leasesiftby Quoqo
What it readsHow it worksPricing
Log in
DATA PROCESSING SCHEDULE

How we process
data for you.

This schedule forms part of the Terms of Service between you and Quoqo, Inc. (USA), and is accepted when the Terms are accepted. No separate signature is needed: every LeaseSift customer is covered by it from the moment they have an account. It governs our processing of personal data contained in the documents you upload.

LAST UPDATED 18 September 2026VERSION 1.1SCHEDULE 1 TO THE TERMS OF SERVICE

Draft. This document is a draft pending review by our legal counsel. It describes how LeaseSift actually works today and we intend to be bound by it, but it has not yet been reviewed by a lawyer. Write to us if anything here matters to your decision.

What this document is

Terms defined in the Terms of Service have the same meaning here. Where this schedule and the Terms conflict on the processing of personal data, this schedule governs. Where this schedule and the Privacy Policy describe the same thing, they are intended to say the same thing; the Privacy Policy is the description and this schedule is the commitment.

Roles of the parties

You are the controller. You decide which lease documents to upload, why, and what to do with the results. In respect of personal data contained in those documents you are the controller under the GDPR and the Data Fiduciary under India's Digital Personal Data Protection Act, 2023.

We are the processor. Quoqo, Inc. processes that personal data on your behalf and on your instructions, as processor under the GDPR and Data Processor under the DPDP Act.

We are a controller in our own right for a narrow set of records, and this schedule does not apply to them:

DataWho decides
Personal data inside the documents you upload, and everything derived from them — extracted text, abstracts, counsel reviews, evidence passages, reports, the review audit trailYou (controller); we process for you
Your users' account records — name, email address, password hash, role, verification state, invitationsUs (controller), to provide and administer the service
Billing records — Stripe identifiers, subscription status, the package ledger, refund requestsUs (controller), including to meet tax and accounting obligations
Security records — event type, endpoint, IP address, user-agent — and error reportsUs (controller), to keep the service secure and working

The review audit trail records who changed which extracted field, and its previous and next values. Because those values come from your documents, the audit trail sits on the processor side of the line above even though it also identifies your own users.

Subject matter, duration, nature and purpose

Subject matter

Personal data contained in commercial lease documents and their amendments, attachments and related material that you or your users upload to LeaseSift, and in the abstracts, reviews, evidence passages, reports and records derived from them.

Duration

For as long as your account exists, and thereafter until the data is deleted in accordance with the Deletion section below.

Nature of the processing

Receiving uploaded files and storing them; extracting text, including by optical character recognition where a file has no text layer; sending document text or files to model providers and to Quoqo Counsel for analysis; structuring the results into an abstract and a counsel review with citations to the source passages; storing those results; recording the corrections and approvals your users make; generating reports; making the material available to your users and to anyone you share it with; and deleting it, on request or when your administrators delete it in the product.

Purpose

To provide the LeaseSift service to you, to support you in using it, to keep it secure, and to derive the de-identified metadata described below.

Categories of personal data

Whatever a commercial lease and its papers contain, which in practice is:

  • names of tenants, landlords, guarantors and, where a party is an individual, that person;
  • names and titles of signatories, witnesses, agents, brokers, property managers and named contacts;
  • postal addresses, including of premises and of individuals, and contact details such as email addresses and telephone numbers;
  • financial and commercial terms attributable to an identified person, such as rent, deposits and guarantee obligations;
  • occasionally, signatures, identification numbers or registration details that appear on the face of a document;
  • and, separately, your users' account data: name, email address, role.

LeaseSift is not designed for special-category or sensitive personal data, and the Terms ask you not to upload it beyond what a lease ordinarily contains.

Categories of data subject

Your personnel who use LeaseSift; the parties to the leases you upload and their personnel and representatives; and any other individual named in a document you upload.

Processing only on your instructions

We process personal data only on your documented instructions, including as to transfers to a third country. Your instructions are: the Terms of Service, this schedule, and your and your users' use of the features of the service — uploading a document, running an abstract, requesting a counsel review, sharing a report, asking us to delete something.

We will also process where we are required to by a law we are subject to. Where that law permits, we will inform you before processing.

We will tell you if, in our opinion, an instruction infringes applicable data protection law. We will not use personal data processed on your behalf for our own purposes, except as set out in the De-identified metadata section below.

Confidentiality of personnel

Access to personal data processed on your behalf is limited to personnel who need it to provide, support or secure the service. Those personnel are bound by written confidentiality obligations and by clause 11 of the Terms.

Platform operator accounts held by our staff have access across customer organisations for support and investigation. Ordinary customer accounts do not.

Security measures

We implement appropriate technical and organisational measures to protect personal data processed on your behalf, having regard to the state of the art, the cost of implementation and the nature, scope and purposes of the processing. The measures set out below are those in place today. They are a description of our current implementation and not a fixed or exhaustive list: security practice evolves, and so will these. We hold no security certification and have not been independently audited.

