Effective Date: August 26, 2026 (supersedes the August 24, 2026 version)
This Data Processing Agreement (“DPA”) supplements the Terms of Service (“Agreement”) between F&D Ventures LLC, doing business as Tormano (“Processor,” “we,” “us”), and the entity agreeing to the Terms of Service (“Controller,” “Customer,” “you”). This DPA applies to the extent that Processor processes Personal Data on behalf of Controller in connection with the Service.
“Data Protection Laws” means all applicable laws relating to Personal Data processing, including GDPR, UK GDPR, Swiss Federal Act on Data Protection, and CCPA/CPRA. “Data Subject” means an identified or identifiable natural person. “Personal Data” means any information relating to a Data Subject processed by Processor on behalf of Controller. “Processing” means any operation on Personal Data. “Sub-processor” means any third party engaged by Processor to process Personal Data on behalf of Controller. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed, as defined in Article 4(12) of the GDPR. “Agreement” means the Tormano Terms of Service published at https://tormano.com/terms, into which this DPA is incorporated.
2.1 Roles. Controller determines the purposes and means of the processing. Processor processes Personal Data only on Controller’s documented instructions. This DPA, the Agreement, the configuration choices Controller makes in the Service and the instructions Controller gives through the Service or in writing to privacy@tormano.com together constitute Controller’s complete documented instructions.
2.2 Subject-matter. Processor’s provision of the Tormano customer relationship management service to Controller under the Agreement, and the processing of Personal Data necessary to do so.
2.3 Nature of the processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, hosting, backup, deduplication, indexing and search, synchronisation with services Controller connects, automated analysis and scoring where Controller enables it, disclosure to the sub-processors identified under Section 6, restriction, erasure and destruction — all by automated means, on Controller’s instruction.
2.4 Purpose of the processing. To provide, operate, secure, support and maintain the Service for Controller, including the features Controller chooses to enable. Processor does not process Controller’s Personal Data for its own purposes, for the purposes of any other customer, for advertising, or to train artificial intelligence models.
2.5 Categories of Data Subjects: Controller’s Authorized Users; and the contacts, donors, prospects, members, volunteers, event attendees, company and organization representatives, and correspondents whose data Controller enters into or connects to the Service.
2.6 Types of Personal Data: names; email addresses; telephone numbers; postal addresses and coordinates derived from them; job titles and employer or organization affiliations; lifecycle, membership and volunteer status; donation, payment, pledge and transaction history; the content of communications, including the bodies of messages in a mailbox Controller connects; notes, tasks, meetings and other activity records; documents Controller uploads; authentication credentials for services Controller connects; usage, audit and log records; and any other data Controller chooses to enter. Controller determines what it submits and is responsible for not submitting the categories the Agreement prohibits.
2.7 Duration: For the term of the Agreement, and thereafter for the 90-day post-termination retention window described in Section 11, and for any further period during which Processor is required by law to retain particular Personal Data.
2.8 Obligations and rights of the Controller are those set out in this DPA, in the Agreement and in Data Protection Laws, and include the right to give and vary instructions, the rights of audit in Section 8, the right to object to a new Sub-processor in Section 6, and the right to have Personal Data deleted or returned under Section 11.
Processor shall:
(a) Documented instructions. Process Personal Data only on Controller’s documented instructions, including with regard to transfers of Personal Data to a third country or an international organisation, unless Processor is required to process by Union or Member State law (or other applicable law) to which Processor is subject. Where such a legal requirement applies, Processor shall inform Controller of that legal requirement before processing, unless that law prohibits Processor from doing so on important grounds of public interest. Where Processor is prohibited from informing Controller, Processor shall challenge the prohibition and seek to disclose as much information as it lawfully can, as soon as it lawfully can.
(b) Confidentiality. Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide the Service.
(c) Security. Take all measures required pursuant to Article 32 of the GDPR, as described in Section 5.
