Legal
Data Processing Agreement
Version: dpa 2026-10-09. In force from 9 October 2026.
This agreement is part of Proppy's Terms of Service, and applies to every firm, including while its first MCSTs are free. It covers the personal data in the invoices and MCST records a managing agent firm puts into Proppy. The person setting up the firm on Proppy agrees to it for the firm, by ticking its box at company setup. The annexes are part of it.
1. Who's who
- The firm is the managing agent that uses Proppy. For the personal data in its MCSTs' records, it's the organisation responsible under Singapore's Personal Data Protection Act 2012 (PDPA), or it acts for the MCST's management corporation that is.
- Proppy is PEBBLEBLACK PTE. LTD., UEN 202531369R. It processes this data for the firm, as a data intermediary. For its own records of the people who use Proppy, such as their sign-ins, Proppy is the organisation, and its Privacy and data notice applies instead.
- Personal data, processing, and data breach mean what the PDPA says they mean.
2. What's processed, and why
- Annex 1 says what data this covers, whose it is, and what Proppy does with it.
- Proppy processes it only to provide Proppy to the firm, on the firm's instructions: this agreement, the Terms of Service, and what the firm's people do in Proppy. That includes measuring and improving how well Proppy reads the firm's own invoices, and how well Ask Proppy answers its people.
- Proppy doesn't use it for anything else, doesn't sell it, and doesn't use it to train any model.
- Proppy never makes payments. It drafts vouchers and, when the firm connects Xero, posts Draft bills when one of the firm's people posts them. Vouchers are approved by the firm's people, or by Proppy under an auto-approval rule the firm's owner sets for an MCST.
- Ask Proppy is the assistant inside the app that answers the firm's people's questions about using Proppy. It only reads: it can't change, approve, or delete anything. To answer, it looks up records in the firm's account that the person's role can already see, and sends the question and what it looked up to Google's paid AI service (Annex 3). Proppy masks NRIC numbers, bank account numbers, emails, and phone numbers in the question before it's sent and kept, and asks people not to paste NRIC numbers or bank details into it.
- If Proppy thinks an instruction breaks the PDPA, it tells the firm.
3. Keeping it safe
- Proppy protects the data with reasonable security arrangements, as the PDPA's protection obligation requires. Annex 2 lists them. Proppy may change them, as long as they protect the data at least as well.
- Everyone at Proppy who can reach the data is bound to keep it confidential, and reaches only what their work needs.
- Proppy's support team opens the firm's account only to help it, read-only, for an hour at a time, with a reason. Every page they open goes in the firm's audit log, and the firm's owner and admins see each visit in Settings.
- Proppy follows the PDPC's advisory guidelines on NRIC numbers: it doesn't ask for them, and masks any it reads from a document, in what it reads and keeps. It keeps each file as received, as the MCST's record, so a number printed on it can still be seen there by the firm's people who may open it.
4. Service providers, and data outside Singapore
- Proppy uses the service providers in Annex 3. Each is bound by its written data processing terms to protect the data, and to use it only to provide its service to Proppy.
- Some of them process the data outside Singapore, as Annex 3 says. Proppy relies on their written terms, which bind them to protect it to a standard comparable to the PDPA's, so the firm can meet the PDPA's transfer limitation obligation.
- Xero isn't one of Proppy's providers. When the firm connects its MCSTs' Xero organisations, Proppy sends bills there on the firm's instruction, and Xero handles them under the firm's own agreement with Xero.
- Proppy emails the firm's owners and admins at least 30 days before it adds or replaces a provider that handles this data, or moves it to another country. The firm can object by email within that time. Proppy then tries to meet the objection. If it can't, and goes ahead, the firm can end its plan without further charge, and Proppy refunds the fees paid in advance for whole months after it ends.
5. A data breach
- Proppy tells the firm without undue delay, as the PDPA requires of a data intermediary, and within 24 hours, after it has credible grounds to believe the firm's data has been breached. It then keeps the firm up to date.
- Proppy says what happened, what data, and about how many people, what it has done, and whom to contact. It shares more as it learns it.
- Proppy helps the firm assess whether the breach is notifiable, within the 30 days the PDPC expects, and helps it notify the PDPC within 3 calendar days of assessing that it is, and the people affected as soon as practicable where significant harm is likely.
- Proppy doesn't notify the PDPC or the people affected about the firm's data itself, unless the firm asks it to or the law requires it.
- Proppy follows its written plan for handling a data breach, and reviews the plan at least once a year.
6. People's requests
Proppy helps the firm answer anyone who asks to see or correct their personal data, within the PDPA's time limits: as soon as reasonably possible, and within 30 days or by telling them by then when it will. The firm's people can find, correct, and export records in Proppy themselves. If someone asks Proppy directly, Proppy passes the request to the firm within 3 working days.
7. How long it's kept
- Proppy keeps the firm's records for the firm's retention period, set in Settings: 5 years at least, which the firm can lengthen to 30, from the end of the financial year of the MCST's that each record belongs to. The Building (Strata Management) Act 2004 (BSMA), called the Building Maintenance and Strata Management Act until 1 October 2025, requires an MCST to keep its records for at least 5 years from the end of the financial year in which the transaction they relate to is completed. Proppy deletes nothing on its own before then.
- If a payment for the firm's plan isn't made when it's due, its account may become read-only, and nothing is deleted.
- If the firm closes its account, Proppy still keeps the MCSTs' records, such as invoices, vouchers, the audit log, and each invoice's history, for the rest of their retention period, so they're there for the MCSTs as the Act requires. The firm's owner can still sign in to read and download them. Once a record's retention period has ended, Proppy deletes it, and its copies in Proppy's backups, and nothing before then. The firm's other data, such as its people's sign-ins and its settings, is deleted with the last of its records, except what the law requires Proppy to keep.
