Data Processing Addendum

Last Updated: September 2, 2026

This Data Processing Addendum (“DPA”) supplements and forms part of the terms and conditions, master services agreement, order form, or other agreement governing Customer’s use of the Services (the “Agreement”) between Fundraise Up Inc., a Delaware corporation, and its Affiliates, as applicable (“Provider”), and the customer that enters into the Agreement (“Customer”). This DPA applies to Provider’s Processing of Customer Personal Data in connection with the Services. Capitalized terms not defined in this DPA have the meanings given in the Agreement. If Customer accepts the Agreement by clicking to accept, executing an Order Form, or using the Services, Customer also accepts this DPA. This DPA does not supersede, amend, or replace any data processing agreement, data protection addendum, or other written agreement relating to the Processing of Customer Personal Data that Customer and Provider have executed in writing. Where such an executed written agreement exists, it remains in full force and effect and governs to the extent of any conflict with this DPA.

1. Definitions

“Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where “control” means direct or indirect ownership or control of more than fifty percent (50%) of the voting interests of the subject entity.

“Applicable Data Protection Laws” means all privacy, data protection, and data security laws and regulations applicable to Provider’s Processing of Customer Personal Data under the Agreement, including, as applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, Australian Privacy Act 1988 (Cth), Canadian Privacy Laws, and U.S. State Privacy Laws.

“Australian Privacy Principles” means the Australian Privacy Principles set out in the Australian Privacy Act 1988 (Cth).

Canadian Privacy Laws” means, collectively, all relevant and applicable private sector Canadian data privacy laws, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”), Alberta’s Personal Information Protection Act (“AB PIPA”), British Columbia’s Personal Information Protection Act (“BC PIPA”) and Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25 (“QC Act”).

“Customer Data” means data, content, records, files, and other information submitted to the Services by or on behalf of Customer, or otherwise Processed by Provider on behalf of Customer in connection with the Services.

“Customer Personal Data” means Personal Data contained in Customer Data that Provider Processes on behalf of Customer in connection with the Services.

“Usage Data” means data about how Customer and its users interact with and use the Services, including technical, performance, and operational data generated by or derived from use of the Services, such as feature usage patterns, system logs, performance metrics, and aggregated or statistical information about Service utilization, that does not constitute Customer Personal Data.

“EEA” means the European Economic Area.

“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council.

“GDPR” means the EU GDPR and, as applicable, the UK GDPR.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Provider.

“Restricted Transfer” means a transfer of Customer Personal Data from the EEA, Switzerland, or the United Kingdom to a country or recipient that is not subject to an adequacy decision or other lawful transfer mechanism under Applicable Data Protection Laws.

“SCCs” means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914, as amended, replaced, or superseded from time to time.

“Subprocessor” means any third party engaged by Provider or a Provider Affiliate to Process Customer Personal Data on behalf of Customer in connection with the Services.

“Subprocessor List” means Provider’s then-current list of Subprocessors made available at https://fundraiseup.com/subprocessors or another successor URL identified by Provider.

“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the United Kingdom Information Commissioner under section 119A(1) of the Data Protection Act 2018, as amended, replaced, or superseded from time to time.

“UK GDPR” means the EU GDPR as retained in United Kingdom law by section 3 of the European Union (Withdrawal) Act 2018, as amended.

“U.S. State Privacy Laws” means U.S. state privacy laws applicable to Provider’s Processing of Customer Personal Data under the Agreement, including, as applicable, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.

The terms “business,” “business purpose,” “controller,” “data subject,” “personal data,” “personal information,” “processor,” “processing,” “sell,” “share,” “service provider,” “supervisory authority,” and similar terms have the meanings given to them under Applicable Data Protection Laws. If a term has materially different meanings under different Applicable Data Protection Laws, the meaning that applies to the relevant Processing will apply.

2. Roles and Scope

2.1 Roles. For purposes of this DPA, Customer is the controller or business, and Provider is the processor or service provider, with respect to Customer Personal Data. If Customer acts as a processor on behalf of another controller, Customer represents that it is authorized to instruct Provider to Process Customer Personal Data as a Subprocessor.

