Sorting by

×

Privacy First Policy

Last Updated: December 23, 2025

✓ SOC 2 Type II Compliant

1. Introduction

Welcome to mPro Digital Edge ("we," "our," "us," or "mPro"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered platform designed for the multifamily property management industry.

🛡️ SOC 2 Commitment

mPro Digital Edge maintains SOC 2 Type II compliance, demonstrating our commitment to security, availability, processing integrity, confidentiality, and privacy. Our controls are independently audited to ensure we meet rigorous industry standards for protecting your data.

By accessing or using our platform, including our AI writing tools, chat assistants, video production features, document intelligence, and other services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

2. Information We Collect

Information You Provide Directly

  • Account Information: Name, email address, phone number, company name, job title, and professional role within the multifamily industry
  • Property Information: Property names, addresses, amenity details, and community descriptions you input for content generation
  • Content & Communications: Text, images, documents, and other content you submit to our AI tools; support inquiries and correspondence
  • Brand Voice Settings: Customized brand guidelines, tone preferences, and communication styles you configure
  • Payment Information: Billing details processed through our secure payment providers (we do not store full credit card numbers)

Information Collected Automatically

  • Usage Data: Features accessed, AI tools utilized, timestamps, session duration, and interaction patterns
  • Device Information: Browser type, operating system, device identifiers, and IP address
  • Log Data: Server logs, error reports, and performance metrics
  • Cookies & Similar Technologies: Session identifiers, preferences, and authentication tokens

Information from Third-Party Integrations

  • Social Media Platforms: Data from Facebook, Instagram, and other connected accounts
  • Property Management Systems: Data you authorize us to access from integrated PMS platforms
  • AI Service Providers: We may receive metadata related to AI processing from our provider partners
⚠️ Fair Housing Compliance Notice

We automatically monitor content generated through our platform for potential Fair Housing violations. Any content flagged for discriminatory language is logged for compliance review. We recommend stripping EXIF/GPS data from uploaded images.

3. How We Use Your Information

Purpose Legal Basis
Service Delivery: Authenticate users, provide AI-powered tools, and personalize your experience Contract Performance
AI Processing: Generate content, analyze documents, create videos, and power chat assistants Contract Performance
Fair Housing Compliance: Monitor outputs for discriminatory content and maintain audit trails Legal Obligation / Legitimate Interest
Security & Fraud Prevention: Detect threats, prevent abuse, and protect platform integrity Legitimate Interest
Analytics & Improvement: Analyze usage patterns to enhance features and user experience Legitimate Interest
Communications: Send service updates, support responses, and (with consent) marketing Contract / Consent
Legal Compliance: Respond to legal requests and fulfill regulatory obligations Legal Obligation

All data processing is conducted in accordance with applicable laws, including GDPR, CCPA, and Meta Platform Terms.

4. Sharing & Disclosure

🔒 Our Commitment

We do not sell, rent, or share your personal data with third parties for their marketing purposes under any circumstances.

We may share information only in the following limited circumstances:

  • AI Service Providers: Data is transmitted to our AI partners (OpenAI, Anthropic, Google, HeyGen, Synthesia, ElevenLabs, and others) solely for processing your requests. All providers are contractually bound to data protection obligations.
  • Infrastructure Providers: Cloud hosting (Microsoft Azure), security services, and technical infrastructure necessary to operate our platform.
  • Professional Services: Auditors, legal counsel, and consultants bound by confidentiality agreements.
  • Legal Requirements: When required by law, court order, or government authority, or to protect rights, safety, or property.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.

5. AI Data Processing

mPro Digital Edge integrates with multiple AI providers to deliver our services. Understanding how your data is processed by AI systems is important:

How AI Processing Works

  • Input Processing: Content you submit is transmitted to appropriate AI providers based on the tool you're using
  • No Model Training: Your content is NOT used to train AI models. We use enterprise API agreements that explicitly prohibit training on customer data.
  • Transient Processing: AI providers process your requests in real-time and do not retain your content after generating outputs
  • Output Monitoring: Generated content passes through our Fair Housing compliance filters before delivery

