Privacy Policy, Service Terms & Information Security
Effective date: March 4, 2026
Privacy Policy
1. Introduction
Endpaper Corporation ("EndPaper," "we," "us," or "our") operates the EndPaper compliance review service and the website at endpaper.ai. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with our website and our compliance review services for real estate brokerages (collectively, the "Service").
EndPaper provides AI-powered transaction compliance review for real estate brokerages. We access our customers' transaction management systems to review documents for compliance issues and deliver findings through those same systems. This Privacy Policy covers both visitors to our website and the data we handle as part of providing the Service to our brokerage customers.
2. Information We Collect
Website Visitors
When you visit endpaper.ai or interact with us, we may collect:
- Contact information. When you fill out a contact form, request a demo, or email us, we collect your name, email address, phone number, company name, and any other information you provide.
- Usage data. We automatically collect log data when you visit our website, including your IP address, browser type, operating system, referring URL, pages visited, and timestamps.
- Device information. We collect device type and screen resolution to ensure the website displays correctly.
Brokerage Customer Data
When providing compliance review services to our brokerage customers, we access and process:
- Transaction documents. We access real estate transaction documents (such as purchase agreements, disclosures, addenda, and amendments) through our customers' transaction management systems (e.g., SkySlope, Command, Brokermint) using credentials provided by the customer.
- Transaction data. Documents may contain personal information about transaction parties, including names, addresses, phone numbers, email addresses, property addresses, and financial details related to real estate transactions.
- Compliance findings. We generate compliance review results, exception notes, and agent guidance based on our analysis of transaction documents.
Our access to and processing of brokerage customer data is governed by our Master Services Agreement and Data Processing Addendum with each customer.
3. How We Use Information
Website Visitor Information
- To respond to inquiries: reply to contact form submissions and demo requests
- To communicate with you: send follow-up information about our services
- To improve the website: analyze usage patterns to improve content and user experience
- To ensure security: detect and prevent fraud, abuse, or security incidents
Brokerage Customer Data
We use brokerage customer data solely to:
- Provide the Service: review transaction documents for compliance with regulatory requirements, MLS rules, and brokerage standards
- Deliver findings: flag compliance issues, generate exception notes, and provide agent guidance within the customer's systems
4. Legal Basis for Processing
If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a legal basis for processing personal data, we rely on the following:
- Contract performance: processing data as necessary to provide the Service as described in our Master Services Agreement
- Legitimate interests: improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights
- Legal obligation: complying with applicable laws and regulations
- Consent: where you have given specific consent for a particular use, which you may withdraw at any time
5. Artificial Intelligence and Document Processing
We use AI systems from third-party providers to assist with compliance review of transaction documents. Here is how this works:
- Transaction document content is sent to AI providers (currently Google Gemini, OpenAI, and Anthropic) for analysis as part of our compliance review process
- AI-generated findings are reviewed by our human compliance specialists before delivery to customers
- We maintain data processing agreements with our AI providers that govern their handling of data
- We do not use customer transaction data to train AI models. Our AI processing providers are contractually prohibited from using data submitted through their paid APIs to train or improve their models
- We select AI providers based in part on their data handling practices and contractual commitments
Our current AI processing providers are Google (Gemini), OpenAI, and Anthropic. We will update this list if our providers change.
6. Information Sharing and Disclosure
We do not sell, rent, or trade personal information. We have not sold personal information in the preceding 12 months.
We may share information with the following categories of third parties, solely as needed to operate the Service:
- AI processing providers: Google (Gemini), OpenAI, and Anthropic for document analysis
- Cloud hosting: for data storage and application hosting
- Email delivery: for transactional communications
Each service provider is bound by agreements that require them to protect data and prohibit them from using it for their own purposes.
We may also disclose information when required by law, subpoena, or court order, or when we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others.
