• Home
  • Organizations
  • Store
HPLY blue logo
HPLY - Cart2
Points: —Favorites
Data Processing Addendum banner for HPLY

Data Processing Addendum

  • Legal & Policies >
  • Data Processing Addendum
Back to Legal & Policies

HPLY DATA PROCESSING ADDENDUM

Effective Date: August 10, 2026

This Data Processing Addendum (the “DPA”) forms part of the written agreement between HPLY Inc. (“HPLY”) and the customer, Nonprofit Organization, business partner, or other entity that has entered into the applicable services agreement, participation agreement, order form, or other written agreement with HPLY (the “Controller” and, together with HPLY, the “Parties”) (the “Agreement”).

This DPA governs HPLY’s Processing of Personal Data on behalf of the Controller in connection with the Services where HPLY acts as a Processor, Service Provider, Contractor, or equivalent entity under Applicable Data Protection Law.

Capitalized terms not defined in this DPA have the meanings given to them in the Agreement or, where applicable, Applicable Data Protection Law.

CORE DATA PROCESSING ADDENDUM

1. Definitions

For purposes of this DPA:

“Applicable Data Protection Law” means privacy, data-protection, and data-security laws applicable to HPLY’s Processing of Personal Data on behalf of the Controller under the Agreement, including, where applicable, the GDPR, UK GDPR and applicable United Kingdom data-protection law, Swiss data-protection law, the California Consumer Privacy Act as amended by the California Privacy Rights Act and implementing regulations (“CCPA”), and applicable U.S. state privacy laws.

“Controller” means the entity that determines the purposes and means of Processing Personal Data, including a “Business” or other equivalent regulated entity where applicable.

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

“GDPR” means Regulation (EU) 2016/679.

“Personal Data” means information that constitutes personal data, personal information, or an equivalent category of regulated information under Applicable Data Protection Law and that HPLY Processes on behalf of the Controller under the Agreement.

“Process,” “Processed,” and “Processing” have the meanings given under Applicable Data Protection Law.

“Processor” means an entity that Processes Personal Data on behalf of a Controller, including a Service Provider, Contractor, or equivalent regulated service provider where applicable.

“Restricted Transfer” means a transfer of Personal Data subject to a legal requirement for an approved international-transfer mechanism or safeguard under Applicable Data Protection Law.

“Security Incident” means an actual breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed by HPLY on behalf of the Controller.

Security Incident does not include unsuccessful attempts or activities that do not compromise Personal Data, including unsuccessful network scans, pings, failed login attempts, unsuccessful denial-of-service attempts, or other unsuccessful attacks or probes.

“Subprocessor” means a third party engaged by HPLY that Processes Personal Data on behalf of the Controller in connection with the Services.

“UK GDPR” means the United Kingdom version of the GDPR as incorporated into and amended by applicable United Kingdom law.

2. Scope and Roles

This DPA applies only to HPLY’s Processing of Personal Data on behalf of the Controller.

The Controller is the Controller, Business, or equivalent regulated entity with respect to Personal Data it submits to HPLY or directs HPLY to Process on its behalf.

HPLY acts as Processor, Service Provider, Contractor, or equivalent entity only to the extent HPLY Processes that Personal Data on behalf of the Controller.

Nothing in this DPA recharacterizes Processing for which HPLY independently determines lawful purposes and means as processor-side Processing where Applicable Data Protection Law recognizes HPLY as an independent Controller or Business for that Processing.

HPLY’s independent-controller Processing may include administration of HPLY’s own business relationship with the Controller, account and contract management, billing records, legal compliance, fraud prevention, security, corporate governance, defense of legal claims, and other purposes for which HPLY independently determines the purposes and means as permitted by applicable law.

HPLY will not treat raw Controller Personal Data as HPLY independent-controller data merely for general service improvement.

To the extent HPLY uses information for service improvement in an independent-controller capacity, that use will be limited to aggregated or de-identified information unless a separate lawful independent-controller purpose applies.

3. Controller Instructions

HPLY will Process Personal Data only on documented instructions from the Controller unless Applicable Data Protection Law requires HPLY to Process Personal Data otherwise.

