Legal

Broad Table, Inc. Data Processing Addendum

Last updated August 5, 2026Version 08052026

This Data Processing Addendum ("DPA") supplements and is incorporated into the Broad Table, Inc. Terms & Conditions or other written agreement between Broad Table, Inc. ("Broad Table," "we," "us," or "our") and the customer or account owner that uses the Closivo Platform ("Customer," "you," or "your") (the "Agreement"). This DPA applies only to the extent Broad Table processes Customer Personal Data on behalf of Customer in connection with the Closivo Platform, and applies whether or not it has been separately signed.

1. Definitions

"Customer Personal Data" means personal information, personal data, or similar regulated information included in Customer Data that Broad Table processes on behalf of Customer. "Data Protection Laws" means privacy, data protection, and security laws applicable to Broad Table's processing of Customer Personal Data in its capacity as a processor, service provider, contractor, or subprocessor. Data Protection Laws do not include laws that apply solely because of Customer's industry, professional or licensing status, location, regulated activities, or independent use of Customer Data, unless those laws separately apply to Broad Table in that capacity. "Subprocessor" means a third party engaged by Broad Table that processes Customer Personal Data on Broad Table's behalf in order to provide or support the Closivo Platform, and does not include a Third-Party Service that Customer connects, authorizes, or directs under the Agreement.

"Security Incident" means a confirmed unauthorized acquisition, access, use, alteration, loss, destruction, or disclosure of Customer Personal Data in Broad Table's possession or control. A Security Incident does not include unsuccessful access attempts, port or vulnerability scans, pings, failed log-in attempts, denial-of-service attempts that are blocked or do not compromise data, or incidents confined to systems, credentials, devices, or connected accounts controlled by Customer or its users.

"Controller," "processor," "business," "service provider," "contractor," "consumer," "personal information," "personal data," "sell," "share," and similar terms have the meanings given under applicable Data Protection Laws.

2. Roles and scope

For Customer Personal Data, Customer acts as a controller or business, or as a processor or service provider acting under the documented instructions of another controller or business, in which case Customer represents that it has authority to appoint Broad Table as a subprocessor and to give the instructions set out in this DPA, and Broad Table acts as a processor, service provider, contractor, or subprocessor, as applicable to Customer's role.

Broad Table acts as an independent controller or business only with respect to personal information it collects for Broad Table's own account administration, billing and collections, platform and account security, fraud prevention, service and legal communications, legal and regulatory compliance, and corporate operations; service usage, telemetry, diagnostic, performance, and product analytics information generated through operation of the Platform; personal information collected from visitors to Broad Table's public-facing websites; and personal information that an individual provides directly to Broad Table in creating or maintaining their own user account, in accepting Broad Table's terms, in communicating with Broad Table, or in exercising a choice Broad Table makes available to them, together with Broad Table's records of those interactions. Broad Table will not treat Customer Personal Data as independent-controller data for analytics, product improvement, model development, benchmarking, or marketing except to the extent that information has been de-identified or aggregated in accordance with Section 10 and applicable law. Broad Table's use of identifiable Customer Personal Data is limited as described in Section 10.

The parties acknowledge that the allocation of roles under Data Protection Laws is determined by the facts of the processing and not solely by the labels used in this DPA.

3. Customer instructions

Customer instructs Broad Table to process Customer Personal Data as described in Annex A (Details of Processing) and to provide, maintain, secure, support, troubleshoot, and administer the Closivo Platform; to enable integrations and customer-configured workflows; to comply with law and legal process; to prevent fraud, abuse, and security incidents; and as otherwise permitted by the Agreement and this DPA. Customer is responsible for ensuring that its instructions comply with Data Protection Laws.

4. Customer responsibilities

Customer is responsible for providing required notices, obtaining required consents and authorizations, maintaining a lawful basis for processing, responding to privacy rights requests where Customer controls the data, configuring user permissions and integrations, ensuring data accuracy, and not submitting restricted data except as expressly supported by the applicable Closivo Service or approved in writing by Broad Table.

5. Broad Table obligations

Broad Table will process Customer Personal Data only for the purposes described in this DPA, the Agreement, applicable product documentation, and Customer's lawful instructions.

