fellos
Why fellos
Who it's forSee itPricing
DocsSign inStart free
  • Terms of Service
  • Privacy Notice
  • Data Processing Addendum
  • Subprocessors

Sections

  1. 1. Definitions
  2. 2. Scope and roles
  3. 3. Processing only on your instructions
  4. 4. Details of the processing
  5. 5. Confidentiality of our staff
  6. 6. Security
  7. 7. Subprocessors
  8. 8. Helping you respond to data subjects
  9. 9. Personal data breaches
  10. 10. Data protection impact assessments
  11. 11. Returning and deleting data
  12. 12. Information and audits
  13. 13. International transfers
  14. 14. Order of precedence
  15. 15. Liability
  16. 16. Term and changes
  17. 17. Governing law
  18. 18. Contact
  19. Annex I: Parties and description of the processing
  20. Annex II: Security measures
  21. Annex III: Subprocessors

fellos Data Processing Addendum

Last updated: September 29, 2026 Effective: September 29, 2026

This Data Processing Addendum ("DPA") is part of the fellos Terms of Service (the "Terms") between maClara, LLC, a Virginia limited liability company ("fellos", "we", "us"), and the organization that uses fellos ("you"). It sets the terms on which we process your members' personal data for you.

You accept this DPA when you accept the Terms. No separate signature is needed. It applies from the moment you create your fellos site, or from its effective date if you were already using fellos.

Sections
  1. 1. Definitions
  2. 2. Scope and roles
  3. 3. Processing only on your instructions
  4. 4. Details of the processing
  5. 5. Confidentiality of our staff
  6. 6. Security
  7. 7. Subprocessors
  8. 8. Helping you respond to data subjects
  9. 9. Personal data breaches
  10. 10. Data protection impact assessments
  11. 11. Returning and deleting data
  12. 12. Information and audits
  13. 13. International transfers
  14. 14. Order of precedence
  15. 15. Liability
  16. 16. Term and changes
  17. 17. Governing law
  18. 18. Contact
  19. Annex I: Parties and description of the processing
  20. Annex II: Security measures
  21. Annex III: Subprocessors

1. Definitions

Words defined in the Terms have the same meaning here. In addition:

  • "Data protection law" means every law on privacy and personal data that applies to the processing under this DPA. That includes the EU General Data Protection Regulation ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws.
  • "Customer personal data" means the personal data that we process for you on your fellos site, as Section 2 describes.
  • "Controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings the GDPR gives them. Where another data protection law uses different words for the same ideas (for example "business" and "service provider"), these words include them.
  • "Subprocessor" means a service provider we engage that processes customer personal data.
  • "SCCs" means the Standard Contractual Clauses for transfers of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

2. Scope and roles

What this DPA covers. Your fellos site holds your members' data. That includes member profiles and history, posts, messages, documents, events, elections, dues and store orders, and the other data listed in Annex I. We process it to provide fellos to you. For that data:

  • you are the controller. You decide whom to invite, what to collect, what to keep and why; and
  • we are your processor. We process it on your behalf and on your instructions (Section 3).

If you are yourself a processor for another controller (for example, if you run a site on behalf of a parent body that decides how its members' data is used), we are your subprocessor. You confirm that the controller has authorized your instructions to us and our use of subprocessors under this DPA.

What this DPA does not cover. We are the controller of the data our Privacy Notice describes as ours: signing up for fellos, your organization's fellos account and subscription, our emails to your site admins, support tickets and the "fellos AI" support chat, and our own websites, fellos.app and signup.fellos.app. The Privacy Notice governs that data, not this DPA.

Account statistics. We may work out counts and usage statistics from your site, for example the number of active members, which sets your plan's member limit. We use them only to bill, run and secure your account, to send your site admins the emails the Privacy Notice describes, and, where the founder allowed analytics, to send the setup figures the Privacy Notice describes.

