Data Processing Addendum

This Data Processing Addendum is incorporated into and forms part of the Buzzbold Principal Services Agreement. See also: Subprocessors | Privacy and Information Use Policy

Last Updated: March 31, 2026


This Data Processing Addendum ("DPA") is incorporated into and forms part of the Buzzbold Principal Services Agreement ("Agreement") between Buzzbold, LLC ("Buzzbold") and the entity identified as Customer in the Agreement ("Customer"). This DPA applies when Buzzbold Processes Customer Personal Data in connection with Services provided under a Statement of Work.

1. Definitions

Capitalized terms not defined herein have the meanings given in the Agreement.

1.1 "Applicable Data Protection Law" means all applicable laws relating to the processing of personal data, including without limitation the California Consumer Privacy Act (CCPA), state privacy and data protection laws, and, to the extent applicable, the EU General Data Protection Regulation (GDPR).

1.2 "Customer Personal Data" means any information that identifies or could reasonably be used to identify a natural person, which Buzzbold Processes on behalf of Customer in connection with the Services. This includes data residing in Customer's systems (such as Salesforce) that Buzzbold accesses or handles in performing the Services.

1.3 "Buzzbold Business Records" means data that Buzzbold creates or maintains for its own legitimate business purposes in connection with the engagement, including but not limited to: time entries, invoices, project plans, internal case notes, resource utilization records, delivery metrics, and communications related to service coordination. Buzzbold is the controller of Buzzbold Business Records.

1.4 "Aggregated Data" means data derived from Customer Personal Data that has been de-identified or aggregated such that it cannot reasonably be used to identify any individual. Buzzbold may retain and use Aggregated Data without restriction for business analysis, benchmarking, and service improvement.

1.5 "Processing" (and "Process") means any operation performed on Customer Personal Data, including collection, access, use, storage, transmission, modification, and deletion.

1.6 "Security Incident" means any confirmed unauthorized access to, or acquisition, disclosure, or use of, Customer Personal Data.

1.7 "Subprocessor" means any third party engaged by Buzzbold that Processes Customer Personal Data on Buzzbold's behalf in connection with the Services.

2. Scope of Processing

2.1 Roles. Customer is the data controller. Buzzbold is the data processor. Buzzbold Processes Customer Personal Data solely as necessary to perform the Services described in each executed Statement of Work.

2.2 Categories of Data. The types of Customer Personal Data Processed depend on the Customer's systems and the Services provided, and may include:

  • Contact information (names, email addresses, phone numbers, mailing addresses)
  • CRM data (records, relationships, and associated metadata)
  • Financial and transaction data
  • Employee and volunteer data
  • Any other personal data present in systems Buzzbold accesses to perform Services

2.3 Data Subjects. Data subjects may include Customer's employees, constituents, donors, volunteers, students, scholarship recipients, and other individuals whose data resides in Customer's systems.

2.4 Processing Restrictions. Buzzbold shall not:

  • (a) Process Customer Personal Data for any purpose other than performing the Services;
  • (b) Sell Customer Personal Data;
  • (c) Share Customer Personal Data for cross-context behavioral advertising;
  • (d) Retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer, except as permitted by this DPA or Applicable Data Protection Law.

3. Buzzbold's Obligations

3.1 Documented Instructions. Buzzbold Processes Customer Personal Data only in accordance with Customer's documented instructions. The executed Statement of Work constitutes Customer's initial instructions. Customer may provide additional written instructions, provided they are consistent with the Agreement. If Buzzbold believes an instruction violates Applicable Data Protection Law, Buzzbold will notify Customer.

3.2 Confidentiality. Buzzbold ensures that all personnel authorized to Process Customer Personal Data are bound by obligations of confidentiality as set forth in Section 6 of the Agreement.

3.3 Security. Buzzbold implements and maintains commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, or destruction, as described in Section 4 of this DPA.

3.4 Cooperation. Buzzbold provides reasonable assistance to Customer with:

  • (a) Responding to data subject rights requests (Section 7);
  • (b) Security Incident notification and response (Section 5);
  • (c) Data protection impact assessments, where required by law;
  • (d) Consultations with supervisory authorities, where required by law.

