This Data Processing Addendum (including any attachments hereto, the “Addendum”) forms part of and is subject to the terms and conditions of the Terms of Service available at inspired.com/terms (the “Agreement”) by and between Inspired Member, Inc., a Delaware corporation (“Inspired”), and the person or entity identified as the customer under the Agreement (“Client”). This Addendum is published at inspired.com/dpa and takes effect automatically upon the effective date of the Agreement without requiring separate execution by either party. It is incorporated into the Agreement by reference.
Order of Precedence. In the event of any conflict or inconsistency among the components of the Agreement, the following order of precedence applies (from highest to lowest): (1) Service Agreement; (2) Ancillary Agreements; (3) Terms of Service; (4) this Addendum; (5) Documentation; and (6) Privacy Policy. Capitalized terms not expressly defined herein have the meanings assigned in the Agreement.
1. Subject Matter and Duration
(a) Subject Matter. This Addendum reflects the parties’ commitment to abide by Data Protection Laws concerning the Processing of Client Personal Data in connection with Client’s use of the Services under the Agreement.
(b) Duration and Survival. This Addendum is effective as of the effective date of the Agreement and shall remain in effect until termination or expiration of the Agreement. Inspired will Process Client Personal Data until the relationship terminates as specified in the Agreement. Sections that by their nature should survive termination (including Sections on Limitation of Liability, Data Deletion, and Client Obligations) shall survive.
2. Definitions
For purposes of this Addendum, the following terms apply:
(a) “Data Protection Laws” means the applicable data privacy, data protection, and cybersecurity laws, rules, and regulations to which Client Personal Data is subject. Data Protection Laws may include, but are not limited to: the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA”); the Virginia Consumer Data Protection Act (“VCDPA”); the Colorado Privacy Act (“CPA”); the Connecticut Data Privacy Act (“CTDPA”); the Utah Consumer Privacy Act (“UCPA”); other applicable U.S. state privacy laws; Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation including Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (as amended by Law 25); the General Data Protection Regulation (EU) 2016/679 (“GDPR”); and the United Kingdom General Data Protection Regulation as defined by the UK Data Protection Act 2018 (“UK GDPR”).
(b) “Personal Data” has the meaning assigned to the term “personal data,” “personal information,” or equivalent term under applicable Data Protection Laws.
(c) “Process” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
(d) “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data attributable to Inspired’s systems.
(e) “Services” means the services that Inspired performs for Client under the Agreement.
(f) “Subprocessor” means Inspired’s authorized vendors and third-party service providers that Process Client Personal Data on Inspired’s behalf.
(g) “Client Personal Data” means Personal Data Processed by Inspired on behalf of Client in connection with the Services. Client Personal Data does not include Aggregated and/or De-Identified Data (as defined in Section 3(k)) or Account Data (as defined in Section 10).
3. Processing Terms for Client Personal Data
(a) Documented Instructions. Inspired shall Process Client Personal Data to provide the Services in accordance with the Agreement, this Addendum, and any documented instructions mutually agreed upon by the parties. Inspired will, unless legally prohibited from doing so, inform Client in writing if it reasonably believes that there is a conflict between Client’s instructions and applicable law. Notwithstanding the foregoing, Inspired shall have no liability for Processing Client Personal Data in accordance with Client’s documented instructions.
(b) Authorization to Use Subprocessors. To the extent necessary to fulfill Inspired’s obligations under the Agreement, Client hereby provides general authorization for Inspired to engage Subprocessors to Process Client Personal Data.
(c) Subprocessor Compliance. Inspired shall: (i) enter into a written agreement with each Subprocessor that imposes data protection obligations consistent with this Addendum; and (ii) remain responsible to Client for its Subprocessors’ failure to perform their obligations with respect to the Processing of Client Personal Data.
(d) Right to Object to Subprocessors. Where required by Data Protection Laws, Inspired will notify Client via email prior to engaging any new Subprocessor that Processes Client Personal Data and allow Client ten (10) days to object. If Client raises a legitimate, documented objection within such period, the parties will work together in good faith to resolve the grounds for the objection. If the parties are unable to resolve the objection within thirty (30) days, Client’s sole remedy shall be to terminate the affected Services upon written notice to Inspired.
(e) Confidentiality. Any person authorized to Process Client Personal Data must be bound by contractual confidentiality obligations or be under an appropriate statutory obligation of confidentiality.
(f) Data Subject Requests. Where required by Data Protection Laws, Inspired agrees to provide commercially reasonable assistance and comply with reasonable instructions from Client related to requests from individuals exercising their rights in Client Personal Data. Inspired may charge Client a reasonable fee for assistance beyond commercially reasonable efforts. Client shall be solely responsible for responding to data subject requests.
(g) CCPA Obligations. To the extent the CCPA applies to Client Personal Data, and unless otherwise permitted by the CCPA, Inspired shall not: (i) retain, use, or disclose Client Personal Data for any purpose other than the specific purpose of performing the Services, or as otherwise permitted by the CCPA; (ii) retain, use, or disclose Client Personal Data for a Commercial Purpose other than providing the Services; (iii) retain, use, or disclose Client Personal Data outside of the direct business relationship between Inspired and Client; or (iv) Sell or Share Client Personal Data. Inspired hereby certifies that it understands the restrictions on its use of Client Personal Data imposed by the CCPA and this Addendum and agrees to comply with those restrictions. Inspired shall notify Client no later than five (5) business days after it makes a determination that it can no longer meet its obligations under the CCPA.
