Privacy Policy & Data Processing Addendum
Last Updated: August 24th, 2026
This Privacy Policy and Data Processing Addendum (collectively, the "Policy") describes how PromotePlus.ai ("Company," "we," "us," or "our") collects, uses, processes, stores, discloses, transfers, and otherwise handles personal information and other data in connection with the Services.
This Policy is incorporated into and subject to the Terms of Use.
If you connect a Google account, Section 6 (Google User Data and Limited Use) explains how we handle the data we access through Google APIs, and it overrides anything else in this Policy that conflicts with it.
BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE AND AGREE TO THIS POLICY.
1. SCOPE; ROLES; RELATIONSHIP OF THE PARTIES
PromotePlus is software you use to run your real estate business: IDX websites, a CRM, marketing automation, AI-generated content, ad campaign management, SMS and mobile messaging, analytics, and connections to other platforms. We call all of that "the Services".
1.1 What the Services are for
- You use the Services for your own business: managing and marketing to your leads, clients, and contacts.
- We connect the Services to other platforms, such as IDX and MLS feeds, AI tools, ad networks, analytics providers, CRMs, and SMS providers. Those connections are a convenience. They do not change your rights or ours under this Policy.
- We may add, change, or remove features and integrations. We will not take away the core functionality you are paying for, unless the law requires it.
1.2 Who does what
Our job. We build, run, and maintain the Services: the infrastructure, the security, support, updates, and any optional integrations. We collect and process your data only as far as we need to in order to run the Services, in line with this Policy and the law. We do not control how you use the Services, including what you write, the campaigns you run, your IDX feeds, the AI output you choose to publish, or how you deal with other platforms.
Your job. Everything you put into the Services is yours to stand behind: whether it is accurate, whether it is legal, and how you use it. You need to follow the laws that apply to you, including privacy, advertising, telecom, and intellectual property law. You also need to get the consents and give the notices required before you process anyone's data through the Services.
1.3 We are separate businesses
This Policy does not make us partners, a joint venture, an agency, or an employer and employee. Neither of us can commit the other to anything, and neither of us is responsible for what the other does, except where this Policy says otherwise.
1.4 Who carries the risk
You take on the risk of how you use the Services, including anything that happens through integrations, AI output, IDX feeds, the CRM, ad campaigns, SMS, or marketing automation. We are not liable for:
- loss, damage, mishandling, unauthorized access to, or misuse of your data;
- your failure to follow a law, regulation, or contract;
- what third-party providers do, fail to do, or produce.
1.5 This section outlasts the contract
These terms keep applying after the Services end, to all data and obligations that came up while you were using them.
2. CATEGORIES OF DATA
Running the Services means we handle a range of data: personal information, sensitive information, usage data, technical metadata, and anything else you or your end users put in or that the Services generate. We call all of it "your data". It reaches us directly from you, from how you use the Services, through integrations, or automatically through things like AI content, analytics, IDX and MLS feeds, ad platforms, CRM workflows, and SMS.
2.1 Personal information
Anything that identifies someone, or could be used to find or contact them:
- names, usernames, and aliases;
- email addresses, phone numbers, and mailing addresses;
- account credentials and login identifiers;
- property preferences, search history, and lead or client details from IDX and MLS feeds, CRM forms, or your website;
- demographic details such as age, gender, or location;
- billing and payment details;
- anything else you or your end users provide.
2.2 Sensitive data
Where it applies, this can include:
- location data or coordinates;
- audio, video, or images submitted for AI processing or IDX display;
- the content of messages, including SMS, chat, and email;
- behavior, preference, and usage data used for personalized marketing, analytics, or AI recommendations.
You are responsible for making sure any sensitive data you put through the Services was collected lawfully and is being used lawfully, under GDPR, UK GDPR, CCPA and CPRA, and any other rules that apply to you.
2.3 Technical and usage data
- IP addresses, browser types, device identifiers, and operating systems;
- interaction logs, clickstream data, page views, searches, and feature usage;
- cookies, web beacons, pixels, SDK data, and other tracking;
- analytics, diagnostics, and error reports from the Services or the platforms they connect to;
- metadata attached to messages, uploads, or AI output.
2.4 Data from integrations
The Services connect to outside platforms: IDX and MLS systems, ad networks, AI services, CRM tools, analytics providers, SMS platforms, and cloud services. Your data may travel to, be processed by, or be stored with those providers. You are responsible for the legal side of those connections, and we are not liable for how those companies handle your data.
2.5 Aggregated and derived data
The Services may produce aggregated, anonymized, or derived data for purposes such as improving the product, analytics, benchmarking, reporting, AI training, and marketing optimization. That data does not identify anyone, and we may use it as we see fit within the law.
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
2.6 What you are responsible for
You decide what data goes into the Services, and you are responsible for making sure that collecting, processing, sending, and storing it is lawful. That includes getting consent from your end users and leads, and putting proper safeguards around sensitive and personal data.
2.7 After you leave
These responsibilities continue after the Services end, and keep applying to all data handled while you were using them.
3. PURPOSES OF PROCESSING
Here is what we do with your data, and why. This covers personal information, sensitive information, technical metadata, behavior data, and aggregated or derived data. Everything below is done in line with this Policy, our agreements with you, and the privacy laws that apply, including GDPR, UK GDPR, CCPA and CPRA, VCDPA, CDPA, and CTDPA.
3.1 To run the Services
- deliver everything the Services do: IDX websites, the CRM, marketing automation, AI content, ad campaign management, SMS and mobile messaging, analytics, and integrations;
- sign you in and control access to accounts and admin functions;
- let people work together inside the Services;
- monitor, troubleshoot, and keep the system running and performing.
