§1What this is
Your members' data is yours. We hold it for you, use it only to run the service you are paying for, and hand it back or delete it when you leave. This page is the enforceable version of that sentence.
This Data Processing Addendum ("Addendum") forms part of the Terms of Service between InformaDev LLC d/b/a TrainedResponder ("TrainedResponder", "we") and the organization that subscribes to the service ("Customer", "you"). It governs our processing of personal information you or your members put into the platform ("Customer Personal Information").
It applies to every customer as a term of the Terms of Service; no signature is needed. If your procurement process requires a countersigned copy, email [email protected] and we will provide one. Where this Addendum and the Terms of Service conflict on the handling of personal information, this Addendum controls.
§2Roles of the parties
For Customer Personal Information, you are the business and controller, and we are the service provider and processor, as those terms are used in the California Consumer Privacy Act as amended ("CCPA") and in the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other US states.
That means you decide what personal information is collected about your members, why, and who inside your organization sees it. We process it only on your documented instructions. Your instructions are: the Terms of Service, this Addendum, the configuration choices you make in the application, and any further written instruction you give us that is consistent with them.
We are separately the business and controller for the account and billing information of the people who administer your subscription, and for visitors to our website. That processing is described in the Privacy Policy, not here.
§3Our obligations
We commit, for as long as we hold Customer Personal Information, that we will:
- Process it only for the limited and specified purposes of providing, securing, supporting, and maintaining the service under our agreement with you.
- Never sell it and never share it for cross-context behavioral advertising, or for targeted advertising under any state's law.
- Never retain, use, or disclose it for any other purpose, including for a commercial purpose of our own, and never outside the direct business relationship between us — except where the law requires disclosure, in which case we will tell you first unless we are legally prohibited from doing so.
- Never combine it with personal information from another source, except as needed to perform a business purpose you have authorized or as the CCPA otherwise permits. One customer's data is never mixed with another's, and we do not build a cross-customer data set of members.
- Comply with the obligations the CCPA and other applicable state privacy laws place on a service provider and processor, and provide the same level of privacy protection those laws require of you.
- Bind every person who handles it to confidentiality, and limit access to those who need it to do their job.
- Tell you promptly if we determine we can no longer meet these obligations, so you can stop and remediate any unauthorized use.
- De-identify or aggregate before using anything for improvement. Where we use service data to improve the platform, it is aggregated or de-identified so it no longer identifies any person or organization, and we do not attempt to re-identify it.
You may take reasonable and appropriate steps to confirm we are using Customer Personal Information consistently with your obligations, and to stop and remediate any unauthorized use. See §9.
§4Your responsibilities
You decide what goes into the platform, and some of it we cannot see coming — a custom member data field is yours to define. So you are responsible for:
- Having a lawful basis to collect the personal information you put in, and giving your members whatever notice your program and applicable law require.
- Obtaining parental or guardian consent before entering a member under 18 where your program or the law requires it.
- The accuracy of what you enter, and for responding to your own members' privacy requests — we will help, and §7 says how.
- Managing who in your organization holds Owner, OrgAdmin, or UnitAdmin access, and removing access promptly when someone leaves.
- Not putting categories of data into the platform that it is not built for — protected health information subject to HIPAA, payment card numbers, or Social Security numbers do not belong in a member record or a custom field.
§5Subprocessors
You authorize us to engage the subprocessors listed below. Each is bound by a written contract imposing data protection obligations no less protective than this Addendum, and we remain responsible to you for their performance.
| Subprocessor | What it does | What it receives |
|---|---|---|
| Hosting provider | Runs the application and its database in the United States. | All Customer Personal Information, at rest. |
| Microsoft (Graph) | Delivers service email. | Recipient name and email address, and the message content. |
| Telnyx | Delivers and receives text messages for members who opt in. | Mobile number, opt-in status, and message content. |
| Stripe | Processes subscription payments. | Billing contact and payment details. No member records. |
| Cloudflare | Bot screening on public signup; lesson video hosting and delivery. | IP address and request metadata; uploaded lesson video. |
| Google (Gemini) or Anthropic (Claude) | Drafts course content when an administrator uses AI generation. | Only the course material submitted for generation. No member records. |
| LocationIQ | Address suggestions in event and unit location fields. | The address text being typed. |
We will give account Owners at least 30 days' notice by email before adding or replacing a subprocessor that handles Customer Personal Information. If you reasonably object on data protection grounds within that period, tell us and we will work with you on a resolution; if we cannot reach one, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
Customer Personal Information is stored in the United States. We do not transfer it outside the United States, and no subprocessor above is engaged to store it elsewhere.
