Data Processing Agreement
Last updated: August 9, 2026
This Data Processing Agreement ("DPA") supplements the $MembershipSoft Terms of Service and satisfies the requirements of GDPR Article 28(3) for processing personal data.
1. Parties & Roles
Data Controller: The Customer (Operator organization using $MembershipSoft).
Data Processor: $MembershipSoft Inc.
2. Subject Matter & Duration
The processing of member personal data for account provisioning, booking, billing, and CRM management for the duration of Customer's subscription.
3. Nature & Purpose
Processing includes collection, storage, and retrieval of member PII (name, email, phone) to provide platform CRM features and billing operations.
4. Technical & Organizational Measures (TOMs)
We implement industry-standard encryption (AES-256-GCM), TLS 1.3, multi-factor authentication, D1 tenant isolation, and granular RBAC to protect member data against unauthorized access.
5. Subprocessing
We engage reputable cloud providers (Cloudflare, Stripe) as subprocessors. We ensure all subprocessing agreements meet GDPR Art. 28(4) requirements and include mandatory security safeguards.
6. Processor Obligations
$MembershipSoft agrees to process data solely on customer instruction, maintain confidentiality, implement technical and organizational security measures (TOMs), assist with DSAR requests, and notify customer of personal data breaches within 72 hours.
7. Approved Subprocessors
| Subprocessor | Service | Location |
|---|---|---|
| Cloudflare | CDN, Workers, D1 Database | Global (Residency Options) |
| Stripe | Payment Processing | US/EU/Global |
| Resend | Transactional Email | US |
| PostHog | Telemetry (GDPR Scrubbed) | EU/US |