Legal · data processing
Data Processing Agreement
The terms on which we process personal data as your processor, where your organisation is the controller.
Last updated
Between:
ThirdSectorBee Ltd, a company incorporated in England and Wales (company number 17359072), whose registered office is at 124 City Road, London, EC1V 2NX (“ThirdSectorBee”, “we”, “us” or the “Processor”);
and
You, a customer of ThirdSectorBee identifiable by the details supplied when you signed up for the service. **(the “Customer” or the “Controller**”).
Each a “Party” and together the “Parties”.
Effective Date: 30/07/2026
1. Background
1.1 The Customer has subscribed to, or is evaluating, the ThirdSectorBee platform — a SaaS application that unifies fundraising, programme delivery, finance and impact data for nonprofit organisations (the “Services”)
1.2 In delivering the Services, ThirdSectorBee will process personal data on behalf of the Customer. This Data Protection Agreement (the “DPA”) sets out the terms on which that processing takes place and forms part of the terms and conditions of use.
1.3 In the event of any conflict between this DPA and the terms and conditions of use in relation to the processing of personal data, this DPA prevails.
2. Definitions
2.1 In this DPA, the following terms have the meanings set out below. Other capitalised terms have the meanings given to them in the terms and conditions of use or in the UK GDPR.
-
“Data Protection Laws” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended), and any other applicable laws relating to the protection of personal data, in each case as in force and as amended from time to time. \
-
“UK GDPR” means the United Kingdom General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018. \
-
“Customer Personal Data” means any personal data (as defined in the UK GDPR) processed by ThirdSectorBee on behalf of the Customer under the terms and conditions of use. \
-
“Sub-processor” means any third party engaged by ThirdSectorBee to process Customer Personal Data. \
-
“Trial Tenant” means an isolated, time-limited instance of the Services provisioned for the Customer for the purpose of evaluating the Services prior to entering into a paid subscription. \
-
“Personal Data Breach”, “Data Subject”, “Processor”, “Controller”, “Processing” (and cognate terms), and “Supervisory Authority” have the meanings given in the UK GDPR. \
3. Status and roles of the Parties
3.1 The Parties acknowledge and agree that, in respect of the processing of Customer Personal Data under the terms and conditions of use:
(a) the Customer is the Controller; and
(b) ThirdSectorBee is the Processor.
3.2 The Customer is responsible for determining the purposes and means of the processing of Customer Personal Data, for the lawfulness of that processing, and for ensuring that it has all necessary rights, consents, lawful bases, and notices in place to enable ThirdSectorBee to process Customer Personal Data as contemplated by the terms and conditions of use.
3.3 ThirdSectorBee will process Customer Personal Data only on the documented instructions of the Customer, including as set out in the terms and conditions of use and this DPA, unless required to do otherwise by applicable law. Where such a legal requirement applies, ThirdSectorBee will inform the Customer of that requirement before processing, unless that law prohibits such notification on important grounds of public interest.
3.4 ThirdSectorBee will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Details of processing (Schedule 1)
4.1 The subject matter, nature and purpose of the processing, the duration, the types of personal data and the categories of data subjects are set out in Schedule 1 (Details of Processing).
5. Confidentiality and non-disclosure
5.1 ThirdSectorBee will treat all Customer Personal Data, and all other Confidential Information of the Customer that comes into its possession through the Services, as strictly confidential.
5.2 ThirdSectorBee will not:
(a) disclose Customer Personal Data to any third party except as expressly permitted by this DPA or the terms and conditions of use, or as required by law (and in such case, will inform the Customer before disclosure where lawfully permitted to do so);
(b) use Customer Personal Data for any purpose other than performing the Services or as expressly instructed by the Customer; or
(c) sell, rent, licence, or otherwise commercialise Customer Personal Data, in whole or in part, including by way of using it (or any derivative of it) to train or improve any artificial intelligence or machine learning model that is made available outside the Customer’s tenant.
5.3 ThirdSectorBee will ensure that all of its personnel, contractors and Sub-processors authorised to process Customer Personal Data:
(a) are bound by written obligations of confidentiality at least as protective as those set out in this clause 5, which obligations survive the termination of their engagement;
(b) are appropriately trained on their data protection obligations; and
(c) access Customer Personal Data only on a need-to-know basis and only to the extent necessary to perform their role.
5.4 The obligations of confidentiality in this clause 5 do not apply to information that:
(a) is or becomes publicly available other than through breach of this DPA;
(b) was lawfully in ThirdSectorBee’s possession before disclosure by the Customer, without obligation of confidentiality;
(c) is independently developed by ThirdSectorBee without reference to Customer Personal Data; or
(d) is required to be disclosed by law, court order, or regulatory authority, in which case ThirdSectorBee will (where lawful) notify the Customer promptly so that the Customer may seek a protective order.
