Hibox for Nonprofits Data Processing Agreement

Effective Date: September 29, 2026

Agreement at a glance

Your organization owns and controls the data it puts into Hibox. We process it only to provide our services, as your service provider. We never sell it, use it for advertising, or use it to train AI models. We protect it with the security measures in Annex B, tell you within 72 hours of confirming a security incident, and delete it when you leave.

This summary is for convenience only. The full agreement below is what applies.

1.Introduction

This Data Processing Agreement ("DPA") is between Hibox LLC, doing business as Hibox for Nonprofits ("Hibox"), and the organization that purchases the Services ("Customer").

This DPA is part of the agreement under which Hibox provides its services to Customer, including the Hibox Terms of Service and any order form (together, the "Agreement"). It explains how Hibox will handle Customer Data on Customer's behalf. It applies for as long as Hibox processes Customer Data.

Back to top

2.Definitions

Words not defined here have the meaning given in the Agreement.

  • "Customer Data" means personal information that Customer or its Users enter into the Services, or that others submit to Customer through the Services, and that Hibox processes on Customer's behalf.
  • "Data Protection Laws" means all United States federal and state privacy and data protection laws that apply to the processing of Customer Data under the Agreement.
  • "Personal Information" means any information that identifies or can reasonably be linked to a specific person.
  • "Process" means any action taken on Customer Data, such as collecting, storing, using, sharing, or deleting it.
  • "Security Incident" means a confirmed breach of security that leads to the accidental or unlawful destruction, loss, change, disclosure of, or access to Customer Data.
  • "Services" means the Hibox software and related services provided under the Agreement.
  • "Subprocessor" means a third party that Hibox engages to process Customer Data.
  • "Users" means the people Customer allows to use the Services, such as staff, volunteers, and board members.
Back to top

3.Roles and Instructions

3.1 Roles. Customer controls Customer Data and decides why and how it is processed. Hibox processes Customer Data only as Customer's service provider.

3.2 Instructions. Hibox will process Customer Data only to provide the Services, as described in the Agreement and Annex A, and as Customer directs through its use of the Services or in writing. Hibox will tell Customer if it believes an instruction breaks Data Protection Laws.

3.3 Limits on use. Hibox will not:

  • Sell or share Customer Data, as those terms are used in Data Protection Laws
  • Use Customer Data for advertising or marketing
  • Keep, use, or disclose Customer Data for any purpose other than providing the Services
  • Combine Customer Data with personal information from other sources, except as needed to provide the Services
  • Use Customer Data to train artificial intelligence models

3.4 Legal requests. If Hibox receives a subpoena, court order, or other legal demand for Customer Data, Hibox will send it to Customer when the law allows and will not disclose Customer Data unless legally required.

3.5 Compliance. Hibox will follow the Data Protection Laws that apply to it as a service provider and will tell Customer if it can no longer meet its duties under them.

Back to top

4.Customer Responsibilities

Customer is responsible for:

  • Having a lawful basis to collect Customer Data and to have Hibox process it
  • Giving any notices and getting any consents required by law, including parent or guardian consent for children
  • Setting User roles and permissions so that only authorized Users can see Customer Data, and removing access promptly when a User no longer needs it
  • Making sure its instructions to Hibox follow Data Protection Laws
  • Following the Hibox Acceptable Use Policy
Back to top

5.Hibox Personnel

Hibox will limit access to Customer Data to employees and contractors who need it to provide or support the Services. Each of them must be bound by a duty of confidentiality and receive training on protecting personal information. Hibox staff will access Customer Data only to provide the Services, provide support Customer requests, keep the Services secure, or meet legal requirements.

Back to top

6.Security

Hibox will use reasonable technical and organizational measures to protect Customer Data, including the measures in Annex B. Hibox may update these measures over time, but will not lower the overall level of protection during the term of the Agreement.

Back to top

7.Subprocessors

7.1 Approval. Customer agrees that Hibox may use Subprocessors to help provide the Services. The current list is in Annex C.

