Effective 14 August 2026. Between the Organisation ("Controller", our customer/tenant) and CommonLynk, operated by Common Ground Solutions (CGS), a limited liability company established under Egyptian Law No. 159 of 1981 ("Processor"). This DPA forms part of, and is governed by, the Terms of Service. It is designed to align with major data protection frameworks, including Article 28 of the EU GDPR, and the data protection laws applicable to the parties.
1. Roles
The Organisation is the Controller of the personal data it enters or uploads about the individuals, households and establishments it records and serves on the platform (each, a "Beneficiary"), and about its staff, contacts and operations (together, "Organisation Data"). CommonLynk is the Processor, processing Organisation Data only to provide the platform and only on the Controller's documented instructions (including via configuration and use of the platform). CommonLynk will inform the Controller if, in its opinion, an instruction infringes applicable law.
2. Subject-matter, duration, nature & purpose
- Subject-matter / nature: hosting, storage, processing and display of Organisation Data to deliver the platform's beneficiary-management, programme, forms, reporting and related features.
- Duration: for the term of the subscription and the retention periods in the Data Retention Policy.
- Types of data: as determined by the Controller — typically identifying data, contact details, programme/attendance records, form responses, and any special-category or children's data the Controller chooses to record. Also includes diagnostic and fault-report data generated by the Controller's use of the platform (Section 5A).
- Categories of data subjects: the Controller's Beneficiaries, staff, and contacts.
3. Processor obligations
CommonLynk will:
- Process Organisation Data only on documented instructions, including for transfers, unless required by law (and will notify the Controller of such a requirement unless legally prohibited).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Schedule A), including the backup, restore and continuity measures in Section 4A.
- Respect the conditions for engaging sub-processors (Section 5).
- Assist the Controller, by appropriate measures — including the per-record and full-workspace export facilities in Section 4A — in responding to data-subject requests (access, correction, deletion, portability, etc.).
- Assist the Controller with security, breach notification, impact assessments and prior consultations, taking into account the information available to CommonLynk.
- On termination, delete or return Organisation Data at the Controller's choice — the self-service retrieval and offboarding facilities in Section 4A operationalise "return" — and delete existing copies unless retention is required by law (see Retention Policy).
- Make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 7).
4. Security measures (Schedule A summary)
Encryption in transit (HTTPS/TLS); per-tenant data isolation; role-based access control; authenticated, ownership-checked access to uploaded files; secrets stored encrypted; regular encrypted, retention-managed tenant backups with a regularly-tested restore process (Section 4A); logging and monitoring; least-privilege administrative access. Full current measures: https://commonlynk.com/legal/security.
4A. Backup, restore, retrieval & continuity
CommonLynk protects Organisation Data against loss and supports the Controller's own continuity and data-portability obligations through the following measures, in addition to Section 4:
- Encryption of backups. Backup packages generated for the Controller within the platform are encrypted at rest with AES-256, under a key dedicated to the backup subsystem and separate from the live-data encryption key; the Controller's downloads are available as AES-256-encrypted archives; all transfers use TLS. CommonLynk's server-level infrastructure snapshots are a separate layer with a different posture, described in the Data Retention Policy.
- Scheduled and on-demand backups. The Controller can configure automatic backups (daily / weekly / monthly), aligned to its own timezone and working week, and can also create a backup on demand, from within its workspace.
- Managed retention. Backup copies are retained on a grandfather-father-son schedule (the most recent daily, weekly and monthly copies) and then automatically pruned; retention counts are automatically verified. Full periods are in the Data Retention Policy.
- Self-service retrieval (portability). At any time while active, and throughout the grace and dormant periods after a lapse, the Controller can download a complete copy of its Organisation Data in open, machine-readable formats (spreadsheets and CSV), together with original uploaded files and a technical database copy — supporting the Controller's Article 20 portability and its own record-keeping.
- Per-data-subject export. The platform can produce a single individual's complete record on request, to help the Controller respond to data-subject access and portability requests (Section 9).