(h) Data Protection Impact Assessments. Where required by Data Protection Laws, Inspired agrees to provide reasonable assistance, at Client’s expense, to Client where the type of Processing performed by Inspired requires a data protection impact assessment and/or prior consultation with the relevant data protection authorities.
(i) Demonstrable Compliance. At Client’s expense, Inspired agrees to provide information reasonably necessary to demonstrate compliance with this Addendum upon Client’s reasonable written request, subject to the limitations set forth in Section 7 (Audits).
(j) Service Optimization. Where permitted by Data Protection Laws, Inspired may Process Client Personal Data: (i) for its internal uses to build or improve the quality of its Services; (ii) to detect Security Incidents; (iii) to protect against fraudulent or illegal activity; and (iv) to comply with applicable legal obligations.
(k) Aggregation and De-Identification. Inspired may: (i) compile aggregated and/or de-identified information in connection with providing the Services, provided that such information cannot reasonably be used to identify Client or any data subject to whom Client Personal Data relates (“Aggregated and/or De-Identified Data”); and (ii) use Aggregated and/or De-Identified Data for any lawful business purpose without restriction, including analytics, benchmarking, product development, and service improvement. Inspired will maintain such data in de-identified form and will not attempt to re-identify any individual from such data.
4. Information Security Program
(a) Security Measures. Inspired shall implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Client Personal Data from unauthorized access, use, disclosure, alteration, or destruction. Inspired determines the specific security measures in its sole discretion, taking into account the nature, scope, context, and purposes of Processing, as well as the risks to data subjects.
(b) Updates to Security Measures. Inspired may update or modify its security measures from time to time, provided that such updates do not materially diminish the overall level of protection afforded to Client Personal Data.
5. Security Incidents
(a) Notice. Upon becoming aware of a confirmed Security Incident, Inspired agrees to provide written notice without undue delay and within the timeframe required under applicable Data Protection Laws to Client. Where possible, such notice will include all available details reasonably required under Data Protection Laws for Client to comply with its own notification obligations to regulatory authorities or affected individuals.
(b) Cooperation. Inspired will take commercially reasonable steps to contain and remediate any confirmed Security Incident. Inspired’s obligations under this Section do not extend to incidents that are caused by Client or Client’s users.
(c) Client Notification Responsibilities. Client is solely responsible for determining whether a Security Incident triggers any notification obligations under applicable Data Protection Laws and for making any required notifications to supervisory authorities, regulators, or data subjects.
6. Cross-Border Transfers of Client Personal Data
(a) General Authorization. Client authorizes Inspired and its Subprocessors to transfer Client Personal Data across international borders, including to the United States, for Processing in connection with the Services.
(b) Transfers of Client Personal Data Originating in the EEA, Switzerland, and/or the UK. Notwithstanding Section 6(a), Client shall not cause Inspired to Process Client Personal Data originating in the European Economic Area (“EEA”), Switzerland, and/or the United Kingdom unless the transfer of such Client Personal Data is subject to a data transfer mechanism recognized under applicable Data Protection Laws as a legitimate basis for the transfer of Personal Data outside the EEA, Switzerland, or the UK (as applicable). If any transfer between Client and Inspired requires execution of the European Commission’s Standard Contractual Clauses (“SCCs”) or the UK International Data Transfer Addendum (“UK IDTA”) in order to comply with Data Protection Laws, the parties shall complete all relevant details in, and execute, such clauses and take all other actions required to legitimize the transfer.
7. Audits
(a) Client Audit Right. Where Data Protection Laws afford Client an audit right, Client (or its appointed representative) may carry out an audit of Inspired’s policies, procedures, and records relevant to the Processing of Client Personal Data, subject to the following conditions:
(i) Any audit must be conducted during Inspired’s regular business hours;
(ii) Client must provide at least thirty (30) days’ prior written notice;
(iii) The audit must be carried out in a manner that prevents unnecessary disruption to Inspired’s operations;
(iv) The audit shall be subject to reasonable confidentiality procedures;
(v) Any audit shall be limited to once per twelve (12) month period, unless required more frequently by a supervisory authority with proper jurisdiction; and
(vi) All costs and expenses associated with any audit shall be borne solely by Client.
(b) Alternative Compliance Demonstration. In lieu of an on-site audit, Inspired may, in its sole discretion, provide Client with a copy of any relevant third-party audit report, certification, or summary of its security practices that reasonably demonstrates compliance with this Addendum.
8. Data Deletion
(a) Deletion Upon Termination. Upon expiration or termination of the Agreement, Inspired will delete all Client Personal Data within a commercially reasonable period, except: (i) backup or archival copies, which shall be deleted in accordance with Inspired’s standard data retention schedule; and (ii) where Inspired is required to retain copies under applicable laws or regulatory requirements, in which case Inspired will isolate and protect such Client Personal Data from any further Processing except to the extent required by applicable law.
