Version 1.1 — effective Sep 26, 2026 · Version history
Document version: 1.1 · Effective date: 2026-09-26 · Last updated: 2026-09-26
Capitalized terms not defined here have the meaning given in the Terms of Service between Customer and True Wind Solutions, LLC (the "Agreement").
For Customer Personal Data, Customer is the Controller/Business and True Wind is the Processor/Service Provider. True Wind will Process Customer Personal Data only (a) on Customer's documented instructions, including as set out in the Agreement and this DPA, (b) as necessary to provide the Service, or (c) as required by law, in which case True Wind will inform Customer before Processing unless legally prohibited from doing so. True Wind will not sell or share Customer Personal Data, and will not retain, use, or disclose it for any purpose other than providing the Service, or as otherwise permitted by Applicable Data Protection Law.
This DPA applies for as long as True Wind Processes Customer Personal Data under the Agreement. The subject matter, nature, and purpose of Processing, categories of Data Subjects, and categories of Personal Data are described in Annex A.
Customer will ensure its instructions comply with Applicable Data Protection Law, including that Customer has an appropriate legal basis for its collection and submission of Customer Personal Data to the Service and for any instruction it gives True Wind. If True Wind believes an instruction violates Applicable Data Protection Law, it will notify Customer (without obligation to actively monitor Customer's compliance).
True Wind will ensure that personnel authorized to Process Customer Personal Data are subject to a written confidentiality obligation and are trained on applicable data protection requirements.
True Wind will implement appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, as described in Annex B. Customer is responsible for configuring the Service's available security controls (e.g., role-based access, admin permissions) appropriately for its own use case.
7.1 General authorization. Customer authorizes True Wind to engage the Subprocessors listed in Annex C as of the effective date of this DPA.
7.2 New subprocessors. True Wind will provide notice (e.g., by email or an update to a published subprocessor list) of any new Subprocessor at least 30 days before it begins Processing Customer Personal Data. Customer may object on reasonable data-protection grounds within that period by contacting privacy@truewindsolutions.com; the parties will work in good faith to resolve the objection, and if unresolved, Customer's remedy is to terminate the affected portion of the Service.
7.3 Subprocessor obligations. True Wind will impose data protection obligations on each Subprocessor materially no less protective than this DPA and will remain liable to Customer for a Subprocessor's failure to meet those obligations.
Where Processing of Customer Personal Data involves a transfer from the European Economic Area, the United Kingdom, or Switzerland to a country not deemed to provide an adequate level of protection, the parties will rely on an appropriate transfer mechanism (e.g., the EU Standard Contractual Clauses (2021) and, for UK transfers, the UK International Data Transfer Addendum), which the parties will execute as Annex D if and when applicable.
True Wind will provide reasonable assistance to Customer, at Customer's expense for anything beyond standard Service functionality, to respond to a verified request from a Data Subject to exercise their rights under Applicable Data Protection Law (e.g., access, correction, deletion, portability), to the extent Customer cannot reasonably fulfill the request using the Service's own functionality (e.g., existing edit/delete features, export/report generation). If True Wind receives a Data Subject request directly regarding Customer Personal Data, it will promptly redirect the request to Customer and will not respond to the Data Subject directly except to confirm the request has been forwarded, unless required by law.
True Wind will notify Customer without undue delay, and in any event within 72 hours of confirming a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it about the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed, and will update that information as it becomes available. True Wind will cooperate with Customer and take reasonable steps to mitigate the effects of a breach.
No more than once per 12-month period, and on at least 30 days' written notice, Customer (or its designated auditor, subject to confidentiality) may request evidence of True Wind's compliance with this DPA. True Wind may satisfy this request by providing a summary of its current security practices, a relevant third-party certification or audit report if available (e.g., a SOC 2 report, once obtained), and responses to a reasonable written security questionnaire, in lieu of an on-site audit, except where Applicable Data Protection Law or a supervisory authority requires further access. True Wind does not currently hold a SOC 2 or similar certification; until one is obtained, audit responses will rely on the security questionnaire and documentation described above rather than a third-party report.
Upon termination or expiration of the Agreement, and consistent with Terms of Service §14.4, Customer may request export of Customer Personal Data within 30 days in a standard format. After that period, True Wind will delete or de-identify Customer Personal Data from active production systems within 60 days, except to the extent retention is required by law, and will ensure any retained copies in routine backups are deleted as those backups are cycled out per True Wind's standard backup retention schedule.
This section governs deletion at the end of the Agreement. For the separate, ongoing redaction schedule that applies to individual Membership Pipeline Manager candidacies while the Agreement is still in effect, see Annex A.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, applied in aggregate across the Agreement and this DPA and not separately for each.
This DPA remains in effect for as long as True Wind Processes Customer Personal Data on Customer's behalf under the Agreement, and survives termination of the Agreement to the extent Customer Personal Data remains in True Wind's possession.
This DPA forms part of the Agreement. In the event of a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls.
Subject matter: True Wind's provision of the Navigator platform (Capital Reserve Manager, Cash Flow Manager, and Membership Pipeline Manager) to Customer.
Duration: For the term of the Agreement plus the export/deletion period described in Section 12.
Retention of Membership Pipeline Manager candidacy data during the Agreement term (resolved 2026-09-22): Independent of the overall Agreement duration above, personal data associated with an individual Membership Pipeline Manager candidacy (including candidate and spouse/children information) is redacted from active production systems at the earlier of (a) the retention period the club customer has configured for its own account (in days, up to a five-year maximum), or (b) five years — in each case measured from the date the candidacy reaches a final outcome (the candidate is admitted to membership, the candidacy is withdrawn by the candidate or the club, or the club's process concludes without admission). Redaction removes identifying details (name, contact information, and family/spouse/children information); a non-identifying record of the candidacy's process history (stage progression, dates, and outcome) is retained for the club's own recordkeeping and reporting. A club may place an individual candidacy on a retention hold to exempt it from this schedule.
Nature and purpose of Processing: Hosting, storage, and processing of Customer Personal Data submitted by Customer or its Authorized Users to enable capital reserve planning, cash flow/financing projections, and membership candidate intake and pipeline tracking, including generating reports and analytics for Customer's own use.
Categories of Data Subjects (as applicable to Customer's use of the Service):
Categories of Customer Personal Data (as applicable to Customer's use of the Service):
Special categories of data: Customer should avoid submitting special categories of Personal Data (e.g., health, racial/ethnic origin, religious belief) to the Service unless necessary for a specific, lawful club purpose; True Wind does not request or design the Service to collect such data as a standard field.
| Subprocessor | Purpose | Location (general) |
|---|---|---|
| Microsoft Corporation (Microsoft Azure, including Azure Communication Services) | Application hosting, database (Postgres), authentication (Entra External ID), transactional email delivery, file/blob storage (e.g., candidate photo uploads), diagnostic monitoring and logging (Application Insights, Log Analytics) | United States |
Netlify hosts True Wind's marketing website and a sales-demo prototype only — it does not process Customer Data — so it is not listed as a Customer Data subprocessor here (see the Privacy Policy for general service providers). True Wind does not currently use a third-party payment processor; billing is handled directly. This Annex will be updated before either changes.
Not currently in use. To be completed (e.g., with the EU Standard Contractual Clauses (2021 Module 2 or 4) and UK IDTA) if and when True Wind processes Customer Personal Data involving a restricted international transfer.