Givebutter Data Processing Addendum
1. Scope and Applicability.
1.1 This Data Processing Addendum (“DPA”) is appended to and incorporated into the Givebutter Terms of Service (the “Terms”) between Givebutter, Inc. (“Company” or “Givebutter”) and the Fundraiser. This DPA is effective and binding on Givebutter as of October 1, 2026. In the event of any conflict between this DPA and the Terms, this DPA controls.
1.2 The Fundraiser is the Controller (or Business, as applicable). Givebutter is the Processor (or Service Provider, as applicable). This DPA governs Givebutter’s Processing of Fundraiser Personal Data.
1.3 This DPA does not govern:
- Personal Data of the Fundraiser’s own administrative users that Givebutter processes to provide Fundraiser with the Services, which is governed by Givebutter’s Privacy Policy;
- Personal Data collected directly by Givebutter from Supporters at checkout, which is governed by the Givebutter’s Privacy Policy (where Givebutter acts as a Controller); or
- Anonymized or de-identified data.
1.4 Where the Fundraiser acts as a Processor (or Service Provider, as applicable) on behalf of an ultimate Controller (or Business, as applicable), the Fundraiser represents and warrants that it has obtained all necessary authority from that Controller (or Business, as applicable) to enter into this DPA and to authorize Givebutter’s Processing of Fundraiser Personal Data as contemplated herein.
2. Definitions.
As used in this DPA, the following terms have the meanings set forth below. Capitalized terms not defined herein have the meanings given in the Terms.
- “Business” has the meaning given under the CCPA.
- “CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code §§ 1798.100–1798.199.100, as amended by the California Privacy Rights Act of 2020, and all implementing regulations promulgated thereunder.
- “Controller” means the entity that determines the purposes and means of Processing Personal Data.
- “Cross-Contextual Behavioral Advertising” has the meaning given under the CCPA.
- “Fundraiser Personal Data” means all Personal Data governed by Data Protection Laws that Company Processes on behalf of Fundraiser pursuant to the provision of Services by Givebutter, specifically personal data relating to third parties (such as donors, Supporters, and contacts) that Fundraiser uploads or imports to the Services or that such third parties provide to the Services via Fundraiser’s pages. Fundraiser Personal Data does not include Personal Data described in Section 1.3(a).
- “Data Protection Laws” means all applicable data protection and privacy laws, including the CCPA/CPRA and any applicable state, federal, or foreign data protection law.
- “Personal Data” means any information that identifies, relates to, or can be used to identify, directly or indirectly, a natural person or household, as defined under applicable Data Protection Laws.
- “Personal Data Breach” means any confirmed breach of security leading to unauthorized access, disclosure, loss, or modification of Fundraiser Personal Data in Company’s control.
- “Process,” “Processing,” and “Processed” mean any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
- “Processor” means the entity that Processes Personal Data on behalf and at the direction of a Controller.
- “Prohibited Data” means government-issued identification numbers, Social Security numbers, medical or health information, and raw payment card data subject to PCI DSS.
- “Sell” and “Share” have the meanings given under the CCPA.
- “Service Provider” has the meaning given under the CCPA.
- “Sub-processor” means a third party engaged by Company that Processes Fundraiser Personal Data.
- “Targeted Advertising” has the meaning given under applicable Data Protection Laws.
3. Processing Purpose and Instructions.
3.1 Company will Process Fundraiser Personal Data only in accordance with Fundraiser’s documented instructions as necessary to provide the Services under the Terms, including operating AI Features as described in the AI Addendum.
Company will not retain, use, or disclose Fundraiser Personal Data for any purpose other than for the specific business purposes set forth in this DPA, the Terms and Appendix 1, except as otherwise permitted by Data Protection Laws.
3.2 Company will not retain, use, or disclose Fundraiser Personal Data outside of the direct business relationship between Company and Fundraiser.
3.3 Company will not combine Fundraiser Personal Data with personal information that it receives from or on behalf of another person or persons, or that it collects from its own interaction with consumers, except as permitted by the CCPA.
3.4 Company will treat all Fundraiser Personal Data as confidential information and will ensure that all personnel authorized to Process Fundraiser Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory.
3.5 Company will not Sell or Share Fundraiser Personal Data. Company will not use Fundraiser Personal Data for Targeted Advertising or Cross-Contextual Behavioral Advertising.
3.6 Company certifies that it understands and will comply with the restrictions set forth in Sections 3.1 through 3.5.
3.7 If Company determines that it can no longer meet its obligations under this DPA, Company will promptly notify Fundraiser to the extent legally permitted and will take commercially reasonable steps to stop and remediate any unauthorized Processing of Fundraiser Personal Data.
