Data.
  • Account Data and Usage Data: we are the controller. We determine the purposes of this processing, which are billing, account administration, security, abuse prevention, and maintaining and improving the Service. Our processing of that data is described in the Privacy Policy, not in this DPA.

Where a resident is also an individual to whom we owe direct obligations (for example, a request to exercise rights over their own account), we handle that request under the Privacy Policy and will keep you informed where the request affects your community records.

4. Details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I. That annex satisfies GDPR Art. 28(3) and forms part of this DPA.

5. Our instructions & your obligations

5.1 What counts as an instruction

We process Community Data only on your documented instructions. Your instructions consist of the Terms of Service, this DPA, your configuration of the Service (the settings, permissions, and features you enable), and any further written instruction you give us that is consistent with them. We will tell you if, in our opinion, an instruction infringes Data Protection Laws, and we may suspend performance of that instruction until it is resolved.

Where the Service applies fixed platform-level retention periods, for example to security logs and post-cancellation backups, those periods form part of the description of the Service rather than a choice you configure, and by subscribing you instruct us to apply them. They are published in the Privacy Policy and may change only with the notice described in Section 15.

We may also process Community Data where required by law that applies to us. In that case we will inform you before processing unless the law prohibits it.

5.2 What we will not do

We will not sell Community Data, share it for cross-context behavioral advertising, use it to build or train generalized machine-learning models, or use it for our own advertising or profiling purposes.

Where one of your administrators runs an AI feature, the specific content submitted to that feature is sent to our AI Sub-processor. Nothing is sent unless an administrator runs one of those tools; residents cannot invoke them. Under that Sub-processor’s commercial terms, content submitted through its API is not used to train its models; retention is limited to what is required to process the request and a trust-and-safety review window, and is governed by those terms. We send only the content the individual task requires, never a community’s full message history or directory, and every AI invocation is written to the community’s audit log.

5.3 Your responsibilities

You are responsible for the lawfulness of the Community Data you submit and of the instructions you give us. In particular you are responsible for having a lawful basis to invite residents and to record the information your community collects, for providing residents with any notice their jurisdiction requires, for configuring the Service in a way that matches your obligations, and for managing your administrators’ access. You are responsible for the accuracy of the roster you import.

6. Confidentiality

Access to Community Data is limited to personnel who require it to deliver, support, or secure the Service, and is granted on a least-privilege basis. Anyone we engage, whether employee or contractor, is bound by a written confidentiality obligation before being granted any access to Community Data, and that obligation survives the end of their engagement.

Staff access to a live community for support purposes is exercised through a support session that is recorded in the community’s audit log and notified by email to the primary or billing contact on file for the community. We can end a session at any time, and you can ask us to end one or to withhold support access. We do not currently offer a self-service control for you to terminate a session yourself.

Separately from support sessions, a small number of authorized personnel hold administrative database access that is not scoped to a single community. It is used only for incident response, recovery from system failure, debugging, and compliance with legal process; it is restricted to personnel with a need to know; every use is logged; and it is subject to the same written confidentiality obligations. It is not used to browse Community Data, and it is not a route by which one community can reach another’s.

7. Security measures

We implement and maintain appropriate technical and organizational measures designed to protect Community Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the risks presented by the processing. Those measures are described in Annex II.

We may update the measures in Annex II over time provided the updates do not materially reduce the overall level of security.

8. Sub-processors

8.1 Authorization

You give us general written authorization to engage Sub-processors to process Community Data. The Sub-processors engaged as of the date of this DPA are listed in Annex III. That Annex separately lists services that receive personal data as independent controllers rather than on our instructions. Those are not Sub-processors, this Section does not apply to them, and Annex III says which is which.

8.2 Our obligations toward them

We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, by written contract. We remain fully liable to you for the performance of each Sub-processor’s obligations.

8.3 Notice of change and your right to object

We will give you at least thirty (30) days’ notice before adding or replacing a Sub-processor, sent to the administrative contact for your community, so that you have time to object. If you reasonably object on data protection grounds, we will work with you in good faith to provide an alternative. If we cannot offer one within a reasonable period, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees for the terminated period.