(d) Sub-processors. Respect the conditions in Article 28(2) and (4) for engaging another processor, as set out in Section 6.
(e) Data Subject rights. Taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Controller’s obligation to respond to requests to exercise the rights in Chapter III of the GDPR, as set out in Section 7.
(f) Articles 32 to 36. Assist Controller in ensuring compliance with the obligations in Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to Processor.
(g) Deletion or return, at Controller’s choice. At the choice of Controller, delete or return all the Personal Data to Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law (or other applicable law) requires storage of the Personal Data. Controller may make that choice at any time up to the end of the retention window in Section 11.1; if Controller makes no choice, Processor deletes. Section 11 states how deletion operates in practice, including what happens to backup copies.
(h) Information and audits. Make available to Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by Controller or another auditor mandated by Controller, on the terms in Section 8.
(i) Unlawful instructions. Processor shall immediately inform Controller if, in Processor’s opinion, an instruction infringes the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection or other applicable Data Protection Laws. Processor may suspend performance of the instruction concerned, without liability for that suspension, until Controller confirms, withdraws or amends it.
Controller shall: (a) comply with Data Protection Laws; (b) ensure all necessary consents and legal bases; (c) provide written instructions; (d) not submit Prohibited Data; and (e) notify Processor of data protection concerns.
Technical and organizational measures including: TLS 1.2/1.3 encryption, Argon2 password hashing, JWT/RSA-256 authentication, CSRF protection, rate limiting, audit logging, XSS prevention, security headers, fail2ban, daily encrypted backups, Docker container isolation, firewall, and regular security assessments.
6.1 General authorization granted. Controller gives Processor general written authorisation to engage Sub-processors, in accordance with Article 28(2) of the GDPR. The current Sub-processor list, including the purpose, processing location and stated compliance posture for each, is maintained at tormano.com/subprocessors and forms part of this DPA.
6.2 Notice of changes. Processor shall give Controller at least 30 days’ notice before a new Sub-processor begins processing Personal Data, and shall give that notice actively: by email identifying the specific Sub-processor being added or replaced, sent to the email address of Controller’s account Owner and to every address Controller has asked Processor to add to the sub-processor notification list at privacy@tormano.com. Processor shall at the same time publish the change on the page named in 6.1, with a revised “Last Updated” date and a dated entry in the change history on that page, so that Controller can confirm what changed and when. Publication alone is not the notice, and Processor does not require Controller to monitor that page in order to receive one. Controller may add an address to the notification list, or remove one, at any time by writing to privacy@tormano.com. This Section governs the addition or replacement of a Sub-processor; it does not require fresh notice for a Sub-processor already named on that page.
6.3 30-day objection period; Controller may object to a new sub-processor by providing written notice to Processor within 30 days of receiving notification. If Processor cannot reasonably accommodate the objection, Controller may terminate the affected portion of the Service by providing written notice.
6.4 Sub-processor obligations. Where Processor engages a Sub-processor, Processor shall impose on that Sub-processor, by contract, data protection obligations that are no less protective than those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures such that the processing meets the requirements of the GDPR. Processor does not represent that this obligation is presently discharged in respect of every Sub-processor already engaged, and states the current position for each openly on the page named in 6.1 — see 6.6. Section 6.5 applies whether or not it is.
6.5 Processor remains fully liable. Where a Sub-processor fails to fulfil its data protection obligations, Processor remains fully liable to Controller for the performance of that Sub-processor’s obligations, in accordance with Article 28(4) of the GDPR. Nothing in this Section limits Section 14.
6.6 What the sub-processor list represents. The list at tormano.com/subprocessors is contractually authoritative as to the identity, purpose and processing location of each Sub-processor. The compliance information shown for each Sub-processor is that provider’s own published claim, repeated so Controller can evaluate it; Processor does not represent that it has independently verified or holds a copy of any Sub-processor’s audit report except where that page says so. That page states the current position on data processing terms with each Sub-processor, and Processor will not describe those terms as executed unless they are.
