This Data Processing Addendum (the DPA) forms part of the AryaPM Terms of Service between AryaPM, a property operations software business based in Kelowna, British Columbia (AryaPM, we, us), and the organisation that has subscribed to the Service (the Client Organisation, you).
It sets out how AryaPM handles personal information on your behalf. You are the organisation accountable for that information under the Personal Information Protection Act (British Columbia), the Personal Information Protection and Electronic Documents Act (Canada) and any other privacy law that applies to you. AryaPM acts as your service provider and processes personal information only for you and on your instructions.
Client Organisations in Ontario, or that manage condominium corporations or rental properties governed by Ontario law, acknowledge that their obligations under the Condominium Act, residential tenancy law and applicable privacy law remain theirs; this DPA describes how AryaPM helps you meet them and does not shift accountability to AryaPM.
1.Definitions
Personal Information means information about an identifiable individual, in any form, that AryaPM processes on your behalf in connection with the Service.
Resident Data means Personal Information about owners, tenants, occupants, guests, property agents, contractors and other individuals connected to a property that you manage, including names, contact details, unit and parking assignments, vehicle and pet records, requests, bookings, ledgers and balances, compliance filings, complaint and bylaw files, communications and the documents you upload.
Client Organisation means the strata corporation, condominium corporation, management company, brokerage, owner or other organisation that has agreed to the Terms and is accountable for the Resident Data entered into its tenancy of the Service.
Authorised Users means the individuals you allow to use the Service under your tenancy, including administrators, staff, council or board members, owners, tenants, agents, technicians, housekeeping, concierge and security personnel.
Sub-processors means third-party providers that AryaPM engages to process Personal Information on its behalf in delivering the Service, such as hosting, payment, messaging and screening providers.
Security Incident means a confirmed accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Personal Information that AryaPM processes for you. It does not include unsuccessful attempts or events that do not compromise the security of Personal Information, such as blocked port scans, failed sign-in attempts or automated probes.
Capitalised terms not defined here have the meaning given in the Terms of Service.
2.Roles and scope
You decide why Personal Information is collected and how it is used. You are responsible for having the authority and, where required, the consent to enter Resident Data into the Service, for the accuracy of what your Authorised Users enter, and for responding to individuals who exercise their privacy rights.
AryaPM processes Personal Information only on your documented instructions. Your documented instructions are the functions of the Service as described in the Terms and in-app, the configuration choices you make in the Service, and any further written instructions you give us that are consistent with the Terms. AryaPM will not use Resident Data for its own purposes, sell it, or disclose it except as this DPA and the Privacy Policy permit or the law requires.
This DPA applies to every property, community and portfolio that runs under your tenancy of the Service, and to every Authorised User you admit to it.
3.Processing instructions and purposes
AryaPM processes Personal Information for the following purposes, each of which is a standing instruction from you when you use the corresponding function:
- Resident directory: maintaining owner, tenant, occupant, agent, vehicle, pet and contact records for the properties you manage, and the household relationships between them.
- Requests and work orders: receiving, routing, scheduling and closing maintenance, concierge, access and service requests, including the photographs and notes your Authorised Users attach.
- Bookings: reserving amenities, guest suites, elevators and moves, and collecting the associated fees and deposits.
- Billing and ledgers: issuing invoices and assessments, recording payments and balances, processing pre-authorised debits where enabled, and producing statements and reports.
- Compliance filings: capturing the statutory forms, insurance certificates, short-term-rental registrations and similar filings that owners and agents submit, and tracking their status.
- Communications: sending the emails, text messages and push notifications you compose or schedule to residents, staff and council, and recording delivery and engagement.
- Governance: recording complaints, bylaw and rule enforcement, council or board decisions, minutes, motions and votes, subject to the access limits built into the Service.
- Leasing and screening, where enabled: collecting applications and, with the applicant's consent, obtaining background, credit or reference checks through a tenant-screening provider.
- Service operation: authentication, access control, audit logging, backups, support, fraud and abuse prevention, and the technical monitoring needed to keep the Service secure and available.
If you believe an instruction would breach privacy law, or if AryaPM believes one of your instructions would, the party that notices must tell the other promptly. AryaPM may decline to act on an instruction it reasonably believes is unlawful.
