Legal
Data Processing Agreement
Last updated: August 3, 2026 · Effective: August 3, 2026
Acceptance
This Data Processing Agreement ("DPA") is incorporated by reference into the Ollegacy Terms of Service. By using the Ollegacy platform to manage personal data of individuals located in the European Economic Area (EEA) or United Kingdom, the Organisation is deemed to have accepted this DPA as of the Effective Date above. No separate signature is required for standard processing; however, Organisations may request a countersigned copy by emailing privacy@ollegacy.com.
1. Parties and Definitions
This Data Processing Agreement is entered into between:
- "Data Controller" / "Organisation": the legal entity that has accepted the Ollegacy Terms of Service and uses the Service to manage a community portal for its members.
- "Data Processor" / "Ollegacy": Transversal Group LLC, incorporated in the State of Florida, United States, operating under the trade name "Ollegacy", which provides the Ollegacy SaaS platform and processes personal data on behalf of the Organisation.
For purposes of this DPA, the following terms have the following meanings:
- "Applicable Data Protection Law" means: (a) Regulation (EU) 2016/679 (GDPR) and all national implementing legislation; (b) the UK General Data Protection Regulation and the UK Data Protection Act 2018 (collectively, "UK GDPR"); and (c) any other applicable data protection or privacy legislation that applies to the processing activities under this DPA.
- "Personal Data" has the meaning given in Applicable Data Protection Law and refers specifically to personal data of the Organisation's Members and community users processed through the Service.
- "Processing" has the meaning given in Applicable Data Protection Law.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA — in particular, Members of the Organisation's community portal.
- "Sub-processor" means any third party engaged by Ollegacy to process Personal Data on behalf of the Organisation.
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries, as adopted by the European Commission in Decision 2021/914.
2. Subject Matter and Details of Processing
2.1 Subject Matter
Ollegacy processes Personal Data as necessary to provide the Ollegacy platform and associated services as described in the Terms of Service, and as further specified in this DPA.
2.2 Duration
Ollegacy processes Personal Data for the duration of the Organisation's active use of the Service, and for a retention period of up to 30 days following termination of the Organisation's account, after which Personal Data is permanently deleted (subject to legal retention obligations described in Section 9).
2.3 Nature of Processing
Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, erasure, and destruction of Personal Data to provide the Service features described in the Terms of Service.
2.4 Purpose of Processing
To deliver the Ollegacy community portal platform, including member profile management, event and meeting management, forum and support wall features, fundraising campaign facilitation, birthday tracking, transactional email notifications, and related features — solely as instructed by the Organisation.
2.5 Categories of Personal Data
- Identification data: full name, email address
- Authentication data: hashed password, OAuth identifiers (Google, LinkedIn)
- Profile data: profile photo, city/state/country, biography, professional story
- Demographic data: birthday month and day (not year), life stage, career stage
- Preference data: "open to" connection preferences, privacy settings
- Community activity data: forum posts and replies, event and meeting RSVPs, support wall posts, solidarity reactions, birthday wishes sent and received
- Fundraising data: fundraising page goals, donation amounts (pledge or payment), donor names
- Technical data: IP addresses (in server logs, retained max 90 days), login timestamps, first login date
2.6 Categories of Data Subjects
Members of the Organisation's community portal (including alumni, faith community members, professional network members, or other individuals admitted by the Organisation), and Organisation Admins to the extent their data is processed as part of the platform service.
3. Processor Obligations
3.1 Documented instructions
Ollegacy will process Personal Data only on documented instructions from the Organisation, as set out in this DPA and the Terms of Service. If Ollegacy is required by Applicable Data Protection Law to process Personal Data for another purpose, Ollegacy will inform the Organisation before such processing, unless the law prohibits such notification.
3.2 Confidentiality
Ollegacy will ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and have received appropriate data protection training. Ollegacy will not permit any person to process Personal Data unless that person is subject to those obligations.
3.3 Technical and organisational security measures
Ollegacy will implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 of the GDPR and as further described in Section 7 of this DPA.
3.4 Data subject rights assistance
Ollegacy will assist the Organisation in responding to Data Subject requests to exercise their rights under Applicable Data Protection Law (access, rectification, erasure, portability, objection, restriction), by making available the technical tools within the Service to fulfil those requests. Where a Data Subject contacts Ollegacy directly, Ollegacy will forward the request to the Organisation without undue delay. Ollegacy will provide reasonable additional assistance on request, at the Organisation's cost for any work beyond standard platform functionality.
3.5 Compliance assistance
Ollegacy will assist the Organisation in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Ollegacy.
3.6 No independent use
Ollegacy will not use Personal Data processed under this DPA for its own marketing, advertising, research, or any purpose beyond the provision of the Service to the Organisation. Ollegacy will not sell, rent, or otherwise make available Personal Data to any third party for that third party's own purposes.
