1. Purpose
This DPA governs the processing of personal data by Neighbourly Hub on behalf of the Controller in connection with the use of the Neighbourly Hub platform.
This Agreement is intended to ensure compliance with the Data Protection Act.
2. Definitions
- "Personal Data": Any information relating to an identifiable individual
- "Processing": Any operation performed on personal data (collection, storage, use, etc.)
- "Controller": The Complex determining purpose and means of processing
- "Processor": Neighbourly Hub processing data on behalf of the Controller
3. Scope of Processing
Neighbourly Hub shall process personal data for the purpose of:
- Providing the platform
- Managing resident and unit records
- Tracking payments and generating reports
- Supporting maintenance and booking workflows
- Ensuring system functionality and security
Processing includes:
- Storage
- Organisation
- Retrieval
- Transmission (where required)
4. Nature and Categories of Data
4.1 Categories of Data Subjects
- Residents
- Property owners
- Administrators
- Authorized users
4.2 Categories of Personal Data
- Names and contact details
- Unit/apartment information
- Payment and account records
- Maintenance and booking records
- System activity logs
5. Controller Obligations
The Controller shall:
- Ensure lawful collection of personal data
- Establish a valid legal basis for processing
- Provide privacy notices to data subjects
- Ensure data accuracy
- Define retention periods
- Control access to the platform
6. Processor Obligations
Neighbourly Hub shall:
- Process personal data only on documented instructions
- Not use personal data for its own purposes
- Implement appropriate technical and organisational measures
- Ensure confidentiality of personnel
- Assist the Controller with data subject requests (where reasonable)
7. Security Measures
Neighbourly Hub shall implement:
Technical Measures
- Encryption in transit (HTTPS)
- Authentication controls
- Role-based access
Organisational Measures
- Restricted administrative access
- Monitoring and logging
- Secure deployment processes
8. Sub-processors
Neighbourly Hub may engage sub-processors, including Render.
Neighbourly Hub shall:
- Ensure sub-processors meet appropriate security standards
- Enter into contractual agreements with sub-processors
The Controller authorises the use of such sub-processors.
9. International Transfers
Personal data may be processed outside Jamaica. Neighbourly Hub shall ensure:
- Appropriate safeguards are in place
- Transfers are limited to necessary processing
10. Data Breach
Neighbourly Hub shall:
- Notify the Controller without undue delay upon becoming aware of a breach
- Provide details of the breach and mitigation steps
The Controller shall be responsible for:
- Notifying affected individuals
- Reporting to regulatory authorities
11. Data Subject Rights
Neighbourly Hub shall, where reasonably required, assist the Controller in responding to:
- Access requests
- Correction requests
- Deletion requests
The Controller remains responsible for responding to such requests.
12. Data Retention & Deletion
Upon termination of services, Neighbourly Hub shall:
- Delete or return personal data (as instructed)
- Retain data only where legally required
13. Audit and Compliance
Neighbourly Hub shall make available information necessary to demonstrate compliance. Formal audits shall:
- Be reasonable in scope
- Not disrupt operations
- Be subject to confidentiality
14. Liability
Neighbourly Hub shall not be liable for:
- Data entered incorrectly by the Controller
- Unlawful collection of data by the Controller
- Misuse of data by authorised users
- Decisions made using platform data
Liability shall be limited to the maximum extent permitted by law.
15. Term
This DPA remains in effect for as long as the Controller uses the Neighbourly Hub platform.
16. Governing Law
This Agreement shall be governed by the laws of Jamaica.
17. Acceptance
By registering and using the Neighbourly Hub platform, the Controller:
- Confirms authority to act on behalf of the Complex
- Agrees to this Data Processing Agreement