Data Processing Addendum
Updated 6 days ago
This Data Processing Addendum governs Gratona’s processing of personal data on behalf of the customer identified in the attached Customer Schedule. It forms part of the agreement under which Gratona provides its services to that customer, including the applicable order or service agreement and the Gratona Terms of Service identified in that agreement (the Agreement).
Supporting documents: Security measures · Data retention and deletion · Subprocessors.
The Customer Schedule identifies the versions incorporated into the parties’ agreement and any service-specific details. Later website updates do not automatically change the accepted terms.
1. Parties and scope
Gratona means the legal entity identified as provider in the Customer Schedule. Customer means the legal entity identified as customer in that schedule. Customer Personal Data means personal data that Gratona processes on Customer’s behalf in providing the services covered by the Agreement (Services), including data submitted by Customer’s authorised users and data generated from that processing.
Data Protection Law means the privacy and data protection laws applicable to that processing, including the EU General Data Protection Regulation 2016/679 (GDPR). Controller, processor, personal data, processing and personal data breach have their meanings under applicable Data Protection Law. A Subprocessor is another processor engaged by Gratona to process Customer Personal Data on Customer’s behalf.
Customer acts as controller and Gratona as processor unless the Customer Schedule expressly identifies Customer as a processor. Where Customer acts as processor, it confirms that it has its controller’s authority to appoint Gratona and issue the instructions recorded here. Gratona acts as subprocessor for that processing.
This Addendum does not govern personal data that either party processes as an independent controller for its own necessary business purposes, such as managing its supplier or customer relationship or complying with its own legal obligations. This exclusion does not authorise Gratona to repurpose Customer’s donor, sponsor or beneficiary records for its own purposes. Each party remains responsible for its independent-controller processing.
The Customer Schedule and Annexes 1–4 form part of this Addendum. Incomplete schedule fields must be completed and agreed before acceptance. A blank field does not authorise processing, a Subprocessor or a transfer.
2. Instructions and permitted processing
Gratona will process Customer Personal Data only on Customer’s documented instructions, including instructions concerning international transfers, unless processing is required by applicable law. In that case, Gratona will notify Customer of the legal requirement before processing unless the law prohibits notification on important grounds of public interest.
The Agreement, this Addendum, the completed schedules and Customer’s authorised configuration and use of the Services constitute documented instructions. Further instructions may be recorded in writing between authorised representatives. Instructions must be lawful and within the agreed service scope. Gratona will promptly inform Customer if it cannot comply and will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law. The parties will resolve the affected instruction before the disputed processing proceeds, except where required by law.
Customer determines the purposes of processing, the records it supplies, the users and connected services it authorises, its retention requirements and the lawful basis for processing. Customer will provide required notices and establish any necessary consents or other legal permissions. These responsibilities do not relieve Gratona of its own obligations.
Gratona will not sell Customer Personal Data, use it for unrelated advertising, or use it to train general-purpose AI models. Gratona will contractually require the same restrictions of Subprocessors to the extent they process Customer Personal Data on its behalf. AI processing is limited to the workflows, data categories, providers and safeguards expressly identified in Annexes 1–3. Enabling an AI feature does not authorise unrelated processing or add a service to Customer’s commercial package.
Any processing of Customer Personal Data to create anonymised information under the Agreement remains subject to this Addendum, lawful documented instructions and applicable law. The uses permitted in the Agreement’s anonymous-information provisions apply only after the information meets the anonymisation requirements stated there. Those provisions do not authorise a recipient to access Customer Personal Data outside this Addendum or override restrictions on data obtained through connected services.
Customer-controlled third-party integrations may receive data on Customer’s instructions. Their classification depends on their actual role: a provider engaged by Gratona to process Customer Personal Data remains a Subprocessor even if an integration is optional. Customer’s separate agreement with an independent service does not remove Gratona’s obligations for the processing Gratona performs.
3. Confidentiality and security
Gratona will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality. Access will be limited to persons who need it to provide, secure or support the Services and who act within their authorised responsibilities.
Taking account of the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, Gratona will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data. The agreed measures are set out in Annex 2. They will address ongoing confidentiality, integrity, availability and resilience, timely restoration after an incident, and a process for regularly assessing the effectiveness of the measures, as appropriate to the risks and recorded in that Annex.
Gratona may update those measures provided that the changes do not materially reduce the overall protection of Customer Personal Data or breach an express commitment in the completed schedules. Any material change to the agreed processing scope, sensitive-data safeguards or residency commitment requires written agreement. Publication of a new policy does not by itself amend this Addendum.
Customer will maintain appropriate access permissions for its users, protect its credentials and use available security controls appropriately. Gratona remains responsible for the security measures allocated to it under this Addendum.