3.2 To support you
- answer your questions, requests, complaints, and support tickets;
- help you use the Services;
- find and fix errors, outages, and security problems;
- run maintenance, updates, patches, and upgrades.
3.3 For marketing and communication
- send SMS, email, push notifications, and other messages, including account updates, transactional notices, alerts, reminders, and promotional content;
- run marketing campaigns across social media, search advertising, email, and other channels;
- measure engagement, performance, and response rates so we can improve marketing content and delivery;
- personalize experiences, content, recommendations, and offers using AI analytics and other automated systems.
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
3.4 For legal and risk reasons
- follow the laws, regulations, standards, and contracts that apply to us;
- detect, prevent, and investigate fraud, misuse, unauthorized access, and illegal activity;
- handle risk, audits, and reporting duties;
- protect the rights, property, and security of us, you, and end users.
3.5 For analytics and improving the product
- analytics, benchmarking, reporting, and business intelligence to improve the Services;
- aggregated and anonymized data for operational insight, AI training, and marketing optimization;
- testing and improving algorithms, AI models, features, and performance;
- deciding what to build next.
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
3.6 Through integrations
Your data may be processed through integrations with IDX and MLS platforms, CRM vendors, AI providers, ad networks, analytics platforms, SMS providers, cloud services, and other tools we need in order to run, maintain, or improve the Services. We are not liable for how those companies handle it.
4. NO SALE OF PERSONAL INFORMATION; LIMITED DISCLOSURE; THIRD-PARTY PROCESSING DISCLAIMER
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
We do not sell or rent personal information, and we do not hand it to other companies for them to exploit commercially on their own. We do not sell personal information as that word is defined under the California Consumer Privacy Act (CCPA) or the California Privacy Rights Act (CPRA). Some of the data sharing we do to run the Services could fall inside those laws' broad definitions of "sale" or "sharing". Where it does, it is only ever to operate, improve, and deliver the Services, never for another company's independent use.
We do pass personal information and other data to third parties where it is needed to run, support, improve, and secure the Services, or to carry out something you asked for, such as marketing campaigns, ad placements, CRM functionality, data sync, and API integrations. Those third parties include service providers, subprocessors, integration partners, advertising platforms, multiple listing services, IDX data providers, analytics providers, infrastructure providers, and communication vendors such as SMS and email delivery services.
Once data reaches a third-party platform, whether you sent it there or it is simply part of how the Services work, that company may collect, use, process, store, and combine it under its own terms and policies. We do not control or monitor what they do with it, and we are not responsible for their security, retention, or compliance.
To the fullest extent the law allows, we are not liable for what third parties do or fail to do, including unauthorized access, a data breach, misuse, resale, re-identification, aggregation, retention, or any other processing on their side, whether it happens in transit or after the data arrives. You take on the risk of using third-party services, integrations, and platforms, including ad platforms, CRM integrations, IDX providers, and communication vendors.
It is up to you to read and follow the terms, privacy policies, and data practices of every third-party service you choose to connect to or interact with through the Services, and to get the disclosures, consents, and authorizations you need from your end users before personal information is collected or shared with them.
5. COOKIES, TRACKING, AND CROSS-CONTEXT BEHAVIORAL ADVERTISING
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
The Services use cookies, web beacons, pixels, local storage, SDKs, and similar technologies ("tracking technologies") to make features work, improve the experience, measure performance, deliver analytics, power CRM and IDX integrations, support advertising, and provide personalized or automated content, recommendations, and messages, including cross-context behavioral advertising.
5.1 How we use them
We and the providers we authorize may use tracking technologies for:
- website and application analytics and performance measurement;
- CRM and marketing automation platforms;
- IDX and MLS integrations for real estate listings;
- AI-generated content, recommendations, and automated decisions;
- advertising platforms, including Google Ads, Facebook Ads, and other digital ad networks;
- SMS, email, and push communications.
These technologies can collect device identifiers, browsing behavior, how people interact with the Services, IP addresses, location, and other usage data. That information may be combined with other data to deliver personalized or targeted content, marketing, and automated recommendations.
5.2 Consent is your responsibility
You confirm that you have obtained every consent, authorization, and disclosure the law requires from your end users and data subjects, including under GDPR, UK GDPR, CCPA, CPRA, VCDPA, and other state, federal, or international privacy rules. That responsibility is yours, and so is the liability if it is not met.
5.3 Third-party tracking
Some tracking technologies belong to other companies: ad networks, analytics providers, AI platforms, CRM integrations, and IDX or MLS feeds. We are not responsible for:
- how those companies collect, use, or process data;
- whether their tracking is accurate, secure, or lawful;
- the output, targeting, or recommendations their technology produces;
- their failure to meet privacy, security, or regulatory obligations.
5.4 Opting out
End users can often turn off or opt out of tracking technologies, including cookies, web beacons, and behavioral advertising, through their browser settings, device settings, or industry opt-out tools. We cannot guarantee that those controls work or that they stop all tracking.
5.5 What we keep and why
Information collected through tracking technologies is retained under the retention and deletion rules in Section 8, and may be used for lawful business purposes, including improving the product, analytics, CRM, marketing, advertising, AI training, and other operations needed to run the Services.
5.6 Limits on our liability
To the fullest extent the law allows, we are not liable for damages, losses, or claims arising from tracking technologies, cross-context behavioral advertising, automated content, or data collection, whether caused by us, by a third-party provider, or by how end users interact with the Services. You take on the responsibility and risk of complying with privacy, security, and advertising law.
5.7 Crossing borders
Tracking technologies can mean personal information is collected, transferred, or processed in more than one country. You are responsible for complying with the international, federal, and state privacy and marketing laws that apply, including GDPR, UK GDPR, CCPA, CPRA, VCDPA, and COPPA, along with any local or regional requirements.
