← My 5th Star

Data Processing Agreement

Last updated: 28 July 2026

This DPA applies to every customer and forms part of the Terms of Service. It is the agreement required by Article 28 GDPR between you (the controller) and us (the processor). No signature is required — it applies automatically — but we will sign a countersigned copy on request.

1. Parties

This agreement is between Elit Virtual LLC, 1942 Broadway, Ste 314C, Boulder, CO 80302, USA, which operates the My 5th Star platform (“we”, the processor), and the customer subscribing to that platform (“you”, the controller). It takes effect when you create an account and continues for as long as we process personal data on your behalf.

2. Roles

You are the controller of the personal data you put into the service — your leads, clients, enquirers and team members. We are the processor. We process that data only on your documented instructions, which for normal use means: operating the service as described in our documentation and interface.

Where we act as controller of our own account and billing data, our Privacy Policy applies instead.

3. Subject matter and duration

We process personal data for as long as you have an account, and for the limited period afterwards described in clause 10.

4. Nature and purpose of processing

Receiving enquiries from your connected channels; generating and sending replies on your behalf using AI; recording enquirer details in your CRM; scheduling viewings; making and transcribing voice calls where you enable that; producing marketing content and reports.

5. Categories of data and data subjects

  • Data subjects: your leads, clients and enquirers; your employees and agents.
  • Data: names, phone numbers, email addresses, message content, budget and property requirements, appointments, notes, and — where voice calling is enabled — call recordings, transcripts and summaries.
  • Special categories: the service is not designed for special-category data under Article 9. Do not put it in.

6. Our obligations

  • Process personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case we tell you first, unless the law forbids it.
  • Ensure everyone authorised to process the data is under a duty of confidentiality.
  • Implement the technical and organisational measures in clause 8.
  • Respect the conditions in clause 7 for engaging sub-processors.
  • Assist you, so far as we reasonably can, in responding to data subject requests.
  • Assist you with your obligations under Articles 32 to 36 (security, breach notification, impact assessments).
  • Delete or return the data at the end of the service, at your choice.
  • Make available the information needed to demonstrate compliance, and allow audits as set out in clause 11.

7. Sub-processors

You give general authorisation for us to engage the sub-processors listed at /subprocessors. We will give at least 30 days’ notice by email before adding a new one that processes personal data. If you reasonably object on data protection grounds within that period, and we cannot offer an alternative, you may terminate the affected part of the service without penalty for the remainder of the term.

Each sub-processor is bound by obligations no less protective than those in this DPA.

8. Security measures

  • Encryption in transit (TLS) and at rest.
  • Tenant isolation: every record is scoped to your account, enforced on each request.
  • Row-level security on the database.
  • Passwords hashed with bcrypt; role-based access; signature-verified webhooks.
  • Rate limiting and abuse protection on public endpoints.
  • Least-privilege access to production data, limited to personnel who need it.
  • Backups managed by our hosting provider, restorable point-in-time.

9. International transfers

Data is stored and the application runs in the EU (Paris). Some sub-processors are outside the EEA; those transfers rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914) together with supplementary measures, or on an adequacy decision.

Be aware: by default the AI model that generates replies is operated by DeepSeek and processes data in China, which has no adequacy decision. If this is not acceptable to you, tell us and we will switch your account to Mistral AI (France) so that model processing stays in the EU. We recommend deciding this before you go live.

10. Deletion and return

You can export or delete your data at any time from the application. On termination we delete your personal data within 90 days, except where we must retain it by law. Backups age out on their normal cycle.

11. Audits

On reasonable written notice, and no more than once a year unless required by a supervisory authority, we will answer a reasonable security questionnaire and provide available documentation. On-site audits are by agreement and at your cost.

12. Personal data breach

We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information we have, and we keep you updated as we learn more. Notifying the supervisory authority and the data subjects is your responsibility as controller; we will help.

13. Your responsibilities

  • Have a lawful basis for the data you put in and for the messages you send.
  • Give your own data subjects the privacy information they are entitled to, including that an AI assistant handles enquiries and that calls may be recorded.
  • Obtain consent where your local law requires it — call recording rules vary.
  • Keep your credentials secure and manage who on your team has access.

14. Contact

partners@my5thstar.com · +32 499 40 97 70 Elit Virtual LLC, 1942 Broadway, Ste 314C, Boulder, CO 80302, USA.