This page is maintained by doimpact.llc to describe how personal data is processed when customers use the platform. It must be reviewed by a qualified lawyer and, if required, executed as a separate agreement before it creates legal obligations.
Data Processing Agreement
Effective date: August 5, 2026
Operator: doimpact.llc, a Delaware limited liability company. Business address: 131 Continental Dr, Suite 305, Newark, DE 19713, US.
1. Roles
The customer is the controller of personal data uploaded into its workspace. doimpact.llc is the processor, except where doimpact.llc determines the purposes and means of processing (for example, account administration and billing), in which case it acts as a controller.
2. Categories of Data Subjects
The customer may upload personal data relating to:
- Employees and contractors (names, contact details, roles, skills, development plans, training records).
- Customer contacts and stakeholders (names, email addresses, phone numbers, job titles).
- Users of the platform (email addresses, authentication data, activity logs).
3. Categories of Personal Data
Data processed may include contact information, professional identifiers, employment details, and any other personal data the customer chooses to upload. The customer is responsible for limiting uploads to data necessary for the agreed purpose and for obtaining lawful grounds for processing.
4. Permitted Processing
doimpact.llc will process personal data only to provide, maintain, secure, and improve the platform; to perform customer support; to comply with legal obligations; and as otherwise instructed by the customer in writing through the platform or support channels.
5. Subprocessors
doimpact.llc may engage subprocessors to support the platform. The current list includes:
- Lovable Cloud — cloud infrastructure, database, authentication, and storage.
- AI model providers — used only for the optional Exec Team Room add-on, and only when enabled by the customer.
- Email delivery providers — for transactional emails, invitations, and notifications.
- Payment processor — Stripe for billing.
We will notify customers of any new subprocessors that materially affect the processing and provide an opportunity to object where required by law.
6. Security Measures
The team implements technical and organizational measures including encryption in transit and at rest, access controls, row-level database security, audit logging, regular reviews, and incident response procedures. Details are described on the Security page.
7. Confidentiality
Personnel who may access personal data are bound by confidentiality obligations and access is limited to the minimum necessary for their role.
8. Data Subject Requests
The customer is responsible for receiving and handling requests from data subjects. The team will assist the customer in fulfilling these requests, including access, correction, deletion, and portability, to the extent technically feasible.
9. Security Incidents
The team will notify the customer without undue delay and no later than 72 hours after becoming aware of a confirmed personal data breach that affects the customer’s data. Notifications will include the nature of the breach, affected data subjects, likely consequences, and measures taken or proposed.
10. Return and Deletion
At the end of the agreement, the team will return or delete the customer’s personal data in accordance with the customer’s instructions, except where retention is required by applicable law. Data may be retained in anonymized or aggregated form for operational analytics.
11. Audit and Compliance
The customer may request reasonable information about the team’s compliance with this DPA. On-site audits are not generally available; the team will provide questionnaires, security documentation, or third-party reports where applicable.
12. International Transfers
Personal data may be transferred to and processed in the United States and other jurisdictions. We rely on Standard Contractual Clauses or equivalent transfer mechanisms for transfers from the EEA, UK, and other jurisdictions requiring such safeguards.
13. Contact
For data processing questions, contact us through /security-contact or email contact@doimpact.app.