2.2 Customer Responsibilities. Customer is responsible for providing all notices, obtaining all consents and authorizations, establishing all legal bases, and satisfying all other requirements necessary for Provider to Process Customer Personal Data in accordance with the Agreement, this DPA, and Applicable Data Protection Laws. Customer will not submit Customer Personal Data to the Services unless Customer has the right to do so. To the extent the Services use cookies or similar technologies on Customer’s website, Customer is responsible for providing appropriate notice to data subjects and, where required by Applicable Data Protection Laws, obtaining valid consent prior to such use of cookies or similar technologies.

2.3 Instructions. Customer instructs Provider to Process Customer Personal Data only as necessary to provide, secure, support, maintain, and improve the Services using Usage Data and Deidentified Data; comply with the Agreement and this DPA; comply with Customer’s documented instructions; and comply with Applicable Data Protection Laws. Provider will not Process Customer Personal Data for any other purpose except as permitted by Applicable Data Protection Laws or this DPA.

2.4 Unlawful Instructions. If Provider reasonably determines that an instruction from Customer violates Applicable Data Protection Laws, Provider will notify Customer unless prohibited by law. Provider may suspend the affected Processing until Customer modifies or confirms the instruction in a manner that Provider reasonably determines is lawful.

3. Processing Details

3.1 Processing Description. The subject matter, duration, nature, and purpose of Processing, the categories of Customer Personal Data, and the categories of data subjects are described in Annex I.

3.2 Changes to Processing Details. Customer will notify Provider if the description in Annex I is inaccurate for Customer’s use of the Services. Provider may update Annex I from time to time to reflect changes to the Services, provided that the update does not materially reduce Provider’s obligations under this DPA.

3.3 Deidentified and Usage Data. Notwithstanding anything to the contrary in this DPA, Provider may collect, generate, use, and disclose Usage Data and data derived from Customer Personal Data that has been aggregated, deidentified, or otherwise rendered reasonably incapable of directly identifying Customer or any individual (“Deidentified Data”) for Provider’s lawful business purposes, including analytics, benchmarking, security, service improvement, machine learning and artificial intelligence model development and improvement, and operational purposes, provided that Provider does not attempt to reidentify any individual from such Deidentified Data. Customer acknowledges that Provider is a Controller or business for such processing.

4. Provider Personnel

4.1 Confidentiality and Access Controls. Provider will ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as necessary to perform their duties in connection with the Services.

4.2 Reliability. Provider will take commercially reasonable steps designed to ensure the reliability of personnel who may have access to Customer Personal Data.

5. Security

5.1 Security measures. Taking into account commercially reasonable industry standards, implementation costs, the nature, scope, context, and purposes of Processing, and the risks to individuals, Provider will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Personal Data Breaches. Those measures are described in Annex II.

5.2 Updates. Provider may update its technical and organizational measures from time to time, provided that such updates do not materially reduce the overall level of protection for Customer Personal Data.

5.3 Government and law enforcement requests. If Provider receives a legally binding request from a governmental, regulatory, or law enforcement authority for access to or disclosure of Customer Personal Data, Provider will, to the extent legally permitted, notify Customer, make a good-faith effort to determine whether the request is legally valid, and disclose only the minimum Customer Personal Data that Provider determines is required to comply with the request. Provider may challenge or seek to limit any governmental request where Provider reasonably determines there are grounds to do so.

6. Subprocessors

6.1 General Authorization. Customer grants Provider general authorization to engage Subprocessors to Process Customer Personal Data in connection with the Services.

6.2 Subprocessor List and Notice. Provider will maintain the Subprocessor List and will provide notice of new Subprocessors by email, through the Services, or through another commercially reasonable mechanism. Customer may subscribe to Subprocessor notices by emailing privacy@fundraiseup.com with “Subscribe” in the subject line and information sufficient to identify Customer and the Agreement.

6.3 Objections. Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice to Provider within fifteen (15) days after Provider’s notice. The parties will work in good faith to resolve the objection. If the parties cannot reasonably resolve the objection, Customer may terminate the affected Services to the extent the Services cannot be provided without the objected-to Subprocessor.