9. Data subject requests

The Service gives your administrators the ability to access, correct, export, and delete Community Data directly, which will resolve most requests without our involvement.

Where a data subject contacts us directly with a request that concerns your community records, we will not respond substantively on your behalf. We will inform you without undue delay and will provide reasonable assistance, at no additional charge, to help you respond within the statutory period. Our internal handling of these requests follows a documented procedure.

9.1 Standing instruction for account-level deletion

You instruct us, as a term of this DPA, to carry out account-level deletion and author-anonymization when a resident exercises a deletion right over data we control: their account credentials, profile, contact details, address link, and profile image, and the anonymization of authorship on content they posted. That instruction is what lets us honour the commitments made to residents in the Privacy Policy without waiting on you each time.

It does not extend to your community’s official records: roster entries you are legally required to keep, financial and assessment records, and violation, architectural, and board records. Those remain yours to decide, and we route requests touching them to you under Section 9 above.

10. Personal data breaches

We will notify you of a Personal Data Breach affecting Community Data without undue delay after becoming aware of it, and in any event within seventy-two (72) hours of confirming that your community is affected.

Our notice will include, to the extent known at the time and updated as our investigation progresses:

  • the nature of the breach, including the categories and approximate number of data subjects and records affected;
  • the likely consequences of the breach;
  • the measures we have taken or propose to take to address it and to mitigate its effects; and
  • a contact point for further information.

We will provide reasonable assistance with your own notification obligations to supervisory authorities, attorneys general, and affected individuals. Our notice is not an acknowledgement of fault or liability.

11. Return & deletion

You may export your community’s data at any time during the term through the Service.

On termination or expiry there is a 14-day reactivation window during which your community remains restorable. After it closes, we take a backup of your community and then delete the live database entirely. The backup exists for one purpose: so that a community that comes back can be restored rather than rebuilt from nothing. It is held in encrypted storage, accessible only to us, and is permanently deleted twelve (12) months after archival.

You can shorten that. On written request to privacy@neighbors.fyi we will purge the backup immediately rather than waiting out the twelve months. Requesting it forfeits the ability to reactivate.

Two exceptions survive deletion. Records we are required to keep for tax, accounting, or fraud-prevention purposes, principally payment and assessment transaction records, are retained in a form from which resident names have been removed. And Community Data may persist briefly in our infrastructure provider’s routine backups, which are overwritten on their normal rotation cycle (see the Privacy Policy for those windows); it remains subject to this DPA until overwritten.

12. Audits & information

On request, we will make available the information reasonably necessary to demonstrate our compliance with this DPA, and will respond to reasonable security questionnaires, at no charge and no more than once per twelve-month period unless a Personal Data Breach or a regulator requires otherwise.

Where that information is not sufficient for your purposes, you may conduct an audit on at least thirty (30) days’ written notice, no more than once per twelve-month period, during business hours, without unreasonably disrupting our operations, and subject to confidentiality obligations. You bear the cost of the audit unless it reveals a material breach of this DPA by us.

13. International transfers

We operate in the United States and store Community Data in the United States. We do not currently offer the Service to customers established in the European Economic Area, the United Kingdom, or Switzerland.

If and to the extent Data Protection Laws of those jurisdictions apply to processing under this DPA, the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 are incorporated into this DPA by reference, with Module Two (controller to processor) applying, with you as data exporter and us as data importer. For those clauses: the optional docking clause applies; the supervisory authority is that of your place of establishment; Clause 9 operates under Option 2 (general written authorization) with the notice period in Section 8.3 above; Clause 17 is governed by the law of Ireland; Clause 18(b) designates the courts of Ireland; and Annex I, Annex II, and Annex III of this DPA populate the corresponding annexes of those clauses. Where the UK GDPR applies, the UK International Data Transfer Addendum applies to those clauses.

14. U.S. state privacy laws

Where the CCPA applies, we act as a service provider. We are prohibited from, and will not, sell or share Community Data, retain, use, or disclose it for any purpose other than performing the Service specified in the Terms of Service, retain, use, or disclose it outside the direct business relationship between us, or combine it with personal data received from another source except as the CCPA permits a service provider to do. We will notify you if we determine we can no longer meet these obligations. We grant you the right to take reasonable steps to stop and remediate unauthorized use.