AI Provider Categories

Tool Category Providers
Smart Writer, Chat Assistants, Document Intelligence OpenAI, Anthropic, Google Gemini, Grok, DeepSeek
Video Production (VideoPro, Avatar Pro, PersonaPro) HeyGen, Synthesia, Fal.AI
Image Generation & Enhancement OpenAI DALL-E, Stable Diffusion, Fal.AI, Freepik, Novita
Voice & Audio ElevenLabs, Speechify, Google TTS, Azure TTS, OpenAI
Search & Research Serper, Perplexity

6. Security Measures

We implement comprehensive security controls aligned with SOC 2 Trust Service Criteria:

Technical Safeguards

  • Encryption in Transit: TLS 1.2+ for all data transmission; HTTPS enforced across all endpoints
  • Encryption at Rest: AES-256 encryption for stored data in our Azure infrastructure
  • Access Controls: Role-based access control (RBAC), principle of least privilege, multi-factor authentication
  • Network Security: Firewalls, intrusion detection systems, DDoS protection, and network segmentation

Application Security

  • Authentication: Bcrypt password hashing, optional SAML SSO for enterprise customers
  • CSRF Protection: Framework-level tokens for all form submissions
  • SQL Injection Prevention: Parameterized queries and input validation throughout
  • Session Management: Secure session tokens with configurable timeout (default: 2 hours)

Operational Security

  • Monitoring: 24/7 system monitoring, automated alerting, and anomaly detection
  • Vulnerability Management: Regular security assessments, penetration testing, and patch management
  • Employee Training: Security awareness training for all personnel; background checks for employees with data access
  • Vendor Management: Security assessments for all third-party providers; Data Processing Agreements in place
✓ Audit & Compliance

Our security controls are independently audited annually. Audit reports (SOC 2 Type II) are available to enterprise customers under NDA. We maintain comprehensive audit trails for all data access and system changes.

7. Data Retention & Disposal

We retain personal data only as long as necessary for the purposes described in this policy or as required by law:

Data Category Retention Period Disposal Method
Account Information Until account deletion + 30 days Secure deletion from all systems
Generated Content As configured by user (default: 90 days) Automated purge
Chat/Assistant Conversations Until user deletion or 1 year inactive Secure deletion
Social Media Dashboard Data Until account/post deletion Immediate purge
Security Logs 1 year Automated purge
Compliance Audit Trails 7 years Secure archival deletion
Anonymized Analytics Indefinite (no PII) N/A - Non-identifiable

Upon account deletion, personal data is removed from live systems immediately. Backup copies are purged within 30 days.

8. Cookies & Tracking Technologies

Cookies We Use

Cookie Type Purpose Duration
Essential Authentication, security, session management Session / 2 hours
Functional User preferences, language settings 1 year
Analytics Usage patterns, feature performance (aggregated) 1 year

Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain platform features. We honor Do Not Track browser signals for non-essential tracking.

9. Your Privacy Rights

Depending on your location, you may have the following rights under GDPR, CCPA, and other privacy laws:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Restrict Processing: Request limitation of how we process your data
  • Object: Object to processing based on legitimate interests

Exercising Your Rights

To exercise any of these rights, contact us at Info@mProDigitalEdge.com with subject line "Privacy Rights Request." We will verify your identity and respond within 30 days (or as required by applicable law).

Right to Lodge a Complaint

If you believe we have violated your privacy rights, you have the right to lodge a complaint with your local data protection authority.

10. Facebook & Social Media Platform Data

When you connect your Facebook or Instagram accounts, you authorize us to collect the specific fields and scopes you approve:

Permissions We May Request

  • Basic Profile: Name, email, profile picture
  • pages_show_list: List of Facebook Pages you manage
  • pages_manage_posts: Create, edit, and delete posts on your Pages
  • pages_read_engagement: Engagement metrics (reactions, comments, shares)
  • read_insights: Page and post analytics (reach, impressions, clicks)
  • business_management: Manage Business Manager assets you own
  • instagram_basic: Basic Instagram Business Account profile
  • instagram_content_publish: Publish posts and Reels on your behalf

How We Use Social Media Data

  • Display and manage your Pages and accounts within our dashboard
  • Schedule, publish, and edit content on your behalf
  • Provide detailed insights and analytics for performance measurement
  • Authenticate and personalize your experience

You can revoke permissions at any time in your Facebook account's Settings → Business Integrations or within our platform settings. This policy does not supersede Meta's Platform Terms or Facebook's Data Policy.

