Legal
Data Processing Agreement
Last updated: June 17, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between your organization (the “Organization,” the data controller) and Cladeworks LLC, operating Fosterling (the data processor), and governs our processing of personal data on your behalf. It supplements our Terms & Conditions and Privacy Notice. Where this DPA conflicts with the Terms on data protection, this DPA controls.
1. Roles
The Organization is the controller of the personal data it submits to Fosterling — including its team members’, volunteers’, fosters’, and adopters’ details. Fosterling is the processor and acts only on the Organization’s documented instructions, which include use of the platform as configured by the Organization.
2. Scope and purpose of processing
Fosterling processes personal data solely to provide and support the service: animal records, intake and fostering, adoptions, volunteer and donor management, communications, and AI-assisted features the Organization enables. We do not process the data for our own purposes, and we do not sell it.
3. Categories of data and data subjects
- Data subjects: Organization staff and volunteers, fosters, adopters, donors, and members of the public who submit forms (e.g. lost-and-found or surrender requests).
- Personal data: names, contact details, account credentials, and the contents of records the Organization creates.
4. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and access data only as needed to deliver and support the service.
5. Security
Fosterling maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls and per-organization isolation, role-based permissions, and audit logging of sensitive actions.
6. Sub-processors
The Organization authorizes Fosterling to engage sub-processors to deliver the service, under data-protection terms no less protective than this DPA. Our principal sub-processors are Supabase (authentication, database, and storage), our hosting and content-delivery provider, Stripe (payments), and Google (via the Lovable AI Gateway) for AI-assisted features. We will give notice of material changes to this list and a chance to object.
7. International transfers
Where personal data is transferred across borders, we rely on an appropriate transfer mechanism (such as Standard Contractual Clauses) with the relevant sub-processor.
8. Assistance to the Organization
Taking into account the nature of processing, Fosterling assists the Organization in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations.
9. Personal data breaches
Fosterling will notify the Organization without undue delay after becoming aware of a personal data breach affecting its data, with the information reasonably available to help the Organization meet its own notification duties.
10. Return and deletion
On termination, and at the Organization’s choice, Fosterling will return or delete the Organization’s personal data, except where retention is required by law.
11. Audits
Fosterling will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with audits on reasonable notice, subject to confidentiality.
Contact
To request a signed copy of this DPA or to raise a data-protection question, email privacy@fosterling.io.