5.5 The confidentiality obligations in this clause 5 survive termination or expiry of the terms and conditions of use and this DPA indefinitely in respect of Customer Personal Data and special category data, and for a period of five (5) years after termination in respect of other Confidential Information.
6. Security measures
6.1 ThirdSectorBee will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to data subjects.
6.2 As a minimum, ThirdSectorBee will:
(a) encrypt Customer Personal Data in transit (using TLS 1.2 or higher) and at rest;
(b) operate role-based access controls with multi-factor authentication for all administrative access;
(c) maintain logical separation between Customer tenants such that one Customer’s data cannot be accessed from another Customer’s tenant;
(d) maintain audit logging of access to and material changes affecting Customer Personal Data;
(e) operate documented backup, disaster recovery, and business continuity procedures;
(f) carry out regular vulnerability scanning and remediation, and periodic penetration testing of the Services; and
(g) operate documented incident response procedures.
6.3 A more detailed description of the technical and organisational measures is set out in Schedule 2 (Technical and Organisational Measures). ThirdSectorBee may update these measures from time to time, provided that the level of protection is not materially reduced.
7. Sub-processors
7.1 The Customer provides general authorisation for ThirdSectorBee to engage Sub-processors in connection with the provision of the Services, subject to this clause 7.
7.2 The list of Sub-processors engaged at the Effective Date is set out in Schedule 3 (Sub-processors), and is also available on request.
7.3 ThirdSectorBee will:
(a) impose written contractual obligations on each Sub-processor that are no less protective than those set out in this DPA;
(b) remain fully liable to the Customer for the acts and omissions of its Sub-processors; and
(c) give the Customer at least thirty (30) days’ prior written notice of the addition or replacement of any Sub-processor.
7.4 The Customer may object on reasonable data protection grounds to any new Sub-processor within fifteen (15) days of notice. If the Parties cannot resolve the objection within a further fifteen (15) days, the Customer may terminate the affected Services on written notice, with a pro-rata refund of pre-paid Fees for the unused portion of the term.
8. International transfers
8.1 ThirdSectorBee will not transfer Customer Personal Data outside the United Kingdom (or, where applicable, the EEA) without ensuring that an appropriate transfer mechanism under Data Protection Laws is in place — for example, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or transfer to a jurisdiction subject to UK adequacy regulations.
8.2 Details of any international transfers (including the location of Sub-processors that process Customer Personal Data outside the UK) are set out in Schedule 3.
9. Assistance to the Customer
9.1 Taking into account the nature of processing and the information available to ThirdSectorBee, ThirdSectorBee will provide reasonable assistance to the Customer in:
(a) responding to requests from Data Subjects to exercise their rights under the UK GDPR (including rights of access, rectification, erasure, restriction, portability, and objection);
(b) carrying out data protection impact assessments and any associated consultations with the Information Commissioner’s Office (“ICO”);
(c) demonstrating compliance with the Customer’s obligations under Data Protection Laws; and
(d) responding to Personal Data Breaches, including in accordance with clause 10.
9.2 ThirdSectorBee may charge a reasonable fee for assistance that is materially in excess of the standard support included with the Services, provided it has given the Customer a fee estimate before incurring such charges.
10. Personal Data Breach notification
10.1 ThirdSectorBee will notify the Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of any Personal Data Breach affecting Customer Personal Data.
10.2 Such notice will, to the extent known at the time and supplemented as more information becomes available, include:
(a) a description of the nature of the breach, including (where possible) the categories and approximate number of Data Subjects and records concerned;
(b) the likely consequences of the breach;
(c) the measures taken or proposed to be taken to address the breach and mitigate its possible adverse effects; and
(d) the contact details of a person from whom further information can be obtained.
10.3 Notification of, or response to, a Personal Data Breach by ThirdSectorBee will not be construed as an acknowledgement of fault or liability.
11. Audit rights
11.1 ThirdSectorBee will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR.
11.2 The Customer may, on at least thirty (30) days’ written notice and no more than once in any twelve (12) month period (except where there has been a Personal Data Breach affecting the Customer or where required by a Supervisory Authority), audit ThirdSectorBee’s compliance with this DPA. Audits will:
(a) be conducted during normal business hours;
(b) be carried out by the Customer or an independent third-party auditor reasonably acceptable to ThirdSectorBee, who is bound by appropriate confidentiality obligations;
(c) not unreasonably interfere with ThirdSectorBee’s operations; and
(d) be at the Customer’s cost, unless the audit reveals a material breach of this DPA, in which case ThirdSectorBee will bear the Customer’s reasonable costs.
11.3 ThirdSectorBee may satisfy audit requests by providing recent third-party audit reports, certifications (such as ISO 27001 or SOC 2, once obtained), or completed information security questionnaires, where these reasonably address the matters that would otherwise be covered by the audit.
