Koolay

Data Processing Agreement (DPA)

Last updated 2026-04-17

This Data Processing Agreement ("DPA") supplements the Terms of Service between Koolay Inc., a Delaware C-Corp at 8 The Green STE D, Dover, DE 19901, USA ("Processor") and the Customer ("Controller") using the Koolay Service. It applies to Personal Data processed by Koolay on behalf of Controller. By accepting the Terms of Service, the Controller enters into this DPA.

1. Definitions

Terms have the meaning given in the EU GDPR unless otherwise defined. Personal Data: any information relating to an identified or identifiable natural person processed by Koolay on behalf of Controller. Subprocessor: any third party engaged by Koolay to process Personal Data.

2. Subject matter and duration

Koolay processes Personal Data on behalf of Controller solely to provide the Service. Processing continues for as long as the Controller's subscription is active.

3. Nature and purpose

Koolay processes Personal Data as necessary to operate the multi-tenant SaaS platform: storage, backup, authentication, donor/membership records, grant/scholarship workflows, event registration, newsletter delivery, AI-assisted drafting, and customer support.

4. Types of Personal Data

Name, email, phone, mailing address, donation history, payment references (Stripe tokens — never card numbers), membership status, application records, IP addresses, log/usage data.

5. Data Subjects

Donors, members, scholarship applicants, event attendees, volunteers, newsletter subscribers, Controller's staff and administrators.

6. Controller instructions

Koolay processes Personal Data only on documented instructions from Controller (including those embedded in Controller's use of the Service and configured settings). Koolay will notify Controller if an instruction appears to violate applicable law.

7. Confidentiality

Koolay ensures personnel authorized to process Personal Data are subject to written confidentiality obligations.

8. Security measures (Art. 32 GDPR)

Full measures: Security Center.

9. Subprocessors

Koolay uses the subprocessors listed at koolay.com/subprocessors. The Controller generally authorizes engagement. Koolay will:

10. Data Subject requests

Koolay provides technical tools (Admin → Settings → GDPR) enabling Controller to fulfill Data Subject rights: access (export), rectification (in-app edit), erasure (immediate purge), portability. If a Data Subject contacts Koolay directly, Koolay forwards to Controller within 5 business days.

11. International transfers

Koolay's infrastructure is primarily in the United States (AWS US-East-1). Where Personal Data is transferred out of the EU/UK, the parties rely on the EU Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum, incorporated by reference. Module Two (Controller-to-Processor) applies by default.

12. Breach notification

Koolay will notify Controller without undue delay and in any case within 72 hours after becoming aware of a Personal Data Breach affecting Controller's data. Notification includes nature of breach, affected data categories and approximate number of data subjects, likely consequences, and measures taken.

13. DPIAs

On reasonable request, Koolay provides information to help Controller conduct DPIAs and prior consultations with supervisory authorities.

14. Audit rights

Koolay will make available to Controller all information necessary to demonstrate compliance with Article 28 GDPR, including third-party audit reports (e.g. SOC 2 once issued). Controller may request an audit no more than once per year; costs are borne by the Controller unless material non-compliance is found.

15. Deletion or return of data

On termination or Controller's request, Koolay will delete Personal Data or return it to Controller within 90 days of the termination effective date. Backup copies are purged within 30 additional days. Logs necessary for legal compliance may be retained as permitted by law.

16. Liability

Liability under this DPA is governed by the liability provisions of the underlying Terms of Service.

17. Term and termination

This DPA is effective from the start of the subscription and remains in force for as long as Koolay processes Personal Data on behalf of Controller.

18. Miscellaneous

This DPA supersedes any prior data-processing agreement. If any provision conflicts with the underlying contract, this DPA controls for matters of data protection. Governing law: Delaware, USA (with GDPR provisions governed by applicable EU law).

Signed by default on acceptance of the Terms of Service. For a counter-signed copy, email [email protected].