FND

Data Processing Agreement

Last updated: July 2026

Roles

For participant data, your organization is the data controller and FND is the data processor under Art. 28 GDPR. FND processes this data only to provide the service described in the Terms, only on your documented instructions, and never for advertising, profiling or resale.

What is processed

Account basics (name, username, optional avatar and interests), organization membership and verification status, meets and planned activities a participant creates or joins, messages inside meets, zone check-in events used for presence and absence auto-revoke, and safety records (reports, incident log entries, a 30-day audit trail). No continuous location tracking exists in the system: presence is derived from zone check-in events only, and live locations are never stored for display.

Duration and deletion

Processing lasts as long as your pass is active. When a participant is revoked or an account is deleted, personal data is removed in full cascade. When your organization ends its use of FND, remaining participant data is deleted on request without undue delay; safety audit records expire on their 30-day cycle.

Sub-processors

Three, all under GDPR-compliant terms: Supabase (database, authentication and storage, hosted on AWS in Ireland), Stripe (payments — processes the paying director's billing details only, never participant data), and Apple (push notifications through APNs). We announce any change of sub-processor to partner organizations in advance.

Where data lives

In the European Union (Ireland). No participant data is transferred outside the EEA in the normal operation of the service.

Security

Access control by verified membership and row-level security on every table; TLS in transit and encryption at rest; the principle that the most sensitive datum — a child's live location — is not collected at all. Reports restrict repeat offenders automatically, and staff approval gates every new team member.

Incidents

If a personal-data breach affects your organization's data, we notify you without undue delay after becoming aware of it, with what we know, what it affects and what we are doing — so you can meet your own 72-hour obligation to your supervisory authority.

Assistance and audits

We assist with data-subject requests (access, correction, deletion) and provide the information reasonably necessary to demonstrate compliance. Write to us and we answer within two business days.

Getting a signed copy

This page is the standing version of the agreement and is incorporated into our Terms of Service. Need a countersigned PDF for your records or your municipality? Write to privacy@findndo.app and we send one within one business day.

The engineering behind these promises: /safety