Data Processing Addendum

Data Processing Addendum

Last Updated: October 5, 2026

This Data Processing Addendum (“DPA”) supplements the Central Terms of Service (“Terms”) and outlines the Parties’ obligations with respect to the Processing of any Customer Personal Data by Central Business Applications Inc., a Mercury Technologies, Inc. affiliate, and its affiliates and subsidiaries, (“Central,” “we,” “us,” and “our”) on behalf of the entity or organization accepting the Terms and this DPA (“you” and “your”) under the Terms. Unless otherwise defined in this DPA or the Terms, all capitalized terms used herein have the meanings given to them in the Definitions section of this DPA.

1. Data processing.

a. Scope. This DPA applies to any Processing of Customer Personal Data by Central in connection with the Terms. The subject matter, duration, nature, and purpose of the processing of Customer Personal Data as well as the type of Customer Personal Data and categories of Data Subjects are described in Appendix 1 (“Details Regarding the Processing”).

b. Roles of the Parties. With respect to Customer Personal Data, Central is a Processor (and a “service provider” under the California Consumer Privacy Act (“CCPA”)) and you are a Controller (and a “business” under the CCPA). Where you are a Processor acting on behalf of a third-party Controller, Central is a Sub-Processor (including Mercury Technologies, Inc. and its affiliates, where engaged in connection with payment execution or related services). In either case, Central, or its Sub-Processors, may collect Customer Personal Data directly from your employees, contractors, payment beneficiaries, and others on your behalf and at your instruction.

c. Use of Personal Information. Central shall only Process Customer Personal Data on your documented instructions, as follows: (a) processing in accordance with the Terms, applicable Order Form(s), and Appendix 1; (b) processing initiated by your employees, contractors, or other authorized users in their use of Central and as authorized by you; (c) processing pursuant to other documented reasonable instructions provided by you that are consistent with the Terms; and (d) where Central is required or permitted by Data Protection Laws to otherwise Process Personal Information.

d. Limitations on Processing of Customer Personal Data. With respect to Customer Personal Data, Central shall not: (i) sell Customer Personal Data or share Customer Personal Data for purposes of targeted advertising; (ii) retain, use, or disclose Customer Personal Data for any commercial purpose except as permitted in this DPA, order form(s), Terms, or your documented instructions; (iii) retain, use, or disclose Customer Personal Data outside the direct business relationship between Central and you, except as required or permitted by law; or (iv) combine any Customer Personal Data with Personal Information that Central receives from another source, except as otherwise permitted for service providers under the CCPA.

e. Excluded Processing. This DPA does not govern Central’s Processing of Personal Information in any of the following capacities, which are instead governed by the Central Privacy Policy or other agreements, as applicable:

  1. Central Processes Personal Information for its own legal, regulatory and corporate governance obligations that are not otherwise covered by Customer’s instructions.

  2. Mercury banking and financial services relationship. Personal Information that Mercury Technologies, Inc., or its affiliated banking and financial services entities Process in connection with: (i) your direct relationship with Mercury for banking, payment, or related financial services, or (ii) Mercury’s own legal obligations, including sanctions screening, tax reporting, and recordkeeping obligations. For the avoidance of doubt, where the same Personal Information is Processed both by Central (as Customer Personal Data under this DPA) and by Mercury (outside this DPA), Central’s Processing remains subject to this DPA notwithstanding Mercury’s separate Processing.

2. Central’s Obligations.

a. Compliance with Data Protection Laws. Central will comply with Data Protection Laws applicable to its role as processor.

b. Confidentiality. Central shall ensure that all personnel who have access to Customer Personal Data or who are authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations.

c. Notification. Central shall inform you if it believes that (a) your instructions would cause you or us to violate this DPA or Data Protection Laws; or (b) Central can no longer comply with this DPA or any Data Protection Laws.

d. Assistance. Central shall reasonably assist you with meeting your obligations under Data Protection Laws, taking into account the nature of Central’s Processing and the information available to Central. Where you require assistance beyond Central’s standard platform functionality, Central shall provide such assistance at your reasonable expense.