6. GOOGLE USER DATA AND LIMITED USE (GOOGLE API SERVICES)
This section covers the data we access through Google APIs when you connect a Google account to PromotePlus. It overrides everything else in this Policy. If another section mentions advertising, marketing optimization, behavioral advertising, AI or machine-learning training, benchmarking, or sharing data with advertising networks, data brokers, or analytics providers, that does not apply to your Google data.
6.1 What we ask for, and why
We only access your Google account after you connect it yourself through Google's consent screen. What we ask for depends on which sync options you turn on:
- Your basic Google account details — always. We use your email address and profile information to identify the Google account you connected, and to show it on your integrations screen.
- Gmail — when you turn on email sync. We read your messages and their attachments so your email conversations with clients show up on the contact's timeline in the CRM. We send the messages you write in PromotePlus. And we mark messages as read or unread, so a message you read in one place shows as read in the other. We don't ask for full access to your mailbox, which would also let us permanently delete your mail.
- Google Calendar — when you turn on calendar sync. We list your calendars and read, create, update, and cancel events, so you can manage showings, appointments, and follow-ups without leaving the CRM.
- Google Contacts — when you turn on contact sync. We read your contacts and create and update them, so your leads and clients stay the same in both Google Contacts and the CRM.
- Google Drive — asked for alongside calendar sync, to support attachments on calendar events. We can only ever see files that PromotePlus created itself, or that you opened with PromotePlus. We can't reach anything else in your Drive. Today, PromotePlus doesn't create, read, download, or store any Drive file.
6.2 AI email drafting
PromotePlus can draft an email reply for you. This only runs when you ask for it. When you do, we send the sender, subject line, and text of a few of the most recent messages in that conversation to OpenAI so it can write the draft. The draft comes back to you to review, and nothing is sent until you send it.
This is the only feature that sends data from your Google account to an AI model. Your calendars, your contacts, and your Drive files are never sent to an AI provider.
Why OpenAI. OpenAI's API terms state that data submitted through their API is not used to train or improve their models. We check a provider's terms, and the plan we are on, before we use it. We do not use providers, plans, or free tiers that train on submitted data, and we do not route your data through model aggregators or gateways where the downstream model cannot be identified.
No training. We never send data from your Google account to an AI provider so it can be trained on, and we never permit a provider to use it to train or improve their models. This covers raw data from your Google account and anything derived or aggregated from it.
6.3 Our Limited Use commitment
PromotePlus.ai's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. That covers the Google Workspace APIs too: the use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. In plain terms:
- We use your Google data only to run the features described in 6.1 and 6.2.
- We do not pass it to anyone else. The only exceptions are when it is needed to run those features (the AI email drafting in 6.2), when the law requires it, or in a merger, acquisition, or sale of the business, and in that case only after we ask you first.
- We never use it for advertising of any kind: no personalized, interest-based, retargeted, or cross-context behavioral ads.
- We never use it to build, improve, or train general-purpose AI or machine-learning models, and we do not pass it to any AI provider that would use it to train or improve theirs. This applies to raw data from your Google account and to anything derived or aggregated from it.
- We do not sell or share it, as those words are defined under the CCPA/CPRA and similar state laws, and we do not give it to ad networks, data brokers, or analytics companies.
- Nobody at PromotePlus reads your Google data. There are four exceptions: you have agreed to it for specific messages, we need to look into a security problem such as abuse, the law requires it, or the data has been aggregated and anonymized for internal operations.
6.4 Disconnecting, revoking, and how long we keep things
You can disconnect a Google account at any time from your integration settings. That stops PromotePlus from using that account and removes it from your active integrations.
Revoking Google's permission is a separate step. Disconnecting inside PromotePlus does not remove the permission recorded in your Google Account. To do that, remove our access at Google Account permissions.
How long we keep it. Data we have already synced, such as messages, calendar events, and contact records, is kept only as long as we need it for the features in 6.1. It is otherwise handled under Section 8 (Data Retention and Deletion), which includes your right to ask us to delete it. For anything to do with your Google data, email us at legal@PromotePlus.ai.
6.5 Keeping it secure
Your Google data travels over encrypted connections (TLS). The OAuth tokens we hold for your connected account are encrypted where we store them, and are not visible to other customers or to anyone outside PromotePlus. Only authorized staff can access them, and only in the cases listed in 6.3.
7. SMS, TEXT MESSAGING, AND MOBILE COMMUNICATIONS
The Services can send and receive text messages, SMS, MMS, push notifications, and other mobile messages, either directly or through an integration. We call these "mobile messages". Sending them is regulated, and the rules that apply include the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, the CCPA and CPRA, GDPR, UK GDPR, and other privacy and marketing law.
7.1 Consent is your responsibility
Before you send anyone a mobile message, you need their valid consent, including any opt-in the law requires. Keeping records of that consent, making sure it is accurate, and running proper opt-in and opt-out is on you.
7.2 What mobile messages cover
- account updates, service notifications, alerts, reminders, and confirmations;
- marketing, promotional, and advertising content, including cross-platform campaigns and AI-generated recommendations;
- IDX and MLS notifications, property updates, and lead follow-ups;
- automated messages triggered by CRM workflows.
How many messages go out depends on how you use the Services, what campaigns you run, and what your automations trigger.
7.3 Opting out
Anyone receiving mobile messages can opt out at any time by replying with a standard command such as STOP or UNSUBSCRIBE. We will process those requests as far as we technically can, but honoring opt-outs under the law is still your responsibility. Once someone opts out, they will not get further messages unless they opt back in.
