← Legal

MissionHand Data Processing Addendum (DPA)

Serve by Design, LLC — Version 1.0 | Effective Date: July 1, 2026



Legal Risk Assessment Summary

Using the Severity × Likelihood framework.

RiskSeverityLikelihoodScoreLevel
Breach of sensitive beneficiary data (social services)5 (Critical)2 (Unlikely)10🟠 HIGH
Regulatory action for CCPA non-compliance as processor3 (Moderate)2 (Unlikely)6🟡 MEDIUM
Contractual liability to nonprofit customer for data breach4 (High)2 (Unlikely)8🟡 MEDIUM
Failure to properly document processor relationship3 (Moderate)3 (Possible)9🟡 MEDIUM

Mitigation via this DPA: Properly documenting the controller/processor relationship and establishing clear breach notification timelines reduces legal exposure and demonstrates good-faith compliance.


Data Processing Addendum

This Data Processing Addendum ("DPA") is entered into between Serve by Design, LLC ("Processor") and the nonprofit organization or other entity subscribing to MissionHand under the Terms of Service ("Controller"). This DPA is incorporated into and forms part of the Terms of Service (the "Agreement").

This DPA is effective as of the date the Controller accepted the Agreement ("Effective Date").


Article 1 — Definitions

Terms defined in the Agreement have the same meaning here. Additionally.

  • "Applicable Data Protection Laws" means all privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including (as applicable) the Florida Information Protection Act (Fla. Stat. § 501.171), the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.), and any other US state privacy laws that apply based on where Personal Data originates.

  • "Controller" means the nonprofit organization that determines the purposes and means of processing of Personal Data — i.e., the MissionHand customer.

  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed — typically a donor, beneficiary, volunteer, or staff member of the Controller.

  • "Personal Data" means any information relating to an identified or identifiable natural person that is contained in Customer Data processed by Processor on Controller's behalf.

  • "Processing" (and "Process") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collecting, recording, storing, adapting, retrieving, using, disclosing, transmitting, or deleting.

  • "Security Incident" means any confirmed unauthorized access, acquisition, use, disclosure, modification, or destruction of Personal Data.

  • "Sub-processor" means any third party engaged by Processor to Process Personal Data on Controller's behalf.


Article 2 — Scope and Nature of Processing

2.1 Role. The parties acknowledge that.

  • Controller is the data controller responsible for Personal Data of its donors, beneficiaries, volunteers, and staff.
  • Processor is the data processor, processing Personal Data solely on Controller's documented instructions.

2.2 Subject Matter. The subject matter of the processing is the operation of the MissionHand platform for nonprofit operations management.

2.3 Duration. Processing continues for the duration of the Agreement and the post-termination wind-down period described in Article 8.

2.4 Nature of Processing. Processor stores, organizes, retrieves, displays, transmits, and deletes Personal Data as directed by Controller's configuration and use of MissionHand.

2.5 Purpose. Processing is performed solely to provide, maintain, and support MissionHand for the Controller's internal nonprofit operations.

2.6 Categories of Personal Data. The categories of Personal Data processed may include.

  • Donor information: name, contact details, donation history, payment method (payment card data is processed by Stripe; Processor stores only a record of the transaction).
  • Beneficiary/client information: name, contact details, demographic information, case notes, social services history, and other information the nonprofit enters in the case management module.
  • Volunteer information: name, contact details, skills, availability, and background check status (if used).
  • Staff/user information: names, email addresses, roles, and login activity.

2.7 Categories of Data Subjects. Donors, beneficiaries/clients, volunteers, and staff of the Controller.

2.8 Sensitive Data. The parties acknowledge that Personal Data processed through the case management module may be sensitive in nature (relating to individuals receiving social services). Controller is responsible for ensuring it has a lawful basis for collecting and processing this data and for providing required notices to Data Subjects.


Article 3 — Processor's Obligations

3.1 Instructions. Processor will Process Personal Data only on Controller's documented instructions, as set forth in this DPA and the Agreement. If applicable law requires Processor to Process Personal Data for another reason, Processor will inform Controller before such Processing (to the extent legally permitted).

3.2 Confidentiality. Processor will ensure that all personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.

3.3 Security. Processor will implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures include.

MeasureDescription
Encryption in transitHTTPS/TLS for all data transmission
Tenant isolationRow-level security in database separates each customer's data
Audit loggingChanges to sensitive data are logged
Encrypted backupsDaily encrypted database backups
Least-privilege accessStaff access limited to what is needed to provide support

Processor does not currently hold SOC 2 or HIPAA certification and makes no representation that its security measures satisfy any particular certification standard.

3.4 No Cross-Contamination. Processor will not combine Personal Data from one Controller with Personal Data from another Controller, except to the limited extent necessary to provide the Service (e.g., shared infrastructure that is isolated at the data layer by row-level security).

3.5 No Sale of Personal Data. Processor will not sell, share, or otherwise transfer Personal Data to any third party for the third party's own purposes.

3.6 Purpose Limitation. Processor will not use Personal Data for any purpose other than the purposes described in this DPA and the Agreement, including not using it to develop competing products or train machine-learning models on behalf of any other party.

3.7 CPRA Service Provider Compliance. To the extent Controller is a "business" subject to the CPRA and Processor is a "service provider" under the CPRA: Processor agrees to comply with applicable CPRA service provider obligations, including processing Personal Data only for the "business purpose" specified in this DPA. If Processor is unable to comply with any CPRA obligation, Processor will notify Controller within 5 days.


Article 4 — Controller's Obligations

Controller represents and warrants that. 4.1 It has a lawful basis under Applicable Data Protection Laws to collect and process the Personal Data it enters into MissionHand.

