It is easy to get lost in the minutiae of privacy policies and terms of service, but what matters most is the values driving the policies. You can read our values around data here. You can also refer to our Terms of Service and our Privacy Policy.

DATA PROCESSING AGREEMENT

Last Updated: August 28, 2026

1. RECITALS AND RELATIONSHIP TO SERVICES AGREEMENT

1.1 This Data Processing Agreement (this “DPA”) is entered into by and between the customer who has accepted the Warchest Terms of Service as amended from time to time (the “Services Agreement”) (“Controller”) and Data Management and Compliance, Inc. DBA Warchest, a Delaware corporation with its principal place of business at 405 Waltham St, Suite 181, Lexington, MA 02421 (“Processor”).

1.2 This DPA is an addendum to, and is incorporated into, the Services Agreement. This DPA governs the Processing of Personal Data by the Processor on behalf of the Controller in connection with the Services provided under the Services Agreement.

1.3 This DPA is effective as of the date the Controller accepts the Services Agreement and shall remain in effect as set forth in Section 13 of this DPA.

1.4 In the event of any conflict or inconsistency between the terms of this DPA and the terms of the Services Agreement with respect to the Processing of Personal Data, the terms of this DPA shall control. All other provisions of the Services Agreement remain in full force and effect.

1.5 Capitalized terms used but not defined in this DPA have the meanings assigned to them in the Services Agreement.

2. DEFINITIONS

As used in this DPA, the following terms have the meanings set forth below. Capitalized terms not defined in this Section have the meanings given in the Services Agreement.

2.1 “Anonymized Information” has the meaning set forth in Section 2.1 of the Services Agreement.

2.2 “Applicable Data Protection Law” means all applicable laws and regulations relating to the processing of Personal Data, including: (a) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA); (b) applicable state comprehensive privacy laws, including the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, and Texas Data Privacy and Security Act; and (c) to the extent applicable, the General Data Protection Regulation (EU) 2016/679 and the UK GDPR.

2.3 “Controller” means the customer that accepted the Services Agreement.

2.4 “Customer Data” has the meaning set forth in Section 2.4 of the Services Agreement.

2.5 “Data Breach” means: (a) any unauthorized access to Customer Data, Reports, or Confidential Information; or (b) any unauthorized intrusion resulting in disclosure of such information.

2.6 “Data Subject” means an identified or identifiable natural person whose Personal Data is processed under this DPA.

2.7 “Personal Data” means any information relating to a Data Subject that is contained within Customer Data, including names, mailing addresses, email addresses, phone numbers, employer and occupation information, contribution details, expenditure and vendor payment information, committee identification numbers, bank account information, and platform account credentials.

2.8 “Processing” (and its cognates) means any operation performed on Personal Data, whether by automated or manual means, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure, or destruction.

2.9 “Processor” means Data Management and Compliance, Inc. DBA Warchest.

2.10 “Services” has the meaning set forth in the Services Agreement.

2.11 “Sub-Processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller in connection with the Services.

3. SCOPE AND PURPOSE OF PROCESSING

3.1 Scope. This DPA applies to all Processing of Personal Data that Processor performs on behalf of Controller in connection with the Services described in the Services Agreement. The Services consist of: (a) Warchest Compliance, which processes Donor Records imported from ActBlue or other donation sources and generates compliance reports for Federal Election Commission and state election filings; and (b) Warchest Cashflow, which provides budget management and cash flow analysis for political committees.

3.2 Purpose Limitation. Processor shall Process Personal Data solely for the purpose of providing the Services to Controller, including campaign finance compliance reporting, budget management, and related political committee operations for United States elections. Processor shall not Process Personal Data for any purpose other than as set forth in this DPA and the Services Agreement, or as otherwise documented in writing by the Controller.

3.3 Controller Instructions. Processor shall Process Personal Data solely on behalf of and under the documented instructions of Controller. The Services Agreement, this DPA, and Controller’s use of the platform’s features and configurations constitute Controller’s documented instructions. If Processor believes that an instruction from Controller infringes Applicable Data Protection Law, Processor shall promptly notify Controller before carrying out the instruction, unless prohibited by law from doing so.

3.4 Processing Details. The categories of data subjects, types of Personal Data, nature and purposes of Processing, and duration of Processing are described in Annex A to this DPA.