6.4 Subprocessor obligations. Provider will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective in substance than those imposed on Provider under this DPA, to the extent applicable to the Subprocessor’s Processing of Customer Personal Data.

6.5 Responsibility. Provider remains responsible for its Subprocessors’ acts and omissions to the extent such acts or omissions cause Provider to breach this DPA.

7. Data Subject and Consumer Requests

7.1 Assistance. Taking into account the nature of the Processing and the information available to Provider, Provider will provide commercially reasonable assistance to Customer as necessary for Customer to respond to requests from data subjects or consumers to exercise rights under Applicable Data Protection Laws.

7.2 Direct Requests. If Provider receives a request from a data subject or consumer relating to Customer Personal Data, Provider will, to the extent legally permitted and reasonably practicable, notify Customer or direct the requester to Customer. Provider will not respond to the request except as instructed by Customer or as required by Applicable Data Protection Laws.

8. Personal Data Breach

8.1 Notice. Provider will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available to Provider that is necessary for Customer to meet its obligations under Applicable Data Protection Laws, including, where available, the nature of the Personal Data Breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed to address the Personal Data Breach.

8.2 Phased Information. Provider may provide information in phases if complete information is not reasonably available at the time of initial notice.

9. Data Protection Impact Assessments and Consultations

Taking into account the nature of the Processing and the information available to Provider, Provider will provide reasonable assistance to Customer, at Customer’s expense unless prohibited by Applicable Data Protection Laws, with data protection impact assessments, privacy impact assessments, and consultations with supervisory authorities or other competent privacy authorities, in each case solely to the extent required by Applicable Data Protection Laws and relating to Provider’s Processing of Customer Personal Data under the Agreement.

10. Return and Deletion

10.1 Deletion or Return. Upon expiration or termination of the Services, Provider will delete or return Customer Personal Data in accordance with the Agreement, this DPA, and Provider’s standard retention, backup, archival, security, and legal compliance practices, including preservation obligations related to actual or reasonably anticipated litigation, investigations, or legal holds.

10.2 Retention Required or Permitted by Law. Provider may retain Customer Personal Data to the extent required or permitted by applicable law, provided that Provider will continue to protect retained Customer Personal Data in accordance with this DPA and will not Process retained Customer Personal Data except for the purpose requiring or permitting retention.

10.3 Backups. Customer Personal Data retained in backups will be protected in accordance with this DPA and deleted in accordance with Provider’s ordinary backup deletion cycles.

10.4 Deidentified Data. Notwithstanding anything to the contrary in this DPA, Provider may retain, use, and disclose data derived from Customer Personal Data that has been aggregated, anonymized, deidentified, or otherwise rendered incapable of identifying Customer or any individual (“Deidentified Data”) for lawful business purposes, including analytics, security, benchmarking, service improvement, and machine learning or artificial intelligence development and improvement, provided that Provider does not attempt to reidentify any individual from such Deidentified Data.

11. Audit and Compliance Documentation

11.1 Documentation. Upon Customer’s reasonable written request, Provider will make available information reasonably necessary to demonstrate Provider’s compliance with this DPA, which may include summaries of security measures, third-party audit reports or certifications, written responses to reasonable security questionnaires, or other documentation determined by Provider to be appropriate.

11.2 Audits. If Applicable Data Protection Laws require Customer to conduct an audit and the documentation made available under Section 11.1 is insufficient to satisfy that requirement, Provider will allow Customer or an independent auditor appointed by Customer to conduct an audit of Provider’s Processing of Customer Personal Data, subject to reasonable advance notice of at least fifteen (15) days, confidentiality obligations acceptable to Provider, normal business hours, reasonable limitations designed to avoid disruption to Provider’s business, and restrictions necessary to protect the confidentiality and security of Provider’s systems and other customers’ data. Audits shall, where reasonably possible, be conducted remotely and through review of existing documentation and reports before any on-site inspection is requested. Customer may not appoint a competitor of Provider as auditor without Provider’s prior written consent. Provider will not be required to disclose information that could compromise the confidentiality, security, or privacy of other customers, systems, or data.

