Data Processing Agreement

Last Updated: July 19, 2026

This Data Processing Agreement ("DPA") governs the processing of personal data by Elective Labs LLC, a Wyoming limited liability company ("Elective Labs" or "Processor"), on behalf of our clients ("Data Controllers") who use our platform to manage their political campaigns and related operations. This DPA applies to all processing of personal data in connection with the Elective Labs service.

1. Definitions

Data Controller: The entity (campaign, candidate, political organization) that determines the purposes and means of processing personal data.

Data Processor: Elective Labs LLC, which processes personal data on behalf of the Data Controller according to documented instructions.

Personal Data: Any information relating to an identified or identifiable natural person (names, email addresses, phone numbers, donation amounts, volunteer activity, etc.).

Processing: Any operation performed on personal data, including collection, storage, use, transfer, deletion, or analysis.

Sub-processor: A third-party service provider authorized by Elective Labs LLC to process personal data on our behalf.

2. Scope & Purpose

Elective Labs LLC processes personal data as a Data Processor solely to provide SaaS services to the Data Controller, including campaign management, fundraising tracking, volunteer coordination, communications, compliance monitoring, and analytics. All processing is performed strictly in accordance with the Data Controller's documented instructions and applicable data protection laws.

3. Data Processing Details

Types of Personal Data Processed:

  • Donor information (names, contact details, donation amounts, contribution history)
  • Volunteer information (names, contact details, availability, shift participation)
  • Campaign finance data (contribution records, compliance documentation)
  • Communication logs (emails, SMS, social media interactions)
  • Staff and officer information (campaign team members, roles, contact details)
  • Constituent and prospect data (engagement metrics, event attendance, communication history)

Data Subjects: Donors, volunteers, campaign staff, officers, constituents, and other individuals whose data is processed through the platform.

Duration of Processing: For the duration of the service agreement and any renewal periods, unless instructed otherwise by the Data Controller.

4. Obligations of the Processor

Elective Labs LLC commits to:

  • Process personal data only on documented instructions from the Data Controller and for no other purpose
  • Ensure that all personnel involved in processing are bound by confidentiality agreements
  • Implement and maintain appropriate technical and organizational security measures
  • Authorize only necessary Sub-processors and maintain a current list available to the Data Controller
  • Notify the Data Controller of any personal data breach without undue delay, and in any event within the timeframes required by applicable law
  • Comply with data subject requests (access, correction, deletion, portability) and assist the Data Controller in responding
  • Return or securely delete all personal data upon termination of the service agreement, as instructed

5. Security Measures

Elective Labs LLC implements and maintains appropriate technical and organizational security measures, including:

  • Encryption of personal data at rest via our cloud provider's server-side encryption (AES-256), with additional application-layer encryption for integration credentials
  • Encryption of personal data in transit using TLS 1.2 or higher
  • Role-based access controls and principle of least privilege
  • Comprehensive audit logging of all data access and processing activities
  • Regular security assessments, penetration testing, and vulnerability scanning
  • Incident response and breach notification procedures
  • Employee security training and background checks for personnel with data access
  • Multi-factor authentication for administrative access

6. Sub-processors

Elective Labs maintains a single, current list of all Sub-processors (including Google Cloud / Firebase, Vercel, Stripe, SendGrid, Twilio, and Anthropic) at electivelabs.org/legal/subprocessors. That page is the authoritative Sub-processor list incorporated into this DPA by reference, including each Sub-processor's function and processing location.

The Data Controller may object to the use of any Sub-processor by providing written notice within 30 days of being informed of the change. Elective Labs will either cease use of the Sub-processor or terminate the service agreement.

7. Data Subject Rights

Elective Labs LLC will, at the Data Controller's request, assist in fulfilling data subject rights requests:

  • Right of access: Data subjects may request a copy of their personal data
  • Right of rectification: Data subjects may request correction of inaccurate personal data
  • Right of erasure: Data subjects may request deletion of their personal data
  • Right of data portability: Data subjects may request their data in a portable format
  • Right to restrict processing: Data subjects may restrict how their data is used

The Data Controller is responsible for responding to data subject requests. Elective Labs LLC will provide reasonable assistance to enable compliance within applicable legal timeframes.

8. Data Transfers

Primary Processing Location: Elective Labs LLC processes personal data primarily in the United States through our cloud infrastructure and service providers.

International Transfers: For transfers of personal data outside the United States, Elective Labs LLC relies on Standard Contractual Clauses (SCCs) and other lawful mechanisms to ensure adequate protection. Data Controllers may request information about the specific transfer mechanisms used for their data.

9. Data Retention & Deletion

During the Agreement: Elective Labs LLC will retain personal data for the duration of the service agreement to provide the platform and services.

After Termination: Upon termination of the service agreement, Elective Labs LLC will, at the Data Controller's election:

  • Delete all personal data within 30 days, or
  • Export all personal data in a structured, portable format for the Data Controller to retain

Elective Labs LLC may retain anonymized data for statistical and compliance purposes, provided such data cannot be linked to any individual.

10. Audit Rights

The Data Controller has the right to audit Elective Labs LLC's compliance with this DPA. Audits must be:

  • Requested in writing with at least 30 days' notice
  • Conducted during normal business hours
  • Subject to confidentiality requirements
  • Limited to once per year unless justified by specific concerns

Upon written request, Elective Labs will furnish a summary of its security practices and, once available, copies of any third-party audit reports.

11. Liability & Indemnification

Elective Labs LLC will indemnify and hold harmless the Data Controller from third-party claims arising from a Processor's failure to comply with this DPA, provided the Data Controller has not contributed to the violation through its own instructions or actions.

Liability for data breaches and processing violations shall be governed by the Terms of Service and applicable law.

12. Term & Termination

This DPA is effective for the duration of the service agreement and any renewals. Upon termination of the service agreement, all obligations under this DPA cease except those that survive termination (such as confidentiality, audit rights, and data deletion).

Either party may terminate this DPA if the other party materially breaches and fails to cure within 30 days of written notice.

13. Contact & Questions

For questions about this Data Processing Agreement or to report a data breach:

Data Protection Officer / Privacy Contact: dpa@electivelabs.org

General Support: support@electivelabs.org

Related documents: Privacy Policy · Terms of Service