The Agreement, this DPA, Controller configurations, authorized use of the Services, support requests, and other documented instructions consistent with the Agreement constitute the Controller’s instructions.

HPLY will not Process Personal Data for a materially different purpose from the Controller’s documented instructions unless the Controller provides additional instructions or Applicable Data Protection Law permits or requires the Processing.

If HPLY believes a Controller instruction violates Applicable Data Protection Law, HPLY may notify the Controller and suspend the affected Processing to the extent reasonably necessary while the Parties evaluate the instruction.

Nothing in this DPA requires HPLY to comply with an instruction that would require HPLY to violate law, materially impair the security or integrity of the Services, disclose another customer’s information, or undertake Processing outside the scope of the Agreement without the Parties’ written agreement.

4. Controller Responsibilities

The Controller is responsible for the lawfulness, accuracy, quality, and appropriateness of Personal Data and for the Controller’s instructions to HPLY.

The Controller represents that it has all rights, notices, consents, authorizations, and lawful bases required for HPLY to Process Personal Data as contemplated by the Agreement and this DPA.

The Controller is responsible for configuring and using the Services in compliance with Applicable Data Protection Law.

The Controller will not instruct HPLY to Process Personal Data in violation of applicable law or to collect categories of Personal Data not reasonably necessary for the Services.

The Controller is responsible for responding to Data Subjects regarding Processing for which the Controller determines the purposes and means, except to the extent this DPA requires HPLY to provide assistance.

5. Processing Details

The subject matter, duration, nature, purposes, categories of Data Subjects, categories of Personal Data, and retention framework applicable to HPLY’s Processor-side Processing are described in Schedule 1.

The Parties agree that Schedule 1 provides the Processing information required by Applicable Data Protection Law for the Processing governed by this DPA.

6. Confidentiality

HPLY will ensure that persons authorized to Process Personal Data on HPLY’s behalf are subject to confidentiality obligations or an appropriate statutory duty of confidentiality.

HPLY will limit access to Personal Data to personnel and service providers that require access for authorized purposes.

HPLY will provide appropriate privacy and security instructions to personnel with access to Personal Data based on their responsibilities.

The confidentiality obligations in this DPA supplement any confidentiality obligations contained in the Agreement.

7. Processing Restrictions

7.1 Purpose Limitation

HPLY will Process Personal Data only for the purposes described in the Agreement, this DPA, documented Controller instructions, or as otherwise permitted or required by Applicable Data Protection Law.

7.2 No Unauthorized Commercial Use

Where HPLY acts as Processor, Service Provider, Contractor, or equivalent entity, HPLY will not use Personal Data for HPLY’s own independent advertising, data brokerage, or unrelated commercial purposes.

7.3 California Service Provider and Contractor Requirements

HPLY will not sell or share such Personal Information, as “sell” and “share” are defined by the CCPA, except to the extent a disclosure or other Processing is expressly permitted for a Service Provider or Contractor under the CCPA.

7.4 Combining Personal Information

Where HPLY acts as a Service Provider or Contractor under the CCPA, HPLY will not combine Personal Information received from or on behalf of the Controller with Personal Information received from or on behalf of another person or collected through HPLY’s own interaction with a consumer except to the extent the combination is permitted for a Service Provider or Contractor under the CCPA.

7.5 Compliance Notification

Where required by Applicable Data Protection Law, HPLY will notify the Controller if HPLY determines that it can no longer satisfy applicable Service Provider, Contractor, Processor, or comparable obligations concerning Personal Data.

7.6 Remediation Rights

Where required by Applicable Data Protection Law, the Controller may take reasonable and appropriate steps to stop and remediate unauthorized Processing of Personal Data by HPLY.

Any such measures must be proportionate to the issue, consistent with Applicable Data Protection Law, and implemented in a manner that does not require HPLY to disclose information concerning other customers, compromise security, disclose privileged materials, or permit unrestricted access to HPLY systems.

8. Security

HPLY will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

HPLY’s minimum technical and organizational measures are described in Schedule 1.

Security measures may evolve over time as HPLY’s Services, technology, risks, and legal obligations change.