7.4 The providers in between
Mobile messages travel through other companies: SMS gateways, phone carriers, ad platforms, AI messaging engines, IDX and MLS integrations, and marketing platforms. We do not control them, and we are not liable for what they do, how they secure data, or whether they follow the law. The risk of using them sits with you, including compliance with TCPA, CAN-SPAM, GDPR, and CPRA.
7.5 Where the risk sits
We are not liable for claims, damages, fines, penalties, or losses that come from sending a mobile message, failing to send one, or having one intercepted or misdelivered, whether the cause is us, a provider, an end user, or a technical failure. You take on the risk of mobile messaging, including legal compliance, consent management, message content, and timing.
7.6 Keeping records
Keeping accurate records of your mobile messaging is your job: consents, opt-out requests, message logs, and compliance documentation. We may offer logging or reporting features, but we do not guarantee that those records are complete or that they make you compliant.
7.7 Recipients in other countries
Some of the people you message may be outside the United States. Complying with the laws that apply there is your responsibility, including GDPR, UK GDPR, and local telecom and marketing rules.
7.8 This section outlasts the contract
These terms keep applying after the Services end, to any mobile message sent while you were using them.
8. DATA RETENTION AND DELETION
We keep your data only as long as we need it: to run the Services, to meet our contractual obligations, to satisfy legal, regulatory, tax, or accounting requirements, to enforce our agreements, to resolve disputes, to prevent fraud, or for other legitimate business reasons.
How we store it. Your data may sit in physical or electronic form, including in backups, archives, and redundant systems. We use commercially reasonable administrative, technical, and organizational safeguards to protect it. No system is completely secure, though, and we cannot promise permanent security or constant availability.
Getting it back, or deleting it. When the Services end or are cancelled, or if you ask us to, we will, as far as we technically can, either return your data in a standard format we agree on, or delete it from our active systems. Removing it from backups and archives can take longer and happens on our normal data lifecycle.
When we keep data anyway. We may hold on to data where we need it to:
- comply with a law, regulation, or legal obligation;
- keep records for tax, accounting, or audit purposes;
- protect our rights, property, or legal interests, or someone else's;
- resolve a dispute, enforce an agreement, or investigate fraud or a security incident;
- meet a legitimate business need that the law allows.
Your part. You are responsible for making sure the data you put into the Services meets whatever retention rules apply to you, and for getting any consents your end users, leads, or others need to give about how their data is kept, stored, and deleted.
Copies held elsewhere. When you use CRM platforms, IDX and MLS feeds, ad networks, AI systems, SMS providers, analytics tools, or other integrations, those companies may keep or process their own copies of your data. We are not liable for how they retain, delete, or handle it, and making sure that side is lawful is your responsibility.
Limits on our liability. To the fullest extent the law allows, we are not liable for claims, damages, or losses arising from data being retained, destroyed, lost, or corrupted, including anything caused by delayed deletion, technical limits, restoring a backup, or the actions of a third party.
This section outlasts the contract. These terms keep applying after the Services end.
9. DATA SECURITY
We use commercially reasonable administrative, technical, and physical safeguards to protect the integrity, confidentiality, and availability of your data, and we apply industry-standard measures. Even so, no system or network is completely secure, and no transfer of data over the internet or any network can be guaranteed to be error-free, uninterrupted, or fully secure.
We are not liable for unauthorized access, disclosure, or loss of your data caused by things outside our reasonable control, such as a breach at a third party, a cyberattack, or a natural disaster. Protecting your own data is still ultimately down to you: how you store it, who you give access to, and how you back it up.
10. CUSTOMER COMPLIANCE OBLIGATIONS
You are responsible for making sure that everything you do with the Services, and every piece of data you collect, submit, process, store, transfer, or disclose through them, follows the federal, state, and international laws, regulations, and contracts that apply to you. Specifically:
10.1 Collect and process data lawfully
Any data you put through the Services has to be collected, processed, and transmitted lawfully, under the privacy, data protection, consumer protection, telecom, marketing, and advertising laws that apply, including GDPR, UK GDPR, CCPA and CPRA, VCDPA, CDPA, and CTDPA. Get the consents, authorizations, notices, and permissions you need from people before you collect or process their data.
10.2 Keep your data accurate
The accuracy, completeness, and timeliness of what you put into the Services is on you. We rely on you to give us accurate, complete, lawful data, and we are not liable for what happens if it is wrong or incomplete.
10.3 Third parties you connect to
When you share data with an integrated third party, such as an IDX or MLS platform, CRM vendor, AI service, ad network, analytics platform, SMS provider, or cloud service, you are responsible for making sure that sharing is lawful and meets your contracts and industry standards. We have no control over those companies and are not liable for what they do.
10.4 Secure your own data
Put commercially reasonable administrative, technical, and organizational protections around the data you put through the Services, including sensitive data, to guard against unauthorized access, disclosure, alteration, loss, or destruction. No system is entirely secure, and you take on the risk of your own processing and that of the third parties you use.
10.5 Meet your regulatory and contractual duties
Everything you run through the Services, including marketing campaigns, SMS, AI output, IDX integrations, CRM workflows, advertising, and analytics, has to comply with:
- data protection and privacy law;
- telecom, spam, and marketing regulations;
- IDX, MLS, and other licensing or contractual requirements;
- the standards and practices that apply in your industry.
10.6 Keep proof, and handle requests
Maintain the policies, procedures, and records you need to show you are meeting these obligations. Responding to data subject requests, audits, regulatory investigations, and legal claims arising from your use of the Services is your responsibility. We may give you reasonable technical help, but compliance itself rests with you.