Your responsibilities. You are responsible for:

  • having a valid legal reason (in the EU and UK, a "lawful basis") for the member data you collect and ask us to process;
  • telling your members how you use their data. Your site's Privacy page is the place for that;
  • getting any consent the law requires, including parental consent for minors you add to your site;
  • making sure your instructions to us comply with data protection law; and
  • the settings you choose, including whom you make a site admin.

3. Processing only on your instructions

We process customer personal data only on your documented instructions. Your instructions are:

  • the Terms and this DPA;
  • the settings your site admins choose, and the features your site admins and members use; and
  • any other written instruction you give us that we agree to.

We will not process customer personal data for any other purpose, unless the law requires us to. In that case we will tell you before we process it, unless the law forbids us to tell you.

If we believe an instruction breaks data protection law, we will tell you. We may then decline to follow it until you confirm or change it.

US state privacy laws. Where a US state privacy law applies to your processing, we act as your service provider or processor under it. We will not sell or share customer personal data, and we will not retain, use or disclose it outside our direct business relationship with you, except as that law allows. We will tell you if we can no longer meet our obligations under that law.

4. Details of the processing

Annex I sets out the details of the processing:

  • subject matter: providing the fellos hosted service to you;
  • duration: for as long as the Terms last, and after that until we delete the data as Section 11 describes;
  • nature and purpose: hosting, storing, displaying, sending, indexing and backing up your site's data so that your organization and its members can use fellos, and supporting and securing the service;
  • categories of data subjects: your members, secondary members, invitees, event attendees, store buyers, and others listed in Annex I; and
  • categories of personal data: listed in Annex I.

Special categories of data. fellos does not ask you to record any special category of personal data, such as health, religious belief or trade union membership. You may choose to record some, for example in a profile field your admins define. In some organizations, membership itself may reveal one, such as a religious or philosophical belief. Where you record or reveal special category data, you are responsible for having a legal reason to. The measures in Annex II apply to all customer personal data alike.

5. Confidentiality of our staff

Only staff who need access to customer personal data to do their jobs have it. Everyone we authorize to process customer personal data is bound by a duty of confidentiality.

Our staff can see your organization's member list, billing and support tickets in our admin tools, and a small number of engineers have database access. We look at your data only to give support you ask for, fix problems, keep the service secure, or meet a legal obligation.

Election ballots. fellos stores each ballot with the voter's identity, to stop anyone voting twice and to show members their own ballot. Staff with database access could technically see individual ballots. We never look at them, except where the law requires us to.

6. Security

We protect customer personal data with the technical and organizational measures in Annex II. We may change those measures over time, but we will not reduce the overall protection they give.

Some measures are yours to use, for example requiring your admins, or all members, to set up a passkey, and choosing who has admin power on your site. Annex II lists them.

7. Subprocessors

General authorization. You authorize us to use subprocessors. The current list is at fellos.app/subprocessors (Annex III). It shows what each subprocessor does and where it processes data.

Our commitments. For each subprocessor, we:

  • put in place a written contract with data protection obligations that protect customer personal data at least as well as this DPA does; and
  • remain responsible to you for its processing of customer personal data, as if it were our own.

Notice of changes. At least 30 days before we add or replace a subprocessor, we will email your site admins and update fellos.app/subprocessors. Anyone can ask to receive those updates by email by writing to privacy@fellos.app.

Your right to object. If you object to a new or replacement subprocessor, write to privacy@fellos.app before the change takes effect. We will try to address your concern. Whether or not we can, you may cancel your subscription with immediate effect, and we will refund any fees you prepaid for the rest of the period.

8. Helping you respond to data subjects

Requests we receive. If a member or anyone else asks us to exercise a data protection right over customer personal data, we will pass the request to your site admins, or ask the person to contact your organization. We will not answer the request ourselves, unless you tell us to or the law requires us to.