7.1 Processor notifies Controller promptly.
7.2 Processor assists with technical means for export, correction, or deletion.
7.3 Processor will not decide a request. Processor will not respond substantively to a Data Subject request about Controller’s Personal Data, and will not grant or refuse it, unless Controller instructs Processor to do so. Where a Data Subject contacts Processor directly, Processor may tell that person that Processor holds the data as a processor for Controller and cannot act on the request itself, and will then refer the person to Controller or forward the request to Controller. Telling someone where to go is not a substantive response and is not restricted by this Section.
8.1 Information on request. Processor shall make available to Controller, on written request and at least once in any 12-month period (and additionally following a Personal Data Breach affecting Controller, where a supervisory authority requires it, or where Controller reasonably requires it to discharge its own obligations, including those in Section 13.7), the information necessary to demonstrate compliance with Article 28 of the GDPR, including a description of the technical and organisational measures in Section 5, the current sub-processor list, and Processor’s responses to a reasonable security questionnaire.
8.2 Audits and inspections. Where the information provided under 8.1 is not sufficient, Controller or an auditor mandated by Controller may audit Processor’s compliance with this DPA, on at least 30 days’ written notice, during business hours, at Controller’s expense, subject to reasonable confidentiality undertakings and without unreasonable disruption to the Service. Processor shall allow for and contribute to such audits, including inspections. Processor operates no datacenter of its own: Personal Data is hosted on infrastructure operated by the hosting Sub-processor identified at tormano.com/subprocessors, and Processor cannot grant physical access to those facilities. For that element, Processor shall provide the information it holds and shall use reasonable efforts to obtain from that Sub-processor such further information or assurances as Controller reasonably requires, and shall tell Controller plainly if it cannot obtain them.
8.3 Remediation. Processor shall promptly remediate, at its own expense, any non-compliance with this DPA identified by an audit, and shall report completion to Controller.
9.1 Notification. Processor shall notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller’s Personal Data. Processor becomes aware at the point it has a reasonable degree of certainty that a security incident has occurred that led to Personal Data being compromised; a short period of investigation to establish that does not postpone notification once it is established. Processor shall not delay an initial notification in order to complete its investigation.
9.2 How and to whom notice is given. Processor shall notify by email to the data-protection or security contact Controller has notified to Processor in writing at privacy@tormano.com, and in every case to the email address of Controller’s account Owner. It is Controller’s responsibility to keep those addresses current. Processor does not undertake to display an in-Service banner, because it operates no such mechanism today and will not contract to send something it cannot send; email under this Section is the notice. Processor’s own contact point for a breach notification, and for any question about one, is privacy@tormano.com.
9.3 Contents of the notification. The notification shall describe, to the extent known: the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects and of Personal Data records concerned; the name and contact details of Processor’s contact point; the likely consequences; and the measures taken or proposed to address the breach and to mitigate its possible adverse effects. Where and insofar as it is not possible to provide that information at the same time, Processor shall provide it in phases without further undue delay.
9.4 Cooperation and records. Processor shall cooperate with Controller and take reasonable steps as directed by Controller to assist in the investigation, mitigation and remediation of the breach, and shall provide Controller with the information Controller reasonably needs to meet its own obligations under Articles 33 and 34 of the GDPR and under applicable breach-notification laws. Processor shall document the facts relating to the breach, its effects and the remedial action taken, and make that documentation available to Controller on request.
9.5 No admission. Processor’s notification is not, and shall not be construed as, an acknowledgement of fault or liability.
10.1 Data may be transferred to and processed in the United States.
10.2 Transfer mechanisms: Standard Contractual Clauses (Decision 2021/914) and supplementary technical and organizational measures.
10.3 SCCs Module Two details: Clause 9(a) Option 2 general authorization; Clause 17 Option 1 Ireland governing law; Clause 18(b) Ireland courts.
