Legal

Data Processing Agreement

Last Modified Date: April 10, 2026
This Groundswell Data Processing Agreement and its Annexes (“DPA”) reflects the parties’ agreement with respect to the Processing of Personal Data by Groundswell Giving Inc. (“Groundswell”) on behalf of an individual or legal entity (“Client”) in connection with a copy of the Enterprise Service Agreement Terms executed by and between Client and Groundswell or, in the absence of an executed agreement, the Groundswell Terms and Conditions available at https://groundswell.io/terms/ (referred to in this DPA as the “Agreement”).

The term of this DPA will follow the term of the Agreement. This DPA is supplemental to, and forms an integral part of, the Agreement and is effective upon its incorporation into the Agreement, which may be specified and referenced in the Agreement, an Order Form, or an executed amendment to the Agreement. In case of any conflict or inconsistency with the terms of the Agreement, this DPA will take precedence over the terms of the Agreement to the extent of such conflict or inconsistency.

Groundswell may update these terms from time to time; provided, however, that no such update will materially diminish Client’s rights or Groundswell’s obligations with respect to Personal Data or Personal Information during the then-current Agreement term without Client’s consent. If Client has an active Groundswell account, Groundswell will notify Client of changes via email.

Capitalized terms used, but not otherwise defined, herein shall have the same meanings assigned to those terms in the Agreement.

1. Definitions

1.1. "European Data Protection Laws" means data protection laws applicable in Europe, including: (i) Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; (iii) applicable national implementations of (i) and (ii); (iv) GDPR as it forms part of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 ("UK GDPR"); and (v) the Swiss Federal Act on Data Protection of 25 September 2020 and its implementing ordinances ("Swiss DPA"), in each case as may be amended, superseded, or replaced.  

1.2.
“CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended from time to time, including without limitation the California Privacy Rights Act of 2020 (“CPRA”), and any binding regulations promulgated thereunder. 

‍1.3. "Personal Data" means any information Processed by Groundswell on behalf of Client relating to an identified or identifiable natural person; see Article 4(1) GDPR. 

‍1.4. "Personal Data Breach" means, according to Article 4(12) GDPR, a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed. 

1.5. “Process” or “Processing” means any operation or set of operations which is performed onPersonal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (see Article 4(2) GDPR).

‍1.6. “Subprocessors” has the meaning as being defined in section 5.1 of this DPA.

1.7. The terms “business”, “business purpose”, “consumer”, “contractor”, “personal information”, “sensitive personal information”, “sell”, “service provider”, “share”, “third party”, and “verifiable consumer request” shall each have their respective meanings under the CCPA.

‍1.8. "Third Country" means a country without a system of ensuring adequate protection within the meaning of Article 45 GDPR.

‍1.9 “UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 currently found at https://ico.org.uk/media/for-organisations/documents/4019539/international data-transfer-addendum.pdf, as may be amended, superseded, or replaced.

2. Scope of the DPA and Transfer Mechanisms for Data Transfers

The subject matter of the Processing under this DPA is the provision of the Services and related implementation, support, administration, security, and reporting activities described in the Agreement and Annex 1. The duration of the Processing is the term of the Agreement, plus any limited period after expiration or termination during which Groundswell Processes Personal Data in accordance with Section 6 or as required by applicable law. With respect to Processing described in Annex 1 that Groundswell performs on Client's behalf in connection with the Services ("Covered Processing"), Client acts as a controller or processor, as applicable, and Groundswell acts solely as a processor or subprocessor, respectively. Where the CCPA applies to Covered Processing, the parties intend Groundswell to act only as Client's service provider or contractor and not as a third party. If Client is a processor, Client represents and warrants that it is authorized to appoint Groundswell as a subprocessor to the extent required by applicable law or contract. 

This DPA applies only to Covered Processing, including Groundswell's hosting, operation, support, security, transmission, reconciliation, reporting, and other Processing of Personal Data within the Services for Client and at Client's direction. The parties acknowledge that the Groundswell Charitable Foundation, as sponsor of donor-advised funds and related charitable programs, separately performs its own charitable, legal, tax, compliance, sanctions-screening, and grant-administration activities. To the extent Groundswell facilitates Client-directed contribution, donation, grant, or distribution workflows through the Services, Groundswell does so as Client's processor, service provider, or contractor with respect to Covered Processing. This DPA does not govern the Groundswell Charitable Foundation's own exercise of charitable discretion or other Processing not performed by Groundswell on Client's behalf. For the avoidance of doubt, nothing in this DPA is intended to characterize Groundswell as a controller with respect to Covered Processing.

