Effective Date: April 9, 2026 · Last Updated: September 24, 2026 · Version 1.2
Who this is for: This Data Processing Agreement (DPA) governs the processing of personal data by VolunteerFlow on behalf of organizations subject to GDPR, CCPA, or similar data protection regulations. It is entered into pursuant to GDPR Article 28.
This Data Processing Agreement ("DPA") is entered into between the nonprofit organization using VolunteerFlow (the "Controller") and PowerHouseTech LLC, a New York limited liability company doing business as VolunteerFlow (the "Processor"), and is incorporated into and governed by the VolunteerFlow Terms of Service.
This DPA, including Annex A (Security Measures), forms part of the Terms of Service and applies automatically to all Personal Data VolunteerFlow processes for Controller, without a separate signature. If the Terms of Service and this DPA conflict on the protection of Personal Data, this DPA controls.
VolunteerFlow processes Personal Data solely for providing the VolunteerFlow SaaS platform and related services as described in the Terms of Service. VolunteerFlow shall not use Personal Data for any other purpose without prior written consent of Controller.
Controller warrants that it has a lawful basis under applicable privacy laws to collect and process the Personal Data, and that all required notices have been provided to Data Subjects. VolunteerFlow shall process Personal Data only in accordance with: (a) documented instructions in the Terms of Service; (b) written organization-specific instructions; and (c) applicable laws.
VolunteerFlow processes the following categories of Personal Data on behalf of Controller:
Where Controller enables the relevant features, VolunteerFlow also processes special or sensitive categories of Personal Data: military and veteran service information; demographic information including gender, race and ethnicity, household composition, and income; criminal history disclosures; government identification references, stored encrypted and returned only in masked form; and health and medical records, stored encrypted and reachable only under an explicit permission grant.
Data Subjects include: volunteers and volunteer applicants; program participants and beneficiaries whose records Controller keeps in the Service; donors and purchasers; organization staff and administrators; and administrative contacts.
Controller consents to the following sub-processors. Each is bound by a written agreement imposing substantially equivalent data protection obligations. VolunteerFlow shall provide Controller with at least 30 days' prior written notice before engaging any new sub-processor.
| Sub-Processor | Purpose |
|---|---|
| Supabase | Cloud database hosting and file storage (United States) |
| Railway | Backend application hosting (United States) |
| Vercel | Website hosting, deployment, and cookieless analytics |
| Resend | Transactional and announcement email delivery |
| Telnyx | SMS and text message delivery |
| Google (Firebase Cloud Messaging) | Push notification delivery to the VolunteerFlow mobile apps |
| Stripe | Subscription billing for VolunteerFlow plans and add-ons |
| Square (Block, Inc.) | Donation, kiosk, and store payments taken on behalf of Controller |
| Checkr | Background check processing, where Controller selects this provider |
| Sterling | Background check processing, where Controller selects this provider |
| Anthropic | AI features (assistant, messaging and report drafting, scheduling suggestions) included in the Impact plan, and photo-based animal record import |
| OpenAI | AI features included in the Impact plan |
Controller is responsible for:
VolunteerFlow shall:
VolunteerFlow shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the Personal Data and the risks of the processing. At a minimum, VolunteerFlow shall maintain the measures described in Annex A. VolunteerFlow may update those measures over time, provided that no update materially reduces the overall protection of Personal Data.
VolunteerFlow maintains incident response procedures and shall notify Controller of Personal Data breaches as set out in Section 9.
Controller acknowledges and consents to VolunteerFlow support staff accessing organization data for technical support and issue resolution. All staff with data access are subject to binding confidentiality agreements. Support sessions may be used to diagnose and resolve technical issues. Each support session is logged, including the staff member, the organization accessed, and when the session started and ended, and is shown to Controller in its security settings.
Controller may request an audit log report showing all staff access to Controller's data. VolunteerFlow shall provide such audit logs within 30 business days.
VolunteerFlow shall notify Controller without undue delay and no later than 72 hours after discovering a Personal Data breach affecting Controller's data. Notification shall include: description of the breach and affected data, likely consequences, measures taken or proposed, and contact information for the responsible official.
