Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between PurposeTech and our customers for the provision of volunteer management services.

Last updated: 1 April 2025

1. Definitions

In this DPA, the following terms have the meanings set out below:

  • "Controller" means the entity that determines the purposes and means of processing Personal Data (typically, our customer).
  • "Processor" means the entity that processes Personal Data on behalf of the Controller (PurposeTech).
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Data Subject" means the individual whose Personal Data is being processed.
  • "Sub-processor" means any third party engaged by PurposeTech to process Personal Data.
  • "Applicable Data Protection Laws" means the New Zealand Privacy Act 2020, the EU General Data Protection Regulation (GDPR), and any other applicable data protection legislation.

2. Scope and Purpose

This DPA applies to the processing of Personal Data by PurposeTech on behalf of the Customer in connection with the provision of our volunteer management services.

The nature and purpose of processing includes:

  • Managing volunteer registrations and profiles
  • Coordinating volunteer shifts and assignments
  • Communicating with volunteers on behalf of the Customer
  • Generating reports and analytics on volunteer activities
  • Processing any other data as instructed by the Customer

3. Obligations of PurposeTech as Processor

PurposeTech agrees to:

  • Process Personal Data only on documented instructions from the Customer
  • Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk
  • Only engage Sub-processors with the Customer's prior authorisation and under a written contract
  • Assist the Customer in responding to Data Subject requests
  • Assist the Customer in ensuring compliance with security, breach notification, and data protection impact assessment obligations
  • Delete or return all Personal Data at the end of the service relationship, at the Customer's choice
  • Make available all information necessary to demonstrate compliance with this DPA

4. Sub-processors

The Customer authorises PurposeTech to engage the Sub-processors listed on our Subprocessors page.

PurposeTech will:

  • Notify the Customer of any intended changes to Sub-processors
  • Give the Customer the opportunity to object to such changes
  • Ensure Sub-processors are bound by data protection obligations no less protective than those in this DPA
  • Remain liable for the acts and omissions of its Sub-processors

5. International Data Transfers

PurposeTech may transfer Personal Data to countries outside New Zealand and the European Economic Area. When doing so, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Transfers to countries with adequate data protection laws
  • Other legally approved transfer mechanisms

6. Security Measures

PurposeTech implements appropriate technical and organisational measures including:

  • Encryption of Personal Data in transit and in some cases at rest
  • Access controls and authentication mechanisms
  • Regular security testing and vulnerability assessments
  • Incident response and business continuity procedures
  • Staff training on data protection and security

For more details, please see our Security & Trust page.

7. Data Breach Notification

In the event of a Personal Data breach, PurposeTech will:

  • Notify the Customer without undue delay (and in any event within 72 hours where feasible)
  • Provide information about the nature of the breach, categories of data affected, and likely consequences
  • Describe measures taken or proposed to address the breach
  • Cooperate with the Customer in investigating and mitigating the breach

8. Audits and Inspections

PurposeTech will make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for audits and inspections conducted by the Customer or an appointed auditor, subject to reasonable notice and confidentiality obligations.

9. Term and Termination

This DPA remains in effect for the duration of our service agreement with the Customer. Upon termination, PurposeTech will, at the Customer's choice, delete or return all Personal Data and certify that it has done so, unless retention is required by law.

Request a Signed DPA

If you require a signed copy of this DPA for your records, please contact our Privacy Officer.

Contact Privacy Officer

Questions about our Data Processing Agreement?

If you have any questions about this DPA, please contact us at privacy@purposetech.io