Compliance is not a feature. It is the foundation.
This page documents APIP's data handling practices, DNC/TCPA compliance process, retention policy, and subprocessor list. If you have questions not answered here, contact us directly.
Last reviewed
- 01Number acquired · source + date stampedPASS
- 02TCPA cell classification (carrier lookup)PASS
- 03National DNC Registry (FTC)PASS
- 04State DNC (FL, TX, CA, NY)SUPPRESS
- 05Litigator-flag databasePASS
- 0614-day re-screen scheduledPASS
- 07Audit log writtenPASS
How APIP handles personal and property data.
Encryption at rest
All data is encrypted at rest using AES-256. Encryption keys are managed by AWS KMS with automatic rotation.
Encryption in transit
All data in transit is encrypted using TLS 1.3. No plaintext transmission of personal data is permitted.
Access controls
Role-based access control (RBAC) limits data access to authorized personnel. All access events are logged.
Data minimization
APIP collects only the data necessary to fulfill the stated purpose. Unnecessary personal data is not retained.
Retention limits
Personal data is retained for no longer than 24 months from last active use. Deletion is automated and logged.
No sale of personal data
We license property intelligence to subscribing clients; we do not sell personal data to advertisers or data brokers. Data is used only for the purposes described in the Privacy Policy.
Seven steps from number to compliant call sheet.
APIP's DNC/TCPA compliance process is documented, auditable, and automated. No number reaches a call sheet without completing all seven steps.
- National DNC Registry (FTC)
- State DNC lists, all active states
- Litigator flag database
- TCPA cell classification
- 14-day automated re-screen
- Full audit log on request
- 01
Number acquisition
Phone numbers are sourced from entity filings, registered agent records, and Tier 1 enrichment providers. Source and acquisition date are stamped on every number.
- 02
TCPA cell classification
Every number is classified as landline or mobile using carrier lookup. Mobile numbers are flagged for TCPA consent requirements before delivery.
- 03
National DNC screen
All numbers are screened against the FTC National DNC Registry. Registered numbers are suppressed from the call sheet and flagged in the record.
- 04
State DNC screen
Numbers are screened against state DNC lists for FL, TX, CA, NY, and all other states with active registries. State suppression is applied independently.
- 05
Litigator flag screen
Numbers are screened against known TCPA litigator databases. Flagged numbers are suppressed and logged with the litigator database source and match date.
- 06
14-day re-screen
All active numbers are re-screened on a 14-day cycle. New DNC registrations, litigator additions, and classification changes are applied automatically.
- 07
Audit log
Every screen event is logged with timestamp, registry version, result, and suppression action. Full audit logs are available to operators on request.
Data retained only as long as legally required.
Retention periods are set by data category, legal basis, and operational necessity. Automated deletion runs on schedule. Manual review is required only for billing records subject to statutory retention.
| Data category | Retention | Legal basis | Deletion |
|---|---|---|---|
| Property records (non-personal) | Indefinite | Legitimate interest | On account closure |
| Owner entity data | 24 months | Legitimate interest | Automated at 24m |
| Contact data (phone, email) | 24 months | Legitimate interest | Automated at 24m |
| DNC screen logs | 36 months | Legal obligation | Automated at 36m |
| CRM outcome feedback | 36 months | Legitimate interest | Automated at 36m |
| Access logs | 12 months | Security | Automated at 12m |
| Billing records | 7 years | Legal obligation | Manual review |
Every third party that touches APIP data, documented.
APIP maintains data processing agreements (DPAs) with all subprocessors that handle personal data. This list is updated when subprocessors are added or removed.
| Subprocessor | Purpose | Location | DPA |
|---|---|---|---|
| Amazon Web Services | Infrastructure, storage, compute | US-East-1 | SIGNED |
| FTC DNC Registry | National DNC compliance screen | United States | N/A |
| Enrichment Provider T1 | Phone, email, contact enrichment | United States | SIGNED |
| Enrichment Provider T2 | Extended contact enrichment | United States | SIGNED |
| GoHighLevel | CRM delivery integration | United States | SIGNED |
| Stripe, Inc. | Payment processing | United States | SIGNED |
What brokers and owners ask about our data.
Where does APIP's data come from?
- Public record. Property, ownership, entity and court records are collected from the county and state offices that publish them, and every field shows its origin and a confidence tier. Contact enrichment comes from vetted providers under signed data processing agreements. Provider names are withheld for competitive reasons and are available under NDA.
How are phone numbers screened before a broker sees them?
- Seven steps, listed on this page: source stamping, TCPA cell classification, a National Do Not Call screen, a state Do Not Call screen, a litigator flag screen, a 14-day automated re-screen, and an audit log entry for every screen. A number that fails any step is suppressed and the reason is recorded on the record.
Does APIP sell personal data?
- No. Personal data is used only to deliver the service to the licensed brokerage partner and is never sold or licensed to third parties. Property records that carry no personal data are kept for as long as the account is open.
How long does APIP keep data?
- By category. Owner entity data and contact data are retained for 24 months from last active use. Do Not Call screen logs are kept for 36 months as a legal obligation, access logs for 12 months, and billing records for 7 years. Deletion is automated and logged. The full retention table is on this page.
How do I request a correction, a deletion or a copy of my data?
- Use the contact form on this site and choose Compliance question. Data subject requests and DPA inquiries receive a response within 2 business days. Data corrections and Do Not Call or TCPA questions receive a response within 1 business day. Security incidents receive a response within 4 hours.
Who can see an owner's record?
- Only the brokerage partner licensed for that owner's market, inside their APIP account. Owner records are never published on this website or in marketing material. The sample owners shown on the public site are composites described by role, never named.
Questions, corrections, and data requests.
For data subject requests, compliance questions, DPA inquiries, or subprocessor updates, contact our compliance team directly. We respond within 2 business days.
Contact compliance →