ALUM.
Log inGet started

Organizations (annex to the Organization Agreement)

Data Processing Addendum

Version 1.0.0 · Effective 2026-07-13

On this page

Annex 1 to the ALUM Organization Agreement Last updated: [DATE]

This Data Processing Addendum ("DPA") forms part of the ALUM Organization Agreement between [ALUM LEGAL ENTITY NAME] ("ALUM", the "Processor") and the Organization (the "Controller"). It governs ALUM's processing of Organization Data on the Organization's behalf and is designed to satisfy Article 28 GDPR and the corresponding processor provisions of the Nigeria Data Protection Act 2023 (NDPA).

1. Definitions

"Data Protection Laws" means the EU GDPR, the UK GDPR, the NDPA 2023 and its subsidiary instruments, and any other data-protection law applicable to the processing. "Organization Data" means personal data processed by ALUM on the Organization's behalf within the Organization's Space, as described in Schedule 1. Other capitalized terms have the meanings in the Organization Agreement, the Terms of Service, or the applicable Data Protection Laws.

2. Roles and Scope

2.1. The Organization is the controller of Organization Data; ALUM is its processor. Each party is an independent controller of the platform-level data described in the Privacy Policy (accounts, identity verification, security, payments infrastructure, compliance).

2.2. This DPA applies for the duration of the Organization Agreement plus any wind-down period under Section 9.

3. Processor Obligations

ALUM shall:

3.1. process Organization Data only on the Organization's documented instructions — which are, collectively: this DPA, the Organization Agreement, and the Organization's lawful configuration and use of the Platform (role settings, fund settings, event settings, moderation actions, exports) — unless required otherwise by law, in which case ALUM will inform the Organization unless prohibited;

3.2. immediately inform the Organization if, in ALUM's opinion, an instruction infringes Data Protection Laws;

3.3. ensure persons authorized to process Organization Data are bound by confidentiality;

3.4. implement appropriate technical and organizational measures per Schedule 2;

3.5. assist the Organization, by appropriate technical and organizational measures and insofar as possible, in responding to data-subject requests (Section 6);

3.6. assist the Organization with its obligations regarding security, breach notification, data-protection impact assessments, and prior consultation, taking into account the nature of processing and information available to ALUM;

3.7. notify the Organization without undue delay after becoming aware of a personal-data breach affecting Organization Data, providing information reasonably required for the Organization's own notification obligations, and cooperating in remediation;

3.8. at the Organization's choice, delete or return Organization Data after the end of services (Section 9);

3.9. make available information necessary to demonstrate compliance with this DPA and allow for audits (Section 8).

4. Controller Obligations

The Organization shall: (a) ensure it has a lawful basis and has provided all required notices for the Organization Data it causes to be processed; (b) issue only lawful instructions; (c) configure roles, permissions, and fund/event settings responsibly; (d) not instruct ALUM to process special-category or children's data except where lawful and notified to ALUM; and (e) handle data it exports from the Platform in compliance with Data Protection Laws.

5. Sub-processors

5.1. The Organization grants general authorization for ALUM to engage sub-processors (hosting, payments, verification, communications, analytics, support tooling). The current list is at [SUB-PROCESSOR LIST LINK].

5.2. ALUM will provide [14] days' notice of intended additions or replacements (via the list page, email, or in-app notice). The Organization may object on reasonable data-protection grounds; if the objection cannot be resolved, the Organization may terminate the affected services under the Organization Agreement.

5.3. ALUM will impose data-protection obligations on sub-processors no less protective than this DPA and remains liable for their performance.

6. Data-Subject Requests

6.1. ALUM will forward to the Organization, without undue delay, any data-subject request it receives that concerns Organization Data, and will not respond substantively on the Organization's behalf except as instructed or required by law.

6.2. The Platform's self-service tools (profile editing, content deletion, membership withdrawal, export features) constitute part of ALUM's assistance. Additional assistance beyond self-service tools may be charged at reasonable rates where requests are excessive.

7. International Transfers

7.1. ALUM may transfer Organization Data internationally only with safeguards required by Data Protection Laws: adequacy decisions; the EU Standard Contractual Clauses (Module 2: controller-to-processor) and UK Addendum, which are incorporated by reference where they apply; and, for transfers governed by the NDPA, mechanisms consistent with the NDPA and NDPC guidance.

7.2. Schedule 1 serves as the description of processing for the purposes of the SCCs' annexes; Schedule 2 serves as the security annex.

8. Audits

8.1. ALUM will make available, on request and under confidentiality: summaries of relevant third-party certifications or audit reports, security documentation, and responses to reasonable written security questionnaires (no more than once per year absent a breach or regulatory requirement).

8.2. Where Data Protection Laws grant the Organization a right of on-site audit that cannot be satisfied under 8.1, an audit may be conducted by an independent auditor, on at least [30] days' notice, during business hours, no more than once per year, at the Organization's cost, without access to other customers' data.

9. Return and Deletion

9.1. Upon termination of the Organization Agreement, the Organization may export Organization Data using Platform tools during a wind-down period of [30] days.

9.2. After the wind-down period, ALUM will delete Organization Data within [90] days, except: (a) data ALUM must retain by law (retained in restricted form); (b) data in encrypted backups, which is deleted per backup rotation cycles not exceeding [180] days; and (c) data in which ALUM is an independent controller (per the Privacy Policy), which ALUM retains under its own retention schedule.

10. Liability

Liability under this DPA is subject to the limitations and exclusions in the Organization Agreement, except where Data Protection Laws provide otherwise. Each party is responsible for administrative fines imposed on it corresponding to its own violations.


Schedule 1 — Description of Processing

  • Subject matter and duration: processing of Organization Data to provide the Platform to the Organization, for the term of the Organization Agreement plus wind-down.
  • Nature and purposes: hosting, storage, transmission, display, organization, analysis (aggregate), backup, and deletion of data within the Organization's Space; delivery of Modules (membership management, funds and donations, events and attendance, posts and communications, and future Modules per the functional framework of the Terms of Service).
  • Categories of data subjects: the Organization's members and prospective members; donors to the Organization's funds (including Guest Donors); event invitees and attendees; the Organization's role-holders.
  • Categories of personal data: identification and contact data (name, email, phone, profile details); membership and role data; donation and dues records (amounts, timestamps, fund, anonymity preference); event participation data; content and communications within the Space; related metadata.
  • Special categories: none intended; membership of certain organization types (e.g., religious bodies) may itself constitute or reveal special-category data, for which the Organization is responsible as controller.
  • Frequency: continuous.

Schedule 2 — Technical and Organizational Measures

  • Encryption of data in transit (TLS 1.2+) and at rest for sensitive data stores.
  • Logical multi-tenant isolation of Organization Spaces; per-organization access scoping.
  • Role-based access control for both platform personnel and Organization role-holders; least-privilege administration; MFA for privileged access.
  • Secure software-development lifecycle, code review, dependency and vulnerability management, penetration testing at reasonable intervals.
  • Logging and monitoring of administrative and financial actions; anomaly and fraud detection.
  • Backup and disaster-recovery procedures with defined recovery objectives; encrypted backups.
  • Vendor due-diligence and contractual controls for sub-processors.
  • Personnel confidentiality undertakings and security training.
  • Incident-response plan with defined escalation and notification workflow.
  • Physical security of data centers via certified cloud providers.

[Adjust Schedule 2 to reflect ALUM's actual implemented measures before publication.]

Questions about these documents? Contact legal@alumweb.org.