Last updated 2026-04-17
This Data Processing Agreement ("DPA") supplements the Terms of Service between Koolay Inc., a Delaware C-Corp at 8 The Green STE D, Dover, DE 19901, USA ("Processor") and the Customer ("Controller") using the Koolay Service. It applies to Personal Data processed by Koolay on behalf of Controller. By accepting the Terms of Service, the Controller enters into this DPA.
Terms have the meaning given in the EU GDPR unless otherwise defined. Personal Data: any information relating to an identified or identifiable natural person processed by Koolay on behalf of Controller. Subprocessor: any third party engaged by Koolay to process Personal Data.
Koolay processes Personal Data on behalf of Controller solely to provide the Service. Processing continues for as long as the Controller's subscription is active.
Koolay processes Personal Data as necessary to operate the multi-tenant SaaS platform: storage, backup, authentication, donor/membership records, grant/scholarship workflows, event registration, newsletter delivery, AI-assisted drafting, and customer support.
Name, email, phone, mailing address, donation history, payment references (Stripe tokens — never card numbers), membership status, application records, IP addresses, log/usage data.
Donors, members, scholarship applicants, event attendees, volunteers, newsletter subscribers, Controller's staff and administrators.
Koolay processes Personal Data only on documented instructions from Controller (including those embedded in Controller's use of the Service and configured settings). Koolay will notify Controller if an instruction appears to violate applicable law.
Koolay ensures personnel authorized to process Personal Data are subject to written confidentiality obligations.
Full measures: Security Center.
Koolay uses the subprocessors listed at koolay.com/subprocessors. The Controller generally authorizes engagement. Koolay will:
Koolay provides technical tools (Admin → Settings → GDPR) enabling Controller to fulfill Data Subject rights: access (export), rectification (in-app edit), erasure (immediate purge), portability. If a Data Subject contacts Koolay directly, Koolay forwards to Controller within 5 business days.
Koolay's infrastructure is primarily in the United States (AWS US-East-1). Where Personal Data is transferred out of the EU/UK, the parties rely on the EU Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum, incorporated by reference. Module Two (Controller-to-Processor) applies by default.
Koolay will notify Controller without undue delay and in any case within 72 hours after becoming aware of a Personal Data Breach affecting Controller's data. Notification includes nature of breach, affected data categories and approximate number of data subjects, likely consequences, and measures taken.
On reasonable request, Koolay provides information to help Controller conduct DPIAs and prior consultations with supervisory authorities.
Koolay will make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR, including third-party audit reports (e.g. SOC 2 once issued). Controller may request an audit no more than once per year; costs are borne by the Controller unless material non-compliance is found.
On termination or Controller's request, Koolay will delete Personal Data or return it to Controller within 90 days of the termination effective date. Backup copies are purged within 30 additional days. Logs necessary for legal compliance may be retained as permitted by law.
Liability under this DPA is governed by the liability provisions of the underlying Terms of Service.
This DPA is effective from the start of the subscription and remains in force for as long as Koolay processes Personal Data on behalf of Controller.
This DPA supersedes any prior data-processing agreement. If any provision conflicts with the underlying contract, this DPA controls for matters of data protection. Governing law: Delaware, USA (with GDPR provisions governed by applicable EU law).
Signed by default on acceptance of the Terms of Service. For a counter-signed copy, email [email protected].