RenloBack to home

    Standard Terms

    STANDARD TERMS TO RENLO SERVICE AGREEMENT

    Last modified: 8 September 2026

    These Standard Terms are between the customer identified in the Order Form ("Customer") and Renlo, Inc., a Delaware corporation ("Renlo" or "Provider"). Capitalised terms are defined in Section 13 or in the Order Form.


    1. Service

    1.1 Access and Use. During the Subscription Period and subject to this Agreement, Customer may access and use the Service, receive Outputs, and use any Software and Documentation as needed to do so, for its internal business purposes.

    1.2 Support. Provider will provide reasonable technical support by email at support@renlo.co during normal business hours, or as otherwise described in the Order Form.

    1.3 User Accounts. Customer is responsible for all activity under its Users' accounts and for its Users' compliance with this Agreement. Customer and its Users must keep credentials confidential and promptly notify Provider of any suspected unauthorised access.

    1.4 Feedback and Usage Data. Customer may provide Feedback, which Provider may use without restriction or obligation. Provider may collect and use Usage Data to operate, secure, improve, and promote its products and services, and will only disclose Usage Data to third parties in aggregated form that does not identify Customer or any User.

    1.5 Customer Content.

    (a) Licence. Customer grants Provider a non-exclusive, worldwide, royalty-free licence, sublicensable to Provider's service providers, to host, copy, process, adapt, and otherwise use Customer Content as needed to provide, maintain, secure, and improve the Product and to comply with Applicable Laws.

    (b) Broker Safeguards. Provider will not disclose to third parties (i) property-level Customer Content that identifies Customer's active deals or opportunities, or (ii) owner names, beneficial ownership details, or owner contact information derived from Customer Content. These restrictions do not limit disclosures to Customer's own workspace, to Provider's service providers under confidentiality obligations, or disclosures required by law.

    (c) Anonymised and Aggregated Data. Provider may derive anonymised or aggregated data from Customer Content and use it for any lawful purpose, provided it does not identify Customer, Customer's clients, any property owner, or any individual.

    (d) Responsibility. Customer is responsible for the accuracy and legality of Customer Content and for having all rights, consents, and licences needed to provide it to Provider for processing under this Agreement.

    (e) Opt-Out. Customer may opt out of Provider's use of Customer Content to improve the Product by emailing support@renlo.co. The opt-out does not apply to processing needed to provide the Product or to comply with Applicable Laws.

    1.6 AI Outputs. The Service uses machine learning, which is probabilistic by nature. Outputs may be inaccurate, incomplete, or fail to reflect real people, places, or facts, and their quality depends substantially on the Customer Content and instructions provided. Customer agrees that: (a) Outputs are not a substitute for professional advice or independent verification; (b) Customer will review Outputs for accuracy and suitability before relying on or sharing them; (c) Customer will not use Outputs about an individual to make decisions with legal or similarly significant effects on that individual, except at Customer's own risk; (d) Outputs may contain content that does not reflect Provider's views; and (e) Outputs may not be unique.

    1.7 Third-Party AI Providers. The Service uses models and technology from third-party AI providers to generate Outputs. Provider may change these providers at any time. Customer's use of AI features is also subject to those providers' usage policies as identified in the Documentation. Provider is not responsible for the availability or performance of third-party AI providers.

    2. Restrictions and Obligations

    2.1 Restrictions. Except as expressly permitted, Customer will not, and will not permit anyone else to: (i) reverse engineer or attempt to discover the source code or underlying algorithms of the Product; (ii) resell, sublicense, or otherwise make the Product available to third parties; (iii) remove proprietary notices; (iv) copy, modify, or create derivative works of the Product; (v) interfere with, degrade, or circumvent security or access controls of the Product; (vi) access accounts or data it is not authorised to access; (vii) use the Product to build a competing product or service; (viii) use the Product, its Outputs, or the Documentation to train or improve any AI model, or for competitive benchmarking; (ix) attempt to manipulate or subvert the Product's AI features through prompt injection or similar techniques; (x) use the Product for High Risk Activities or in violation of Applicable Laws; or (xi) submit Customer Content for which Customer lacks the necessary rights or consents.

    2.2 Suspension and Removal. Provider may suspend Customer's access to the Product if Customer materially breaches this Agreement, fails to pay undisputed Fees when due, or uses the Product in a way that harms the Product or others. Provider will try to give notice before suspending and will restore access once the issue is resolved. Provider is not obliged to monitor Customer Content or Outputs but may remove content it reasonably believes violates this Agreement or Applicable Laws.

