Legal
Data Processing Agreement
Effective September 1, 2026
Appendix B to the StratusLIVE Subscription Agreement Terms of Use and Conditions
This Data Processing Agreement (“DPA” or this “Appendix B”) is entered into by and between StratusLIVE, LLC (“StratusLIVE” or “Processor”) and the Subscriber identified in the applicable Order Form (“Controller”), and forms an integral part of, and is incorporated by reference into, the StratusLIVE Subscription Agreement Terms of Use and Conditions available at stratuslive.com/terms/ (the “Agreement”) and the StratusLIVE Data Privacy Policy available at stratuslive.com/data-privacy-policy/. This DPA governs the Processing of Personal Data by StratusLIVE on behalf of Controller in connection with the Service. Capitalized terms not defined in this DPA have the meanings given to them in the Agreement. In the event of a conflict between this DPA and a separately negotiated and signed DPA addendum executed by both parties, the negotiated addendum controls.
1. Definitions
- “Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and U.S. state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and comparable state privacy laws.
- “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given in the GDPR, and “Business,” “Service Provider,” “Consumer,” “Sell,” and “Share” have the meanings given in the CCPA, in each case to the extent applicable to the Personal Data at issue. “Personally Identifiable Information” or “PII,” as used in the Agreement, is a subset of Personal Data.
- “Sub-processor” means any third party engaged by Processor to Process Personal Data on behalf of Controller in connection with the Service.
- “Special Categories of Personal Data” means personal data revealing racial or ethnic origin, religious or philosophical beliefs, health data, or other categories of data afforded heightened protection under Applicable Data Protection Laws.
- “Corporate Partners” means the companies, employers, or other organizations through which employees or members participate in workplace giving, matching gift, or volunteering programs facilitated through the Service.
2. Roles of the Parties
Controller is the Controller (or, under the CCPA, the Business) with respect to Personal Data processed through the Service, and StratusLIVE is the Processor (or Service Provider). StratusLIVE will Process Personal Data solely as a Processor acting on behalf of Controller — including where Controller authorizes access by its donors, members, volunteers, Corporate Partners, and Corporate Partners' employees — and shall not Process such Personal Data for its own independent purposes, except as necessary to provide, maintain, secure, and improve the Service, to comply with law, or as otherwise permitted under Applicable Data Protection Laws.
3. Scope, Nature, and Purpose of Processing
StratusLIVE Processes Personal Data to provide the fundraising, CRM, donor engagement, workplace giving, volunteer management, event, and related software and services described in the Agreement, including: enabling donation and payment processing; hosting and managing donor, member, and volunteer records; facilitating and reporting on fundraising and giving campaigns; enabling Controller's communications with its donors, members, and volunteers; and providing AI-assisted features as described in Section 3.2 of the Agreement and Section 14 of this DPA. StratusLIVE will Process Personal Data only for the duration of the Agreement and solely for these purposes and any other purposes documented in writing by Controller and agreed to by StratusLIVE.
4. Categories of Data Subjects and Personal Data
4.1 Data Subjects
Data Subjects may include: Controller's donors, members, constituents, and volunteers; Controller's employees and authorized users; and Corporate Partners and their employees or members who participate in workplace giving, matching gift, or volunteering programs facilitated through the Service.
4.2 Personal Data
Categories of Personal Data may include: names, postal and email addresses, phone numbers, employer and employee identifiers, donation and giving history, payment card or bank account tokens (processed via StratusLIVE's payment Sub-processors), payroll deduction references, volunteer hours and interests, and other information Controller elects to store in or transmit through the Service.
4.3 Special Categories of Personal Data
Controller shall not submit Special Categories of Personal Data to the Service unless Controller has independently determined that such submission is lawful and necessary, and has notified StratusLIVE in writing in advance. Controller acknowledges that some Special Categories of Personal Data (for example, health-related giving designations in cause-based fundraising) may be incidentally processed where Controller elects to configure the Service to capture such data, and Controller remains solely responsible for the lawful basis for collecting and Processing such data.
