Data Processing Addendum

Last updated: September 2026

This DPA is incorporated into our Terms of Service for every organization that requires one; no separate signature is needed, though we'll countersign a copy on request. See also the Privacy Policy and the Subprocessors list.

1. Parties, roles, and scope

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Nonsilebo LLC, the operator of Occam (“Occam,” the “Processor”), and the organization that accepts them (the “Organization,” the “Controller”). It applies whenever Occam processes personal data on the Organization's behalf in providing the Service — chiefly the donor, supporter, and constituent records the Organization manages with Occam.

For that data, the Organization is the controller and Occam is the processor. For the account data of the Organization's own staff and for the operation of the platform itself, Occam acts as an independent controller as described in the Privacy Policy.

2. Details of processing

Subject matter and nature: hosting, storing, and processing the Organization's fundraising data to provide the Service — donation processing, event and auction management, CRM, messaging, website hosting, social publishing, analytics, and reporting.

Duration: the term of the Organization's use of the Service, plus the deletion period in Section 8.

Categories of data subjects: the Organization's donors, supporters, members, event attendees, bidders, purchasers, volunteers, and newsletter subscribers.

Categories of personal data: names and contact details (email, phone, postal address), giving and transaction history, event registrations, memberships, pledges, bids, communications history and preferences, and notes the Organization's staff record. Payment card and bank details are processed by Stripe and never stored by Occam.

3. Instructions

Occam processes the Organization's personal data only on the Organization's documented instructions — which consist of the Terms, this DPA, and the Organization's use of the Service's features — unless processing is required by law, in which case Occam will inform the Organization unless the law prevents it. Occam does not sell the Organization's personal data, use it for advertising, or use it to train machine-learning models.

4. Confidentiality and personnel

Occam ensures that everyone it authorizes to process the Organization's personal data is bound by confidentiality obligations and accesses only what their role requires.

5. Security

Occam implements appropriate technical and organizational measures to protect personal data, including: encryption in transit (TLS) and at rest; database-enforced tenant isolation, so one organization's data cannot be read from another's context; field-level encryption for stored credentials such as social account tokens; role-based access control and audit logging; and vulnerability management. Our current practices are summarized on the Security page.

6. Subprocessors

The Organization authorizes Occam to engage the subprocessors listed on the Subprocessors page, and Occam remains responsible for their performance. Occam will update that page before adding or replacing a subprocessor and, on request, will notify the Organization of such changes by email. If the Organization has a reasonable objection to a new subprocessor, it may terminate the affected part of the Service and receive an export of its data.

7. Assistance with data subject requests

The Service includes tools for the Organization to answer data subject requests itself: exporting an individual's full record, correcting it, and permanently erasing it. Taking those tools into account, Occam will provide reasonable further assistance with requests under applicable data protection law (such as GDPR and CCPA), and will forward to the Organization any request Occam receives directly about the Organization's data.

8. Deletion and return

When the Organization stops using the Service, Occam will, at the Organization's choice, return its personal data as an export and/or delete it, within 30 days of the request, except where law requires longer retention. Backups are deleted on their normal expiry cycle.

9. Personal data breaches

Occam will notify the Organization without undue delay after becoming aware of a personal data breach affecting the Organization's personal data, and will provide the information reasonably needed for the Organization to meet its own notification obligations.

10. Audits

On request, no more than once a year unless required by a supervisory authority, Occam will make available the information reasonably necessary to demonstrate compliance with this DPA — including completed security questionnaires and summaries of any third-party assessments — and will allow audits as required by applicable law, conducted with reasonable notice and without disrupting the Service.

11. International transfers

Occam processes personal data in the United States. Where the Organization transfers personal data subject to GDPR or UK data protection law to Occam, the parties agree that the European Commission's Standard Contractual Clauses (Module 2, controller to processor), and the UK Addendum where applicable, are incorporated into this DPA by reference, with the details of processing in Section 2 and the security measures in Section 5 serving as their annexes. A signed copy is available on request.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If this DPA conflicts with the Terms, this DPA controls for the processing of personal data.