Except as otherwise specified in a Statement of Work, assistance under this Section 3.4 is provided at Customer's then-current hourly rate.

4. Security Measures

4.1 Current Controls. Buzzbold maintains the following security measures, which are subject to ongoing improvement as Buzzbold's compliance program matures:

  • (a) Encryption: Data encrypted in transit using TLS 1.2 or higher. Encryption at rest where supported by platform providers.
  • (b) Access Controls: Multi-factor authentication (MFA) enforced on all primary platforms, including Google Workspace, Salesforce, cloud infrastructure (AWS, GCP), financial systems (Xero, BILL, Stripe), collaboration tools (Slack, GitHub), credential management (1Password), and AI tools (ElevenLabs). Buzzbold is developing a formal MFA audit procedure to maintain compliance across all systems as part of its compliance program.
  • (c) Personnel Security: Background checks conducted on personnel via Checkr. All personnel bound by confidentiality obligations.
  • (d) Credential Management: Secrets and credentials managed through 1Password with per-service vault isolation.
  • (e) Infrastructure: Production services hosted on established cloud platforms (Salesforce, Google Cloud Platform, Amazon Web Services). Platform providers maintain their own security certifications.
  • (f) Monitoring: Proactive exception monitoring for customer Salesforce orgs. Automated alerting for anomalous activity.
  • (g) Access Reviews: Periodic review of personnel access to customer systems.

4.2 Compliance Program. Buzzbold is actively developing its compliance program toward industry certifications (such as SOC 2). As certifications are obtained, they will be made available to Customer under Section 9.

4.3 Updates. Security measures may be updated from time to time, provided that any update does not materially decrease the overall level of protection.

5. Security Incident Notification

5.1 Notification. Buzzbold notifies Customer without undue delay, and in no event later than seventy-two (72) hours, after confirming a Security Incident involving Customer Personal Data.

5.2 Content of Notification. Notification includes, to the extent reasonably available:

  • (a) The nature of the Security Incident, including the categories and approximate number of data subjects affected;
  • (b) The likely consequences of the Security Incident;
  • (c) The measures taken or proposed to address the Security Incident and mitigate its effects;
  • (d) The name and contact information of Buzzbold's designated point of contact.

5.3 Cooperation. Buzzbold cooperates with Customer in investigating and remediating the Security Incident and in meeting Customer's notification obligations under Applicable Data Protection Law. Buzzbold's reasonable costs incurred in providing assistance beyond initial notification are recoverable at Customer's then-current hourly rate.

5.4 No Admission. Notification of a Security Incident does not constitute an admission of fault or liability by Buzzbold.

6. Subprocessors

6.1 General Authorization. Customer provides general authorization for Buzzbold to engage Subprocessors to Process Customer Personal Data. The current list of Subprocessors is maintained at:

https://buzzbold.com/subprocessors

6.2 Notification of Changes. Buzzbold provides Customer fourteen (14) days' prior written notice before engaging a new Subprocessor that will Process Customer Personal Data. Notice is provided via email to the address associated with the Customer's account.

6.3 Evaluation Period. Buzzbold may evaluate prospective Subprocessors using synthetic or anonymized data without triggering the notification requirement of Section 6.2. If an evaluation requires access to Customer Personal Data, Buzzbold provides notice per Section 6.2 and limits the evaluation to thirty (30) days, after which the standard Subprocessor approval process applies.

6.4 Objection. Customer may object to a new Subprocessor by providing written notice to Buzzbold within fourteen (14) days of receiving notice under Section 6.2. The parties shall work in good faith to resolve the objection. If the objection cannot be reasonably resolved, Customer may terminate the affected Statement of Work upon written notice, and Buzzbold will refund any prepaid fees for Services not yet rendered.

6.5 Subprocessor Obligations. Buzzbold ensures that each Subprocessor is bound by data protection obligations no less protective than those in this DPA.

