1. Scope and definitions
This Data Processing Addendum (DPA) forms part of the Client/Nonprofit Agreement when RaiseRace processes personal information on Client’s behalf (Client Personal Data). Terms such as controller, processor, business, service provider, personal data, personal information, processing, and data subject have the meanings given by applicable privacy law.
2. Roles and instructions
Client is the controller or business and RaiseRace is the processor or service provider for Client Personal Data. RaiseRace will process Client Personal Data to provide, secure, support, and improve the contracted service; follow Client’s documented lawful instructions; and comply with applicable law. The Client/Nonprofit Agreement and Client’s configured use of the service constitute documented instructions.
Client is responsible for the lawfulness, accuracy, notices, consents, permissions, and instructions associated with Client Personal Data. RaiseRace will notify Client if it reasonably believes an instruction violates applicable privacy law, unless prohibited from doing so.
3. Processing details
Processing may include collection, recording, organization, storage, retrieval, use, transmission, display, restriction, deletion, and other operations needed to provide the service. Data subjects may include Client personnel, fundraisers, participants, team members, donors, supporters, beneficiaries, and other people whose information Client submits or collects through RaiseRace.
Client Personal Data may include identity, contact, account, campaign, participation, communication, donation, transaction, device, and preference information. RaiseRace does not require Client to submit raw payment credentials, government identifiers, medical records, or other unnecessary sensitive data.
4. Confidentiality and security
RaiseRace will ensure that personnel authorized to process Client Personal Data are subject to confidentiality obligations. RaiseRace will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the service and risk, including access controls, authentication, encryption in transit, tenant separation, logging, backups, vulnerability management, and incident procedures.
5. Subprocessors
Client provides general authorization for RaiseRace to use subprocessors to provide the service. RaiseRace will require subprocessors to protect Client Personal Data under obligations materially consistent with this DPA and remains responsible for their performance to the extent required by applicable law.
RaiseRace’s core subprocessors are identified in the Privacy Policy. RaiseRace will provide reasonable notice of a material new subprocessor upon request or through an available client notice mechanism. Client may object on reasonable data-protection grounds, and the parties will work in good faith toward a commercially reasonable solution.
6. Security incidents
RaiseRace will notify Client without undue delay after confirming a security incident involving unauthorized access to or acquisition, use, disclosure, alteration, or destruction of Client Personal Data. RaiseRace will provide available information reasonably needed for Client’s legal obligations and will take reasonable steps to contain, investigate, and remediate the incident.
Notification is not an admission of fault or liability. Client is responsible for regulatory or individual notices relating to Client Personal Data unless applicable law assigns that obligation to RaiseRace.
7. Assistance and rights requests
Taking into account the nature of processing and information available, RaiseRace will provide reasonable assistance with verified data-subject requests, security and breach obligations, and legally required impact assessments or regulator consultations. RaiseRace may charge reasonable fees for assistance that is unusually burdensome and not caused by RaiseRace’s breach.
8. Return, deletion, and retention
At the end of the service, RaiseRace will make available the standard export described in the Client/Nonprofit Agreement and will delete or de-identify Client Personal Data when it is no longer required to provide the service, subject to legal, accounting, security, fraud-prevention, backup, dispute, and record-retention obligations.
9. Compliance information and audits
RaiseRace will make available information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient and applicable law requires an audit, Client may conduct one audit per year through an independent auditor under confidentiality obligations, during normal business hours, on reasonable notice, without accessing another client’s data or unreasonably disrupting the service. Client bears its audit costs unless the audit identifies a material breach by RaiseRace.
10. Restricted uses and U.S. state privacy laws
RaiseRace will not sell Client Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the business purposes specified in the Agreement, or combine it with personal information from another source except as permitted by applicable law to provide or secure the service.
11. International transfers and precedence
If applicable law requires additional transfer terms, the parties will enter the then-current standard contractual clauses or another valid transfer mechanism. If this DPA conflicts with the Client/Nonprofit Agreement regarding processing of Client Personal Data, this DPA controls. The Agreement’s liability provisions otherwise apply to this DPA.