3.8 The nature and purpose of Processing, categories of Personal Data, categories of data subjects, and other details of Processing are described in Appendix 1.
4. Fundraiser Representations and Obligations.
4.1 Fundraiser represents and warrants that it has obtained all necessary consents, authorizations, and approvals, and has provided all required notices, under applicable Data Protection Laws to permit Company to Process Fundraiser Personal Data as contemplated by this DPA and the Agreement.
4.2 Fundraiser will not provide, upload, or import any Prohibited Data to the Services. Prohibited Data includes: government-issued identification numbers, Social Security numbers, medical or health information, and raw payment card data subject to PCI DSS. For clarity, payment card data entered by Supporters at checkout is collected directly by Stripe and does not enter Company’s systems.
4.3 Where Fundraiser acts as a processor (or Service Provider, as applicable) on behalf of an ultimate Controller (or Business, as applicable), Fundraiser represents that it has obtained all necessary authority from such Controller (or Business, as applicable) to engage Company as a sub-processor and to enter into this DPA on the controller’s behalf.
5. Anonymized and Aggregated Data.
5.1 Company may create anonymized or aggregated data derived from Fundraiser Personal Data and use such data for any lawful business purpose, including without limitation analytics, benchmarking, product improvement, and training Company’s own predictive models.
5.2 Company will maintain anonymized and aggregated data in a form that cannot reasonably be used to identify any individual Data Subject. Company will not attempt to re-identify any anonymized or aggregated data.
5.3 Anonymized and aggregated data is not Fundraiser Personal Data for purposes of this DPA, and the obligations of this DPA do not apply to such data once it has been anonymized or aggregated in accordance with applicable Data Protection Laws.
6. Security Measures.
6.1 Company will implement and maintain reasonable technical and organizational security measures designed to protect Fundraiser Personal Data against unauthorized access, destruction, loss, alteration, or disclosure. Such measures will be appropriate to the nature, scope, and purposes of the Processing and the risks involved.
6.2 Company will periodically review and update its security measures to address evolving threats and changes in industry standards, provided that Company will not materially diminish the overall level of protection afforded to Fundraiser Personal Data during the term of the Terms.
6.3 Company’s security measures include, at a minimum: encryption of Fundraiser Personal Data in transit and at rest, access controls limiting personnel access on a need-to-know basis, and regular security assessments.
7. Personal Data Breach Notification.
7.1 Company will notify Fundraiser without undue delay after confirming a Personal Data Breach affecting Fundraiser Personal Data. Such notification will be made by email to the address associated with Fundraiser’s account or by other reasonable means.
7.2 Company’s notification will include, to the extent reasonably available at the time of notification: (a) a description of the nature of the Personal Data Breach, including the categories and approximate number of records affected; (b) the likely consequences of the breach; and (c) the measures taken or proposed to contain and remediate the incident.
7.3 Company will take reasonable steps to contain, investigate, and remediate any confirmed Personal Data Breach and will provide Fundraiser with additional information as it becomes reasonably available.
7.4 Company’s obligation to notify Fundraiser under this Section 7 is not an acknowledgment of fault or liability with respect to the Personal Data Breach.
8. Data Subject Rights.
8.1 If Company receives a request from a Data Subject exercising rights under applicable Data Protection Laws with respect to Fundraiser Personal Data (a “Data Subject Request”), Company will promptly notify Fundraiser and redirect the Data Subject to Fundraiser.
8.2 Taking into account the nature of the Processing and the information available to Company, Company will cooperate with and reasonably assist Fundraiser in responding to Data Subject Requests, including requests for access, correction, deletion, portability, or restriction of Processing.
8.3 Company will use commercially reasonable efforts to honor verified deletion requests directed by Fundraiser within the functionality of the Services.
8.4 Company will not independently respond to a Data Subject Request unless required by applicable law, in which case Company will notify Fundraiser in advance to the extent legally permitted.
8.5 Taking into account the nature of the Processing and the information available to Company, Company will provide Fundraiser with reasonable assistance necessary to enable Fundraiser to conduct and document data protection assessments required under applicable Data Protection Laws. Company may charge reasonable fees for assistance that exceeds standard support functionality.
9. Sub-Processors.
9.1 General Authorization. Fundraiser grants Company general authorization to engage Sub-processors to Process Fundraiser Personal Data in connection with the Services.
9.2 Sub-processor List. Company maintains a current list of Sub-processors at its Trust Center. Fundraiser may access the current list by visiting the Givebutter Trust Center or by contacting support@givebutter.com.
9.3 Notification of Changes. Company will notify Fundraiser of any new Sub-processor by updating the Sub-processor list. Fundraiser may object to a new Sub-processor by providing written notice to Company within ten (10) days of the update, stating reasonable grounds for the objection. If the parties are unable to resolve the objection, Fundraiser may terminate the affected portion of the Terms.