  • Tenant isolation in the database. Row-level security is enabled on the tables holding customer data. The application connects as a restricted database role that cannot bypass it, and each request pins its organisation for the duration of a single transaction, so a query cannot read another organisation's rows. On the lease and billing tables the policies are forced even against the table owner.
  • Per-user scoping. Where an organisation is configured to keep documents private to the person who uploaded them, that is applied in the query, not only in the interface.
  • Credentials. Passwords are stored as bcrypt hashes and never in plain text. Login timing is equalised so that accounts cannot be enumerated.
  • Account creation. No account, credential or reserved address exists until the email address has been proved by following an emailed single-use link.
  • Sessions. Sessions last 30 days, are carried in an HttpOnly, Secure, SameSite=Lax cookie that scripts cannot read, are destroyed on sign-out, and are all destroyed when a password is reset.
  • Tokens. Invitation and password-reset links are single-use, time-limited and stored only as hashes.
  • Document storage. Original files are held in a private object-storage bucket. No public or pre-signed URLs are issued; a file is served only through a route that authenticates the request first.
  • Encryption at rest — object storage. Every object in the Cloudflare R2 bucket holding original files, together with its metadata, is encrypted at rest with AES-256 under keys Cloudflare manages. Cloudflare applies this to all R2 objects automatically; it is not configurable by us and cannot be disabled. We hold no separate key, so this protects the stored objects against loss of the underlying media, not against Cloudflare or against compromise of our bucket credentials.
  • Encryption at rest — database and cache, where we make no claim. Extracted document text, abstracts, findings, the audit trail and a time-limited cache of analysis output are held in PostgreSQL and Redis operated by our hosting provider. That provider publishes no statement about encryption of the underlying volumes, so we make no representation that this data is encrypted at rest, and we do not encrypt it at the application layer today. We will state otherwise only when we can evidence it.
  • Transport. Traffic to the service and to every sub-processor is carried over TLS. Connections between the application, the database and the cache run inside our hosting provider's isolated private network and are not TLS-encrypted; the isolation is the measure there, not transport encryption.
  • Abuse controls. Requests are rate-limited, logins and signups are throttled, cross-site requests to sensitive routes are rejected, and security events are recorded.
  • Error reporting. Before an error report leaves our systems, the user, request, breadcrumbs, extra data and local variables are removed and every message and exception value is replaced with a fixed string, so that document contents cannot travel in a stack trace.
  • Least privilege in billing. The payment integration runs on a restricted key, and card details are never received by us.

We may add to or change these measures from time to time, provided that the overall level of protection is not reduced.

Sub-processors

You authorise us to engage the sub-processors below. Each is engaged under a written contract and we remain responsible to you for their performance. This list is the same list as in the Privacy Policy; the two are kept identical.

Sub-processorRoleRegion
RailwayApplication hosting, PostgreSQL database and Redis cache — all stored dataSingapore (asia-southeast1)
Cloudflare R2Object storage for original uploaded filesBucket location hint APAC
OpenAIModel provider: text extraction and analysis; optical character recognition of page images where a file has no text layerRegion not specified by us
GroqModel provider for general document analysis, where configuredRegion not specified by us
Quoqo CounselThe counsel review; receives document text or the original filesRegion not specified by us
StripePayments; collects and holds card and billing details directlyRegion not specified by us
ResendTransactional emailRegion not specified by us
SentryError reporting, on scrubbed eventsRegion not specified by us
Zoho DeskSupport mailboxRegion not specified by us

Notice of a change. Before we engage a new sub-processor that will receive personal data processed on your behalf, we will update this list and the Privacy Policy and notify your account admins by email or in the product at least 30 days beforehand. If you reasonably object on data protection grounds within that period, tell us at hello@quoqo.com; if we cannot offer a reasonable alternative, you may terminate the affected subscription and we will refund the unused part of any prepaid period.

International transfers

Personal data processed under this schedule moves as follows:

  • it is stored and processed on servers in Singapore;
  • original files are held in object storage with an APAC location hint;
  • it is accessible to our personnel in India, who operate and support the service;
  • the contracting entity is in the United States;
  • document content is transmitted to the model providers and to Quoqo Counsel, and email, payment and error-reporting data to the remaining sub-processors, in regions those providers determine.

We have not put standard contractual clauses in place and have not appointed a representative in the European Union. If your organisation requires a specific transfer mechanism, contact us at hello@quoqo.com before uploading personal data to which it applies.

Assistance: data subject requests and breaches

Data subject requests

The service lets your admins and users read, correct, export and delete the material in their organisation, which is the primary means of responding to a request. An administrator can delete a document and everything derived from it, and can erase a user; what that does and does not remove is set out under Deletion and return below. Where a request cannot be answered that way, we will use commercially reasonable efforts to assist you, on reasonable notice and to an extent proportionate to the nature of the processing, the information available to us and the resources of a company of our size.