Groundswell will not transfer Personal Data to any country or recipient not recognized as providing an adequate level of protection for Personal Data (within the meaning of applicable European Data Protection Laws), unless it first takes all such measures as are necessary to ensure the transfer is in compliance with applicable European Data Protection Laws. Such measures may include (without limitation) transferring such data to a recipient that is covered by a suitable framework or other legally adequate transfer mechanism recognized by the relevant authorities or courts as providing an adequate level of protection for Personal Data, to a recipient that has achieved binding corporate rules authorization in accordance with European Data Protection Laws, or to a recipient that has executed appropriate standard contractual clauses in each case as adopted or approved in accordance with applicable European Data Protection Laws.

Client acknowledges that in connection with the performance of the Agreement, Groundswell Giving Inc. is a recipient in the United States of Personal Data originating in the European Union, the European Economic Area and/or their member states, Switzerland, or the United Kingdom. The parties agree that the Standard Contractual Clauses will be incorporated by reference and form part of the Agreement as follows:

(a) EEA Transfers. In relation to Personal Data that is subject to the GDPR (i) Client is the "data exporter" and Groundswell Giving Inc. is the "data importer"; (ii) the Module Two terms apply to the extent the Client is a Controller of Personal Data and the Module Three terms apply to the extent the Client is a Processor of Personal Data; (iii) in Clause 7, theoptional docking clause, does not apply; (iv) in Clause 9, Option 2 applies, and changes to Subprocessors will be notified in accordance with the Section 5 of this DPA; (v) in Clause 11, the optional language is deleted; (vi) in Clauses 17 and 18, the parties agree that the governing law and forum for disputes for the Standard Contractual Clauses will be the Republic of Ireland (without reference to conflicts of law principles); (vii) the Annexes of the Standard Contractual Clauses will be deemed completed with the information set out in the Annexes of this DPA; and (viii) if and to the extent the Standard Contractual Clauses conflict with any provision of this DPA the Standard Contractual Clauses will prevail to the extent of such conflict.

(b) UK Transfers. In relation to Personal Data that is subject to the UK GDPR, the Standard Contractual Clauses will apply in accordance with sub-section (a) and the following modifications (i) the Standard Contractual Clauses will be modified and interpreted in accordance with the UK Addendum, which will be incorporated by reference and form an integral part of the Agreement; (ii) Tables 1, 2 and 3 of the UK Addendum will be deemed completed with the information set out in the Annexes of this DPA and Table 4 will be deemed completed by selecting “neither party”; and (iii) any conflict between the terms of the Standard Contractual Clauses and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.

(c) Swiss Transfers. In relation to Personal Data that is subject to the Swiss DPA, the Standard Contractual Clauses will apply in accordance with sub-section (a) and the following modifications (i) references to "Regulation (EU) 2016/679" will be interpreted as references to the Swiss DPA; (ii) references to "EU", "Union" and "Member State law" will be interpreted as references to Swiss law; and (iii) references to the "competent supervisory authority" and "competent courts" will be replaced with the "the Swiss Federal Data Protection and Information Commissioner " and the "relevant courts in Switzerland."

Client expressly authorizes Groundswell to transfer Personal Data to Groundswell-affiliated entities and/or other Subprocessors located in locations outside the European Economic Area, as is reasonably required to provide support, perform technical projects, or perform other types of services under the Agreement, provided that, to the extent applicable, either: (i) such locations are recognized by the competent authority as providing an adequate level of data protection; or (ii) Groundswell has implemented the Standard Contractual Clauses, the UK Addendum, or another legally valid transfer mechanism, as applicable, with such affiliates and/or other Subprocessors.

3. Processing of Personal Data

3.1. Groundswell shall Process Personal Data only on Client's documented instructions, including with respect to transfers of Personal Data to a Third Country or an international organization, unless applicable law to which Groundswell is subject requires otherwise. The Agreement, this DPA, Client's configuration and use of the Services, and any other documented instructions agreed by the parties constitute Client's complete documented instructions as of the Effective Date. Client may issue further documented instructions consistent with and within the scope of this DPA and the Agreement. Groundswell shall promptly inform Client if, in Groundswell's opinion, an instruction infringes GDPR, the CCPA, or other applicable data protection law. If Groundswell is required by applicable law to Process Personal Data other than on Client's instructions, Groundswell shall inform Client of that legal requirement before the relevant Processing unless that law prohibits such notice on important grounds of public interest.

