Last updated: August 20, 2026 · Forms part of the Terms of Service
This Data Processing Addendum ("DPA") applies when DonorGraph LLC, a Nevada limited liability company ("DonorGraph"), processes personal information on behalf of a customer ("Customer"). It is incorporated into the Terms of Service. Where this DPA conflicts with the Terms, this DPA controls for matters of data protection.
This DPA governs Customer Data only: the records Customer uploads, imports, or creates in the Services, such as its own donor and constituent lists, gift records, notes, and communications. For Customer Data, Customer is the controller (or "business") and DonorGraph is the processor (or "service provider").
This DPA does not cover the public-records research data that DonorGraph independently compiles from sources such as IRS Form 990 filings, FEC and state campaign-finance records, SEC filings, property records, and DOL filings. DonorGraph determines the purposes and means of that processing itself and is the controller of it. That data is described in our Privacy Policy, and individuals may exercise rights over it directly with us via Your privacy rights. We draw this line explicitly because conflating the two would misstate who is responsible for what.
DonorGraph processes Customer Data only on Customer's documented instructions, including as necessary to provide the Services and as required by law. If DonorGraph believes an instruction violates applicable data-protection law, it will inform Customer.
DonorGraph limits access to Customer Data to personnel who need it to provide or support the Services, and binds them to confidentiality obligations.
DonorGraph maintains technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest, role-based access control, least-privilege credentials, and audit logging. Security measures are described in the Privacy Policy. DonorGraph does not currently hold a SOC 2 attestation and does not represent that it does.
Customer authorises DonorGraph to engage the subprocessors listed at donorgraph.com/subprocessors.html. DonorGraph will give at least 30 days' notice before adding a subprocessor that processes Customer Data, by updating that page and emailing account administrators. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees. DonorGraph remains liable for its subprocessors' performance.
DonorGraph will provide reasonable assistance so Customer can respond to requests from individuals to access, correct, delete, or port their information, and will promptly forward any such request it receives directly. Where an individual asks about information held by a specific Customer, DonorGraph will refer them to that Customer.
DonorGraph will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting Customer Data, and will provide the information reasonably available to help Customer meet its own notification obligations.
On termination, Customer may export its Customer Data through the Services. DonorGraph deletes Customer Data from production systems 30 days after account termination; backups are purged on a rolling 90-day cycle.
With respect to Customer Data and to the extent the California Consumer Privacy Act applies, DonorGraph acts as a "service provider". DonorGraph will not sell or share Customer Data; will not retain, use, or disclose it except to perform the Services or as permitted by the CCPA; and will not combine it with personal information from other sources except as the CCPA permits a service provider to do. DonorGraph certifies that it understands and will comply with these restrictions.
On reasonable written request, no more than once per year, DonorGraph will make available information necessary to demonstrate compliance with this DPA and will respond to reasonable security questionnaires.
The Services are operated from the United States and Customer Data is stored there. DonorGraph does not offer an EU or UK data-residency option and does not currently rely on Standard Contractual Clauses; customers subject to GDPR should evaluate this before uploading personal data of EU or UK residents.
Each party's liability under this DPA is subject to the limitations in the Terms of Service.
Questions or a countersigned copy: legal@donorgraph.com.