4. Subprocessors
Customer gives general written authorisation for the Subprocessors identified in the completed Annex 3. Gratona will give Customer at least 30 calendar days’ written notice before an additional or replacement Subprocessor begins processing Customer Personal Data. The notice will identify the provider, processing purpose, relevant locations and material safeguards, and will be sent to the Customer notice contact. Updating a website alone does not replace this notice.
Customer may object within 15 calendar days after receiving notice on reasonable grounds relating to the protection of Customer Personal Data. The parties will work in good faith to resolve the objection, including considering an alternative provider or a way to provide the affected function without the disputed processing. Gratona will not provide Customer Personal Data to the disputed Subprocessor while a timely objection remains unresolved.
If a timely objection remains unresolved at the end of the notice period and no reasonable solution is available, either party may terminate the affected Services on written notice before the disputed processing begins. Gratona will refund unused prepaid fees attributable to the terminated Services; fees for Services already provided remain payable. If the affected function cannot reasonably be separated from the remaining Services, Customer may terminate the affected subscription on the same basis. Nothing in this section limits a more favourable cancellation right expressly agreed in the Agreement.
Before a Subprocessor processes Customer Personal Data, Gratona will enter into a written contract imposing data protection obligations that provide at least the protection required by this Addendum for the relevant processing, including appropriate security and lawful transfer safeguards. Gratona remains responsible to Customer for the Subprocessor’s performance of those obligations. On request, Gratona will provide information needed to demonstrate these arrangements and copies of relevant Subprocessor terms where required by the applicable transfer clauses, with lawful redactions to protect confidential information.
5. Personal data breaches
Gratona will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. This obligation applies irrespective of ordinary support hours, weekends and holiday support arrangements.
The initial notification will include the information then available about the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact for further information. Gratona may provide information in phases as it becomes available and will not delay initial notification solely because an investigation is incomplete.
Gratona will take appropriate steps to contain, investigate and remedy the breach and will reasonably assist Customer with its notification and other legal obligations, taking account of the nature of processing and the information available to Gratona. Customer remains responsible for deciding whether and how to notify individuals or authorities, except where Gratona has a separate legal obligation. Gratona will coordinate relevant communications where legally permitted.
Notification or assistance does not by itself admit fault or liability. Routine unsuccessful attempts that do not compromise Customer Personal Data are not personal data breaches under this section.
6. Assistance and individual rights
Taking account of the nature of processing, Gratona will assist Customer through appropriate technical and organisational measures, insofar as possible, in responding to requests to exercise individuals’ rights under Data Protection Law. If Gratona receives such a request directly concerning Customer Personal Data, it will promptly notify Customer and will not independently fulfil it except on Customer’s instructions or where required by law.
Taking account of the nature of processing and the information available to it, Gratona will assist Customer with security of processing, breach notification, data protection impact assessments and prior consultation with supervisory authorities. Gratona will provide relevant information about its processing, safeguards and Subprocessors for those purposes.
Ordinary assistance available through the Services is included in the subscription. Where Customer requests substantial additional work beyond ordinary assistance, the parties may agree reasonable charges in advance. Gratona will not charge for remedying its own breach of this Addendum, condition mandatory assistance on a new fee agreement, or delay assistance required to meet a statutory deadline because a fee is disputed.
7. Information and audits
Gratona will make available information reasonably necessary to demonstrate compliance with this Addendum and will allow for and contribute to audits, including inspections, by Customer or an independent auditor mandated by Customer.
The parties will first use relevant documentation, responses and available independent assurance reports where these adequately address the audit purpose. This does not require Customer to accept documents as a substitute where an inspection is reasonably necessary or required by law. No certification or independent audit report is represented as held unless expressly identified in Annex 2.
Routine audits will ordinarily occur no more than once in a twelve-month period, on at least 30 calendar days’ notice, during normal business hours and subject to proportionate confidentiality and security arrangements. These limits do not restrict an audit required by a competent authority, following a relevant breach, where there are reasonable grounds to suspect material non-compliance, or otherwise required by Data Protection Law or the applicable transfer clauses. Notice will be shortened where necessary for those circumstances.
Audits will avoid unreasonable disruption and unnecessary disclosure of other customers’ data, privileged material, credentials or trade secrets. The parties will agree an alternative means of demonstrating compliance where direct access would create such a risk. These protections will not be used to prevent a legally required audit. Intrusive technical testing requires a separately agreed testing scope.
Customer bears its own audit costs. Any charge for exceptional assistance by Gratona requires prior written agreement, except that Gratona bears reasonable costs of addressing its own material non-compliance. Charges will not make mandatory audit rights ineffective.