3.2. Groundswell must limit the access to Personal Data to its employees and Subprocessors for whom access to said data is reasonably necessary to fulfill Groundswell's obligations to Client. Groundswell must ensure that persons authorized to Process Personal Data are bound by the same or equivalent confidentiality obligations as Groundswell and/or are under an appropriate statutory obligation of confidentiality.

3.3. Groundswell shall implement and maintain appropriate technical and organizational measures in line with Article 32 GDPR. For this purpose, the parties agree on the security measures set forth in Annex 2 for the Processing of Personal Data.

3.4. The appropriate technical and organizational security measures must be determined with due regard to:
‍
(i) the state of the art,
(ii) the cost of their implementation, and
(iii) the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.

3.5. Groundswell shall make available to Client upon request information necessary to demonstrate compliance with Groundswell's obligations set forth in Article 28 GDPR, applicable CCPA obligations, and applicable transfer requirements, and allow for and reasonably assist with audits, inspections, manual reviews, automated scans, certifications, and other reasonable technical or operational testing conducted by Client or an independent third party auditor appointed by Client, as follows:

(i) Groundswell shall at its own cost obtain and make available upon Client’s request an audit report from an independent auditor regarding Groundswell's compliance with the data security requirements of the controls defined in SOC 2 Type 2 Security Trust Service Criteria (or equivalent standard). Such audit report must be issued on the basis of a recognized standard for such reports.

(ii) In addition, Client is entitled, no more than once every 12 months except where required by a competent supervisory authority, following a Personal Data Breach, or where Client reasonably believes Groundswell is not complying with this DPA, to conduct or have conducted an audit, including an inspection, if and to the extent the audit report set forth in the preceding paragraph does not meet the requirements set forth in Article 28 GDPR, is reasonably necessary for Client to verify Groundswell's compliance with applicable CCPA obligations, or is reasonably necessary to verify applicable transfer safeguards. Any third party auditor shall not be a competitor of Groundswell, and shall, upon Groundswell's request, sign a customary non-disclosure agreement to treat all information obtained or received from Groundswell confidentially, and may share any such information obtained or received only with Client and Groundswell. Client shall be responsible for costs of the audit, and agrees to pay Groundswell a reasonable fee per audit to be mutually agreed by the parties to cover Groundswell assistance with the audit.

3.6. Groundswell shall without undue delay, unless such notification is prohibited under applicable law, notify Client about any:

(i) request by a legal authority for disclosure of Personal Data Processed under the Agreement; or
(ii) request for access to Personal Data received regarding an identified data subject.

3.7. Groundswell shall notify Client without undue delay after becoming aware of a Personal Data Breach. The notification shall at least describe the nature of the Personal Data Breach (including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned) and the measures taken or proposed by Groundswell to address the Personal Data Breach.

3.8. Groundswell shall provide reasonable and timely assistance to Client to help enable Client to respond to: (i) any request from a data subject or consumer to exercise rights under applicable data protection laws, including rights of access or know, correction, objection, erasure or deletion, data portability, opt-out of sale or sharing, and limitation of the use or disclosure of sensitive personal information, as applicable; and (ii) any other correspondence, enquiry, or complaint received from a data subject, consumer, regulator, or other third party in connection with the Processing of Personal Data.

In the event that any such request, correspondence, enquiry, or complaint is made directly to Groundswell, Groundswell shall promptly inform Client and provide full details of the same, except to the extent prohibited by law. Where the CCPA applies, Groundswell shall either act on Client’s behalf in accordance with Client’s documented instructions for responding to the request or inform the requester that the request cannot be acted upon because it has been sent to a service provider or contractor, unless applicable law requires otherwise.

3.9. Groundswell shall, upon Client's request, reasonably assist Client in ensuring compliance with Client's obligations pursuant to Articles 32 to 36 GDPR (including security of Processing, notification of Personal Data Breach, data protection impact assessments, and prior consultation) and, to the extent applicable, Client's obligations under Sections 1798.100(d) through (f), 1798.105, 1798.106, 1798.110, 1798.115, 1798.120, 1798.121, 1798.130, and 1798.135 of the CCPA and applicable CCPA regulations concerning cybersecurity audits, risk assessments, and automated decision-making technology, based on the nature of Processing and the information available to Groundswell.

