Legal
Data Processing Addendum
Last updated September 20, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Givevery Enterprise Inc., a British Columbia corporation (BC1258390) ("givevery"), and the Customer that has agreed to the Agreement ("Customer").
In plain terms: you're in charge of your donors' data, and we handle it only on your instructions. The rest of this document makes that binding, in the detail your legal and procurement teams will look for.
This DPA applies automatically when the Customer accepts the Agreement. It does not need to be signed to be effective. Customers that want a countersigned copy can sign the execution block at the end and send it to privacy@givevery.com. We will return a countersigned copy.
1. Definitions
Terms not defined here have the meaning given in the Agreement.
- "Applicable Data Protection Law" means all privacy and data protection laws that apply to the processing of Customer Personal Data under the Agreement. These include, as applicable: Canada's Personal Information Protection and Electronic Documents Act (PIPEDA); British Columbia's Personal Information Protection Act (BC PIPA); Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25 (the "Québec Act"); Alberta's Personal Information Protection Act; the EU General Data Protection Regulation 2016/679 (GDPR); the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection; and U.S. state privacy laws, including the California Consumer Privacy Act (CCPA).
- "Customer Personal Data" means personal information in Customer Data that givevery processes on Customer's behalf.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Supervisory Authority" have the meanings given in the GDPR. Under Canadian law, "Controller" means the organization responsible for personal information, and "Processor" means a service provider acting under a written mandate. Under U.S. law, "Processor" includes a "service provider".
- "Security Incident" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. It includes a "confidentiality incident" under the Québec Act and a "breach of security safeguards" under PIPEDA.
- "Subprocessor" means a third party givevery engages to process Customer Personal Data.
- "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0).
2. Roles and scope
2.1 Customer is the Controller of Customer Personal Data. givevery is the Processor and processes it on Customer's behalf.
2.2 The subject matter, nature, purpose, duration, categories of data and categories of Data Subjects are described in Annex I.
2.3 This DPA doesn't apply to personal information givevery processes as a Controller, such as dashboard account data, website data, and billing records. givevery's Privacy Policy covers that information.
2.4 Customer's responsibilities. Customer is responsible for:
- having a lawful basis, and giving any required notice or obtaining any required consent, for the processing;
- the accuracy of Customer Personal Data;
- making sure its instructions comply with Applicable Data Protection Law.
3. Processing on Customer's instructions
3.1 givevery will process Customer Personal Data only on Customer's documented instructions, unless the law requires otherwise. In that case, givevery will tell Customer before processing unless the law prohibits it. The Agreement, this DPA and Customer's use and configuration of the Services are Customer's complete instructions.
3.2 givevery will tell Customer promptly if it believes an instruction infringes Applicable Data Protection Law.
3.3 givevery will not:
- sell or share Customer Personal Data (as those terms are defined in the CCPA);
- keep, use or disclose it for any purpose other than providing the Services, including its own commercial purposes;
- use it outside the direct business relationship with Customer;
- combine it with personal information from other sources, except as permitted by Applicable Data Protection Law;
- use it to train artificial-intelligence models.
givevery certifies that it understands and will comply with these restrictions. It will notify Customer if it can no longer meet its obligations under the CCPA.
4. givevery personnel and security
4.1 Confidentiality. givevery will make sure that everyone authorized to process Customer Personal Data is bound by confidentiality obligations and has access only as needed to perform their role.
4.2 Security measures. givevery will implement and maintain the technical and organizational measures described in Annex II. givevery may update these measures over time, provided the overall level of protection is not reduced.
5. Subprocessors
5.1 General authorization. Customer gives a general authorization for givevery to engage Subprocessors. The current Subprocessors are listed at givevery.com/subprocessors (Annex III), and Customer approves them.
5.2 Notice of changes. givevery will give at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data. Notice will be given by updating the Subprocessor page and emailing subscribed Customers.
5.3 Objection. Customer may object to a new Subprocessor on reasonable data-protection grounds, in writing, within the notice period. If so, the parties will discuss the concern in good faith. If givevery cannot reasonably accommodate the objection, Customer may terminate the affected Services without penalty and receive a refund of any prepaid, unused fees.
5.4 Flow-down and liability. givevery will enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective than this DPA. givevery remains responsible for its Subprocessors' performance.
6. Security Incidents
6.1 Notice. givevery will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data.
6.2 Content. The notice will describe, to the extent known:
- the nature of the incident;
- the categories and approximate number of Data Subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address it;
- a contact point.
givevery will provide further information as it becomes available.
