Data processing agreement
A DPA must describe the role FundDaddy actually performs for a customer.
FundDaddy is a controller for the professional directory it builds for its own purposes. It may be a processor for some customer-owned notes or workflow data, but that role has not yet been mapped or approved.
Updated 31 August 2026
Draft status. A review draft: not indexed, and not final until checked by qualified counsel.
01
Is a DPA available for acceptance?
Not yet. One party is now settled — the processor would be Entro314 Labs SINGLE MEMBER P.C. (Entro314 Labs), Γ.Ε.ΜΗ. 193782603000 — but the customer contracting model, the controller/processor analysis over each data category, and a versioned acceptance mechanism are not. Presenting it as click-to-accept while the scope is undefined would create a contract nobody could perform.
02
What must the final DPA contain?
- Subject matter, duration, nature and purpose of processing.
- Data categories and groups of data subjects.
- Documented-instruction, confidentiality, security and assistance terms.
- Deletion or return, audit, incident and rights-request procedures.
- Verified subprocessors, authorization model and international-transfer terms.
- A schedule that separates FundDaddy’s controller activity from processor activity.
03
Does a customer DPA govern the FundDaddy directory?
Not merely because a customer uses the service. FundDaddy decides why and how it assembles the core professional directory, which points to an independent-controller role for that processing. A contract label cannot change the factual role.