1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement or in Applicable Privacy Law.
"Applicable Privacy Law" means all U.S. state privacy and data protection laws applicable to the processing of Customer Personal Information under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA"), the Texas Data Privacy and Security Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Oregon Consumer Privacy Act, and other comparable state laws, in each case as in effect and applicable.
"Business" and "Service Provider" have the meanings given under the CCPA. For purposes of the CCPA, Customer is the Business and Reach is the Service Provider.
"Controller" and "Processor" have the meanings given under Applicable Privacy Law other than the CCPA. For purposes of those laws, Customer is the Controller and Reach is the Processor.
"Customer Personal Information" means personal information, as defined under Applicable Privacy Law, that Reach processes on Customer's behalf under the Agreement, as further described in Annex 1. Customer Personal Information does not include personal information about Customer's own users/team members in their capacity as users of the Service.
"Consumer" means a natural person about whom Customer Personal Information relates, including a resident or contact whose information a team member records in the Service.
"Process" or "Processing" means any operation performed on Customer Personal Information, whether or not by automated means, including collection, recording, storage, use, disclosure, and deletion.
"Sell," "Share," "Sale," and "Sharing" have the meanings given under the CCPA.
"Sub-processor" means a third party engaged by Reach to process Customer Personal Information on Reach's behalf.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Information processed by Reach. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Information, including unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems.
2. Roles of the Parties
2.1 Allocation of roles. As between the parties with respect to Customer Personal Information, Customer is the Business / Controller and Reach is the Service Provider / Processor. Customer determines the purposes and means of the processing; Reach processes only as instructed by Customer and as described in this DPA.
2.2 Customer's instructions. Customer instructs Reach to process Customer Personal Information only: (a) to provide the Service in accordance with the Agreement; (b) as further specified through Customer's use of the Service (including the features Customer's team members use); (c) as documented in this DPA; and (d) as further agreed in writing. Reach will not process Customer Personal Information for any other purpose.
2.3 Customer's responsibilities. Customer is responsible for the lawfulness of the Customer Personal Information it and its team members enter into the Service and for the accuracy, quality, and legality of that information and the means by which it was obtained. Customer represents and warrants that:
(a) it has provided all notices and obtained all rights, consents, and authorizations required under Applicable Privacy Law to enter the Customer Personal Information into the Service and to have it processed as described in this DPA;
(b) its instructions for processing comply with Applicable Privacy Law; and
(c) it will not enter into the Service any category of information prohibited by Section 4 of the Agreement (including sensitive personal information, information about children under 13, government identifiers, financial account numbers, or biometric data) without an appropriate legal basis and a direct relationship with the Consumer.
2.4 The notes field and free-text entry. Customer acknowledges that the Service includes free-text fields (including the pin "notes" field) into which team members may enter unstructured information. Customer is solely responsible for ensuring that information entered into free-text fields complies with Applicable Privacy Law and the Agreement. Reach does not monitor, review, or control the contents of free-text fields.
3. Reach's Processing Obligations
3.1 Processing on instructions only. Reach will process Customer Personal Information only on Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law. If Reach is required by law to process Customer Personal Information other than as instructed, Reach will inform Customer of that legal requirement before processing, unless the law prohibits such notice.
3.2 CCPA Service Provider certification. Reach certifies that it understands the restrictions in this Section 3.2 and will comply with them. With respect to Customer Personal Information, Reach will not:
(a) Sell or Share the Customer Personal Information;
(b) retain, use, or disclose the Customer Personal Information for any purpose other than the business purposes specified in this DPA and the Agreement, including retaining, using, or disclosing it for a commercial purpose other than providing the Service;
(c) retain, use, or disclose the Customer Personal Information outside the direct business relationship between Reach and Customer; or
(d) combine the Customer Personal Information with personal information that Reach receives from, or on behalf of, another person, or collects from its own interaction with the Consumer, except as permitted by the CCPA for a service provider.
3.3 Same level of protection. Reach will provide the same level of privacy protection to Customer Personal Information as is required of Customer by Applicable Privacy Law.
3.4 Compliance and notice of inability. Reach will comply with its obligations as a Service Provider / Processor under Applicable Privacy Law. Reach will notify Customer if it determines that it can no longer meet its obligations under Applicable Privacy Law, and upon such notice Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Information.
3.5 Confidentiality. Reach will ensure that persons authorized to process Customer Personal Information are bound by an appropriate duty of confidentiality.
3.6 Cooperation. Taking into account the nature of the processing, Reach will provide reasonable assistance to Customer, through appropriate technical and organizational measures, in fulfilling Customer's obligations under Applicable Privacy Law, including obligations relating to Consumer rights requests (Section 5), security (Section 6), and Security Incidents (Section 7), insofar as this is possible and proportionate to the information available to Reach.
4. Sub-processors
4.1 General authorization. Customer provides general authorization for Reach to engage Sub-processors to process Customer Personal Information, subject to this Section 4. The Sub-processors engaged as of the Effective Date are listed in Annex 3.