3. Your Obligations.

a. Compliance and Lawful Basis. You represent and warrant that you are authorized to submit your employees’ and contractors’ personal information to Central for payroll and related processing, that you have informed or will inform those individuals that their data is processed by a third party, and that your use of the Services complies with applicable Data Protection Laws.

b. Notification. You shall promptly notify Central of any matters that materially affect Central’s Processing, including Data Subject requests requiring Central’s assistance and regulatory inquiries or investigations related to Customer Personal Data Processed through the Services.

4. Security.

a. Required Safeguards. Central shall implement and maintain appropriate technical and organizational measures designed to protect against the unauthorized or unlawful Processing of Customer Personal Data, and against the accidental loss or destruction of, or damage to, Customer Personal Data, taking into account the costs of implementation, the nature, scope, context and purposes of Processing, and the risks to Data Subjects. Central’s current Security Measures are described in Appendix 2.

5. Security Incidents.

a. Notification. Central shall notify you without undue delay after confirming a Security Incident that affects your Customer Personal Data. Notifications under this Section will be made by email to the contact on file. For the avoidance of doubt, notification of a Security Incident under this Section shall not be construed as an admission of fault or liability by Central. Further, Central’s notification and remediation obligations under this Section do not apply to Security Incidents caused by your actions or those of your authorized users.

b. Content of the Notification. Central’s notification shall include to the extent reasonably known at the time of notification, a general description of the Security Incident and a contact point for further information. Central shall provide additional information as it becomes reasonably available and as necessary for you to comply with your own notification obligations under Data Protection Laws. Central is not required to provide information that would compromise an ongoing investigation, violate law, or breach Central’s obligations.

c. Mitigation. Central shall take commercially reasonable steps to investigate, contain, and remediate the effects of the Security Incident. Each Party shall bear its own costs in responding to a Security Incident, except that Central shall bear the costs of investigation and remediation to the extent the Security Incident was caused by Central’s breach of this DPA.

d. Publicity. Neither party may publish publicly or to any third party any information related to any Security Incident that identifies the other Party without the other Party’s prior written consent, except to the limited extent required by applicable law or by Central’s obligations to its regulators.

6. Demonstrating Compliance.

a. Reports and Certifications. Central shall use commercially reasonable efforts to maintain or obtain industry-standard certifications and audit reports covering its Processing of Customer Personal Data, which may include coverage under Mercury’s group-level security program. Upon written request, and no more than once per calendar year, Central shall make available relevant security documentation demonstrating compliance with Appendix 2. Such documentation shall be treated as Central’s Confidential Information.

b. Audits and Inspections. You acknowledge that the audit reports provided under Section 6(a) constitute Central’s primary mechanism for demonstrating compliance. If those reports are demonstrably insufficient to verify Central’s compliance and an audit is required by Data Protection Laws or by your competent Supervisory Authority, you may request an audit of Central’s relevant Processing activities, subject to the following: (i) at least 45 days’ prior written notice; (ii) not more than once per calendar year; (iii) conducted during business hours without unreasonable interference with Central’s operations; (iv) you shall bear all costs associated with the audit; (v) by an auditor (not a Central competitor) bound by confidentiality; (vi) the scope limited to Central’s compliance with this DPA; and (vii) the Parties will mutually agree upon the scope, timing, and duration of the audit and any reimbursement rate for Central’s reasonable costs before the audit commences. Customer must promptly provide Central with information regarding any actual or suspected non-compliance with this DPA discovered during the course of an audit.