Our help. Your site gives your site admins tools to meet most requests: they can see and correct member records, download the member roster (CSV, Excel or PDF), and deactivate members. Where those tools are not enough, we will give you reasonable help, taking into account the nature of the processing. For example:

  • a copy of your site's other records: a site admin can write to support@fellos.app, and we will provide CSV files, with uploaded files as a zip, within 30 days, at no charge; and
  • removing one member's data: deactivating a member does not delete their data. A site admin can write to privacy@fellos.app to have a specific member's data removed.

9. Personal data breaches

If we become aware of a personal data breach affecting customer personal data, we will tell your site admins by email without undue delay, and within 72 hours of becoming aware of it.

Our notice will describe, as far as we know at the time:

  • what happened, and when;
  • the categories and approximate number of people and records affected;
  • the likely consequences;
  • what we have done, and are doing, to deal with the breach and reduce its effects; and
  • whom to contact for more information.

Where we cannot give all of this at once, we will give it in stages, without further undue delay. We will take reasonable steps to contain the breach and to help you meet your own obligations to notify supervisory authorities and the people affected. You decide whether to notify them about your members' data. Where the law requires us to notify a regulator ourselves, we will.

Telling you about a breach is not an admission of fault or liability.

10. Data protection impact assessments

Where data protection law requires you to carry out a data protection impact assessment, or to consult a supervisory authority before processing, we will give you reasonable help. We will do so by giving you information about fellos that you do not otherwise have: this DPA, the Privacy Notice, the measures in Annex II and the subprocessor list, and answers to your reasonable questions about them.

11. Returning and deleting data

This table repeats, word for word, the table in Section 13 of the Terms and Section 9 of the Privacy Notice.

Situation What happens to the data
Getting a copy of your data A site admin can download the member roster (CSV, Excel or PDF) at any time. For the rest of the site's records, a site admin can write to support@fellos.app, and we will provide CSV files, with uploaded files as a zip, within 30 days, at no charge.
A paused site When a paid plan ends, the site is paused at the end of the paid period. Nothing is deleted while it is paused, apart from routine clean-up, such as the expiry of old notifications, feed items, session records and email logs. Site admins can still sign in to reach Billing, the member-roster download and member deactivation; Comptrollers can reach Billing. We keep a paused site's data for 12 months, and email its site admins 30 days and 7 days before we delete it. Until then, they can export the data, resubscribe, or move to the Free plan if the site fits it. After 12 months, we delete the site and its data as for a closed site.
Closing a site On a confirmed request from a site admin, we delete the site's database records and uploaded files within 30 days. Copies in backups expire on the backup schedule, within 35 days. We keep billing records for as long as tax law requires.
After termination by us We keep the site's data for 12 months, as for a paused site, with the same warnings, and the data export stays available to its site admins. Unlike a paused site, it cannot be reopened by resubscribing or moving to the Free plan. After 12 months, we delete the site and its data as for a closed site. A site that was already paused keeps its original deletion date.
Backups Up to 35 days. Data deleted from the service stays in backups until they expire.
Removing one member's data Deactivating a member does not delete their data: the site keeps the member's profile and history. To have a specific member's data removed, a site admin can write to privacy@fellos.app. If a member asks us directly, we will pass the request to the site's admins.

If the law requires us to keep any customer personal data after these periods, we will keep it confidential and use it only for the purpose the law requires.

Billing records are our own records as the controller (Section 2). They are not customer personal data.

12. Information and audits

We will make available to you the information you reasonably need to show that we meet our obligations under this DPA and Article 28 of the GDPR. We do this in two ways:

  • Documents. This DPA, the Privacy Notice, the measures in Annex II and the subprocessor list describe how we process customer personal data. fellos holds no security certification, such as SOC 2 or ISO 27001.
  • A written questionnaire, once a year. Once in any 12-month period, you may send us a reasonable written security or data-protection questionnaire at privacy@fellos.app. We will answer it within a reasonable time. You will keep our answers confidential.

We do not offer on-site audits or inspections.