4.Sub-processors
You authorise AryaPM to engage Sub-processors in the following categories to deliver the Service. AryaPM remains responsible to you for each Sub-processor’s performance and binds each of them to written data-protection obligations that are no less protective than this DPA.
- An enterprise cloud infrastructure provider that hosts the Service's database, file storage and authentication in a Canadian data-centre region.
- A cloud application-hosting and content-delivery provider that serves the web application and runs its server-side functions.
- A PCI-compliant payment processor that handles card and bank-account payments, payouts and pre-authorised debits.
- Email, SMS and push delivery providers that carry the messages you send through the Service.
- A tenant-screening provider, used only for clients that enable leasing and only with the applicant's consent.
- Operational tooling providers for error monitoring, source control, automated backups and support ticketing, which may process limited Personal Information incidentally.
A current list of Sub-processors, with the category, function and processing location of each, is available to Client Organisations on request to support@aryapm.ca. AryaPM will give you at least 30 days’ written notice before adding or replacing a Sub-processor in a way that materially changes how your Personal Information is processed. If you have a reasonable, privacy-related objection, tell us within that period; we will work with you in good faith to resolve it, and if we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rated refund of prepaid Fees for the terminated part.
5.Security measures
AryaPM maintains technical and organisational measures appropriate to the sensitivity of Resident Data, including at minimum:
- Encryption of Personal Information in transit (TLS) and at rest.
- Role-based access control, so that each Authorised User sees only the records their role and property permit.
- Tenant isolation enforced at the database layer with row-level security policies, so that one Client Organisation's data is never returned to another.
- Multi-factor authentication and passkey (biometric) sign-in for Authorised Users, and mandatory strong authentication for AryaPM staff.
- Audit logs of privileged actions and of every change to financial records, retained for the life of the tenancy.
- Automated encrypted backups taken every six hours and retained for 14 days, stored separately from the live database.
- Least-privilege access for AryaPM staff: production access is limited to the individuals who need it, is logged, and is reviewed when roles change.
- Vulnerability management, including automated dependency monitoring, prompt patching of the platform and its dependencies, and secrets kept out of the browser and out of source control.
- Secure development practices, including code review of changes that touch authentication, tenancy boundaries or payments, and verification of signatures on inbound webhooks from Sub-processors.
AryaPM may update these measures over time provided the overall level of protection does not decrease. A written summary of current controls is available to you on request, as described in section 12 (Audits).
6.Confidentiality of personnel
AryaPM ensures that every employee, contractor and agent who may access Personal Information is bound by a written confidentiality obligation, has been trained in the handling of personal information, and accesses Personal Information only to the extent needed to deliver, support or secure the Service. Access is removed promptly when a person’s role ends.
7.Security incident notification
AryaPM will notify you of a Security Incident affecting your Personal Information without undue delay, and in any event no later than 72 hours after AryaPM has confirmed the incident. Notice goes to the administrator contacts on your account by email, and by telephone where you have provided a number for urgent matters.
The notification will include, so far as it is known at the time:
- The nature of the incident, including the categories and approximate number of individuals and records affected.
- When it occurred and when AryaPM became aware of it.
- The likely consequences for the individuals concerned.
- The measures AryaPM has taken or proposes to take to contain and remedy it.
- A contact person at AryaPM for further information.
Where the details are not all available at once, AryaPM will provide them in phases as they become known. AryaPM will co-operate with you and, at your direction, assist you in meeting any obligation you have to notify affected individuals or a privacy commissioner. AryaPM will not notify individuals or regulators on your behalf unless you ask it to or the law requires it.
8.Assistance with requests and assessments
Individuals may ask you for access to, or correction of, their Personal Information. The Service gives Authorised Users self-serve tools to view and correct their own household records, and gives your administrators the ability to export, correct and, where lawful, delete an individual’s records. Where a request cannot be met with those tools, AryaPM will assist you within 10 business days of a written request so that you can respond within the statutory timeline.
If a request reaches AryaPM directly, AryaPM will refer the individual to you and will not respond on the substance without your instruction, unless the law requires otherwise.
AryaPM will provide reasonable assistance with privacy impact assessments and with consultations with a privacy regulator that relate to the Service, drawing on the controls summary and Sub-processor list described in this DPA. Assistance beyond what is reasonable in the circumstances may be subject to a reasonable charge agreed in advance.