- Point-in-time restore. The Controller can restore its workspace — or a single module or record — to an earlier backup. A restore first takes an automatic safety snapshot and can be reverted within a defined window. CommonLynk regularly and automatically tests the restore process, aligning with the requirement to regularly test and evaluate the effectiveness of security measures (e.g. GDPR Article 32(1)(d)).
- Erasure persists across restore. Where the Controller erases a data subject's records, that erasure is recorded and honoured on any subsequent restore — a restore does not resurrect records erased after the backup was taken.
- Optional Controller-held escrow. The Controller may configure delivery of its backup copies to storage the Controller itself owns and controls, encrypted with a passphrase the Controller sets, so the Controller holds an independent copy outside CommonLynk's infrastructure. Storage the Controller so nominates is the Controller's own facility, not a CommonLynk sub-processor. Where the destination is a cloud account the Controller connects (for example Google Drive, Dropbox or OneDrive), CommonLynk uses app-folder-scoped access only and can access only the backup files it creates — never any other content in the Controller's account.
- Offboarding package. When a subscription lapses, CommonLynk generates a final, complete backup package at the start of the grace period and keeps it available for the Controller to download throughout the grace and dormant periods (see the Data Retention Policy) before any scheduled deletion. This operationalises Section 3(7).
5. Sub-processors
The Controller provides general authorisation for CommonLynk to engage sub-processors (e.g. email delivery, payment processing, cloud hosting/backups) listed in Schedule B (Sub-processor list) at the end of this DPA. CommonLynk will (a) impose data-protection obligations on each sub-processor at least as protective as this DPA, (b) remain fully liable for its sub-processors, and (c) give the Controller at least 30 days' prior notice of intended additions or replacements, allowing the Controller to object on reasonable data-protection grounds. For the avoidance of doubt, storage the Controller nominates for escrow under Section 4A(8) is not a CommonLynk sub-processor.
5A. Diagnostic data and fault reports
CommonLynk operates an in-platform fault-reporting and support facility. When the platform encounters an error, or a user of the Controller's workspace reports a problem, CommonLynk records diagnostic data: the technical error details, the page address and view, the browser and operating system, the interface language, timestamps, the acting user and workspace, and a trail of the immediately preceding user actions limited to the type of action and the name of the control used — never field values, entered text, or record contents. A user may additionally choose to attach a screenshot or file.
Reports are classified, diagnosed and answered by CommonLynk personnel. The following commitments apply in addition to Sections 3 and 5:
- Screenshots and uploaded files stay in access-controlled storage. They are processed only by authorised CommonLynk personnel, are unreachable from the public web, and are never transmitted outside the platform — including as an attachment to any internal or external email.
- Access to screenshots is logged. Each occasion on which CommonLynk personnel open a screenshot attached to a report is recorded in an append-only audit log available to the Controller on request under Section 7.
- Human daily review. CommonLynk personnel receive an internal daily summary of new reports in order to triage them. That summary is transmitted through CommonLynk's email sub-processor named in Schedule B and contains no screenshots and no uploaded files — it carries links that open the report inside the platform, where each access is logged under clause 2.
- No solely automated decision-making. No outcome of a report is determined by automated means, and no automated process effects any change to Organisation Data or produces legal or similarly significant effects for any data subject.
- Retention. Diagnostic data, screenshots and reports are retained and deleted in accordance with the Data Retention Policy.
For the avoidance of doubt, diagnostic data that contains personal data of the Controller's data subjects is Organisation Data and is governed by this DPA in full.
Revision note. This Section was revised and narrowed on 18 August 2026. The commitments above are more restrictive than those they replace, and no processing previously described has been added.
6. Personal data breaches
CommonLynk will notify the Controller without undue delay after becoming aware of a personal data breach affecting Organisation Data, with the information the Controller reasonably needs to meet its own notification obligations (which, under some laws, can be as short as 72 hours to a regulator). CommonLynk will not notify the Controller's data subjects or regulators on the Controller's behalf unless instructed.