3.10. In the event Client’s designated account manager at Groundswell cannot assist with a data privacy enquiry, Client may contact privacy@groundswell.io.

3.11. Assistance contemplated by this Section 3 shall be provided to Client at no charge if the request can be fulfilled by supplying readily available documentation in Groundswell’s possession.

3.12. To the extent Groundswell Processes Personal Information subject to the CCPA on Client’s behalf, the parties acknowledge and agree that Client is disclosing such Personal Information to Groundswell only for the limited and specified business purposes described in the Agreement and Annex 1, and Groundswell is acting as Client’s service provider and not as a third party with respect to such Personal Information. To the extent Groundswell is deemed a contractor rather than a service provider for any Processing, Groundswell shall comply with the obligations applicable to contractors under the CCPA and this DPA, and Groundswell certifies that it understands and will comply with the restrictions set forth in this Section 3.

3.13. Groundswell shall not: (i) sell or share Personal Information; (ii) retain, use, or disclose Personal Information for any purpose other than the limited and specified business purposes set forth in the Agreement and Annex 1, or as otherwise permitted by the CCPA and its implementing regulations; (iii) retain, use, or disclose Personal Information outside of the direct business relationship between Groundswell and Client, except as otherwise permitted by the CCPA and its implementing regulations; or (iv) combine Personal Information received from, or on behalf of, Client with personal information received from, or on behalf of, another person or collected from Groundswell’s own interaction with a consumer, except as expressly permitted by the CCPA and its implementing regulations.

3.14. Groundswell shall provide the same level of privacy protection for Personal Information as is required by the CCPA, shall comply with all applicable obligations of a service provider and, if applicable, a contractor under the CCPA, shall implement reasonable security procedures and practices appropriate to the nature of the Personal Information, and shall not retain Personal Information for longer than is reasonably necessary and proportionate to achieve the limited and specified business purposes described in the Agreement and this DPA, unless otherwise required by applicable law.

3.15. Groundswell shall promptly notify Client if Groundswell determines that it can no longer meet its obligations under the CCPA. Upon notice from Groundswell or if Client otherwise reasonably determines that Groundswell has used Personal Information in an unauthorized manner, Client may take reasonable and appropriate steps to stop and remediate such unauthorized use, including by requiring Groundswell to provide relevant information, certifications, or documentation demonstrating remediation, subject to appropriate confidentiality protections.

3.16. Groundswell shall enable Client to comply with verifiable consumer requests and other CCPA requests applicable to Client. Without limiting Section 3.8, Groundswell shall, upon Client’s instructions and within commercially reasonable timeframes, provide relevant Personal Information in its possession, correct inaccurate Personal Information or enable Client to do so, delete Personal Information or enable Client to do so, and provide assistance with requests to know or access, delete, correct, data portability, opt out of sale or sharing, and limit the use or disclosure of sensitive personal information, in each case to the extent applicable to Groundswell’s Processing of Personal Information on Client’s behalf.

3.17. At Client’s direction, Groundswell shall delete Personal Information or enable Client to delete it and shall notify its own service providers or contractors to delete Personal Information collected, used, processed, or retained by Groundswell on Client’s behalf. Groundswell shall also notify any service providers, contractors, or third parties that may have accessed such Personal Information from or through Groundswell to delete such Personal Information unless the information was accessed at Client’s direction or such notification proves impossible or involves disproportionate effort.

3.18. To the extent required by applicable CCPA regulations, Groundswell shall cooperate with Client in connection with Client's cybersecurity audits, risk assessments, and automated decision-making technology compliance activities by making available information in Groundswell's possession, custody, or control that is reasonably necessary for those compliance activities and by not misrepresenting any fact materially relevant to such activities, in each case subject to appropriate confidentiality protections.

3.19. Groundswell may engage Subprocessors to Process Personal Information on Client’s behalf only in accordance with Section 5. Any Subprocessor that assists Groundswell with Processing Personal Information subject to the CCPA must be bound by a written contract that imposes at least the same CCPA-related restrictions and obligations on the Subprocessor as those imposed on Groundswell under this DPA. Groundswell remains fully liable for each Subprocessor’s acts and omissions with respect to such Processing.