Equivalent commitments apply where the Virginia, Colorado, Connecticut, Texas, Florida, or other U.S. state privacy statutes govern the processing, and we will act as a processor as those statutes define the term.

15. Liability & term

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA takes effect when you accept the Terms of Service and continues for as long as we process Community Data on your behalf. Sections that by their nature should survive termination will do so.

We may update this DPA to reflect changes in the Service, our Sub-processors, or applicable law. We will post the updated version at this URL with a new “Last updated” date and, where the change materially reduces your rights or our obligations, give you advance notice as described in the Terms of Service.

Notices under this DPA, including an objection under Section 8.3 and a request for a countersigned copy, may be sent to privacy@neighbors.fyi. Formal legal notices under the Terms of Service go to legal@neighbors.fyi as provided there.

16. Signature

The signature block below is provided for reference purposes only. This DPA becomes legally binding upon your acceptance of the Terms of Service, as stated in Section 1. If your records require a countersigned copy, you may complete this block and send it to privacy@neighbors.fyi, and we will return a copy executed on our side.

Signature block (reference only)
CustomerLoomfield Labs, LLC
By:By:
Name:Name: Patrick Burgart
Title:Title: Sole Member
Date:Date:

Annex I. Processing details

A. The parties

Data exporter (controller): the Customer, being the community association, cooperative, management company, or other entity that subscribes to the Service. Contact details are those held in the Customer’s account. Activities relevant to the transfer: administering a residential community.

Data importer (processor): Loomfield Labs, LLC d/b/a neighbors.fyi, 7901 4th St N, STE 300, St. Petersburg, FL 33702, USA. Contact: privacy@neighbors.fyi. Activities relevant to the transfer: providing a hosted residents-only community portal.

B. Description of processing

Subject matterProvision of the neighbors.fyi community portal to the Customer.
DurationThe term of the Terms of Service, plus the deletion period in Section 11.
Nature & purposeHosting, storage, transmission, display, backup, search, notification, and deletion of Community Data in order to operate the Customer’s community portal and the features the Customer enables.
Categories of data subjectsResidents and their household members, property owners (including non-resident owners), community board members and administrators, community staff and managers, and vendors or contractors the Customer records.
Categories of personal dataIdentity and contact data (name, email address, profile photo, and a telephone number where a resident chooses to provide one on a marketplace listing); residential address and unit designation; account and authentication data (hashed password, authentication events, role and permission assignments); user-generated content (messages, posts, comments, photographs, documents, requests, violation and architectural records, poll and vote records where not anonymous); financial records relating to dues, assessments, and fees, excluding card and bank details, which are held by our payment Sub-processor and never reach our systems.
Special category dataNone requested or required. The Service provides no field for special category data and the Customer is instructed not to submit it.
FrequencyContinuous, for the duration of the agreement.
RetentionFor the term; then a 14-day reactivation window, then live-database deletion, then backup deletion at 12 months (Section 11). Detailed per-record retention is published in the Privacy Policy.

Annex II. Security measures

The following measures are in place. They are described at a level that is meaningful without disclosing detail that would itself create risk.

