Skip to content
ShelterCurrent
ProductHow it worksPricingSecurity
Sign inTry the demoSign up
ProductHow it worksPricingSecurityTry the demoSign upSign in
Approved legal document.This page is rendered from the canonical, approved, version-controlled project document.

ShelterCurrent Data Processing Addendum

Version: 1.0
Effective date: 2026-08-12

This Data Processing Addendum (DPA) is between Elm and Ink LLC, a Missouri limited liability company doing business as ShelterCurrent (Provider), and the organization that electronically accepts it (Customer). It forms part of the ShelterCurrent Terms of Service (Terms). Capitalized terms not defined here have the meanings in the Terms.

1. Definitions and roles

Applicable Data Protection Law means a U.S. federal, state, or local law that applies to a party's Processing of Customer Personal Data under the Agreement. Customer Data means information Customer or its Authorized Users submit to or generate through the Service for Customer. Customer Personal Data means personal data, personal information, or a substantially similar category within Customer Data that Provider Processes on Customer's behalf. Process includes collecting, accessing, using, storing, transmitting, restricting, deleting, or otherwise handling information. Security Incident has the meaning in Annex D. Subprocessor means a third party Provider engages to Process Customer Personal Data on Customer's behalf.

For Customer Personal Data, Customer is the controller, business, or regulated entity and Provider is its processor, service provider, or contractor, as applicable. Each party is responsible for duties the law assigns to it. Provider acts independently for limited business-contact, account, billing, security, fraud-prevention, contract, and legal-compliance information described in the Privacy Notice.

2. Instructions and purpose limits

Customer instructs Provider to Process Customer Personal Data only to provide, secure, maintain, support, back up, export, and delete the Service; follow Customer's lawful configuration and instructions; perform Annex A; and comply with law. The Agreement and Customer's authorized use are the complete instructions. Provider will notify Customer if it reasonably believes an instruction violates Applicable Data Protection Law and may suspend the affected Processing while the parties address it.

Provider will not retain, use, or disclose Customer Personal Data outside the direct business relationship or for another purpose except as permitted by the Agreement or law. Provider will not sell it; share it for cross-context behavioral advertising; use it for targeted advertising or independent marketing; combine it with other personal data except as legally permitted and necessary to perform the Service; use identifiable shelter-client records or notes to train a general-purpose or cross-customer AI model; or attempt to reidentify properly deidentified information.

Provider certifies that it understands and will comply with these restrictions. Customer may take reasonable steps to stop and remediate unauthorized use.

3. Customer duties and prohibited data

Customer will provide lawful instructions; establish its authority for collection and Processing; provide required notices and consent; configure users, roles, exports, and workflows; collect only what is necessary; and respond to individuals and authorities as controller or business. Customer is responsible for its grants, licensing, public-records, recordkeeping, and other program obligations.

The Standard Service excludes the prohibited and regulated data listed in the Terms, including data requiring Provider to execute a HIPAA business associate agreement, 42 C.F.R. Part 2 records, victim-service or comparable-database records, dedicated youth-program records, Social Security numbers, complete payment-card data, scanned identification documents, and unrestricted narrative case files. Provider does not offer a BAA or specialized configuration. A field or technical ability to enter information does not authorize prohibited use.

4. Confidentiality and security

Provider will require personnel authorized to Process Customer Personal Data to owe enforceable confidentiality duties, receive role-appropriate training, and access data only as needed for assigned duties. Provider will apply reasonable least privilege and revoke unnecessary access.

Provider will maintain the administrative, technical, organizational, and physical safeguards in Annex B. Measures may change with technology and risk if the overall protection is not materially reduced.

5. Subprocessors

Customer gives general authorization for Provider to use the Subprocessors in Annex F. Provider will conduct proportionate diligence and enter written terms requiring each Subprocessor to protect Customer Personal Data consistently with this DPA for its Processing. Provider remains responsible for its obligations where a Subprocessor performs them on Provider's behalf.

Provider will provide reasonable advance electronic notice of a new or replacement Subprocessor when practicable. Emergency changes necessary for security, legality, or continuity may occur first, with notice without undue delay. Where Applicable Data Protection Law requires an objection process, Customer may raise documented data-protection concerns. Provider may adopt reasonable mitigation or allow cancellation of the affected Service, but is not required to provide an alternative provider. A system Customer selects and directs Provider to send data to is Customer's recipient, not Provider's Subprocessor.

6. Assistance and compliance information

Taking into account the nature of Processing and information available, Provider will reasonably assist Customer with authenticated individual-rights requests, required assessments, security duties, legally required notifications, and regulator inquiries concerning Customer Personal Data. If Provider receives a request directly, it will route the request to Customer unless prohibited by law and will act on Customer's lawful instruction.