11.3 Frequency and Cost. Audits under Section 11.2 may not occur more than once per calendar year unless required by Applicable Data Protection Laws or following a confirmed Personal Data Breach affecting Customer Personal Data. Customer is responsible for all costs of any audit and for the acts and omissions of its auditors and representatives.

11.4 Remediation. If an audit identifies a material deficiency in Provider’s compliance with this DPA, Customer will notify Provider in writing, and Provider will use commercially reasonable efforts to remediate the deficiency within a reasonable period based on the nature and severity of the deficiency.

12. International Transfers

12.1 Transfer Mechanisms. Customer authorizes Provider and its Subprocessors to make Restricted Transfers as necessary to provide the Services, provided that Provider implements an appropriate transfer mechanism recognized by Applicable Data Protection Laws, including, as applicable, the SCCs, the UK Addendum, an adequacy decision, or another lawful transfer mechanism.

12.2 SCCs. For Restricted Transfers subject to the EU GDPR, the SCCs are incorporated into this DPA and completed as set forth in Annex III. For Restricted Transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA and completed as set forth in Annex III. If Swiss data protection law applies, the SCCs will be interpreted to include applicable Swiss law adjustments.

12.3 Onward Transfers. Provider will ensure that an appropriate transfer mechanism is in place before making a Restricted Transfer of Customer Personal Data to a Subprocessor, to the extent required by Applicable Data Protection Laws.

12.4 Limited Agency. Solely to the extent necessary to implement the SCCs or UK Addendum for Restricted Transfers to Provider Affiliates or Subprocessors, Customer authorizes Provider to enter into the SCCs or UK Addendum on Customer’s behalf with such Provider Affiliates or Subprocessors.

13. U.S. State Privacy Law Terms

13.1 Service Provider and Processor Restrictions. To the extent U.S. State Privacy Laws apply and Provider Processes Customer Personal Data as a service provider or processor, Provider will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA or as otherwise permitted by U.S. State Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Provider and Customer except as permitted by U.S. State Privacy Laws; or (d) combine Customer Personal Data with personal data received from or on behalf of another person except as permitted by U.S. State Privacy Laws.

Notwithstanding the foregoing, Provider may Process Customer Personal Data for internal operations and other purposes permitted under U.S. State Privacy Laws, including security and integrity, fraud detection and prevention, debugging, error detection and repair, quality assurance, analytics, auditing, maintaining and improving the Services, and other internal operational uses reasonably aligned with Customer’s expectations and the business purposes described in the Agreement and this DPA.

13.2 Assistance and Flow-Downs. Provider will provide reasonable assistance to Customer as necessary for Customer to comply with applicable consumer request obligations under U.S. State Privacy Laws, and Provider will require Subprocessors to comply with obligations consistent with this Section 13 to the extent applicable to their Processing of Customer Personal Data.

13.3 Certification. Provider certifies that it understands and will comply with the restrictions in this Section 13.

14. Term

This DPA will remain in effect for so long as Provider Processes Customer Personal Data under the Agreement. Expiration or termination of this DPA will not affect obligations that, by their nature or express terms, apply for so long as Provider retains Customer Personal Data.

15. Indemnification and Liability

15.1 Indemnification. The indemnification obligations in the Agreement apply to claims arising out of or relating to this DPA. If the Agreement does not contain an applicable indemnity, Customer will defend, indemnify, and hold harmless Provider and its Affiliates, officers, directors, employees, and agents from and against third-party claims, damages, costs, and expenses, including reasonable attorneys’ fees, arising from Customer’s unlawful instructions, Customer’s failure to provide required notices or obtain required consents or legal bases, or Customer’s breach of this DPA or Applicable Data Protection Laws.

15.2 Liability. The exclusions and limitations of liability in the Agreement apply to liability arising out of or relating to this DPA, except to the extent prohibited by Applicable Data Protection Laws. This DPA does not create a separate or additional liability cap.