7.2 Hibox duties. Hibox will have a written agreement with each Subprocessor that protects Customer Data at least as well as this DPA. Hibox remains responsible for the work of its Subprocessors.

7.3 New Subprocessors. Hibox will give Customer at least 30 days notice before adding or replacing a Subprocessor, by updating the list and notifying Customer's account administrator by email. If Customer has a reasonable data protection concern, Customer may object in writing during that time. The parties will work in good faith to resolve the concern. If they cannot, Customer may end the affected Services and receive a refund of any prepaid fees for the unused period.

7.4 Providers with their own duties. Some providers, such as Stripe for payments and Checkr and Sterling for background screening, also have their own legal duties and terms. Checkr and Sterling are consumer reporting agencies under the Fair Credit Reporting Act. When Customer uses these services, the provider's own terms also apply, and Customer may need to accept those terms directly with the provider.

Back to top

8.Security Incidents

8.1 Notice. Hibox will notify Customer without undue delay, and no later than 72 hours after confirming a Security Incident. Notice will go to Customer's account administrator by email.

8.2 Details. The notice will include what Hibox knows at the time, such as what happened, the types of Customer Data involved, the likely number of people affected, and the steps Hibox is taking. Hibox will send updates as it learns more.

8.3 Response. Hibox will take reasonable steps to contain the Security Incident and reduce harm. Hibox will help Customer meet any legal duty to notify affected people or government agencies. Customer decides whether and how to notify the people whose information was involved, unless the law requires Hibox to give notice directly.

8.4 No admission. Notice of a Security Incident is not an admission of fault.

Back to top

9.Requests from Individuals

Most requests can be handled by Customer directly in the Services, such as viewing, correcting, exporting, or deleting records. If a person contacts Hibox directly to access, correct, or delete Customer Data, Hibox will send the request to Customer and will not respond on its own unless Customer asks it to. Hibox will give Customer reasonable help with requests Customer cannot handle through the Services.

Back to top

10.Audits and Information

10.1 Information. When Customer asks in writing, Hibox will provide information reasonably needed to show that it follows this DPA. This may include completed security questionnaires, summaries of its security practices, and any available third party security reports.

10.2 Audits. If the information in 10.1 is not enough to meet a legal or funder requirement, Customer may ask to audit Hibox's compliance with this DPA, no more than once a year. Customer must give at least 30 days written notice. The parties will agree on the scope, timing, and length of the audit in advance. Audits must be done during normal business hours, must not disrupt the Services, and must protect the confidentiality of other customers' data. Customer pays its own costs.

Back to top

11.Return and Deletion

11.1 Export. Customer may export Customer Data from the Services at any time during the term of the Agreement.

11.2 After the Agreement ends. Customer will have 30 days after the Agreement ends to export its Customer Data. After that, Hibox will delete or deidentify Customer Data within [NUMBER] days, unless the law requires Hibox to keep it. Copies in backups are kept for up to 30 days and will stay protected under this DPA until they are deleted.

11.3 Confirmation. When Customer asks, Hibox will confirm in writing that deletion is complete.

Back to top

12.Special Types of Data

12.1 Children's data. Hibox will use information about children only to provide the Services to Customer and will never use it for advertising or marketing. Customer is responsible for getting any parent or guardian consent required by the Children's Online Privacy Protection Act (COPPA) and other laws.

12.2 School records. If Customer stores education records it receives from a school, Hibox will act under Customer's direct control for those records, will use them only to provide the Services, and will not share them except as allowed by the Family Educational Rights and Privacy Act (FERPA). Customer is responsible for its data sharing agreements with schools.

12.3 Health records. The Services are not designed to store records covered by the Health Insurance Portability and Accountability Act (HIPAA). Hibox does not act as a business associate under HIPAA, and Customer will not use the Services for records that require a business associate agreement.

12.4 Background screening. Customer is responsible for following the Fair Credit Reporting Act (FCRA) and state laws when it uses background screening results in the Services.

