Data Processing Addendum

Last updated: July 20, 2026

This Data Processing Addendum (“DPA”) forms part of the service agreement between Hybrid Capital Group LLC (“Provider”) and each brokerage organization using the Hybrid platform (“Customer”), and applies to personal data the Provider processes on the Customer’s behalf.

1. Roles

For personal data the Customer and its users submit to the Platform — including member accounts, borrower contact details, and deal information — the Customer is the controller (it decides why and how the data is used) and the Provider is the processor, acting on the Customer’s documented instructions. The Provider acts as an independent controller only for its own account records and platform security logs.

2. Details of processing

  • Subject matter and purpose — operating a commercial loan referral platform: account management, deal submission and pipeline tracking, document storage, commission tracking, notifications, and prospect research.
  • Duration — the term of the Customer’s service agreement, plus the wind-down period described in Section 8.
  • Categories of data subjects — the Customer’s members (agents, managers, administrators), borrowers, and business contacts surfaced by prospect research.
  • Categories of personal data — names, email addresses, phone numbers, company details, deal and property information, uploaded documents, and business contact details. The Platform is not designed to process government IDs, financial account numbers, or other sensitive categories, and the Customer agrees not to submit them outside fields intended for that purpose.

3. Provider obligations

  • Process personal data only on the Customer’s documented instructions, including as configured through the Platform, unless required by law.
  • Ensure personnel authorized to process personal data are bound by confidentiality.
  • Implement and maintain the technical and organizational measures in Section 5.
  • Assist the Customer, taking into account the nature of processing, with data subject requests and with the Customer’s compliance obligations regarding security and breach notification.
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

4. Subprocessors

The Customer authorizes the Provider to engage the following subprocessors, each bound by data protection obligations no less protective than this DPA:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and delivery.
  • Resend — transactional email delivery.
  • Slack — operational notifications to the platform team.
  • Commercial data providers (property, business listing, and contact enrichment services) — prospect research performed at the Customer’s direction.

The Provider will give the Customer advance notice of new subprocessors handling Customer personal data, and the Customer may object on reasonable data protection grounds.

5. Security measures

  • Encryption of personal data in transit (TLS) and at rest.
  • Tenant isolation enforced at the database layer with row-level security: every query is scoped to the requesting user’s role and organization.
  • Role-based access control across distinct user portals; administrative access on a least-privilege basis.
  • Hashed credentials; secrets held in managed environment configuration, not in code.
  • Audit trails of deal stage changes; soft-deletion with controlled permanent removal.

6. Personal data breaches

The Provider will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably required for the Customer to meet its own notification obligations.

7. Data subject requests

If a data subject contacts the Provider directly about data controlled by the Customer, the Provider will forward the request to the Customer without undue delay and assist with fulfilling it through the Platform’s tools.

8. Return and deletion

On termination of the service agreement, the Customer may request an export of its data. After a reasonable wind-down period, the Provider deletes Customer personal data from production systems, except where retention is required by law, with backups expiring on their normal rotation schedule.

9. Processing location

Personal data is processed in the United States by the Provider and the subprocessors listed above. If processing of data subject to international transfer restrictions is required in the future, the parties will put in place an appropriate transfer mechanism before such processing begins.

10. Liability and order of precedence

Each party’s liability under this DPA is subject to the limitations of liability in the service agreement. If this DPA conflicts with the service agreement on data protection matters, this DPA controls.

11. Contact

Hybrid Capital Group LLC
8785 Sawgrass Way, Duluth, GA, 30097, USA
support@hybridcre.com