5. Processor Obligations
StratusLIVE shall:
- (a) Process Personal Data only on documented instructions from Controller, including instructions conveyed through Controller's use and configuration of the Service, unless required to do otherwise by applicable law, in which case StratusLIVE shall, to the extent permitted by law, inform Controller of that legal requirement before Processing;
- (b) promptly inform Controller if, in StratusLIVE's opinion, an instruction from Controller infringes Applicable Data Protection Laws;
- (c) ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- (d) implement and maintain appropriate technical and organizational measures as described in Section 7;
- (e) taking into account the nature of the Processing, assist Controller, insofar as reasonably possible, in responding to requests from Data Subjects seeking to exercise their rights under Applicable Data Protection Laws;
- (f) assist Controller in ensuring compliance with its obligations relating to the security of Processing, Personal Data Breach notification, and, where applicable, data protection impact assessments, taking into account the nature of Processing and the information available to StratusLIVE;
- (g) at Controller's choice, delete or return all Personal Data after the end of the provision of Services relating to Processing, and delete existing copies, in accordance with Section 15; and
- (h) make available to Controller information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits in accordance with Section 12.
6. Confidentiality
The Service and any Personal Data Processed through it are Confidential Information of the disclosing party under Section 6 of the Agreement, and this DPA does not limit or reduce either party's confidentiality obligations under that Section.
7. Security Measures
StratusLIVE shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, including, as applicable: encryption of Personal Data in transit and at rest; access controls and authentication; regular testing and evaluation of the effectiveness of security measures; the ability to restore availability of and access to Personal Data in a timely manner following an incident; and the backup and disaster recovery measures described in Section 3.5 of the Agreement.
8. Sub-processors
8.1 Authorized Sub-processors
Controller provides general written authorization for StratusLIVE to engage the following categories of Sub-processors to provide the Service, as updated from time to time at stratuslive.com/subprocessors in accordance with Section 8.3:
- Microsoft Azure — cloud hosting and infrastructure
- Microsoft 365 — business productivity and communications
- Confluent — data streaming infrastructure
- Authorize.net — payment processing
- PayPal — payment processing
- Stripe — payment processing
- MongoDB — database hosting
- Snowflake — data warehousing and analytics
- Sendgrid — transactional and marketing email delivery
- Zendesk — customer support ticketing
- HubSpot — customer relationship and marketing management
8.2 Flow-Down and Liability
StratusLIVE shall enter into a written agreement with each Sub-processor imposing data protection obligations substantially similar to those set out in this DPA. StratusLIVE remains fully liable to Controller for the performance of each Sub-processor's obligations.
8.3 Notice and Objection
StratusLIVE will provide at least fourteen (14) days' advance notice — via the sub-processor list referenced above and, upon request, by email to Controller's designated contact — before engaging any new Sub-processor that will Process Personal Data. Controller may object to a new Sub-processor on reasonable data protection grounds by written notice within that notice period; the parties will work in good faith to resolve the objection, and if unresolved, Controller's sole remedy is to terminate the Agreement with respect to the affected Service without penalty.
9. International Data Transfers
StratusLIVE is based in the United States and primarily processes Personal Data in the United States. Where Personal Data is transferred internationally — including where Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to the United States, or to any other jurisdiction not deemed to provide an adequate level of data protection — StratusLIVE relies on appropriate safeguards recognized under applicable data protection law, including the EU Standard Contractual Clauses or the UK International Data Transfer Addendum, which shall be deemed incorporated into this DPA by reference to the extent applicable.
10. Data Subject Requests
StratusLIVE shall, taking into account the nature of the Processing, provide reasonable assistance to Controller, including by appropriate technical and organizational measures, to enable Controller to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If StratusLIVE receives a request directly from a Data Subject, StratusLIVE will not respond directly, other than to acknowledge receipt, and will promptly forward the request to Controller.