7. Data Retention
- Website visitor contact information (name, email from contact forms): retained for as long as the business relationship or inquiry is active, then deleted within 90 days
- Website usage and log data: retained for up to 90 days for operational purposes
- Brokerage customer transaction data: retained for the duration of the customer's service agreement, then deleted or returned within 30 days of termination at the customer's election
- Compliance review results: retained for the duration of the customer's service agreement as part of the Service
Brokerage customers may request deletion of their data at any time by contacting us. Deletion is subject to the terms of our Master Services Agreement.
8. Data Security
We use industry-standard security measures to protect information, including encryption in transit (TLS) and at rest. Access to customer data is restricted to authorized personnel who need it to provide the Service and is limited on a need-to-know basis. All personnel with access are subject to confidentiality obligations. While we take reasonable steps to protect information, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate or incomplete information
- Deletion: request that we delete your personal information
- Portability: request your data in a structured, machine-readable format
- Restriction: request that we limit how we process your data
- Objection: object to processing based on legitimate interests
To exercise any of these rights, contact us at support@endpaper.ai. We will respond to verified requests within 30 days (or 45 days if we need an extension, with notice to you).
For individuals whose data appears in transaction documents: If your personal information is contained in transaction documents that we process on behalf of a brokerage customer, please direct your privacy requests to the brokerage that holds your transaction records. We process that data as a service provider on behalf of the brokerage and will assist the brokerage in responding to your request.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: you may request the categories and specific pieces of personal information we have collected about you in the past 12 months
- Right to delete: you may request deletion of your personal information, subject to certain exceptions
- Right to non-discrimination: we will not discriminate against you for exercising your privacy rights
- Right to opt out of sale: we do not sell your personal information. We do not share your personal information for cross-context behavioral advertising
We honor Global Privacy Control (GPC) signals as a valid opt-out request. To submit a rights request, email support@endpaper.ai.
11. International Data Transfers
The Service is hosted in the United States. If you access our website from outside the United States, your information will be transferred to and processed in the United States. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy.
12. Cookies
Our website uses essential cookies required to maintain your session. These cookies are strictly necessary for the website to function. We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
13. Children's Privacy
The Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will delete that information promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify affected parties by email or by posting a notice on the website at least 30 days before the changes take effect. The "Effective date" at the top of this page indicates when this policy was last updated.
Service Terms
15. About the Service
EndPaper provides AI-powered transaction compliance review for real estate brokerages. We connect to our customers' existing transaction management systems, review documents for compliance with regulatory requirements, MLS rules, and brokerage-specific standards, and deliver findings directly within those systems. Our service combines automated AI analysis with human specialist verification. Customers do not access EndPaper software directly. The full terms of our service relationship with brokerage customers are governed by a separate Master Services Agreement.
16. Intellectual Property
The Service, including its design, systems, algorithms, and documentation, is owned by EndPaper and is protected by intellectual property laws. These terms do not grant you any rights to our trademarks, logos, or brand features. Compliance findings and reports generated for customers may be used, shared, and distributed by the customer as they see fit.
17. AI-Generated Content and Disclaimers
Compliance findings and other outputs generated by EndPaper are produced using a combination of artificial intelligence and human review. While we strive for accuracy, customers should be aware that:
- AI-generated compliance findings are not legal advice and should not be relied upon as a substitute for professional legal, real estate, or regulatory guidance
- AI outputs may contain errors, omissions, or inaccuracies, including missed compliance issues or incorrect flagging
- EndPaper's review does not replace the designated broker's ultimate responsibility for regulatory compliance
- Customers are solely responsible for reviewing and acting on compliance findings and for maintaining their own compliance programs
We strongly recommend that brokerages maintain their own compliance oversight and consult with qualified legal professionals for decisions with regulatory or legal consequences.
18. Disclaimer of Warranties
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, THAT AI-GENERATED OUTPUTS WILL BE ACCURATE, COMPLETE, OR RELIABLE, OR THAT THE SERVICE WILL MEET YOUR SPECIFIC REQUIREMENTS.
