Data Processing Agreement

For organisations using connected data

Data Processing Agreement

Draft for review: This page outlines processing commitments to confirm in a signed agreement where Charity Automate processes personal data for a charity or other organisation.

Roles and instructions

The customer is normally the controller and Charity Automate is a processor for personal data placed into workflows. We process it only to provide the configured service, on documented instructions.

Customer responsibilities

The customer decides which records to retrieve, actions to run and recipients to contact. The customer must have a lawful basis, provide required notices, configure permissions and review automated outputs where human oversight is needed.

Security, subprocessors and incidents

  • Encrypted storage for service credentials in WordPress.
  • Capability-based access controls for plugin administration.
  • HTTPS, run-level logs and background processing controls.
  • Reasonable incident detection, containment and investigation measures.
  • Connected services may include Beacon CRM, SendGrid, OpenRouter and Stripe.

Deletion and assistance

We will provide reasonable assistance with data subject requests, security enquiries and incident investigations. When the service ends, data should be deleted or returned unless retention is required by law. Contact hello@charityautomate.com.