6.6 Liability. Buzzbold remains liable for the acts and omissions of its Subprocessors to the same extent as if Buzzbold had performed the Processing directly, subject to the limitations of liability in the Agreement.

7. Data Subject Rights

7.1 Assistance. Buzzbold provides reasonable assistance to Customer in responding to requests from data subjects exercising their rights under Applicable Data Protection Law (including rights of access, correction, deletion, portability, and objection).

7.2 Direct Requests. If Buzzbold receives a data subject request directly, Buzzbold promptly notifies Customer and does not respond to the request without Customer's instruction, unless required by law.

7.3 Billing. Unless otherwise specified in a Statement of Work, Buzzbold's assistance under this Section 7 is provided at Customer's then-current hourly rate.

8. International Data Transfers

8.1 Processing Location. Buzzbold primarily Processes Customer Personal Data within the United States.

8.2 Transfer Safeguards. If Processing of Customer Personal Data outside the United States becomes necessary, Buzzbold implements appropriate safeguards as required by Applicable Data Protection Law (such as Standard Contractual Clauses or equivalent mechanisms) and notifies Customer in advance.

9. Audits and Compliance

9.1 Information. Upon Customer's reasonable written request (no more than once per twelve-month period), Buzzbold makes available information reasonably necessary to demonstrate compliance with this DPA.

9.2 Reports and Certifications. Where available, Buzzbold provides copies of relevant audit reports, certifications, or compliance summaries in lieu of an on-site audit.

9.3 On-Site Audits. On-site audits are available by mutual written agreement, with reasonable advance notice, during normal business hours, and at Customer's expense. On-site audits shall not unreasonably interfere with Buzzbold's business operations.

9.4 Confidentiality. Audit results and any information provided under this Section 9 constitute Buzzbold's Confidential Information under the Agreement.

10. Legal Requests and Cost Recovery

10.1 Legal Process Procedures. Buzzbold's response to legal process (including subpoenas, court orders, and regulatory inquiries) involving Customer Personal Data is governed by the procedures set forth in Buzzbold's Privacy and Information Use Policy and incorporated herein by reference. These procedures include, without limitation:

  • (a) Requirement of a formally issued subpoena from a court of valid jurisdiction;
  • (b) Customer notification within ten (10) business days of Buzzbold becoming aware of the legal process;
  • (c) A fifteen (15) calendar day hold period before production, during which Customer may object in writing;
  • (d) Limitation of production scope to data explicitly and validly requested;
  • (e) Production limited to data within Buzzbold-controlled systems only.

10.2 Cost Recovery. Unless otherwise specified in a Statement of Work, Customer reimburses Buzzbold's reasonable costs incurred in responding to legal process related to Customer's data, including attorney fees and staff time, at Customer's then-current hourly rate. Buzzbold provides Customer with a good-faith estimate before incurring material costs, where practicable.

10.3 Minimum Disclosure. Buzzbold discloses only the minimum Customer Personal Data required to comply with the legal process. Buzzbold reserves the right to challenge requests it deems overly broad or disproportionate.

10.4 Customer-Controlled Systems. For clarity, Buzzbold will not extract data from Customer-controlled systems or services in response to legal process without Customer's knowledge and direction. Buzzbold may provide support to Customer with export or delivery of such data under Customer's direction, billed at Customer's then-current hourly rate.

11. Data Classification and Retention

11.1 Data Categories. The parties acknowledge three categories of data arising from the engagement:

  • (a) Customer Personal Data — personal data Buzzbold Processes on Customer's behalf, subject to the full obligations of this DPA, including deletion upon termination;
  • (b) Buzzbold Business Records — data Buzzbold creates or maintains for its own legitimate business purposes (as defined in Section 1.3), for which Buzzbold is the controller and retains in accordance with its own retention policies;
  • (c) Aggregated Data — de-identified or aggregated data (as defined in Section 1.4) that Buzzbold may retain and use without restriction.