§6Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- Encryption in transit — TLS on every connection to the application.
- Credential protection — passwords stored hashed and salted; platform secrets held encrypted rather than in configuration files; account lockout after repeated failed sign-ins.
- Tenant isolation — every record is scoped to one organization, enforced in the data layer rather than left to each screen.
- Role-based access — Owner, OrgAdmin, UnitAdmin, and Member roles, plus unit-level scoping, all set by you.
- Audit trail — administrative actions written to an append-only record your Owners and OrgAdmins can review.
- Least-privilege operational access — support and diagnostic access to production is read-only and token-gated.
- Backups — encrypted, retained on a rotation, and restorable.
We may change these measures as technology moves, but not in a way that materially reduces the overall security of the service.
§7Member requests
Your members' privacy requests are yours to answer, because the record is yours. Most of what a request asks for you can do yourself, immediately, in the application: view a member's full record, correct it, export it, deactivate them, or delete them.
If a member contacts us directly, we will not act on the request ourselves. We will tell them to contact you, and forward the request to your Owners and OrgAdmins so nothing is lost. Where you need help — an export we can produce faster, a deletion that spans records — we will provide reasonable assistance at no charge, and we will act on your deletion and correction instructions promptly.
§8Security incidents
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Information, we will notify your account Owners without undue delay and no later than 72 hours after we confirm it. The notice will describe what we know: the nature of the incident, the categories and approximate number of records involved, the likely consequences, and the steps we are taking.
We will cooperate reasonably with your own investigation and with any notifications you are required to make. Notifying you is not an admission of fault by either of us.
§9Demonstrating compliance
On written request, and no more than once a year unless a regulator or a confirmed incident requires otherwise, we will make available the information reasonably necessary to demonstrate our compliance with this Addendum, and respond to a reasonable security questionnaire.
Where that is not sufficient for your obligations, we will work with you in good faith on a proportionate assessment, conducted on reasonable notice, during business hours, without unreasonable disruption, and subject to confidentiality. We will not give any auditor access to another customer's data.
§10Return and deletion
You can export your data at any time while your account is open. On termination or expiration, you have 30 days to request an export, after which we delete or de-identify Customer Personal Information within 60 days of the end of the subscription term.
We may keep what the law requires us to keep — invoices and payment records for tax and accounting purposes — and residual copies persist in encrypted backups until they age out on their rotation. Anything retained stays subject to this Addendum for as long as we hold it.
§11Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing a training, qualification, and operations management platform to the Customer. |
| Nature and purpose | Storage, organization, retrieval, display, transmission, and deletion of member and training records, so the Customer can run training, track qualifications, schedule and staff activities, and report on them. |
| Categories of data subjects | The Customer's members, volunteers, staff, and administrators; emergency contacts named by them; and outside responders the Customer records for mutual aid. |
| Categories of personal information | Identifiers and contact details; emergency contact details; a government-issued responder or badge number where recorded; unit, rank, role, and qualifications; course, exam, and evaluation results; event attendance, hours, mileage, and equipment; uploaded documents and images; whatever the Customer defines in its own custom fields; and usage and audit records. |
| Sensitive personal information | Account credentials, and a government-issued identification number where the Customer records one. Used only to perform the service. |
| Frequency | Continuous, for the term of the subscription. |
| Duration | The term of the subscription, plus the deletion window in §10. |
| Location | United States. |
§12Changes
We may update this Addendum to reflect a change in the law, a new subprocessor, or a change in how the service works. We will not make a change that materially reduces your protections without giving account Owners at least 30 days' notice by email, and the effective date at the top always tells you which version is current.
Procurement and security review
Send questionnaires, countersignature requests, and security questions to [email protected].
InformaDev LLC d/b/a TrainedResponder