Broad Table will require personnel, contractors, and Subprocessors with access to Customer Personal Data to be subject to written confidentiality obligations, and will limit access to those who need it to perform their role. Broad Table will maintain commercially reasonable administrative, technical, physical, and organizational safeguards appropriate to the nature and sensitivity of Customer Personal Data and the reasonably foreseeable risks to it, as required by applicable Data Protection Laws. Specific controls, certifications, retention periods, and testing commitments apply only if set out in a security measures exhibit or other agreement signed by a Broad Table Officer.

If Broad Table determines that it can no longer meet a material obligation under this DPA, or an obligation that applicable Data Protection Laws require Broad Table to notify Customer about, Broad Table will notify Customer without undue delay.

6. Subprocessors

Customer authorizes Broad Table to engage Subprocessors to provide and support the Closivo Platform, including hosting, infrastructure, database, analytics, payment, communications, authentication, security, support, AI and automation, logging, and monitoring providers, and software development and support personnel.

Broad Table will maintain a current list of Subprocessors and will make it available to Customer on reasonable written request, subject to confidentiality obligations. Customer generally authorizes Broad Table to engage and replace Subprocessors.

Where applicable Data Protection Laws require advance notice of a new Subprocessor, Broad Table will provide that notice by the means and within the period the applicable law requires, and in the absence of a specified period, at least fifteen (15) days in advance by email to Customer's administrative contact or by in-product notice.

Broad Table may engage a replacement Subprocessor immediately, without advance notice, where reasonably necessary for security, legal compliance, service availability, or business continuity, and will provide notice as soon as reasonably practicable where notice is required. Otherwise, Customer may object to a new Subprocessor within fifteen (15) days of notice on reasonable, documented data-protection grounds. If Customer objects, Broad Table may, at its option, decline to engage the Subprocessor for Customer's data, propose a commercially reasonable change to the affected processing or configuration, or, if neither is reasonably practicable, terminate only the affected Closivo Service on notice. Termination under this paragraph does not affect any other Closivo Service. A termination by Broad Table under this paragraph is treated as a termination for convenience under the "Payment and Cancellations" section of the Agreement, and the pro-rata refund of prepaid, unused fees for the affected Closivo Service described there is Customer's sole and exclusive remedy for that termination. No other refund, credit, damages, or remedy is available except as expressly required by applicable law.

Broad Table will impose on each Subprocessor, by written contract, data protection obligations required by applicable Data Protection Laws and appropriate to the services and processing involved, including obligations of confidentiality and security and, where required, obligations corresponding to those in this DPA. Where a Subprocessor performs services through its own affiliates, subcontractors, or personnel, Broad Table will require the Subprocessor to remain responsible for their acts and omissions to the extent applicable Data Protection Laws require. Broad Table remains responsible for its Subprocessors' processing of Customer Personal Data to the extent required by applicable Data Protection Laws, in all cases subject to the exclusions and limitations of liability in the Agreement and Section 16.

A Subprocessor may engage its own subcontractors. Broad Table's obligation with respect to those subcontractors is to require the Subprocessor to impose equivalent data protection obligations on them and to remain responsible for their performance. Broad Table does not identify a Subprocessor's own subcontractors, and any Subprocessor list Broad Table provides covers only the Subprocessors that Broad Table engages directly.

Where a Subprocessor is contracted through an entity in one country but performs work through personnel or affiliates in another, any Subprocessor list Broad Table provides will identify the countries from which Customer Personal Data is actually accessed, not only the country of the contracting entity.

A Third-Party Service that Customer connects, authorizes, or directs, including an accounting system such as Xero, is not a Subprocessor of Broad Table. Data that flows to such a service flows at Customer's direction and under Customer's relationship with that provider.

Broad Table will not knowingly authorize a Subprocessor that provides artificial intelligence or automation services to use identifiable Customer Personal Data to train a generally available model. Broad Table may engage such providers under enterprise, API, no-training, zero-retention, or comparable contractual settings appropriate to the processing. If a provider's terms or practices materially cease to satisfy Broad Table's obligations under this DPA, Broad Table may suspend, restrict, replace, or discontinue the affected functionality, and has no obligation to continue using any particular provider.