6.3 Cooperation. givevery will take reasonable steps to contain, investigate and mitigate the incident. It will give Customer reasonable help with Customer's obligations to:
- notify regulators and individuals, including the Commission d'accès à l'information du Québec (where there is a risk of serious injury), the Office of the Privacy Commissioner of Canada (where there is a real risk of significant harm), and Supervisory Authorities under the GDPR;
- keep a register of incidents under the Québec Act and PIPEDA.
6.4 No admission. Notifying Customer of a Security Incident is not an admission of fault or liability.
7. Data Subject requests
7.1 givevery will provide features that let Customer access, correct, export and delete Customer Personal Data, including data export in a structured, commonly used technological format to support portability requests under the GDPR and section 27 of the Québec Act.
7.2 If givevery receives a request directly from a Data Subject about Customer Personal Data, it will forward the request to Customer within 5 business days and will not respond itself, except to confirm that it has been forwarded. givevery will give reasonable help where Customer cannot fulfil the request through the Services.
8. Assessments and assistance
givevery will give Customer reasonable information and help, taking into account the nature of the processing, for:
- data protection impact assessments and prior consultations under the GDPR;
- privacy impact assessments under the Québec Act, including assessments required before personal information is communicated outside Québec (section 17). On request, givevery will provide a transfer information package describing:
- where data is processed;
- the Subprocessors involved;
- the safeguards that apply;
- the legal frameworks of the destination jurisdictions.
9. Audits
9.1 Documentation. On written request, no more than once a year, givevery will provide:
- a completed security questionnaire, and a summary of its security program and policies;
- once available, its most recent SOC 2 report (under NDA);
- a summary of its most recent third-party penetration test.
9.2 Audits. If the documentation in 9.1 isn't enough to show compliance with this DPA, or a Supervisory Authority requires it, or after a Security Incident, Customer may carry out an audit (or have one done by an independent auditor bound by confidentiality) on these terms:
- at least 30 days' written notice;
- no more than once in any 12-month period, except after a Security Incident or where a regulator requires it;
- during business hours, and in a way that doesn't unreasonably disrupt operations or compromise the security of other customers' data;
- at Customer's own cost.
The parties will agree the scope in advance.
10. International transfers
10.1 Location. givevery stores Customer Personal Data primarily in Canada. givevery and its Subprocessors may process it in the other locations listed in Annex III.
10.2 EU/EEA. Transfers of Customer Personal Data from the EEA to givevery in Canada are covered by the European Commission's adequacy decision for Canada (Decision 2002/2/EC), to the extent it applies. Where the adequacy decision doesn't apply, the SCCs are incorporated into this DPA as follows:
- Module Two (Controller to Processor) applies.
- Clause 7: the optional docking clause applies.
- Clause 9: Option 2 (general written authorization) applies, with the notice period in section 5.2.
- Clause 11: the optional language does not apply.
- Clause 13: the competent Supervisory Authority is the authority of the EU Member State where Customer is established or, if Customer is not established in the EU, where its EU representative is established. If neither applies, it is the Irish Data Protection Commission.
- Clauses 17 and 18: the governing law and courts are those of Ireland.
- Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this DPA.
10.3 Onward transfers. givevery will make sure onward transfers to Subprocessors outside Canada and the EEA are protected by one of the following:
- the SCCs (Module Three, Processor to Processor);
- the EU-U.S. Data Privacy Framework;
- another lawful transfer mechanism.
10.4 UK. For transfers subject to the UK GDPR, the UK Addendum applies. Table 1 is completed with the parties' details in Annex I. Table 2 selects the SCC modules and options described above. Table 3 is completed by Annexes I to III. For Table 4, both parties may end the Addendum.
10.5 Switzerland. For transfers subject to the Swiss FADP, the SCCs apply with these adaptations:
- references to the GDPR are read as references to the FADP;
- the competent authority is the Swiss Federal Data Protection and Information Commissioner;
- "Member State" includes Switzerland, so Data Subjects there can bring claims in their place of habitual residence.
10.6 Canada and Québec. givevery will protect Customer Personal Data transferred outside Canada or Québec with contractual and other safeguards that provide a comparable level of protection to Applicable Data Protection Law.
10.7 Precedence. If the SCCs or the UK Addendum conflict with this DPA, the SCCs or the UK Addendum prevail.
11. Québec-specific commitments
In accordance with section 18.3 of the Québec Act, givevery will:
- use Customer Personal Data only to carry out the mandate or contract;
- keep it confidential and protect it with the measures in Annex II;
- destroy it (or return it) when the Agreement ends, subject to section 12;
- notify Customer's person in charge of the protection of personal information without delay of any breach, or attempted breach, of these obligations, including a confidentiality incident;
- allow Customer to verify compliance, as set out in section 9.
12. Return and deletion
12.1 During the Agreement and for 60 days after it ends, Customer can export Customer Personal Data through the Services.