4.2 Flow-down obligations. Reach will impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection for Customer Personal Information as those in this DPA, to the extent applicable to the nature of the Sub-processor's services.
4.3 Notice of changes and right to object. Reach will give Customer at least 30 days' prior notice before adding or replacing a Sub-processor by updating the list in Annex 3 (or a successor online list) and providing notice through the Service or by email. If Customer reasonably objects to a new Sub-processor on data protection grounds within that 30-day period, the parties will work in good faith to resolve the objection. If the objection cannot be resolved, Customer may, as its sole and exclusive remedy, terminate the affected portion of the Service by closing the relevant team and ceasing use.
4.4 Liability for Sub-processors. Reach remains responsible for the acts and omissions of its Sub-processors with respect to Customer Personal Information to the same extent Reach would be liable if performing the services directly, subject to the limitations of liability in Section 9.
5. Consumer Rights Requests
5.1 Assistance. Taking into account the nature of the processing, Reach will provide Customer with reasonable assistance, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Consumers exercising their rights under Applicable Privacy Law (including rights to know, access, correct, delete, and obtain a portable copy).
5.2 Forwarding requests. If Reach receives a request directly from a Consumer relating to Customer Personal Information, Reach will, where it can reasonably identify the relevant Customer, advise the Consumer to submit the request to Customer and, where appropriate, forward the request to Customer. Reach will not respond to such a request itself except on Customer's documented instructions or as required by law.
5.3 Customer's self-service tools. Customer acknowledges that the Service provides tools that allow Customer's authorized team members to access, correct, and delete Customer Personal Information directly, and that use of these tools is the primary means by which Customer responds to Consumer rights requests.
6. Security
6.1 Security measures. Reach will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Information against a Security Incident, as described in Annex 2. Customer acknowledges that the measures in Annex 2 are appropriate to the nature of the Service as of the Effective Date and that Reach may update them from time to time, provided the updates do not materially reduce the overall level of protection.
6.2 Customer's role in security. Customer is responsible for its own use of the Service, including maintaining the confidentiality of team member credentials, configuring team roles and permissions appropriately, and promptly removing team members who should no longer have access.
7. Security Incidents
7.1 Notification. Reach will notify Customer without undue delay, and in any event no later than 72 hours after becoming aware of a Security Incident affecting Customer Personal Information.
7.2 Contents of notice. The notification will, to the extent known and reasonably available to Reach at the time, describe the nature of the Security Incident, the categories and approximate number of Consumers and records affected, the likely consequences, and the measures taken or proposed to address it. Reach may provide information in phases as it becomes available.
7.3 Cooperation. Reach will take reasonable steps to mitigate the effects of the Security Incident and will cooperate with Customer in Customer's investigation and response, including assisting Customer with any notification obligations Customer may have under Applicable Privacy Law.
7.4 No admission. Reach's notification of or response to a Security Incident is not an acknowledgment of fault or liability.
8. Deletion and Return of Customer Personal Information
8.1 On termination. Following expiration or termination of the Agreement, or on Customer's earlier written request, Reach will delete Customer Personal Information in its possession, except to the extent retention is required by law or permitted by this DPA. Deletion will be completed within the timeframes described in the Privacy Policy retention schedule (generally within 30 days from active systems and 90 days from backups).
8.2 Return before deletion. Before deletion, Customer may export Customer Personal Information using the Service's export features. If Customer requires assistance beyond the Service's standard export functionality, Customer must request it in writing before the Agreement terminates.
8.3 Permitted retention. Reach may retain Customer Personal Information to the extent required by Applicable Privacy Law or other law, and only for as long as required, provided Reach continues to protect it in accordance with this DPA and processes it only as necessary for the retention purpose.
9. Liability
9.1 Liability cap. Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement (including Section 11 of the Terms of Service). Any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. For the avoidance of doubt, this DPA does not increase or create any liability beyond the cap stated in the Agreement.
9.2 No separate cap. The parties agree that this DPA does not establish a separate or higher limitation of liability for claims relating to Customer Personal Information.
10. Audits and Demonstration of Compliance
10.1 Documentation-based audits. Reach will make available to Customer information reasonably necessary to demonstrate Reach's compliance with this DPA. Customer's audit right is satisfied by Reach responding, no more than once per twelve-month period (absent a Security Incident or a specific regulatory requirement), to a reasonable written security and compliance questionnaire submitted by Customer, and by providing relevant documentation in Reach's possession.
10.2 On-site audits. Reach is not required to permit on-site or physical audits of its facilities or systems except where Customer is specifically required to conduct such an audit by a governmental authority with jurisdiction over Customer, or where Applicable Privacy Law mandates an on-site audit that cannot be satisfied under Section 10.1. Any such audit will be conducted: (a) on at least 30 days' prior written notice; (b) during normal business hours; (c) no more than once per twelve-month period; (d) in a manner that does not unreasonably disrupt Reach's operations or compromise the confidentiality or security of other customers' data; and (e) at Customer's sole expense.
