VolunteerFlow
HomeFeaturesHow it worksPricingAboutOrganizations
Start free

Data Processing Agreement

Effective Date: April 9, 2026 · Last Updated: September 24, 2026 · Version 1.2

Who this is for: This Data Processing Agreement (DPA) governs the processing of personal data by VolunteerFlow on behalf of organizations subject to GDPR, CCPA, or similar data protection regulations. It is entered into pursuant to GDPR Article 28.

This Data Processing Agreement ("DPA") is entered into between the nonprofit organization using VolunteerFlow (the "Controller") and PowerHouseTech LLC, a New York limited liability company doing business as VolunteerFlow (the "Processor"), and is incorporated into and governed by the VolunteerFlow Terms of Service.

This DPA, including Annex A (Security Measures), forms part of the Terms of Service and applies automatically to all Personal Data VolunteerFlow processes for Controller, without a separate signature. If the Terms of Service and this DPA conflict on the protection of Personal Data, this DPA controls.


1. Definitions

  • Controller: The nonprofit organization determining the purposes and means of processing volunteer Personal Data.
  • Processor: PowerHouseTech LLC dba VolunteerFlow ("VolunteerFlow"), processing Personal Data on behalf of the Controller in accordance with instructions.
  • Data Subject: Any individual to whom Personal Data relates, including volunteers, staff, and administrative contacts.
  • Personal Data: Information relating to identified or identifiable individuals, including names, emails, phones, dates of birth, emergency contacts, volunteer hours, background check results, training certifications, waivers, messages, and files.
  • Processing: Any operation on Personal Data such as collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
  • Sub-Processor: Any entity processing Personal Data on behalf of the Controller under a contract with substantially equivalent data protection obligations.
  • GDPR: The European Union General Data Protection Regulation (EU 2016/679).
  • CCPA: The California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.).

2. Scope and Purpose

VolunteerFlow processes Personal Data solely for providing the VolunteerFlow SaaS platform and related services as described in the Terms of Service. VolunteerFlow shall not use Personal Data for any other purpose without prior written consent of Controller.

Controller warrants that it has a lawful basis under applicable privacy laws to collect and process the Personal Data, and that all required notices have been provided to Data Subjects. VolunteerFlow shall process Personal Data only in accordance with: (a) documented instructions in the Terms of Service; (b) written organization-specific instructions; and (c) applicable laws.

3. Types of Personal Data Processed

VolunteerFlow processes the following categories of Personal Data on behalf of Controller:

  • Volunteer identity information (names, emails, phones, addresses, dates of birth)
  • Emergency contact information
  • Volunteer activity and hours records
  • Applications and submissions
  • Training and certification records
  • Background check results
  • Waiver and consent records
  • Communication records (messages, SMS)
  • Donation, payment, and order records
  • File uploads and attachments

Where Controller enables the relevant features, VolunteerFlow also processes special or sensitive categories of Personal Data: military and veteran service information; demographic information including gender, race and ethnicity, household composition, and income; criminal history disclosures; government identification references, stored encrypted and returned only in masked form; and health and medical records, stored encrypted and reachable only under an explicit permission grant.

Data Subjects include: volunteers and volunteer applicants; program participants and beneficiaries whose records Controller keeps in the Service; donors and purchasers; organization staff and administrators; and administrative contacts.

4. Sub-Processors

Controller consents to the following sub-processors. Each is bound by a written agreement imposing substantially equivalent data protection obligations. VolunteerFlow shall provide Controller with at least 30 days' prior written notice before engaging any new sub-processor.

Sub-ProcessorPurpose
SupabaseCloud database hosting and file storage (United States)
RailwayBackend application hosting (United States)
VercelWebsite hosting, deployment, and cookieless analytics
ResendTransactional and announcement email delivery
TelnyxSMS and text message delivery
Google (Firebase Cloud Messaging)Push notification delivery to the VolunteerFlow mobile apps
StripeSubscription billing for VolunteerFlow plans and add-ons
Square (Block, Inc.)Donation, kiosk, and store payments taken on behalf of Controller
CheckrBackground check processing, where Controller selects this provider
SterlingBackground check processing, where Controller selects this provider
AnthropicAI features (assistant, messaging and report drafting, scheduling suggestions) included in the Impact plan, and photo-based animal record import
OpenAIAI features included in the Impact plan

5. Controller Obligations

Controller is responsible for:

  • Ensuring a lawful basis under GDPR, CCPA, and applicable laws for collecting and processing Personal Data
  • Providing required notices to Data Subjects regarding collection, processing, and sharing of Personal Data, including notice of VolunteerFlow's role as Processor
  • Obtaining all necessary consents from Data Subjects and maintaining documentation
  • Compliance with all statutory notice requirements
  • Not using the Services to create, receive, maintain, or transmit protected health information, as defined under HIPAA, in the capacity of a covered entity or business associate unless a Business Associate Agreement signed by both parties is in effect

6. Processor Obligations

VolunteerFlow shall:

  • Ensure all persons authorized to access Personal Data are subject to binding confidentiality obligations
  • Process Personal Data only in accordance with documented instructions of Controller
  • Upon receipt of Data Subject rights requests, promptly notify Controller and provide reasonable assistance
  • Not use Personal Data for any purpose other than providing the Services
  • Manage sub-processors in accordance with this DPA

7. Security Measures

VolunteerFlow shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of the Personal Data and the risks of the processing. At a minimum, VolunteerFlow shall maintain the measures described in Annex A. VolunteerFlow may update those measures over time, provided that no update materially reduces the overall protection of Personal Data.

VolunteerFlow maintains incident response procedures and shall notify Controller of Personal Data breaches as set out in Section 9.

8. VolunteerFlow Staff Access

Controller acknowledges and consents to VolunteerFlow support staff accessing organization data for technical support and issue resolution. All staff with data access are subject to binding confidentiality agreements. Support sessions may be used to diagnose and resolve technical issues. Each support session is logged, including the staff member, the organization accessed, and when the session started and ended, and is shown to Controller in its security settings.

Controller may request an audit log report showing all staff access to Controller's data. VolunteerFlow shall provide such audit logs within 30 business days.

9. Data Breach Notification

VolunteerFlow shall notify Controller without undue delay and no later than 72 hours after discovering a Personal Data breach affecting Controller's data. Notification shall include: description of the breach and affected data, likely consequences, measures taken or proposed, and contact information for the responsible official.

VolunteerFlow shall provide information necessary for Controller to determine whether Data Subject or regulatory authority notification is required.

10. Data Retention and Deletion

VolunteerFlow shall retain Personal Data for the duration of the service agreement and any legally required retention period thereafter, unless Controller directs otherwise in writing.

Upon termination or expiration of the service agreement, VolunteerFlow shall make all Personal Data available for export in a standard portable format for 30 days, and shall then permanently delete all Personal Data from active systems using secure deletion methods within 60 days after that export period ends, or sooner at Controller's written request.

VolunteerFlow shall delete Personal Data from backup systems within 30 days after deletion from active systems, as backups expire on a rotation of no more than 30 days, unless Controller has requested retention. Upon completion of data deletion, VolunteerFlow shall provide Controller with written certification that all Personal Data has been deleted in accordance with this DPA.

11. Data Subject Rights Assistance

Upon receipt of Data Subject access, deletion, portability, or correction requests, VolunteerFlow shall promptly notify Controller and provide reasonable assistance to enable Controller to fulfill the request within applicable legal timeframes (typically 30 days under GDPR). Assistance is provided at no additional charge except for requests requiring substantial development costs.

12. International Data Transfers

Controller acknowledges that VolunteerFlow uses Supabase as its primary hosting provider. Personal Data may be stored on servers located in the United States. For controllers subject to GDPR, VolunteerFlow relies on Standard Contractual Clauses (SCCs) for international data transfers. VolunteerFlow shall execute Data Processing Addenda incorporating SCCs as necessary.

13. GDPR Article 28 Compliance

This DPA is entered into pursuant to GDPR Article 28 and incorporates the mandatory clauses required by that Article. To the extent the Services involve processing of Personal Data of individuals located in the European Union, VolunteerFlow acts as a Processor under GDPR Article 28, and this DPA shall govern that processing relationship.

14. CCPA and Service Provider Compliance

To the extent the Services involve processing of Personal Data of California residents, VolunteerFlow is a Service Provider under CCPA Section 1798.100(d). As a Service Provider, VolunteerFlow shall not retain, use, or disclose Personal Data except as necessary to perform the Services; shall not sell Personal Data; shall not use Personal Data for any commercial purpose other than providing the Services; and shall not combine Personal Data received from Controller with Personal Data from other sources.

To the extent the Services involve Personal Data of New York residents, VolunteerFlow shall maintain reasonable safeguards as required by the New York SHIELD Act (N.Y. Gen. Bus. Law § 899-bb) and shall notify Controller of any breach of the security of the system affecting Controller's data as required by N.Y. Gen. Bus. Law § 899-aa, and in any event within the period set out in Section 9. VolunteerFlow shall likewise maintain the measures in Annex A for Personal Data of residents of any other state whose law requires a service provider to protect personal information by contract, including Massachusetts (201 CMR 17.00).

