Skip to main content

Data Processing Addendum

Effective 3 July 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between NC Digital Pods Inc. (“Pamweni”, the “processor”) and the group or organization using the service (the “customer”, the “controller”). It applies whenever Pamweni processes personal data of the customer’s members on the customer’s behalf.

1. Subject matter and details of processing

Subject matter and duration. Processing of member personal data to provide the Pamweni service, for as long as the customer maintains a group, plus the retention periods in our Privacy Policy.

Nature and purpose. Storing and organizing member rosters; scheduling and composing event messages; sending event invitations, RSVP requests, and reminders by SMS and WhatsApp; recording messaging consent; and keeping an audit history of changes.

Categories of data subjects. The customer’s members and external participants.

Categories of personal data. Names, email addresses, phone numbers, group roles, birthdays and anniversaries (where the customer records them), availability notes (which may incidentally reveal health information, e.g. “illness”), RSVP and participation history, messaging consent records, and message delivery logs. Where the customer is a religious or other special-category community, membership itself may indirectly reveal special-category information; the customer is responsible for an appropriate lawful basis (see §2).

2. Controller responsibilities

The customer instructs Pamweni to process member data by using the service, and warrants that it has a lawful basis (and any required consent or notice, including for any special-category data) for entering member details, recording occasions, and messaging members. Pamweni provides the consent tooling (double opt-in, per-group and per-channel consent records, STOP handling), but the legal responsibility for the roster is the customer’s.

3. Processor obligations

  • Process member data only to provide the service and on the customer’s documented instructions (given through the product), unless law requires otherwise — in which case we will inform the customer unless prohibited.
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Apply the technical and organizational measures in §5.
  • Engage sub-processors only under §4.
  • Assist the customer with data-subject requests (§6) and with the customer’s own security, breach-notification, and impact-assessment obligations, taking into account the nature of the processing.
  • Notify the customer without undue delay after becoming aware of a personal-data breach affecting their members’ data, with the information reasonably needed for the customer’s own notifications.
  • Delete or return member data at the end of the service (§7).
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the customer or their mandated auditor, on reasonable notice and no more than once per year unless a breach has occurred.

4. Sub-processors

The customer generally authorizes the sub-processors listed at pamweni.com/subprocessors. We will update that page at least 14 days before adding or replacing a sub-processor that handles member data; the customer may object by stopping use of the service and deleting their group before the change takes effect. Each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than this DPA, and Pamweni remains liable for their performance.

5. Security measures

Row-level security isolating each group’s data; encryption in transit; encryption at rest provided by our database hosting provider; passwordless magic-link sign-in; hashed, scoped API tokens; least-privilege access controls; PII-scrubbed operational alerts; an append-only audit log; and a 30-day soft-delete-then-purge retention lifecycle with automated erasure of personal data from historical records. Details in the Privacy Policy.

6. Data-subject requests

Requests from members go to the customer, as controller. Pamweni provides self-service tools for the customer to respond: a per-member data export (access and portability), per-member erasure (which removes the member and scrubs their details from the group’s history, while retaining messaging-consent records as legal evidence), and a full group export. Where a request needs more than the tools provide, we will assist at the customer’s reasonable request via privacy@pamweni.com.

7. Deletion and return

The customer may export their group’s full data at any time, and may delete the group in the product. Deletion removes the group immediately and permanently erases its data after a 30-day recovery window, except records we must retain by law (billing records and messaging-consent evidence). Erased data may persist in encrypted backups for a limited period before those backups are rotated out.

8. International transfers

Member data is processed in Canada and stored in the United States (see the sub-processor list). Where the GDPR or UK GDPR applies to the customer’s members, transfers rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum), which are incorporated into our agreements with the relevant sub-processors, or on an applicable adequacy decision.

9. Governing law

This DPA is governed by the same law as the Terms of Service (Ontario, Canada), except where the incorporated Standard Contractual Clauses require otherwise for the customers and members they protect.

10. Contact

Questions about this DPA: privacy@pamweni.com.