4.2 It has provided required privacy notices to Data Subjects whose Personal Data is entered into MissionHand.

4.3 It will use MissionHand only in accordance with Applicable Data Protection Laws and the Agreement.

4.4 It will promptly notify Processor of any changes to its instructions that may affect Processor's ability to comply with this DPA.


Article 5 — Sub-processors

5.1 Authorization. Controller grants Processor general authorization to engage Sub-processors as necessary to provide MissionHand. The current list of Sub-processors is set out in the Sub-processor List (Document 4 of the MissionHand Legal Package, also available at https://missionhand.com/legal/subprocessors).

5.2 Notice of Changes. Processor will update the Sub-processor List at least 30 days before adding or replacing a Sub-processor. Processor will post updates at https://missionhand.com/legal/subprocessors and notify Controller by email if Controller has opted in to Sub-processor change notifications.

5.3 Sub-processor Obligations. Processor will impose data protection obligations on Sub-processors that are no less protective than those in this DPA. Processor remains responsible for Sub-processor compliance.


Article 6 — Data Subject Rights Assistance

6.1 Processor's Role. Because Processor is a processor, not a controller, Processor is not the appropriate party to respond directly to Data Subject rights requests. If Processor receives a rights request directly from a Data Subject (e.g., a donor asking for their donation history), Processor will forward it to Controller within 5 business days and will not respond directly unless Controller instructs Processor to do so or applicable law requires otherwise.

6.2 Technical Assistance. Processor will provide Controller with reasonable technical assistance to help Controller respond to Data Subject rights requests (access, correction, deletion, portability), to the extent technically feasible. MissionHand includes built-in export tools that Controller can use to fulfill portability requests.

6.3 Deletion Requests. If Controller instructs Processor to delete specific Personal Data in response to a Data Subject's deletion request, Processor will use commercially reasonable efforts to do so in the production system promptly. Copies in encrypted backups will be overwritten within the normal backup rotation cycle.


Article 7 — Security Incident Notification

7.1 Notification to Controller. If Processor confirms a Security Incident involving Controller's Personal Data, Processor will notify Controller within 10 days of confirming the incident. This timeline is consistent with Florida's FIPA requirement for third-party agents (Fla. Stat. § 501.171(3)) and is designed to enable Controller to fulfill its own legal notification obligations to individuals and regulators (Florida requires individual notification within 30 days of a breach).

7.2 Content of Notification. Processor's notice will include, to the extent known at the time.

  • The date and nature of the incident.
  • Categories and approximate number of Personal Data records affected.
  • Categories and approximate number of Data Subjects affected.
  • The likely consequences of the Security Incident.
  • Measures taken or proposed to address the incident.

Processor may provide this information in stages if all details are not immediately available.

7.3 Cooperation. Processor will cooperate with Controller and take reasonable steps to investigate and mitigate the Security Incident. Processor will provide Controller with information reasonably needed for Controller to notify affected individuals and regulators as required.

7.4 No Admission. Processor's notification does not constitute an admission of liability or fault.


Article 8 — Return and Deletion of Personal Data

8.1 During Wind-Down Period. Upon expiration or termination of the Agreement, Processor will retain Personal Data in read-only storage for 60 days (the "Wind-Down Period"), during which Controller may request an export of its data.

8.2 Deletion. After the Wind-Down Period, Processor will delete or destroy Personal Data from production systems using appropriate methods. Residual copies in encrypted backups will be overwritten within Processor's standard backup rotation cycle.

8.3 Certification. Upon Controller's written request, Processor will provide written certification of deletion.

8.4 Legal Hold. Processor will retain Personal Data beyond the Wind-Down Period to the extent required by applicable law, and only for as long as required. Processor will notify Controller of any such legal hold obligation.


Article 9 — Audit Rights

9.1 Documentation. Processor will make available to Controller, on written request, information reasonably necessary to demonstrate Processor's compliance with this DPA, including this DPA itself, the Sub-processor List, and descriptions of security measures.

9.2 Audits. Controller may, at its own expense and on reasonable prior written notice (not less than 30 days), conduct an audit of Processor's data processing practices as they relate to Controller's Personal Data, no more than once per calendar year. Such audits must be conducted during normal business hours and in a manner that does not unreasonably disrupt Processor's operations.

9.3 Third-Party Auditors. Controller may engage a third-party auditor to conduct the audit on its behalf, provided the auditor is subject to confidentiality obligations.


Article 10 — Transfers of Personal Data

10.1 US Processing. All Personal Data is processed and stored by Processor and its Sub-processors within the United States. Processor does not transfer Personal Data to countries outside the United States under this Agreement.

10.2 Future EU/UK Transfers. This DPA does not include Standard Contractual Clauses (SCCs) or a UK International Data Transfer Addendum (IDTA). If Controller anticipates that EU or UK data subjects' Personal Data will be processed through MissionHand, the parties will execute appropriate transfer mechanisms (including EU SCCs Module 2: Controller-to-Processor) before such processing begins.


Article 11 — Liability and Indemnification

11.1 Applicability of Agreement Cap. Each party's liability under this DPA is subject to the limitations of liability set forth in the Agreement (Section 11 of the Terms of Service).

11.2 Processor Liability. Processor will be liable to Controller for damages caused by Processor's breach of its obligations under this DPA, subject to the aggregate liability cap in the Agreement. Processor is not liable for damages caused by Controller's instructions or Controller's own data practices.


Article 12 — General Provisions

12.1 Precedence. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA takes precedence.

12.2 Amendments. Processor may update this DPA to reflect changes in law or Sub-processors, with the same notice requirements as the Agreement.

12.3 Governing Law. This DPA is governed by the laws of the State of Florida, consistent with the Agreement.

12.4 Severability. If any provision of this DPA is found unenforceable, the remaining provisions continue in full force and effect.