4. Organisation Obligations
The Organisation represents, warrants, and undertakes that:
- It has and will maintain a lawful basis under Applicable Data Protection Law for collecting and directing the processing of Personal Data through the Service;
- It has provided and will maintain a privacy notice to Data Subjects (its Members) that accurately describes the processing activities carried out through the Service;
- It has obtained and will maintain any required consents from Data Subjects, including in respect of birthday data collection and any sensitive personal data;
- It will not instruct Ollegacy to process Personal Data in a manner that would violate Applicable Data Protection Law;
- It will respond to Data Subject requests within the timeframes required by Applicable Data Protection Law and will notify Ollegacy of any such requests that require Ollegacy's technical assistance;
- It will promptly update Ollegacy if its instructions change in a way that affects how Ollegacy processes Personal Data.
5. Sub-processors
5.1 General authorisation
The Organisation grants Ollegacy general written authorisation to engage the sub-processors listed in Schedule A of this DPA (and in Ollegacy's Privacy Policy at ollegacy.com/privacy) for the specific purposes described therein.
5.2 Sub-processor obligations
Before engaging any sub-processor, Ollegacy will enter into a written data processing agreement with that sub-processor imposing data protection obligations no less protective than those in this DPA. Ollegacy remains fully liable to the Organisation for the performance of each sub-processor's data protection obligations.
5.3 Notification of changes
Ollegacy will inform the Organisation of any intended changes to the list of sub-processors (additions or replacements) by updating the sub-processor list at ollegacy.com/privacy and notifying Organisation Admins via email at least 14 days before the change takes effect. The Organisation may object to a new sub-processor within 14 days of notification on reasonable, documented grounds relating to data protection. If the parties cannot resolve the objection, the Organisation may terminate the Service on written notice, without penalty for the remainder of the current billing period.
6. Security Incident Notification
6.1 Processor notification obligation
Without undue delay and, where feasible, within 48 hours of becoming aware of a Security Incident involving Personal Data processed under this DPA, Ollegacy will notify the Organisation. The notification will include, to the extent available at the time: (a) the nature of the Security Incident, including categories and approximate number of Data Subjects and Personal Data records affected; (b) the likely consequences of the Security Incident; (c) the measures taken or proposed to address the Security Incident and mitigate its effects.
6.2 Further information
Where the information listed in 6.1 cannot be provided simultaneously, Ollegacy may provide it in phases without undue further delay.
6.3 Controller's regulatory obligation
The Organisation acknowledges that it is solely responsible for determining whether and how to notify the relevant supervisory authority (under Article 33 GDPR, within 72 hours) and affected Data Subjects (under Article 34 GDPR). Ollegacy's notification to the Organisation under Section 6.1 does not constitute a determination that notification is required or that a reportable breach has occurred.
6.4 No admission
Nothing in this Section 6 constitutes an admission by Ollegacy of fault or liability in connection with any Security Incident.
7. Technical and Organisational Security Measures (Article 32 GDPR)
Ollegacy maintains the following technical and organisational measures, which may be updated from time to time to reflect improvements in security practice:
- Encryption in transit: All data transmitted between clients and Ollegacy's servers is encrypted using TLS 1.2 or higher (HTTPS enforced).
- Encryption at rest: The production database (PostgreSQL on Railway) and file storage (Backblaze B2) are encrypted at rest using industry-standard AES-256 or equivalent.
- Password hashing: All passwords are hashed using bcrypt with a work factor of 12 before storage. Plaintext passwords are never stored or logged.
- Access token management: Access tokens are short-lived (15-minute expiry). Refresh tokens are stored as HttpOnly, Secure cookies and are rotated on each use to limit the impact of token theft.
- OAuth CSRF protection: OAuth authentication flows (Google, LinkedIn) use cryptographically random, single-use, time-limited CSRF state tokens to prevent account hijacking.
- Rate limiting: All API endpoints are protected by distributed rate limiting backed by a Redis cluster, preventing brute-force, credential-stuffing, and denial-of-service attacks.
- Access control: Role-based access control is enforced for all operations. Multi-tenancy isolation ensures that Organisation data is strictly segregated at the database and application layer — no cross-tenant data access is possible through the application.
- Least privilege: Platform staff access to tenant data is restricted to the minimum necessary for legitimate support operations and is subject to access logging.
- Input validation: API inputs are validated and type-checked using schema validation (Zod) before processing, reducing injection attack surfaces.
- Dependency management: Software dependencies are reviewed for known vulnerabilities before deployment.
- Backup and recovery: Encrypted database backups are performed regularly. Backups are retained for up to 30 days.
- Infrastructure security: The production environment is hosted on Railway (US West), which maintains SOC 2 Type II compliance. Vercel (CDN) maintains SOC 2 Type II compliance. Both providers are subject to DPAs with Ollegacy.
8. International Data Transfers
8.1 Transfer to the United States
Personal Data processed under this DPA may be transferred to and stored in the United States, where Ollegacy's infrastructure and most sub-processors are located. The United States does not have an adequacy decision from the European Commission for general data transfers.