Nothing in this section limits a right that a supervisory authority has, or an audit right under the SCCs or data protection law that cannot be limited by agreement. If you use such a right, the audit must take place during business hours, on reasonable notice, and under a duty of confidentiality, and you will pay its costs.

13. International transfers

Where the data is. We are based in the United States. We store all customer personal data in the United States, with Amazon Web Services in US East (Northern Virginia). The subprocessor list shows where each subprocessor processes data. We are not certified under the EU-US Data Privacy Framework.

Transfers from the European Economic Area. Where the GDPR applies to your processing of customer personal data and that data is transferred to us in the United States, the SCCs are incorporated into this DPA by reference. You are the "data exporter" and we are the "data importer". They apply as follows:

  • Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you are a processor for another controller.
  • Clause 7 (the docking clause) is included.
  • Clause 9(a): Option 2, general written authorization, applies. We will give at least 30 days' notice of an intended change to our subprocessors, as Section 7 describes.
  • Clause 11(a): the optional language on an independent dispute resolution body does not apply.
  • Clause 13(a): the competent supervisory authority is the one Clause 13(a) points to. That depends on where you are established in the EU, where your EU representative is established if you have appointed one, or, if neither applies, where your members are. Annex I, Part C repeats this.
  • Clause 17: Option 1 applies. The SCCs are governed by the law of Ireland.
  • Clause 18(b): disputes are resolved by the courts of Ireland.
  • Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this DPA.

Transfers from the United Kingdom. For transfers of customer personal data subject to UK data protection law, the UK Addendum is incorporated into this DPA by reference, and applies to the SCCs as incorporated above.

  • Table 1: the parties and their details are as set out in Annex I.
  • Table 2: the Addendum EU SCCs are the SCCs as incorporated in this section, with the modules and options chosen above.
  • Table 3: the Appendix Information is set out in Annexes I, II and III of this DPA.
  • Table 4: neither party may end the UK Addendum under its Section 19.

As the UK Addendum's mandatory clauses provide, it is governed by the laws of England and Wales, and disputes under it are resolved by the courts of England and Wales.

Transfers from Switzerland. For transfers of customer personal data subject to the FADP, the SCCs apply as incorporated above, with these changes:

  • the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for those transfers;
  • references to the GDPR include the FADP;
  • "Member State" in Clause 18(c) does not prevent data subjects in Switzerland from bringing a claim where they habitually reside; and
  • Clauses 17 and 18 otherwise apply as chosen above.

Transfer assessments. We will give you the information about our processing and our subprocessors that you reasonably need to assess a transfer under the SCCs.

New versions. If the European Commission, the UK Information Commissioner or the Swiss authorities replace or update these mechanisms, we may adopt the replacement by updating this DPA, as Section 16 describes.

14. Order of precedence

If documents conflict:

  1. the SCCs and the UK Addendum, where they apply, prevail over this DPA and the Terms;
  2. this DPA prevails over the Terms on the processing of personal data; and
  3. otherwise the Terms apply.

15. Liability

Each party's liability arising out of or relating to this DPA, and the SCCs and the UK Addendum where they apply, is subject to the limitation of liability in the Terms. The limit in the Terms is the total for all claims under the Terms, this DPA, the SCCs and the UK Addendum together. There is no separate or higher limit for claims about personal data.

This section does not limit any liability to data subjects under Clause 12 of the SCCs, or any liability that data protection law does not allow to be limited.

16. Term and changes

This DPA lasts as long as the Terms, and after that for as long as we process customer personal data.

We may update this DPA as the Terms' section on changes describes: for a material change, we will email your site admins at least 30 days before it takes effect. We will not use an update to reduce the protection this DPA gives customer personal data, unless data protection law or a supervisory authority requires the change.

17. Governing law

This DPA is governed by the law that governs the Terms, and disputes under it are resolved as the Terms provide. The SCCs and the UK Addendum are governed by the law, and subject to the courts, set out in Section 13.