3.5 United States Processing. All Processing of Personal Data under this DPA occurs within the United States, subject to the cross-border transfer provisions set forth in Section 9 of this DPA.

4. PROCESSOR OBLIGATIONS

4.1 Instructions. Processor shall Process Personal Data only on the documented instructions of Controller, including with respect to transfers of Personal Data, unless required to do so by Applicable Data Protection Law. If Processor believes an instruction from Controller infringes Applicable Data Protection Law, Processor shall promptly notify Controller.

4.2 Confidentiality. Processor shall ensure that all personnel authorized to Process Personal Data are bound by written confidentiality obligations.

4.3 Security. Processor shall implement and maintain the technical and organizational security measures described in Section 7 of the Services Agreement and Annex B of this DPA.

4.4 Records. Processor shall maintain records of Processing activities carried out on behalf of Controller as required by Applicable Data Protection Law.

4.5 Assistance. Processor shall provide reasonable assistance to Controller in conducting data protection impact assessments where required by Applicable Data Protection Law.

4.6 Restrictions on Use. Processor shall not: (a) sell, share, or otherwise make Personal Data available to third parties for cross-context behavioral advertising; (b) use Personal Data for any purpose other than providing the Services; or (c) combine Personal Data with personal data received from or on behalf of other parties, except as necessary to provide the Services.

4.7 CCPA Service Provider Certification. To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), applies to Processor’s Processing of Personal Data, Processor certifies that it: (a) understands and will comply with its obligations under the CCPA as a service provider; (b) will not sell or share Personal Data; and (c) will not retain, use, or disclose Personal Data for any purpose other than performing the Services or as otherwise permitted by the CCPA.

5. SUB-PROCESSORS

5.1 General Authorization. Controller grants prior general written authorization for Processor to engage the Sub-Processors identified in Processor’s current Sub-Processor list as of the effective date of this DPA. Processor shall make its current list of Sub-Processors available to Controller upon written request. Processor shall enter into a written agreement with each Sub-Processor that imposes data protection obligations no less protective than those set forth in this DPA, including restrictions on the use, retention, and disclosure of Personal Data.

5.2 Notification of Changes. Processor shall notify Controller in writing at least thirty (30) days before engaging any new Sub-Processor or replacing an existing Sub-Processor. Such notice shall identify the proposed Sub-Processor, describe the Processing to be performed, and specify the location of Processing.

5.3 Objection Right. Controller may object to a new or replacement Sub-Processor by providing written notice to Processor within fifteen (15) days of receiving the notification described in Section 5.2. The parties shall negotiate in good faith to resolve the objection. If the parties are unable to resolve the objection within thirty (30) days of Controller’s notice, Controller may terminate the portion of the Services that requires the use of the objected-to Sub-Processor without penalty.

5.4 Liability. Processor shall remain fully liable to Controller for the acts and omissions of its Sub-Processors to the same extent Processor would be liable if performing the Processing directly under this DPA.

6. DATA SUBJECT RIGHTS

6.1 Assistance with Data Subject Requests. Processor shall, to the extent commercially reasonable and as required by Applicable Data Protection Law, assist Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law, including rights of access, correction, deletion, objection, restriction, and data portability.

6.2 Forwarding of Requests. If Processor receives a request directly from a Data Subject relating to Personal Data processed on behalf of Controller, Processor shall promptly, and in no event later than five (5) business days, forward the request to Controller without responding to the Data Subject.

6.3 No Direct Response. Processor shall not respond directly to any Data Subject request unless expressly instructed to do so by Controller in writing.

6.4 Cooperation. Processor shall provide Controller with such information and technical assistance as is reasonably necessary to enable Controller to respond to Data Subject requests within the timeframes required by Applicable Data Protection Law. Controller shall reimburse Processor for reasonable costs incurred in providing assistance under this Section 6 that exceeds routine or de minimis effort, provided Processor obtains Controller’s prior written approval before incurring such costs.

7. SECURITY MEASURES

7.1 General Obligation. Processor shall implement and maintain technical and organizational security measures appropriate to the nature, scope, context, and purposes of Processing, designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. These measures shall meet or exceed the security standards described in Sections 7.6 and 7.7 of the Services Agreement.

