Last updated: August 19, 2026 | Version: 2026-08-v1

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the PatronSend Terms of Service(the "Terms") between PatronSend Technologies Inc. ("PatronSend", "we", "us") and the organization identified in the applicable account ("Customer", "you"). This DPA applies whenever PatronSend processes Personal Information on your behalf in connection with the Service. If there is any conflict between this DPA and the Terms regarding the processing of Personal Information, this DPA prevails.

1. Definitions

"Account Data" means information relating to your organization and its authorized users, including names, email addresses, organization details, billing information, and usage data.

"Donor Data" means Personal Information relating to your donors, patrons, and other individuals that you submit to, or that is synced into, the Service, including names, contact details, addresses, donation history, and the contents of receipts, acknowledgment letters, and other documents generated through the Service.

"Personal Information"means information about an identifiable individual, and includes "personal data" and "personal information" as defined under applicable Privacy Laws.

"Privacy Laws"means all privacy and data protection laws applicable to the processing of Personal Information under this DPA, including (as applicable) Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, New Zealand's Privacy Act 2020, Australia's Privacy Act 1988 (including the Australian Privacy Principles), the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation, and applicable US state privacy laws.

"Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Donor Data processed by PatronSend.

"Sub-processor"means a third-party service provider engaged by PatronSend to process Donor Data on PatronSend's behalf in order to provide the Service.

2. Roles of the Parties

2.1 Donor Data: PatronSend as processor and agent

As between the parties, you are the controller of (and the agency that holds) Donor Data. PatronSend holds and processes Donor Data solely as your agent and service provider, for the sole purpose of providing the Service to you, and does not use, disclose, or retain Donor Data for its own purposes. Donor Data held by PatronSend is held on your behalf and is treated as held by you.

2.2 Account Data: PatronSend as controller

PatronSend acts as an independent controller of Account Data, which it processes as described in the PatronSend Privacy Policy, including to operate, secure, support, and improve the Service. For clarity, PatronSend's service-improvement and analytics activities are limited to Account Data and aggregated, de-identified usage information; they do not extend to Donor Data.

2.3 Your responsibilities

You are responsible for:

  • the accuracy and lawfulness of the Donor Data you submit to the Service;
  • having a lawful basis (including any required notice to, or authorization from, donors) for the collection of Donor Data and its disclosure to PatronSend; and
  • responding to requests from donors regarding their Personal Information, as described in Section 7.

3. Processing Instructions

PatronSend will process Donor Data only:

  • to provide, maintain, and support the Service in accordance with the Terms;
  • as documented in this DPA;
  • as otherwise instructed by you through the Service's features and settings or in writing; and
  • as required by applicable law, in which case PatronSend will (unless legally prohibited) notify you of the legal requirement before processing.

This DPA and your use of the Service's features constitute your complete documented instructions. PatronSend will notify you if, in its opinion, an instruction would violate applicable Privacy Laws.

4. Confidentiality

PatronSend limits access to Donor Data to personnel and contractors who need access to provide the Service, and ensures that all such persons are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality.

5. Security

PatronSend implements and maintains appropriate technical and organizational measures to protect Donor Data against Security Incidents, as described in Annex B. These measures include encryption of data in transit and at rest, role-based access controls, secrets management, logging and monitoring, and regular backups. PatronSend may update Annex B from time to time, provided the updates do not materially reduce the overall protection of Donor Data.

6. Security Incident Notification

6.1 Notice to you

PatronSend will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting your Donor Data. The notice will describe, to the extent known: the nature of the incident, the categories and approximate volume of Donor Data affected, the measures taken or proposed to address the incident, and a contact point for further information. PatronSend will supplement the notice as further information becomes available.

6.2 Cooperation

PatronSend will provide reasonable cooperation and information to assist you in meeting any obligation you have under Privacy Laws to notify a regulator (including the Office of the Privacy Commissioner in New Zealand or Canada) or affected individuals. As between the parties, you are responsible for determining whether a regulatory or individual notification obligation applies and for making any such notification, and PatronSend will not notify a regulator or your donors directly unless required by law.

6.3 No fault admission

PatronSend's notification of a Security Incident is not an acknowledgment of fault or liability.

7. Donor Requests and Assistance

7.1 Routing

If PatronSend receives a request directly from a donor regarding their Personal Information (including a request for access, correction, or deletion), PatronSend will direct the donor to you and will not respond substantively except as required by law.

7.2 Assistance

Taking into account the nature of the processing, PatronSend will provide reasonable assistance, including through the Service's search, export, correction, and deletion features, to enable you to respond to donor requests within the timeframes required by applicable Privacy Laws.

8. Sub-processors

8.1 Authorization

You authorize PatronSend to engage the Sub-processors listed in Annex A.1to process Donor Data for the purposes described there. PatronSend will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, to the extent applicable to the services the Sub-processor provides, and remains responsible to you for each Sub-processor's performance.

