Data Processing Addendum
Effective 2026-08-11.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between ParkDwell, Inc. (“ParkDwell,” “Processor”) and the customer organisation (“Customer,” “Controller”). It governs ParkDwell’s processing of Personal Data on the Customer’s behalf.
1. Roles
The Customer is the Controller of Personal Data relating to its residents, guests, staff, and parkers. ParkDwell is the Processor of that data and processes it only on the Customer’s documented instructions.
Use of the Service constitutes the Customer’s instruction to process Personal Data as necessary to provide it. ParkDwell is a separate Controller for account, billing, and support data relating to the Customer’s own personnel; that processing is described in the Privacy Policy.
2. Subject matter and scope
| Subject matter | Provision of the parking management Service. |
| Duration | The term of the Terms of Service, plus the deletion period in Section 9. |
| Nature and purpose | Hosting, storage, and processing to administer parking: permits, spot assignments, waitlists, bookings, payments, access control, enforcement records, and notifications. |
| Categories of data subject | Residents, guests and visitors, parkers, and the Customer’s staff. |
| Categories of Personal Data | Name, email address, phone number, unit or address, vehicle registration (licence plate) and description, photographs of vehicles taken during patrol, permit and reservation records, payment method references and transaction history, gate access events, IP address and device information. |
| Special categories | None are required by the Service. The Customer must not upload special-category data (such as health or biometric data). Accessible-parking designations are recorded as a property of a space, not a person. |
3. ParkDwell’s obligations
- Process Personal Data only on the Customer’s documented instructions, unless required by law — in which case we will notify the Customer unless legally prohibited.
- Ensure personnel with access are bound by confidentiality obligations.
- Implement the technical and organisational measures described in Section 5.
- Assist the Customer in responding to data subject requests (Section 7).
- Assist with data protection impact assessments and regulator consultations, taking into account the nature of processing and the information available to us.
- Make available the information reasonably necessary to demonstrate compliance (Section 8).
- Not sell Personal Data, not share it for cross-context behavioural advertising, and not retain, use, or disclose it for any purpose other than performing the Service — as those terms are defined under the CCPA/CPRA.
4. Customer’s obligations
The Customer is responsible for:
- Having a lawful basis for the Personal Data it enters or generates, and providing any required notice to residents, guests, and parkers.
- The lawfulness of its parking rules and any enforcement action, including signage, notice periods, appeal rights, and towing authorisation. See Section 4 of the Terms.
- Configuring roles so staff see only what their duties require.
- Obtaining consent where required — in particular for SMS. The Service records SMS consent per individual and will not send to anyone who has not opted in.
- Responding to data subject requests from its residents and parkers as Controller.
5. Security measures
- Encryption — in transit (TLS) and at rest.
- Tenant isolation — enforced at the database layer, so records belonging to one property are not readable by another. This boundary is covered by an automated test suite.
- Access control — role-based permissions; least-privilege internal access; support access is scoped and audited.
- Audit logging — privileged actions are recorded with the acting account, timestamp, IP, and user agent.
- Payment data — handled by Stripe (PCI DSS Level 1). Full card numbers never reach ParkDwell systems.
- Backups — automated database backups with point-in-time recovery, and a documented restore procedure.
- Rate limiting and abuse controls on public endpoints.
6. Subprocessors
The Customer authorises ParkDwell to engage subprocessors. Our current list is published at parkdwell.com/subprocessors, covering hosting, database and authentication, payment processing, email and SMS delivery, licence-plate recognition, and error monitoring.
We will give at least 30 days’ notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Customer may terminate the affected part of the Service without penalty. We remain liable for our subprocessors’ performance.
7. Data subject requests
The Service provides self-service tools so the Customer can respond directly: an organisation-wide data export from the admin console, an individual export for each resident, and the ability to correct or remove records.
If we receive a request directly from one of the Customer’s data subjects, we will refer them to the Customer and will not respond substantively except to confirm the referral, unless legally required. We will assist the Customer where the tools above are insufficient.
Erasure has limits. Financial records (charges, refunds, ledger entries) are retained where required by tax and accounting law even after an erasure request; in that case we restrict processing rather than delete. Where a resident holds an active permit, the Customer must reassign or end that permit before their records can be removed.
8. Audits
On reasonable written request, and no more than once in any twelve-month period (unless required by a regulator or following a Security Incident), we will provide information reasonably necessary to demonstrate compliance with this DPA. Where available we will satisfy audit requests by providing third-party reports or completed security questionnaires. On-site audits are by agreement, at the Customer’s expense, and subject to confidentiality.
9. Return and deletion
The Customer may export its data at any time during the term. On termination, the Customer has 30 days to export. After that, we will delete Personal Data within 90 days, except where retention is required by law (Section 7) or where data exists in routine backups — which are overwritten on their normal cycle and remain protected by this DPA until then.
10. Security incidents
We will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a breach affecting the Customer’s Personal Data. The notice will describe what we know: the nature of the incident, categories and approximate number of records affected, likely consequences, and the measures taken. We will provide updates as the investigation develops and cooperate with the Customer’s own notification obligations. Notification is not an acknowledgement of fault.
11. International transfers
ParkDwell and its subprocessors process Personal Data in the United States. For transfers of Personal Data from the EEA, UK, or Switzerland, the parties incorporate the European Commission’s Standard Contractual Clauses (Module Two, Controller to Processor) and, for the UK, the ICO’s International Data Transfer Addendum. Where they apply, the SCCs prevail over this DPA in the event of conflict.
12. General
This DPA supplements the Terms of Service. In the event of conflict on the subject of data protection, this DPA prevails. Liability is subject to the limitations in the Terms. This DPA terminates automatically with the Terms, subject to the survival of Sections 7–9.
13. Contact
Privacy and data protection: privacy@parkdwell.com. To request a countersigned copy of this DPA, contact legal@parkdwell.com.
Questions? Email legal@parkdwell.com.