4. Client's General Obligations

Client will comply with all obligations applicable to it under applicable data protection laws and regulations, including establishing an appropriate legal basis for Covered Processing, providing any required notices, and ensuring that its instructions to Groundswell are lawful. Client has the right to issue documented instructions, to object to Subprocessors on reasonable data protection grounds as set forth in Section 5, and to instruct the return or deletion of Personal Data under Section 6.

5. Other Data Processors

5.1. Groundswell may engage other processors ("Subprocessors") to Process Personal Data under this DPA only with Client's prior general written authorization under this Section 5. Groundswell shall enter into a written agreement with each Subprocessor that imposes data protection obligations that are no less protective than those set forth in this DPA, to the extent applicable to the services performed by the Subprocessor, including the obligations required by Article 28(3) GDPR and any applicable CCPA-specific restrictions and obligations.

5.2. Groundswell shall maintain an up-to-date list of Subprocessors, including their identity, location, and a description of the Processing they perform, and shall provide or make the list available to Client upon request. Prior to engaging a new Subprocessor or replacing an existing one, Groundswell shall inform Client's administrator and Client's contact at least 30 days in advance, thereby giving Client the opportunity to object on reasonable data protection grounds. If Client makes a reasonable objection and the parties are unable to resolve it within a reasonable period, Client may terminate the affected Services or the relevant portion of the Agreement upon written notice.

5.3. Groundswell shall remain fully liable to Client for the performance of its Subprocessors' obligations hereunder.

6. Data Retrieval and Deletion

6.1. Client may retrieve its Personal Data at any time during the Term as set forth in the Agreement.

6.2. At Client's choice, promptly upon the expiration or earlier termination of the Agreement, or earlier upon Client's request, Groundswell shall return to Client or securely destroy or render unreadable or undecipherable each and every original and copy in every media of all Personal Data in Groundswell's possession, custody, or control, except to the extent applicable law requires retention. If Client requests return, Groundswell may make the Personal Data available for export in a commercially reasonable, commonly used format and shall thereafter delete the remaining copies in accordance with this Section 6.

6.3. Notwithstanding Section 6.2, Personal Data contained in routine backups may be retained until deleted in accordance with Groundswell's general backup cycle, provided that such backups remain protected in accordance with this DPA, are put beyond ordinary use, and are not restored except as required for disaster recovery, security, or business continuity purposes. Such backups shall be deleted no later than approximately six (6) months from the decommissioning of Client's portal.

6.4. Groundswell shall provide to Client, upon Client's request, written confirmation that return or deletion has occurred in accordance with this Section 6. If applicable law does not permit Groundswell to return or destroy Personal Data as set forth herein, Groundswell shall ensure the privacy, confidentiality, and security of such Personal Data in accordance with the standards agreed in this DPA and shall not use or disclose any such retained Personal Data except to the extent required by applicable law.

ANNEX 1

Categories of data, categories of data subjects, and purposes of the Processing. This Annex 1 describes only Covered Processing, as defined in Section 2, that Groundswell performs as Client's processor and, where applicable, service provider or contractor in connection with the Services. It does not describe separate processing performed by or for the Groundswell Charitable Foundation in its capacity as sponsor of donor-advised funds or related charitable programs.