HPLY may modify its security measures provided that HPLY does not materially decrease the overall level of protection for Personal Data during the applicable Services without a lawful and reasonable basis.

Nothing in this DPA represents that any security measure eliminates all risk.

9. Security Incidents

HPLY will notify the Controller of a Security Incident without undue delay after HPLY becomes aware of the Security Incident.

HPLY’s notification obligation is not conditioned on completion of a forensic investigation or final confirmation of every fact concerning the Security Incident.

To the extent reasonably available and legally permissible, HPLY’s notice may include information concerning:

(a) the nature of the Security Incident;

(b) affected categories of Personal Data and Data Subjects;

(c) known or reasonably anticipated consequences;

(d) measures taken or proposed to contain, investigate, mitigate, or remediate the Security Incident; and

(e) contact information for reasonable follow-up.

HPLY may provide information in phases as facts become available.

HPLY’s notification of or response to a Security Incident is not an admission of fault, liability, or violation of law.

The Controller is responsible for determining whether it has a legal obligation to notify Data Subjects, regulators, customers, or other parties, except to the extent Applicable Data Protection Law independently assigns a notification obligation to HPLY.

HPLY will provide reasonable assistance concerning a Security Incident as required by Applicable Data Protection Law and this DPA.

10. Data Subject Requests

Taking into account the nature of HPLY’s Processing, HPLY will provide reasonable assistance to the Controller in responding to requests by Data Subjects to exercise rights under Applicable Data Protection Law.

If HPLY receives a request directly from a Data Subject concerning Personal Data HPLY Processes solely on behalf of the Controller, HPLY may direct the Data Subject to the Controller unless Applicable Data Protection Law requires HPLY to respond directly.

HPLY may provide technical functionality that permits the Controller to access, correct, export, restrict, or delete certain Personal Data through the Services.

Where a request requires additional assistance beyond functionality ordinarily included in the Services, HPLY will provide reasonable assistance where required by Applicable Data Protection Law.

HPLY is not required to disclose Personal Data or information in a manner that would adversely affect the rights or security of another person, disclose another customer’s data, or violate applicable law.

11. Data Protection Impact Assessments and Prior Consultation

Taking into account the nature of the Processing and information available to HPLY, HPLY will provide reasonable assistance to the Controller with data-protection impact assessments and prior consultations with supervisory authorities where required by Applicable Data Protection Law and where the requested assistance relates to HPLY’s Processing under the Agreement.

The Controller remains responsible for determining whether an assessment or consultation is legally required and for completing the Controller’s portions of that process.

HPLY may satisfy its assistance obligation by providing relevant documentation, security information, processing descriptions, standardized responses, or other information reasonably available to HPLY.

12. Government and Law-Enforcement Requests

If HPLY receives a legally binding demand from a governmental authority for Personal Data Processed on behalf of the Controller, HPLY will, to the extent legally permitted:

(a) notify the Controller before disclosure;

(b) review the demand for facial validity and legal authority;

(c) seek clarification, narrowing, or protective treatment where reasonably appropriate;

(d) disclose only the Personal Data reasonably required by the legally binding demand; and

(e) document the request and HPLY’s response as reasonably appropriate.

HPLY is not required to challenge a lawful governmental demand in every circumstance.

Nothing in this Section requires HPLY to violate applicable law, court orders, legal process, or restrictions on disclosure.

13. Return and Deletion of Personal Data

Upon termination or expiration of the Services involving Processor-side Personal Data, HPLY will, at the Controller’s request and subject to applicable functionality, return or delete Personal Data as required by Applicable Data Protection Law.

HPLY may retain Personal Data Processed on behalf of the Controller after termination only where:

(a) applicable law requires retention; or

(b) protected backup, archival, or deletion mechanics reasonably require temporary residual retention.

Where residual backup retention applies, HPLY will continue to protect the Personal Data and will not actively Process it except for restoration, security, legal compliance, or deletion-related purposes permitted by Applicable Data Protection Law.

Independent-controller records lawfully maintained by HPLY are not subject to Processor-side deletion requirements merely because the Agreement terminates.