18. Contact

maClara, LLC (fellos), a Virginia limited liability company

For Write to
Questions about this DPA, objections to a subprocessor, the annual questionnaire, and subprocessor updates privacy@fellos.app
Reporting a security problem security@fellos.app
Data exports and closing a site support@fellos.app
Legal notices legal@fellos.app

We send notices under this DPA to your site admins' email addresses.


Annex I: Parties and description of the processing

A. The parties

Data exporter

  • Name: the organization that accepts the Terms, as named in its fellos account.
  • Contact: the site admins on that account, at their own email addresses.
  • Activities relevant to the transfer: using fellos to run its organization's site for its members.
  • Role: controller. Where it acts for another controller, processor.
  • Signature and date: accepting the Terms, on the date it accepts them.

Data importer

  • Name: maClara, LLC (fellos), a Virginia limited liability company, United States.
  • Contact: privacy@fellos.app. Legal notices: legal@fellos.app.
  • Activities relevant to the transfer: providing the fellos hosted service to the data exporter.
  • Role: processor. Where the data exporter is a processor, subprocessor.
  • Signature and date: publishing the Terms and this DPA, and accepting the data exporter's acceptance, on the date of that acceptance.

B. Description of the processing and transfer

Categories of data subjects

  • The organization's members, current and former, including its officers and site admins.
  • Secondary members, such as spouses.
  • People invited to join, whether or not they accept.
  • Event attendees and ticket holders.
  • Store buyers.
  • Visitors to the organization's site who make a choice on its cookie banner.
  • Other people whom the organization or its members mention in posts, messages, documents and records.

Categories of personal data

What the site holds depends on what the organization collects and which features it uses. It may include:

  • member profiles and history: names, email addresses, phone numbers, home addresses, photos, membership type and dates, officer positions, and any profile fields the organization defines;
  • secondary members and their link to a primary member;
  • workflow requests, such as membership, transfer and deactivation requests, with their approvals and attachments;
  • election records, including nominations and ballots (each ballot is stored with the voter's identity);
  • posts, comments, reactions and documents, with their revisions and uploaded files;
  • direct messages between members;
  • event RSVPs, tickets and check-ins;
  • dues and store orders, including items bought, payment status and, for store orders, the member's name and, where the profile has them, phone number and home address as billing and shipping address. Card details go to the organization's Stripe account and never reach fellos;
  • invitations: email addresses the organization enters to invite co-admins and members;
  • sign-in methods: passwords (stored only as bcrypt hashes), passkeys, and links to Google, GitHub or Apple sign-in where the organization enables them;
  • session records: the browser's user agent, the IP address, and an approximate location (country, region and city) looked up on our own servers;
  • an audit log of admin actions: who acted, what changed, and the IP address;
  • consent records from the site's cookie banner: the choice, the region, whether a Global Privacy Control signal was sent, the browser's user agent, a hashed form of the IP address, and the member's user id or a random anonymous id; and
  • notification settings and push subscriptions, and data for wallet passes that members add.

Special categories of data

None are required. The organization may choose to record some (Section 4). The measures in Annex II apply to all customer personal data alike.

Frequency of the transfer

Continuous, for as long as the organization uses fellos.

Nature of the processing

Hosting, storage, retrieval, display, sending by email and push notification, search indexing, processing by AI features, backup, export and deletion.

The AI features send content to our AI provider, a subprocessor:

  • automatically: group posts and comments, each with its author's name and member type, the group's name and the thread's title, for search; recent group posts, without author names, for the members' weekly digest summary; and new replies to threads that already have a summary, with the thread's posts and their authors' names and member types; and
  • when someone uses the feature: group search (the search text), Ask AI (the question, your organization's name and type, and the posts and whole threads it searches and reads, with each author's name and member type), Summarize (the thread's posts, with their authors' names and member types), and the page-writing and page-style helpers.

Purpose of the processing

To provide fellos to the organization under the Terms, so that it and its members can use its site; to secure the service; and to give the support the organization asks for.