9.Data location and cross-border processing
Personal Information is stored primarily in Canada: the Service’s database, file storage, authentication records and backups are hosted in a Canadian data-centre region operated by our cloud infrastructure provider.
Some Sub-processors that provide compute, content delivery, payment processing, email, SMS or push delivery, or tenant screening may process Personal Information transiently outside Canada, most commonly in the United States, while a page is served, a message is delivered or a payment is authorised. Such processing is limited to what the function requires and is governed by the written obligations described in section 4.
By using the Service you acknowledge and, where required, consent to this processing, and you are responsible for any notice to individuals that your privacy law requires about storage or access outside Canada. Where the law of a jurisdiction you operate in restricts cross-border processing, tell us and we will work with you on the configuration or contractual measures that law requires.
10.Retention, return and deletion
AryaPM retains Personal Information for the term of your subscription and as long as needed to provide the Service to you. You may export your records from the Service at any time during the term using the reporting and export tools, or by asking support@aryapm.ca for a bulk export.
- Export window: for 30 days after your subscription ends, your administrators may export your records, or ask AryaPM to deliver a bulk export in a commonly used, machine-readable format.
- Purge: after the export window, AryaPM will delete or irreversibly anonymise your Personal Information from live systems within 90 days.
- Backups: copies held in encrypted backups age out under the retention schedule in section 5 and are not restored except to recover the Service; they are deleted when the schedule expires.
- Exceptions: AryaPM may keep records it is legally required to retain (for example, payment and tax records) or that it reasonably needs to establish or defend legal claims, and will continue to protect them under this DPA until they are deleted.
- Certificate: on request, AryaPM will provide written confirmation that deletion has been completed.
Statutory records belong to you. Nothing in this section limits your obligation to keep the records that the Strata Property Act, the Condominium Act, tenancy law or your governing documents require you to keep after you leave the Service.
11.Liability
Each party’s liability arising out of or related to this DPA, including for a breach of it and for any Security Incident, is subject to the exclusions and the cap on liability in the Terms of Service (see Terms, Limitation of liability). This DPA does not create any additional or separate limit; a claim under this DPA and a claim under the Terms are counted together toward that single cap.
12.Audits
AryaPM will make the following available so that you can satisfy yourself, and any regulator, that Personal Information is handled as this DPA describes:
- An annual written summary of AryaPM's security and privacy controls, and the current Sub-processor list, on request at no charge.
- Reports of third-party assessments, penetration tests or examinations of the Service, as and when they are available, under confidentiality.
- Written answers to reasonable security questionnaires, within a reasonable time.
- An on-site or remote audit of AryaPM's relevant controls by you or an independent auditor you appoint and AryaPM reasonably accepts, by agreement on scope, timing and confidentiality, at your cost, no more than once in any 12-month period unless a Security Incident or a regulator's demand requires otherwise.
Audits must not unreasonably disrupt AryaPM’s operations, must respect the confidentiality of other Client Organisations’ data, and must not require AryaPM to breach its obligations to a Sub-processor. AryaPM will correct any material deficiency an audit identifies within a reasonable, agreed time.
13.Term and precedence
This DPA takes effect when you accept it or when you first use the Service after the effective date above, whichever is earlier, and continues for as long as AryaPM processes Personal Information for you, including during the export and purge periods in section 10.
This DPA forms part of the Terms of Service and is governed by the law of British Columbia and the laws of Canada applicable there, as the Terms provide. If this DPA conflicts with the Terms, the Privacy Policy or an Order on a matter concerning the protection of Personal Information, this DPA prevails. On every other matter the Terms prevail. AryaPM may update this DPA as described in the Terms; material changes will be notified to your administrators and will not reduce the protection of Personal Information without your agreement.
14.How to accept
A company administrator accepts this DPA in the Service on behalf of the Client Organisation. By accepting, the administrator confirms that they are authorised to bind the organisation. Acceptance is recorded in the Service’s agreements ledger with the document version, the date and time, and the accepting user, and is available to your administrators on request.
If your organisation requires a countersigned copy or negotiated changes, write to support@aryapm.ca with “DPA” in the subject line. Until a negotiated version is signed, this published version governs.
Questions about this document: support@aryapm.ca. AryaPM is based in Kelowna, British Columbia, Canada. This document was last updated on September 9, 2026.