Data Processing Agreement
Last updated: June 2025
This Data Processing Agreement ("DPA") forms part of the agreement between Good2Govern ("Processor") and any organisation ("Controller") that uses the Good2Govern platform to store or process personal data relating to their members, volunteers, staff, service users or beneficiaries. By using Good2Govern to store such data, you agree to the terms of this DPA.
1. Definitions
- "Controller" — the organisation subscribing to Good2Govern that determines the purposes and means of processing personal data.
- "Processor" — Good2Govern, which processes personal data on behalf of the Controller.
- "Personal Data" — any information relating to an identified or identifiable natural person, as defined under UK GDPR.
- "Processing" — any operation performed on personal data (storage, retrieval, use, disclosure, etc.).
- "UK GDPR" — the UK General Data Protection Regulation as retained in UK law under the Data Protection Act 2018.
2. Subject matter and scope
Good2Govern processes personal data on behalf of the Controller as part of providing the platform. The types of personal data and categories of data subjects are:
- Data subjects: volunteers, trustees, staff, members, beneficiaries, contractors or other individuals whose records are stored by the Controller on the platform.
- Data types: names, contact details, dates of birth, DBS certificate information, employment/volunteer records, compliance documents, incident records, and other governance-related data entered by the Controller.
- Purpose: operating and maintaining the Good2Govern platform, including storage, retrieval, backup and support of Controller data.
3. Processor obligations
Good2Govern (as Processor) shall:
- Process personal data only on the documented instructions of the Controller (i.e. as required to provide the platform service).
- Ensure that authorised personnel processing personal data are bound by appropriate confidentiality obligations.
- Implement appropriate technical and organisational security measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure or access.
- Not engage sub-processors without informing the Controller and ensuring equivalent data protection obligations are in place.
- Assist the Controller with subject access requests, deletion requests and other data subject rights obligations under UK GDPR.
- Notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting Controller data.
- On termination of the service, delete or return Controller personal data as requested, unless retention is required by law.
4. Controller obligations
The Controller shall:
- Ensure it has a lawful basis for processing and sharing personal data with Good2Govern.
- Provide appropriate privacy notices to data subjects whose data is stored on the platform.
- Ensure it is registered with the ICO (Information Commissioner's Office) where required.
- Not instruct Good2Govern to process personal data in a way that would breach UK GDPR.
- Manage and respond to data subject requests, with assistance from Good2Govern where needed.
5. Sub-processors
Good2Govern uses the following sub-processors to deliver the platform service:
- Base44 — platform infrastructure, hosting and data storage.
- Stripe — payment processing (billing data only).
- OpenAI / AI providers — AI content generation (inputs anonymised where possible).
We will provide reasonable advance notice of any intended changes to sub-processors. A current list is available on request.
6. Security measures
Good2Govern implements appropriate technical and organisational measures including: encryption of data in transit and at rest; access controls and authentication; regular security testing; and staff confidentiality obligations. Full details are available on request.
7. International transfers
Personal data may be processed by our sub-processors in countries outside the UK or EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, in accordance with UK GDPR requirements.
8. Data retention and deletion
Good2Govern will retain Controller data for the duration of the subscription. Upon subscription termination, Controller data will be retained for up to 90 days to allow for data export, after which it will be securely deleted. Controllers may request deletion at any time by contacting us.
9. Governing law
This DPA is governed by the laws of England and Wales and is subject to UK GDPR.
10. Contact
For data protection queries or to exercise rights under this DPA, contact us at info@good2govern.co.uk.