8.2 Changes

PatronSend will give you at least 30 days' notice (by email or in-Service notice) before adding or replacing a Sub-processor that processes Donor Data. If you reasonably object on data protection grounds within that period, the parties will discuss the objection in good faith; if the objection cannot be resolved, you may terminate the affected subscription and Section 10 (Retention, Return, and Deletion) will apply.

8.3 Customer-directed services

Platforms that you connect to the Service under your own account and agreement, including Spektrix (as your data source) and your own email marketing platform (such as Dotdigital) used for sending, act on your behalf under your agreements with them and are not PatronSend Sub-processors.

9. Data Location

9.1 General

PatronSend processes Donor Data in the locations identified in Annex A and Annex C. Primary processing occurs in North America.

9.2 New Zealand Customers

For Customers that are New Zealand donee organizations, issued receipt documents and the associated donation records are stored and processed in the United States (AWS us-east-1). A backup copy of issued receipt documents is replicated to the Amazon Web Services Asia Pacific (New Zealand) Region (Auckland). Schedule 1 describes how PatronSend supports the Customer's record-keeping obligations in respect of those records.

9.3 Cross-border safeguards

Where Donor Data is transferred to or accessed from a country other than the country in which it was collected, PatronSend will ensure the transfer is protected by this DPA and any additional safeguards required by applicable Privacy Laws, including the jurisdiction-specific provisions in the Schedules.

10. Retention, Return, and Deletion

10.1 Retention

PatronSend retains issued documents and associated Donor Data in accordance with the retention provisions of the Terms, in support of your statutory record-keeping obligations.

10.2 Post-termination access

Following cancellation or termination, your account converts to read-only access as described in the Terms, and you may continue to access and export previously issued documents and records.

10.3 Return

At any time, including on termination, PatronSend will at your request provide your Donor Data, including all issued receipts and associated donation records, in a commonly used, machine-readable electronic format, at no additional charge.

10.4 Deletion

PatronSend will delete Donor Data on your written instruction, except to the extent retention is required by applicable law. You are responsible for ensuring that a deletion instruction is consistent with your own record-retention obligations (including obligations to tax authorities), and PatronSend may ask you to confirm this before completing deletion. PatronSend does not delete issued document records on its own initiative during the retention period described in the Terms.

11. Audit and Information

On your written request, no more than once per 12-month period (or following a Security Incident affecting your Donor Data), PatronSend will make available information reasonably necessary to demonstrate compliance with this DPA, including its current security documentation, Sub-processor list, and summaries of any third-party security assessments PatronSend holds. This Section describes your sole audit rights under this DPA; on-site audits are not provided.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms, and this DPA does not increase either party's total aggregate liability beyond what is provided there, except to the extent such a limitation is not permitted by applicable Privacy Laws.

13. Term; Order of Precedence; Amendment

This DPA takes effect when you accept the Terms (or, for existing Customers, on the effective date notified to you) and continues for as long as PatronSend processes Donor Data on your behalf, including any post-termination read-only period. Sections 6, 7, 10, 11, and 12 survive termination for as long as PatronSend holds Donor Data. Material amendments to this DPA that reduce its protections will be made only with notice to you and effective no earlier than 30 days after notice, and Section 8.2's objection mechanics apply by analogy.

Annex A: Sub-processors

A.1 Sub-processors that process Donor Data

These are the Sub-processors authorized under Section 8.1, and the notice and objection mechanics in Section 8.2 apply to changes to this list.

Sub-processorPurposeLocation of processing
Amazon Web Services, Inc.Cloud hosting, compute, and file storageUnited States (us-east-1); New Zealand (ap-southeast-6) for backup copies of NZ Customers' issued receipt documents per Schedule 1
Neon, Inc.Managed database hostingUnited States
Inngest, Inc.Background job processing and workflow orchestrationUnited States
Resend, Inc.Transactional email delivery, including delivery of receipts and acknowledgment letters to donors where the Customer's account is configured to send through ResendUnited States
Datadog, Inc.Application monitoring and error trackingUnited States

A.2 Service providers that process Account Data only

These providers do not process Donor Data and are therefore not Sub-processors as defined in Section 1. They are listed for transparency.

ProviderPurposeLocation of processing
Clerk, Inc.Authentication and user management for the Customer's authorized usersUnited States
Stripe, Inc.Subscription billing and payment processing for the Customer's account; no donor card dataUnited States
Upstash, Inc.Caching of organization entitlements and feature flags, and API rate limitingUnited States

A.3 Customer-directed services

These are not Sub-processors. Spektrix (the Customer's ticketing/CRM platform and data source); the Customer's own email marketing platform (e.g., Dotdigital) where the Customer routes sending through its own account. See Section 8.3.

