KidsCircleKidsCircle

Data Processing Agreement

KidsCircle — Between KidsCatalyst (Processor) and Customer (Controller)

Last updated: 2026-07-02

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between KidsCatalyst (a limited liability company in formation), together with Kevin Rogers and Marsha Rogers (collectively, “KidsCatalyst” or “Processor”), and the organization that uses the KidsCircle platform (the “Customer” or “Controller”). It governs the processing of Personal Data that Processor performs on the Controller’s behalf. If the Agreement and this DPA conflict on data-protection matters, this DPA controls. It is effective when the Controller accepts the Agreement.

1. Definitions

  • “Applicable Data Protection Laws” means all privacy and data-protection laws that apply, which may include U.S. state privacy laws (such as the Texas Data Privacy and Security Act), the EU/UK GDPR where relevant, and the laws of countries where Data Subjects are located.
  • “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Sub-processor” have the meanings given under Applicable Data Protection Laws (a “service provider” under U.S. laws is treated as a Processor).
  • “Customer Personal Data” means Personal Data in Customer Data that Processor processes on the Controller’s behalf, including data about the Controller’s children, staff, and sponsors.

2. Roles and Scope

The Controller is the controller of Customer Personal Data, and Processor is the processor acting on the Controller’s behalf. Processor will process Customer Personal Data only to provide the Service and only on the Controller’s documented instructions, unless required by law (in which case Processor informs the Controller unless legally prohibited). Details of processing are in Annex A.

3. Processor Obligations

  • process only on the Controller’s documented instructions, and flag any instruction believed to violate the law;
  • ensure personnel authorized to process the data are bound by confidentiality;
  • implement the technical and organizational security measures in Annex C;
  • assist the Controller in responding to Data Subject requests;
  • assist with security, breach notification, and data-protection impact assessments;
  • not sell the data or use it for advertising or any purpose other than providing the Service; and
  • delete or return the data at the end of the Agreement (Section 8).

4. Sub-processors

The Controller provides general authorization for Processor to engage sub-processors to support the Service; the current list is maintained on our Sub-processors page. Processor imposes data-protection obligations on each sub-processor substantially similar to these, remains responsible for their performance, and gives notice of intended additions or replacements with a reasonable opportunity to object on reasonable data-protection grounds.

5. Data Subject Rights

Taking into account the nature of processing, Processor assists the Controller by appropriate measures, insofar as possible, in fulfilling the Controller’s obligation to respond to Data Subject requests. If Processor receives a request directly, it refers the Data Subject to the Controller unless legally required to act.

6. Personal Data Breach

Processor notifies the Controller without undue delay after becoming aware of a breach affecting Customer Personal Data, provides reasonably available information to help the Controller meet its obligations, and takes reasonable steps to mitigate and remediate.

7. International Transfers

Where a cross-border transfer requires a transfer mechanism under Applicable Data Protection Laws, the parties cooperate to put an appropriate mechanism in place (for example, the EU/UK Standard Contractual Clauses), incorporated by reference where they apply.

8. Return or Deletion

On termination, and following any export window in the Agreement, Processor deletes or returns Customer Personal Data at the Controller’s choice and deletes existing copies unless retention is required by law; backups are deleted in the ordinary backup cycle. See our Data Retention & Deletion practices in the Privacy Policy.

9. Audits and Records

Processor makes available information reasonably necessary to demonstrate compliance and allows for reasonable audits, subject to reasonable confidentiality, security, and notice limitations; it may satisfy this by providing security documentation where available.

10. Children’s Personal Data

Customer Personal Data may include information about children. The Controller is responsible for obtaining all required consents and legal bases. Processor processes such data only to provide the Service, applies data-minimization and retention limits, and maintains a written information security program.

11. Liability & 12. Governing Law

Each party’s liability under this DPA is subject to the limitations in the Agreement. This DPA is governed by the law specified in the Agreement (the State of Texas), except that where the GDPR or another mandatory law applies to a given processing activity, that law governs to the extent required.

Annex A — Details of Processing

  • Subject matter: provision of the KidsCircle sponsorship-management Service.
  • Duration: the term of the Agreement, plus any export/deletion window.
  • Nature/purpose: hosting, storage, transmission, display, and management of sponsorship communications (letters, photos, emails).
  • Data types: names; contact details; photos; letters/message content; birthdays; school and sponsorship details; account and usage data.
  • Data subjects: the Controller’s sponsored children and staff; sponsors/donors; and the Controller’s authorized users.

Annex B — Sub-processors

See the current Sub-processors list.

Annex C — Security Measures

  • role-based, least-privilege access controls for authorized users;
  • encryption of Personal Data in transit;
  • passwordless magic-link authentication;
  • tenant-scoped isolation in a multi-tenant architecture — every request scoped to the organization with server-side authorization, plus database row-level security enabled as a deny-by-default backstop;
  • reputable infrastructure and sub-processors with their own security programs;
  • logging and monitoring of access and activity;
  • regular backups; and
  • a written information security program reviewed periodically.

Organizations that require a signed/countersigned copy of this DPA can request one at hello@kidscircle.net.