7. Consumer and data subject requests

Broad Table will provide reasonable assistance, taking into account the nature of the processing and the information available to Broad Table, to help Customer respond to consumer or data subject requests that Customer is required to honor under Data Protection Laws, including requests to access, correct, delete, or obtain a portable copy of personal information, and requests to opt out where applicable. If Broad Table receives a request relating to Customer Personal Data controlled by Customer, Broad Table may direct the requester to Customer or notify Customer where appropriate and legally permitted. Broad Table will provide assistance available through the standard functionality of the applicable Closivo Service at no additional charge. Assistance that is extraordinary, customized, duplicative, or engineering-intensive may be charged at Broad Table's then-current professional services rates, except where applicable law requires Broad Table to bear the cost.

8. Security incidents

Broad Table will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data processed by Broad Table on Customer's behalf.

The notice will include the information reasonably available to Broad Table at the time and reasonably necessary for Customer to meet its legal obligations, and may be supplemented in phases as the investigation develops. Broad Table will take reasonable steps to investigate, contain, and mitigate the incident and will reasonably cooperate with Customer's own legal obligations.

Customer is responsible for determining whether the incident requires notification to individuals, regulators, or other parties where Customer is the controller or business, and for making any such notification. Broad Table's notification or response to an incident is not an admission of fault or liability.

9. Deletion and return

Deletion or return at Customer's direction. At Customer's direction upon expiration or termination of the applicable services, or upon completion of the provision of those services, Broad Table will delete or return Customer Personal Data, except to the extent retention is required or permitted by applicable law. Broad Table will initiate deletion following a valid direction and will complete deletion from active systems in accordance with its commercially reasonable standard deletion procedures, subject to technical constraints, backup and disaster recovery cycles, legal holds, security requirements, and legally permitted or required retention. This obligation applies only to Customer Personal Data that Broad Table retains at the time it receives the direction, and does not require Broad Table to restore, reconstruct, or retrieve data from backup or disaster recovery media, or to produce data in a non-standard format or perform extraordinary engineering work without payment of a reasonable fee. If Customer gives no direction within thirty (30) days after expiration or termination, Customer instructs Broad Table to delete Customer Personal Data in accordance with Broad Table's standard retention and deletion procedures. This provision does not apply to data that has been lawfully de-identified or aggregated so that it is no longer Customer Personal Data. Subject to the foregoing, this obligation is not conditioned on Customer giving the direction within any particular period after termination. A fixed deletion timeline applies only if set out in an agreement signed by a Broad Table Officer.

Standard export window. To use Broad Table's standard post-termination export functionality, Customer must request it before termination or within thirty (30) days afterward. After that window, Broad Table has no obligation to produce data in any particular format, and any export Broad Table elects to provide may be subject to a reasonable fee for the engineering effort involved.

Absent direction. During the thirty (30) days following expiration or termination, if Customer has given no direction, Broad Table may delete, archive, de-identify, or restrict Customer Personal Data in accordance with the Agreement, the Privacy Policy, its backup practices, its retention schedule, and its legal and security obligations. After that period, the deemed instruction stated above applies. Broad Table may satisfy that instruction by deletion or by lawful de-identification, in accordance with its standard retention and deletion procedures, which may provide for a period of archival or restricted retention before deletion or de-identification occurs. Broad Table may also retain Customer Personal Data as otherwise described in this Section 9. Customer remains responsible for exporting Customer Data it needs before termination.

Broad Table may retain Customer Personal Data where required by law, legal process, legal hold, dispute preservation, security, fraud prevention, accounting, tax, or backup obligations. Retained data remains subject to this DPA and will not be actively processed for other purposes.

To the extent of any conflict, this Section 9 controls over the statement in the Agreement that Broad Table has no obligation to return or export Customer Data after termination.

10. De-identified, aggregated, and derived data

Broad Table may create and use de-identified, anonymized, or aggregated data, operational insights, benchmarks, statistics, and learnings derived from Customer Data and Platform usage for lawful business purposes, including analytics, product improvement, security, fraud prevention, AI and automation, and service development, provided that such data is not used to identify Customer or an individual except as permitted by law.