Such independent-controller records remain subject to HPLY’s applicable legal obligations and privacy notices.

14. Subprocessors

14.1 General Authorization

The Controller provides general written authorization for HPLY to engage Subprocessors to Process Personal Data on behalf of the Controller in connection with the Services.

14.2 Notice of New Subprocessors

HPLY will provide at least fifteen (15) days’ advance notice before authorizing a new Subprocessor to Process Personal Data on behalf of the Controller, unless advance notice is legally or operationally impracticable.

Where advance notice is impracticable, HPLY will provide notice as soon as reasonably practicable.

HPLY may provide notice through email, an account notification, a maintained Subprocessor list, or another reasonable written method.

14.3 Subprocessor Contract Requirements

HPLY will enter into a written agreement with each Subprocessor that Processes Personal Data on behalf of the Controller and will impose the same data-protection obligations applicable to the Processing delegated to that Subprocessor as required by Applicable Data Protection Law, including appropriate confidentiality, security, purpose-limitation, Security Incident, deletion or return, and cooperation obligations.

14.4 Responsibility for Subprocessors

HPLY remains responsible for a Subprocessor’s Processing of Personal Data to the extent required by Applicable Data Protection Law and the Agreement.

14.5 Controller Objections

The Controller may object to a new Subprocessor on reasonable and documented data-protection grounds by notifying HPLY during the applicable notice period.

The Parties will work in good faith to address the objection.

Where HPLY cannot reasonably accommodate a valid objection, HPLY may offer a commercially reasonable alternative, discontinue the affected Processing, or permit termination of the affected Service as provided by the Agreement.

An objection does not require HPLY to terminate a Subprocessor used across HPLY’s Services where HPLY can provide a lawful and reasonable alternative.

15. Subprocessor Information

HPLY will maintain information identifying Subprocessors that Process Personal Data on behalf of Controllers and will make the then-current Subprocessor information available through a method designated by HPLY or upon reasonable request.

The information may include the Subprocessor’s name, Processing function, and Processing location or region where reasonably available and appropriate.

A third party that Processes information as an independent Controller rather than on HPLY’s behalf is not a Subprocessor merely because it interacts with the Services.

16. Audits and Compliance Information

HPLY will make available information reasonably necessary to demonstrate compliance with Processor obligations under Applicable Data Protection Law.

The Controller will first use existing documentation reasonably available from HPLY, including relevant security documentation, questionnaires, policies, certifications if any are actually maintained, or other compliance materials, before requesting an audit.

Except following a Security Incident affecting the Controller’s Personal Data, documented material noncompliance, or where Applicable Data Protection Law or a regulator requires otherwise, the Controller may not conduct more than one audit in any twelve-month period.

Any audit must:

(a) be limited to HPLY’s Processing of the Controller’s Personal Data;

(b) occur during normal business hours with reasonable advance notice;

(c) be conducted in a manner designed to minimize disruption;

(d) be subject to appropriate confidentiality obligations;

(e) be conducted by the Controller or an independent auditor that is not a competitor of HPLY;

(f) avoid access to another customer’s data or confidential information;

(g) avoid access to HPLY source code, penetration-testing materials, vulnerability details, privileged communications, internal fraud models, credentials, or other security-sensitive information except where Applicable Data Protection Law expressly requires otherwise; and

(h) be conducted remotely or through documentation review where that method reasonably satisfies the applicable requirement.

On-site audits are permitted only where legally required or where reasonably necessary because existing documentation and remote review cannot adequately address a specific material compliance issue.

The Controller is responsible for its audit costs unless Applicable Data Protection Law or the Agreement requires otherwise.

HPLY may require the Controller to reimburse HPLY for reasonable costs associated with unusually burdensome or repeated audit requests not resulting from HPLY’s material noncompliance, to the extent permitted by Applicable Data Protection Law and the Agreement.

17. International Transfers

HPLY will use an international-transfer mechanism required by Applicable Data Protection Law when HPLY makes a Restricted Transfer of Personal Data on behalf of the Controller.

The international-transfer provisions in Schedule 2 apply only where a Restricted Transfer requires them.