Annex B: Security Measures

PatronSend maintains, at minimum:

  • Encryption. TLS 1.2+ for all data in transit; encryption at rest for databases, file storage, and backups.
  • Access control. Role-based access; unique credentials; multi-factor authentication for administrative access; access limited to personnel who require it to provide the Service.
  • Secrets management. Credentials and API keys stored in a managed secrets service; no credentials in source code.
  • Tenant isolation. Logical separation of Customer data with organization-scoped access controls enforced at the application and query layer.
  • Monitoring and logging. Application and infrastructure monitoring, error tracking, and audit logs retained for a minimum of two years.
  • Backups and recovery. Automated backups with defined recovery procedures; storage versioning for issued document records.
  • Vulnerability management. Dependency and infrastructure patching; security review of changes to authentication, access control, and document-generation code paths.
  • Personnel and contractors. Written confidentiality obligations for all personnel and contractors with access to Donor Data.

Annex C: Data Location Summary

Customer jurisdictionIssued documents & donation recordsApplication database & processing
Canada, United States, Australia, United KingdomUnited States (AWS us-east-1)United States (AWS us-east-1)
New ZealandUnited States (AWS us-east-1)United States (AWS us-east-1)

Backup copies of issued receipt documents for New Zealand Customers are additionally replicated to the AWS Asia Pacific (New Zealand) Region (Auckland). See Schedule 1.

Schedule 1: New Zealand

This Schedule applies where the Customer is established in New Zealand or is an approved donee organization under the Income Tax Act 2007 (NZ).

1. Agency

PatronSend holds and processes Donor Data solely as the Customer's agent for the purpose of providing the Service, within the meaning of section 11 of the Privacy Act 2020. Donor Data held by PatronSend is accordingly treated as held by the Customer.

2. Comparable safeguards

Without limiting Section 1 of this Schedule, PatronSend agrees to handle Donor Data in a manner that provides safeguards comparable to those in the Information Privacy Principles of the Privacy Act 2020, including: collecting and using Donor Data only for the purpose of providing the Service (IPPs 1, 10); ensuring reasonable security safeguards (IPP 5); assisting the Customer to give effect to donor access and correction rights (IPPs 6, 7); and not retaining Donor Data longer than provided in the Terms and this DPA (IPP 9). This Schedule is intended to constitute an agreement of the kind contemplated by IPP 12(1)(c)(v) (contractual comparable safeguards), should IPP 12 be held to apply to any disclosure of Donor Data to PatronSend.

3. Records location and access

Issued receipt documents and the associated donation records for the Customer are stored in the United States, with a backup copy of issued receipt documents replicated to the AWS Asia Pacific (New Zealand) Region (Auckland). PatronSend acknowledges that the Customer has record-keeping obligations under the Tax Administration Act 1994 (including sections 22 and 32) and the Goods and Services Tax Act 1985 (section 75), and will:

  • maintain the integrity and accessibility of these records consistent with the Contract and Commercial Law Act 2017;
  • make these records available to the Customer, and through the Customer to the Commissioner of Inland Revenue, on request, in an electronic and usable format, in a timely manner, and at no cost to Inland Revenue; and
  • on termination of the Service, return the records to the Customer in a meaningful and usable format as described in Section 10 of this DPA.

4. Offshore storage

The Customer's records are stored outside New Zealand as described in Section 3 of this Schedule. PatronSend is seeking the Commissioner's authorisation under section 22(8)(a) of the Tax Administration Act 1994 to store taxpayer electronic records outside New Zealand, and will notify the Customer of the grant, and of any withdrawal, of that approval. The Customer remains responsible for its own record-keeping obligations under the Inland Revenue Acts, including any authorisation it requires in respect of offshore storage of its records.

5. Notifiable privacy breaches

PatronSend's obligations under Section 6 of this DPA include providing the information reasonably required for the Customer to assess whether a Security Incident is a notifiable privacy breach under Part 6 of the Privacy Act 2020 and to notify the Office of the Privacy Commissioner and affected individuals where required.

Schedule 2: Canada

PatronSend processes Donor Data on the Customer's behalf consistent with PIPEDA's accountability principle: the Customer remains accountable for Donor Data transferred to PatronSend for processing, and this DPA constitutes the contractual protection through which the Customer ensures a comparable level of protection while the data is being processed by PatronSend. PatronSend acknowledges the Customer's record-retention obligations under the Income Tax Act (Canada) in respect of official donation receipts.

Schedule 3: Australia

Where the Customer discloses Donor Data to PatronSend from Australia, PatronSend agrees to handle that data in a manner consistent with the Australian Privacy Principles, so that the Customer may reasonably conclude, for the purposes of APP 8.2(a), that PatronSend is bound by obligations that have the effect of protecting the data in a way that, overall, is at least substantially similar to the APPs. PatronSend will assist the Customer with any notification assessment under the Notifiable Data Breaches scheme.

Schedule 4: United Kingdom and European Union

Where UK GDPR or EU GDPR applies to Donor Data, this DPA is intended to satisfy the requirements of Article 28(3), with the Customer as controller and PatronSend as processor. The subject matter, nature, purpose, and duration of processing are as described in the Terms and this DPA; the categories of data subjects are the Customer's donors and patrons; and the categories of Personal Information are as described in the definition of Donor Data. Where an international transfer mechanism is required, the parties will execute the applicable standard contractual clauses (or UK addendum/IDTA) on request.

Contact

Questions about this DPA: