This Data Processing Agreement (“DPA”) is incorporated into the Terms of Service between CMJ Consulting LLC(“CMJ Consulting”) and The Food Group (“Customer”) covering The Food Group Verify (the “Service”). It governs how CMJ Consulting handles Customer Data, and it controls over the Terms of Service on any data-protection matter.
There is no separate signed agreement for the Service. This DPA takes effect when Customer begins using the Service and binds CMJ Consulting from that point, whether or not the parties later sign anything. Customer may request a signature copy at any time.
1. Definitions
- 1.1 “Customer Data” means all data, content, and records Customer or its Authorized Users submit to, or that the Service generates on Customer’s behalf within, the Service — including participant contact information, survey responses, verification evidence, email delivery events, and gift card issuance records.
- 1.2 “Participant Data” means Customer Data about an individual who responded to a Customer survey or was sent a verification request.
- 1.3 “Personal Data” means Customer Data that identifies or can reasonably be linked to an individual.
- 1.4 “Subprocessor” means a third party CMJ Consulting uses to process Customer Data in providing the Service.
- 1.5 “Data Incident” means a confirmed unauthorized access to, or acquisition, loss, or disclosure of, Customer Data in CMJ Consulting’s control.
2. Roles and ownership
- 2.1 Ownership. As between the parties, Customer owns and controls all Customer Data at all times. CMJ Consulting obtains no ownership rights in Customer Data.
- 2.2 Roles. Customer is the controller of Customer Data. CMJ Consulting acts solely as Customer’s service provider and data processor, handling Customer Data only on Customer’s documented instructions and as needed to provide the Service.
- 2.3 Instructions. CMJ Consulting will notify Customer if it believes an instruction violates applicable law, and may pause the affected processing until the parties resolve the question.
3. Scope and sensitivity of the data
- 3.1 Expected data. The Service is designed to deduplicate survey responses, verify that a respondent is a real and distinct person, and record gift card issuance. Customer Data is expected to consist of participant names, email addresses, phone numbers, mailing addresses, household size, the original survey responses, verification session evidence, and gift card records.
- 3.2 Sensitivity. The parties acknowledge that Participant Data identifies people who sought food assistance, and that disclosure could cause them real harm. CMJ Consulting will treat Participant Data as confidential regardless of whether it is classified as sensitive under a particular statute.
- 3.3 Excluded data. The Service is not intended to collect or store Social Security numbers, government identification numbers, financial account or payment card numbers, immigration status, or health records. Customer will not submit such data except as the parties agree in writing.
- 3.4 Payment data. Gift cards are purchased and delivered outside the Service. CMJ Consulting does not process payment card or bank account information.
4. Use of Customer Data
- 4.1 Permitted use. CMJ Consulting will process Customer Data only to provide, maintain, secure, and support the Service, and as otherwise instructed by Customer in writing.
- 4.2 No sale; no secondary use. CMJ Consulting will not sell, rent, or share Customer Data, and will not use it for advertising, for building or training advertising or marketing profiles, or for any purpose other than providing the Service. CMJ Consulting will not use Customer Data to train AI models.
- 4.3 Aggregated / de-identified data. CMJ Consulting may use aggregated or de-identified data that cannot reasonably be linked to Customer or any individual to operate and improve the Service, and will not attempt to re-identify it.
- 4.4 Personnel. CMJ Consulting limits access to Customer Data to personnel who need it to provide the Service, and binds them to confidentiality obligations.
5. Subprocessors
5.1 Authorized subprocessors. Customer authorizes CMJ Consulting to use the following subprocessors to host and process Customer Data:
- Google LLC — Google Cloud Platform and Firebase (hosting, database, file storage, and authentication). Data stored in the United States.
- Google LLC — reCAPTCHA Enterprise. Assesses whether a verification page visit is automated; receives the visitor’s IP address and browser signals. United States.
- Microsoft Corporation — Microsoft Entra ID. Authenticates Customer staff sign-in; receives staff identity only, never Participant Data. United States.
- ActiveCampaign, LLC — Postmark. Delivers verification email and reports delivery events; receives participant name and email address and the message content. United States.
A current list, including what each subprocessor receives, is maintained at /legal/subprocessors.
- 5.2 Flow-down. CMJ Consulting remains responsible for its Subprocessors and will impose data-protection obligations on them that are no less protective than those in this DPA.
- 5.3 Changes. CMJ Consulting will give Customer at least 30 days’ notice before adding or replacing a Subprocessor that processes Customer Data. If Customer reasonably objects on data-protection grounds, the parties will work in good faith to resolve the concern; if they cannot, Customer may terminate the affected Service and receive a pro-rated refund.
6. Security
- 6.1 Safeguards. CMJ Consulting will maintain administrative, technical, and physical safeguards designed to protect Customer Data appropriate to its sensitivity, including: encryption of Customer Data in transit and at rest; role-based access control with server-side enforcement, so that no Customer Data is readable directly by a browser; single-use, time-limited verification links stored only as a hash; audit records of verification decisions; regular backups; and periodic review of its security practices. CMJ Consulting relies on the underlying certifications of its cloud host (Google Cloud / Firebase), which maintains industry-standard certifications such as SOC 2 and ISO 27001.
- 6.2 Customer controls. Customer is responsible for managing its Authorized Users’ access and roles, for removing access promptly when a staff member leaves, and for handling exported files — which leave the Service’s protections behind — with care.
7. Data incidents
- 7.1 Notice. CMJ Consulting will notify Customer without undue delay, and in any event within 72 hours of confirming a Data Incident affecting Customer Data. Notice will describe what is known about the incident, the data involved, and the steps CMJ Consulting is taking.
- 7.2 Response. CMJ Consulting will take reasonable steps to investigate, contain, and remediate the incident, and will reasonably cooperate with Customer’s own breach-response and notification obligations, including under Minn. Stat. § 325E.61 and applicable federal law. As controller, Customer is responsible for determining whether and how to notify affected individuals or regulators.
8. Individual requests and legal demands
- 8.1 Individual requests. Because Customer controls Customer Data, requests from participants to access, correct, or delete their information are directed to and handled by Customer. CMJ Consulting will provide Customer reasonable, timely tools or assistance to locate, export, correct, and delete Customer Data so Customer can meet its response deadlines, and will forward to Customer any such request it receives directly.
- 8.2 Third-party and legal demands. If CMJ Consulting receives a subpoena, court order, or government demand for Customer Data, it will, unless legally prohibited, promptly notify Customer so Customer can seek a protective order or otherwise respond, and will not disclose Customer Data except as legally required.
9. Return and deletion
- 9.1 Export. During the Term and for at least 30 days after termination, Customer may export its Customer Data in a usable format. CMJ Consulting will provide reasonable assistance with export.
- 9.2 Deletion. Within 60 days after termination, and after the export window, CMJ Consulting will delete or de-identify Customer Data in its production systems, and will delete it from routine backups within the normal backup rotation cycle, unless retention is required by law. On Customer’s written request, CMJ Consulting will confirm deletion.
- 9.3 Deletion during the Term. CMJ Consulting will delete individual records on Customer’s instruction. The Service does not delete participant records automatically, and a risk score never causes a deletion.
10. Data location
10.1 Customer Data is stored and processed in the United States. CMJ Consulting will not transfer Customer Data outside the United States without Customer’s prior written consent.
11. Audit and records
11.1 On reasonable written request — no more than once per year unless required after a Data Incident or by law — CMJ Consulting will provide Customer with a summary of its data-security practices and available Subprocessor compliance reports, so Customer can verify CMJ Consulting’s compliance with this DPA without unduly disrupting operations or compromising other customers’ data.
12. Term and general
12.1 This DPA takes effect when Customer begins using the Service and remains in effect while CMJ Consulting holds Customer Data. It survives termination of the Terms of Service until Customer Data is returned or deleted. This DPA is incorporated into and governed by the Terms of Service, including their governing-law and liability provisions — except that CMJ Consulting’s obligations of confidentiality and data security under this DPA are excluded from the liability cap in Terms §12.
Acceptance
This DPA is accepted through Customer’s use of the Service under the Terms of Service; no signature is required for it to bind CMJ Consulting. Customer may request a standalone signature copy at any time. Questions: cmjconsultingmn@gmail.com. See also our Privacy Policy and Subprocessors list.