11. Security Incident Response

We maintain a comprehensive incident response program aligned with SOC 2 requirements:

Our Incident Response Process

  1. Detection & Analysis: Continuous monitoring systems detect potential security events; our security team analyzes and classifies incidents
  2. Containment: Immediate steps to limit impact and prevent further unauthorized access
  3. Investigation: Thorough investigation to determine scope, cause, and affected data
  4. Notification: Affected individuals and relevant authorities notified as required by law
  5. Recovery: Systems restored to secure operation with enhanced safeguards
  6. Post-Incident Review: Analysis and documentation to prevent recurrence
⚠️ Breach Notification Commitment

In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware of the breach, providing details of the incident and steps you can take to protect yourself.

Reporting Security Concerns

If you discover a potential security vulnerability or have concerns about data security, please report it immediately to Info@mProDigitalEdge.com with subject line "Security Concern."

12. Data Deletion Requests

You maintain control over your data. When you delete your account or specific content, we take immediate action:

Account Deletion

All personal profile information, posts, generated content, comments, and uploaded media are removed from live systems immediately upon deletion confirmation.

Individual Content Deletion

Specific posts, documents, or other content and related metadata are purged immediately upon deletion.

Assistance with Deletion

If you believe any data remains after deletion or need assistance:

  1. Email us at Info@mProDigitalEdge.com with subject "Data Deletion Assistance"
  2. Include your username and registered email address
  3. We will investigate and confirm complete removal within 5 business days

Note: For compliance and fraud prevention, we retain anonymized logs that contain no personally identifiable information. These logs are automatically purged after 30 days.

13. Subprocessors & Third-Party Services

We engage trusted third-party service providers (subprocessors) to help deliver our services. All subprocessors are contractually bound to data protection obligations equivalent to this policy.

Category Purpose Location
Cloud Infrastructure Hosting, storage, computing United States (Azure)
AI Processing Content generation, analysis United States
Payment Processing Subscription billing United States
Email Services Transactional & support emails United States
Analytics Aggregated usage metrics United States
Security & Compliance Monitoring, auditing United States

A complete list of subprocessors is available to enterprise customers upon request.

14. International Data Transfers

mPro Digital Edge is headquartered in the United States. If you access our services from outside the United States, your data will be transferred to and processed in the United States.

Transfer Mechanisms

For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on:

  • Standard Contractual Clauses (SCCs): EU-approved contractual safeguards with our subprocessors
  • Supplementary Measures: Technical and organizational measures to ensure adequate protection
  • Data Protection Agreements: Contractual commitments from all AI and service providers

By using our services, you consent to the transfer of your information to the United States and other countries that may have different data protection rules than your country.

15. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or other factors.

How We Notify You

  • Minor Changes: Updated policy posted here with new "Last Updated" date
  • Material Changes: Email notification to registered users at least 30 days before changes take effect
  • In-App Notice: Prominent notification within the platform for significant updates

Your continued use of our services after changes become effective constitutes acceptance of the revised policy.

16. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your data, please contact us:

mPro Digital Edge

Email: Info@mProDigitalEdge.com

Phone: +1 772-418-3816

Address: 1995 NW Fork Road, Stuart, Florida 34994

For privacy-specific inquiries, please use subject line "Privacy Inquiry" to ensure prompt routing to our data protection team.

This Privacy Policy was last reviewed for SOC 2 compliance on July 13, 2025.

Who we are

Our website address is: https://app.mprodigitaledge.com

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select "Remember Me", your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

What security certifications does mPro Digital Edge hold?

mPro Digital Edge is pursuing SOC 2 Type II certification, with completion targeted for Early 2026 Our platform undergoes regular security assessments and penetration testing. We can provide our most recent security assessment summary upon request under NDA.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Security Assessments & Certifications

Do you carry cyber liability insurance? A: Yes. mPro Digital Edge maintains cyber liability and errors & omissions insurance coverage. Certificate of insurance is available upon request during the procurement process.

 

Can we conduct our own security assessment or send a vendor security questionnaire? A: Absolutely. We welcome security questionnaires (SIG, CAIQ, or custom formats) and can accommodate reasonable security assessment requests as part of the enterprise onboarding process.

Can we control access at the property level?