- The firm can ask Proppy to delete an MCST's records sooner, once it has handed them over to the MCST's management corporation or its new managing agent, such as with the download of all of the MCST's records in Proppy. The firm's owner asks in writing, saying the handover is done, and Proppy then deletes them within 30 days. If the firm no longer exists, Proppy gives an MCST's records to its management corporation when its council asks in writing, with its resolution, and then deletes them.
- If Proppy stops providing its service altogether, it gives the firm at least 90 days' notice to download its MCSTs' records, and deletes them after that, except what the law requires it to keep.
- Ask Proppy's conversations, which are the questions, the answers, the look-ups made to answer them, and the ratings, are records of how the assistant is used, which Proppy processes for the firm under this agreement. They're not part of the MCST records that the BSMA requires an MCST to keep, or that the firm's retention setting covers. They're deleted automatically 90 days after the conversation was last used, and each person can delete their own sooner. A copy in the database's daily backups is deleted when that backup expires.
- Proppy confirms each deletion in writing if the firm asks.
8. Checking
Proppy answers the firm's reasonable questions about how it protects the data. When the firm asks, once a year or after a breach, it shares a summary of how it has tested and reviewed its security. The firm can ask for an audit by an independent auditor, at its own cost, with 30 days' notice, under a confidentiality agreement.
9. The firm's obligations
The firm makes sure it may lawfully give this data to Proppy for these purposes, including processing outside Singapore, and tells the people concerned where the PDPA requires it. Proppy provides model clauses for the firm's agreement with each MCST, which help it cover this. The firm can ask for them at james@talktoproppy.com.
10. How it fits with the Terms
This agreement lasts as long as Proppy processes the firm's data. Where it and the Terms of Service disagree about personal data, this agreement wins. The Terms' limits on liability apply to this agreement too. Custom terms that Proppy and the firm agree in writing add to this agreement, and win where they differ.
Annex 1: the processing
| About | Details |
|---|---|
| Whose data | Suppliers' staff, the firm's staff who use Proppy, condo managers, council members, and others named in the MCSTs' invoices and records |
| What data | Names, work emails, phone numbers, and addresses; suppliers' bank details on invoices and vouchers; job titles; signatures on vouchers; who did what in Proppy, and when. NRIC numbers are masked in what Proppy reads, and never asked for; a file kept as received still shows any printed on it. Questions people type into Ask Proppy and its answers, with NRIC numbers, bank account numbers, emails, and phone numbers masked, the look-ups it made to answer, and people's ratings of its answers |
| What Proppy does with it | Receives invoices by email or upload; reads, checks, codes, and routes them; makes payment vouchers and audit packs; posts Draft bills to the firm's Xero files when the firm connects them, or makes ledger files; keeps the records and their audit trail, and exports an MCST's records for a handover. Answers people's questions in Ask Proppy, which only reads; the same AI model checks a sample of its answers automatically, and a weekly report to Proppy's team lists answers by ID only |
| How long | For the firm's retention period, as section 7 says. Ask Proppy's conversations: 90 days from the conversation's last use |
Annex 2: security measures
- Encryption in transit, with TLS, and at rest, for the database, files, and backups. Xero sign-in tokens are encrypted again, with a key only Proppy has.
- Each firm's data kept apart: every query is limited to the signed-in person's firm, tested on every route.
- Row level security on every table, so the database's own public interface can't read any of it.
- Ask Proppy reads the firm's records through a read-only database account, limited by row level security to the signed-in person's firm, and, for an auditor, a condo manager, or a council member, to their MCSTs.
- Sign-in with a password of at least 8 characters, for each person, with their email address confirmed first. There's no second sign-in step (two-factor).
- Roles with least privilege, set by the firm. An auditor sees only the MCSTs the firm gives them.
- Sessions that end after the firm's idle time, 4 hours by default, and after the firm's longest sign-in, 12 hours by default.
- Rate limits on every request, sign-in attempts, invitations, uploads, and exports.
- An append-only audit log of every change, approval, posting, and support visit.
- NRIC numbers masked in what Proppy reads from documents.
- Logs that name documents by ID and fields by name, never their contents.
- Error reports without invoice contents or personal data.
- Daily database backups, a nightly copy of files with a second provider, and a restore test every 3 months.
- Support access that's read-only, time-limited, logged, and visible to the firm.
- A written plan for handling a data breach, and a Data Protection Officer at james@talktoproppy.com.
Annex 3: service providers
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, sign-in, and invoices' files | Singapore |
| Railway | Runs the app, and keeps a backup copy of invoices' files | Singapore |
| Google, through its paid AI service | Reads invoices, and writes Ask Proppy's answers and checks a sample of them | Any country where Google has facilities, such as the United States |
| Resend | Sends sign-in and invitation emails, and emails telling a condo manager how many invoices wait for them to confirm the work, with a link and nothing from the invoices, and receives the invoices emailed to Proppy's addresses where the firm uses them | Sends from Japan; keeps its records in the United States |
| Sentry | Reports of errors in the app, with no invoice contents or personal data | Germany (Sentry's EU region) |
| Zoho | Proppy's own email, for anything the firm emails Proppy, such as a support request | Singapore |
Proppy uses only Google's paid AI service. Google's terms for it don't let Google use the content to improve its products, bind Google by its data processing terms, and let it keep the content for a limited time only to detect misuse and meet legal requirements.