Data Processing Addendum
Effective: 10 August 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer identified in an order form or Fundify account (“Customer”) and Hitaji Technologies LLC, a Delaware limited liability company doing business as Fundify (“Fundify”), when Fundify processes personal data on Customer’s behalf. It takes effect when Customer accepts the Fundify Terms of Service, signs an agreement incorporating it, or uses the Service to process personal data.
1. Roles and scope
Customer is the data controller and Hitaji Technologies LLC is the data processor for personal data contained in Customer Data, except where either party is independently a controller under applicable law. Each party will comply with the Uganda Data Protection and Privacy Act, 2019, its Regulations, and other data protection law applicable to its own processing.
Terms such as controller, processor, personal data, processing, and data subject have the meanings in applicable data protection law. If this DPA conflicts with the main agreement on personal-data processing, this DPA controls.
2. Processing instructions
Fundify will process personal data only to provide, secure, maintain, and support the Service; on Customer’s documented instructions; or as required by law. The agreement, Customer’s configuration and use of the Service, and support requests are documented instructions. Fundify will notify Customer if it reasonably believes an instruction violates applicable data protection law, unless prohibited from doing so.
3. Processing details
| Subject matter | Hosting and processing Customer Data to provide Fundify’s club-management, reporting, document, communication, support, security, and optional AI features. |
|---|---|
| Duration | The agreement term plus the deletion and backup periods described in the agreement. |
| Nature and purpose | Collection, recording, organisation, storage, retrieval, consultation, calculation, transmission, display, support, security monitoring, export, restriction, and deletion. |
| Data subjects | Customer’s members, administrators, treasurers, officers, employees, invitees, borrowers, payers, contacts, and other people whose data Customer submits. |
| Personal data | Identity and contact data; membership and role data; authentication and audit data; contribution, loan, fine, asset, income, expense, distribution, and other financial records; documents, notes, communications, and AI prompts; device and request metadata. |
| Sensitive data | Financial information and any sensitive data Customer chooses to include in documents, notes, or communications. Customer must not submit sensitive data unnecessary for its authorised use. |
4. Customer responsibilities
Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its collection and instructions; providing required notices; obtaining consent or another valid legal basis; handling data subject requests as controller; configuring access appropriately; and ensuring that its use of the Service complies with applicable law.
5. Personnel and confidentiality
Fundify will ensure that personnel authorised to process personal data are subject to confidentiality obligations and receive access only as needed for their duties.
6. Security
Taking into account the state of the art, implementation costs, scope and context of processing, and risk to individuals, Fundify will maintain appropriate administrative, technical, and organisational measures. These include, as appropriate:
- TLS for data in transit and provider encryption at rest;
- hashed passwords, session protection, and optional multi-factor authentication;
- role-based, tenant-scoped, and least-privilege access controls;
- audit logging, error monitoring, rate limiting, and security review;
- backup, recovery, vulnerability remediation, and incident-response processes; and
- provider due diligence and contractual data-protection duties.
Customer is responsible for secure endpoints, user access, permission configuration, credential protection, and backups or exports within its control.
7. Security incidents
Fundify will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer personal data. Notice will include available information reasonably needed for Customer’s legal duties, and Fundify will take reasonable steps to contain, investigate, and mitigate the incident. Notification is not an admission of fault. Customer is responsible for notices to regulators and data subjects unless law assigns that duty to Fundify.
8. Subprocessors
Customer gives general authorisation for Fundify to use the providers on our Subprocessors page. Fundify will impose data-protection obligations appropriate to the services each subprocessor performs and remains responsible for their performance to the extent required by applicable law.
For an enterprise Customer subscribed to change notices, Fundify will provide reasonable advance notice of a new subprocessor. Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a commercially reasonable solution. If none is available, Customer may stop using the affected feature or terminate it, and Fundify will refund prepaid fees for its unused remainder.
9. Assistance
Taking into account the nature of processing and information available, Fundify will provide reasonable assistance with data subject requests, security obligations, breach notifications, data protection impact assessments, and regulator consultations. Customer remains responsible for determining whether and how to respond. Assistance beyond standard Service functionality may be charged at agreed rates where legally permitted.
10. International transfers
Customer authorises processing in countries where Fundify and its subprocessors operate. Fundify will use safeguards required by applicable law for cross-border transfers, including contractual and organisational measures and assessment of recipient protections. The parties will cooperate to execute a legally required transfer mechanism.
11. Return and deletion
During the term, Customer may retrieve data through available export features. After termination or a valid deletion instruction, Fundify will delete or return Customer personal data within the periods stated in the agreement, unless law requires retention. Data in backups will remain protected, isolated from ordinary use, and deleted through the normal backup lifecycle.
12. Information and audits
Fundify will make available information reasonably necessary to demonstrate compliance with this DPA. No more than once annually, Customer may request relevant independent reports or submit a reasonable written security questionnaire. If those materials are insufficient, Customer may conduct an audit through a mutually agreed independent auditor, on at least 30 days’ notice, during business hours, without accessing other customers’ data or unreasonably disrupting the Service. Customer bears audit costs unless the audit identifies a material breach by Fundify.
13. Contact
Send DPA, security, or privacy requests to hello@contact.usefundify.com. Enterprise Customers needing a countersigned copy may request one at that address.