Provider will provide remote written information reasonably necessary to demonstrate compliance when Applicable Data Protection Law requires it. Nothing in this DPA grants a general audit, inspection, penetration-testing, source-code, facility-access, or certification right. Provider may protect other customers, confidential information, security, and service availability. The Standard Service price does not include custom questionnaires, routine onsite audits, or bespoke security or evidence packages.

7. Legal demands

Unless prohibited by law, Provider will notify Customer before disclosing Customer Personal Data in response to compulsory legal process. Provider will review the demand, direct the requester to Customer when appropriate, and disclose only the minimum legally required.

8. Return, deletion, and term

Annex C governs retention, export, and deletion. This DPA begins only when its effective version is accepted and continues while Provider Processes Customer Personal Data. Duties concerning retained data, confidentiality, security, legal demands, and deletion survive as necessary to complete them.

If this DPA conflicts with the Terms concerning Processing of Customer Personal Data, this DPA controls for that subject. The Terms' disclaimers, exclusions, liability cap, governing law, venue, and general terms apply to this DPA.

9. Acceptance and contact

The individual accepting this DPA represents authority to bind Customer. The electronic acceptance record identifies Customer, actor, version, timestamp, and transaction or request identifier.

Elm and Ink LLC d/b/a ShelterCurrent
9755 N Lucerne Ave, Kansas City, MO 64154, USA
Privacy: privacy@sheltercurrent.com
Security: security@sheltercurrent.com
Billing: billing@sheltercurrent.com
Support: support@sheltercurrent.com
Legal: legal@sheltercurrent.com

Annex A — Processing Details

TopicDescription
Subject matterAn eligible private nonprofit organization or private business Customer's use of the Standard Service for ordinary workforce-managed nongovernmental U.S. shelter operations alongside a separate HMIS. Governmental, public-authority, tribal, procurement/public-records/appropriations/sovereign-immunity, and personal/consumer use is excluded.
DurationThe paid term, the post-term schedule in Annex C, and any narrow documented legal hold.
Nature and purposeCollection, organization, storage, retrieval, use, transmission to authorized recipients, restriction, export, backup, security, support, and deletion necessary to provide the Service on Customer's instructions.
FrequencyContinuous or as initiated by Authorized Users during the term, plus scheduled security, recovery, and deletion operations.
IndividualsShelter applicants, clients, residents, former residents, waitlisted or turned-away people, adult household members, accompanied minors, emergency or referral contacts, Customer personnel, and Authorized Users.
DataMinimum necessary identity and contact details; household relationships; shelter or external HMIS identifiers other than Social Security numbers; referrals; controlled intake and accommodation information; facility, bed, reservation, stay, waitlist, turnaway, census, incident, task, supply, report, export, configuration, consent, retention, and audit records; and Authorized User identity and activity records.
Sensitive characteristicsCustomer Data may reveal homelessness, shelter location, family relationships, disability or accommodation needs, safety concerns, incidents, or limited health-related inferences. Prohibited data in Section 3 is excluded.
LocationThe Service is for U.S.-based Customers and U.S. shelter operations. Provider does not guarantee that every provider operation, network path, storage copy, or support action occurs only in the United States.

Annex B — Security Measures

Provider will maintain safeguards appropriate to the sensitivity and risk of Customer Personal Data, including:

  • named security ownership, risk review, written policies, personnel confidentiality, and access revocation;
  • verified individual workforce accounts; controlled public owner signup; invitation-only membership in an existing organization; TOTP multifactor authentication for every Admin and Staff account; session controls; and no shared accounts or existing-organization self-join;
  • least-privilege roles, organization and facility scoping, deny-by-default authorization, database-enforced tenant isolation, and separation of production and nonproduction data;
  • encryption in transit, provider-managed encryption at rest, managed secrets, protected credentials, and authenticated encrypted recovery mechanisms;
  • attributable audit events for critical actions, restricted security logging, reasonable log minimization, and time synchronization;
  • secure development and release controls, code review, dependency and secret scanning, vulnerability handling, supported dependencies, and synthetic-only nonproduction use;
  • managed recovery, continuity, incident response, evidence preservation, and restoration procedures proportionate to the Service; and
  • Subprocessor diligence, written data-protection terms, and controlled support access.

No safeguard makes a system completely secure. Provider may replace a technology or provider with reasonably comparable protection.

Annex C — Retention and Deletion

Customer Data

During the paid term, Provider retains Customer Data unless Customer deletes it or gives a lawful instruction. Customer is responsible for retaining records it must preserve and exporting them before scheduled deletion. The Standard Service does not include a configurable category-retention engine.

After the paid term:

  1. the workspace is read-only for 30 days for authenticated organization export;
  2. Provider deletes or renders inaccessible Customer Data in active production systems within the following 30 days; and
  3. Neon recovery history rolls off within 7 days after active deletion.