8. International transfers and government requests
Customer authorises processing only in the locations described in the completed schedules and subject to the safeguards required by Data Protection Law. Disclosure of a processing location is not, by itself, a lawful international-transfer mechanism.
For a transfer requiring safeguards under GDPR Chapter V, the parties will use the applicable arrangements in Annex 4. Gratona will maintain appropriate safeguards for onward transfers and comply with the assessment, notification, challenge, cooperation and suspension obligations in the applicable transfer clauses. The parties will document any required transfer impact assessment and supplementary measures before relying on those clauses.
If Gratona receives a legally binding demand for Customer Personal Data from a public authority, it will notify Customer where legally permitted, assess the demand’s lawfulness, challenge it where required by the applicable transfer clauses, and limit disclosure to what it is legally required to provide. Where notification is prohibited, Gratona will use the efforts required by those clauses to obtain permission to notify Customer.
If the agreed transfer safeguards can no longer be met, Gratona will promptly notify Customer and the parties will suspend the affected transfers until lawful safeguards are restored or will follow the applicable termination and return or deletion requirements.
9. Return, deletion and retention
At the end of the Services, Customer may choose return or deletion of Customer Personal Data, subject to any retention required by applicable law. The Agreement’s 30-calendar-day export period applies unless a longer period is agreed in writing. Customer may request deletion sooner. Return will include the records and associated content described in the completed export schedule, in a commonly used, machine-readable format where applicable.
Following return, or where Customer chooses deletion, Gratona will delete remaining copies within the periods in Annex 2, except to the extent retention is required by law. If Customer has not given a choice by the end of the export period, Gratona will notify Customer and provide a further 15 calendar days to give instructions before treating the absence of instructions as an instruction to delete. This additional instruction period does not create a longer hosted-service entitlement.
Any residual backup copies will remain protected, isolated from ordinary use and deleted through the defined backup-expiry process in Annex 2. If a backup is restored for recovery, relevant deletion instructions will be reapplied. Backups do not create an indefinite retention exception. Where law requires retention, Gratona will identify the requirement and duration where legally permitted, restrict processing to that requirement, and delete the data when the requirement ends.
Gratona will require its Subprocessors to apply corresponding return and deletion obligations. It will provide written confirmation of deletion on request and as required by the applicable transfer clauses. This Addendum continues to protect Customer Personal Data for as long as Gratona or its Subprocessors retain it.
10. Relationship with the Agreement
For a conflict concerning protection of Customer Personal Data, mandatory transfer clauses take precedence, followed by this Addendum and its completed schedules, then the Agreement. A Customer Schedule may specify processing details or additional safeguards but cannot reduce mandatory transfer protections. The Agreement continues to govern commercial matters not expressly addressed here.
To the extent permitted by Data Protection Law, the Agreement’s liability exclusions and limitations apply to this Addendum as part of the same aggregate liability arrangement. This provision does not create a monetary cap where the Agreement contains none. Nothing limits an individual’s statutory rights, a supervisory authority’s powers, or any liability that cannot lawfully be limited, including liability under mandatory transfer clauses where those clauses prohibit the limitation.
This Addendum does not add a service-level agreement, uptime guarantee, certification, data-residency option or commercial feature entitlement. Governing law and dispute provisions in the Agreement apply except where the applicable transfer clauses require otherwise. Changes to this Addendum require written agreement by both parties.
Annex 1 — Processing details
Item | Processing covered |
|---|---|
Subject matter | Provision of the Gratona Services selected in the Customer Schedule. |
Duration | The service term and the limited return, deletion and legally required retention periods recorded in this Addendum and Annex 2. |
Nature of processing | Collection through authorised forms and imports; organisation, storage, retrieval, updating, linking and reporting; customer-directed communications and disclosures; support and troubleshooting; permitted translation or other agreed AI processing; export, restriction and deletion. Only selected workflows are authorised. |
Purposes | Operating Customer’s fundraising, donor relationship and programme administration workflows and providing the related Services under the Agreement. |
Data subjects | Customer’s donors, prospective donors, sponsors, beneficiaries, children and their guardians, staff, volunteers, partner contacts and authorised users, to the extent relevant to selected Services. |
Ordinary data | Names, contact details, identifiers, account and access information, programme and sponsorship relationships, donation and pledge records, payment references and status, preferences, consent records, correspondence, photographs, documents, notes and service activity records, to the extent supplied or generated in the selected workflows. |
Financial information | Donation amounts and history, payment-provider identifiers, mandate or payment references, and any bank details expressly authorised in the Customer Schedule. No processing of card security codes is authorised. Payment credentials handled directly by a payment provider remain subject to that provider’s actual role and terms. |
Frequency | Ongoing or event-driven during use of the Services, including initial and subsequent imports. |
Restricted data | Article 9 special-category data, criminal-conviction data under Article 10, government identity documents and detailed safeguarding case files require express identification, purpose and safeguards in the Customer Schedule before submission. Ordinary photographs are not treated as biometric identification data merely because they depict a person; biometric identification is not authorised. |
Children’s data | Only data reasonably necessary for the agreed programme. Customer determines lawful authority, notices and consent requirements. Recipient visibility, publication of photographs, correspondence access and any AI use must follow the agreed safeguards in the Customer Schedule and Annex 2. |
AI processing | Only the specifically authorised workflows and data categories in the Customer Schedule, using providers in Annex 3. Outputs remain subject to Customer’s review. This Addendum does not authorise automated decisions producing legal or similarly significant effects on individuals. |
Annex 2 — Security, retention and export measures
The completed security schedule attached to the Customer Schedule specifies the controls applicable to Customer Personal Data, including access management; transmission and storage protection; tenant and file access boundaries; incident response; backup and restoration; secure development; personnel controls; logging; deletion; and assistance with individual rights.