Back to top

13.General Terms

13.1 Term. This DPA lasts as long as the Agreement, and after that for as long as Hibox holds any Customer Data.

13.2 Liability. Each party's liability under this DPA, including any liability related to a Security Incident, is subject to the limits and exclusions of liability in the Agreement. Hibox does not offer any separate or additional liability for Security Incidents.

13.3 Order of precedence. If this DPA conflicts with the Agreement about the processing of Customer Data, this DPA controls.

13.4 Changes. Hibox may update this DPA to reflect changes in law or in the Services, but no update will lower the protection of Customer Data. Hibox will notify Customer's account administrator by email at least 30 days before an update takes effect.

13.5 Governing law. This DPA is governed by the same law that governs the Agreement.

13.6 Acceptance. By purchasing or using the Services, Customer agrees to this DPA. No signature is required. Hibox will provide a formal copy of this DPA for signature when Customer asks.

13.7 Public agencies. If Customer is a school district, city, county, or other public agency, public records laws may apply to the Agreement and this DPA. Hibox will work with Customer to protect confidential information, such as security details, to the extent those laws allow.

13.8 Security and privacy contact. Questions about security, privacy, or this DPA can be sent to support@hibox.co.

Back to top

Annex A: Details of Processing

ItemDetails
PurposeProviding the Hibox Services to Customer, including support and security
Nature of processingStoring, organizing, displaying, sending, reporting on, exporting, and deleting Customer Data as directed through the Services
DurationThe term of the Agreement, plus the export and deletion periods in Section 11
People whose data is processedParticipants and their families, staff, volunteers, board members, donors, and people outside the organization who submit forms or book meetings
Types of Customer DataNames and contact details; birth dates; enrollment, attendance, and program records; household income and demographics; allergies, medications, and custody or pickup details; HR, pay, leave, and time records; background screening results; donor and gift records; payment records; grant records; emails, text messages, chat messages, and files; training records
Sensitive dataInformation about children; background screening results; household income; demographic information; basic health details for program safety
SubprocessorsListed in Annex C
LocationUnited States
Back to top

Annex B: Security Measures

  • Encryption. Customer Data is encrypted in transit and at rest.
  • Access control. Customers set role based permissions for their Users, including field level permissions for sensitive information. Hibox staff access is limited to those who need it and is removed promptly when no longer needed.
  • Login security. Passwords are stored in hashed form. [Two factor authentication is available to Users.]
  • Data separation. Each Customer's data is kept logically separate from other customers' data.
  • Hosting. The Services are hosted on Amazon Web Services (AWS) in the United States. AWS maintains industry standard physical and network security.
  • Backups. Customer Data is backed up regularly, and backups are kept for 30 days. Hibox keeps a disaster recovery plan to restore the Services after a major outage, and backups are stored separately from production systems.
  • Monitoring. Systems are monitored for unusual activity, and access to production systems is logged.
  • Updates. Software and systems are kept up to date with security fixes.
  • Staff. Hibox staff with access to Customer Data sign confidentiality agreements and receive security and privacy training.
  • Incident response. Hibox keeps a written plan for responding to Security Incidents.
Back to top

Annex C: Subprocessors

As of the Effective Date, Hibox uses these Subprocessors.

SubprocessorServiceCustomer Data involved
Amazon Web Services (AWS)Cloud hosting and data storageAll Customer Data
TwilioText message deliveryPhone numbers and text message content
SendItEmail deliveryEmail addresses and email content
StripePayment processing for program fees and donationsPayer names, contact details, payment details, and amounts
CheckrBackground screeningInformation about the person being screened and screening results
SterlingBackground screeningInformation about the person being screened and screening results
OpenAIAI featuresInformation included in a request when a User uses an AI feature. OpenAI may keep this data for up to 30 days for abuse monitoring and does not use it to train its models.
UptimeRobotService uptime monitoringNone
Back to top