a) Categories of Personal Data 
The Personal Data Processed by Processor may concern the following categories of data, depending on the Services purchased and the data submitted by Client or its authorized users, and only to the extent such data is processed on Client's behalf through the Services:
  • Identification and contact data, such as name, employer, job title, department, postal address, email address, telephone number, and other similar contact details.
  • Account, profile, and access-management data, such as account identifiers, employee or user identifiers, account settings, role or permission data, authentication-related data, and audit logs.
  • Communications and support data, such as correspondence, support requests, service notifications, and records of interactions with Client or its authorized users.
  • Contribution, donation, grant recommendation, distribution recommendation, payment instruction, funding source, transaction, bank account, and payment card data submitted in connection with the Services, together with related status, confirmation, and reconciliation data maintained for Client through the Services.
  • Volunteer, matching, grant management, employee assistance fund, and related program data submitted through or generated within the Services.
  • Device, usage, and online identifier data, such as mobile device ID, cookie ID, Internet Protocol (IP) address, advertising identifier, approximate location data, and activity or event logs.
  • Any other Personal Data that Client or its authorized users choose to submit to the Services consistent with the Agreement and this DPA.
b) Categories of data subjects
The Personal Data Processed by Processor may concern the following categories of data subjects, depending on the Services purchased and the data submitted by Client or its authorized users, and only to the extent their Personal Data is processed on Client's behalf through the Services: 
  • Employees, contractors, agents, directors, officers, students, Client administrators, and other individuals authorized by Client and/or its affiliates to use or access the Services.
  • Donors, volunteers, applicants, beneficiaries, and other individuals whose Personal Data Client or its authorized users submit to, or cause to be generated through, the Services.
  • Donors, volunteers, applicants, beneficiaries, and other individuals whose Personal Data Client or its authorized users submit to, or cause to be generated through, the Services.
  • Representatives and contacts of nonprofit organizations, charities, grantees, or other recipient organizations with which Client or its authorized users interact, nominate, or make recommendations through the Services.
c) Nature and purpose of the Processing operations
The nature of the Processing may include collecting, recording, organizing, structuring, storing, hosting, adapting, retrieving, consulting, using, transmitting, disclosing by making available, reconciling, reporting, restricting, deleting, and destroying Personal Data, in each case as necessary for the following limited and specified purposes and only to the extent performed on Client's behalf:
  • Hosting, operating, administering, and making available the Groundswell corporate giving, corporate DAF administration, gift and match, volunteering, grant management, employee assistance fund, and related web and mobile services purchased by Client.
  • Onboarding, implementing, configuring, integrating, migrating data to, and customizing the Services for Client.
  • Processing, recording, transmitting, reconciling, and reporting on contributions, donations, grant recommendations, distribution recommendations, funding sources, payment instructions, volunteer activities, employee assistance fund applications, communications, and other workflows initiated by or on behalf of Client and its authorized users through the Services.
  • Providing customer support, troubleshooting, service communications, security monitoring, misuse detection, incident response, maintenance, repair, backup, disaster recovery, and analytics necessary to provide, secure, support, and improve the reliability and security of the Services for Client.
  • Complying with Client's documented instructions and with applicable law to the extent Groundswell is required to Process Personal Data in connection with Covered Processing.
For the avoidance of doubt, Covered Processing includes Groundswell's facilitation of Client-directed workflows through the Services, but does not include the Groundswell Charitable Foundation's separate sponsorship, grant-approval, grant-denial, holding, release, redirection, or other charitable or compliance determinations that Groundswell does not perform on Client's behalf.
d) Special categories of data
Groundswell does not require special categories of Personal Data for ordinary use of the Services. Depending on the Services purchased and the data submitted by Client or its authorized users, Processor may Process special categories of Personal Data or other sensitive data only to the extent submitted to the Services or otherwise instructed by Client, including:
  • Data revealing religious or philosophical beliefs or political opinions that may be inferred from or contained in donation, contribution, grant, or recipient-selection data.
  • Health or similar sensitive data contained in employee assistance fund or similar applications or supporting documentation, where applicable.
  • Other special categories of Personal Data that Client or its authorized users choose to submit, if any, provided such submission is necessary, lawful, and authorized under the Agreement and applicable law.

ANNEX 2

Security measures 

‍
(1) Processor shall Process Personal Data in accordance with applicable law to which Processor is subject and in accordance with the data security requirements of the controls defined by latest available SOC 2 Type 2 implemented controls (or equivalent standard).  

(2) Processor shall appoint a fixed contact point for Client to carry out any matters in relation to the Processing of Personal Data.

(3) Processor shall ensure that Processor's employees receive adequate training and instructions, including, but not limited to, education on general safety awareness, relevant security policies and procedures, and Personal Data Processing. 

(4) Processor shall maintain organizational and technical measures to ensure separation of data between clients and systems. 