Provider may retain only affected data required by a specific legal duty or narrow documented legal hold. It will restrict ordinary use and delete the data when the basis ends. If recovery requires restoration of an earlier copy, Provider will reapply recorded deletions and restrictions before ordinary use. Provider may retain deletion evidence that does not contain deleted record contents.

Provider-controlled records

RecordDefault period
Authentication and security logs12 months
Support, contact, and privacy-request records2 years after closure
Security Incident and documented no-harm determination records5 years after closure
Billing, tax, legal-assent, refund, and deletion evidence7 years
Deidentified statisticsIndefinitely while maintained in deidentified form

A specific legal duty, fraud or security investigation, dispute, or narrow legal hold may require longer retention. Provider will delete or deidentify the record when that basis ends.

Annex D — Security Incidents

A Security Incident means confirmed unauthorized acquisition of, access to, use of, disclosure of, alteration of, loss of, or destruction of Customer Personal Data in Provider's or a Subprocessor's custody or control. It excludes unsuccessful scans, pings, blocked login attempts, denial-of-service attempts, and similar activity that does not compromise Customer Personal Data, and events solely in Customer-controlled systems that do not compromise the Service.

Provider will notify Customer without undue delay after becoming aware that a Security Incident occurred, and within any shorter period Applicable Data Protection Law requires Provider to notify Customer. Provider will not delay an initial notice solely because investigation is incomplete.

To the extent known and reasonably available, phased notices will describe the nature and timing; affected Customer environment, data categories, and approximate scope; likely consequences; containment, investigation, mitigation, and recovery; reasonable Customer actions; and a follow-up contact. Provider will correct material inaccuracies and give material updates as investigation progresses.

Provider will take reasonable steps to contain and investigate, preserve relevant evidence, mitigate harm, remediate causes, restore integrity and availability, and cooperate with Customer's legally required assessment and notice. Customer ordinarily controls notices concerning its Customer Personal Data. Provider may make a notice it is independently required to make and, where permitted, will coordinate with Customer. Notice is not an admission of fault.

Incident notices are sent to Customer's current security or administrator contact. Customer must keep those contacts current. Suspected incidents should be reported to security@sheltercurrent.com without sensitive details in ordinary email.

Annex E — U.S. State Terms

Where Applicable Data Protection Law imposes controller/processor, business/ service-provider, or contractor terms, Provider will:

  • Process Customer Personal Data only under Customer's documented instructions and for the limited purposes in the Agreement;
  • maintain confidentiality and reasonable security;
  • not sell or share Customer Personal Data, use it for targeted advertising, or retain, use, disclose, or combine it outside the permitted business purpose except as law allows;
  • require Subprocessors to protect the data under written terms;
  • reasonably assist with authenticated rights requests, required assessments, security, legally required notices, and deletion;
  • provide compliance information and notify Customer if Provider determines it can no longer meet an applicable obligation; and
  • permit Customer to take reasonable steps to stop and remediate unauthorized Processing.

Accommodation, disability, safety, referral, location, or incident information may be consumer health data under state law even when it is not HIPAA protected health information. Customer is responsible for a required collection notice, consent, and lawful purpose. Provider will Process that data only on Customer's binding instructions, assist with applicable rights, and not sell it or use it to infer health status for an independent purpose.

This Annex applies only to the extent the relevant state law applies and does not expand the Standard Service's prohibited-data boundary.

Annex F — Subprocessors

ProviderFunctionCustomer Personal Data involvedLocation disclosure
Cloudflare, Inc.Application edge, network security, Workers runtime, and static deliveryRequest/network metadata, Authorized User session and security information, and Customer Personal Data transiting application requestsAccording to Cloudflare's applicable service configuration, DPA, and provider disclosures; no U.S.-only guarantee
WorkOS, Inc.Workforce identity, verified email, TOTP MFA for every Admin and Staff account, organization membership, sessions, recovery, and lifecycle eventsAuthorized User identity, business email, organization, role, authentication, session, device/IP, and security metadata; no shelter-client records intendedAccording to WorkOS's applicable service configuration, terms, and provider disclosures; no U.S.-only guarantee
Neon, LLCManaged PostgreSQL database, connection services, availability, and recovery historyCustomer Personal Data stored in the Service, configuration, Authorized User attribution, and audit eventsAccording to the selected production region, Neon's terms, and provider disclosures; no U.S.-only guarantee

Stripe, LLC is a separate billing provider for Customer administrator, billing, transaction, and payment information. It is not a Subprocessor for shelter Customer Personal Data under the designed data flow. GitHub and Cloudflare R2 are not Customer Personal Data paths under the Service described by this DPA.

ShelterCurrent

Shelter operations software for small teams.

ProductPricingSecurityTry the demoSign upPrivacyTermsDPASupportStatusContact