11. Personal Data Breach Notification
StratusLIVE shall notify Controller without undue delay, and in any event within seventy-two (72) hours after becoming aware of a Personal Data Breach affecting Controller's Personal Data. Such notice shall, to the extent then known, describe: the nature of the breach; the categories and approximate number of Data Subjects and Personal Data records concerned; the likely consequences of the breach; and the measures taken or proposed to address the breach and mitigate its effects. StratusLIVE shall provide reasonable and timely cooperation and information to Controller as Controller reasonably requires to meet its own notification obligations under Applicable Data Protection Laws.
12. Audits and Compliance
StratusLIVE maintains a SOC 2 Type II report, refreshed no less than annually. No more than once per twelve (12) month period, and upon at least thirty (30) days' prior written notice, Controller (or a mutually agreed, independent third-party auditor bound by confidentiality) may audit StratusLIVE's compliance with this DPA during normal business hours, without unreasonably interfering with StratusLIVE's business operations. StratusLIVE may satisfy an audit request by providing Controller with a copy of its then-current SOC 2 Type II report, and Controller agrees to accept such report in lieu of an on-site audit unless (a) a Personal Data Breach has occurred within the preceding twelve months, or (b) Applicable Data Protection Law or a Supervisory Authority requires a direct audit. Audit reports and findings are Confidential Information of StratusLIVE under the Agreement. Controller shall bear its own costs of any audit; StratusLIVE may charge its then-current time and materials rate for support beyond providing existing documentation.
13. U.S. State Privacy Law Requirements
To the extent the CCPA or another comparable U.S. state privacy law applies to Personal Data processed under this DPA, StratusLIVE certifies that it:
- (a) will Process Personal Data solely as a Service Provider/Processor on behalf of Controller and for the specific business purposes set out in this DPA;
- (b) will not Sell or Share Personal Data;
- (c) will not retain, use, or disclose Personal Data for any purpose other than the specific business purposes described in this DPA, including not for any commercial purpose other than providing the Service, unless otherwise permitted by applicable law;
- (d) will not combine Personal Data received from Controller with personal data received from other sources, except as permitted under applicable law; and
- (e) will notify Controller if it can no longer meet its obligations under applicable state privacy law.
14. Artificial Intelligence Processing
Any AI or AI Agent functionality provided as part of the Service is subject to Section 3.2 (AI-assisted Features) and Section 6.2 (AI Model Training Restriction) of the Agreement. StratusLIVE confirms that Public AI Models (as defined in the Agreement) are not connected to, and do not Process, Personal Data submitted through the Service, and that Personal Data is not used to train any Public AI Model.
15. Term, Termination, and Data Disposition
This DPA remains in effect for as long as StratusLIVE Processes Personal Data on behalf of Controller under the Agreement. Upon termination or expiration of the Agreement, and within sixty (60) days of Controller's request, StratusLIVE shall, at Controller's choice, return or delete all Personal Data in its possession or control, including copies held by Sub-processors, except to the extent applicable law requires StratusLIVE to retain some or all of such Personal Data, in which case StratusLIVE will isolate and protect that data from further Processing except as required by such law. StratusLIVE shall provide written confirmation of deletion upon Controller's request. Personal Data contained in routine backup copies described in Section 3.5 of the Agreement will be deleted in the ordinary course as those backups are cycled out, and in no event later than ninety (90) days following termination.
16. Liability
Each party's aggregate liability arising out of or related to this DPA is subject to the limitation of liability set out in Section 5.2(f) of the Agreement — in no event shall either party's aggregate liability under the Agreement and this DPA, taken together, exceed the total fees paid or payable by Subscriber to StratusLIVE in the twelve (12) months immediately preceding the event giving rise to the claim — except to the extent Applicable Data Protection Laws prohibit the limitation of such liability.
17. Order of Precedence; General
In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA shall control. In all other respects, this DPA is governed by the terms of the Agreement.