This Data Processing Addendum, including its Annexes ("DPA"), forms part of the Terms of Service or other written agreement (the "Agreement") between the customer ("Customer", "you") and Entrevest, LLC ("Entrevest", "CentraView", "we", "us") governing your use of the CentraView platform and services (the "Services"). It applies to the extent Entrevest processes Personal Data on your behalf in providing the Services and where such processing is subject to Applicable Data Protection Law. If you accept the Agreement, this DPA applies; where it conflicts with the Agreement on the subject of data protection, this DPA controls.
1. Definitions
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws including the California Consumer Privacy Act as amended ("CCPA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR (or the equivalent terms, such as "business", "service provider", and "consumer", under US state law).
- "Customer Personal Data" means Personal Data contained in Customer Data that Entrevest processes on your behalf in providing the Services.
- "Subprocessor" means a third party engaged by Entrevest to process Customer Personal Data.
- "Standard Contractual Clauses" ("SCCs") means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries.
2. Roles and scope of processing
As between the parties, you are the Controller of Customer Personal Data and Entrevest is the Processor, except where you act as a Processor on behalf of a third-party controller, in which case Entrevest is a Subprocessor and you warrant that you have the authority and instructions of that controller. Entrevest will process Customer Personal Data only as a Processor on your behalf. The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.
3. Processing instructions
Entrevest will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case Entrevest will inform you unless legally prohibited). The Agreement, this DPA, and your configuration and use of the Services constitute your complete and documented instructions. Entrevest will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law, without obligation to actively monitor your compliance.
4. Confidentiality
Entrevest ensures that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and process the data only as instructed.
5. Security
Entrevest implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. These measures are described in Annex II and may be updated over time provided the level of protection is not materially degraded.
6. Subprocessors
You provide general authorization for Entrevest to engage Subprocessors to process Customer Personal Data in connection with the Services. Entrevest maintains a current list of Subprocessors (Annex III or a location referenced there) and will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA. Entrevest remains responsible for its Subprocessors' performance of their obligations. Entrevest will give notice of any intended addition or replacement of a Subprocessor with a reasonable opportunity to object on reasonable data-protection grounds; if you object, the parties will work in good faith to resolve it, and if not resolved you may terminate the affected Services.
7. Data Subject requests
Taking into account the nature of the processing, Entrevest will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights. The Services provide functionality that lets you access, correct, delete, restrict, or export Customer Personal Data. If Entrevest receives a request from a Data Subject relating to Customer Personal Data, it will, where legally permitted, direct the Data Subject to you or promptly forward the request to you, and will not otherwise respond except on your instructions.
8. Personal Data Breach
Entrevest will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to assist you in meeting your obligations to notify supervisory authorities or Data Subjects. Entrevest's notification is not an acknowledgment of fault or liability.
9. Data protection impact assessments
Taking into account the nature of processing and the information available to it, Entrevest will provide reasonable assistance to you with data protection impact assessments and prior consultations with supervisory authorities that you are required to carry out under Applicable Data Protection Law in relation to the Services.
10. Return and deletion
On termination or expiry of the Services, Entrevest will, at your choice, delete or return Customer Personal Data, and delete existing copies, unless retention is required by law. The Services provide export functionality you may use before termination. Following a reasonable wind-down period, Entrevest may delete Customer Personal Data in the ordinary course, subject to legal retention requirements.
11. Audits
Entrevest will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To the extent permitted, Entrevest may satisfy this obligation by making available third-party audit reports, certifications, or a completed security questionnaire; on-site audits will be on reasonable prior notice, no more than once per year (except where required following a Personal Data Breach or by a supervisory authority), during business hours, subject to confidentiality, and without disrupting Entrevest's operations or the data of other customers.
12. International transfers
Entrevest may process Customer Personal Data in the United States and other countries. Where Entrevest processes Customer Personal Data that is subject to the GDPR, UK GDPR, or FADP and transfers it to a country that has not received an adequacy decision, the parties agree that the transfer is subject to appropriate safeguards as follows, which are incorporated into this DPA by reference:
- EU transfers. The SCCs apply. Module Two (Controller to Processor) applies where you are a Controller, and Module Three (Processor to Processor) applies where you act as a Processor. The optional docking clause (Clause 7) applies; under Clause 9, Option 2 (general written authorization) applies with the notice period in Section 6; the audit and subprocessor mechanics are as set out in this DPA; the governing law and forum under Clauses 17 and 18 are those of Ireland; and Annexes I–III of this DPA populate the SCC Annexes.