Retention

As Section 11 of this DPA describes.

Transfers to subprocessors

As listed at fellos.app/subprocessors (Annex III), for the subject matter, nature and duration described there and in this Annex.

C. Competent supervisory authority

As Clause 13(a) of the SCCs provides:

  • where the data exporter is established in an EU Member State, the supervisory authority of that Member State;
  • where it is not, but has appointed a representative under Article 27(1) of the GDPR, the supervisory authority of the Member State where the representative is established; and
  • where it has not appointed one, the supervisory authority of the Member State where the data subjects whose data is transferred are located.

For transfers under the UK Addendum, the UK Information Commissioner. For transfers subject to the FADP, the Swiss Federal Data Protection and Information Commissioner.


Annex II: Security measures

These are the technical and organizational measures we use to protect customer personal data.

Hosting

  • The service, its database and its file storage are hosted by Amazon Web Services in US East (Northern Virginia). fellos runs no data centers of its own.

Encryption in transit

  • Every fellos site is served over HTTPS only.

Sign-in and passwords

  • We store passwords only as bcrypt hashes, so they can't be read back.
  • Organizations can require their admins, or all members, to set up a passkey.
  • Each sign-in creates a session record, with the browser's user agent, the IP address and an approximate location, which is looked up on our own servers rather than through a third-party service.
  • We limit the rate of some requests, to slow down abuse.

Credentials and payment details

  • The passwords and keys fellos uses to connect to other services are stored encrypted.
  • Card details are entered on Stripe's page and never reach fellos.

Access by our staff

  • Only staff who need access have it. Our staff can see an organization's member list, billing and support tickets in our admin tools, and a small number of engineers have database access.
  • We look at an organization's data only to give support it asks for, fix problems, keep the service secure, or meet a legal obligation.
  • Everyone we authorize to process customer personal data is bound by a duty of confidentiality.
  • Staff never look at individual election ballots, except where the law requires us to.

Access within each site

  • The product shows a member's election choices only to that member. Everyone else, election conductors and site admins included, sees only totals.
  • An audit log records admin actions on each site: who acted, what changed, and the IP address.

Subprocessors

  • Each subprocessor is bound by a written contract with data protection obligations (DPA Section 7).
  • Under contract with fellos, our AI provider, WATTER, Inc., which provides OTTO, keeps none of the content it receives and does not train on it.

Backups and deletion

  • Backups are kept for up to 35 days, and then expire.
  • Data is deleted on the schedule in DPA Section 11.

Breaches

  • We tell affected organizations' site admins about a personal data breach without undue delay, and within 72 hours of becoming aware of it (DPA Section 9).

Certification

  • fellos holds no security certification, such as SOC 2 or ISO 27001.

Measures the organization controls

  • Requiring passkeys for its members.
  • Choosing who is a site admin, and who holds other roles with extra access.
  • Enabling Google, GitHub or Apple sign-in, through sign-in apps it registers with those providers itself, or not.
  • Turning group summaries on or off.
  • Configuring its site's cookie banner, and its own Terms and Privacy pages.
  • Deactivating members who leave, and asking us to remove a member's data (DPA Section 8).

Annex III: Subprocessors

You give a general authorization to our use of subprocessors (DPA Section 7). The current list, with what each subprocessor does and where it processes data, is at fellos.app/subprocessors. That list forms this Annex, as updated under Section 7.

fellos

Product

  • Why fellos
  • Who it's for
  • Pricing
  • Docs

Platform

  • The Record
  • Elections
  • The Feed
  • Discussions
  • Documents

Company

  • See it running
  • Meet the builder
  • Security
  • hello@fellos.app
  • Instagram
  • © 2026 fellos
  • ·
  • Terms
  • ·
  • Privacy
  • ·

One optional category: Analytics, which covers product analytics. Nothing for it loads until you accept. Your choice also applies on signup.fellos.app. What we collect