19. Limitation of Liability
TO THE FULLEST EXTENT PERMITTED BY LAW, ENDPAPER AND ITS OFFICERS, DIRECTORS, EMPLOYEES, AND AGENTS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO THE SERVICE, INCLUDING BUT NOT LIMITED TO:
- Missed compliance issues or inaccurate findings
- Lost profits, revenue, or business opportunities
- Damages resulting from reliance on AI-generated content
- Loss of data or unauthorized access to information
- Regulatory fines, penalties, or enforcement actions
- Service interruptions or downtime
OUR TOTAL AGGREGATE LIABILITY FOR ANY CLAIMS ARISING FROM OR RELATED TO THE SERVICE SHALL NOT EXCEED THE AMOUNT PAID TO US BY THE APPLICABLE CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
20. Indemnification
You agree to indemnify, defend, and hold harmless EndPaper and its officers, directors, employees, and agents from any claims, damages, losses, liabilities, or expenses (including reasonable attorneys' fees) arising from: (a) your use of the Service, (b) your violation of these terms, or (c) your violation of any rights of a third party.
21. Dispute Resolution
If you have a concern, please contact us first at support@endpaper.ai so we can try to resolve it informally. If we cannot resolve a dispute informally within 30 days, either party may pursue binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. Arbitration will take place in King County, Washington. Each party will bear its own costs, and the arbitrator's decision will be final and enforceable in any court of competent jurisdiction.
Class action waiver: you agree to resolve disputes with us on an individual basis only. You waive any right to participate in a class action, class arbitration, or representative proceeding.
22. Termination
Either party may terminate the service relationship in accordance with the Master Services Agreement. We may suspend or terminate access to the Service if we believe these terms have been violated or if continued access poses a risk to the Service or other users. We will provide reasonable notice when possible.
Upon termination, we will delete or return customer data in accordance with our Privacy Policy and the Master Services Agreement. Sections 16, 17, 18, 19, 20, 21, and 24 survive termination.
23. Force Majeure
We are not liable for any failure or delay in performing our obligations under these terms due to events beyond our reasonable control, including natural disasters, war, terrorism, pandemics, labor disputes, government actions, power failures, internet or telecommunications failures, or cyberattacks.
24. Governing Law
These terms are governed by and construed in accordance with the laws of the State of Washington, without regard to its conflict of law provisions. Any disputes shall be subject to the exclusive jurisdiction of the federal and state courts in Seattle, Washington.
25. General Provisions
- Entire agreement. These terms, together with our Privacy Policy and any applicable Master Services Agreement, constitute the entire agreement between you and EndPaper regarding the Service and supersede any prior agreements.
- Severability. If any provision of these terms is found to be unenforceable, the remaining provisions will continue in full force and effect.
- Waiver. Our failure to enforce any provision of these terms does not constitute a waiver of that provision or any other provision.
- Assignment. You may not assign your rights or obligations under these terms without our prior written consent. We may assign our rights and obligations without restriction.
26. Changes to These Terms
We may update these Service Terms from time to time. If we make material changes, we will notify affected parties by email or by posting a notice on the website at least 30 days before the changes take effect.
Information Security Policy
EndPaper takes the security of customer data seriously. This policy describes the technical and organizational measures we maintain to protect the confidentiality, integrity, and availability of information entrusted to us by our brokerage customers.
27. Data Classification
We classify data into the following categories, each with appropriate handling requirements:
- Customer Transaction Data: Real estate transaction documents and associated personal information (names, addresses, financial details). Treated as confidential. Access restricted to authorized personnel and systems required to perform compliance review.
- Customer Credentials: Authentication credentials provided by customers for accessing their transaction management systems. Treated as highly sensitive. Access restricted to the application systems that require them.
- Internal Business Data: EndPaper's own operational data, including aggregated analytics and service performance metrics. Does not contain individually identifiable customer information.
28. Encryption
- In transit: All data transmitted between EndPaper systems, customers, and third-party providers is encrypted using TLS (Transport Layer Security). SSL is enforced across all production systems, and HTTP Strict Transport Security (HSTS) headers are enabled.
- At rest: Customer data stored in our systems is encrypted at rest using industry-standard encryption provided by our cloud infrastructure (AWS). This includes database storage and file storage (S3).
