Home/Data Processing Addendum

Data Processing Addendum

Last updated July 17, 2026

Plain-language summary (not a substitute for the full addendum): this document governs how Entrevest, LLC processes personal data on behalf of you, our customer, when you use CentraView. You are the controller of that data; we are your processor and act on your instructions. It sets out our security commitments, our use of subprocessors, how we handle data-subject requests and breaches, how data is returned or deleted, and the safeguards we use for international transfers.

This Data Processing Addendum, including its Annexes ("DPA"), forms part of the Terms of Service or other written agreement (the "Agreement") between the customer ("Customer", "you") and Entrevest, LLC ("Entrevest", "CentraView", "we", "us") governing your use of the CentraView platform and services (the "Services"). It applies to the extent Entrevest processes Personal Data on your behalf in providing the Services and where such processing is subject to Applicable Data Protection Law. If you accept the Agreement, this DPA applies; where it conflicts with the Agreement on the subject of data protection, this DPA controls.

1. Definitions

2. Roles and scope of processing

As between the parties, you are the Controller of Customer Personal Data and Entrevest is the Processor, except where you act as a Processor on behalf of a third-party controller, in which case Entrevest is a Subprocessor and you warrant that you have the authority and instructions of that controller. Entrevest will process Customer Personal Data only as a Processor on your behalf. The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.

3. Processing instructions

Entrevest will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case Entrevest will inform you unless legally prohibited). The Agreement, this DPA, and your configuration and use of the Services constitute your complete and documented instructions. Entrevest will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law, without obligation to actively monitor your compliance.

4. Confidentiality

Entrevest ensures that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and process the data only as instructed.

5. Security

Entrevest implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. These measures are described in Annex II and may be updated over time provided the level of protection is not materially degraded.

6. Subprocessors

You provide general authorization for Entrevest to engage Subprocessors to process Customer Personal Data in connection with the Services. Entrevest maintains a current list of Subprocessors (Annex III or a location referenced there) and will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA. Entrevest remains responsible for its Subprocessors' performance of their obligations. Entrevest will give notice of any intended addition or replacement of a Subprocessor with a reasonable opportunity to object on reasonable data-protection grounds; if you object, the parties will work in good faith to resolve it, and if not resolved you may terminate the affected Services.

7. Data Subject requests

Taking into account the nature of the processing, Entrevest will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights. The Services provide functionality that lets you access, correct, delete, restrict, or export Customer Personal Data. If Entrevest receives a request from a Data Subject relating to Customer Personal Data, it will, where legally permitted, direct the Data Subject to you or promptly forward the request to you, and will not otherwise respond except on your instructions.

8. Personal Data Breach

Entrevest will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to assist you in meeting your obligations to notify supervisory authorities or Data Subjects. Entrevest's notification is not an acknowledgment of fault or liability.

9. Data protection impact assessments

Taking into account the nature of processing and the information available to it, Entrevest will provide reasonable assistance to you with data protection impact assessments and prior consultations with supervisory authorities that you are required to carry out under Applicable Data Protection Law in relation to the Services.

10. Return and deletion

On termination or expiry of the Services, Entrevest will, at your choice, delete or return Customer Personal Data, and delete existing copies, unless retention is required by law. The Services provide export functionality you may use before termination. Following a reasonable wind-down period, Entrevest may delete Customer Personal Data in the ordinary course, subject to legal retention requirements.

11. Audits

Entrevest will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To the extent permitted, Entrevest may satisfy this obligation by making available third-party audit reports, certifications, or a completed security questionnaire; on-site audits will be on reasonable prior notice, no more than once per year (except where required following a Personal Data Breach or by a supervisory authority), during business hours, subject to confidentiality, and without disrupting Entrevest's operations or the data of other customers.

12. International transfers

Entrevest may process Customer Personal Data in the United States and other countries. Where Entrevest processes Customer Personal Data that is subject to the GDPR, UK GDPR, or FADP and transfers it to a country that has not received an adequacy decision, the parties agree that the transfer is subject to appropriate safeguards as follows, which are incorporated into this DPA by reference:

If a transfer mechanism is invalidated or a new one is required, the parties will work in good faith to implement an alternative lawful mechanism.

13. US state privacy law (service provider terms)

Where the CCPA or a similar US state privacy law applies, Entrevest acts as a "service provider" (or "processor") and processes Customer Personal Data solely to provide the Services and for the business purposes in the Agreement. Entrevest will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than the business purposes specified, or outside the direct business relationship, except as permitted by law; or (c) combine it with other data except as permitted for a service provider. Entrevest certifies that it understands and will comply with these restrictions.

14. Liability

Each party's liability arising out of or related to this DPA and the SCCs, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's liability means aggregate liability under the Agreement and this DPA together.

15. General

This DPA is governed by the law and subject to the forum of the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise. Except as modified here, the Agreement remains in effect. If any provision of this DPA is held invalid, the remainder continues in effect. This DPA supersedes any prior data-processing terms between the parties for the Services.


Annex I — Details of processing

A. Parties

Data exporter: the Customer, acting as Controller (or Processor), whose identity and contact details are in the account and the Agreement. Data importer: Entrevest, LLC, acting as Processor, provider of the CentraView Services; contact privacy@centraview.com.

B. Description of processing

C. Competent supervisory authority

Where the GDPR applies, the supervisory authority of the EU member state in which you (or your EU representative) are established, or as determined by the SCCs; for the UK, the Information Commissioner's Office; for Switzerland, the Federal Data Protection and Information Commissioner.

Annex II — Technical and organizational security measures

Entrevest maintains measures that include, as applicable:

These measures reflect current practice and may evolve; the safeguards above will not be materially reduced during the term.

Annex III — Subprocessors

Entrevest engages Subprocessors to provide the Services, which may include providers of cloud hosting and managed database infrastructure, email delivery, error monitoring, and — where you connect them at your direction — the third-party services you authorize (such as Google). A current list of Subprocessors, with their processing role and location, is available on request at privacy@centraview.com and will be published or provided as described in Section 6.

Contact

Questions about this DPA, or requests to execute a countersigned copy, can be sent to privacy@centraview.com. CentraView is a platform of Entrevest, LLC.