Tutelium
    • Overview
    • Finance & Accounting
    • Giving & Fundraising
    • People & CRM
    • Planning & Operations
    • Governance & Compliance
    • How Tutelium works
    • For Churches
    • For Nonprofits
  • Pricing
    • Blog
    • Security & Trust
  • Contact
Log in Get early access
Tutelium
  • Overview
  • Finance & Accounting
  • Giving & Fundraising
  • People & CRM
  • Planning & Operations
  • Governance & Compliance
  • How Tutelium works
  • For Churches
  • For Nonprofits
Pricing
  • Blog
  • Security & Trust
Contact
Log in Get early access
Legal

Data Processing Agreement

Last updated: September 5, 2026

On this page

Roles How we process US service provider rules Security Subprocessors Requests from people Incidents Proof and audits Return and delete Liability What we process Security measures Subprocessors list Contact
Terms Privacy Data processing Cookies AI use Acceptable use
In short

Your organization decides why personal information goes into Tutelium. We process it only to run the product for you. This agreement is part of the Terms of Service when you use the product. It is written for US customers (CCPA service-provider rules) and also covers GDPR Article 28 if European data protection law applies to a given activity.

1. Roles

You (the customer organization) are the business / controller for personal information you submit into the service. Tutelium Corp. is the service provider / processor. We do not use that information for our own marketing, and we do not sell it.

This DPA does not cover information for which Tutelium Corp. is itself the business (website visitors, your billing contact, and similar). That is in the Privacy Policy.

Stripe, when you connect your organization’s Stripe account for gifts, provides payment services under your Stripe agreement. Stripe may also process some data for its own fraud and compliance purposes. We are not merchant of record for those gifts.

2. How we process

We process only on your documented instructions. Using the product (including settings you click) is an instruction. If a law requires us to process in another way, we will tell you if we are allowed to. Our people who see customer data are bound to keep it confidential.

Duration: for as long as the Terms last, plus the retention windows in Annex 1. Confidentiality survives.

3. US service provider terms

When the CCPA / CPRA applies, Tutelium Corp. is a service provider (and, where the facts fit, a contractor) for customer content. We will:

  • Process personal information only for the business purposes in Annex 1 and the Terms.
  • Not sell it or share it for cross-context behavioral advertising.
  • Not retain, use, or disclose it outside the direct business relationship, except as the CCPA allows.
  • Not combine it with personal information from other sources except to provide the service, as the regulations allow.
  • Help you honor consumer requests that you must fulfill as the business.
  • Tell you if we can no longer meet these duties, and let you take reasonable steps (including stopping processing) if we use the information in an unauthorized way.

If GDPR applies, we also meet the processor duties in Article 28 (assistance, security, subprocessors, audits, delete or return). For transfers of European personal information to the United States we will use a lawful tool (for example the EU Standard Contractual Clauses) when that is required.

4. Security

We take appropriate technical and organizational measures. Annex 2 lists the main ones. You are responsible for your users, roles, and what you upload.

5. Subprocessors

You authorize us to use the subprocessors in Annex 3. We will impose data-protection terms that are no less protective than this DPA. We remain responsible to you for their work for us. We will post material changes to the list and give you a chance to object before a new subprocessor starts on your data. If you object on reasonable data-protection grounds and we cannot accommodate you, you may cancel as in the Terms.

6. Requests from people

If a donor, volunteer, or other person contacts us about data your organization holds, we will point them to you unless the law says we must answer. We will give you reasonable help so you can respond.

7. Security incidents

If we become aware of a personal data breach affecting your customer content, we will notify you without undue delay, with information you reasonably need for your own notices. We will not notify affected individuals for you unless the law requires us to or you ask us in writing.

8. Proof and audits

We will make available information reasonably needed to show we meet this DPA. You may audit (or have an independent auditor audit) under reasonable notice, during business hours, no more than once per year unless a competent authority or a confirmed incident requires more. Audits must not unreasonably disrupt the service or other customers. We may satisfy an audit with current independent reports where they cover the request.

9. Return and deletion

When the service ends, we give you a reasonable export window, then delete or anonymize personal information in customer content, except copies we must keep under law (including the financial-administration baseline) or that remain in backups until those backups rotate. Soft-delete is not erasure. Backups are not a substitute for erasure.

10. Liability

Liability under this DPA follows the Terms of Service, including the cap and the exclusions, except where a mandatory privacy law says a limit cannot apply to that claim.

Annex 1 — What we process

  • Purpose: books, bank matching, receipts, reporting, expense claims and volunteer portal / Church Center, Form 990 pack preparation (not e-file), custom domain for books access, People care SMS and login codes, live giving through your Stripe account (software and posting only), Solon assistance.
  • Types of data: user account fields; names, addresses, and contact details of relations; bank and transaction data; receipts; claim amounts and payee account identifiers; volunteer schedule and check-in fields you store; EIN and officer fields you enter in a pack; donor checkout fields and Stripe IDs for gifts; SMS numbers, bodies, and consent flags; hostname and change-log actor IDs for custom domain. Full card PAN is out of scope for Tutelium when Stripe Payment Element is used correctly.
  • People: your users; donors, members, volunteers, claimants, and others who appear in your books or portals; officers whose details you enter; payers on your giving page.
  • Retention: books-supporting data and gift rows, seven-year baseline (or longer if the law requires); officer PII beyond the books, only while needed; SMS bodies, up to 12 months; security / custom-domain change logs, 12 to 24 months. Soft-delete is not erasure.

Annex 2 — Security measures

  • TLS in transit; encryption at rest
  • Role-based access and least privilege
  • Logical separation of customer environments
  • Logging, monitoring, and audit trails
  • US hosting for the US product, with backups
  • AI paths that do not give language models a live database connection to the books; OCR only on files you supply

Annex 3 — Subprocessors

ProviderWhat they doTypical region
SupabaseAuthentication, database, file storageUS country projects
Application host (Vercel or successor)App hosting; TLS for verified custom domainsConfirm in operations
Stripe(A) Tutelium subscription billing (our merchant account). (B) Your Stripe account for gifts (you are merchant of record; we process limited checkout and webhook data)Per Stripe account
OpenAI, L.L.C.Minimized assistant prompts; receipt OCRPer API configuration
Twilio Inc.People care SMS and login one-time codes, when enabledUS default; per Twilio order form
Microsoft mailbox pathTransactional authentication email, when configuredPer operations
PlaidBank connection, only if you enable itUS

Firma e-sign is used for some partner documents. It is not a default subprocessor for customer books until we list it here.

Contact

Questions: contact page. Tutelium is offered by Tutelium Corp., a Delaware corporation. EIN 42-4484663. Delaware registered office: 8 The Green, Suite B, Dover, Delaware 19901.

Tutelium

Run your mission. Not your software.

Copyright . Tutelium. All rights reserved.

Product

  • Platform
  • Solon AI
  • Integrations
  • Pricing

Solutions

  • For Nonprofits
  • For churches
  • Blog

Support & Contact

  • About us
  • Contact
  • Security
  • FAQ
About us Privacy Policy Terms of Service Cookie Policy Responsible AI Use Data Processing Agreement Acceptable Use Do Not Sell or Share
Tutelium
Platform Overview Finance & Accounting Giving & Fundraising People & CRM Planning & Operations Governance & Compliance How Tutelium works
Solutions For Churches For Nonprofits
Pricing
Resources Blog Security & Trust
Contact
Log in Get early access