Yes. mPro Digital Edge supports hierarchical role-based access control aligned with typical property management structures. Administrators can grant or restrict access by role (leasing agent, regional manager, maintenance coordinator), by property, or by portfolio. When an employee transfers properties or leaves the organization, access is revoked from a single control point—eliminating the risk of orphaned accounts across multiple AI tools.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Visitor comments may be checked through an automated spam detection service.

How can we verify that our data won't be used for training?

A: We can provide documentation of our Enterprise API agreements with each model provider (OpenAI, Anthropic, Google, etc.) that explicitly prohibit training on customer data. These contractual protections flow through to your organization. Additionally, your legal team can review our Data Processing Agreement (DPA) which codifies these protections.

Multifamily-Specific Compliance

 

Q: How does mPro Digital Edge support Fair Housing compliance? A: Unlike generic AI tools, mPro Digital Edge includes built-in Fair Housing guardrails that flag potentially discriminatory language before it's published. All AI-generated content related to leasing, advertising, and resident communication is logged with timestamps, creating the audit trail required for HUD compliance reviews and fair housing investigations.

Q: Can we demonstrate to auditors what AI was used to generate specific content? A: Yes. Every prompt and output is logged with user identification, timestamp, and the specific AI model used. This documentation can be exported for legal discovery, compliance audits, or Fair Housing investigations—something impossible to reconstruct when employees use scattered consumer tools.

Here’s a summary of how we address key security concerns:

01

CSRF Protection

Laravel implements CSRF protection automatically for forms, which helps prevent unauthorized requests.

02

SQL Injection Prevention

Using a query builder that employs parameter binding significantly reduces the risk of SQL injection, ensuring that user inputs are properly escaped.

03

Authentication System

Laravel features a robust authentication system that simplifies handling user authentication while securely hashing passwords using the bcrypt algorithm.

04

Data Encryption

The framework utilizes OpenSSL to encrypt sensitive data, enhancing overall security.

05

Password Hashing

Integrated bcrypt password hashing provides a strong defense against password cracking attempts.

06

Secure Routing and Middleware

Middleware allows developers to define access control for routes, restricting access to authorized users only.

Overall, we have a comprehensive set of tools and practices to secure your input and output using our applications.

Our commitments

Our commitments give you ownership and control over your business data (inputs and outputs from ChatGPT Team, ChatGPT Enterprise, ChatGPT Edu, Claude, Gemini, and our API Platform) and support your compliance needs.

Ownership

Control

Security

Faq

Does this system train its models by using my data?

By default, we do not use your business data to train our models. However, if you have explicitly opted in to share your data with us (for example, through our opt-in feedback system to improve our services), we may use the shared data to train our models.

Who owns my input and out put?

As between you and our AI platforms: you retain all rights to the inputs you provide to our services and you own any output you rightfully receive from our services to the extent permitted by law. We only receive rights in input and output necessary to provide you with our services, comply with applicable law, and enforce our policies.

Can you support my complaince with GDPR and other privacy laws?

Yes, we are able to execute a Data Processing Addendum (DPA) with customers for that use of ChatGPT Team, ChatGPT Enterprise, ChatGPT Edu, and the API in support of their compliance with GDPR and other privacy laws. Please complete our DPA form to execute a DPA with OpenAI.

Why do you only allow business emails for sign up

Sign Up with Your Business Email

We accept corporate email addresses only. Free email providers (such as Gmail, Yahoo, Outlook.com) are prohibited.

Why business emails only?
- Ensures authentic business identity verification
- Protects sensitive property and resident data
- Maintains professional industry standards
- Prevents unauthorized access to confidential multifamily data

Options to get started:
- Sign in with your business email
- Connect with LinkedIn

Need an exception? Submit a request through our business verification form.

Your security matters: Business email requirements help us maintain a trusted network of verified multifamily professionals while protecting sensitive property information and resident data from potential misuse.

We do not accept Gmail, Outlook.com, Yahoo Mail, Zoho Mail, AOL Mail, iCloud Mail, or Yandex, Mailfence, Neo Mail, Apple, GMX, Mail.com, Proton Mail, Tutanota, Mailfence, Neo, and Yandex. Mail, Titan, Fastmail, Minute Mail, Tuta and Hushmail.

Sign in with Linkedin or register with our support department by completing this form.