Broad Table may process identifiable Customer Personal Data only to provide, maintain, secure, support, troubleshoot, administer, and evaluate the Closivo Services for the account that supplied it, and to detect, investigate, and prevent security incidents, fraud, and abuse. Broad Table may apply a signal or indicator derived from that activity to protect other customers and the Platform, but will not disclose the underlying identifiable Customer Personal Data to another customer.

Broad Table will not use identifiable Customer Personal Data to train or improve any model, system, benchmark, or dataset whose learnings are applied for other customers. Cross-customer product improvement, analytics, benchmarking, and model development use only de-identified or aggregated data, and Broad Table will apply commercially reasonable measures designed to prevent the resulting outputs from being attributable to a particular customer, will not attempt to re-identify that data, and will not provide it to any third party for the purpose of re-identification. Broad Table will not sell Customer Personal Data.

11. Sensitive and restricted data

Customer may submit SSNs, EINs, and similar identity information only through features that expressly support such data, such as supported 1099 or identity-related workflows. Customer may submit bank account and routing information only through features that expressly support such data, and only in the fields provided for that purpose; Customer may not place financial account information in free-text fields, notes, or unsupported uploads. Documents submitted through, or received into a workspace by, the document intake features of a Closivo Service are supported uploads for purposes of this Section, and the exceptions for permitted commission and settlement information stated in the Agreement apply to this Section.

Customer may not submit protected health information, full payment card data, children's data, biometric identifiers used for identification, consumer reports, export-controlled technical data, or other restricted data unless Broad Table expressly agrees in a signed written agreement. The restricted data provisions of the Agreement, including any exceptions stated there for commission, settlement, closing, and transaction information received from a title company, settlement agent, escrow agent, or closing attorney in the ordinary operation of a Closivo Service, apply to this DPA.

12. Hosting location; access from outside the United States

Closivo's primary production environment and primary Customer Personal Data stores are hosted in the United States. Certain Subprocessors may process or temporarily store limited information, such as logs, error reports, support records, or AI processing requests, in other countries. Broad Table will identify those countries on reasonable written request.

Broad Table may permit personnel, contractors, and Subprocessors located outside the United States, including software development and support personnel located in Sri Lanka, to access Customer Personal Data stored in the United States for the purpose of building, maintaining, supporting, securing, and troubleshooting the Platform. That access is subject to written confidentiality obligations, role-based access controls, logging, and the safeguards described in Section 5. Remote access does not change the location of Broad Table's primary production stores, although access from another country may constitute processing of Customer Personal Data in that country under some laws. Broad Table will identify the countries from which such access occurs upon reasonable written request.

Customer may not intentionally offer the Platform to, or use the Platform to systematically process personal data of, individuals located outside the United States, or data governed by the data protection laws of a jurisdiction outside the United States, without Broad Table's prior written approval. Incidental information concerning a non-U.S. person in connection with a U.S. transaction does not by itself violate this restriction. Customer remains responsible for determining whether non-U.S. law applies to its use of the Platform and for obtaining any required approval. If Broad Table approves such use and applicable Data Protection Laws require a transfer mechanism, the parties will execute the applicable transfer addendum, Standard Contractual Clauses, or other mechanism required by law.

13. Audits and information requests

Upon reasonable written request, and no more than once in any twelve (12) month period unless a Security Incident affecting Customer Personal Data has occurred or applicable Data Protection Laws or a regulator require otherwise, Broad Table will provide information reasonably necessary to demonstrate compliance with this DPA.

Broad Table will ordinarily satisfy such requests through existing documentation, written responses, completed security questionnaires, and independent audit or assessment reports where available. Any additional review will be conducted remotely and only to the extent reasonably necessary to satisfy an express requirement of applicable Data Protection Laws.

No customer, auditor, or assessor has a right to enter Broad Table's or a Subprocessor's facilities, access production or administrative systems, inspect source code, conduct penetration testing or vulnerability exploitation, interview personnel, or review raw configurations or logs, unless a regulator or applicable law expressly requires it and no reasonable documentary or remote alternative is sufficient, or Broad Table separately agrees in writing. In no case will any assessment extend to another customer's data or Confidential Information. Customer bears all costs of any assessment unless a final determination by a regulator, a tribunal of competent jurisdiction, or an independent assessor the parties mutually agree upon establishes material noncompliance by Broad Table. Expanded assessment rights, including on-site rights, apply only if set out in an agreement signed by a Broad Table Officer.

