Data Processing Agreement (DPA)
Last updated: August 9, 2026
This Data Processing Agreement ("DPA") supplements the MembershipSoft Terms of Service and satisfies the requirements of GDPR Article 28(3) for processing personal data.
1. Parties & Roles
Data Controller: The Customer (Operator organization using MembershipSoft).
Data Processor: MembershipSoft Inc.
2. Subject Matter & Duration
The processing of member personal data for account provisioning, booking, billing, and CRM management for the duration of Customer's subscription.
3. Nature & Purpose of Processing
Hosting, database storage, message dispatch, payment collection, and operational management of customer CRM records.
4. Categories of Data Subjects
Customer staff operators, end-user members, subscribers, and registered participants.
5. Categories of Personal Data
Name, email address, billing records, attendance logs, phone number, and custom CRM field data.
6. Processor Obligations
MembershipSoft agrees to process data solely on customer instruction, maintain confidentiality, implement technical and organizational security measures (TOMs), assist with DSAR requests, and notify customer of personal data breaches within 72 hours.
7. Approved Subprocessors
| Subprocessor | Country | Purpose | Privacy Notice / DPA |
|---|---|---|---|
| Cloudflare, Inc. | USA | Edge CDN, D1 database, Workers, R2 storage | cloudflare.com/privacypolicy |
| Stripe, Inc. | USA | Payment processing (tokenized card data) | stripe.com/privacy |
| Resend, Inc. | USA | Transactional email delivery | resend.com/legal |
| Telnyx LLC | USA | SMS / VoIP communications | telnyx.com/privacy |
| PostHog, Inc. | USA | Product analytics (consent-gated) | posthog.com/privacy |
| Plausible Analytics | EU (Estonia) | Aggregate pageview analytics (cookieless) | plausible.io/privacy |
8. Technical & Organizational Measures (TOMs)
We enforce TLS 1.3 in transit, AES-256 field encryption at rest, multi-tenant D1 isolation, role-based access control (RBAC), and automated vulnerability scans.
9. International Data Transfers
Transfers outside the EEA/UK rely upon EU Standard Contractual Clauses (SCCs Module 2: Controller to Processor) and UK Addendum.
10. Term & Data Deletion
Upon subscription termination, Customer member PII is deleted or anonymized within 30 days of written request in accordance with GDPR Art. 17.