12. Trial Tenants: live data and deletion on exit
12.1 The Parties acknowledge that the Customer may, in order to meaningfully evaluate the Services, choose to load live or production personal data into a Trial Tenant. This clause 12 sets out how Customer Personal Data is handled in that context.
12.2 Status during trial. During the trial period, the Customer remains the Controller and ThirdSectorBee remains the Processor of any Customer Personal Data loaded into the Trial Tenant. All other terms of this DPA — including confidentiality (clause 5), security (clause 6), sub-processors (clause 7), and breach notification (clause 10) — apply equally to processing in the Trial Tenant.
12.3 Customer responsibilities. The Customer is responsible for ensuring that it has a lawful basis to load live personal data into the Trial Tenant and that doing so is consistent with the privacy notices and any consents given to Data Subjects. The Customer should consider whether minimised, redacted, or pseudonymised data would be sufficient for evaluation purposes. ThirdSectorBee will, on request, provide reasonable guidance on data minimisation in trial scenarios.
12.4 Isolation. Each Trial Tenant is provisioned as a logically isolated environment. Customer Personal Data in a Trial Tenant is not used for any purpose other than enabling the Customer’s evaluation of the Services and the provision of associated support, and is not commingled with the data of any other customer.
12.5 Trial duration. Unless otherwise agreed in writing, a Trial Tenant remains active for the trial period set out in the terms and conditions of use or Trial Agreement (the “Trial Period”). The Trial Period may be extended only by written agreement (which may include email).
12.6 Outcome at end of Trial Period. Within fourteen (14) days after the end of the Trial Period, the Customer must notify ThirdSectorBee in writing whether it:
(a) proceeds to a paid subscription, in which case the Trial Tenant may, with the Customer’s instruction, be promoted to a production tenant and the Customer Personal Data retained in accordance with the terms and conditions of use; or
(b) does not proceed, in which case clause 12.7 applies.
If the Customer does not give notice within that period, ThirdSectorBee will treat the trial as not proceeding and clause 12.7 applies.
12.7 Deletion process where the Customer does not proceed. Where the Customer does not proceed:
(a) ThirdSectorBee will, at the Customer’s option (to be specified in writing), either:
(i) export the Customer Personal Data from the Trial Tenant in a structured, commonly used, machine-readable format (CSV or JSON) and provide it to the Customer via a secure transfer mechanism; or
(ii) delete the Customer Personal Data from the Trial Tenant without exporting it;
(b) Default position. If the Customer does not specify a preference, ThirdSectorBee will proceed to delete the Customer Personal Data without exporting it;
(c) Deletion timeline. ThirdSectorBee will complete the deletion (and, if requested, the export) within thirty (30) days of the end of the Trial Period or the Customer’s instruction, whichever is later;
(d) Scope of deletion. Deletion covers Customer Personal Data held in the live Trial Tenant database, file storage, search indices, caches, application logs to the extent they contain Customer Personal Data, and any working copies held by ThirdSectorBee personnel. Routine encrypted backups containing Customer Personal Data will be overwritten in the ordinary course of the backup cycle, which is no longer than thirty-five (35) days; until overwritten, backups remain subject to the confidentiality and security obligations in this DPA and will not be restored except as required by law;
(e) Certification. On completion of deletion, ThirdSectorBee will, on request, provide the Customer with written confirmation that deletion has been carried out in accordance with this clause 12.7;
(f) Retention exceptions. ThirdSectorBee may retain Customer Personal Data only to the extent, and for as long as, required by applicable law, in which case ThirdSectorBee will:
(i) inform the Customer of the legal requirement and the data retained;
(ii) protect the retained data in accordance with this DPA; and
(iii) process it only for the purposes of, and to the extent required by, that legal requirement.
12.8 No charge for deletion. ThirdSectorBee will not charge the Customer for the deletion process described in clause 12.7. A reasonable fee may apply to bespoke export formats outside CSV or JSON, agreed with the Customer in advance.
13. Return and deletion on termination of a paid subscription
13.1 On termination or expiry of the terms and conditions of use (other than in respect of a Trial Tenant, which is governed by clause 12), ThirdSectorBee will, at the Customer’s choice expressed in writing within thirty (30) days of termination:
(a) return all Customer Personal Data to the Customer in a structured, commonly used, machine-readable format; or
(b) delete all Customer Personal Data,
and in either case will then delete all existing copies, save as required by applicable law. Clauses 12.7(d) (scope of deletion), 12.7(e) (certification), and 12.7(f) (retention exceptions) apply equally to deletion under this clause 13.