    3. Privacy and Security

    3.1 Personal Data. Customer Content will ordinarily include Personal Data about Customer's contacts, clients, and counterparties. Customer is the controller of that Personal Data and Provider processes it on Customer's behalf under the Data Processing Addendum (the "DPA"), which forms part of this Agreement and controls in the event of conflict regarding Personal Data.

    3.2 Recording Consents. Where Customer uses the Service to record, transcribe, or analyse calls or meetings, Customer is responsible for obtaining any consent required from participants under Applicable Laws.

    3.3 Prohibited Data. Customer will not submit Prohibited Data to the Product unless the Order Form expressly permits it.

    3.4 Security. Provider will use commercially reasonable measures to protect the Service against unauthorised access, alteration, or disclosure.

    4. Payment

    4.1 Fees. Fees, billing frequency, and the number of seats are set out in the Order Form. Unless the Order Form states otherwise, Fees are in U.S. Dollars, exclude Sales Taxes, and are non-refundable except where this Agreement expressly provides a refund.

    4.2 Seats. The Service is licensed per seat. Each seat is for one named User at a time and credentials may not be shared. Customer may add seats at any time; added seats are charged pro rata for the remainder of the current billing period. Changes to the number of seats are otherwise made as described in the Order Form or through the Service.

    4.3 Payment Method. Customer authorises Provider and its Payment Processor to charge the payment method on file for all Fees on a recurring basis until the Subscription ends. Invoiced amounts are due within 30 days of the invoice date. Provider may charge reasonable interest on amounts that are more than 30 days overdue, at a rate not exceeding what Applicable Laws allow.

    4.4 Taxes. Customer is responsible for all sales, use, VAT, GST, withholding, and similar taxes on Fees ("Sales Taxes"), other than taxes on Provider's income.

    4.5 Disputes. Customer must raise any good-faith dispute over Fees within 30 days of the charge or invoice and pay all undisputed amounts on time. The parties will work in good faith to resolve the dispute.

    5. Term and Termination

    5.1 Term and Renewal. Each Order Form begins on its Order Date, runs for the Subscription Period, and renews automatically for successive periods of the same length unless either party gives notice of non-renewal before the end of the current period.

    5.2 Termination for Cause. Either party may terminate this Agreement on notice if the other party materially breaches it and fails to cure within 30 days of notice, or becomes insolvent or ceases to do business.

    5.3 Effect of Termination. On expiration or termination, Customer's right to use the Product ends and Customer will pay all Fees accrued before termination. Customer may export its Customer Content through the Service for a reasonable period after termination, after which Provider will delete it as described in the DPA. Sections 1.4, 1.5(a)–(d), 1.6, 1.7, 2.1, 4, 5.3, and 6 through 13 survive termination.

    6. Warranties

    6.1 Mutual. Each party warrants that it has the authority to enter into this Agreement and will comply with Applicable Laws in performing it.

    6.2 From Customer. Customer warrants that Customer Content, and its use as contemplated by this Agreement, does not infringe any third party's intellectual property, privacy, or other rights, and that Customer has obtained all consents required from any individual whose Personal Data, voice, or likeness appears in Customer Content.

    6.3 From Provider. Provider warrants that the Service will perform materially as described in the Documentation. Customer's sole remedy for breach of this warranty is for Provider to use reasonable efforts to correct the issue, or, if Provider cannot do so within a reasonable time, for Customer to terminate the affected Order Form and receive a prorated refund of prepaid Fees for the remainder of the Subscription Period.

    7. Disclaimer

    Except as expressly stated in Section 6, the Product is provided "as is". Provider disclaims all other warranties, express, implied, or statutory, including merchantability, fitness for a particular purpose, title, and non-infringement, to the maximum extent permitted by Applicable Laws. PROVIDER DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT OUTPUTS WILL BE ACCURATE OR COMPLETE. OUTPUTS ARE NOT LEGAL, FINANCIAL, INVESTMENT, OR OTHER PROFESSIONAL ADVICE AND ARE NOT INTENDED TO BE THE BASIS FOR ANY INVESTMENT OR BUSINESS DECISION. Beta Products are provided "as is" without any warranty and may be changed or withdrawn at any time.

    8. Limitation of Liability

    8.1 Cap. Except for Customer's payment obligations, Customer's breach of Section 2.1 or 6.2, and either party's indemnification obligations, each party's total cumulative liability arising out of or relating to this Agreement will not exceed the Fees paid or payable by Customer in the 12 months before the event giving rise to the claim.