9.4 Sub-processor Obligations. Company will use commercially reasonable efforts to enter into written agreements with each Sub-processor imposing data protection obligations substantially equivalent to those set forth in this DPA.
9.5 Liability. Company remains liable for the acts and omissions of its Sub-processors to the same extent Company would be liable if performing the Processing directly under this DPA.
10. AI Processing.
To the extent AI Features (as defined in the AI Addendum) Process Fundraiser Personal Data, such Processing is part of the Services and is subject to both this DPA and the AI Addendum. For clarity:
- Commercial AI Features may transmit Fundraiser Personal Data to AI Model Providers (as Sub-processors) to generate feature outputs. These providers are listed on the Company’s Sub-processor list.
- Homegrown Models are trained on aggregated, de-identified data. Join keys such as account IDs may be used to assemble training datasets but are removed before model training and are not used by or accessible to the models. The models themselves do not use Fundraiser Personal Data.
- AI infrastructure services (such as observability and logging tools) may log requests containing Fundraiser Personal Data for quality and performance monitoring. These services are treated as Sub-processors.
11. Fundraiser Rights.
11.1 Questionnaire and Compliance Monitoring. Fundraiser may take reasonable and appropriate steps to monitor Company’s compliance with this DPA, including through a written data protection questionnaire submitted to Company (no more than once per twelve-month period), to which Company will respond within a reasonable timeframe.
11.2 Confidentiality. All questionnaire responses and other compliance information provided under this Section 11 constitute Company’s confidential information and may not be disclosed to third parties without Company’s prior written consent, except as required by law.
12. Duration, Return, and Deletion of Fundraiser Personal Data.
12.1 Term. This DPA remains in effect for the duration during which Company provides Services to Fundraiser and will terminate automatically upon termination or expiration of the Terms, except that the obligations set forth in this DPA will continue to apply for as long as Company retains any Fundraiser Personal Data.
12.2 Deletion or Return. Upon termination or expiration of the period during which Company provides Services to Fundraiser and upon Fundraiser’s written request, Company will use commercially reasonable efforts to delete or anonymize Fundraiser Personal Data within a reasonable period. If Fundraiser requests return of Fundraiser Personal Data in a standard format, Company will use commercially reasonable efforts to accommodate such request. Company may charge reasonable fees for assistance that exceeds standard support functionality.
12.3 Exceptions. Company may retain Fundraiser Personal Data to the extent required by applicable law or as part of regular backup and archive systems. Any Fundraiser Personal Data so retained will remain subject to the protections of this DPA until deleted or anonymized.
13. Miscellaneous.
13.1 Termination. This DPA terminates automatically upon termination or expiration of the period during which Company provides Services to Fundraiser. Notwithstanding termination, the obligations of this DPA continue in full force for so long as Company retains any Fundraiser Personal Data.
13.2 Limitation of Liability. Company’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in the Terms.
13.3 Charges for Assistance. Company may charge reasonable fees for assistance requested by Fundraiser that exceeds the functionality already available through the Services.
13.4 Conflict. In the event of any conflict between this DPA and the Terms, this DPA controls with respect to the Processing of Fundraiser Personal Data.
13.5 Entire DPA. This DPA, together with the Terms, the AI Addendum, and Appendix 1, constitutes the complete agreement between the parties regarding the Processing of Fundraiser Personal Data.
Appendix 1: Details of Processing
This Appendix 1 forms part of the DPA and describes the Processing of Fundraiser Personal Data.
| Element | Description |
|---|---|
| Nature and Purpose of Processing | Processing Fundraiser Personal Data to provide the Services, including: hosting and managing CRM contact records; enabling communication features; powering AI Features; generating analytics and reports; facilitating donor management; and related platform operations. |
| Duration of Processing | For the term of the Terms plus the period required to delete or return Fundraiser Personal Data in accordance with Section 12. |
| Categories of Data Subjects | Donors, supporters, contacts, and other individuals whose Personal Data is uploaded or imported by the Fundraiser. |
| Categories of Personal Data | Names, email addresses, phone numbers, postal addresses, donation history, engagement data, transaction records, employer information, dates of birth, gender, pronouns, household information, tags, segments, and other Personal Data submitted by the Fundraiser through the Services. |
| Special Categories of Data | None. Fundraiser represents it will not submit special categories of data or Prohibited Data. |
| Processing Operations | Collection, storage, organization, retrieval, use, disclosure by transmission to Sub-processors (including AI Model Providers), anonymization, and deletion. |
| Sub-processors | A current list of Sub-processors is maintained at the Company’s Trust Center. Contact support@givebutter.com for access. |