7.2 Minimum Security Measures. Without limiting Section 7.1, Processor shall implement the following measures, with full details set forth in Annex B:

  1. Encryption of Personal Data at rest and in transit using industry-standard protocols;
  2. Role-based access controls limiting access to Personal Data to authorized personnel with a legitimate need;
  3. Authentication requirements, including single sign-on (SSO) and multi-factor authentication (MFA) where available;
  4. Regular security assessments and vulnerability testing;
  5. Employee training on data protection and information security;
  6. Documented incident response procedures.

7.3 AI Tool Controls. With respect to AI tools used in Processor’s operations, Processor shall ensure that: (a) model training on inputs and outputs is contractually disabled on all company-managed AI accounts; and (b) access to Customer Data through AI tools is limited and subject to anonymization requirements in accordance with Processor’s internal AI policy.

7.4 Review and Updates. Processor shall periodically review and update its security measures to address evolving threats and changes in Processing activities, provided that no update shall materially diminish the overall level of protection afforded to Personal Data under this DPA.

8. DATA BREACH NOTIFICATION

8.1 Notification Obligation. Processor shall notify Controller of a confirmed Data Breach without undue delay and in no event later than seventy-two (72) hours after Processor becomes aware that a Data Breach has been confirmed. This seventy-two (72) hour notification period supersedes and replaces the thirty (30) day notification window set forth in Section 7.8 of the Services Agreement with respect to any breach involving Personal Data.

8.2 Contents of Notification. The Processor’s notification to Controller shall include, to the extent reasonably available at the time of notification:

  1. The nature of the Data Breach, including the categories and approximate number of Data Subjects affected;
  2. The categories and approximate volume of Personal Data affected;
  3. The likely consequences of the Data Breach;
  4. The measures taken or proposed by Processor to address the Data Breach, including measures to mitigate its adverse effects;
  5. The name and contact information of the Processor’s designated point of contact for the incident.

8.3 Ongoing Updates. Where complete information is not available within the initial seventy-two (72) hour period, Processor shall provide information in phases without further undue delay as it becomes available.

8.4 Cooperation. Processor shall cooperate with Controller’s investigation and mitigation efforts related to any Data Breach, including by preserving relevant evidence, providing reasonable access to affected systems and records, and assisting Controller in meeting any notification obligations under Applicable Data Protection Law.

8.5 No Independent Notification. Processor shall not notify any Data Subject, regulatory authority, or third party of a Data Breach without Controller’s prior written authorization, unless required by Applicable Data Protection Law.

9. CROSS-BORDER DATA TRANSFERS

9.1 Data Storage Location. All Personal Data processed under this DPA is stored and processed in the United States. Processor does not maintain data centers, servers, or storage infrastructure outside the United States.

9.2 Access from Outside the United States. The Services are designed for US election compliance, and all data processing occurs within the United States. Where an authorized user accesses the Services from outside the United States, including from the European Economic Area (“EEA”), the United Kingdom, or Switzerland, the following provisions apply:

  1. The underlying Processing of Personal Data remains in the United States regardless of the user’s location of access.
  2. To the extent such access constitutes a transfer of Personal Data from a jurisdiction with cross-border transfer restrictions, the parties agree to execute the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two: Controller to Processor) or the UK International Data Transfer Addendum, as applicable. These instruments are incorporated by reference as Annex C to this DPA.
  3. Processor will implement supplementary measures as appropriate, including encryption in transit and access controls consistent with Section 7 of this DPA and Annex B.
  4. Controller is responsible for determining whether its use of the Services, including access by its personnel from outside the United States, complies with Applicable Data Protection Law in the jurisdiction from which the user accesses the Services.

9.3 Proportionality. This Section 9 is a contingency provision reflecting the limited likelihood of cross-border access. Nothing in this Section 9 alters the scope of Processing described in Section 3 or Annex A, which is limited to US election-related data processed within the United States.

10. DATA RETENTION AND DELETION

10.1 Retention During the Term. Processor shall retain Personal Data for the duration of the Services Agreement and shall process such data only as necessary to provide the Services in accordance with Controller’s documented instructions.

10.2 Post-Termination Retrieval. Upon termination or expiration of the Services Agreement, Processor shall make all Personal Data available to Controller for electronic retrieval for a period of sixty (60) days following the effective date of termination (the “Retrieval Period”). This sixty-day Retrieval Period supersedes the thirty-day window set forth in Section 12.5(e) of the Services Agreement with respect to Personal Data.

