Your organization decides why personal information goes into Tutelium. We process it only to run the product for you. This agreement is part of the Terms of Service when you use the product. It is written for US customers (CCPA service-provider rules) and also covers GDPR Article 28 if European data protection law applies to a given activity.
1. Roles
You (the customer organization) are the business / controller for personal information you submit into the service. Tutelium Corp. is the service provider / processor. We do not use that information for our own marketing, and we do not sell it.
This DPA does not cover information for which Tutelium Corp. is itself the business (website visitors, your billing contact, and similar). That is in the Privacy Policy.
Stripe, when you connect your organization’s Stripe account for gifts, provides payment services under your Stripe agreement. Stripe may also process some data for its own fraud and compliance purposes. We are not merchant of record for those gifts.
2. How we process
We process only on your documented instructions. Using the product (including settings you click) is an instruction. If a law requires us to process in another way, we will tell you if we are allowed to. Our people who see customer data are bound to keep it confidential.
Duration: for as long as the Terms last, plus the retention windows in Annex 1. Confidentiality survives.
3. US service provider terms
When the CCPA / CPRA applies, Tutelium Corp. is a service provider (and, where the facts fit, a contractor) for customer content. We will:
- Process personal information only for the business purposes in Annex 1 and the Terms.
- Not sell it or share it for cross-context behavioral advertising.
- Not retain, use, or disclose it outside the direct business relationship, except as the CCPA allows.
- Not combine it with personal information from other sources except to provide the service, as the regulations allow.
- Help you honor consumer requests that you must fulfill as the business.
- Tell you if we can no longer meet these duties, and let you take reasonable steps (including stopping processing) if we use the information in an unauthorized way.
If GDPR applies, we also meet the processor duties in Article 28 (assistance, security, subprocessors, audits, delete or return). For transfers of European personal information to the United States we will use a lawful tool (for example the EU Standard Contractual Clauses) when that is required.
4. Security
We take appropriate technical and organizational measures. Annex 2 lists the main ones. You are responsible for your users, roles, and what you upload.
5. Subprocessors
You authorize us to use the subprocessors in Annex 3. We will impose data-protection terms that are no less protective than this DPA. We remain responsible to you for their work for us. We will post material changes to the list and give you a chance to object before a new subprocessor starts on your data. If you object on reasonable data-protection grounds and we cannot accommodate you, you may cancel as in the Terms.
6. Requests from people
If a donor, volunteer, or other person contacts us about data your organization holds, we will point them to you unless the law says we must answer. We will give you reasonable help so you can respond.
7. Security incidents
If we become aware of a personal data breach affecting your customer content, we will notify you without undue delay, with information you reasonably need for your own notices. We will not notify affected individuals for you unless the law requires us to or you ask us in writing.
8. Proof and audits
We will make available information reasonably needed to show we meet this DPA. You may audit (or have an independent auditor audit) under reasonable notice, during business hours, no more than once per year unless a competent authority or a confirmed incident requires more. Audits must not unreasonably disrupt the service or other customers. We may satisfy an audit with current independent reports where they cover the request.
9. Return and deletion
When the service ends, we give you a reasonable export window, then delete or anonymize personal information in customer content, except copies we must keep under law (including the financial-administration baseline) or that remain in backups until those backups rotate. Soft-delete is not erasure. Backups are not a substitute for erasure.
10. Liability
Liability under this DPA follows the Terms of Service, including the cap and the exclusions, except where a mandatory privacy law says a limit cannot apply to that claim.
Annex 1 — What we process
- Purpose: books, bank matching, receipts, reporting, expense claims and volunteer portal / Church Center, Form 990 pack preparation (not e-file), custom domain for books access, People care SMS and login codes, live giving through your Stripe account (software and posting only), Solon assistance.
- Types of data: user account fields; names, addresses, and contact details of relations; bank and transaction data; receipts; claim amounts and payee account identifiers; volunteer schedule and check-in fields you store; EIN and officer fields you enter in a pack; donor checkout fields and Stripe IDs for gifts; SMS numbers, bodies, and consent flags; hostname and change-log actor IDs for custom domain. Full card PAN is out of scope for Tutelium when Stripe Payment Element is used correctly.
- People: your users; donors, members, volunteers, claimants, and others who appear in your books or portals; officers whose details you enter; payers on your giving page.
- Retention: books-supporting data and gift rows, seven-year baseline (or longer if the law requires); officer PII beyond the books, only while needed; SMS bodies, up to 12 months; security / custom-domain change logs, 12 to 24 months. Soft-delete is not erasure.
Annex 2 — Security measures
- TLS in transit; encryption at rest
- Role-based access and least privilege
- Logical separation of customer environments
- Logging, monitoring, and audit trails
- US hosting for the US product, with backups
- AI paths that do not give language models a live database connection to the books; OCR only on files you supply
Annex 3 — Subprocessors
| Provider | What they do | Typical region |
|---|---|---|
| Supabase | Authentication, database, file storage | US country projects |
| Application host (Vercel or successor) | App hosting; TLS for verified custom domains | Confirm in operations |
| Stripe | (A) Tutelium subscription billing (our merchant account). (B) Your Stripe account for gifts (you are merchant of record; we process limited checkout and webhook data) | Per Stripe account |
| OpenAI, L.L.C. | Minimized assistant prompts; receipt OCR | Per API configuration |
| Twilio Inc. | People care SMS and login one-time codes, when enabled | US default; per Twilio order form |
| Microsoft mailbox path | Transactional authentication email, when configured | Per operations |
| Plaid | Bank connection, only if you enable it | US |
Firma e-sign is used for some partner documents. It is not a default subprocessor for customer books until we list it here.
Contact
Questions: contact page. Tutelium is offered by Tutelium Corp., a Delaware corporation. EIN 42-4484663. Delaware registered office: 8 The Green, Suite B, Dover, Delaware 19901.