DRAFT — testing only · not final, pending legal review

Data Processing Addendum

Effective date August 13, 2026 · Version 1.0 · Last reviewed August 13, 2026

This draft Data Processing Addendum (“DPA”) supplements the Master Subscription Agreement between the parish or diocese (“Customer”) and Stewardvine, and describes how Stewardvine processes personal information on the Customer's behalf. It is written for U.S. state privacy law and is intended as a concrete point of assurance for parishes and diocesan reviewers. Stewardvine sells software only and never takes custody of donor funds.

1. Roles of the parties

For personal information processed under this DPA, the Customer is the controller/business and Stewardvine is the processor/service provider. Square is a named sub-processor for payment processing and acts under its own agreements with the Customer and with Stewardvine as applicable. Stewardvine processes personal information only to provide the Software.

2. Scope, nature & purpose; data categories & subjects

The subject matter is Stewardvine's provision of the Software; the nature and purpose is processing donation metadata and account information to operate contactless giving, reconciliation, and communications for the parish. The categories of data subjects and personal information are described in [to be finalized] and generally include parish administrators/volunteers (identity and account data) and donors (donation metadata, and email only if voluntarily provided). Stewardvine does not receive raw card data.

3. Processing on documented instructions

Stewardvine processes personal information only on the Customer's documented instructions, including as set out in the Agreement and this DPA, unless required by law, in which case Stewardvine will inform the Customer where legally permitted. Stewardvine will not retain, use, disclose, or otherwise process the personal information for any purpose other than providing the Software, and not for its own commercial purposes.

4. Personnel confidentiality

Stewardvine ensures that personnel authorized to process personal information are bound by appropriate confidentiality obligations and are trained on their responsibilities, and it limits access to those who need it to provide the Software.

5. Security measures

Stewardvine implements and maintains reasonable and appropriate administrative, technical, and organizational measures designed to protect personal information, taking into account the nature of the processing. Architecture facts: card data is captured inside Apple's Secure Element and Square's SDK and encrypted to Square (never reaching Stewardvine's servers), connection tokens are stored encrypted, and administrative access is controlled and logged. This DPA makes no certification or compliance-standard claim. [to be finalized]

6. Sub-processor authorization

The Customer authorizes Stewardvine to engage sub-processors to provide the Software. The current sub-processors, including Square, are listed on the Subprocessor List. Stewardvine will provide notice before adding or replacing a sub-processor ([to be finalized]), giving the Customer a reasonable opportunity to object on reasonable data-protection grounds. Stewardvine will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA (flow-down), and remains responsible for its sub-processors' performance.

7. Assistance with data-subject rights

Taking into account the nature of the processing, Stewardvine will provide reasonable assistance to enable the Customer to respond to verified requests from data subjects to access, correct, delete, or port their personal information, including by appropriate technical and organizational measures where feasible.

8. Breach notification

Stewardvine will notify the Customer without undue delay, and in any event within [to be finalized], after becoming aware of a personal-data breach affecting the Customer's personal information, and will provide information reasonably available to assist the Customer's own notification obligations.

Drafting note: align the notification timeline with statutory deadlines, including California SB 446 (breach-notification timing — 30 days to consumers / 15 business days to the Attorney General as applicable). Confirm exact triggers and clocks with counsel. [to be finalized]

9. Assistance with DPIAs

Stewardvine will provide reasonable assistance to the Customer with data-protection impact assessments and related consultations, to the extent required by applicable law and taking into account the information available to Stewardvine.

10. Deletion or return on termination

On termination or expiration of the Agreement, Stewardvine will, at the Customer's choice, delete or return the personal information it processes on the Customer's behalf, and delete existing copies except where retention is required by law. Stewardvine will revoke the OAuth tokens connecting the Software to the parish's own Square account. [to be finalized]

11. Audit cooperation

Stewardvine will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audits, subject to appropriate confidentiality, scope, frequency, and notice conditions. [to be finalized]

12. CCPA/CPRA certification

Stewardvine certifies that it acts as a service provider and that it will not: (a) sell or share the personal information; (b) retain, use, or disclose it for any purpose other than providing the Software, or outside the direct business relationship; or (c) combine it with personal information from other sources except as permitted by the CCPA/CPRA. Stewardvine understands and will comply with these restrictions.

13. International transfers

The Software is offered to U.S. parishes and dioceses, and Stewardvine does not target the EU/EEA. Standard Contractual Clauses (SCCs) would apply only if any EU/UK personal data were in scope, which is generally not applicable here. [to be finalized]

14. Order of precedence & acceptance

This DPA is incorporated into and forms part of the Master Subscription Agreement and is accepted together with it by clickwrap, with version tracking and timestamped consent logs. In the event of a conflict regarding the processing of personal information, this DPA controls over the body of the Agreement. [to be finalized]

Questions about this policy? Contact privacy@stewardvine.com.

← Back to the Legal hub