VolunteerFlow shall provide information necessary for Controller to determine whether Data Subject or regulatory authority notification is required.
VolunteerFlow shall retain Personal Data for the duration of the service agreement and any legally required retention period thereafter, unless Controller directs otherwise in writing.
Upon termination or expiration of the service agreement, VolunteerFlow shall make all Personal Data available for export in a standard portable format for 30 days, and shall then permanently delete all Personal Data from active systems using secure deletion methods within 60 days after that export period ends, or sooner at Controller's written request.
VolunteerFlow shall delete Personal Data from backup systems within 30 days after deletion from active systems, as backups expire on a rotation of no more than 30 days, unless Controller has requested retention. Upon completion of data deletion, VolunteerFlow shall provide Controller with written certification that all Personal Data has been deleted in accordance with this DPA.
Upon receipt of Data Subject access, deletion, portability, or correction requests, VolunteerFlow shall promptly notify Controller and provide reasonable assistance to enable Controller to fulfill the request within applicable legal timeframes (typically 30 days under GDPR). Assistance is provided at no additional charge except for requests requiring substantial development costs.
Controller acknowledges that VolunteerFlow uses Supabase as its primary hosting provider. Personal Data may be stored on servers located in the United States. For controllers subject to GDPR, VolunteerFlow relies on Standard Contractual Clauses (SCCs) for international data transfers. VolunteerFlow shall execute Data Processing Addenda incorporating SCCs as necessary.
This DPA is entered into pursuant to GDPR Article 28 and incorporates the mandatory clauses required by that Article. To the extent the Services involve processing of Personal Data of individuals located in the European Union, VolunteerFlow acts as a Processor under GDPR Article 28, and this DPA shall govern that processing relationship.
To the extent the Services involve processing of Personal Data of California residents, VolunteerFlow is a Service Provider under CCPA Section 1798.100(d). As a Service Provider, VolunteerFlow shall not retain, use, or disclose Personal Data except as necessary to perform the Services; shall not sell Personal Data; shall not use Personal Data for any commercial purpose other than providing the Services; and shall not combine Personal Data received from Controller with Personal Data from other sources.
To the extent the Services involve Personal Data of New York residents, VolunteerFlow shall maintain reasonable safeguards as required by the New York SHIELD Act (N.Y. Gen. Bus. Law § 899-bb) and shall notify Controller of any breach of the security of the system affecting Controller's data as required by N.Y. Gen. Bus. Law § 899-aa, and in any event within the period set out in Section 9. VolunteerFlow shall likewise maintain the measures in Annex A for Personal Data of residents of any other state whose law requires a service provider to protect personal information by contract, including Massachusetts (201 CMR 17.00).
Controller may request audit information regarding VolunteerFlow's compliance with data protection obligations. VolunteerFlow shall provide audit information within 30 business days of request. VolunteerFlow does not currently hold a third-party audit report such as SOC 2. Until it does, VolunteerFlow shall answer reasonable written security questionnaires and, once in any twelve-month period and on at least 30 days' notice, make available the information reasonably necessary to demonstrate compliance with this DPA. Where VolunteerFlow later obtains a current third-party audit report, it may provide that report in satisfaction of audit requests.
This DPA is effective as of the date it is accepted by Controller and shall remain in effect for the duration of the service agreement. Upon termination, VolunteerFlow shall cease processing Personal Data and shall return or delete all Personal Data as directed by Controller in accordance with Section 10.
This DPA shall be governed by and construed in accordance with the laws of the State of New York, without regard to its conflict of law provisions.
For questions regarding this DPA, data protection practices, or privacy concerns, contact:
Email: legal@volunteerflow.us
This DPA should be read together with our Privacy Policy and Terms of Service. A plain-language summary of Annex A is published at volunteerflow.us/security; if the two differ, this Annex controls.
VolunteerFlow maintains at least the following technical and organizational measures.
Effective as of April 9, 2026.