11.2 Data Return and Deletion. Upon termination or expiration of the Agreement (or an applicable Statement of Work), or upon Customer's written request:

  • (a) Buzzbold revokes all personnel credentials and access to Customer-controlled systems within five (5) business days. Customer is responsible for deactivating Buzzbold user accounts within Customer's systems;
  • (b) Buzzbold deletes or returns working copies of Customer Personal Data in Buzzbold-controlled systems within thirty (30) days, at Customer's election;
  • (c) Encrypted backups containing Customer Personal Data held in Buzzbold's backup infrastructure (as described in Buzzbold's Client Data Storage Security policy) are retained for up to ninety (90) days post-termination, after which they are permanently deleted;
  • (d) Buzzbold certifies deletion in writing upon request;
  • (e) Buzzbold may retain Customer Personal Data beyond these periods only to the extent required by Applicable Data Protection Law or where necessary to establish, exercise, or defend legal claims, provided that such data remains subject to the protections of this DPA;
  • (f) Sections 11.1(b) and 11.1(c) are not affected by Customer's deletion request — Buzzbold retains its Business Records and Aggregated Data.

11.3 Customer Systems. For clarity, Customer Personal Data residing in Customer's own systems (such as Customer's Salesforce org) is not in Buzzbold's possession and is not subject to Buzzbold's deletion obligations. Buzzbold's obligation upon termination is to revoke its personnel's access to such systems and delete any copies in Buzzbold's possession.

12. SOW-Level Customization

12.1 Exclusions. A Statement of Work may exclude specific Subprocessors or categories of Processing from the scope of Services for that engagement.

12.2 Additional Requirements. A Statement of Work may impose additional data protection requirements beyond this DPA for a specific engagement. In the event of a conflict, the more protective provision prevails.

12.3 Service-Specific Terms. Where Services involve specialized data types or regulatory requirements (such as FERPA-protected education records), the applicable Statement of Work shall identify such requirements and any corresponding modifications to this DPA.

13. Use of AI Tools

13.1 Disclosure. Buzzbold uses artificial intelligence tools in the delivery of Services. This includes, without limitation:

  • (a) AI-assisted notetaking during meetings and consultations;
  • (b) AI-assisted code review, configuration analysis, and exception monitoring;
  • (c) AI-assisted communication drafting and summarization.

13.2 Data Protection. AI tool providers that Process Customer Personal Data are included in the Subprocessor list maintained at the URL referenced in Section 6.1 and are bound by data protection obligations no less protective than those in this DPA.

13.3 Acknowledgment. Customer acknowledges and consents to Buzzbold's use of AI tools as described in this Section 13 as a condition of receiving Services. This acknowledgment is integral to the delivery model and is not subject to opt-out for individual engagements.

13.4 Transparency. Upon request, Buzzbold provides Customer with a description of the AI tools used in connection with Customer's Services and their role in Processing Customer Personal Data.

14. Amendment and Replacement

14.1 Amendment. This DPA may be amended by mutual written agreement of the parties without requiring amendment of the Agreement.

14.2 Regulatory Updates. Buzzbold may update this DPA to reflect changes in Applicable Data Protection Law. Buzzbold provides Customer fourteen (14) days' prior written notice of material changes.

14.3 Customer Objection. If Customer objects to a material change under Section 14.2, the parties shall negotiate in good faith. If the parties cannot reach agreement within thirty (30) days, Customer may terminate the affected Statement of Work(s) upon written notice.

14.4 Replacement. This DPA may be replaced in its entirety by a successor addendum executed by both parties, which shall supersede this DPA upon its effective date.

14.5 Version Control. The current version of this DPA is published alongside the Agreement. Prior versions are retained for reference but are not operative.

15. Governing Law

This DPA is governed by the laws of the State of Missouri, without regard to choice-of-law principles, consistent with Section 13.4 of the Agreement.

16. Order of Precedence

In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to the Processing of Customer Personal Data. In the event of any conflict between this DPA and a Statement of Work, the more protective provision prevails.


This DPA is effective when incorporated by reference into the Agreement pursuant to Section 9.4 of the Principal Services Agreement, and applies to all Statements of Work that involve Processing of Customer Personal Data.


Buzzbold, LLC — Privacy and Information Use PolicyPrincipal Services AgreementSubprocessors