15. Audit Rights

Controller may request audit information regarding VolunteerFlow's compliance with data protection obligations. VolunteerFlow shall provide audit information within 30 business days of request. VolunteerFlow does not currently hold a third-party audit report such as SOC 2. Until it does, VolunteerFlow shall answer reasonable written security questionnaires and, once in any twelve-month period and on at least 30 days' notice, make available the information reasonably necessary to demonstrate compliance with this DPA. Where VolunteerFlow later obtains a current third-party audit report, it may provide that report in satisfaction of audit requests.

16. Term and Termination

This DPA is effective as of the date it is accepted by Controller and shall remain in effect for the duration of the service agreement. Upon termination, VolunteerFlow shall cease processing Personal Data and shall return or delete all Personal Data as directed by Controller in accordance with Section 10.

17. Governing Law

This DPA shall be governed by and construed in accordance with the laws of the State of New York, without regard to its conflict of law provisions.

18. Contact

For questions regarding this DPA, data protection practices, or privacy concerns, contact:
Email: legal@volunteerflow.us

This DPA should be read together with our Privacy Policy and Terms of Service. A plain-language summary of Annex A is published at volunteerflow.us/security; if the two differ, this Annex controls.


Annex A. Security Measures

VolunteerFlow maintains at least the following technical and organizational measures.

A.1 Access control and authentication

  • Passwords are stored only as bcrypt hashes. Repeated failed sign-ins temporarily lock the account.
  • Multi-factor authentication (an authenticator app or an emailed code) is available to every staff account. On the Impact plan, Controller's administrators can prevent users from turning it off.
  • Access within Controller's account follows the roles and permissions Controller sets. Health and medical records are reachable only under an explicit permission grant.
  • On the Impact plan, Controller can restrict staff access to allowlisted IP addresses.
  • Sessions use signed tokens in httpOnly, Secure cookies. Every request confirms the session is still active, users can view and revoke their own sessions, and the web application signs staff out after 30 minutes of inactivity.
  • Sign-in endpoints are rate limited, as is the platform as a whole.

A.2 Encryption

  • All data in transit is encrypted with TLS, and browsers are instructed to use HTTPS only (HSTS).
  • The database and file storage are encrypted at rest by the hosting provider.
  • Health and medical records, government identification references, and locked case notes are additionally encrypted at the application level with AES-256-GCM, using keys derived per organization. These records are refused, not stored, if that encryption is unavailable. Encryption keys can be rotated under a documented procedure.

A.3 Separation of customer data

  • Every request is scoped to the organization it belongs to, and location restrictions set by Controller are applied on the server.
  • An automated check on every code change rejects database queries against customer data that lack an organization filter.

A.4 Logging and monitoring

  • Sign-ins and administrative changes are logged.
  • Every VolunteerFlow support session is logged as described in Section 8 and shown to Controller.
  • Error monitoring is configured not to collect passwords, cookies, or authentication headers.

A.5 Secure development

  • Every code change, and the full codebase weekly, is scanned automatically for committed secrets and for known vulnerabilities in dependencies. High and critical dependency findings block the change unless reviewed and recorded.
  • Uploaded files are checked against their actual content type, not only their name.
  • Outbound webhooks may only reach public HTTPS addresses, and private network addresses are blocked.
  • Browser security headers, including a Content Security Policy, HSTS, and frame and content-type protections, are set on the web application.

A.6 Personnel

  • Everyone with access to Personal Data is bound by confidentiality obligations and receives access only as needed for support, operations, or security.

A.7 Backups and continuity

  • The database is backed up daily by the hosting provider, and backups expire on a rotation of no more than 30 days.
  • VolunteerFlow maintains a written disaster recovery procedure.

A.8 Incidents

  • VolunteerFlow maintains incident response procedures and notifies Controller of Personal Data breaches within the period in Section 9.

Effective as of April 9, 2026.

VolunteerFlow

The volunteer management platform built for organizations that want to make a bigger impact.

Disabled Military Veteran-Owned Business
Product
How it worksFeaturesPricing
Company
AboutCareersContact
Legal
Privacy PolicyTerms of ServiceAcceptable UseCookie PolicyBilling & RefundsData ProcessingSecurity

© 2026 VolunteerFlow. All rights reserved.

Status