Document 4: Data Processing Agreement (DPA)
Plain-language summary: This is the detailed agreement about donor data. It confirms that your charity is in charge of that data (the controller) and that Relae only handles it on your instructions (the processor). It sets out how we protect it, who our sub-processors and connected data sources are, what happens if there is a breach, how we help you answer donor requests, and that we return or delete the data when you leave.
1. Roles
This DPA forms part of the Agreement. For Donor Data, the Customer is the Controller and Relae is the Processor. Relae processes Donor Data only to provide the Services and only on the Customer's documented instructions (including those given through normal use of the Platform), unless law requires otherwise, in which case Relae will inform the Customer unless legally prohibited.
2. Purpose limitation and confidentiality
Relae will process Donor Data only for the purpose of providing the Services and the purposes described in this DPA. Relae will not use Donor Data for its own purposes. Personnel with access are bound by written confidentiality obligations and access on a least-privilege basis. If the future Benchmark Cooperative launches, any use of opted-in Customers' data for anonymized aggregates will be governed by Document 8 before any pooling begins; no pooling occurs today.
3. Customer obligations
The Customer warrants it has the right to provide the Donor Data and to instruct Relae to process it, and that it has met its own obligations as Controller (notice, consent, and lawful basis) for its collection and use of Donor Data, including for any Connected Data Source it chooses to attach.
4. Regional processing and the operating company
Donor Data is stored and processed in the Customer's Region. For the Canadian Region: the data store is Supabase ca-central-1, application compute runs in Montreal, and interactive AI runs on Amazon Nova through AWS Bedrock in a Canadian region. The operating and contracting company, Touch Grass AB, is located in Sweden, and its personnel may access the system in the course of operating and supporting it; this access is subject to the same confidentiality, least-privilege, and security obligations as all Relae access, wherever it occurs. The two consented or entitlement-gated flows that leave the Region (donor research and funder research) are described in clause 6 and the Privacy Policy.
5. Sub-processors and connected data sources
The Customer authorizes Relae to engage the Sub-processors listed on Relae's Sub-processor and Data Source page, maintained at relae.ai/subprocessors and incorporated into this DPA by reference. That page is the authoritative, current list; Relae keeps it accurate as Sub-processors and available Connected Data Sources change, and the snapshot in Schedule 2 below is provided for convenience as of this DPA's date and does not override the page. Relae will impose data-protection obligations on each Sub-processor materially equivalent to this DPA, and remains responsible for their performance. During the Beta phase, Relae may add, replace, or change Sub-processors and underlying infrastructure without advance notice, so that it can develop and stabilize the Platform; Relae will update the page and send the Customer an email or in-app notice promptly when it does, and will give advance notice where practicable. Once the Platform reaches general availability, Relae will give at least thirty (30) days' notice, by email or in-app notice to the account's notified contact and by updating the page, before adding or replacing a Sub-processor. In either phase, the Customer may object to a new Sub-processor on reasonable data-protection grounds, and if an objection cannot be resolved, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid unused fees as its exclusive remedy. Connected Data Sources (such as an event platform) are engaged at the Customer's direction, and the Customer is responsible for its own relationship and lawful basis with that source; Relae is not responsible for a Connected Data Source's acts, omissions, availability, or the accuracy of the data it supplies. Relae may make additional Connected Data Sources available over time; each operates only for a Customer that chooses to connect it, and the connection surface describes the data involved, the direction of the flow, and the source's region before the Customer connects, and that connection surface is the operative disclosure for that source. A service that processes Donor Data on Relae's behalf, rather than at the Customer's direction from the Customer's own account, is a Sub-processor and is treated as one under this clause, whatever it is called.
Customer-authorized connections. Where Relae makes an API, export mechanism, or other connection method available, a third party the Customer authorizes to access its data through that method (for example by issuing it a key or credential) acts for the Customer, not for Relae, and is not a Sub-processor. An authenticated request through such a method is the Customer's documented instruction to disclose the data it returns, and once data is delivered in accordance with that instruction, Relae's processing responsibility for the delivered copy ends; what the authorized third party does with it is a matter between the Customer and that party, and the Customer is responsible for authorizing only parties it may lawfully disclose the data to. Relae remains responsible for the connection mechanism itself: that it authenticates properly, that a credential reaches only the issuing Customer's own data, and that the Customer can revoke a credential at any time. Nothing in this paragraph limits Relae's obligations for a failure of that mechanism.
Schedule 2: Sub-processors and connected data sources (convenience snapshot as of 14 July 2026; the live page is authoritative)
------------------- ---------------- ---------------- ---------------------------
**Function** **Provider** **Region** **Data and purpose**
Cloud database, Supabase ca-central-1 Primary data store,
auth, storage (Canada) authentication, file
storage for the Canadian
Region.
Application hosting Vercel Compute pinned Application hosting.
to Montreal Request compute for the
(yul1); global Canadian Region runs in
edge for content Canada; no Donor Data is
delivery stored at the edge.
Interactive AI Amazon Nova via Canada Donor-capture assistance,
AWS Bedrock (ca-central-1) coaching, thank-you
drafting, and the Ask Relae
assistant. Identifier
redaction applied before
calls; prompts are not used
to train models and are not
retained by the model
service.
AI and web research Anthropic API United States Used only for the opt-in
(consented / and web-search donor-research feature
entitlement-gated services (name and public
only) identifying context, never
the private record) and the
entitlement-gated funder
research (organization
names only). Contractual
no-training and
no-retention terms apply.
