This Data Processing Addendum (“DPA”) forms part of Givable’s Terms of Service (“Terms”) between Givable LLC (“Givable”) and the Organization using the Services (“Organization”). It applies whenever Givable processes Customer Personal Data on the Organization’s behalf, and it takes effect automatically, without signature, when the Organization accepts the Terms. If this DPA conflicts with the Terms, this DPA controls for the processing of Customer Personal Data.
Capitalized terms not defined here have the meanings given in the Terms.
1. Definitions
- “Customer Personal Data” means personal data within Customer Data that Givable processes on the Organization’s behalf in providing the Services.
- “Data Protection Laws” means the laws that apply to the processing of Customer Personal Data, which may include the EU General Data Protection Regulation (“GDPR”), the UK GDPR, Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and substantially similar provincial laws, including Québec’s Act respecting the protection of personal information in the private sector, and the California Consumer Privacy Act (“CCPA”).
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- “Subprocessor” means a third party engaged by Givable that processes Customer Personal Data.
- “Standard Contractual Clauses” means the clauses approved by the European Commission in Decision 2021/914, and the equivalent UK addendum, as they apply to the transfer.
Terms such as “controller,” “processor,” “data subject,” “personal data,” and “processing” have the meanings given in the applicable Data Protection Laws, and include their equivalents under those laws, such as “business” and “service provider” under the CCPA.
2. Roles and Instructions
The Organization is the controller of Customer Personal Data, and Givable is its processor. Where the Organization is itself a processor for another party, Givable is its subprocessor, and the Organization is responsible for obtaining that party’s authorization.
Givable processes Customer Personal Data only on the Organization’s documented instructions. Those instructions are the Terms, this DPA, the Organization’s configuration and use of the Services, and any other written instructions the parties agree. Givable will tell the Organization if it believes an instruction infringes Data Protection Laws, unless the law prohibits it.
The Organization is responsible for the lawfulness of its instructions and of the Customer Personal Data it provides, including having a lawful basis for processing and providing any notices and obtaining any consents that Data Protection Laws require.
Annex 1 describes the processing.
3. Givable’s Obligations
Givable will:
- process Customer Personal Data only as described in Section 2, unless the law requires otherwise, in which case Givable will inform the Organization before processing unless the law prohibits it
- ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, and access it only as described in Section 7 of the Terms
- maintain the technical and organizational measures described in Annex 2, which Givable may update as long as the overall level of protection is not reduced
- taking into account the nature of the processing, help the Organization meet its obligations for security, Security Incident notification, data protection impact assessments, and consultation with regulators, using the information available to Givable
- keep records of its processing activities as Data Protection Laws require
4. Subprocessors
The Organization gives Givable general authorization to engage Subprocessors. Givable will:
- make its current list of Subprocessors available to the Organization on request
- impose on each Subprocessor, by written contract, data protection obligations that provide at least the level of protection in this DPA
- remain responsible to the Organization for each Subprocessor’s performance of those obligations
- notify the Organization’s account administrators at least 30 days before adding or replacing a Subprocessor. Where a change is needed urgently for security or to keep the Services running, Givable will notify the Organization as soon as possible after the change.
The Organization may object to a new Subprocessor on reasonable data protection grounds by writing to privacy@givable.com within 30 days of the notice. The parties will work in good faith to resolve the objection. If they cannot, the Organization may terminate the affected Services, and Givable will refund any fees paid in advance for the period after termination.
5. Data Subject Requests
If Givable receives a request from a data subject about Customer Personal Data, Givable will direct the data subject to the Organization and will not respond to the request itself, except to confirm it was received, unless the Organization authorizes it or the law requires it. The Services include tools that let the Organization access, correct, export, and delete Customer Personal Data. Where those tools are not enough, Givable will provide reasonable assistance so the Organization can respond within the time Data Protection Laws allow.
6. Security Incidents
Givable will notify the Organization’s account administrators without undue delay after becoming aware of a Security Incident. The notice will describe, as far as then known, the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Givable will provide further information as it becomes available, take reasonable steps to contain and remedy the incident, and cooperate with the Organization so it can meet its own notification and record-keeping obligations. Notice of a Security Incident is not an acknowledgment of fault or liability.
7. International Transfers
Givable is based in the United States. Givable’s databases are hosted in the United States unless the Organization has a dedicated database in another region. Files and media are stored and delivered through a global network, and Customer Personal Data may be processed in the United States and in other countries where Givable or its Subprocessors operate.
Where Data Protection Laws require a transfer mechanism for Customer Personal Data transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses apply and are incorporated into this DPA by reference, as follows: Module Two (controller to processor), or Module Three (processor to processor) where the Organization is a processor; Clause 7 (docking clause) applies; under Clause 9, option 2 (general authorization) applies, with the notice period in Section 4 of this DPA; under Clause 11, the optional language does not apply; Clauses 17 and 18 are governed by, and disputes resolved in, the courts of Ireland; and Annexes I and II of the clauses are completed by Annexes 1 and 2 of this DPA. For transfers from the United Kingdom, the UK International Data Transfer Addendum applies to those clauses. For transfers from Switzerland, references to the GDPR are read as references to the Swiss Federal Act on Data Protection.
For Customer Personal Data subject to Canadian Data Protection Laws, Givable will protect it with a level of protection comparable to what those laws require, including when it is processed outside Canada, and will support the Organization in any assessment it must carry out before communicating personal information outside Québec.