7. Complaints and Data Subject Requests.

a. Notification. Central shall promptly notify you, and in any event within a timeframe that enables you to comply with applicable response deadlines under Data Protection Laws, after receiving any request from a Data Subject to exercise rights under Data Protection Laws with respect to the Processing of your Customer Personal Data.

b. Cooperation. Central shall provide you with commercially reasonable cooperation and assistance, through Central’s standard platform functionality, to enable you to respond to Data Subject requests. Where you require assistance beyond Central’s standard platform functionality, Central shall provide such assistance at your reasonable expense. Central shall cooperate, upon request, with any supervisory authority in the performance of its tasks, to the extent such cooperation relates to the Processing of your Customer Personal Data.

c. No Direct Response. Central shall not respond directly to any Data Subject, except to direct the Data Subject to you, unless authorized by you or required by Data Protection Laws, in which case Central shall inform you of the legal requirement before responding (to the extent permitted by law).

8. Subprocessing.

a. General Authorization. You provide general written authorization for Central to engage Subprocessors to Process Customer Personal Data in connection with the Services.

b. Notification and Requirements. Central maintains a current Subprocessor List available upon request by contacting support@central.inc. You may request the Subprocessor List at any time to review current Subprocessors and raise any objection. If you have a reasonable, documented objection to any Subprocessor based on data protection grounds, you must notify Central in writing and Central will work in good faith to resolve your objection. If your objection cannot be resolved within 30 days, you may terminate the portion of the Services that requires the objected-to Subprocessor by written notice to Central, as your sole remedy.

c. Liability. Central shall be liable for the acts and omissions of its Subprocessors to the same extent Central would be liable if performing the relevant Processing directly under this DPA. For the avoidance of doubt, where a Subprocessor Processes Customer Personal Data as your directly authorized agent, such as a reporting agent or third-party administrator for tax filing purposes, acting under your own authorization rather than Central’s instructions, that Processing is not performed on Central’s behalf and is not subject to this Section 8(c).

d. Third-Party Controller. You acknowledge that certain third parties in the payment, benefits, tax, and compliance chain may act as independent Controllers with respect to Personal Information they receive. Processing of Personal Information by these third parties is governed by their own privacy notices and applicable law.

9. International Transfers.

Central primarily Processes Personal Information in the United States. Central and its Subprocessors may Process Personal Information in other jurisdictions as necessary to provide the Services, subject to the transfer safeguards described in this Section. Central may not engage in a Restricted Transfer without ensuring that appropriate safeguards are in place as required by Data Protection Laws. Any Restricted Transfer is subject to the following.

a. Transfers from the EEA. Where a Restricted Transfer is made from the EEA, such transfers are made pursuant to the EU SCCs, which are hereby deemed entered into (and incorporated into this DPA by reference) and completed as follows:

  1. Module Two (Controller to Processor) of the EU SCCs apply when you are a controller and Central is Processing Customer Personal Data for you as a processor.

  2. Module Three (Processor to Sub-Processor) of the EU SCCs apply when you are a processor and Central is processing Customer Personal Data on behalf of you as a sub-processor.

  3. For each module, where applicable the following applies:

    A. The optional docking clause in Clause 7 does not apply

    B. In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of sub-processor changes shall be as set forth in Section 8;

    C. In Clause 11, the optional language does not apply;

    D. In Clause 13, the competent supervisory authority is the Irish Data Protection Commission;

    E. In Clause 17 (Option 1), the EU SCCs will be governed by the laws of Ireland.

    F. In Clause 18(b), disputes will be resolved before the courts of Ireland.

    G. The information required in Annex I of the EU SCCs is hereby populated with the information in Appendix 1 (Details Regarding the Processing) of this DPA. You shall be the ‘data exporter’ and Central shall be the ‘data importer’;

    H. Appendix 2 (“Security Measures”) to this DPA contains the information required in Annex II of the EU SCCs; and

    I. By entering into this DPA, we are deemed to have signed the EU SCCs as incorporated herein, including their Annexes.

b. Transfers from Switzerland. Where a Restricted Transfer is made from Switzerland, the EU SCCs apply to the transfer except that:

  1. in Clause 13, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner if the Restricted Transfer is governed by the Swiss Federal Act on Data Protection;

  2. eferences to “Member State” in the EU SCCs refer to Switzerland, and data subjects located in Switzerland may exercise and enforce their rights under the EU SCCs in Switzerland; and

  3. references to the “General Data Protection Regulation,” “Regulation 2016/679,” and “GDPR” in the EU SCCs refer to the Swiss Federal Act on Data Protection (as amended or replaced).