    8.2 Exclusion. Neither party will be liable to the other for lost profits or revenues, or for indirect, consequential, special, exemplary, or punitive damages, even if advised of their possibility.

    8.3 Scope. These limitations apply regardless of the theory of liability, and nothing in this Agreement excludes liability that cannot be excluded under Applicable Laws.

    9. Indemnification

    9.1 By Provider. Provider will defend Customer against third-party claims that the Service, used in accordance with this Agreement, infringes that third party's intellectual property rights, and will pay resulting damages and reasonable legal fees finally awarded or agreed in settlement. Provider may, at its option, modify the Service to make it non-infringing, obtain a licence, or terminate the affected Order Form and refund prepaid Fees pro rata. This obligation does not cover claims arising from Customer Content, unauthorised modifications, use in breach of this Agreement, or combination with items not provided by Provider.

    9.2 By Customer. Customer will defend Provider against third-party claims arising from Customer Content, Customer's use of the Product in breach of this Agreement, or Customer's failure to obtain required consents, and will pay resulting damages and reasonable legal fees finally awarded or agreed in settlement.

    9.3 Procedure. The indemnified party must promptly notify the indemnifying party of the claim, give it sole control of the defence and settlement (provided no settlement admits fault on the indemnified party's behalf without its consent), and provide reasonable cooperation at the indemnifying party's expense.

    10. Confidentiality

    Each party will use the other's Confidential Information only to perform this Agreement, will protect it with at least reasonable care, and will not disclose it except to employees, advisors, and service providers who need to know it and are bound by confidentiality obligations, or as required by law (with reasonable notice where permitted). Confidential Information does not include information that is public through no fault of the recipient, already known to the recipient without restriction, received from a third party without restriction, or independently developed. These obligations continue for three years after termination, and indefinitely for trade secrets.

    11. Intellectual Property

    Provider owns all right, title, and interest in the Product, including improvements developed during the Subscription Period. Customer owns all right, title, and interest in Customer Content. As between the parties, Customer owns Outputs, subject to Provider's rights in the Product and to the fact that Outputs may not be unique.

    12. General Terms

    12.1 Governing Law and Courts. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-laws rules. The parties will attempt in good faith to resolve any dispute through discussion before starting legal proceedings. Any legal proceeding will be brought exclusively in the state or federal courts located in Delaware, and each party submits to their jurisdiction. Either party may seek injunctive relief in any court to protect its intellectual property or Confidential Information. Each party waives any right to a jury trial.

    12.2 Entire Agreement. This Agreement, together with the Order Form, the DPA, and Provider's Privacy Policy, is the entire agreement between the parties on its subject and supersedes all prior discussions. Terms in Customer's purchase orders or vendor forms do not apply.

    12.3 Changes. Provider may update these Standard Terms by posting the updated version at renlo.co and giving Customer reasonable notice. Changes apply from the start of Customer's next Subscription Period, or earlier if Customer agrees. Changes to an Order Form must be agreed in writing by both parties.

    12.4 Assignment. Neither party may assign this Agreement without the other's consent, except to a successor in a merger, acquisition, or sale of substantially all of its assets, on notice.

    12.5 Publicity. Provider may identify Customer by name and logo as a customer. Any case study or testimonial requires Customer's approval.

    12.6 Notices. Notices must be in writing and sent by email to the addresses in the Order Form (for Provider, support@renlo.co). Email notices are effective when sent, unless the sender receives a delivery failure.

    12.7 Force Majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, except payment obligations.

    12.8 Export and Sanctions. Customer will comply with applicable export control and sanctions laws and represents that it is not located in an embargoed country or on any restricted-party list.

    12.9 Miscellaneous. The parties are independent contractors. There are no third-party beneficiaries. If any provision is unenforceable, the rest remains in effect. A waiver must be in writing. Provider may use subcontractors and remains responsible for their performance. Section headings are for convenience only. This Agreement may be signed electronically and in counterparts.

    13. Definitions

    "Affiliate" means an entity that controls, is controlled by, or is under common control with a party.

    "Agreement" means the Order Form as governed by these Standard Terms and the documents they incorporate.

    "Applicable Laws" means the laws and regulations that apply to a party or to the Product.

    "Beta Product" means any feature or version of the Product identified as beta, preview, early access, or similar.

    "Confidential Information" means non-public information disclosed by one party to the other in connection with this Agreement that is marked confidential or would reasonably be understood as confidential. Customer Content is Customer's Confidential Information; non-public information about the Product is Provider's.