10.7 Liability and indemnity
We are not liable for fines, penalties, claims, or damages that come from your failure to follow the law, a regulation, or a contract. You agree to defend and indemnify us, our affiliates, and our officers, directors, employees, and agents against any claims, liabilities, losses, costs, or expenses, including legal fees, resulting from your failure to meet these obligations.
10.8 This section outlasts the contract
These obligations keep applying after the Services end, to all data handled through them.
11. GDPR COMPLIANCE
11.1 Scope and Roles
To the extent the Services involve the processing of personal data of individuals located in the European Union (EU), the European Economic Area (EEA), or the United Kingdom (UK) ("EU Data Subjects"), Customer acknowledges and agrees that:
10.1.1 Customer as Data Controller: Customer determines the purposes and means of processing EU Data Subjects' personal data and acts as the data controller under applicable GDPR and UK GDPR regulations.
10.1.2 Company as Data Processor: Company acts as a data processor with respect to Customer Data and shall process such data solely on documented instructions from Customer, except where processing is required by law.
10.1.3 No Independent Determination: Company does not determine the purposes or means of processing and shall not be deemed a controller with respect to Customer Data unless otherwise expressly stated in writing.
11.2 Legal Bases for Processing
Customer represents and warrants that it has a valid legal basis for all personal data submitted or processed through the Services. Such legal bases may include, without limitation:
- Consent of the data subject
- Performance of a contract with the data subject
- Compliance with legal obligations
- Legitimate interests pursued by Customer, provided that such interests do not override the fundamental rights of the data subject
- Protection of vital interests or public interest where applicable
Company relies exclusively on the documented instructions of Customer and assumes no responsibility for the legal sufficiency of the Customer's chosen legal basis.
11.3 Data Subject Rights
Company shall, to the extent reasonably possible, assist Customer in fulfilling its obligations under GDPR to respond to requests from data subjects regarding:
- Access to their personal data
- Rectification of inaccurate or incomplete personal data
- Erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Objection to processing
- Withdrawal of consent, where processing is consent-based
Customer acknowledges that Company may require reasonable verification of identity and that Company is not liable for any consequences arising from incomplete or fraudulent requests.
11.4 Subprocessors
10.4.1 Authorization: Customer authorizes Company to engage subprocessors to perform processing activities related to the Services.
10.4.2 Subprocessor Obligations: Company ensures that any subprocessor is subject to equivalent contractual obligations to protect the personal data and to process it only on documented instructions from Company.
10.4.3 Liability: Company remains fully liable for the acts and omissions of subprocessors in relation to Customer Data, subject to applicable law.
11.5 Security of Processing
Company implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including but not limited to:
- Pseudonymization and encryption of personal data
- Ongoing confidentiality, integrity, availability, and resilience of processing systems
- Regular testing and evaluation of security measures
- Ability to restore data following physical or technical incidents
Company does not guarantee absolute security and Customer acknowledges inherent risks of digital processing.
11.6 Data Breach Notification
In the event of a confirmed personal data breach affecting Customer Data, Company shall notify Customer without undue delay after becoming aware of the breach. Notification may include:
- Nature and scope of the breach
- Categories and approximate number of affected data subjects
- Potential consequences of the breach
- Measures taken or proposed to mitigate the breach
Customer retains responsibility for fulfilling any regulatory notification obligations to supervisory authorities and affected data subjects.
11.7 International Transfers
Customer acknowledges that Customer Data may be transferred to, processed, or stored in countries outside the EU/EEA/UK. Company shall implement appropriate safeguards for such transfers, including without limitation:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding corporate rules where applicable
- Other legally recognized transfer mechanisms
Customer consents to such transfers and acknowledges that Company is not responsible for changes in local law affecting the processing of data post-transfer.
11.8 Deletion and Return of Data
Upon termination of Services, Company shall, at Customer's choice:
- Delete all Customer Data, or
- Return all Customer Data in a mutually agreed format
unless retention is required by law or regulation, in which case Company shall segregate and protect retained data.
11.9 Limitation of Liability and Indemnification
Company shall not be liable for:
- Customer's failure to obtain consent or comply with GDPR obligations
- Regulatory fines or penalties imposed on Customer
- Misuse of Customer Data by Customer, end users, or third-party integrations
Customer agrees to indemnify and hold Company harmless from all claims, damages, or regulatory actions arising from Customer's noncompliance with GDPR or related data protection laws.
12. CALIFORNIA PRIVACY RIGHTS
If you are a resident of California, you may have certain rights under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable state privacy laws (collectively, "California Privacy Laws"). These rights are in addition to any rights you may have under other sections of this Policy.
12.1 Information We Collect and Disclose
Under California Privacy Laws, you have the right to request information regarding the categories of personal information we collect, process, and disclose about you, including:
- categories of personal information collected;
- sources from which personal information is collected;
- purposes for which personal information is collected and used;
- categories of third parties with whom personal information is shared; and
- specific pieces of personal information we have collected about you.
12.2 Access, Correction, and Deletion Rights
California residents may request to:
- access the personal information we have collected about them;
- obtain a copy of specific personal information in a portable and readily usable format;
- request correction of inaccurate, incomplete, or outdated personal information; and
- request deletion of personal information we have collected, subject to applicable exceptions (including legal obligations, fraud prevention, or legitimate business purposes).
12.3 Opt-Out of Sale or Sharing
Although Company does not sell personal information for monetary consideration, under California Privacy Laws, "sale" or "sharing" may be broadly interpreted to include certain disclosures to third parties for business purposes. California residents have the right to opt out of such disclosures. Requests to opt out may be submitted in accordance with the instructions provided below.
