Effective Date: September 29, 2026
Your organization owns and controls the data it puts into Hibox. We process it only to provide our services, as your service provider. We never sell it, use it for advertising, or use it to train AI models. We protect it with the security measures in Annex B, tell you within 72 hours of confirming a security incident, and delete it when you leave.
This summary is for convenience only. The full agreement below is what applies.
This Data Processing Agreement ("DPA") is between Hibox LLC, doing business as Hibox for Nonprofits ("Hibox"), and the organization that purchases the Services ("Customer").
This DPA is part of the agreement under which Hibox provides its services to Customer, including the Hibox Terms of Service and any order form (together, the "Agreement"). It explains how Hibox will handle Customer Data on Customer's behalf. It applies for as long as Hibox processes Customer Data.
Back to topWords not defined here have the meaning given in the Agreement.
3.1 Roles. Customer controls Customer Data and decides why and how it is processed. Hibox processes Customer Data only as Customer's service provider.
3.2 Instructions. Hibox will process Customer Data only to provide the Services, as described in the Agreement and Annex A, and as Customer directs through its use of the Services or in writing. Hibox will tell Customer if it believes an instruction breaks Data Protection Laws.
3.3 Limits on use. Hibox will not:
3.4 Legal requests. If Hibox receives a subpoena, court order, or other legal demand for Customer Data, Hibox will send it to Customer when the law allows and will not disclose Customer Data unless legally required.
3.5 Compliance. Hibox will follow the Data Protection Laws that apply to it as a service provider and will tell Customer if it can no longer meet its duties under them.
Back to topCustomer is responsible for:
Hibox will limit access to Customer Data to employees and contractors who need it to provide or support the Services. Each of them must be bound by a duty of confidentiality and receive training on protecting personal information. Hibox staff will access Customer Data only to provide the Services, provide support Customer requests, keep the Services secure, or meet legal requirements.
Back to topHibox will use reasonable technical and organizational measures to protect Customer Data, including the measures in Annex B. Hibox may update these measures over time, but will not lower the overall level of protection during the term of the Agreement.
Back to top7.1 Approval. Customer agrees that Hibox may use Subprocessors to help provide the Services. The current list is in Annex C.
7.2 Hibox duties. Hibox will have a written agreement with each Subprocessor that protects Customer Data at least as well as this DPA. Hibox remains responsible for the work of its Subprocessors.
7.3 New Subprocessors. Hibox will give Customer at least 30 days notice before adding or replacing a Subprocessor, by updating the list and notifying Customer's account administrator by email. If Customer has a reasonable data protection concern, Customer may object in writing during that time. The parties will work in good faith to resolve the concern. If they cannot, Customer may end the affected Services and receive a refund of any prepaid fees for the unused period.
7.4 Providers with their own duties. Some providers, such as Stripe for payments and Checkr and Sterling for background screening, also have their own legal duties and terms. Checkr and Sterling are consumer reporting agencies under the Fair Credit Reporting Act. When Customer uses these services, the provider's own terms also apply, and Customer may need to accept those terms directly with the provider.
Back to top8.1 Notice. Hibox will notify Customer without undue delay, and no later than 72 hours after confirming a Security Incident. Notice will go to Customer's account administrator by email.
8.2 Details. The notice will include what Hibox knows at the time, such as what happened, the types of Customer Data involved, the likely number of people affected, and the steps Hibox is taking. Hibox will send updates as it learns more.
8.3 Response. Hibox will take reasonable steps to contain the Security Incident and reduce harm. Hibox will help Customer meet any legal duty to notify affected people or government agencies. Customer decides whether and how to notify the people whose information was involved, unless the law requires Hibox to give notice directly.
8.4 No admission. Notice of a Security Incident is not an admission of fault.
Back to topMost requests can be handled by Customer directly in the Services, such as viewing, correcting, exporting, or deleting records. If a person contacts Hibox directly to access, correct, or delete Customer Data, Hibox will send the request to Customer and will not respond on its own unless Customer asks it to. Hibox will give Customer reasonable help with requests Customer cannot handle through the Services.
Back to top10.1 Information. When Customer asks in writing, Hibox will provide information reasonably needed to show that it follows this DPA. This may include completed security questionnaires, summaries of its security practices, and any available third party security reports.