  • Tenant isolation. Each community is provisioned into its own separate database, rather than sharing tables with other communities. A defect in tenant-scoping logic therefore cannot expose one community’s resident records to another. A separate central database holds account-administration data (your billing and primary contact details, plan and household counts, support tickets and their messages, platform audit entries, and encrypted archival backups). It is reachable only with service-role credentials, is scoped in application code, and is denied to all client roles by policy.
  • Access control within a community. Row Level Security is enforced at the database layer, so a request must carry an authenticated session for the correct community before any record is read. Administrative capability is further divided into scoped, per-module permissions rather than a single administrator flag.
  • Encryption. All connections use HTTPS. Data at rest is encrypted by our infrastructure provider. Long-lived credentials we hold on a community’s behalf are additionally wrapped with application-level envelope encryption before storage.
  • Payment data. Card and bank account details are collected and stored by our PCI-compliant payment Sub-processor and never traverse or persist in our systems.
  • Staff authentication. Multi-factor enrollment is mandatory for all personnel with access to the operations console: it is enforced at the application layer, and an account with no verified authenticator cannot reach any console surface. Every sensitive administrative action additionally requires a fresh step-up multi-factor challenge, and that check fails closed.
  • Accountability. Administrative actions within a community are written to a community-visible audit log with the actor’s identity and a timestamp. Successful sign-ins are logged. Password resets and email changes are logged by our authentication Sub-processor.
  • Support access. Staff access to a live community for support is exercised through a support session that is recorded in the community’s audit log and notified by email to the community’s primary or billing contact. The session is banner-flagged in the interface for the staff member operating it.
  • Abuse resistance. Unauthenticated and cost-bearing endpoints are rate-limited. Security headers, including a content security policy, are applied at the edge.
  • Resilience. Production databases are backed up daily by our infrastructure provider and those backups are retained for seven days.
  • Secure development. Every change runs through automated linting, type checking, and an automated test suite in continuous integration before release, and dependencies are monitored for known vulnerabilities with automated update pull requests.
  • Vulnerability reporting. We publish a coordinated disclosure policy at /security-policy and a machine-readable contact at /.well-known/security.txt.

We do not currently hold a SOC 2 or ISO 27001 certification, and we say so plainly rather than implying otherwise. If your procurement process requires one, contact us before subscribing so that expectations are set correctly.

Annex III. Sub-processors and other recipients

The following Sub-processors process Community Data on our instructions, under a written contract that incorporates data-protection terms no less protective than this DPA. Changes are governed by Section 8.3. The categories each one receives are limited to what the corresponding feature requires.

Sub-processorPurposeData received
Supabase, Inc.Database, authentication, and file storageAll Community Data
Vercel, Inc.Application hosting, edge delivery, and page-view / performance analyticsCommunity Data in transit; request logs; cookieless page-view and Web Vitals events
Stripe, Inc.Dues, assessment, and fee processingPayer name, email, amounts; card and bank details held solely by Stripe
Plus Five Five, Inc. (Resend)Transactional and community email deliveryRecipient name and email address; message content
Anthropic, PBCAI features, only when an administrator runs oneThe specific content submitted to the feature, plus an opaque account identifier for the invoking user (abuse attribution and erasure requests). Not used for model training under their terms (§5.2)
Google LLC (Google Workspace)Google Meet space creation and meeting-transcript retrieval, only where the Customer connects itMeeting transcripts, including attendee names and speech. Governed by the Google Cloud Data Processing Addendum, under which Google is a processor
Functional Software, Inc. (Sentry)Application error monitoringError and stack-trace data, tagged with the account identifier, role, and community of the affected user. Request bodies, cookies, and headers are scrubbed before transmission

Independent controllers (not Sub-processors)

The services below also receive personal data when the corresponding feature is used, but they do not process it on our instructions. Each acts as an independent controller under its own privacy policy and determines its own purposes, so we do not warrant their processing under this DPA and Section 8.3 does not apply to them. We disclose them because the Customer needs a complete picture of where data goes, and because the Customer’s own privacy notice to residents may need to account for them.

RecipientPurposeData received
Google LLC (Google Maps APIs)Map rendering; address geocoding and address autocompleteProperty and resident-entered street addresses submitted for geocoding or autocomplete; map coordinates for display. Google classifies its Maps APIs as a controller service and governs them by its Controller-Controller Data Protection Terms
KIKLIKO, Inc. (Klipy)GIF search and delivery in chatThe searching resident’s query and IP address; the IP address of any resident who later views a posted GIF, which is delivered from Klipy rather than from us. Klipy publishes no data-processing terms
jsDelivrContent delivery for the emoji image setIP address and user agent of the requesting browser. No Community Data
Apple, Google, Mozilla push servicesDelivery of web push notifications, only for residents who enable themPush endpoint and delivery metadata. Payload contents are encrypted end to end and are not readable by the push service

Questions about this DPA, and requests for a countersigned copy, go to privacy@neighbors.fyi, or by mail to neighbors.fyi, 7901 4th St N, STE 300, St. Petersburg, FL 33702, USA.