  4. The EU SCCs as modified by this section shall be known as the “Swiss SCCs”.

c. Transfers from the UK. Where a Restricted Transfer is made from the United Kingdom, the UK Transfer Addendum is incorporated into this DPA by reference and applies to the transfer.

d. General. Central may neither participate in, nor permit any Subprocessor to participate in, any onward Restricted Transfer unless the further Restricted Transfer is made in compliance with Data Protection Laws and in accordance with applicable Standard Contractual Clauses or an alternative legally compliant transfer mechanism.

10. Termination.

a. Termination. This DPA terminates automatically upon termination or expiration of the Terms. This DPA may not be terminated independently of the Terms except as expressly provided herein. Your sole remedy for Central’s breach of this DPA is as set forth in the Terms. For clarity, a material breach of this DPA by Central constitutes a material breach of the Terms for the purposes of the Terms’ termination provisions.

b. Return or Deletion of Customer Personal Data. Following termination of this DPA, Central shall make Customer Personal Data available for export for 90 days. After that period, Central may delete Customer Personal Data from its systems, unless further preservation is required or otherwise prohibited by law.

11. Liability and Indemnification.

a. Limitation of Liability. Each party’s liability arising from this DPA is subject to the limitations and exclusions set forth in Section 17 (Limitation of Liability) of the Terms.

b. Mutual Indemnification. Each party shall defend, indemnify, and hold harmless the other party, its officers, directors, employees, and affiliates, from and against any third-party claims, losses, liabilities, damages, penalties, fines, costs, and expenses, including reasonable attorneys’ fees, arising from the indemnifying party’s material breach of this DPA or violation of Data Protection Laws in connection with its obligations under this DPA, subject to the limitation of liability in the Terms. The Indemnification Procedure set forth in the Terms governs any Claim under this Section.

12. General.

a. Governing Law and Jurisdiction. This DPA shall be governed by and interpreted in accordance with the governing law and jurisdiction provisions in the Terms.

b. Conflict. In the event of a conflict or inconsistency between the Terms, this DPA, and the Standard Contractual Clauses, the terms of the following documents will prevail (in order of precedence) with regard to the Processing of Customer Personal Data: the Standard Contractual Clauses; then this DPA; and then the Terms.

13. Definitions.

Capitalized terms not defined in this section have the meanings assigned to them in the Terms or Data Protection Laws.

a. “Customer Personal Data” means Customer Data, as defined in the Terms, that constitutes Personal Information and that Central Processes on your behalf in connection with the Services. Customer Personal Data does not include Personal Information described in Section 1(e), Excluded Processing.

b. “Data Subject” means a natural person that is identified by or identifiable from Personal Information.

c. “Data Protection Laws” means all applicable laws, rules, regulations, and guidance related to privacy, data protection, or cybersecurity, including but not limited to: (i) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”); (ii) the Virginia Consumer Data Protection Act (Va. Code §§ 59.1-575 et seq.) (“VCDPA”); (iii) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”); (iv) the Swiss Federal Act on Data Protection; (v) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) (together with the EU GDPR, the “GDPR”); (vi) the UK Data Protection Act 2018; and (vii) the Privacy and Electronic Communications (EC Directive) Regulations 2003; and any other applicable state, federal, or international laws, rules, regulations, and guidance related to privacy and data protection in each case, as updated, amended or replaced from time to time.

d. “EU SCCs” means the Standard Contractual Clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time), as modified by the Section 9(a) (EEA Transfers) of this DPA.