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
12.4 Methods for Exercising California Privacy Rights
California residents may exercise these rights by:
- contacting Company at legal@PromotePlus.ai, or by mail at PromotePlus.ai, 1217 E Cape Coral PKY, Suite #94, Cape Coral, FL 33904;
- submitting a verifiable request, including sufficient information to allow Company to verify your identity;
- using any online request portal, email address, or toll-free telephone number provided for this purpose.
Company may require verification of your identity and may request additional information to fulfill your request. Company will respond within the timeframe required under applicable law.
12.5 Non-Discrimination
Company will not discriminate against you for exercising any of your California Privacy Rights, including by denying services, charging different prices, or providing a different level or quality of service, except as permitted under California Privacy Laws.
12.6 Third-Party Disclosures
California residents acknowledge that, in connection with the Services, personal information may be disclosed to third-party service providers, advertising platforms, IDX/MLS systems, AI services, analytics providers, CRM platforms, or other integrations. Company disclaims liability for the acts, omissions, or compliance practices of such third parties and Customer assumes responsibility for ensuring that any such disclosures comply with applicable laws and obtain any required consents.
12.7 Limitations and Exceptions
Certain rights under California Privacy Laws may be limited or unavailable, including but not limited to:
- personal information collected before the applicability of the law;
- information necessary to complete a transaction or fulfill a contract;
- information required to detect or prevent fraud or illegal activity;
- information subject to other legal or regulatory obligations.
12.8 Updates to Rights and Requests
Company may update procedures or contact information for exercising California Privacy Rights at any time, and such updates will be reflected in this Policy. Customers are responsible for reviewing this Policy periodically to remain informed of changes.
13. OTHER U.S. STATE LAWS
In addition to California-specific rights, the Services and Company operations may be subject to, and Customer acknowledges and agrees to comply with, other applicable state-level privacy, consumer protection, marketing, or data protection laws in the United States ("State Privacy Laws"), including but not limited to laws enacted in Virginia (VCDPA), Colorado (CDPA), Connecticut (CTDPA), Utah, and any other state with applicable data protection or privacy legislation.
13.1 Compliance Responsibility
Customer is solely responsible for ensuring that its use of the Services, including collection, processing, storage, sharing, or transmission of personal information, marketing campaigns, communications, CRM operations, IDX integrations, AI-driven outputs, SMS, email, or push notifications, complies with all applicable State Privacy Laws. Customer represents and warrants that it has obtained all necessary consents, notices, and authorizations required by law and has implemented all required procedures to satisfy such laws.
13.2 Rights Under State Laws
Depending on the jurisdiction of Customer or end users, individuals may have certain rights under State Privacy Laws, including but not limited to:
- the right to access personal information collected about them;
- the right to correct inaccurate, incomplete, or outdated personal information;
- the right to request deletion or restriction of processing of personal information;
- the right to opt out of the sale or sharing of personal information;
- the right to receive a copy of any disclosures made to third parties; and
- the right to submit verifiable requests to exercise these rights.
Customer assumes full responsibility for implementing procedures to facilitate such rights and for responding to requests in accordance with the law. Company may provide reasonable technical assistance, but Company does not assume responsibility for the timeliness, completeness, or accuracy of Customer's compliance efforts.
13.3 Third-Party Disclosures
Customer acknowledges that personal information may be disclosed to third-party service providers, including but not limited to IDX/MLS platforms, CRM vendors, advertising networks, AI service providers, analytics platforms, and SMS/communications providers. Customer assumes full responsibility for ensuring that any such disclosures comply with applicable State Privacy Laws and that all required contractual, consent, or notice obligations are satisfied. Company expressly disclaims liability for the actions, omissions, or compliance of third parties.
13.4 Data Security and Risk Allocation
Customer is solely responsible for implementing reasonable administrative, technical, and organizational measures to protect personal information in accordance with applicable State Privacy Laws. Company employs commercially reasonable safeguards; however, no system is completely secure, and Company shall not be liable for unauthorized access, disclosure, loss, or corruption of data, including through third-party services.
13.5 Liability Limitation and Indemnification
To the fullest extent permitted by law, Company shall have no liability for fines, penalties, claims, or damages arising from Customer's or third-party failure to comply with any State Privacy Laws. Customer agrees to indemnify, defend, and hold harmless Company from and against any such claims, liabilities, or regulatory actions resulting from or related to Customer's or third-party processing of personal information, marketing campaigns, communications, IDX integrations, CRM usage, or AI-generated outputs.
13.6 Updates and Changes to Laws
Customer acknowledges that State Privacy Laws are evolving and may impose additional obligations over time. Customer is responsible for monitoring legal developments and ensuring ongoing compliance with all applicable state, federal, and local regulations. Company may, at its discretion, update its Policies to reflect changes in applicable laws, but ultimate compliance responsibility rests with Customer.
13.7 Survival
The provisions of this section shall survive any termination, suspension, or expiration of the Services, this Policy, or any agreements between Customer and Company, and shall remain in full force and effect for all personal information collected, processed, stored, or transmitted through the Services.
14. DATA PROCESSING ADDENDUM (DPA)
14.1 Scope
This DPA applies where Company processes personal data on behalf of Customer.
14.2 Instructions
Company shall process data only on documented instructions from Customer, except as required by law.
14.3 Confidentiality
Company personnel are subject to confidentiality obligations.
14.4 Security Measures
Company implements reasonable technical and organizational safeguards.
14.5 Subprocessors
Company may engage subprocessors and remains responsible for their performance.
14.6 Data Subject Requests
Company shall assist Customer in responding to requests where required.
14.7 Data Breach
Company shall notify Customer of confirmed data breaches as required by law.