10.2 Audits. If the information in 10.1 is not enough to meet a legal or funder requirement, Customer may ask to audit Hibox's compliance with this DPA, no more than once a year. Customer must give at least 30 days written notice. The parties will agree on the scope, timing, and length of the audit in advance. Audits must be done during normal business hours, must not disrupt the Services, and must protect the confidentiality of other customers' data. Customer pays its own costs.
Back to top11.1 Export. Customer may export Customer Data from the Services at any time during the term of the Agreement.
11.2 After the Agreement ends. Customer will have 30 days after the Agreement ends to export its Customer Data. After that, Hibox will delete or deidentify Customer Data within [NUMBER] days, unless the law requires Hibox to keep it. Copies in backups are kept for up to 30 days and will stay protected under this DPA until they are deleted.
11.3 Confirmation. When Customer asks, Hibox will confirm in writing that deletion is complete.
Back to top12.1 Children's data. Hibox will use information about children only to provide the Services to Customer and will never use it for advertising or marketing. Customer is responsible for getting any parent or guardian consent required by the Children's Online Privacy Protection Act (COPPA) and other laws.
12.2 School records. If Customer stores education records it receives from a school, Hibox will act under Customer's direct control for those records, will use them only to provide the Services, and will not share them except as allowed by the Family Educational Rights and Privacy Act (FERPA). Customer is responsible for its data sharing agreements with schools.
12.3 Health records. The Services are not designed to store records covered by the Health Insurance Portability and Accountability Act (HIPAA). Hibox does not act as a business associate under HIPAA, and Customer will not use the Services for records that require a business associate agreement.
12.4 Background screening. Customer is responsible for following the Fair Credit Reporting Act (FCRA) and state laws when it uses background screening results in the Services.
Back to top13.1 Term. This DPA lasts as long as the Agreement, and after that for as long as Hibox holds any Customer Data.
13.2 Liability. Each party's liability under this DPA, including any liability related to a Security Incident, is subject to the limits and exclusions of liability in the Agreement. Hibox does not offer any separate or additional liability for Security Incidents.
13.3 Order of precedence. If this DPA conflicts with the Agreement about the processing of Customer Data, this DPA controls.
13.4 Changes. Hibox may update this DPA to reflect changes in law or in the Services, but no update will lower the protection of Customer Data. Hibox will notify Customer's account administrator by email at least 30 days before an update takes effect.
13.5 Governing law. This DPA is governed by the same law that governs the Agreement.
13.6 Acceptance. By purchasing or using the Services, Customer agrees to this DPA. No signature is required. Hibox will provide a formal copy of this DPA for signature when Customer asks.
13.7 Public agencies. If Customer is a school district, city, county, or other public agency, public records laws may apply to the Agreement and this DPA. Hibox will work with Customer to protect confidential information, such as security details, to the extent those laws allow.
13.8 Security and privacy contact. Questions about security, privacy, or this DPA can be sent to support@hibox.co.
Back to top| Item | Details |
|---|---|
| Purpose | Providing the Hibox Services to Customer, including support and security |
| Nature of processing | Storing, organizing, displaying, sending, reporting on, exporting, and deleting Customer Data as directed through the Services |
| Duration | The term of the Agreement, plus the export and deletion periods in Section 11 |
| People whose data is processed | Participants and their families, staff, volunteers, board members, donors, and people outside the organization who submit forms or book meetings |
| Types of Customer Data | Names and contact details; birth dates; enrollment, attendance, and program records; household income and demographics; allergies, medications, and custody or pickup details; HR, pay, leave, and time records; background screening results; donor and gift records; payment records; grant records; emails, text messages, chat messages, and files; training records |
| Sensitive data | Information about children; background screening results; household income; demographic information; basic health details for program safety |
| Subprocessors | Listed in Annex C |
| Location | United States |
As of the Effective Date, Hibox uses these Subprocessors.
| Subprocessor | Service | Customer Data involved |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and data storage | All Customer Data |
| Twilio | Text message delivery | Phone numbers and text message content |
| SendIt | Email delivery | Email addresses and email content |
| Stripe | Payment processing for program fees and donations | Payer names, contact details, payment details, and amounts |
| Checkr | Background screening | Information about the person being screened and screening results |
| Sterling | Background screening | Information about the person being screened and screening results |
| OpenAI | AI features | Information included in a request when a User uses an AI feature. OpenAI may keep this data for up to 30 days for abuse monitoring and does not use it to train its models. |
| UptimeRobot | Service uptime monitoring | None |