Data Processing Addendum

Effective October 2, 2026

The terms under which Conferus processes personal data on behalf of the organizations that use it.

1. Parties and scope

This Data Processing Addendum ("DPA") forms part of the Organization Representative Agreement and Acceptable Use Policy (the "Agreement") between Night Raven Enterprises LLC, a New Mexico limited liability company doing business as Conferus ("Conferus"), and the organization that accepts it (the "Organization"). It applies to personal data that Conferus processes on the Organization's behalf in providing the Service ("Organization Personal Data"). Terms not defined here have the meaning given in the Agreement or in applicable data protection law.

2. Roles

The Organization is the controller (or "business") of Organization Personal Data and Conferus is its processor (or "service provider"). The Organization is responsible for having a lawful basis and any notices and consents needed to collect Organization Personal Data and to have Conferus process it.

3. Processing on instructions

Conferus will process Organization Personal Data only to provide the Service and on the Organization's documented instructions. The Agreement, this DPA and the Organization's use and configuration of the Service are its complete instructions. Conferus will tell the Organization if it believes an instruction violates applicable law, unless the law prohibits that.

Conferus will not sell or share Organization Personal Data, retain, use or disclose it for any purpose other than providing the Service (or outside the direct business relationship with the Organization), or combine it with personal data from other sources except as the Service requires and the law permits.

4. Confidentiality

Conferus will ensure that anyone it authorizes to process Organization Personal Data is bound by a duty of confidentiality and accesses it only as needed to provide, support or secure the Service.

5. Security

Conferus will implement and maintain appropriate technical and organizational measures to protect Organization Personal Data, including those in Annex 2. Conferus may update these measures as long as the overall level of protection is not reduced.

6. Subprocessors

The Organization authorizes Conferus to engage the subprocessors listed on the Conferus Subprocessors page (conferus.net/legal/subprocessors). Conferus will bind each subprocessor by a written agreement with data protection obligations no less protective than this DPA, and remains responsible for its subprocessors' performance.

Conferus will notify the Organization by email at least 30 days before a new subprocessor begins processing Organization Personal Data. The Organization may object on reasonable data protection grounds within that period; the parties will discuss the objection in good faith, and if it cannot be resolved the Organization may cancel the affected Service without penalty.

7. Requests from individuals

Most requests can be handled directly in the Service: the Organization can view, correct and export member records, and delete or archive them. Taking into account the nature of the processing, Conferus will help the Organization respond to requests from individuals to exercise their rights. If Conferus receives such a request directly, it will refer the individual to the Organization and will not respond itself except to confirm the referral, unless the law requires otherwise.

8. Personal data breaches

Conferus will notify the Organization without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Organization Personal Data. The notice will describe, as far as then known, the nature of the breach, the data and individuals affected, its likely consequences and the measures taken or proposed, and Conferus will provide updates as more is learned. Conferus will reasonably help the Organization meet its own notification obligations. Notice is not an admission of fault.

9. Assessments and consultations

Conferus will provide reasonable information the Organization needs to carry out data protection impact assessments and any prior consultations with supervisory authorities about the Service.

10. Return and deletion

While its subscription is active, the Organization can export its member records and its accounting journal from the Service, and may ask Conferus for a complete copy of its data. When the subscription ends, Conferus keeps Organization Personal Data for 90 days so the Organization can reactivate or ask for its data, and then deletes it, unless the law requires Conferus to keep it. Copies in backups are deleted as the backups expire. The Organization may ask for earlier deletion by writing to privacy@conferus.net.

11. Audits

Conferus will make available the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and answers to reasonable security questionnaires (security@conferus.net). If that information is not enough to meet a legal requirement, the Organization may audit Conferus's compliance, at its own cost, no more than once a year, on at least 30 days' written notice, during business hours, in a way that does not disrupt the Service or compromise other customers' data, and subject to confidentiality.

12. International transfers

Conferus and its subprocessors process Organization Personal Data in the United States. Where the law that applies to the Organization restricts such transfers (for example the GDPR), the parties agree that the applicable standard contractual clauses approved for that purpose are incorporated by reference, with the Organization as data exporter and Conferus as data importer, and the details of processing in Annex 1.

13. Liability, term and precedence

Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA lasts as long as Conferus processes Organization Personal Data. If this DPA conflicts with the Agreement on data protection, this DPA controls. The English version controls over any translation. Notices under this DPA go to legal@conferus.net.

Annex 1 — Details of processing

  • Subject matter and duration: providing the Service for the term of the Agreement and the retention period in Section 10.
  • Nature and purpose: storing, organizing, displaying, transmitting (including sending email on the Organization's behalf), analyzing and deleting data to provide membership, dues, events, donations, communications and accounting features.
  • Categories of individuals: the Organization's members, prospective members, donors, event guests, contacts, contractors, and its staff users.
  • Categories of personal data: names; contact details (email, phone, mailing address) and contact preferences; photos; member numbers, levels and status; dues, payment, donation and event records; communications sent through the Service; for contractors, the last four digits of the taxpayer number.
  • Special categories: none are required by the Service. Membership in some organizations (for example a religious or trade union organization) may itself reveal such information; the Organization is responsible for its lawful basis.

Annex 2 — Technical and organizational measures

  • Encryption of data in transit (TLS) and at rest by the hosting provider.
  • Separation of each organization's data by row-level security rules enforced in the database.
  • Role-based access for each organization's staff, with permissions set by its administrators.
  • Passwords stored only as salted hashes; login rate limits and account lockout after repeated failed attempts.
  • Rate limits on public forms and sensitive actions.
  • An append-only activity log of financial changes, and an audit log of platform administrator actions.
  • Month closing that locks financial records for closed periods.
  • Card and bank account numbers handled only by Stripe, never stored by Conferus.
  • Automated review of bulk emails and public content, and link scanning, to prevent abuse.
  • Error monitoring and alerting.
  • Managed database backups by the hosting provider.
  • Access to production systems limited to authorized personnel.

Annex 3 — Subprocessors

The current list of subprocessors, their purpose and location is published at conferus.net/legal/subprocessors and forms part of this DPA.

Questions? Write to legal@conferus.net.