This Data Processing Agreement ("DPA") forms part of, and is governed by, the CoopTools Terms of Service (the "Agreement") between CoopTools LLC ("CoopTools" or "Processor") and the cooperative customer ("Cooperative" or "Controller"). This DPA applies to CoopTools's processing of Personal Data on behalf of the Cooperative in connection with the Service. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that CoopTools processes on behalf of the Cooperative through the Service, including the personal information of the Cooperative's members, employees, contractors, and joint-use contacts.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
"Controller" means the Cooperative, which determines the purposes and means of processing Personal Data.
"Processor" means CoopTools, which processes Personal Data on behalf of the Controller.
"Sub-processor" means a third party engaged by CoopTools to process Personal Data in connection with the Service.
"Data Subject" means the individual to whom Personal Data relates.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by CoopTools.
2. Roles and Scope
The Cooperative is the Controller of Personal Data it submits to the Service, and CoopTools is the Processor. CoopTools processes Personal Data only on behalf of the Cooperative and in accordance with this DPA. The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.
3. Processing Instructions
CoopTools shall process Personal Data only: (a) to provide, maintain, secure, and support the Service in accordance with the Agreement; (b) as further instructed by the Cooperative in writing, where such instructions are consistent with the Agreement; and (c) as required by applicable law, in which case CoopTools will inform the Cooperative of the legal requirement before processing unless prohibited by law. CoopTools shall promptly notify the Cooperative if, in its opinion, an instruction violates applicable data protection law.
4. Confidentiality
CoopTools shall ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and process Personal Data only as necessary to provide the Service.
5. Security Measures
CoopTools shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against a Security Incident. These measures include, at a minimum:
- Database-enforced tenant isolation (Row Level Security) so that one cooperative's data cannot be accessed by another.
- Encryption of Personal Data in transit (TLS) and at rest.
- Client-side encryption of offsite backups before they leave CoopTools's infrastructure.
- Private file storage accessible only through short-lived, authorized access links.
- Role-based access controls and authenticated access; no public self-registration for cooperative or attacher accounts.
- Access logging for document retrieval and an immutable audit log for privileged administrative actions.
- Rate limiting and abuse protections on public and sensitive endpoints.
A more detailed description of these measures is provided in the CoopTools Security Overview, which is incorporated by reference. CoopTools may update its security measures provided that the updates do not materially reduce the overall level of protection.
6. Sub-processors
The Cooperative provides general authorization for CoopTools to engage the Sub-processors listed in Annex B to process Personal Data in connection with the Service. CoopTools shall: (a) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA; and (b) remain responsible for each Sub-processor's performance of its obligations.
CoopTools shall provide notice of any intended addition or replacement of a Sub-processor, giving the Cooperative an opportunity to object on reasonable data-protection grounds. If the Cooperative reasonably objects and the parties cannot resolve the objection, the Cooperative may terminate the affected portion of the Service as its remedy.
7. Data Subject Requests
Taking into account the nature of the processing, CoopTools shall provide reasonable assistance to the Cooperative, through appropriate technical and organizational measures and insofar as possible, to respond to requests from Data Subjects to exercise their rights under applicable law. Where a Data Subject submits a request directly to CoopTools, CoopTools shall, unless legally prohibited, direct the Data Subject to the Cooperative and notify the Cooperative. The Service includes self-service capabilities (including export and an erase-personal-information function for signed documents) that enable the Cooperative to respond to many such requests directly.
8. Security Incident Notification
CoopTools shall notify the Cooperative without undue delay after becoming aware of a Security Incident affecting the Cooperative's Personal Data. The notification shall describe, to the extent known, the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed to address it. CoopTools shall take reasonable steps to mitigate and remediate the incident and shall cooperate with the Cooperative's reasonable requests in connection with the Cooperative's own notification obligations.
9. Return and Deletion of Personal Data
Upon termination or expiration of the Agreement, CoopTools shall, at the Cooperative's election, make Personal Data available for export for a period of thirty (30) days. The Cooperative's Personal Data is then scheduled for deletion and permanently removed from CoopTools's active systems after a grace period (currently ninety (90) days) through a controlled deletion process that removes records and associated stored files across the platform, except to the extent retention is required by applicable law or is contained in routine backups that are deleted in the ordinary course according to defined retention cycles. Account deletion is an explicit, administrator-initiated action and does not occur automatically based on billing status.
In addition, CoopTools applies the following automated retention controls during the term: signed documents and associated Personal Data are purged after a configurable default of eighty-four (84) months; document-access and administrative audit logs are purged after twenty-four (24) months; and soft-deleted items are purged after thirty (30) days. Operational records are retained for the life of the account, consistent with federal disaster-assistance record-retention expectations, and are removed through account deletion.
10. Audits and Compliance
CoopTools shall make available to the Cooperative information reasonably necessary to demonstrate compliance with this DPA, including its Security Overview and a current sub-processor list. Where a Cooperative reasonably requires additional assurance, CoopTools shall cooperate with reasonable, scoped requests for information, subject to confidentiality and to not unreasonably disrupting CoopTools's operations or compromising the security of other customers.
11. International Transfers
CoopTools processes and stores Personal Data using infrastructure located in the United States. The Cooperative shall not submit Personal Data subject to data-transfer restrictions that CoopTools is not equipped to handle without first agreeing on appropriate safeguards with CoopTools.
12. Liability and Term
Each party's liability under this DPA is subject to the limitations and exclusions of liability set forth in the Agreement. This DPA takes effect on the effective date of the Agreement and remains in effect for as long as CoopTools processes Personal Data on behalf of the Cooperative.
Annex A — Description of Processing
| Subject matter | Provision of field-operations software to the Cooperative. |
|---|---|
| Duration | For the term of the Agreement and the post-termination export period. |
| Nature and purpose | Storage, organization, retrieval, transmission, and deletion of cooperative data to operate the Service. |
| Types of Personal Data | Names, email addresses, phone numbers, signature data on e-signed documents, and contact details of cooperative members, employees, contractors, and joint-use attacher contacts; grantor and grantee names on recorded land and easement instruments; document-access metadata (including IP address); location metadata in photos. |
| Categories of Data Subjects | Cooperative members; cooperative employees and contractors; joint-use (attacher) company contacts; parties to recorded land instruments; authorized platform users. |
Annex B — Authorized Sub-processors
| Sub-processor | Function |
|---|---|
| Supabase | Database, authentication, file storage, server functions (primary processor). |
| Vercel | Web application hosting and content delivery. |
| Backblaze B2 | Encrypted offsite backup storage. |
| GitHub | Source control and backup automation. |
| Railway | Hosting for the optional read-only GIS map feed into a Cooperative's own ArcGIS. |
| Resend | Transactional email delivery. |
| Cloudflare | CAPTCHA protection on public forms. |
| Esri / ArcGIS | Map basemaps and geocoding. |
| Google Maps Platform | Street View and map embeds. |
| OpenStreetMap | Key-free basemap fallback (mobile). |
| Anthropic | AI help assistant (processes help-question text). |
This list is current as of the version date. CoopTools will update it when sub-processors change, per Section 6.
Acceptance
This DPA is incorporated into and accepted as part of the CoopTools Terms of Service. Questions may be directed to seth@cooptools.io.