    "Customer Content" means data, documents, recordings, and other materials submitted to the Product by or on behalf of Customer or its Users, excluding Feedback and Usage Data.

    "Documentation" means the usage guides and descriptions of the Service Provider makes available.

    "Feedback" means suggestions or comments about the Product.

    "Fees" means the amounts payable under an Order Form.

    "High Risk Activity" means any use where failure of the Product could reasonably be expected to cause death, bodily injury, or environmental damage.

    "Order Form" means an order document accepted by both parties that identifies the Customer, seats, Fees, Subscription Period, and any other business terms.

    "Outputs" means the documents, summaries, transcripts, analyses, records, and other results the Service generates from Customer Content.

    "Payment Processor" means the third-party payment provider Provider uses to process payments.

    "Personal Data" has the meaning given in the DPA.

    "Product" means the Service, Software, and Documentation.

    "Prohibited Data" means protected health information regulated by HIPAA, payment card and bank account numbers, government-issued identification numbers, and similar categories of sensitive data under Applicable Laws.

    "Service" means Renlo's AI-native CRM and deal platform for commercial real estate brokers, made available at renlo.co and related applications.

    "Software" means any client-side software, browser extension, or application Provider makes available as part of the Product.

    "Subscription Period" means the initial term stated in the Order Form and each renewal term.

    "Usage Data" means data about the provision, use, and performance of the Product, including account information, feature usage, and technical logs. Usage Data is not Customer Content.

    "User" means an individual who uses the Product through Customer's account.


    Exhibit A — Data Processing Addendum

    Last modified: 8 September 2026

    This Data Processing Addendum ("DPA") forms part of the Renlo Standard Terms (the "Agreement") between Renlo, Inc. ("Renlo") and the customer identified in the Order Form ("Customer"). It describes how Renlo processes Personal Data on Customer's behalf in providing the Service. Capitalised terms not defined here have the meanings in the Agreement. If this DPA conflicts with the Agreement on the subject of Personal Data, this DPA controls.

    1. Definitions

    "Customer Personal Data" means Personal Data in Customer Content, or in Outputs generated from Customer Content, that Renlo processes on Customer's behalf.

    "Data Protection Laws" means the U.S. federal and state privacy laws that apply to the processing of Customer Personal Data, including the California Consumer Privacy Act as amended ("CCPA") and similar state laws.

    "Personal Data", "Controller", "Processor", "Data Subject", and "Processing" have the meanings given in Data Protection Laws. Under the CCPA, "Controller" includes "business" and "Processor" includes "service provider".

    "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Personal Data in Renlo's or its Subprocessors' possession.

    "Subprocessor" means a third party Renlo engages to process Customer Personal Data.

    2. Roles

    Customer is the Controller of Customer Personal Data and Renlo is its Processor (or sub-processor, where Customer is itself a Processor). Annex 1 describes the processing. This DPA does not apply to Usage Data or account information that Renlo processes as an independent Controller under its Privacy Policy.

    3. Customer's Obligations

    Customer will comply with Data Protection Laws in its use of the Service, including by having a lawful basis for collecting Customer Personal Data and providing it to Renlo, giving any required notices, and obtaining any required consents. Where the Service is used to record or transcribe calls or meetings, Customer is responsible for obtaining any consent required from participants. Customer will not submit Prohibited Data unless the Order Form permits it. Customer's instructions to Renlo must be lawful.

    4. Renlo's Obligations

    4.1 Instructions. Renlo will process Customer Personal Data only on Customer's documented instructions, which consist of the Agreement, this DPA, Customer's configuration and use of the Service, and any other instructions agreed in writing. Renlo will inform Customer if it believes an instruction violates Data Protection Laws, unless prohibited from doing so.

    4.2 Additional Processing. To the extent permitted by Data Protection Laws, Renlo may also process Customer Personal Data to detect and respond to Security Incidents and fraud, to comply with legal obligations, and, unless Customer has opted out under Section 1.5(e) of the Agreement, to improve the Service.

    4.3 Confidentiality. Renlo will ensure its personnel who access Customer Personal Data are bound by confidentiality obligations.

    4.4 Security. Renlo will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as described in Annex 2, and may update those measures over time provided the overall level of protection is not materially reduced.

    4.5 Security Incidents. Renlo will notify Customer without undue delay after becoming aware of a Security Incident, will provide the information reasonably available to help Customer meet its own notification obligations, and will take reasonable steps to contain and remediate the incident. Notification is not an admission of fault.

