Roles
Where Coopsphere processes personal information on behalf of a customer organization, the organization is the controller (or data controller equivalent) and Coopsphere is the processor. This addendum applies in addition to the Terms of Service.
Scope of processing
- Subject matter: provision of the Coopsphere cooperative-management platform.
- Duration: for the term of the subscription plus the applicable retention window.
- Categories of data subjects: administrators, officers, members and other users designated by the organization.
- Categories of data: identity, contact, membership, KYC, financial, governance, document and usage information.
Processor obligations
- Process personal information only on documented instructions from the organization, unless required otherwise by law.
- Ensure that personnel with access are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures, as described in the Security Overview.
- Assist the organization with data-subject requests and with security, breach-notification and impact-assessment obligations, taking into account the nature of the processing.
- Delete or return personal information at the end of the service, subject to legal retention requirements.
Subprocessors
Coopsphere uses the subprocessors listed in the Subprocessor List. We impose data-protection obligations on subprocessors that are consistent with this addendum, and we remain responsible for their performance. Customers will be informed of material changes to the list.
International transfers
Where processing involves transfers across borders, we apply appropriate contractual and technical safeguards suitable to the transfer and the applicable law.
Security incidents
Coopsphere will notify the affected organization without undue delay after becoming aware of a personal-data breach affecting its data, and will provide the information reasonably available to support the organization's own notification obligations.