Nothing in this DPA treats a transfer as a Restricted Transfer when Applicable Data Protection Law does not require a contractual or other transfer safeguard.

18. Indemnification

Indemnification obligations relating to this DPA, privacy, security, or Processing are governed exclusively by the Agreement.

This DPA does not create an additional indemnification obligation unless the Parties expressly agree otherwise in writing.

19. Limitation of Liability

Claims arising out of or relating to this DPA, privacy, security, or Processing are subject to the liability exclusions, limitations, caps, procedures, and allocation of risk in the Agreement, except to the extent Applicable Data Protection Law does not permit the applicable limitation.

This DPA does not create a separate or additional liability cap.

20. Insurance

Insurance obligations, if any, are governed by the Agreement.

This DPA does not create a separate insurance requirement.

21. Confidentiality and Privilege Protections

Nothing in this DPA requires either Party to disclose attorney-client privileged information, attorney work product, trade secrets unrelated to the Processing at issue, another customer’s confidential information, source code, credentials, penetration-test exploit details, or other information whose disclosure would materially impair security, except to the extent Applicable Data Protection Law expressly requires disclosure.

Where disclosure is legally required, the Parties will reasonably cooperate concerning protective measures where appropriate.

22. Amendments

This DPA may be amended only:

(a) as permitted by the Agreement;

(b) by written agreement of the Parties; or

(c) through documentation reasonably necessary to satisfy a mandatory change in Applicable Data Protection Law.

HPLY will not make a unilateral amendment that materially reduces the Controller’s mandatory data-protection rights except as permitted by the Agreement and Applicable Data Protection Law.

If a mandatory legal change requires an amendment and the Parties cannot reasonably agree on compliant terms, either Party may exercise any termination or other rights available under the Agreement or applicable law.

23. Order of Precedence

If this DPA conflicts with the Agreement concerning HPLY’s Processor-side obligations for Personal Data, this DPA controls solely with respect to that conflict unless the Agreement expressly states that a more specific negotiated privacy or security provision controls.

The Agreement otherwise remains in effect.

Applicable mandatory law controls over any conflicting contractual provision to the extent required by law.

24. Term and Survival

This DPA remains in effect for as long as HPLY Processes Personal Data on behalf of the Controller under the Agreement.

Provisions concerning confidentiality, deletion, retained backups, audits, liability, international transfers, and other obligations that by their nature should survive remain effective for as long as necessary to fulfill their purpose.

25. General Terms

The governing-law, dispute-resolution, notice, assignment, force-majeure, waiver, severability, and other general provisions of the Agreement apply to this DPA unless this DPA expressly provides otherwise.

Electronic acceptance of this DPA is valid to the extent permitted by applicable law.

SCHEDULE 1 — PROCESSING DETAILS AND MINIMUM TECHNICAL AND ORGANIZATIONAL MEASURES

1. Subject Matter

HPLY Processes Personal Data on behalf of the Controller as reasonably necessary to provide the Services described in the Agreement and to perform related support, security, administration, and legally required Processor functions.

2. Duration

Processing continues for the term of the Agreement and for any limited period afterward during which HPLY is authorized or legally required to retain Processor-side Personal Data under Section 13 of this DPA.

3. Nature of Processing

Depending on the Services used, HPLY may perform activities such as:

(a) receiving Personal Data from or at the direction of the Controller;

(b) hosting and storing Personal Data;

(c) organizing, structuring, retrieving, displaying, transmitting, or otherwise making Personal Data available through authorized Service functionality;

(d) authenticating accounts and authorized users;

(e) administering accounts, profiles, transactions, or communications;

(f) providing technical and customer support;

(g) securing systems and detecting fraud, abuse, or unauthorized activity;

(h) performing backup, recovery, troubleshooting, and service maintenance;

(i) facilitating exports, corrections, restrictions, return, or deletion;

(j) assisting with Data Subject requests, Security Incidents, legal obligations, and audits; and

(k) other Processing expressly documented in the Agreement or Controller instructions.

