Third Party Index

Snapshot 49587

Document
Data processing addendum
URL
https://centerfuze.com/trust-center/dpa/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
59205 bytes
SHA-256 (raw)
133cb8fe5b607629f5efc5cd63fdc2de02333dbeb412565d8b0eb4c89bdb03c1
SHA-256 (normalized text)
33df297a3314f08651b778b0a4e1181dde61271c74f26e61274c448c3e1e3aea

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Your privacy choices
Necessary technologies keep this site secure. Analytics and Advertising/Marketing are off unless you choose them. When Global Privacy Control is active, Accept All enables Analytics only and Advertising/Marketing stays off.
Legal
Data Processing Addendum
Publication date: January 1, 2026 · Effective date: January 1, 2026 · Version 1.0
CenterFuze Data Processing Addendum
Effective date: January 1, 2026
Version: 1.0
This Data Processing Addendum (“DPA”) forms part of the Customer Subscription Agreement or other agreement governing Customer's use of the Services (“Agreement”) between Customer and CenterFuze, LLC (“CenterFuze”). It applies when CenterFuze processes Customer Personal Data on Customer's behalf.
1. Definitions
“Applicable Data Protection Law” means privacy and data-protection law applicable to CenterFuze's processing under the Agreement, including GDPR, UK GDPR, the CCPA/CPRA, and applicable U.S. state comprehensive privacy laws. “Customer Personal Data” means Personal Data within Customer Data that CenterFuze processes on Customer's behalf. “Data Subject,” “Controller,” “Processor,” “Personal Data,” “Process,” “Sale,” “Share,” and “Supervisory Authority” have the meanings under applicable law. “Security Incident” means a confirmed unauthorized acquisition of, access to, or disclosure, alteration, or destruction of Customer Personal Data in CenterFuze's possession or control, excluding unsuccessful attempts that do not compromise Customer Personal Data.
2. Roles and instructions
Customer is the Controller or Business and CenterFuze is the Processor or Service Provider. If Customer is a Processor, CenterFuze is its Subprocessor. Customer instructs CenterFuze to process Customer Personal Data to provide, secure, support, and maintain the Services; perform the Agreement; follow authorized use and configuration; and comply with other documented lawful instructions. The Agreement, Customer's use, and this DPA constitute documented instructions.
CenterFuze will process Customer Personal Data only on documented instructions unless law requires otherwise. Where legally permitted, CenterFuze will notify Customer before required processing. CenterFuze will inform Customer if an instruction, in its reasonable opinion, violates Applicable Data Protection Law and may suspend the affected processing while the parties resolve the issue.
Customer is responsible for its lawful basis, notices, consents, instructions, data accuracy, data minimization, and configuration and warrants that its instructions comply with law.
3. Confidentiality and personnel
CenterFuze will limit access to personnel who need it to provide and secure the Services and ensure they are bound by confidentiality obligations and receive appropriate privacy and security responsibilities.
4. Security
CenterFuze will maintain reasonable administrative, technical, and organizational measures appropriate to risk, including:
multi-tenant AWS-hosted production infrastructure with logical tenant separation;
encryption in transit and at rest for supported production data;
multi-factor authentication for privileged access;
role-based access control and access lifecycle procedures;
audit logging, monitoring, and incident response;
code review, controlled release, vulnerability management, and change management;
daily backups, protected backup access, and recovery procedures;
vendor risk review and confidentiality obligations; and
business continuity and disaster recovery processes.
CenterFuze may update measures provided overall protection is not materially reduced. Customer is responsible for its users, endpoints, credentials, source systems, identity provider, configurations, integrations, exports, and lawful use.
5. Security Incidents
CenterFuze will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notice will be sent to the account security contact and will include information reasonably available concerning the nature, affected data and individuals, likely consequences, mitigation, and contact point. Information may be provided in phases. CenterFuze's notice is not an admission of fault or liability.
CenterFuze will take reasonable steps to contain, investigate, remediate, and mitigate the Security Incident and will reasonably cooperate with Customer's legally required assessment and notification. Customer is responsible for notices unless law imposes a direct obligation on CenterFuze.
6. Data Subject requests
Taking into account the nature of processing, CenterFuze will provide reasonable technical and organizational assistance enabling Customer to respond to Data Subject requests. If CenterFuze receives a request concerning Customer Personal Data, it will direct the requester to Customer unless legally prohibited. Customer is responsible for evaluating and responding. Additional custom assistance may be subject to reasonable fees where permitted.
7. Regulatory assistance
CenterFuze will provide reasonable information and assistance for Customer's data protection impact assessments, prior consultations, and legally required regulator inquiries concerning CenterFuze's processing, taking into account the nature of processing and information available.
8. Subprocessors
Customer provides general authorization for CenterFuze to use subprocessors listed at the Trust Center. CenterFuze will impose written data-protection duties substantially consistent with this DPA and remains responsible for their performance to the extent required by the Agreement and law.
CenterFuze will give at least 15 days' notice before a new subprocessor begins materially processing Customer Personal Data. Customer may object during that period on reasonable documented data-protection grounds. The parties will attempt a commercially reasonable resolution. If none is available, CenterFuze may permit Customer to terminate only the affected Service and receive a refund of prepaid unused fees for that Service. This is Customer's sole remedy for a valid unresolved objection.