12.2 After that, givevery will delete Customer Personal Data from production systems within 30 days. Backup copies will be overwritten on their normal rotation. Until then, they remain protected under this DPA.
12.3 givevery may keep limited Customer Personal Data where the law requires it (for example, its own 7-year transaction ledger for tax and audit purposes, as described in its Privacy Policy). Any retained data stays protected under this DPA and is used only for the purpose it was retained for.
12.4 On request, givevery will confirm deletion in writing.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement. However, nothing in this DPA limits either party's liability to Data Subjects under the SCCs or where Applicable Data Protection Law doesn't allow it to be limited.
14. Term, governing law and precedence
14.1 Term. This DPA remains in effect for as long as givevery processes Customer Personal Data.
14.2 Governing law. Except as provided in section 10, this DPA is governed by the law that governs the Agreement: British Columbia and the applicable federal laws of Canada.
14.3 Precedence. If this DPA conflicts with the Agreement, this DPA prevails on matters of data protection.
Annex I – Description of processing
A. List of parties
| Data exporter | Data importer | |
|---|---|---|
| Name | Customer (as identified in its givevery account or Order Form) | Givevery Enterprise Inc. |
| Address | As in Customer's account | British Columbia, Canada (full registered address available on request) |
| Contact | Customer's account owner or privacy officer | Mo Tabesh, CEO and Privacy Officer, privacy@givevery.com |
| Activities | Fundraising for Customer's charitable or nonprofit purposes | Providing the givevery donation platform |
| Role | Controller | Processor |
| Signature and date | Given by accepting the Agreement | Given by accepting the Agreement |
B. Description of processing
| Categories of Data Subjects | Donors and prospective donors; recipients of tributes and dedications; Customer staff and volunteers named in Customer Data |
|---|---|
| Categories of personal data | Name; email; phone number; mailing address; donation amount, currency, date, frequency, campaign or fund; tribute and dedication details and messages; tax-receipt details; limited payment details from Stripe (card brand, last 4 digits, expiry, status, identifiers); IP address, device and browser data; email delivery status |
| Sensitive data | None intended. Depending on Customer's mission, the fact of a donation may indirectly reveal religious, philosophical or political beliefs. Safeguards: tenant isolation by row-level security; MFA; encryption in transit and at rest; least-privilege access; no use for profiling or marketing; no disclosure except to Subprocessors |
| Frequency of transfer | Continuous, for the duration of the Agreement |
| Nature of processing | Collection, storage, organization, retrieval, transmission, display, export and deletion as needed to provide the Services |
| Purpose | Processing donations; issuing receipts and confirmations; sending tribute notifications; dashboard reporting and exports; security, fraud and abuse prevention; support |
| Retention | For the term of the Agreement, then as described in section 12 |
| Transfers to Subprocessors | As listed in Annex III, for the purposes and in the locations shown there |
C. Competent Supervisory Authority
As set out in section 10.2 (Clause 13).
Annex II – Technical and organizational security measures
| Area | Measures |
|---|---|
| Access control | MFA required for all dashboard users; minimum 12-character passwords; role-based access; least-privilege access for givevery personnel; production access restricted to authorized engineers |
| Tenant isolation | Postgres row-level security (RLS) policies isolate each Customer's data |
| Encryption | TLS 1.2+ for data in transit; AES-256 encryption at rest, managed by hosting providers |
| Payment data | Card data is collected and processed directly by Stripe (a PCI DSS Level 1 service provider). givevery never receives or stores full card numbers or CVCs. |
| Data residency | Primary database, authentication and storage are hosted in Canada (AWS ca-central-1) |
| Logging and monitoring | Audit logs of security-relevant events, kept for 1 year; error monitoring with PII scrubbing |
| Abuse prevention | Rate limiting of APIs and donation endpoints; Stripe fraud screening |
| Availability and backups | Managed database backups; infrastructure on providers with redundant data centres |
| Secure development | Code changes reviewed before deployment; secrets kept in managed environment variables, never in source code; dependency vulnerability scanning |
| Vendor management | Subprocessors assessed for security before engagement and bound by written data-protection terms |
| Incident response | Documented incident response procedure, including the notification commitments in section 6 |
| Personnel | Confidentiality obligations for all personnel; access removed promptly when personnel leave |
| Data minimization and deletion | Only data needed for the Services is collected; customer export; deletion as described in section 12 |
Annex III – Subprocessors
See givevery.com/subprocessors. This list is incorporated by reference and updated as described in section 5.
Optional execution block
| Customer | Givevery Enterprise Inc. | |
|---|---|---|
| Signature | ||
| Name | Mo Tabesh | |
| Title | Chief Executive Officer | |
| Date |