14. CCPA/CPRA service provider and contractor terms

This Section 14 applies to the extent the California Consumer Privacy Act, as amended, and its implementing regulations (collectively, the "CCPA") apply and Broad Table processes Personal Information on behalf of Customer as a service provider or contractor.

Customer makes Personal Information available to Broad Table only for the limited and specified business purposes described in the Agreement, this DPA, and Annex A, which the parties agree are specific and not generic.

Broad Table will:

  • not sell or share such Personal Information;
  • not retain, use, or disclose such Personal Information for any purpose other than the business purposes specified in the Agreement, this DPA, and Annex A, including not retaining, using, or disclosing it for a commercial purpose other than those business purposes, except as otherwise permitted by the CCPA;
  • not retain, use, or disclose such Personal Information outside the direct business relationship between Broad Table and Customer, except as permitted by the CCPA;
  • not combine such Personal Information with personal information received from or on behalf of another person, or collected from Broad Table's own interactions with a consumer, except as permitted by the CCPA;
  • comply with the obligations applicable to it under the CCPA and provide the same level of privacy protection as the CCPA requires of a business with respect to such Personal Information;
  • notify Customer without undue delay if Broad Table determines that it can no longer meet its obligations under the CCPA with respect to such Personal Information;
  • provide reasonable assistance to Customer in responding to verifiable consumer requests, and in cooperating with cybersecurity audits, risk assessments, and automated decision-making obligations to the extent applicable to the processing and required of Customer under the CCPA; and
  • engage subcontractors that process such Personal Information only under a written contract that imposes obligations substantially equivalent to those in this Section 14.

Customer may take reasonable and appropriate steps to confirm that Broad Table's use of such Personal Information is consistent with Customer's obligations under the CCPA. Broad Table will cooperate with those steps, including by responding to reasonable written inquiries and questionnaires and providing available documentation. This right exists independently of Section 13. Customer will exercise it subject to reasonable confidentiality, security, non-disruption, scheduling, and cost-allocation procedures, using documentary and remote methods where sufficient, and without access to source code, production systems, or another customer's data, provided that those procedures do not materially prevent Customer from exercising a right that applicable law requires Broad Table to grant. Upon written notice from Customer identifying an unauthorized use of such Personal Information, Broad Table will take reasonable and appropriate steps to stop and remediate that use.

To the extent Broad Table acts as a contractor, Broad Table certifies that it understands the restrictions in this Section 14 and will comply with them.

If Broad Table receives a subpoena, court order, warrant, civil investigative demand, or other compulsory legal process seeking Customer Personal Data, Broad Table will, unless legally prohibited or where an emergency involving risk to life or safety makes it impracticable, notify Customer before responding, provide Customer with a copy of the process where permitted, and direct the requesting party to Customer where appropriate. Broad Table will disclose only the information it reasonably believes is legally required. Broad Table has no obligation to object to, challenge, narrow, or seek to quash any process, and nothing in this Section requires Broad Table to delay or decline compliance with binding legal process. Costs of responding are allocated as provided in the “Third-Party Legal Process” section of the Agreement.

16. Liability

To the maximum extent permitted by applicable law, each party's liability arising out of or relating to this DPA is subject to the exclusions, disclaimers, and limitations of liability set out in the Agreement, and all claims under this DPA and the Agreement together are subject to those limitations in the aggregate. Claims arising under this DPA, and claims arising from a security incident affecting Customer Personal Data, are subject to the aggregate limit in the “Limitation of Liability” section of the Agreement, regardless of how the claim is characterized. No separate or elevated limit applies unless expressly stated in an agreement signed by a Broad Table Officer.

17. Order of precedence

This DPA is incorporated into the Agreement, whether or not it has been separately signed. If there is a conflict between this DPA and the Agreement, this DPA controls solely with respect to Broad Table's obligations as a processor, service provider, contractor, or subprocessor in processing Customer Personal Data on Customer's behalf. All other terms of the Agreement remain in effect. A data processing addendum signed by a Broad Table Officer, as defined in the Agreement, controls over this posted DPA to the extent of any conflict, and a description of product functionality or a supported data type in the Agreement is not a conflict with this DPA.