10.3 Deletion. Following expiration of the Retrieval Period, Processor shall delete all Personal Data in its possession and certify such deletion in writing to Controller upon request, subject to the following exceptions:

  1. Data that Processor is required to retain under applicable law or regulation, which shall be retained only for so long as legally required and subject to the confidentiality and security obligations of this DPA;
  2. Anonymized Information, as defined in Section 2.1 of the Services Agreement, which does not constitute Personal Data and is not subject to this deletion requirement; and
  3. Personal Data retained in routine backup systems, which Processor shall delete in accordance with its standard backup rotation schedule, not to exceed ninety (90) days following the end of the Retrieval Period.

10.4 Survival of Obligations. The confidentiality and security obligations of this DPA shall continue to apply to any Personal Data retained pursuant to Section 10.3 until such data is deleted.

11. AUDITS AND COMPLIANCE VERIFICATION

11.1 Right to Audit. Controller may audit Processor’s compliance with this DPA no more than once per calendar year, upon at least thirty (30) days’ prior written notice, during normal business hours, and at Controller’s sole expense. Any such audit must not unreasonably interfere with Processor’s business operations or the operations of Processor’s other customers.

11.2 Third-Party Reports. Processor may satisfy an audit request by providing Controller with a third-party audit report covering the systems and processes relevant to the Processing of Personal Data under this DPA. Processor shall make such reports available within a reasonable period following Controller’s request.

11.3 On-Site Audit. If Controller reasonably determines that a third-party report provided under Section 11.2 is insufficient to verify Processor’s compliance with this DPA, Controller may conduct or commission an independent third-party to conduct an on-site audit of Processor’s facilities and systems. Any auditor engaged by Controller must execute a confidentiality agreement with Processor on terms reasonably acceptable to Processor before commencing the audit. The scope of any on-site audit shall be limited to verifying compliance with the obligations set forth in this DPA.

11.4 Cooperation. Processor shall cooperate with Controller’s reasonable audit requests and provide access to relevant records, systems, and personnel as necessary to verify compliance. Processor shall promptly remediate any material non-compliance identified through an audit conducted under this Section 11.

12. LIABILITY AND INDEMNIFICATION

12.1 Limitation of Liability. Each party’s total aggregate liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in Section 10 of the Services Agreement, including the carve-outs stated in Section 10.5.

12.2 Processor Indemnification. Processor shall indemnify, defend, and hold harmless Controller and its officers, directors, employees, and agents from and against any losses, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising from Processor’s material breach of this DPA, including without limitation: (a) unauthorized Processing of Personal Data; (b) failure to implement the security measures required by this DPA; or (c) failure to comply with the breach notification obligations set forth in Section 8.

12.3 Controller Indemnification. Controller shall indemnify, defend, and hold harmless Processor and its officers, directors, employees, and agents from and against any losses, damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising from Controller’s documented instructions that violate Applicable Data Protection Law, provided that Processor has notified Controller of the potential violation in accordance with Section 4 of this DPA prior to carrying out such instructions.

12.4 Indemnification Procedures. The indemnified party shall: (a) promptly notify the indemnifying party in writing of any claim; (b) grant the indemnifying party sole control of the defense and settlement of such claim; and (c) provide reasonable cooperation at the indemnifying party’s expense. Failure to provide prompt notice shall not relieve the indemnifying party of its obligations except to the extent materially prejudiced by such failure.

13. TERM, TERMINATION, AND SURVIVAL

13.1 Effective Date. This DPA is effective as of the date the Controller accepts the Services Agreement and does not require separate execution to become binding.

13.2 Term. This DPA remains in effect for the duration of the Services Agreement, including any renewal terms, plus any data retention or deletion period specified in Section 10 of this DPA.

13.3 Termination. Termination or expiration of the Services Agreement automatically terminates this DPA, subject to the surviving obligations set forth in Section 13.4 below. Neither party may terminate this DPA independently of the Services Agreement except as expressly provided in Section 5 (Sub-Processors).

13.4 Survival. The following provisions, together with any obligations that by their nature should survive termination, will remain in effect after termination or expiration of this DPA:

  1. Section 2 (Definitions), to the extent necessary to interpret surviving provisions;
  2. Section 4.1 (confidentiality obligations of Processor personnel);
  3. Section 8 (Data Breach Notification), with respect to any breach discovered after termination but relating to Personal Data processed during the term;
  4. Section 10 (Data Retention and Deletion), until all Personal Data has been deleted or returned in accordance with its terms;
  5. Section 11 (Audits and Compliance Verification), for a period of twelve (12) months following the completion of all data deletion obligations;
  6. Section 12 (Liability and Indemnification);
  7. Section 14 (Governing Law, Jurisdiction, and Miscellaneous).

