Kingdom Perspective, LLC — My Purpose Plan Version 1.0 · Effective on execution


This Data Processing Agreement ("DPA") forms part of the Agreement between ________ ("Customer") and Kingdom Perspective, LLC ("Provider") and applies to Provider's processing of Customer Personal Data in connection with the My Purpose Plan services (the "Services").

1. Definitions

  • "Personal Data" — information that identifies, relates to, or could reasonably be linked with an identified or identifiable natural person.
  • "Customer Personal Data" — Personal Data processed by Provider on behalf of Customer in providing the Services, comprising Customer Business Data and Employer-Linked Content, including within those categories Personal Data of Customer's employees who use the Services ("Employee Users"). Personal-Scope Content is not Customer Personal Data.
  • "Employee-Authored Content" — content created within the Services by an Employee User, comprising Employer-Linked Content and Personal-Scope Content. Employee-Authored Content remains subject to Section 6 in every circumstance, including Customer's termination under Section 5.2 and an individual Employee User's departure under Section 5.3.
  • "Employer-Linked Content" — the Employee-Authored Content that exists by reason of Customer's provision of the Services: check-in and check-out entries, including written reflections; recognition sent to colleagues ("shout-outs"); posts to Customer's organization feed; monthly workplace survey responses; and the AI-generated daily check-in content derived from these.
  • "Personal-Scope Content" — the Employee-Authored Content personal to the Employee User's own account: the purpose statement and its inputs; purpose tiles, tasks, and plans; messages; uploaded images; feedback submitted to Provider; and volunteer applications. Provider processes Personal-Scope Content as described in Section 2.5.
  • "Customer Business Data" — Customer Personal Data that is not Employee-Authored Content, including account and administrative records, billing records, and the aggregated, role-attributed workforce reporting described in Section 6. Customer Business Data is the data covered by Customer's delete-or-return election under Section 5.2.
  • "Applicable Data Protection Law" — the United States state privacy and data protection laws applicable to the processing of Customer Personal Data under this DPA.
  • "Sell" and "Share" have the meanings given in Applicable Data Protection Law.

2. Roles and Scope of Processing

  1. Customer is the business or controller, and Provider processes Customer Personal Data as Customer's service provider or processor, solely for the purposes described in Exhibit A.
  2. Provider shall process Customer Personal Data only in accordance with this DPA and the documented functionality of the Services, which constitutes Customer's complete processing instructions. Additional instructions require written agreement of the parties.
  3. Provider shall not: (a) Sell or Share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than providing the Services, or outside the direct business relationship with Customer; or (c) combine Customer Personal Data with Personal Data received from other sources, except as permitted by Applicable Data Protection Law for security, deduplication, or service improvement internal to the Services.
  4. Provider certifies that it understands and will comply with the restrictions in this Section 2. Provider shall notify Customer without undue delay if it determines it can no longer meet its obligations under Applicable Data Protection Law.
  5. Personal-Scope Content. Provider processes Personal-Scope Content in its direct relationship with each Employee User, as a business in its own right under its published Privacy Policy, and not on Customer's behalf or instruction. It is defined in this DPA because Sections 5 and 6 depend on the distinction: Personal-Scope Content is outside Customer's right of access, is not subject to Customer's election under Section 5.2, and is unaffected by termination of the Agreement, remaining governed by the Employee User's own account.

3. Confidentiality

Provider shall ensure that all personnel authorized to process Customer Personal Data are bound by written confidentiality obligations and process Customer Personal Data only as needed to perform their functions.

4. Security

Provider shall implement and maintain administrative, technical, and physical safeguards appropriate to the nature of the Customer Personal Data processed, as described in Exhibit B, including encryption in transit and at rest, role-restricted access, and automated verification of the access restrictions stated in Section 6.