8. Audits
Givable will make available to the Organization the information reasonably necessary to demonstrate compliance with this DPA. This includes, once issued, Givable’s most recent SOC 2 report, provided under confidentiality. If that information is not enough to meet a requirement of Data Protection Laws or a regulator, the Organization may conduct an audit, no more than once a year unless a regulator requires otherwise or following a Security Incident, on at least 30 days’ written notice, during business hours, in a way that does not disrupt the Services or compromise other customers’ data, under confidentiality, and at the Organization’s expense.
9. Return and Deletion
The Organization may export Customer Personal Data at any time while its account is active, and for 30 days after termination, as described in the Terms. After that period, Givable will delete Customer Personal Data from its active systems, and it will be removed from backups as those backups expire in the ordinary course, except where Data Protection Laws or other laws require Givable to keep it. Givable will continue to protect any data it keeps under this DPA for as long as it keeps it.
10. California Service Provider Terms
For Customer Personal Data subject to the CCPA, Givable acts as a service provider. Givable will not sell or share Customer Personal Data; will not retain, use, or disclose it for any purpose other than the business purposes of providing the Services as described in the Terms and this DPA; will not retain, use, or disclose it outside the direct business relationship with the Organization; and will not combine it with personal information Givable receives from others, except as the CCPA permits. Givable will comply with the CCPA’s obligations for service providers and will notify the Organization if it can no longer meet them. The Organization may take reasonable steps to stop and remedy any unauthorized use.
11. Liability and Term
Each party’s liability arising out of or related to this DPA is subject to the limitations of liability in the Terms, except where Data Protection Laws do not allow that limitation. This DPA remains in effect for as long as Givable processes Customer Personal Data on the Organization’s behalf. Givable may update this DPA as described in Section 30 of the Terms, and no update will reduce the overall level of protection for Customer Personal Data.
12. Contact
Questions about this DPA, notices, and objections may be sent to Givable’s Privacy Officer at privacy@givable.com, or by mail to Givable LLC, Attn: Privacy Officer, 9864 Cherry Valley Ave SE, Caledonia, MI 49316, USA.
Annex 1: Details of Processing
Parties. The data exporter is the Organization (controller, or processor where applicable). The data importer is Givable LLC (processor). Contact for both is as set out in the account and in Section 12.
Subject matter and duration. Givable processes Customer Personal Data to provide the Services, for as long as the Organization uses them and as described in Section 9.
Nature and purpose. Hosting, storing, and organizing supporter records; processing donations, recurring gifts, event registrations, and other transactions through the Organization’s payment accounts; sending email and text messages on the Organization’s behalf; generating receipts; publishing fundraising pages and content the Organization chooses to publish; reporting and analytics for the Organization; Givable AI features the Organization enables; screening posted content for policy violations; support; and security.
Categories of data subjects. Donors, supporters, and prospective supporters; peer-to-peer fundraisers and team members; event registrants and guests; recipients of the Organization’s messages; leads and contacts the Organization records; and the Organization’s own users.
Categories of personal data. Contact details (name, email, phone, mailing address); giving and transaction history, including recurring schedules and receipts; payment references (full card numbers are handled by the payment processor and not stored by Givable); event registrations, tickets, seating, and check-in; communication history and preferences, including consent to receive messages; content and media, including photos and written updates; responses to custom questions the Organization creates; notes and other free text the Organization records; account and login information for supporter portal users; and technical data such as IP addresses and device information.
Sensitive data. The Services are not designed for special categories of personal data. The Organization should collect such data, for example health information in custom questions, only where necessary and lawful, and is responsible for doing so.
Frequency. Continuous, while the Organization uses the Services.
Annex 2: Technical and Organizational Measures
Givable maintains the following measures, and may update them as long as the overall level of protection is not reduced.
- Encryption. Data is encrypted in transit with TLS and at rest with AES-256.
- Data separation. Each customer’s supporter data is stored in its own database, separate from other customers’ data.
- Access control. Role-based permissions control what each user can see and do. Users sign in with securely hashed passwords, passkeys, or single sign-on, and can use two-factor authentication.
- Personnel access. Givable personnel access Customer Personal Data only to provide support, maintain and secure the Services, or comply with law. Support sessions in which personnel sign in to an account are logged.
- Logging and monitoring. Givable logs security-relevant account activity and monitors its systems for availability and unusual activity.
- Payment data. Card details are collected by the payment processor’s secure payment fields and are never stored on Givable’s systems.
- AI safeguards. Before content is sent to an AI model provider, personal data such as names, email addresses, phone numbers, postal addresses, and payment details is replaced with placeholders. Administrators can turn AI features off or limit them.
- Abuse protection. Public forms use bot protection and rate limiting.
- Backups and recovery. Databases have point-in-time backups to support recovery.
- Deletion and retention. Retention periods are applied automatically, as described in the Privacy Policy, and Customer Personal Data is deleted as described in Section 9.
- Vendor management. Givable keeps a register of the vendors that receive customer data and requires written data protection terms from each Subprocessor.
- Compliance program. Givable is building its security program to SOC 2 standards, and its SOC 2 audit is in progress.
Annex 3: Subprocessors
The current list of Subprocessors is available to the Organization on request from privacy@givable.com. Changes are made as described in Section 4.