If a request about data we process on your behalf comes to us directly, we will not respond to it ourselves, except to tell the individual to contact you. We will forward it to your account admins promptly.

Personal data breaches

We will notify your account admins of a personal data breach affecting personal data processed on your behalf without undue delay after we become aware of it. The notification will describe what we know at the time: the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in stages as it becomes available.

We will use commercially reasonable efforts to assist you in meeting your own notification obligations to a supervisory authority, to the Data Protection Board of India, or to affected individuals.

Impact assessments

We will use commercially reasonable efforts to assist with data protection impact assessments and any prior consultation with a supervisory authority, taking into account the information available to us and proportionate to our size.

Deletion and return

You may export reports and abstracts from the workspace at any time while your account is open. At any time, and on termination, you may ask us to delete personal data processed on your behalf by writing to hello@quoqo.com.

Documents and users can be deleted from the product by an administrator of your organisation, which removes the originals from object storage together with the extracted text, abstracts, counsel reviews, evidence passages and derived records, and which also destroys the copy held by Quoqo Counsel where the document was sent for a counsel review. Erasing a user overwrites their personal data and transfers their work to a colleague you name; the record of decisions made survives under an internal identifier that no longer corresponds to any person. Deleting a whole organisation is carried out by us on request and removes every document, abstract, review, user and session in it. Individual saved analyses, notes, deadlines, redline sessions and conversations can also be deleted from the workspace; deleting a saved analysis removes that record and not the underlying document.

Nothing is deleted on a schedule. We hold the material for as long as your account exists and until it is deleted under this section.

The following are deliberately retained and are not removed by a deletion request:

  • billing and tax records, including invoices, payments, credit notes and the package ledger, which we are required to keep and which are append-only;
  • security event records, including IP addresses, kept indefinitely so that abuse can be investigated; there is no schedule on which they expire;
  • a record of the deletion itself — who asked, when, why, and how much was removed — kept as the evidence that the request was carried out; it holds no document content;
  • a record of which version of the Terms, the Privacy Policy and this schedule was accepted and when, with the IP address, browser and link to the individual removed, so that what remains says only that the organisation agreed to a named version on a date;
  • an empty organisation record — its identifier and billing references, with the name and all content removed — because the billing records above refer to it;
  • de-identified metadata already derived under the section below, which no longer identifies any person, party or property;
  • backups held by our hosting provider, which age out on that provider's cycle rather than on demand;
  • records held by Stripe in connection with payments; and
  • certain traces at Quoqo Counsel, named in the sub-processor table above. A deletion in the product now destroys the copy it held — the file sent to it, the text it extracted, the review it produced and every passage it quoted. What remains is its own record that a review ran, which holds identifiers and timestamps and no part of the document; whatever the model provider it uses retained of the text; and its hosting provider's backups, which age out on that provider's cycle. Where no Counsel identifier was recorded — for documents deleted before this capability existed, and for an upload interrupted before the identifier it returned could be stored — the copy cannot be named and removal remains available on request to us.

De-identified metadata

As a documented purpose under this schedule and consistently with clause 7 of the Terms of Service, we derive de-identified metadata from the processing and use it to operate, evaluate and improve the service and to train and evaluate our own models. That material is limited to extracted structure, corrections, review decisions and quality signals, with identifiers stripped.

The following are not used for that purpose: the files you upload, their full extracted text, page images of them, the verbatim evidence passages cited from them, the names of parties or individuals, property and premises identifiers, and your organisation's and users' details.

Material used for this purpose is de-identified before use, must not reasonably permit the identification of you, your users, a party to a lease or a property, and is not sold or licensed to anyone as a dataset. We do not attempt to re-identify it.

Audit and information

We will use commercially reasonable efforts to make available to you the information reasonably necessary to demonstrate compliance with this schedule. That information is this document, the Privacy Policy and written answers to your security questions.

On reasonable written notice, at a reasonable frequency, and to an extent proportionate to the resources of a company of our size, we will use commercially reasonable efforts to respond to a written security questionnaire or to hold a remote review session with you. Any such review is subject to confidentiality, must not disrupt the service or affect other customers, and is at your cost. We do not offer on-site audits or access to production systems.

General

This schedule takes effect when the Terms of Service are accepted and continues for as long as we process personal data on your behalf. We may update it; where an update materially affects our processing of personal data we will give your account admins at least 30 days' notice, as provided in the sub-processors and Privacy Policy sections.

Clause 13 of the Terms of Service limits our liability, including for claims arising from breach of this schedule.

Questions about this schedule, and requests for a countersigned copy or for additional transfer documentation, go to hello@quoqo.com.

A note on what LeaseSift produces

Findings, abstracts, counsel reviews and reports are not legal, tax or accounting advice. They are produced substantially by automated systems, which make mistakes. Review the governing documents and obtain advice from a qualified professional before relying on anything LeaseSift produces.

leasesiftby QuoqoA Quoqo product · Lease abstraction & reviewPricingPrivacyTermsData processing