8.2 Transfer mechanisms — Ollegacy as processor
For transfers of Personal Data from the EEA to the United States made under this DPA, the parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor) in Commission Implementing Decision (EU) 2021/914 are hereby incorporated into this DPA by reference. For transfers from the United Kingdom, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs (as appropriate) applies. The parties agree that the details required to complete those templates are as follows:
- Data exporter: the Organisation (as described in the Organisation's account details)
- Data importer: Transversal Group LLC (Ollegacy)
- Categories of data subjects and personal data: as described in Section 2 of this DPA
- Frequency of transfer: continuous, for the duration of the Service
- Nature of processing: as described in Section 2 of this DPA
- Retention period: as described in Section 9 of this DPA
- Technical and organisational measures: as described in Section 7 of this DPA
8.3 Sub-processor transfers
Ollegacy ensures that transfers to sub-processors in third countries are covered by appropriate transfer mechanisms (SCCs or adequacy decisions) under Applicable Data Protection Law, as described in Section 5.2 and Schedule A.
9. Data Return and Deletion
9.1 Return or deletion on termination
Upon termination of the Organisation's Ollegacy account or upon written request, Ollegacy will, at the Organisation's choice: (a) return to the Organisation a complete export of all Personal Data processed under this DPA in a machine-readable format (JSON or CSV); or (b) permanently and irreversibly delete all such Personal Data. The Organisation may make this request within 30 days of account termination. After 30 days, Ollegacy will permanently delete all Personal Data associated with the terminated account without further notice.
9.2 Legal retention exception
Notwithstanding 9.1, Ollegacy may retain Personal Data to the extent required by Applicable Data Protection Law or other applicable law (for example, financial transaction records for 7 years as required by U.S. tax law). Such retained data will be processed only for the purposes of complying with the retention obligation and will be protected in accordance with this DPA.
9.3 Certification
Upon request, Ollegacy will provide written certification that all Personal Data has been deleted in accordance with this Section 9.
10. Audit Rights
10.1 Information and audit
Ollegacy will make available to the Organisation all information reasonably necessary to demonstrate compliance with this DPA. Ollegacy will allow for and contribute to audits, including inspections, conducted by the Organisation or an auditor mandated by the Organisation, no more than once per calendar year and upon at least 30 days' written notice.
10.2 Conditions
Any audit will be conducted during Ollegacy's normal business hours, in a manner that does not unreasonably interfere with Ollegacy's business operations, and subject to the Organisation's auditor entering into a reasonable confidentiality agreement with Ollegacy. The Organisation will bear all costs associated with such an audit.
10.3 Certification alternative
Ollegacy may satisfy its audit obligations by providing a current SOC 2 Type II report or equivalent third-party security certification covering the relevant processing, where available, in lieu of a direct audit.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Ollegacy Terms of Service. Where both parties are responsible for damage caused by a processing activity that violates Applicable Data Protection Law, each party shall be held liable for the damage attributable to its own actions or omissions.
12. Term and Termination
This DPA is effective as of the Effective Date and remains in force for as long as Ollegacy processes Personal Data on behalf of the Organisation under the Terms of Service. This DPA automatically terminates upon the deletion or destruction of all Personal Data in accordance with Section 9. The obligations set out in Sections 3, 6, 7, 9, and 10 survive termination.
13. Governing Law
Without prejudice to any rights of Data Subjects under Applicable Data Protection Law, this DPA is governed by the law of the State of Florida, United States. For EEA/UK Data Subjects, the incorporated SCCs and IDTA are governed by the law specified in those instruments.
Schedule A — Approved Sub-processors
The following sub-processors are approved as of the Effective Date of this DPA. Ollegacy will provide 14 days' prior notice of changes to this list.
| Sub-processor | Country | Purpose | Data Transferred | Transfer Mechanism |
|---|---|---|---|---|
| Railway Technologies, Inc. | United States | Cloud infrastructure hosting; PostgreSQL database; Redis cache | All Personal Data stored in the Ollegacy database | EU SCCs (Module 2); UK IDTA |
| Vercel, Inc. | United States | Frontend application hosting and CDN delivery | IP addresses (edge logs); session indicators | EU SCCs (Module 2); UK IDTA |
| Stripe, Inc. | United States | Payment processing for subscriptions and community donations | Billing email, subscription status, donation amounts, donor name | EU SCCs; Stripe DPA |
| Resend, Inc. | United States | Transactional email delivery | Recipient email address, recipient name, email content | EU SCCs (Module 2); UK IDTA |
| Backblaze, Inc. | United States | Cloud object storage for profile photos and media uploads | Profile photos and any other Member-uploaded media files | EU SCCs (Module 2); UK IDTA |
| Google LLC | United States | OAuth2 authentication ("Sign in with Google") | Name, email, Google account identifier (at sign-in only) | Google DPA / SCCs |
| LinkedIn Ireland Unlimited Company | Ireland / United States | OAuth2 authentication ("Sign in with LinkedIn") | Name, email, LinkedIn account identifier (at sign-in only) | LinkedIn DPA / SCCs |
Contact & Countersigned Copies
For questions about this DPA, to request a countersigned copy, or to submit a Data Subject rights request on behalf of your Members, contact us at:
Transversal Group LLC (operating as Ollegacy)
State of Florida, United States
Privacy & DPA: privacy@ollegacy.com