- UK transfers. The UK International Data Transfer Addendum to the SCCs applies and is incorporated, with the SCCs completed as above and the UK Addendum tables populated by this DPA.
- Swiss transfers. The SCCs apply with amendments so that references are read to include the FADP and the Swiss Federal Data Protection and Information Commissioner as a supervisory authority.
If a transfer mechanism is invalidated or a new one is required, the parties will work in good faith to implement an alternative lawful mechanism.
13. US state privacy law (service provider terms)
Where the CCPA or a similar US state privacy law applies, Entrevest acts as a "service provider" (or "processor") and processes Customer Personal Data solely to provide the Services and for the business purposes in the Agreement. Entrevest will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified, or outside the direct business relationship, except as permitted by law; or (c) combine it with other data except as permitted for a service provider. Entrevest certifies that it understands and will comply with these restrictions.
14. Liability
Each party's liability arising out of or related to this DPA and the SCCs, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means aggregate liability under the Agreement and this DPA together.
15. General
This DPA is governed by the law and subject to the forum of the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise. Except as modified here, the Agreement remains in effect. If any provision of this DPA is held invalid, the remainder continues in effect. This DPA supersedes any prior data-processing terms between the parties for the Services.
Annex I — Details of processing
A. Parties
Data exporter: the Customer, acting as Controller (or Processor), whose identity and contact details are in the account and the Agreement. Data importer: Entrevest, LLC, acting as Processor, provider of the CentraView Services; contact privacy@centraview.com.
B. Description of processing
- Categories of Data Subjects: your contacts, leads, customers, and prospects; your Users and personnel; and other individuals whose Personal Data you include in Customer Data.
- Categories of Personal Data: identifiers and contact details (name, email, phone, address); professional information (company, role); communications content and metadata (including email you connect or import); activity, notes, and records you create; and other data you choose to store. You should not submit special categories of Personal Data except as intended and lawful.
- Special categories: not intended to be processed; if present, no additional restrictions are applied by Entrevest beyond the security measures in Annex II.
- Nature and purpose: hosting, storing, organizing, associating, transmitting, and displaying Customer Personal Data to provide the CRM, email-association, support, and related Services described in the Agreement.
- Frequency: continuous, for the duration of the Services.
- Duration: the term of the Agreement plus any wind-down and legally required retention period, per Section 10.
C. Competent supervisory authority
Where the GDPR applies, the supervisory authority of the EU member state in which you (or your EU representative) are established, or as determined by the SCCs; for the UK, the Information Commissioner's Office; for Switzerland, the Federal Data Protection and Information Commissioner.
Annex II — Technical and organizational security measures
Entrevest maintains measures that include, as applicable:
- Encryption: encryption of data in transit (TLS/HTTPS) and encryption at rest of sensitive credentials and secrets (for example, AES-256-GCM for stored access tokens).
- Access control: role- and permission-based access within the Services, tenant/workspace separation of Customer Data, unique accounts, and support for multi-factor authentication.
- Least privilege and authentication: restricted administrative access on a need-to-know basis and authenticated access to systems.
- Resilience and backup: managed, backed-up database infrastructure with recovery capabilities.
- Operational security: logging and monitoring, change management, and vendor management for Subprocessors.
- Incident response: procedures to detect, respond to, and notify Personal Data Breaches under Section 8.
These measures reflect current practice and may evolve; the safeguards above will not be materially reduced during the term.
Annex III — Subprocessors
Entrevest engages Subprocessors to provide the Services, which may include providers of cloud hosting and managed database infrastructure, email delivery, error monitoring, and — where you connect them at your direction — the third-party services you authorize (such as Google). A current list of Subprocessors, with their processing role and location, is available on request at privacy@centraview.com and will be published or provided as described in Section 6.
Contact
Questions about this DPA, or requests to execute a countersigned copy, can be sent to privacy@centraview.com. CentraView is a platform of Entrevest, LLC.