Connected event Eventbrite United States Where a Customer connects
data source its Eventbrite account, the
(optional, at the Platform reads event and
Customer's attendance data, which can
direction) include donor personal
information, into the
Customer's workspace.
Read-only; nothing is
written back.
Public registry CRA / Canada Charity-registry and
lookups open.canada.ca (government) public-filing lookups.
Relae sends only a charity
business number; no donor
personal information.
------------------- ---------------- ---------------- ---------------------------6. Cross-border flows
The standing cross-border characteristics of the service are: (a) the operating company is in Sweden, as described in clause 4; (b) the consented donor-research feature sends a prospect's name and public identifying context (entity type, city, education, and known employer, board, or company affiliations) with web-search queries to United States services, and never sends giving history, amounts, ratings, prospect types, tags, or notes; and (c) the entitlement-gated funder research sends organization names only to United States services. For each, Relae makes the disclosures applicable law requires, imposes protection materially equivalent to this DPA by contract, and, for personal information of Quebec residents, conducts the privacy assessment Law 25 requires. The donor-research flow operates only for organizations that have opted in, and the opt-in surface enumerates exactly what is and is not sent. If a government authority, court, or other third party demands access to Donor Data, in any country including Sweden or the United States, Relae will not disclose it except as legally required, will attempt to redirect the demand to the Customer as Controller, will challenge or seek to narrow overbroad demands where reasonably possible, will disclose only the minimum required, will notify the Customer promptly unless legally prohibited from doing so, and will keep a record of such demands.
7. Automated processing; the dedupe exception; per-donor AI consent
AI outputs are suggestions confirmed by a person, and no decision producing legal or similarly significant effects about a Donor is made by automated means alone. Two specifics are stated for completeness. First, the duplicate-record merge: where an organization turns it on (it is off by default), the Platform can automatically merge records it identifies as duplicates of the same person; merges are reversible, and this is the only automated record-altering process in the Platform. Second, per-donor AI access: for a real customer organization, the Ask Relae assistant works only with aggregate figures until the organization gives an explicit per-organization opt-in allowing the assistant to work with live individual donor records. That opt-in is the organization's instruction, as Controller, authorizing per-donor AI processing.
8. Assistance with Data-Subject requests
Donors direct their privacy requests to the Customer. Relae will provide reasonable assistance, taking into account the nature of processing, to help the Customer respond to access, correction, deletion, and withdrawal requests within legal timelines, including through export and deletion tools within the Platform.
9. Breach notification and incident records
Relae will notify the Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a breach of security safeguards affecting Donor Data, with the information then reasonably available, and will update the Customer as more becomes known. Relae will assist the Customer with the Customer's own reporting and notification obligations under PIPEDA and applicable provincial law, including Quebec Law 25. Relae maintains a documented breach-response procedure, and keeps a register of confidentiality incidents affecting Donor Data, including incidents that do not meet the threshold for notification, which it makes available to the Customer on reasonable request.
10. Audit
Relae will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, ordinarily by providing documentation, security summaries, or, when available, third-party reports. Given the small-vendor and small-charity relationship, on-site audits are not the default; a Customer with a specific, reasonable concern may request additional information or, at its cost and no more than once a year, a proportionate audit on reasonable notice.
11. Return and deletion
On termination, Relae will, at the Customer's choice, return or delete Donor Data within thirty (30) days after the export window described in the Master Subscription Agreement closes, except where law requires retention, and will delete remaining copies subject to that exception. Where the Customer has enabled receipt issuance, duplicate copies of issued receipts are part of the Customer's export, and the Customer, as the charity responsible for CRA record-keeping, is responsible for retaining its exported duplicates for the period CRA requires; Relae does not retain them on the Customer's behalf after return or deletion completes unless the parties agree otherwise in writing. Backups are overwritten on their ordinary cycle, not to exceed ninety (90) days, after which residual Donor Data in backups is no longer restored to live systems.
12. De-identified and anonymized data
Within the Services, Relae may de-identify Donor Data to operate features (for example, identifier redaction before an AI call). De-identified data remains Donor Data under this DPA. Anonymized aggregate data would be created only under the future Benchmark Cooperative (Document 8), only from opted-in Customers, and only at the anonymization standard in the Shared Definitions; no such data is created today.
Schedule 1: Security measures
These measures describe the current posture, stated to be accurate rather than aspirational.
- Regional data storage: the Canadian Region's data store is pinned to Supabase ca-central-1, with application compute in Montreal (yul1), so request processing for Canadian customers occurs in Canada.
- Tenant isolation enforced by row-level security, with each organization's workspace logically separated; the active organization is bound to the session and backstopped at the database layer.
- Encryption of Donor Data in transit (TLS) and at rest.
- Role-based access for Authorized Users, including officer-role gating on report and export routes; portal and shared-report surfaces strip donor personal information server-side and are viewer-scoped.
- Identifier redaction before AI model calls: roster names, emails, phone numbers, and addresses (Canadian postal formats, English and French street forms) are replaced with placeholders before prompts are sent, and reattached locally. Names of people not in the organization's records are not detected by the current redaction and can reach the in-region model, as described in Document 7.
- Least-privilege access for Relae personnel, bound by written confidentiality obligations, with operational access from Sweden subject to the same controls.
- A documented breach-response procedure and a register of confidentiality incidents (clause 9).
- No third-party advertising trackers, marketing pixels, session recording, or chat widgets anywhere in the Platform.
Operational commitments under confirmation: certain operational controls (multi-factor authentication enforcement, backup-restore testing cadence, and periodic access review) are being formalized as part of launch readiness and will be reflected here once confirmed, so that this Schedule never states more than is true.