FNDData Processing Agreement

Documents · Agreements

Data Processing Agreement

Art. 28 GDPR. The organization is the controller, FND is the processor.

Version
v2.0
In force since
1 July 2026
Last updated
1 July 2026
Contents
14 · 9 min read

In short

This page is the standing agreement and is part of the Terms of Service.

Need it on paper with your organization's details and our signature? Generate it at /dpa/sign in two minutes.

Sub-processors are listed at /subprocessors and change only with 30 days' notice.

Participant data stays in the EU; no participant data ever reaches Stripe or our mail provider.

Definitions

Controller
The partner organization, which decides why and how participant data is processed.
Processor
FND, which processes that data only on the controller's documented instructions.
Personal data
As defined in Art. 4 GDPR, limited here to the categories in clause 4.
Sub-processor
A third party engaged by FND to process personal data on the controller's behalf.
  1. 1.Parties and roles

    For participant data, the partner organization is the controller and FND is the processor under Art. 28 GDPR. For FND's own billing, sales and website data, FND is a controller in its own right, governed by the Privacy Policy rather than by this agreement.

  2. 2.Subject matter and duration

    FND processes personal data solely to provide the service described in the Terms of Service, for as long as the organization's pass is active, plus the retention periods published at /retention.

  3. 3.Instructions

    FND processes personal data only on the controller's documented instructions, which consist of the Terms of Service, the settings the organization chooses in the cabinet, and any further written instruction it sends us.

    1. 3.1We never process participant data for advertising, profiling, resale, or the training of machine-learning models.
    2. 3.2If we believe an instruction breaches the GDPR or Belgian data protection law, we say so before acting on it.
    3. 3.3Where EU or member-state law forces us to process beyond the controller's instructions, we inform the controller first unless that law forbids it.
  4. 4.Data subjects and categories

    The scope of this agreement, stated exhaustively.

    Data subjectsCategories of personal data
    Participants (mostly minors)name, username, optional avatar and interests, organization membership and verification status, meets created or joined, messages inside meets, zone check-in events, reports and incident records
    Staff approved by the organizationname, role, account credentials, moderation actions
    The director who buys the passname, organization, email, payment metadata held at Stripe

    No special-category data under Art. 9 is requested by the service. No continuous location tracking exists: presence is derived from zone check-in events only, and live locations are never stored.

  5. 5.Confidentiality

    Every person authorised by FND to process personal data is bound to confidentiality, including after the engagement ends. Access is granted on a need-to-know basis and withdrawn the day it is no longer needed.

  6. 6.Security measures (Art. 32)

    Technical and organisational measures appropriate to the risk, described in full at /security.

    1. 6.1Row-level security on every table, so a query cannot cross an organization boundary even if application code is wrong.
    2. 6.2TLS in transit, encryption at rest, and secrets held outside the codebase.
    3. 6.3Access to production requires multi-factor authentication and is limited to the operator of FND.
    4. 6.4Daily backups with point-in-time recovery, and restores tested rather than assumed.
    5. 6.5Data minimisation as the primary control: the most sensitive datum, a child's live location, is not collected at all.
  7. 7.Sub-processors

    The controller gives general written authorisation for FND to engage the sub-processors listed at /subprocessors, each bound by data protection terms no less protective than this agreement.

    1. 7.1We announce any addition or replacement at least 30 days before it takes effect.
    2. 7.2The controller may object on reasonable data protection grounds within those 30 days. If we cannot resolve the objection, the controller may terminate the affected part of the service and receive a refund for the unused part of the term.
    3. 7.3FND remains fully liable to the controller for its sub-processors' performance.
  8. 8.International transfers

    Participant data is stored in the European Union, on Supabase infrastructure hosted with AWS in Ireland.

    1. 8.1Push notifications pass through Apple's APNs, carrying a device token and the notification text.
    2. 8.2Payment and transactional email involve providers with United States operations, under Standard Contractual Clauses. Neither receives participant data.
    3. 8.3Any new transfer mechanism is disclosed at /subprocessors before it is used.
  9. 9.Assistance to the controller

    Taking into account the nature of the processing, FND assists the controller with appropriate technical and organisational measures.

    1. 9.1Data-subject requests: access, rectification, erasure, restriction, portability and objection. We answer the controller within two business days. The procedure is at /rights.
    2. 9.2Security obligations under Arts. 32 to 36, including any data protection impact assessment and prior consultation.
    3. 9.3The cabinet lets a director act on most requests directly, without waiting for us.
  10. 10.Personal data breach

    If a personal data breach affects the controller's data, FND notifies the controller without undue delay after becoming aware of it, and in any case within 24 hours.

    1. 10.1The notification states what we know, which categories and roughly how many people are affected, the likely consequences, and the measures taken or proposed.
    2. 10.2We keep the controller updated as the picture develops, so it can meet its own 72-hour obligation to its supervisory authority.
    3. 10.3Our own incident handling, including how a report reaches us out of hours, is described at /security.
  11. 11.Return and deletion

    At the controller's choice, FND deletes or returns all personal data at the end of the service, and deletes existing copies unless EU or member-state law requires storage.

    1. 11.1A revoked participant or a deleted account is removed in full cascade, including their photos and messages.
    2. 11.2Safety audit records expire on their own 30-day cycle.
    3. 11.3Absent a different instruction, an organization's data is deleted after the period at /retention, so a returning camp does not start from zero.
    4. 11.4Deletion is confirmed in writing on request.
  12. 12.Information and audits

    FND makes available all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, by the controller or an auditor it mandates.

    1. 12.1In practice most requests are satisfied by the material at /trust: this agreement, the sub-processor registry, the retention schedule and the security overview.
    2. 12.2An on-site or remote audit is arranged on reasonable notice, no more than once a year unless an incident or a supervisory authority requires otherwise.
  13. 13.Precedence

    This agreement forms part of the Terms of Service. Where the two conflict on the processing of personal data, this agreement prevails. It is governed by Belgian law.

  14. 14.Getting a countersigned copy

    This page is the standing version of the agreement and applies from the moment a pass is bought, signed or not.

    1. 14.1For a countersigned copy carrying your organization's name, address and signatory, use the generator at /dpa/sign. It produces a print-ready document with our signature, in your language, in about two minutes.
    2. 14.2A copy is emailed to the address you give, and stays available at its own stable link.
    3. 14.3If your legal department needs changes to the text, write to us: we would rather negotiate once and publish the result than keep a private version per school.

Change log

  1. v2.01 July 2026

    • Rewritten to follow the order of Art. 28(3), clause by clause.
    • Added a data subject and category table, a 24-hour breach notification commitment, and an explicit sub-processor objection right.
    • Replaced 'countersigned copy on request' with the self-serve generator at /dpa/sign.
    • Corrected the sub-processor list: the website's hosting and mail providers are now named alongside Supabase, Stripe and Apple.
  2. v1.016 May 2026

    • First published version, at launch.

Issued by

FND (Find 'n Do)

Belgium

Supervisory authority

Gegevensbeschermingsautoriteit / Autorité de protection des données

www.gegevensbeschermingsautoriteit.be

Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.

Write to us