16. General

16.1 Order of Precedence. If there is a conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Customer Personal Data. If there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum, as applicable, control with respect to the relevant Restricted Transfer. This DPA does not supersede, amend, or replace any data processing agreement, data protection addendum, or other written agreement relating to the Processing of Customer Personal Data that has been executed in writing by Customer and Provider (an “Executed Data Protection Agreement”). If an Executed Data Protection Agreement exists, it remains in full force and effect and controls to the extent of any conflict with this DPA, and this DPA applies only to the extent it addresses matters not addressed by that Executed Data Protection Agreement. Nothing in this DPA operates to reduce, waive, or otherwise modify any right or obligation of either party under an Executed Data Protection Agreement.

16.2 Independent Contractors. The parties are independent contractors. Except for the limited agency authorization in Section 12.4, this DPA does not create any partnership, joint venture, agency, fiduciary, or employment relationship between the parties.

16.3 Changes Required by Law. Provider may update this DPA or applicable transfer mechanisms to address changes in Applicable Data Protection Laws, provided that such updates do not materially reduce the protection provided to Customer Personal Data. If Customer reasonably objects to an update, the parties will work in good faith to resolve the objection.

16.4 Notices. Notices under this DPA must be provided in accordance with the Agreement. Notices to Provider regarding privacy matters may also be sent to legal@fundraiseup.com or privacy@fundraiseup.com.

16.5 Severability. If any provision of this DPA is invalid or unenforceable, the remainder of this DPA will remain in effect, and the invalid or unenforceable provision will be interpreted or amended to achieve the parties’ original intent to the maximum extent permitted by law.

Annex I. Description of Processing

Subject matter of Processing: Provider’s provision of the Services to Customer, including operation of an online fundraising and donation platform for charitable organizations.

Duration of Processing: For the term of the Agreement and for any period thereafter during which Provider Processes Customer Personal Data in accordance with the Agreement, this DPA, and applicable retention, backup, archival, security, and legal compliance practices.

Nature and purpose of Processing: Receiving, collecting, recording, organizing, structuring, storing, hosting, using, retrieving, transmitting, disclosing to authorized Subprocessors, deleting, and otherwise Processing Customer Personal Data as necessary to provide, secure, support, maintain, and improve the Services, including analytics, fraud prevention, automation, and machine learning-enabled platform functionality.

The Services include an AI-powered donation optimization tool (the “Optimization Tool”) that processes contextual, environmental, behavioral, and technical signals collected from visitors to Customer’s website to generate personalized donation-related recommendations, including suggested donation amounts, recurring donation suggestions, and fee-coverage recommendations. The Optimization Tool operates within parameters set by Customer, including Customer’s ability to enable or disable the Optimization Tool and to set limits on suggested donation amounts.

Categories of data subjects: Individuals who make donations to Customer; individuals who work for or represent Customer; and other individuals whose Personal Data is submitted to the Services by or on behalf of Customer.

Categories of Customer Personal Data: Name, contact information, email address, postal address or location information, employer name, IP address, transaction details, donation details, device and technical data (including browser type, device type, operating system, connection type, connection speed, battery level and charging status, and processor performance); online identifiers; behavioral interaction data and related data collected through Customer’s website (including date and time of visit, number of pages viewed, number of prior visits, time spent on the website, cursor movement patterns, and scroll depth); city- and country-level geolocation derived from IP address; and payment-related information such as tokenized or truncated payment card information. Provider does not intentionally store full payment card numbers or payment card verification codes except to the extent expressly described in the Agreement or applicable payment processing documentation.

Sensitive or special categories of data: The Services are not designed to require special categories of Personal Data. Customer will not submit special categories of Personal Data, sensitive personal information, or similarly regulated data to the Services unless permitted under the Agreement and Applicable Data Protection Laws. Depending on Customer’s organization, campaign, or donor context, donation activity may support inferences relating to sensitive topics. Customer is responsible for determining whether such data is sensitive or specially regulated in Customer’s circumstances.

Frequency of transfer: Continuous, as Customer and its users use the Services.

Subprocessor transfers: The subject matter, nature, and duration of Processing by Subprocessors are substantially the same as described in this Annex I, except as otherwise described in the Subprocessor List.

Annex II. Technical and Organizational Measures

Provider maintains technical and organizational measures designed to protect Customer Personal Data against Personal Data Breaches. These measures may include the following, as applicable to the Services and Provider’s systems:

Encryption: Encryption of data at rest and data in transit using commercially reasonable encryption protocols, including TLS 1.2 or higher for public network connectivity and AES-256 or comparable encryption where appropriate.