14.8 Deletion or Return
Upon termination, Company may delete or return data at its discretion, unless retention is required.
15. INTERNATIONAL TRANSFERS
Customer acknowledges and agrees that, in connection with the provision of the Services, Company may collect, process, store, and transfer personal information, Customer Data, or other information to jurisdictions outside of the country in which the Customer or data subject resides ("International Transfers"). Such transfers may include, without limitation, transfers to servers, service providers, subsidiaries, affiliates, cloud providers, AI platforms, CRM systems, IDX integrations, advertising networks, analytics platforms, or SMS and communication providers located in the United States or other countries.
15.1 Compliance with Applicable Law
Customer acknowledges that International Transfers may implicate various data protection and privacy laws, including but not limited to the General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other international, federal, or state data protection regulations. Customer assumes full responsibility for ensuring that any such transfers, processing, or storage of personal information complies with all applicable laws, including the implementation of any required safeguards, contractual clauses, or consent mechanisms.
15.2 Mechanisms for Lawful Transfers
Company may, in its sole discretion, rely on one or more lawful mechanisms for International Transfers, including but not limited to:
- Standard contractual clauses approved by the European Commission or other competent authorities;
- Binding corporate rules;
- Adequacy determinations issued by competent regulatory authorities;
- Explicit consent obtained by Customer from data subjects; or
- Other mechanisms permitted under applicable law.
Customer acknowledges that Company makes reasonable efforts to implement such mechanisms where applicable but cannot guarantee compliance by third parties, regulators, or data recipients. Customer is responsible for ensuring that any personal information submitted or transmitted through the Services is processed in accordance with applicable law.
15.3 Third-Party Transfers
Customer acknowledges that International Transfers may involve third-party service providers, including cloud providers, CRM platforms, IDX/MLS systems, advertising networks, AI platforms, analytics providers, and SMS or communications providers. Company expressly disclaims any liability for the actions, omissions, or compliance practices of such third parties with respect to International Transfers. Customer assumes all risk and responsibility for such third-party transfers, including obtaining any necessary consents, implementing appropriate safeguards, and complying with applicable laws.
15.4 Risk Allocation
Customer acknowledges that International Transfers may involve risks, including but not limited to differences in legal protections, regulatory enforcement, privacy standards, and technical security measures. Customer assumes all risk associated with such transfers, and Company shall not be liable for any loss, unauthorized access, disclosure, or breach of data occurring during or resulting from International Transfers.
15.5 Recordkeeping and Documentation
Customer is responsible for maintaining any required records, documentation, or notices related to International Transfers, including contracts, consents, or legal authorizations, to demonstrate compliance with applicable data protection and privacy laws. Company may provide reasonable technical or administrative support for recordkeeping, but ultimate responsibility rests with Customer.
15.6 Survival
The provisions of this section shall survive any termination, suspension, or expiration of the Services, this Policy, or any agreement between Customer and Company and shall remain in full force and effect with respect to all personal information transferred internationally during the term of the Services.
16. AI AND AUTOMATED DECISION-MAKING
Google data exception: this does not apply to data we access through Google APIs. Section 6 (Google User Data and Limited Use) covers that data and overrides this section.
We use artificial intelligence, machine learning, and other automated tools, some built by us and some from other companies, to analyze and work with data. That includes:
- looking at how users, leads, and others behave and interact;
- generating, suggesting, or editing content, messages, recommendations, and other output;
- giving you and your end users predictions, suggestions, and personalized guidance;
- making automated decisions or scoring within campaigns you run, CRM workflows, and other parts of the Services.
Two things to be clear about:
- AI output is a probability, not a fact. It can be wrong, incomplete, misleading, biased, or out of date, and we make no promises about its accuracy, reliability, suitability, or legality.
- Checking AI output before you act on it is your job, as is making sure the way you use it follows the law, your industry's rules, and your own policies.
We are not liable for any decision, action, or inaction that you, your end users, or anyone else takes based on AI output or an automated recommendation. You take on the risk of using AI and automated processing, including relying on its output in marketing campaigns, real estate transactions, communications, and content.
Nothing here obliges us to monitor, verify, correct, or validate AI output or automated decisions. That stays with you.
17. THIRD-PARTY SERVICES AND INTEGRATIONS
The Services link to and integrate with other companies' websites, tools, APIs, widgets, and platforms. We call these "third-party services", and they include IDX feeds, multiple listing services, ad platforms, marketing automation tools, analytics providers, communication services, and AI content providers. They are there for convenience and interoperability. Here is what that means for you.
We do not control them, and we do not endorse them. We do not operate, manage, or monitor third-party services, and we make no promises about whether they are available, accurate, legal, secure, functional, reliable, or compliant. A link or an integration is not a recommendation.
You take on the risk. Using, relying on, or integrating with a third-party service is at your own risk, including any data that gets sent, processed, or shared along the way. We are not responsible for loss, damage, interruption, error, unauthorized access, misuse, or a legal violation that results from it.
Their rules are yours to follow. Reading and complying with each third-party service's terms, privacy policy, licence agreement, and legal requirements is your responsibility, including anything governing how personal information is collected, processed, stored, or shared.
Building an integration does not change that. We may offer technical integrations with third-party services, such as APIs, IDX feeds, ad platforms, AI services, or marketing automation tools. Offering one does not make us responsible for that service's security, compliance, performance, or output.
Data that moves between them. Anything sent to or received from a third-party service is still covered by your obligations under this Policy and the law. We do not promise that those companies will meet any privacy, security, or regulatory requirement, and making sure your side complies, including with GDPR, CCPA, CPRA, and TCPA, is up to you.