5. Retention and Deletion

  1. Provider retains and disposes of Customer Personal Data in accordance with its published Data Retention Schedule, which is incorporated by reference. Provider shall not materially reduce the protections of the Schedule during the term without notice to Customer.
  2. Upon termination or expiration of the Agreement, Provider shall, at Customer's election, delete or return Customer Business Data (return being in a commonly used, machine-readable format) within the periods stated in the Schedule (§3, Customer contract termination), save where retention is required by law (in which case Provider retains only what the law requires, for the period the law requires). This election does not extend to Employee-Authored Content, which Section 6 places outside Customer's right of access in every circumstance, including termination. Provider shall dispose of employer-linked Employee-Authored Content per Section 5.3 upon termination, following the same roster-wide process as an individual Employee User's departure.
  3. When Customer removes an Employee User from the Services, or upon Customer's termination under Section 5.2, that individual's Employer-Linked Content — together with job role, work area, and reminders — is deleted or de-identified per the Schedule without further instruction; recognition is retained for the recipient with the departing Employee User's identifying fields removed. Personal-Scope Content and consent records are not disposed of by removal or by Customer's termination and remain governed solely by that individual's own account, per Section 2.5. Employment and billing records are retained under the Schedule's legal-obligation periods.

6. Employee-Authored Content; Access Restrictions

  1. The parties acknowledge that the value of the Services to Employee Users depends on the confidentiality of Employee-Authored Content from their employer. Accordingly, and notwithstanding any other provision of the Agreement: - Customer has no right of access to Employee-Authored Content, and Provider shall not disclose it to Customer. This restriction does not extend to tasks on a collaborative tile — shared between an Employee User and colleagues — which Provider transmits, together with the contributing Employee Users' name, email address, role, and organization identifier, to a workspace Customer's administrator has connected, on Customer's instruction, as described in Exhibit C; - Customer receives only aggregated reporting attributing content to job role, containing no names or direct identifiers, restricted to roles with at least three distinct contributing Employee Users in the reporting period; an AI-generated summary of that reporting, where included, is produced under the same role-level, threshold-gated aggregation and is not attributed to any individual; - Provider shall not disclose to Customer whether an individual Employee User participates in check-ins or reflections, with what frequency, or the status of any consent election. This restriction does not extend to features that identify participants to their team by design: team recognition ("shout-outs"), which an Employee User enters by choosing to send one, and the task-completion leaderboard, which ranks completion of assigned team tasks and is visible to the employer.
  2. These restrictions are enforced at Provider's database layer and verified by automated test.
  3. Nothing in this Section limits an Employee User's own statutory rights, which Provider honors directly through the Services.

7. Sensitive Data and Consent

Provider obtains opt-in consent from Employee Users before processing user-authored content that may reveal sensitive Personal Data, maintains records evidencing such consent, and provides withdrawal mechanisms, each as described in Provider's Privacy Policy. Customer shall not instruct Provider to process sensitive Personal Data of Employee Users outside this consent framework.

8. Data Subject Requests

  1. Provider provides in-application mechanisms through which Employee Users exercise access, correction, deletion, and portability rights directly, and Provider responds within the periods stated in its Privacy Policy.
  2. Where Customer receives a verifiable request concerning Customer Personal Data that Customer cannot fulfil through the Services' administrative functions, Provider shall provide reasonable assistance, taking into account the nature of the processing.
  3. Provider shall not respond to a request from Customer for Employee-Authored Content; Section 6 controls.

9. Security Incidents

Provider shall notify Customer without undue delay after becoming aware of a security incident resulting in unauthorized access to, or unauthorized disclosure, loss, or alteration of, Customer Personal Data, and in no event later than 72 hours after confirming the incident, and shall provide information reasonably required for Customer to meet its own notification obligations under applicable breach notification statutes. Provider's notification shall describe the nature of the incident, the categories and approximate number of individuals affected, measures taken, and a contact point, and may be preliminary and supplemented as investigation proceeds.