- Application secrets: API keys, credentials, and other secrets are managed through encrypted credential storage and environment-variable injection. Secrets are never stored in source code repositories.
29. Access Control
- Principle of least privilege: Access to customer data is limited to the minimum number of authorized personnel necessary to operate the Service.
- Multi-factor authentication: All personnel with access to production systems are required to use multi-factor authentication (MFA) on all accounts.
- Authentication: Internal systems use OAuth 2.0 (Google) for user authentication. API access is secured with JWT tokens that expire after one hour.
- Workspace isolation: Customer data is logically separated by workspace. Each brokerage customer's data is isolated from other customers within the application.
30. Infrastructure Security
- Cloud hosting: EndPaper's production infrastructure is hosted on Amazon Web Services (AWS), which maintains SOC 2, ISO 27001, and other security certifications.
- Application containers: Our application runs in Docker containers with non-root user execution, reducing the impact of potential vulnerabilities.
- SSL certificates: Production SSL certificates are automatically provisioned and renewed via Let's Encrypt.
- Sensitive data filtering: Logging systems are configured to automatically filter and redact sensitive fields (passwords, tokens, keys, email addresses, SSNs, and financial data) to prevent accidental exposure in logs.
31. Application Security
- Static analysis: We use automated static security analysis tools to scan our codebase for common vulnerabilities including SQL injection, cross-site scripting (XSS), and other OWASP Top 10 risks.
- Code review: All code changes are reviewed before deployment to production.
- Dependency management: We monitor third-party dependencies for known security vulnerabilities and apply updates promptly.
- Error monitoring: Application errors are tracked and monitored to identify and respond to potential security issues quickly.
32. Third-Party Provider Security
We evaluate the security practices of third-party providers before integrating them into our Service. Our current providers include:
- Amazon Web Services (AWS): Cloud infrastructure, data storage, and file storage. SOC 2 and ISO 27001 certified.
- Google (Gemini): AI document analysis. Data processing agreements in place.
- OpenAI: AI document analysis. Data processing agreements in place.
- Anthropic: AI document analysis. Data processing agreements in place.
We maintain data processing agreements with all providers that handle customer data. These agreements require providers to maintain appropriate security measures and restrict their use of customer data to providing services to EndPaper.
33. Personnel Security
- Confidentiality obligations: All personnel with access to customer data are bound by confidentiality obligations.
- Security awareness: Personnel are briefed on data handling expectations, acceptable use of customer data, and security best practices as part of onboarding.
- Access review: Access to production systems is reviewed when personnel join or leave the organization, and permissions are revoked promptly upon departure.
34. Incident Response
In the event of a security incident involving customer data:
- Notification: We will notify affected customers without undue delay and within 72 hours of becoming aware of a confirmed breach involving their data, consistent with applicable law.
- Investigation: We will promptly investigate the scope, cause, and impact of the incident and take steps to contain and remediate the issue.
- Cooperation: We will cooperate with affected customers and, where required, with regulatory authorities in connection with any investigation or notification obligations.
- Documentation: We will document the incident, our response, and any corrective actions taken.
35. Data Handling and Disposal
- Retention: Customer data is retained only for the duration of the service relationship, as described in our Privacy Policy and Master Services Agreement.
- Deletion: Upon termination of the service relationship, customer data is deleted or returned within 30 days at the customer's election. We will provide written confirmation of deletion upon request.
- Backups: Data backups follow the same retention and deletion policies as primary data stores.
36. Continuous Improvement
We regularly review and update our security practices as our team, technology, and the threat landscape evolve. We welcome security questions from customers and prospective customers. For security inquiries or to report a vulnerability, contact us at security@endpaper.ai.
37. Contact Us
If you have questions about this Privacy Policy, our Service Terms, our Information Security Policy, or wish to exercise your privacy rights, contact us at:
Endpaper Corporation
720 Seneca Street Ste 107 #759
Seattle, WA 98101
Email: support@endpaper.ai