(b) Data Retrieval. Client may request return of Client Personal Data prior to termination through the functionality made available through the Services. Inspired is not obligated to maintain Client Personal Data after the termination of the Agreement except as set forth in this Section 8.
9. Client Obligations and Representations
(a) Client Representations. Client represents and warrants that: (i) it has complied and will continue to comply with all applicable Data Protection Laws; (ii) it has provided data subjects whose Client Personal Data will be Processed in connection with the Agreement with a privacy notice or similar document that clearly and accurately describes Client’s practices with respect to the Processing of Personal Data; (iii) it has obtained and will obtain and continue to have all necessary rights, lawful bases, authorizations, consents, and licenses for the Processing of Client Personal Data as contemplated by the Agreement; (iv) Inspired’s Processing of Client Personal Data in accordance with the Agreement will not violate Data Protection Laws or cause a breach of any agreement or obligation between Client and any third party; and (v) Client’s Processing instructions to Inspired will at all times comply with applicable Data Protection Laws.
(b) Client Responsibility. Client is solely responsible for: (i) the accuracy, quality, and legality of Client Personal Data and the means by which Client acquired such data; (ii) ensuring that it has an appropriate legal basis for each Processing activity it instructs Inspired to perform; and (iii) responding to requests from data subjects. Inspired shall have no liability arising from Client’s failure to comply with its obligations under this Section 9 or applicable Data Protection Laws.
10. Account Data
Client agrees that Inspired may Process Account Data in accordance with Inspired’s then-current Privacy Policy. “Account Data” means Personal Data relating to an authorized user’s relationship with Inspired, including login credentials, usage data, and related information Processed in connection with Client’s use of the Services. Account Data is not Client Personal Data, and the terms of this Addendum do not apply to Account Data.
11. Processing Details
Processing Details. The subject matter, duration, nature and purpose of Processing, the types of Client Personal Data, and the categories of Data Subjects are set out in Exhibit A.
12. Limitation of Liability
(a) EXCLUSION OF CONSEQUENTIAL DAMAGES. IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, EXEMPLARY, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM OR IN CONNECTION WITH THIS ADDENDUM OR THE SERVICES, WHETHER IN TORT, CONTRACT, NEGLIGENCE, STRICT LIABILITY, OR OTHERWISE, EVEN IF INFORMED OF THE POSSIBILITY OF SUCH DAMAGES IN ADVANCE.
(b) CAP ON LIABILITY. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY’S AGGREGATE LIABILITY UNDER THIS ADDENDUM SHALL NOT EXCEED THE AMOUNTS ACTUALLY PAID BY CLIENT TO INSPIRED IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. IF NO FEES HAVE BEEN PAID, INSPIRED’S TOTAL LIABILITY SHALL NOT EXCEED ONE HUNDRED DOLLARS ($100.00).
(c) Application. This Section 12 applies to the maximum extent permitted by applicable law and is in addition to, and not in limitation of, any limitation of liability set forth in the Agreement. In the event of conflict between this Section and the Agreement’s limitation of liability, the Agreement shall control.
13. Miscellaneous
(a) Entire Agreement. This Addendum, together with the Agreement, constitutes the entire agreement between the parties regarding the subject matter hereof. Except as modified by this Addendum, the Agreement remains in full force and effect.
(b) Governing Law. This Addendum shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws principles, consistent with the Agreement.
(c) Amendments. Inspired may update this Addendum from time to time to reflect changes in Data Protection Laws or Inspired’s data processing practices. Material changes will be communicated to Client through the Services or via email.
(d) Severability. If any provision of this Addendum is held to be invalid or unenforceable, such provision shall be modified to the minimum extent necessary to make it valid and enforceable, and the remaining provisions shall remain in full force and effect.
(e) Contact. Questions regarding this Addendum should be directed to: legal@inspired.com.
Exhibit A — Details of Processing
Subject Matter. Provision of the Inspired donor-sponsored gifting platform and the Inspired-hosted gift experience pursuant to the Agreement.
Duration. The term of the Agreement, plus any retention period required by law or described in Section 8.
Nature and Purpose. Determining eligibility for and attribution of Donation Gifts; delivering the Inspired Experience; providing reporting and analytics to Client regarding campaign performance; fraud prevention; legal and charitable-compliance obligations.
Categories of Data Subjects. End Users of Client (and of Client’s Merchants) who become eligible for or redeem a Donation Gift; Client and Merchant personnel (business contacts).
Categories of Personal Data. Transaction or event identifiers, order identifiers, and campaign/attribution identifiers; email address (where transmitted to deliver a gift or provided by the End User to Inspired); cause selection and communication preferences; device and usage data (IP address, browser and device information, pages viewed, interaction data, access times). Payment information for voluntary donations is collected and processed directly by the third-party payment processor; Inspired does not receive or store payment card data.
Sensitive/Special Category Data. None. Inspired does not collect Social Security numbers, financial account numbers, government identification numbers, health data, biometric identifiers, or precise geolocation.
Frequency of Transfer. Continuous, for the duration of the Agreement.