This Data Processing Addendum (“DPA”) forms part of the agreement between the entity identified in the ordering document or master services agreement (“Customer”) and GroupApp, Inc., located at 440 N Barranca Ave #3601, Covina, CA 91723 USA (“GroupApp”) (together, the “Parties”).
1) Scope and Roles
1.1 This DPA applies to GroupApp’s Processing of Personal Data on behalf of Customer in connection with GroupApp’s hosted platform for online communities, courses, and live events (the “Service”).
1.2 The Parties agree that Customer is the Controller and GroupApp is the Processor (or, where Customer acts as a Processor, GroupApp is a Subprocessor).
2) Definitions
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Personal Data Breach” have the meanings given in Data Protection Laws.
“Data Protection Laws” means, as applicable, the EU GDPR, UK GDPR, and other laws governing Personal Data based on Customer’s use of the Service.
Capitalized terms not defined here have the meanings in the Agreement.
3) Customer Instructions
3.1 GroupApp will Process Personal Data only on documented instructions from Customer unless required by law.
3.2 The Agreement (including this DPA) constitutes Customer’s instructions. Any additional instructions must be mutually agreed in writing and may be subject to additional fees. GroupApp is not required to act on instructions that are unreasonable, inconsistent with the Agreement, or technically infeasible.
4) Confidentiality and Personnel
4.1 GroupApp ensures personnel authorized to Process Personal Data are subject to confidentiality obligations and receive appropriate training.
4.2 Access is limited to personnel with a need to know to deliver the Service.
5) Security Measures
5.1 GroupApp maintains appropriate technical and organizational measures designed to protect Personal Data as described in Annex C.
5.2 GroupApp may update such measures provided the overall level of protection is not materially reduced.
6) Subprocessors
6.1 Customer authorizes GroupApp to use Subprocessors to support the Service. Current Subprocessors are listed in Annex B.
6.2 GroupApp will:
(a) Impose materially similar protection obligations on Subprocessors; and
(b) Remain responsible for their performance.
6.3 GroupApp will provide at least 30 days’ notice of new or replaced Subprocessors via webpage and/or email. Customer may object on reasonable data-protection grounds. If unresolved, Customer may terminate only the affected portion of the Service.
7) Personal Data Breach
7.1 GroupApp will notify Customer without undue delay (generally within 72 hours) after confirming a Personal Data Breach.
7.2 Notice will include, where available: description of the breach, categories of Data Subjects and records involved, likely consequences, and steps taken or proposed to address it. Notifications may be provided in phases.
7.3 GroupApp is not required to provide forensic reports, detailed root-cause analysis, or engage external consultants unless mutually agreed and subject to additional fees.
8) Assistance
8.1 Taking into account the nature of Processing, GroupApp will provide commercially reasonable assistance to:
(a) help respond to Data Subject requests; and
(b) support DPIAs or consultations required under Data Protection Laws;
in each case only to the extent such obligations relate to GroupApp’s Processing of Customer Personal Data.
8.2 All such assistance is subject to:
(a) mutually agreed scope;
(b) timing that does not materially interfere with GroupApp’s business operations; and
(c) reimbursement of GroupApp’s reasonable costs.
8.3 If requests are manifestly unfounded, excessive, or repetitive, GroupApp may charge a reasonable fee or decline to assist.
9) Audits and Information
9.1 On written request, GroupApp will, at Customer’s expense, provide information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries and policy excerpts under NDA. GroupApp is not required to disclose information that would compromise security, is confidential, or commercially sensitive.
9.2 Customer may conduct an audit no more than once every 12 months only where required under Data Protection Laws and only after reviewing the information provided under Section 9.1 and determining it is insufficient. Any audit must:
(a) be limited in scope;
(b) require 30 days’ written notice;
(c) occur during normal hours;
(d) not interfere with operations; and
(e) be at Customer’s expense.
9.3 On-site audits are permitted only if required by Data Protection Laws or after a confirmed material breach and only after remote/desk methods are exhausted. Customer must reimburse GroupApp’s reasonable costs.
10) International Transfers
10.1 Customer acknowledges Personal Data will be stored and processed in the United States and may be transferred from the EEA/UK as necessary to deliver the Service.
10.2 Where required, the Parties enter the EU Standard Contractual Clauses (EU SCCs), Module 2, as provided in Annex D.
10.3 For UK transfers, the UK Addendum applies per Annex E.
10.4 The Parties may discuss implementing alternative safeguards if the SCCs become invalid. Any GroupApp work relating to such safeguards must be mutually agreed, may incur additional fees, and will not require actions that materially interfere with operations.
11) Government / Third-Party Requests
11.1 Where legally permitted, GroupApp will notify Customer of legally binding requests for disclosure of Personal Data by public authorities. GroupApp has no obligation to challenge or contest such requests.
11.2 GroupApp will not disclose Personal Data to third parties except as instructed by Customer or required by law. GroupApp’s obligations under this section are limited to forwarding requests where legally permitted.
12) Return and Deletion
12.1 At termination, Customer may request export of Personal Data. GroupApp will delete Customer Personal Data within 30 days, subject to standard backup retention (up to ~35 days), after which data is overwritten.
12.2 On request, GroupApp will confirm deletion.
13) Liability and Precedence
13.1 Liability under this DPA is subject to the limitations in the Agreement unless prohibited by law.
13.2 If this DPA conflicts with the Agreement, this DPA controls for privacy/security; otherwise the Agreement governs.
14) Term
This DPA applies for the term of the Agreement and terminates once GroupApp deletes all Customer Personal Data under Section 12.
ANNEX A — Details of Processing
• Subject matter: Delivery of the GroupApp hosted platform
• Duration: Term of the Agreement + backup retention
• Nature and purpose: Hosting, storage, transmission, and related Processing required to provide, maintain, secure, support, and improve the Service, solely at GroupApp’s discretion
• Categories of data: Basic account info, profile details, content, usage/activity data, course/event data, payment metadata (no card data)
• Special Categories: Not intended
• Data Subjects: End-users, members, customers, staff with admin access
• Frequency: Continuous with user activity
• Retention: As described in Section 12
ANNEX B — Subprocessors
Amazon Web Services — hosting (US)
Amazon SES — email delivery (US)
Stripe — payments (US/EU)
HubSpot — CRM (US)
Customer.io — email automation (US)
Mixpanel — product analytics (US)
Google Analytics — web analytics (US)
Cloudflare — CDN/security (global)
ANNEX C — Technical and Organizational Measures (TOMs)
• Role-based access
• Password hashing
• TLS encryption in transit
• Encryption at rest where supported
• MFA for admin systems
• Regular access reviews
• Segmented environments
• Patching and vulnerability scanning
• Logging and alerting
• Secure development practices
• Backup + recovery
• Incident response runbooks
• Subprocessor due diligence
ANNEX D — EU SCCs
EU Standard Contractual Clauses Module 2 are incorporated by reference.
Annex summaries correspond to Annex A–C above.
ANNEX E — UK Addendum
The UK Addendum is incorporated by reference and completed using information matching Annexes A–C.