18. Contact

Broad Table, Inc.
790 Florida St, Ste 3
Mandeville, LA 70448
Email: legal@broadtable.co

Annex A

Details of Processing

The processing described below is for the Real Estate Commission Application. Additional Closivo Services may be covered by a supplemental annex incorporated into this DPA.

Item Description
Subject matter Provision, operation, support, security, troubleshooting, and account-specific evaluation of the subscribed Closivo Services, together with product improvement in accordance with Section 10. The remainder of this Annex describes processing for the Real Estate Commission Application; additional Closivo Services may be covered by a product-specific processing schedule, an order form processing description, an in-product data processing notice, or a supplemental annex incorporated into this DPA.
Duration The subscription term, plus the retention periods described in the Agreement, this DPA, and the Privacy Policy, subject to backup cycles and legally required retention.
Nature of processing Collection, receipt of documents by upload and by email from senders the Customer has approved, or, where the Customer enables that setting, from other senders, hosting, storage, organization, parsing and extraction from documents, calculation, classification, reconciliation, generation of workflow records, synchronization with customer-connected systems, transmission to customer-designated recipients, support, security monitoring, logging, de-identification, restriction, and deletion.
Purposes of processing Deal intake, including receipt, holding, and review of documents and related information sent to Customer's workspace by third parties where intake features are enabled; commission calculation, allocation, and split determination; generation of commission disbursement authorizations and related workflow documents; generation and synchronization of accounts receivable and accounts payable records; accounting system synchronization; approval routing; payout tracking and status display; 1099 and identity workflows (conditional); payment initiation (conditional); customer support; security, fraud prevention, and abuse prevention; and integrations that Customer connects or directs.
Categories of data subjects Customer personnel and administrators; brokers; real estate agents and contractors affiliated with Customer; payees including agents, referral parties, franchises, and vendors; title company, settlement, and escrow personnel; closing attorneys; and transaction counterparties and other persons whose information Customer submits, whose information is received from Customer's connected systems, or whose information is contained in or accompanies documents sent to Customer's workspace through intake features, including the senders of those documents.
Categories of personal data Names, business contact information, usernames and account credentials, roles, permissions, and brokerage affiliation; property and transaction details; commission, split, deduction, and payout information; documents submitted by upload or by email, or received into a workspace through intake features, relating to a transaction, together with associated sender information, including listing agreements, purchase contracts, inspection reports, disclosures, closing disclosures, and settlement statements, together with any information those documents contain; invoices, bills, and receivable and payable records; account and field mappings; support and communications records; system, authentication, and integration logs and device, browser, and IP information, in each case to the extent included in Customer Data; and configuration data.
Sensitive or special categories Authentication identifiers, tokens, role and permission records, and credential-related metadata. SSNs and EINs, where submitted through supported identity and 1099 workflows (conditional) or where contained within a document submitted to a workspace. Financial account information, where submitted through supported payment functionality (conditional) or where contained within a document submitted to a workspace. Broad Table does not require or request sensitive information within submitted documents. Automated document processing, including optical character recognition, text extraction, parsing, and AI-assisted processing, may process some or all of the content of a submitted document. Broad Table does not intentionally identify, index as a dedicated field, use, or display sensitive information appearing incidentally within a document, except as reasonably necessary for a supported feature, security, troubleshooting, legal compliance, or Customer-authorized support.
Frequency of processing Continuous for hosting, logging, and security; otherwise as initiated by Customer, its authorized users, its connected systems, or scheduled synchronization.
Retention As described in the "Data retention" section of the Privacy Policy and Section 9 of this DPA. Financial and tax records, including 1099-related identity information, may be retained for the period required by law or standard business practice.
Subprocessor categories Cloud hosting and infrastructure; database and storage; authentication; logging, monitoring, and error reporting; analytics and product experience; email and communications; customer support tooling; AI and automation providers; payment processing (conditional); and software development and support personnel, including personnel located in Sri Lanka. The current Subprocessor list is available on reasonable written request.

Scroll horizontally to see the full table on smaller screens.