That schedule must identify the actual arrangements and periods for each relevant data store, including files, logs and backups. A general reference to a policy or a supplier’s certification does not replace the agreed measures. The schedule is part of the parties’ binding processing arrangement when accepted.
Annex 3 — Subprocessors and processing locations
The completed Subprocessor schedule attached to the Customer Schedule identifies each authorised Subprocessor’s legal name, country of establishment, purpose, data categories and relevant processing locations. The schedule also identifies the applicable onward-transfer safeguards. It covers infrastructure, file storage, backups, logging, communications, customer support, payments and AI to the extent each provider acts as Gratona’s Subprocessor.
Customer-appointed independent services are identified separately where needed to describe the data flow. Their inclusion in a data-flow record does not automatically classify them as Gratona’s Subprocessors. Changes to the authorised Subprocessor schedule follow section 4.
Annex 4 — EEA international transfer terms
Where the parties identify the European Commission’s Standard Contractual Clauses under Implementing Decision (EU) 2021/914 as an applicable lawful transfer mechanism in the Customer Schedule, the relevant clauses in that decision are incorporated into this Addendum by reference without alteration except for the selections and completed details permitted by the clauses. Acceptance of this Addendum includes acceptance and signature of those clauses and their completed annexes. The parties will not rely on the 2021/914 SCCs for a transfer outside the scope of that decision, including where the importer’s relevant processing is directly subject to the GDPR and those clauses are unavailable for that transfer; an applicable alternative mechanism must be agreed before the affected transfer begins.
Official text: European Commission Implementing Decision (EU) 2021/914.
SCC provision | Selection |
|---|---|
Module | Module Two where Customer is controller and Gratona processor. Module Three applies only where the Customer Schedule expressly identifies Customer as processor and Gratona as subprocessor. Unselected modules do not apply. |
Clause 7 | Optional docking clause is not used. |
Clause 9(a) | Option 2, general written authorisation; at least 30 calendar days’ prior notice of additions or replacements. Section 4 records the objection procedure. |
Clause 11 | Optional independent dispute-resolution language is not used. |
Clause 13 and Annex I.C | The competent supervisory authority identified in the Customer Schedule in accordance with Clause 13. |
Clause 17 | Option 1; the law of the EU Member State identified in the Customer Schedule, allowing third-party beneficiary rights. |
Clause 18(b) | Courts of the EU Member State identified in the Customer Schedule. |
Annex I.A | Parties, contacts, roles, activities, signatures and dates in the Customer Schedule. |
Annex I.B | Annex 1 as specified by the Customer Schedule, including sensitive-data safeguards and transfer duration. |
Annex II | The completed security schedule under Annex 2, including measures supporting assistance to Customer. |
Subprocessor details | The completed Annex 3 schedule records authorised providers under general authorisation. Specific-authorisation Annex III is not selected. |
The SCCs prevail over inconsistent terms. This Addendum does not modify their third-party beneficiary rights, liability, audit rights or transfer suspension requirements. The parties will fulfil Clause 14’s assessment and documentation requirements and Clause 15’s obligations concerning public-authority access.
For transfers outside the scope of these SCCs, the parties will identify and enter into an applicable lawful mechanism before the transfer. This Annex does not assert participation in the EU–US Data Privacy Framework. UK or Swiss transfer adaptations apply only if completed and expressly agreed for the relevant processing.
Prepared with reference to the Common Paper DPA Standard Terms, Version 1.1, available under CC BY 4.0. This is an adapted Gratona document. Its instructions, AI restrictions, Subprocessor notice and objection process, breach notice, audit procedure, retention terms and schedules differ from the Common Paper standard. Common Paper’s standard terms are not separately incorporated into this Addendum.