10.4 UK International Data Transfer Addendum (version B1.0) is incorporated for transfers subject to the UK GDPR, with the Standard Contractual Clauses in 10.2 as its Approved EU SCCs.
10.5 Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses in 10.2 apply with the following adaptations: the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to a Member State or to the GDPR are read as references to Switzerland and to the Swiss Federal Act on Data Protection respectively; and the Clauses also protect the data of legal entities until the Swiss Act ceases to extend to them.
10.6 No Data Privacy Framework reliance. Processor does not rely on the EU-U.S. Data Privacy Framework, the UK Extension to it, or the Swiss-U.S. Data Privacy Framework as a transfer mechanism under this DPA. The mechanisms in 10.2 to 10.5 are the mechanisms relied on.
11.1 90-day retention window post-termination, during which Customer Data remains available for export. Controller may instead require return or earlier deletion at any time during that window, under Section 3(g).
11.2 Deletion at the end of the 90-day retention window (unless legally required to retain). Personal Data that Processor is required by law to retain is retained only for the period and purpose the law requires, remains subject to Section 5, and is deleted when that requirement ends.
11.3 Written certification of deletion. On written request, Processor shall provide Controller with a written certification of deletion. The certification confirms deletion from Processor’s live production systems, and states on its face that encrypted off-site backup copies may still exist. Processor does not certify that no copy exists anywhere, because that would not be true of any system that keeps backups, and Processor will not issue a certification worded as though it were.
11.4 Backups. Personal Data deleted from live systems remains in Processor’s encrypted, off-site backups until those backups age out. There is more than one rotation and Processor states all of them rather than the shortest: daily database backups and the transaction-log archive are deleted after 35 days; a monthly database snapshot is taken on the first of each month and retained for 12 months. Deleted Personal Data can therefore persist in backup storage for up to approximately 13 months. Encrypted configuration archives and archived application logs are currently retained indefinitely; those hold operational data such as IP addresses and request metadata rather than Controller’s records. Backup copies are encrypted, are not accessible from the Service, are not used for any purpose other than restoring the Service after a failure, and remain subject to the security measures in Section 5 and to this DPA for as long as they exist. If a backup is restored into live systems, Processor shall re-apply, without undue delay, any deletion it had performed before that backup was taken, using its own records of those deletions. Where Controller requires deletion within a shorter period than these rotations, Controller should say so in its request and Processor will tell Controller whether and how that can be achieved.
12.1 Processing per Article 28 GDPR; assist with DPIAs (Art. 35) and prior consultation (Art. 36).
12.2 Data protection contact: privacy@tormano.com.
13.1 Roles. For Personal Data that is personal information within the meaning of the California Consumer Privacy Act as amended by the CPRA (“CCPA”), Controller is the “business” and Processor is a “service provider”. Terms used in this Section have the meanings given to them in the CCPA and its implementing regulations. This Section is the parties’ agreement for the purposes of Civil Code section 1798.140(ag)(1) and 11 CCR section 7051.
13.2 Limited and specified purposes. Controller discloses personal information to Processor only for the limited and specified business purposes set out in Sections 2.2 to 2.4 of this DPA — providing, operating, securing, supporting and maintaining the Tormano customer relationship management service for Controller, by the operations listed in Section 2.3. Those purposes are specified so that Processor cannot substitute a purpose of its own, and the parties agree they are not stated in generic terms.
13.3 No sale, no sharing. Processor shall not sell personal information and shall not share it for cross-context behavioural advertising, as those terms are defined by the CCPA.
13.4 No retention, use or disclosure for any other purpose. Processor shall not retain, use or disclose the personal information for any purpose other than the business purposes specified in 13.2, including for a commercial purpose other than those business purposes, or as otherwise permitted by the CCPA. Processor shall not retain, use or disclose the personal information outside the direct business relationship between Processor and Controller. Processor shall not use the personal information to build or improve a profile of any individual for any purpose other than performing the Service for Controller, and shall not use it to train artificial intelligence models.