4. Purposes of Processing

The purposes of Processing may include:

(a) providing the contracted Services;

(b) administering authorized accounts and user access;

(c) processing information submitted through authorized workflows;

(d) supporting the Controller;

(e) maintaining security, fraud prevention, availability, and integrity;

(f) complying with documented Controller instructions;

(g) supporting legally required privacy and security obligations; and

(h) performing other Processor functions reasonably necessary to provide the Services.

HPLY will not use raw Controller Personal Data for general independent service improvement except as permitted by Section 2 of this DPA.

5. Categories of Data Subjects

Depending on the Controller’s use of the Services, Data Subjects may include:

(a) the Controller’s employees, personnel, contractors, volunteers, and authorized representatives;

(b) customers, users, members, donors, prospective donors, or supporters whose information the Controller lawfully submits to HPLY;

(c) beneficiaries, contacts, vendors, or business partners whose information the Controller lawfully submits to HPLY;

(d) account administrators and authorized Service users; and

(e) other identifiable individuals whose Personal Data is lawfully submitted to HPLY by or at the direction of the Controller for the contracted Services.

6. Categories of Personal Data

Depending on the Services and Controller instructions, Personal Data may include:

(a) identifiers, such as name, username, account identifier, email address, telephone number, mailing address, and IP address;

(b) account and authentication information;

(c) professional or organizational information, including role, title, employer, affiliation, and authorization information;

(d) transaction, payment-status, reconciliation, or Donation-administration information where applicable, excluding complete payment credentials where those are collected directly by a Payment Processor;

(e) communications, support requests, and information submitted through Service workflows;

(f) technical, device, security, session, and log information;

(g) profile information, preferences, and authorized content;

(h) privacy-request and compliance information; and

(i) other Personal Data the Controller lawfully submits through functionality covered by the Agreement.

HPLY does not require the Controller to submit categories of Personal Data that are not reasonably necessary for the Services.

7. Sensitive or Special Categories of Personal Data

The Controller should not submit sensitive or special-category Personal Data unless the applicable Service requires or expressly supports that Processing and the Controller has a lawful basis to do so.

Where HPLY Processes sensitive or special-category Personal Data on behalf of the Controller, the Processing is subject to the protections in this DPA and any additional requirements imposed by Applicable Data Protection Law.

Complete payment-card credentials, bank credentials, government identity documents, taxpayer information, and comparable highly sensitive data may be collected directly by specialized providers rather than HPLY where appropriate.

8. Retention

Processor-side Personal Data is retained for the duration reasonably necessary to provide the contracted Services and then returned, deleted, or retained only as permitted by Section 13 of this DPA.

Retention may vary based on Controller instructions, Service configuration, backup lifecycle, legal requirements, and technical deletion processes.

Independent-controller records lawfully maintained by HPLY are governed separately.

MINIMUM TECHNICAL AND ORGANIZATIONAL MEASURES

9. Security Governance

HPLY maintains reasonable security practices appropriate to the nature of the Services, Personal Data, and risks involved.

Security responsibilities may be allocated among personnel or service providers based on role and operational need.

10. Access Controls

HPLY uses reasonable controls designed to limit access to systems and Personal Data to authorized persons with a legitimate business need.

Access may be restricted based on role, function, system, environment, or other appropriate criteria.

HPLY may revoke or modify access when authorization changes.

11. Authentication

HPLY uses authentication controls reasonably appropriate to the applicable systems and risk.

Authentication methods may vary by system, user type, environment, and functionality.

12. Credential Protection

HPLY uses reasonable measures designed to protect authentication credentials and prevent unauthorized credential use.

Personnel and authorized users are expected to protect credentials and report suspected compromise.

13. Data Transmission

HPLY uses reasonable protections for Personal Data transmitted over public or untrusted networks where appropriate to the nature of the Processing.

14. Data Storage

HPLY uses reasonable safeguards designed to protect Personal Data stored in systems used to provide the Services.

The specific safeguards may vary by system, provider, data type, and risk.

15. Logging and Monitoring

HPLY may maintain logs and monitoring appropriate to security, availability, fraud prevention, troubleshooting, and investigation.

Logging practices are designed to support legitimate operational and security purposes without unnecessarily expanding collection of Personal Data.