7. Audits
CommonLynk will make available information reasonably necessary to demonstrate compliance with this DPA and allow audits/inspections by the Controller or its appointed auditor, on reasonable notice, during business hours, subject to confidentiality and not unreasonably disrupting operations. CommonLynk may satisfy audit requests through up-to-date third-party certifications or reports where available.
8. International transfers
Where CommonLynk processes or transfers Organisation Data across borders, it will apply the safeguards required by applicable law — which may include regulator authorisations, the European Commission's 2021 Standard Contractual Clauses (Module Two for controller-to-processor and Module Three for processor-to-processor transfers) or equivalent contractual safeguards, and/or in-region hosting where a jurisdiction so requires. The parties will cooperate to put the appropriate mechanism in place for the Controller's data subjects.
9. Data-subject requests
If CommonLynk receives a request from a data subject relating to Organisation Data, it will not respond directly (except to confirm the request should go to the Controller) and will promptly forward it to the Controller and assist as set out above. The platform's per-record export and full-workspace retrieval facilities (Section 4A(4)–(5)) are available to the Controller to help it fulfil access and portability requests.
10. Liability, term & precedence
This DPA's liability is subject to the limitations in the Terms of Service. It takes effect when the Controller accepts the Terms and continues while CommonLynk processes Organisation Data. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails.
Schedule B — Sub-processor list
What this page is
A sub-processor is a third-party company that processes personal data on CommonLynk's behalf in order to deliver the service. This page names every one of them, says what each processes and where, so that an Organisation using CommonLynk can satisfy its own accountability and donor due-diligence obligations.
Notice of change. We give Organisations at least 30 days' advance notice before adding or replacing a sub-processor. An Organisation may object on reasonable data-protection grounds; the process is in the DPA Section 5. To receive change notices, contact our Data Protection Officer, Yasmine Ossama — dpo@commonlynk.com.
Last reviewed: 18 August 2026.
Current sub-processors
Brevo
- Purpose: Outbound transactional email — account, billing, support and notification messages
- Personal data processed: Recipient name and email address, message subject and body, delivery metadata
- Processing location: EU
- Status: Active
Paymob
- Purpose: Card payment processing
- Personal data processed: Billing name, contact details, payment identifiers. CommonLynk never receives or stores card numbers — these are entered on the provider's own hosted page
- Processing location: Egypt
- Status: Configured — not yet processing live cardholder data; activated when the first live payment is taken
Contabo GmbH
- Purpose: Server infrastructure hosting (VPS running the platform and its databases, including the first tenant workspace) and access-controlled off-site backup storage
- Personal data processed: All platform data — at rest, in processing, and within full backups
- Processing location: Germany (EU)
- Status: Active
Hosting expansion. As CommonLynk grows, additional workspaces may be hosted with other providers or in other countries. Each such provider will be named on this list and Organisations given advance notice before it is added, per the DPA Section 5.
Not sub-processors
Listed so that the absence is deliberate rather than an oversight — due-diligence reviewers ask about these:
GeoNames
- Why it is not a sub-processor: CommonLynk retrieves public administrative-division reference data from it. No personal data is sent.
Public exchange-rate source
- Why it is not a sub-processor: Rates are fetched; nothing is sent.
IP-to-country lookup (local database)
- Why it is not a sub-processor: Visitor country (for currency/language) is read from a local database; no IP address is sent to any third party.
Contabo GmbH's own hardware maintenance
- Why it is not a sub-processor: Covered by the hosting agreement above, not a separate engagement.
Controller-connected escrow storage (Google Drive / Dropbox / OneDrive / S3)
- Why it is not a sub-processor: When an Organisation connects its own storage to receive backup copies, that account is the Organisation's own facility, not a CommonLynk sub-processor. CommonLynk uses app-folder-scoped access and can touch only the backup files it creates. See DPA Section 4A(8).
What we require of every sub-processor
Per DPA Section 5, each sub-processor is bound by a written agreement imposing data-protection obligations at least as protective as those CommonLynk owes its Organisations, and CommonLynk remains fully liable for their performance.