14. Liability
14.1 The liability of each Party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the terms and conditions of use.
14.2 Nothing in this DPA limits or excludes any liability that cannot be limited or excluded by law, including liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or liability under section 168 of the Data Protection Act 2018.
15. Term and termination**
15.1 This DPA takes effect on the Effective Date and continues for the duration of the terms and conditions of use.
15.2 Clauses that by their nature should survive termination (including clauses 5 (Confidentiality), 12.7 (Deletion on trial exit), 13 (Return and deletion), and 14 (Liability)) will survive.
16. General
16.1 Notices. Notices under this DPA must be given in writing to the addresses set out at the start of this DPA, or to such other address as a Party notifies in writing. Email notice is sufficient where the relevant clause expressly permits it.
16.2 Variation. No variation of this DPA is effective unless in writing and signed by both Parties.
16.3 Severance. If any provision of this DPA is held to be unenforceable, the remaining provisions continue in full force.
16.4 Governing law and jurisdiction. This DPA is governed by the laws of England and Wales, and the Parties submit to the exclusive jurisdiction of the courts of England and Wales.
Continued use of the ThirdSectorBee software shall be deemed to imply acceptance of this agreement.
Schedule 1 — Details of Processing
Subject matter of the processing: The provision of the ThirdSectorBee SaaS platform, which unifies fundraising, programme delivery, finance, and impact data for the Customer.
Duration of the processing: For the term of the terms and conditions of use, plus any retention period required by clause 12 (Trial Tenants), clause 13 (Return and Deletion), or by law.
Nature and purpose of the processing: Hosting, storing, transmitting, displaying, indexing, backing up, and otherwise processing Customer Personal Data as necessary to provide the Services and associated support to the Customer.
Types of personal data: (to be confirmed with each Customer; typically includes)
- Identification and contact data of supporters, donors, members, volunteers, trustees, employees, beneficiaries, programme participants, and prospects (name, postal address, email, phone, date of birth, identifiers);
- Financial and transactional data (donation history, payment metadata — but not full card numbers, which are handled by the Customer’s or ThirdSectorBee’s PCI-compliant payment provider);
- Communication preferences and consent records;
- Engagement and relationship data (interactions, notes, segmentation);
- Programme participation and outcomes data;
- Where the Customer chooses to record it: special category data (for example, health information about beneficiaries) or criminal offence data — only where the Customer has confirmed a lawful basis for doing so and has notified ThirdSectorBee in writing.
Categories of Data Subjects:
- The Customer’s supporters, donors, members, and prospects;
- The Customer’s beneficiaries and programme participants;
- The Customer’s volunteers, trustees, staff, and contractors;
- Other individuals whose personal data the Customer chooses to load into the Services.
Schedule 2 — Technical and Organisational Measures
A summary of the technical and organisational measures implemented by ThirdSectorBee. [To be completed and maintained — typical content includes:]
- Encryption: TLS 1.2+ in transit; AES-256 at rest.
- Access control: Role-based access controls; MFA mandatory for all administrative access; principle of least privilege; quarterly access reviews.
- Tenant isolation: Logical separation of Customer tenants at the application and data layer.
- Authentication: Customer-side SSO support; password complexity and rotation policy; brute-force protection.
- Network security: Cloud infrastructure hosted in UK regions; security groups and private networking; web application firewall.
- Logging and monitoring: Audit logs of access and material changes; centralised log aggregation; alerting on anomalous activity.
- Backups: Encrypted automated backups; documented retention; tested restoration procedures.
- Vulnerability management: Regular vulnerability scanning; dependency monitoring; documented patching SLAs; periodic penetration testing.
- Personnel: Background checks where lawful; written confidentiality obligations; data protection and security training on induction and at least annually.
- Incident response: Documented incident response plan covering detection, containment, eradication, recovery, notification, and post-incident review.
- Sub-processor governance: Due diligence on Sub-processors; written contractual flow-down of obligations.
- Physical security: Reliance on the physical security controls of the underlying cloud infrastructure provider (which holds relevant certifications such as ISO 27001 and SOC 2).
Schedule 3 — Sub-processors
The Sub-processors listed below are engaged at the Effective Date. ThirdSectorBee will maintain an up-to-date list and notify the Customer of changes in accordance with clause 7.
| Sub-processor | Purpose | Location of processing | Transfer mechanism (if outside UK) |
| Amazon Web Services EMEA SARL | Cloud infrastructure hosting | UK (eu-west-2, London) | N/A |
| Stripe Payments UK Ltd | Billing and payment processing | UK / EEA | Standard Contractual Clauses + UK Addendum, as applicable |
| Amazon SES | Transactional email delivery | UK (eu-west-2, London) | N/A |
| Pendo | User analytics and support | UK / EEA | N/A |
| Algolia | Full-text search | UK / EEA | N/A |
— End of Data Protection Agreement —