16. Vulnerability and Patch Management

HPLY uses reasonable processes designed to identify and address security vulnerabilities and apply security updates appropriate to the systems and risks involved.

No particular remediation period is guaranteed unless expressly stated in the Agreement.

17. Malware and Threat Protection

HPLY uses reasonable technical or operational protections designed to reduce risks from malicious software, unauthorized activity, and other security threats appropriate to the environment.

18. Backup and Recovery

HPLY may use backups or recovery processes reasonably appropriate to the availability and continuity needs of the Services.

Nothing in this DPA establishes a particular recovery-time objective, recovery-point objective, backup frequency, or disaster-recovery certification unless expressly stated in the Agreement.

19. Change Management

HPLY uses reasonable controls appropriate to changes affecting systems that Process Personal Data.

20. Secure Development and Configuration

Where HPLY develops or configures systems used to Process Personal Data, HPLY uses reasonable practices designed to reduce security risk appropriate to the nature of the system and Processing.

This DPA does not represent that HPLY maintains any particular secure-development certification or formal framework unless separately documented.

21. Incident Response

HPLY maintains processes reasonably designed to identify, investigate, contain, and respond to suspected security events affecting systems that Process Personal Data.

Security Incident notification is governed by Section 9 of this DPA.

22. Personnel Confidentiality

Persons authorized to Process Personal Data are subject to confidentiality obligations or an appropriate duty of confidentiality.

23. Service Provider Oversight

HPLY uses reasonable processes to evaluate and manage service providers that Process Personal Data on HPLY’s behalf based on the nature and risk of the Processing.

Subprocessor obligations are governed by Sections 14 and 15.

24. Physical Security

Where physical infrastructure is operated by third-party hosting or cloud providers, physical security may be managed by those providers under their applicable security programs.

HPLY does not represent that it independently operates the physical data centers used by those providers unless expressly stated otherwise.

25. Data Minimization

HPLY seeks to limit Processor-side access and Processing to Personal Data reasonably necessary for the contracted Services and documented Controller instructions.

26. Disposal and Deletion

HPLY uses reasonable processes designed to delete or render Personal Data inaccessible when deletion is required under the Agreement, this DPA, or applicable law, subject to backup and legal-retention limitations described in Section 13.

27. No Unverified Certifications or Control Commitments

Nothing in this Schedule represents that HPLY maintains a SOC report, ISO certification, PCI certification, penetration-testing schedule, specific encryption configuration, specific recovery objective, or other certification or control unless HPLY expressly confirms that fact in separate written documentation.

SCHEDULE 2 — SUBPROCESSORS AND INTERNATIONAL TRANSFERS

1. Subprocessor Framework

The Controller provides general authorization for HPLY to engage Subprocessors in accordance with Section 14 of the DPA.

HPLY will maintain then-current information concerning Subprocessors that Process Personal Data on behalf of Controllers and will make that information available through a method designated by HPLY or upon reasonable request.

Subprocessor information may identify the provider, Processing function, and location or region of Processing where reasonably available and appropriate.

The absence of a third party from a Subprocessor list does not make the third party a Subprocessor where the third party acts independently rather than Processing Personal Data on HPLY’s behalf.

2. European Economic Area

Where HPLY makes a Restricted Transfer subject to the GDPR and an adequacy decision or another lawful transfer basis is not available, the applicable modules of the European Commission’s then-current Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, or a successor mechanism valid under Applicable Data Protection Law, will apply to the Restricted Transfer.

The applicable module will be determined by the legal roles of the exporting and importing Parties for the relevant transfer.

To the extent required for the applicable transfer:

(a) the optional docking clause will apply where legally appropriate;

(b) the supervisory authority will be determined in accordance with the GDPR;

(c) the governing law of the SCCs will be the law of an EEA Member State that permits third-party beneficiary rights under the SCCs, selected consistently with the applicable transfer and Agreement; and

(d) the courts with jurisdiction will be those determined under the applicable SCCs and mandatory law.

The Processing details in Schedule 1 and the security measures in Schedule 1 are incorporated into the applicable SCC annexes to the extent they satisfy the information required for the Restricted Transfer.