(5) Access Control of Processing Areas 
Processor shall maintain suitable measures in order to prevent unauthorized persons from gaining access to the data Processing equipment (namely telephones, database and application servers and related hardware) where the Personal Data is Processed or used. This is accomplished by measures such as:
  • establishing security areas;
  • protection and restriction of access paths;
  • securing the decentralized telephones, data Processing equipment and personal computers; 
  • establishing access authorizations for employees and third parties, including the respective documentation; 
  • regulations on card-keys;
  • restriction on card-keys;
  • all access to the data center where Personal Data is hosted is logged, monitored, and tracked;
  • the data center where Personal Data is hosted is secured by a security alarm system;
  • and - other appropriate security measures. 
(6) Access Control to Data Processing Systems 
Processor shall maintain suitable measures to prevent its Personal Data Processing systems from being used by unauthorized persons. This is accomplished by measures like: 
  • identification of the terminal and/or the terminal user to the Processor systems;
  • automatic time-out of user terminal if left idle, with identification and password required to reopen;
  • automatic turn-off of the user ID when several erroneous passwords are entered;
  • log file of events (monitoring of break-in-attempts); 
  • issuing and safeguarding of identification codes;
  • dedication of individual terminals and/or terminal users, and identification characteristics exclusive to specific functions; 
  • employee policies and training with respect to each employee's access rights to Personal Data (if any), including informing employees about their obligations and the consequences of any violations of such obligations, to ensure that employees will only access Personal Data and resources required to perform their job duties; and 
  • all access to data content is logged and monitored.
(7) Access Control to Use Specific Areas of Data Processing Systems 
Processor commits that the persons entitled to use its Personal Data Processing system are only able to access the data within the scope and to the extent covered by its access permission (role or authorization) and that Personal Data cannot be read, copied or modified or removed without authorization. This shall be accomplished by:
  • employee policies and training with respect to each employee’s access rights to the Personal Data;
  • allocation of individual terminals and/or terminal user, and identification characteristics exclusive to specific functions;
  • monitoring capability in respect of individuals who delete, add or modify the Personal Data;
  • effective and measured disciplinary action against individuals who access Personal Data without authorization;
  • release of Personal Data only to authorized persons;
  • control of files, controlled and documented destruction of Personal Data; and
  • policies controlling the retention of back-up copies.
(8) Availability Control 
Processor shall maintain suitable measures to ensure that Personal Data are protected from accidental destruction or loss. This is accomplished by: 
  • infrastructure redundancy;
  • Regularly Scheduled backup is setup with the cloud provider in case of failure.
  • complying with Processor’s business continuity policy; and
  • any detected security incident is recorded.
For all applications supported by the Processor, the following controls will be implemented:

(9) Transmission Control 
Processor shall maintain suitable measures to prevent the Personal Data from being read, copied, altered or deleted by unauthorized parties during the transmission thereof or during the transport of the data media. This is accomplished by:
  • use of industry standard firewall and encryption technologies to protect the gateways and pipelines through which the data travels (e.g. TLS/SSL);
  • encryption of certain highly confidential data (e.g., personally identifiable information such as National ID numbers, credit or debit card numbers) within system transmission; and
  • logging relevant security metadata for data transmissions.
(10) Input Control 
Processor implements suitable measures to ensure that it is possible to check and establish whether and by whom Personal Data has been input into Personal Data Processing systems or removed. This is accomplished by:  
  • an authorization policy for the input of data into memory, as well as for the reading, alteration and disposal of stored Personal Data;
  • authentication of the authorized personnel; 
  • protective measures for the data input into memory, as well as for the reading, alteration and disposal of stored Personal Data; 
  • utilization of user codes (passwords);
  • following a policy according to which all employees of Processor who have access to Personal Data Processed for Client shall reset their passwords at a minimum once in a 180 day period, or as defined in Processor’s IT Security Policy and in line with potential multi-factors of authentication;
  • providing that entries to Data Processing facilities (the rooms housing the computer hardware and related equipment) are capable of being locked; 
  • automatic log-off of user IDs that have not been used for a substantial period of time;
  • proof established within Processor’s organization of the input authorization; and
  • electronic recording of entries. 
(11) Processor system administrators (if any) 
Processor shall maintain measures to monitor its system administrators and to ensure that they act in accordance with instructions received. This is accomplished by:
  • individual appointment of system administrators;
  • adoption of suitable measures to register system administrators' access logs and keep them secure, accurate and unmodified for at least six months;
  • yearly audits of system administrators’ activity to assess compliance with assigned tasks, the instructions received by importer and applicable laws; 
  • keeping an updated list with system administrators’ identification details (e.g. name, surname, function or organizational area) and tasks assigned.
(12) Separation of Processing for different Purposes 
Processor shall maintain suitable measures to ensure that Personal Data collected for different purposes can be Processed separately. This is accomplished by:
  • access to Personal Data is separated through application security for the appropriate users; and
  • modules within Processor’s database separate which data is used for which purpose, i.e., by functionality and function. 
Client acknowledges and agrees that Processor may change its security policies and related security measures, provided that Processor maintains, at all times, an overall level of security as least as stringent as the one set forth in this DPA.