10. Subprocessors

  1. Customer provides general authorization for the subprocessors listed in Exhibit C (as maintained in Provider's published subprocessor register).
  2. Provider shall: (a) impose data protection obligations on each subprocessor no less protective than this DPA; (b) remain responsible for subprocessors' performance; and (c) provide notice of the addition or replacement of a subprocessor at least 30 days before it processes Customer Personal Data, during which Customer may object on reasonable data-protection grounds.
  3. Where Customer so objects and the parties do not resolve the objection within thirty (30) days of good-faith discussion, Customer may terminate the affected Services on written notice, without penalty beyond fees accrued.

11. Demonstration of Compliance

Upon written request no more than once annually, Provider shall make available documentation reasonably necessary to demonstrate compliance with this DPA, which may include its retention registry and enforcement test results, its data protection assessment (under confidentiality), and summaries of third-party reviews. Audits are satisfied by documentation review; on-site inspection is not provided. Customer may, upon reasonable prior written notice, take reasonable and appropriate steps permitted by Applicable Data Protection Law to stop and remediate unauthorized use of Customer Personal Data.

12. General

  1. This DPA is effective as of the date of its execution and continues for the term of the Agreement plus any period during which Provider retains Customer Personal Data.
  2. In the event of conflict between this DPA and the Agreement concerning the processing of Customer Personal Data, this DPA controls.
  3. Liability under this DPA is subject to the limitations and exclusions of the Agreement.
  4. Notices under this DPA are sent to the addresses stated in the Agreement, with a copy to privacy@mypurposeplan.com.

Exhibit A — Processing Details

Item Description
Subject matter Provision of the My Purpose Plan Services
Duration Term of the Agreement, plus retention periods of the Data Retention Schedule
Nature and purpose Hosting and storage; content generation and translation by artificial intelligence for the authoring user; aggregated workforce reporting; service communications; support
Categories of data subjects Employee Users; Customer administrative contacts
Categories of Personal Data Account information (name, email, role); Employer-Linked Content; device and usage data; billing records. Personal-Scope Content is processed by Provider as a business in its own right (Section 2.5), not on Customer's behalf
Sensitive Personal Data User-authored content may reveal religious beliefs or health information; processed only under the consent framework of Section 7

Exhibit B — Security Measures (summary)

Encryption in transit and at rest (Google Cloud Platform, United States); role-based access control with a dedicated, narrowed grant for user content; database-layer access rules verified by automated test; automated retention enforcement with per-category disposal logging; deletion verification by automated export; payment processing isolated to Stripe and the mobile app stores (no card data on Provider systems).

Exhibit C — Subprocessors

Per Provider's published subprocessor register as of the Effective Date: Google Cloud / Firebase (hosting, database, authentication, storage, push messaging, crash reporting, analytics); OpenAI (content generation and translation); Google (Gemini API) (content generation and translation, as a failover provider); Stripe (payments); RevenueCat (mobile in-app subscription management — receives app user id, email address, and purchase history for mobile users); SendGrid (email); Google Maps (coordinate-to-location lookup for volunteer search, user-initiated; coordinates not stored).

Where Customer's administrator connects a workspace (currently, Notion) to the Services, Provider transmits selected Employee-Authored Content and identity data to that workspace on Customer's instruction, and receives task information from that workspace at Customer's direction to populate the corresponding collaborative tiles. This is not a subprocessor relationship and the workspace is not listed above: the receiving account is Customer's own and is governed by Customer's own agreement with that provider, so no term of this DPA attaches to data once it arrives there.

Separately, where an individual Employee User applies to a volunteer opportunity through the Services' "Connect" feature, Provider transmits that individual's name, email address, and any attachment they supply to the platform hosting the opportunity (currently, Idealist) and through it to the posting organization. This is neither a subprocessor relationship nor a Customer-directed one: the transmission occurs at the individual Employee User's own election, to a recipient that individual selects, and the recipient is the controller of the application it receives. Customer gives no instruction and bears no obligation in respect of it, and Provider retains no copy of the attachments.