1. Parties and purpose
This Data Processing Addendum ("DPA") forms part of the agreement between Nicholas Schiavi, a sole proprietor doing business as NeighborlyEvents in California ("NeighborlyEvents", the "Processor") and the community, association, club or organization that uses the Service (the "Customer", the "Controller") under the Terms of Service. It applies whenever NeighborlyEvents processes personal data on the Customer's behalf. Where this DPA and the Terms conflict on the processing of personal data, this DPA governs.
The Customer executes this DPA by countersigning a copy; NeighborlyEvents provides one on request to [email protected]. Its text is published here so that a board can review it before asking.
2. Roles
The Customer decides which of its members' and attendees' data enters the Service and for what purpose, and is the controller of that data. NeighborlyEvents processes it only to provide the Service and is the processor. For the limited data NeighborlyEvents collects for its own purposes — account credentials, billing records, operational logs and security records — NeighborlyEvents is an independent controller under its Privacy Policy.
3. Description of the processing
- Subject matter. Running the Customer's community: events, registrations and check-ins, club rosters and dues, volunteer scheduling, facility reservations, polls, petitions, and the communications that go with them.
- Duration. For as long as the Customer's account is active, plus the retention period in section 9.
- Nature and purpose. Storage, display, transmission (email and push notifications the Customer sends), payment processing through Stripe, and generation of the reports and exports the Customer requests.
- Categories of data subjects. The Customer's residents, members, event attendees, volunteers, club organizers, vendors and sponsors.
- Categories of personal data. Name, email address, phone number, home address where the Customer verifies residency, registration and attendance records, answers to registration questions the Customer writes, payment amounts and Stripe identifiers (never card numbers), photos the Customer or its members upload, and device push tokens.
- Special categories. None are required by the Service. The Customer must not collect special-category data through custom registration questions without a lawful basis of its own.
4. Processing on instructions
NeighborlyEvents processes personal data only on the Customer's documented instructions, which are: the Terms, this DPA, and the Customer's use of the Service's features. NeighborlyEvents will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law. NeighborlyEvents does not sell personal data, does not use it for advertising, and does not use it to train machine-learning models.
5. Confidentiality
Only people who need access to operate the Service have it, and they are bound by confidentiality obligations. Platform administrator access to a community's data is limited to support and is visible in the interface while it is in use.
6. Security
NeighborlyEvents maintains the technical and organizational measures described on the Security overview, including encryption in transit, encryption at rest at the storage layer, passwordless authentication, scoped access by community, static security analysis and dependency scanning in the release pipeline, and rate limiting. NeighborlyEvents may update these measures provided the overall level of protection does not decrease.
7. Sub-processors
The Customer authorizes the sub-processors listed on the Security overview. NeighborlyEvents will publish a change to that list, with a note in the page's change history, at least 30 days before a new sub-processor handles personal data, and will email organizers about it. A Customer that objects on reasonable data-protection grounds may terminate the affected part of the Service and receive a pro-rated refund of any prepaid fees. NeighborlyEvents remains responsible for its sub-processors' performance.
8. Assistance to the Customer
Taking into account the nature of the processing, NeighborlyEvents will assist the Customer in responding to requests from data subjects (access, correction, deletion, portability) — members can delete their own account in the mobile app, and the whole-community export provides portability in open formats — and in meeting the Customer's obligations regarding security, breach notification and data-protection impact assessments, to the extent the Customer cannot do so through the Service itself.
9. Return and deletion
During the term, the Customer can export its data at any time (whole-community archive; per-event exports). When the Customer closes its account, or on a wind-down of the Service, NeighborlyEvents provides the archive and deletes the Customer's personal data 90 days later, unless earlier deletion is requested or retention is required by law (for example, payment records). Backups are overwritten on their own cycle.
10. Personal-data breach
NeighborlyEvents will notify the Customer without undue delay, and within 72 hours of confirming a personal-data breach affecting the Customer's data, with what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Notifications go to the Customer's organizer notification address.
11. Audits
On request, and no more than once a year unless required by a supervisory authority or following a breach, NeighborlyEvents will make available the information reasonably necessary to demonstrate compliance with this DPA: the Security overview, the internal policy set, and answers to a reasonable written questionnaire. An on-site or third-party audit may be agreed in a negotiated contract, at the Customer's expense, with reasonable notice and scope.
12. Location of processing
Personal data is processed and stored in the United States, in the AWS US West (N. California) region and the sub-processors' US facilities. NeighborlyEvents does not transfer the Customer's personal data outside the United States.
13. California residents
Where the California Consumer Privacy Act applies, NeighborlyEvents acts as a service provider to the Customer. It will not sell or share the personal data, will not retain, use or disclose it for any purpose other than performing the Service, will not combine it with personal data received from other sources except as permitted, and will notify the Customer if it can no longer meet these obligations. The Customer may take reasonable steps to stop and remediate unauthorized use.
14. Liability, term and governing law
The limitations of liability in the Terms apply to this DPA. This DPA lasts as long as NeighborlyEvents processes personal data for the Customer. It is governed by the law that governs the Terms.