    4.6 Data Subject Requests. Renlo will promptly forward to Customer any request it receives directly from a Data Subject about Customer Personal Data, and will reasonably assist Customer in responding, primarily through the functionality of the Service.

    4.7 Assistance and Compliance Information. Renlo will provide reasonable assistance with Customer's data protection impact assessments and regulator consultations where required by Data Protection Laws and relevant to the Service. On reasonable request, Renlo will provide information reasonably necessary to demonstrate compliance with this DPA, such as responses to a security questionnaire and copies of any third-party audit reports or certifications it holds. If Data Protection Laws require an audit that cannot be satisfied this way, Customer or an independent auditor bound by confidentiality may conduct one on reasonable notice, during business hours, no more than once a year, without unreasonably disrupting Renlo's operations, and at Customer's expense.

    5. Subprocessors

    Customer authorises Renlo to use Subprocessors. Renlo will provide its current list of Subprocessors on request, and will give Customer reasonable advance notice of any new Subprocessor. Customer may object in writing on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected Order Form and receive a prorated refund of prepaid Fees. Renlo will impose data-protection obligations on each Subprocessor no less protective than those in this DPA and remains responsible for its Subprocessors' performance.

    6. Processing Location and Non-U.S. Laws

    Customer authorises Renlo and its Subprocessors to process Customer Personal Data in the United States and in other countries where they operate. The Service is currently offered to U.S. customers. If Customer submits Personal Data subject to the data protection laws of another jurisdiction (such as the EU or UK), Customer will notify Renlo, and the parties will agree any additional terms those laws require, such as standard contractual clauses, before that data is processed.

    7. CCPA and U.S. State Law

    To the extent the CCPA or a similar U.S. state law applies, Renlo acts as a service provider or processor and will: process Customer Personal Data only to provide the Service under the Agreement; not sell or share it; not retain, use, or disclose it outside the direct business relationship with Customer or for any other purpose, except as the law permits; not combine it with Personal Data from other sources except as the law permits; provide the level of privacy protection the law requires; notify Customer if it can no longer meet its obligations; and allow Customer to take reasonable steps to ensure compliance and to stop and remediate unauthorised use.

    8. Return and Deletion

    For a reasonable period after the Agreement ends, Customer may export Customer Content through the Service. After that, Renlo will delete Customer Personal Data within a reasonable time, and from backups in the ordinary course of its backup rotation, except where retention is required by law, in which case it remains protected under this DPA. Anonymised or aggregated data that does not identify any individual, Customer, or Customer's client is not subject to deletion. Renlo will confirm deletion in writing on request.

    9. Liability and Term

    Liability under this DPA is subject to the limitations in the Agreement. This DPA applies for as long as Renlo processes Customer Personal Data.


    Annex 1 — Details of Processing

    Parties. Customer, at the notice address in the Order Form, as Controller. Renlo, Inc., a Delaware corporation, support@renlo.co, as Processor.

    Subject matter and purpose. Providing Renlo's AI-native CRM and deal platform for commercial real estate brokers, including hosting, organising, enriching, transcribing, summarising, and analysing Customer Content and generating Outputs.

    Duration. The Subscription Period plus the return and deletion period in Section 8.

    Data Subjects. Customer's employees and Users; Customer's clients, prospects, and contacts; property owners, tenants, investors, lenders, brokers, and other counterparties; participants in recorded calls and meetings.

    Personal Data. Names, contact details, job titles and employers; property ownership and transaction information; communications including emails, notes, call and meeting recordings and transcripts; deal and pipeline activity; and any other Personal Data Customer chooses to submit.

    Sensitive data. None intended.

    Frequency. Continuous during the Agreement.

    Annex 2 — Security Measures

    Renlo maintains commercially reasonable security measures appropriate to the nature of the data and the size of its business, including:

    • access controls based on role and least privilege, with multi-factor authentication for Renlo personnel;
    • encryption of Customer Personal Data in transit and at rest;
    • hosting with reputable cloud providers that maintain recognised security certifications;
    • logical separation of each customer's data;
    • logging and monitoring of access to production systems;
    • regular backups;
    • a process for responding to and learning from security incidents;
    • confidentiality obligations and security awareness for personnel;
    • review of Subprocessors' security practices before engagement; and
    • contractual terms with AI providers that prohibit them from training their models on Customer Personal Data.

    Renlo will continue to develop its security programme as it grows and may adopt additional or replacement measures over time.

    Copyright © 2026 Renlo, Inc. All rights reserved.

    © 2026 RenloTermsPrivacyfounders@renlo.co