13.5 No combining. Processor shall not combine the personal information it receives from or on behalf of Controller with personal information it receives from or on behalf of another person, or collects from its own interaction with a consumer, except as 11 CCR section 7050(a) permits — namely to perform the services specified in this DPA on Controller’s behalf, to prevent, detect or investigate security incidents, to debug and repair errors, to comply with law, or for the internal use permitted by section 7050(a)(5). This restriction is the one imposed by 11 CCR section 7051(a)(5).
13.6 Same level of privacy protection. Processor shall comply with all applicable obligations the CCPA places on a service provider and shall provide the same level of privacy protection as the CCPA requires of a business with respect to the personal information it processes for Controller.
13.7 Controller’s right to monitor and to stop unauthorised use. Controller has the right to take reasonable and appropriate steps to ensure that Processor uses the personal information in a manner consistent with Controller’s obligations under the CCPA. The rights in Section 8 are one way Controller may exercise it. On notice from Controller of an unauthorised use of personal information, Controller has the right to take reasonable and appropriate steps to stop and remediate that use, and Processor shall cooperate with those steps.
13.8 Notification if Processor can no longer comply. Processor shall notify Controller if Processor determines that it can no longer meet its obligations under the CCPA, as required by 11 CCR section 7051(a)(8). Notice shall be given without undue delay after that determination, by the method in Section 9.2. No fixed hour or day figure is stated here because the regulation states none, and a self-imposed deadline in a contract is an additional way to be in breach rather than an additional protection for Controller.
13.9 Sub-service providers. Where Processor engages another person to assist it in processing personal information for Controller, Processor shall notify Controller as provided in Section 6 and shall enter into a written contract with that person that complies with 11 CCR section 7051(c) and imposes the obligations in this Section 13. Processor remains liable to Controller as provided in Section 6.5.
13.10 Assistance with consumer requests. Processor shall assist Controller in responding to verifiable consumer requests to know, delete, correct, opt out and limit, by the technical means described in Section 7 and within the timescales Controller requires to meet its own deadlines. Where a consumer submits such a request directly to Processor, Processor shall inform the consumer that it cannot act on the request in its capacity as service provider and shall either refer the consumer to Controller or forward the request to Controller.
13.11 Deletion and correction downstream. On Controller’s instruction to delete or correct personal information in response to a consumer request, Processor shall delete or correct it in its own systems and shall notify any sub-service provider engaged under 13.9 to do the same, in each case subject to the exceptions the CCPA permits and to the backup position stated in Section 11.4.
13.12 Certification. Processor certifies that it understands the restrictions in this Section 13 and will comply with them.
13.13 Other U.S. state privacy laws. Where Controller is subject to the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, the Montana Consumer Data Privacy Act or a comparable state law, Processor acts as Controller’s “processor” under that law, and this DPA constitutes the contract that law requires between a controller and a processor. Sections 3, 6, 7, 8, 9 and 11 satisfy the duties of confidentiality, sub-processor engagement and flow-down, assistance with consumer rights requests, audit or assessment, breach notification and deletion or return that those laws impose.
14.1 Limitation of Liability. Each party’s total aggregate liability under or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement (Terms of Service). For the avoidance of doubt, the liability caps, consequential damages exclusions, and other limitations in the Agreement apply to all claims arising under this DPA, including claims related to data breaches, unauthorized processing, or failure to comply with Data Protection Laws.
14.2 Controller Liability. Controller shall be solely liable for the lawfulness of its processing instructions and the accuracy, quality, and legality of Personal Data provided to Processor. Processor shall have no liability for any claim arising from processing performed in accordance with Controller’s documented instructions.
This DPA remains in effect for the duration of the Agreement and as long as Processor retains any Personal Data. Termination of the Agreement does not release obligations regarding retained data.
DPA prevails over Agreement for Personal Data processing. SCCs prevail over DPA.
F&D Ventures LLC
Data Protection Contact: privacy@tormano.com
Website: https://tormano.com