Nothing in this Section treats SCCs as applicable where Applicable Data Protection Law does not require them.

3. Switzerland

Where a Restricted Transfer is subject to Swiss data-protection law and a contractual transfer safeguard is required, the Parties will use the EU Standard Contractual Clauses as recognized or adapted under applicable Swiss law, or another legally valid Swiss transfer mechanism.

References in the applicable transfer mechanism will be interpreted and adapted as necessary to reflect Swiss law, Swiss Data Subjects, the competent Swiss authority, and other legally required Swiss modifications.

Swiss transfer requirements apply only to the extent legally required for the relevant Restricted Transfer.

4. United Kingdom

Where contractual safeguards are required, the Parties will use the then-current International Data Transfer Agreement issued by the UK Information Commissioner, the then-current International Data Transfer Addendum to the EU Standard Contractual Clauses, or another legally valid United Kingdom transfer mechanism, as applicable.

The Parties will apply the version, elections, and information legally required for the relevant Restricted Transfer based on the Parties’ roles and the applicable United Kingdom legal framework.

Nothing in this DPA treats a United Kingdom transfer mechanism as applicable where United Kingdom law does not require one.

5. Transfer Mechanism Hierarchy

Where more than one legally valid transfer mechanism is available, HPLY may use an adequacy decision, recognized certification or framework, approved contractual mechanism, or another lawful transfer basis permitted by Applicable Data Protection Law.

If an applicable transfer mechanism is invalidated, replaced, or no longer legally sufficient, the Parties will cooperate in good faith to implement a legally valid replacement to the extent required for continued Restricted Transfers.

6. Government Access and Transfer Protections

For Restricted Transfers requiring contractual safeguards, HPLY will comply with applicable obligations concerning governmental access requests, including review, transparency, challenge, minimization, and notification to the extent required by the applicable transfer mechanism and law.

Nothing in this Section requires HPLY to violate a legally binding prohibition on disclosure.

7. Transfer Assessments and Supplementary Measures

Where Applicable Data Protection Law requires a transfer impact assessment, transfer risk assessment, data protection test, or comparable assessment for a Restricted Transfer, the Party responsible for initiating the Restricted Transfer will complete the assessment required by applicable law.

HPLY will provide reasonable assistance and information available to HPLY that is relevant to the assessment, including information concerning Processing, security measures, Subprocessors, and governmental-access practices where required and legally permissible.

The Parties will consider supplementary technical, contractual, or organizational measures where required by Applicable Data Protection Law and reasonably appropriate to the relevant Restricted Transfer.

For a Restricted Transfer subject to United Kingdom law, the Party responsible for initiating the Restricted Transfer will complete any transfer risk assessment or data protection test required by applicable United Kingdom law. HPLY will provide reasonable assistance and information available to HPLY for that assessment where required by this DPA.

8. Conflicts With Transfer Mechanisms

If a provision of this DPA conflicts with a mandatory provision of an applicable international-transfer mechanism, the mandatory transfer-mechanism provision controls solely with respect to the relevant Restricted Transfer.

The remainder of this DPA and the Agreement remain in effect.

9. No Automatic Application

International-transfer provisions in this Schedule become operative only to the extent a Restricted Transfer requires the applicable mechanism under Applicable Data Protection Law.

Nothing in this Schedule represents that every transfer of Personal Data is a Restricted Transfer or that HPLY currently transfers Personal Data to every jurisdiction addressed in this Schedule.

CONTACT INFORMATION

Questions concerning this DPA may be directed to:

HPLY Inc. 3517 Camino del Río South Suite 215, Mailbox #83 San Diego, CA 92108 United States

Email: support@hply.org

HPLY

HPLY helps people discover trusted nonprofit organizations, learn about their missions, and give with confidence.

HPLY iOS app coming soonHPLY Android app coming soon

Company

  • Home
  • Contact
  • About Us
  • Press Room
  • Careers
  • FAQs

Contact

  • support@hply.org

Copyright © 2026 HPLY. All Rights Reserved.

Legal|Privacy Policy