Customer-directed integrations that act independently or under Customer's agreement are not CenterFuze subprocessors.
9. International transfers
Customer authorizes processing in the United States and locations identified in the Subprocessor List. Where Customer Personal Data subject to GDPR is transferred to a country without an adequacy decision, the EU Commission Standard Contractual Clauses, Module Two (Controller to Processor) or Module Three (Processor to Processor), as applicable, are incorporated. The optional docking clause applies; Clause 9 Option 2 applies with the notice period in Section 8; Clause 11 does not apply; the parties select the law and courts of Ireland for Clauses 17 and 18; and Annexes I–III are completed by this DPA and its schedules.
For UK restricted transfers, the UK International Data Transfer Addendum is incorporated and completed using the parties and information in this DPA, with neither party permitted to terminate solely under its change provision where an approved alternative mechanism remains available. For Swiss transfers, references are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority, and protected persons include legal entities while the law provides such protection.
CenterFuze will provide reasonable information concerning supplementary measures and government-access requests, subject to law and confidentiality.
10. CCPA and U.S. state terms
For Customer Personal Data subject to applicable U.S. state law, CenterFuze is a Service Provider, Contractor, or Processor. CenterFuze will not Sell or Share Customer Personal Data; retain, use, or disclose it outside the business purposes in the Agreement or permitted by law; or combine it with personal information from other sources except as legally permitted to provide the Services. CenterFuze will provide the same level of privacy protection required by applicable law, notify Customer if it can no longer meet its obligations, and permit Customer to take reasonable steps to stop and remediate unauthorized use.
11. Audit and information rights
Once per 12-month period, and additionally after a material Security Incident or regulator request, CenterFuze will provide information reasonably necessary to demonstrate compliance, which may include questionnaires, policy summaries, provider assurance reports, PCI evidence, testing summaries, or other appropriate evidence. Information is subject to confidentiality and security restrictions.
If that information is insufficient and law requires further audit, Customer may request an audit by an independent qualified auditor who is not a competitor, is bound by confidentiality, and follows CenterFuze's reasonable security rules. Audits require at least 30 days' notice, occur during business hours, avoid disruption, exclude other customers' data and privileged information, and are at Customer's expense unless they identify a material uncured breach by CenterFuze. The parties will agree scope before an on-site review.
12. Return and deletion
Customer may export Customer Personal Data during the Subscription Term and for 90 days after expiration or termination. At the end of that period, CenterFuze will delete Customer Personal Data from active systems unless law requires retention. Residual encrypted or protected backup copies will expire or be overwritten under CenterFuze's backup lifecycle and remain subject to this DPA until deletion. CenterFuze may retain limited account, transaction, security, and legal records as an independent Controller where permitted by law.
13. Liability and conflict
Liability under this DPA is subject to the Agreement's exclusions and caps. If this DPA conflicts with the Agreement concerning processing of Customer Personal Data, this DPA controls. If the Standard Contractual Clauses conflict with this DPA, the Clauses control.
14. Term and acceptance
This DPA begins when Customer accepts the Agreement or first submits Customer Personal Data and continues until CenterFuze completes processing. Customer accepts this DPA through the same clickwrap or signature used for the Agreement. An individual accepting represents authority to bind Customer as Controller, Business, or Processor.
Schedule 1 — Processing details
Subject matter: Provision, security, support, maintenance, integration, analytics, and administration of the Services.
Duration: Subscription Term plus the 90-day export period and backup lifecycle.
Nature and purposes: Collection, recording, organization, storage, retrieval, consultation, use, transmission, integration, analysis, support, protection, export, deletion, and other processing instructed through the Services.
Data subjects: Customer personnel; Authorized Users; Customer's customers, prospects, patients, members, vendors, partners, contractors, and other individuals whose data Customer submits.
Data categories: Business contact and account data; identity and authentication data; CRM and ERP records; billing, invoice, payment-token and transaction metadata; subscription, usage, project and time records; communications; support data; device, log, audit, and integration data; healthcare and insurance information when the Healthcare Module and BAA apply; and other data Customer elects to submit.
Sensitive data: PHI under the BAA; financial account/payment metadata; credentials; and other sensitive data Customer is authorized to submit through approved workflows. Full PAN and sensitive authentication data are not intended to be stored by CenterFuze outside the assessed PCI environment.
Frequency: Continuous or as initiated by Customer and Authorized Users.
Schedule 2 — Parties
Data exporter: Customer identified in the account or Order Form.
Data importer: CenterFuze, LLC, 433 Plaza Real, Ste 275, Boca Raton, FL 33432; [email protected].
Competent authority: Determined under applicable transfer law.
Signature: Electronic acceptance of the Customer Agreement.
Version archive
Version 1.0 is preserved as an immutable public record.
View archived version 1.0