10.3 Confidentiality of audit information. All information disclosed in connection with an audit is Reach's confidential information and may be used by Customer solely to verify Reach's compliance with this DPA.
11. General
11.1 Order of precedence. This DPA is incorporated into and forms part of the Agreement. Except as expressly modified by this DPA, the Agreement remains in full force and effect. With respect to the processing of Customer Personal Information, if there is a conflict between this DPA and any other part of the Agreement, this DPA controls.
11.2 Governing law and venue. This DPA is governed by the laws of the State of California, and any dispute relating to it is subject to the governing law, venue, and dispute-resolution provisions of the Agreement (including the arbitration agreement and class action waiver in Section 18 of the Terms of Service).
11.3 Changes to this DPA. Reach may update this DPA from time to time to reflect changes in Applicable Privacy Law, changes to the Service, or changes to Sub-processors. For material changes, Reach will provide notice as described in the Agreement. Customer's continued use of the Service after the effective date of an updated DPA constitutes acceptance of the updated DPA, except where additional consent is required by law.
11.4 Severability. If any provision of this DPA is found to be unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force and effect.
11.5 No third-party beneficiaries. This DPA does not confer any rights on any third party, except that Consumers retain whatever rights they have directly under Applicable Privacy Law.
ANNEX 1 — Details of Processing
Subject matter of the processing Reach's provision of the Reach field outreach tracking Service to Customer under the Agreement.
Duration of the processing For the term of the Agreement, plus the retention periods described in Section 8 and the Privacy Policy.
Nature and purpose of the processing Collection, recording, organization, storage, structuring, display, synchronization across devices and team members, export at Customer's direction, and deletion of Customer Personal Information, for the purpose of enabling Customer to plan, conduct, record, and analyze field outreach activities.
Categories of Consumers (data subjects) Individuals whom Customer's team members visit, contact, or record during outreach activities, including residents at visited addresses and other contacts.
Categories of Customer Personal Information
- Location information: pin coordinates (latitude and longitude) and associated address-level location
- Outreach classification data: residence type, contact/answer status, and response type
- Free-text notes entered by team members, which may contain additional information about a Consumer
- Attribution metadata: the team member who created or last edited a record, and associated timestamps
Sensitive information Customer is instructed not to enter sensitive personal information, information about children under 13, government identifiers, financial account numbers, or biometric data, as set out in Section 4 of the Agreement and Section 2.3 of this DPA. To the extent Customer or its team members nonetheless enter such information into free-text fields in violation of those terms, Customer remains solely responsible for it.
Frequency of the processing Continuous, for the duration of the Agreement, based on Customer's and its team members' use of the Service.
ANNEX 2 — Technical and Organizational Security Measures
Reach maintains the following measures, which it may update provided the overall level of protection is not materially reduced:
Encryption - Encryption of Customer Personal Information in transit using TLS. - Encryption of Customer Personal Information at rest within Google Cloud / Firebase infrastructure.
Access control - Role-based access within the Service (Owner, Team Lead, Member), enforced through database security rules. - Restriction of administrative access to Reach's backend to authorized personnel only. - Multi-factor authentication on administrative accounts used to manage the Service infrastructure. - Hashed storage of user passwords; plaintext passwords are never stored or accessible to Reach.
Application integrity - App-integrity attestation (Apple App Attest via Firebase App Check) to help ensure that only legitimate instances of the Reach application can access backend services.
Infrastructure security - Use of Google Firebase / Google Cloud as the underlying infrastructure provider, which maintains its own industry-standard physical and environmental security controls and independent security certifications. - Database security rules that constrain read and write access to Customer Personal Information based on team membership and role.
Operational measures - Review of third-party software dependencies for known security vulnerabilities. - Logging of access to backend services for security and abuse-prevention purposes.
Data minimization and segregation - Customer Personal Information is logically segregated by team. - Reach does not enable Firebase Analytics or Crashlytics, and does not collect advertising identifiers.
ANNEX 3 — Authorized Sub-processors
As of the Effective Date, Reach engages the following Sub-processors to process Customer Personal Information:
| Sub-processor | Service Provided | Processing Location |
|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Firebase App Check) | Cloud database hosting, authentication, and application-integrity attestation for Customer Personal Information | United States |
| Apple Inc. (App Attest) | Application-integrity attestation supporting Firebase App Check | United States |
Note on infrastructure-only providers. Reach's website hosting (Porkbun LLC), contact-form processing (Web3Forms), and bot-prevention (hCaptcha / Intuition Machines, Inc.) do not process Customer Personal Information as defined in this DPA; they process only information related to website visitors and individual Reach users, which is governed by the Privacy Policy rather than this DPA. They are therefore not listed as Sub-processors of Customer Personal Information.
This DPA is provided to satisfy the service provider and processor contracting requirements of applicable U.S. state privacy laws, including Cal. Civ. Code § 1798.100(d) and § 1798.140(ag), and the comparable processor-contract provisions of the Texas, Virginia, Colorado, Connecticut, and Oregon privacy statutes, in effect as of the "Last Updated" date above. It is not a substitute for review by licensed counsel.