Access controls: Role-based access controls, unique user credentials, least-privilege access principles, and procedures designed to restrict access to authorized personnel with a business need to access Customer Personal Data.

Network and infrastructure security: Firewalls, network segmentation, intrusion detection or monitoring tools, logging, and other safeguards designed to monitor and protect Provider systems.

Vulnerability and patch management: Processes designed to identify, evaluate, and remediate vulnerabilities, including regular patching of systems and software.

Personnel measures: Confidentiality obligations and security training for personnel with access to Customer Personal Data.

Data minimization: Processes designed to limit collection and retention of Customer Personal Data to what is reasonably necessary for the Services and applicable legal, security, backup, archival, and operational purposes.

Incident response: Incident response procedures designed to identify, investigate, mitigate, and provide notice of Personal Data Breaches in accordance with this DPA.

Provider management: Contractual and operational controls for Subprocessors that Process Customer Personal Data on Provider’s behalf.

Business continuity: Backup, disaster recovery, and business continuity practices designed to support availability and resilience of the Services.

Annex III. Standard Contractual Clauses and UK Addendum

For Restricted Transfers subject to the EU GDPR, the SCCs are incorporated into this DPA and completed as follows:

Module Two applies to transfers from Customer as controller to Provider as processor.

Module Three applies to transfers from Customer as processor to Provider as Subprocessor, if and to the extent Customer acts as a processor on behalf of another controller.

Clause 7, the optional docking clause, is included.

For Clause 9, the parties select Option 2, general written authorization. Provider will provide notice of new Subprocessors as described in Section 6 of this DPA.

For Clause 11, the optional language regarding an independent dispute resolution body is not included.

For Clause 17, the parties select Option 1 and the laws of Ireland.

For Clause 18, the parties select the courts of Ireland.

Annex I(A) of the SCCs are completed by Annex IV of this DPA. Annex I(B) of the SCCs are completed by Annex I of this DPA.

Annex I(C) of the SCCs identifies the Irish Data Protection Commission as the competent supervisory authority to the extent legally permissible.

Annex II of the SCCs is completed by Annex II of this DPA.

Annex III of the SCCs is completed by the Subprocessor List.

For Restricted Transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA and completed as follows:

Table 1 is completed with the party information in Annex IV of this DPA.

Table 2 is completed by reference to the SCCs as incorporated and completed by this Annex III.

Table 3 is completed by Annex I, Annex II, Annex IV, and the Subprocessor List.

Table 4 is completed so that either party may end the UK Addendum to the extent permitted by its terms and this DPA.

By entering into the Agreement, the parties are deemed to have signed the UK Addendum.

For transfers subject to Swiss data protection law, the SCCs will be interpreted to protect data subjects in Switzerland, references to the GDPR will include applicable Swiss data protection law, and references to an EU Member State will not be interpreted to exclude data subjects in Switzerland from enforcing their rights in Switzerland.

Annex IV. List of Parties

Data Exporter

FieldDetails
NameCustomer, as identified in the Agreement or applicable Order Form.
AddressCustomer’s address as identified in the Agreement, applicable Order Form, or Customer’s account information.
ContactCustomer’s contact person as identified in the Agreement, applicable Order Form, or Customer’s account information.
Activities relevant to transferCustomer’s use of the Services.
RoleController or processor, as applicable.
Signature and dateBy entering into the Agreement, Customer is deemed to have signed the SCCs and UK Addendum as of the effective date of the Agreement or applicable Order Form.

Data Importer

FieldDetails
NameFundraise Up Inc.
Address219 36th Street, 4th Floor, Suite 100, Brooklyn, New York 11232, USA
ContactPrivacy Team, Fundraise Up Inc., privacy@fundraiseup.com
Activities relevant to transferProvision of the Services, including operation of an online fundraising and donation platform for charitable organizations.
RoleProcessor or Subprocessor, as applicable.
Signature and dateBy entering into the Agreement, Provider is deemed to have signed the SCCs and UK Addendum as of the effective date of the Agreement or applicable Order Form.