Responsibility and scope
Customer organizations are expected to determine the purposes of their property-management records, while LeaseGrid provides the service and protects platform operations. The precise legal roles remain subject to formal legal and privacy review.
Data minimisation
Public forms and APIs apply typed field limits. Role-scoped responses are designed to omit internal notes, unrelated financial details and records outside the authorized organization or property scope.
Security controls
Current safeguards include authorization boundaries, audit trails, request limits, secure headers, redacted logs, encrypted transport and separated environments. Public workspace login and owner data intake remain gated.
Hosting and providers
The web and API services use approved hosting infrastructure. Live payment, messaging, push-notification and production file-storage providers remain disabled; transfer, subprocessor and contract review is required before any later activation.
Rights and incidents
Access, correction, restriction or deletion requests require identity and authority verification, applicable retention or legal-hold checks, and an auditable outcome. Suspected incidents follow the recorded escalation and rollback process.