14. GOVERNING LAW, JURISDICTION, AND MISCELLANEOUS

14.1 Governing Law. This DPA and any dispute arising out of or in connection with it shall be governed by and construed in accordance with the laws of the Commonwealth of Massachusetts, without regard to its conflict of laws principles, consistent with Section 13.1 of the Services Agreement.

14.2 Jurisdiction. The parties submit to the exclusive jurisdiction of the state and federal courts located in the Commonwealth of Massachusetts for the resolution of any dispute arising under or in connection with this DPA.

14.3 Notices. All notices required or permitted under this DPA shall be in writing and delivered in accordance with the notice provisions of the Services Agreement. Notices related to Data Breaches under Section 8 of this DPA shall be sent to the email address associated with the Controller’s account and, where available, by any additional method reasonably calculated to provide prompt actual notice.

14.4 Amendments. This DPA may not be modified or amended except by a written instrument signed or electronically accepted by both parties. Processor may update the Annexes to this DPA and its Sub-Processor list in accordance with the procedures specified in this DPA.

14.5 Severability. If any provision of this DPA is held invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect. The parties shall negotiate in good faith a replacement provision that achieves the original intent to the extent permitted by law.

14.6 Waiver. No failure or delay by either party in exercising any right under this DPA shall constitute a waiver of that right. Any waiver must be in writing and signed by the waiving party.

14.7 Entire Agreement. This DPA, together with the Services Agreement, the Annexes attached hereto, and Processor’s current Sub-Processor list, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior or contemporaneous agreements, understandings, or representations on that subject.

IN WITNESS WHEREOF, the parties have executed this Data Processing Agreement as of the date the Controller accepts the Services Agreement.

 

ANNEXES

ANNEX A: DETAILS OF PROCESSING

Element Description
Categories of Data Subjects Campaign donors and contributors; political committee staff and officers; campaign vendors and consultants; authorized platform users
Types of Personal Data Names, mailing addresses, email addresses, phone numbers, employer and occupation information, contribution amounts and dates, expenditure details and vendor payment information, committee identification numbers, platform account credentials and usage data
Purposes of Processing Campaign finance compliance reporting (FEC and state filings), budget management and cash flow analysis, address verification, and related political committee operations for US elections
Nature of Processing Collection, storage, organization, retrieval, validation, reporting, and deletion of Personal Data through cloud-based software
Duration For the term of the Services Agreement plus any applicable retention period specified in Section 10 of this DPA

 

ANNEX B: TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES

  1. Encryption: TLS 1.2 at rest; TLS 1.2 or higher in transit.
  2. Access Controls: Role-based access controls; principle of least privilege enforced across all systems.
  3. Authentication: Single sign-on (SSO) and multi-factor authentication (MFA) where available for all personnel accessing Customer Data.
  4. Monitoring: Continuous logging and monitoring of access to production systems; automated alerting for anomalous activity.
  5. Incident Response: Documented incident response plan with defined roles, escalation procedures, and post-incident review.
  6. AI Tool Controls: Model training on inputs and outputs contractually disabled on all company-managed AI accounts; access to Customer Data through AI tools limited and subject to anonymization requirements per internal AI policy.
  7. Employee Training: Security awareness training for all personnel upon onboarding and at least annually thereafter; personnel bound by written confidentiality obligations.
  8. Physical Security: All infrastructure hosted in Google Cloud Services data centers with SOC 2 Type II certified physical security controls.

ANNEX C: STANDARD CONTRACTUAL CLAUSES (REFERENCE)

If Processing under this DPA constitutes a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to the United States, the parties agree to execute the applicable EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two: Controller to Processor) or the UK International Data Transfer Addendum (as issued by the UK Information Commissioner’s Office), as applicable. These instruments are incorporated by reference into this DPA and will be completed and executed by the parties promptly upon either party’s reasonable determination that such a transfer has been triggered. The full text of the SCCs and UK IDTA is not reproduced in this document.

Last Updated: August 28, 2026