No partnership. Nothing here creates a partnership, joint venture, fiduciary relationship, agency, or employment relationship between us and any third-party provider. We take on no duty of care for how they operate.
Limits on our liability. We are not liable for what third-party services do or fail to do, including errors, failures, breaches, misuse, misrepresentation, or breaking the rules. The risk of engaging, integrating, or relying on them is yours.
What they collect. Interacting with a third-party service may mean it collects, stores, processes, or shares personal information under its own policies. Getting the necessary consents, giving the right disclosures, and staying legal about that is your responsibility.
18. DO NOT TRACK (DNT)
The Services do not respond to "Do Not Track" signals, browser settings, or similar mechanisms that signal a preference not to be tracked. There is no consistent industry standard for these signals, and not responding to them is consistent with common practice and applicable law.
What that means in practice:
- we may keep collecting, processing, and analyzing data from website visitors and end users, whether or not a DNT signal is present;
- other companies, including ad platforms, analytics vendors, IDX providers, CRM integrations, AI tools, and messaging platforms, may track or process data in ways we do not control and may ignore DNT signals too;
- we are not responsible for how those companies collect, use, or track data, including their handling of DNT signals;
- making sure your own use of the Services follows the law on tracking, behavioral profiling, and privacy preferences is your responsibility, including on the websites, CRM systems, campaigns, and automations you control;
- nothing here obliges us to monitor, change, or restrict how third parties or your own systems track people.
By using the Services, you consent to information being collected, processed, and used as described in this Policy, regardless of any DNT or similar browser signal.
19. CHILDREN'S PRIVACY
The Services are not meant for children under thirteen (13), or for anyone below the age at which they can lawfully consent to their data being processed where a higher age applies, such as in the European Union or the United Kingdom. We refer to them here as children.
19.1 Do not put children's data into the Services
You confirm that you will not knowingly submit, upload, send, or process any child's personal information through the Services. We do not knowingly collect, process, or store personal information from children.
19.2 Parental consent
If we find out that we hold personal information from or about a child, we will take commercially reasonable steps to delete it right away. Getting the parent or guardian consent needed for any data collection, processing, or marketing involving children is your responsibility, including for:
- creating accounts, profiles, or registrations;
- submitting information to CRM or lead systems;
- sending automated marketing or other communications;
- using IDX-enabled property search;
- interacting with AI-generated content or recommendations.
19.3 No marketing to children
Neither of us may send marketing, promotional, or automated messages to children. Every SMS, email, push notification, and other message has to respect age-appropriate law and parental consent requirements. You are liable for any breach of that.
19.4 Third parties
We use outside providers, including IDX feeds, ad networks, SMS platforms, analytics, and AI systems. We are not responsible for how they handle children's data, and making sure they comply with children's privacy law is your responsibility.
19.5 The laws that apply
You agree to follow every law protecting children's personal information, including:
- the Children's Online Privacy Protection Act (COPPA) in the United States;
- GDPR and UK GDPR rules for minors, including Article 8 on parental consent;
- state-specific children's privacy laws;
- the equivalent laws in other countries.
We are not liable if you or a third party fails to meet those requirements, and you agree to indemnify us against claims, fines, penalties, and damages arising from a violation involving children's data.
19.6 Deletion and parental requests
If we are told that a child's personal information has been collected, we will delete it promptly as far as we technically can. You agree to help us find, remove, or correct that data and to respond to parental and legal requests about children.
19.7 Limits on our liability
To the fullest extent the law allows, we are not liable for any actual or alleged unauthorized collection, use, or disclosure of children's information, including anything done by you, an end user, or a third-party provider. That risk and liability is yours.
20. CHANGES TO THIS POLICY
We may change this Policy at any time, without notice unless the law requires it. Changes might come from new laws or regulations, industry standards, security requirements, how we run the business, new technology, or changes to the platforms we integrate with, such as IDX and MLS systems, CRM platforms, ad networks, AI services, SMS providers, analytics platforms, and cloud infrastructure.
If you keep using the Services after we update this Policy, you accept the updated version. We may tell you about material changes by email, an in-product notice, or a post on our website, but we are not liable if you or your end users do not receive or read that notice.
Check this Policy from time to time so you know where you stand, particularly on:
- how personal information is collected, processed, stored, or transferred;
- your rights and obligations under privacy law, including GDPR, UK GDPR, CCPA and CPRA, VCDPA, CDPA, CTDPA, and other federal, state, or international law;
- third-party integrations, APIs, CRM systems, IDX and MLS feeds, AI output, advertising, SMS, and other marketing communications;
- security, retention, deletion, and risk management.
If you do not follow this Policy as updated, we may suspend, restrict, or end your access to the Services, on top of any other remedy available to us. This section keeps applying after the Services end.
21. GOVERNING LAW
This Policy is governed by and interpreted under the laws of the State of Florida, without regard to conflict of laws rules that would apply another state's law.
Any claim or dispute arising out of or relating to this Policy, the Services, or how either is interpreted, enforced, or breached, including claims under federal, state, or local law, has to be brought in the state or federal courts in Lee County, Florida. Both of us agree to the personal jurisdiction and venue of those courts and give up any objection to them, including on grounds of forum non conveniens.
No statute or regulation applying another jurisdiction's law applies to a dispute under this Policy. If any part of this Policy turns out to be invalid, illegal, or unenforceable, it will be enforced as far as it can be and the rest stays in force.
Nothing here stops us from seeking an injunction or other equitable relief in any jurisdiction to protect our intellectual property, confidential information, or proprietary rights.
This section keeps applying after the Services end.
22. CONTACT
PromotePlus.ai
1217 E Cape Coral PKY
Suite #94
Cape Coral, FL 33904
legal@PromotePlus.ai