e. “Personal Information” means information that constitutes “personal data,” “personal information,” “personally identifiable information,” or any analogous terms, as defined under applicable Data Protection Law.

f. “Process,” “Processed,” “Processing,” and related terms mean any operation performed on data, including the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of the data.

g. “Restricted Transfer” means any transfer of Customer Personal Data from one jurisdiction to another that is subject to restrictions under any applicable Data Protection Laws.

h. “Security Incident” means a breach of security leading to the accidental or unlawful unauthorized acquisition of, access to, disclosure of or loss of Customer Personal Data in Central’s possession or control that compromises the confidentiality, integrity, or availability of such Customer Personal Data.

i. “Security Measures” means the security measures attached to this DPA as Appendix 2.

j. “Services” means that services that Central is providing to you under the Terms or applicable order form(s).

k. “Standard Contractual Clauses” or “SCCs” mean the EU SCCs, Swiss SCCs, and EU SCCs as amended by the UK Transfer Addendum.

l. “Subprocessor” means any organization or third party engaged by Central to Process Customer Personal Data in the course of providing the Services.

m. “UK Transfer Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, published by the UK Information Commissioner’s Office on March 21, 2022, which is completed with the information as set forth herein.


Appendix 1

A. List of Parties

Data exporter(s)

  • Identity and contact details: The data exporter is the entity identified as “you” or “your” in the DPA. The address and relevant contact person for you are as set forth in the Terms or as otherwise provided at the time of contracting.

  • Activities relevant to the data transferred under these clauses: Performance of the Services pursuant to the Terms and any applicable order form(s).

  • Role: For transfers under Module 2 of the EU SCCs, You are a controller. For transfers under Module 3 of the EU SCCs, you are a processor.

Data importer(s)

  • Identity and contact details: The data importer is Central. The address for Central is as set forth in the applicable Order Form(s). Contact information: support@central.inc.

  • Activities relevant to the data transferred under these clauses: Performance of the Services pursuant to the Terms and any applicable order form(s).

  • Role: Processor.

B. Description of the Transfer and Processing


Categories of Data Subjects

Current and former employees, agents, contractors, payment beneficiaries, or other Service Providers of yours who are natural persons and who have been authorized by you to use the Services or designated by you to receive payments through the Services.

Dependents and beneficiaries of current and former employees of yours.

Any other individual whose Personal Information is received by Central through a third-party integration with the Services that you have enabled or from a user in connection with their use of the Services.

Categories of Personal Information

You determine and control the extent and types of Personal Information you submit to the Services or that is collected by Central or its Sub-Processors at your direction. Depending on the nature of the Services used, Personal Information may include: contact information, employment and compensation data, government identifiers, financial information, tax information, payment instructions and transaction information, demographic information, benefits enrollment data, and dependent/beneficiary information, log and device data, and other data associated with use of the Services.

Sensitive Data transferred

Depending on the use case: demographic data revealing racial or ethnic origin, government-issued identification numbers, financial account information, and where applicable to the Services, health-related information (e.g., health insurance benefits and claims information).

Frequency of the Processing

Continuous basis depending on use of the Services by you

Nature and purpose of the Processing

Processing necessary to provide the Services described in the Terms or applicable order form(s), including to: set up, operate, maintain, and support the Services; help ensure security and integrity; prevent and investigate security or fraud issues; verify or maintain the quality and safety of Personal Information; develop and improve service features and functionalities; and comply with any legal and regulatory obligations.

Duration of the Processing

Subject to Section 10 (Termination), for the Term of the Terms, plus any applicable legal retention period.


Appendix 2
Security Measures

Central implements the following technical and organizational measures to protect Personal Information:

  1. Organizational Measures

    (a) Information Security Program. Central maintains a written information security program designed to protect the confidentiality, integrity, and availability of Personal Information.

    (b) Personnel. Central ensures that personnel authorized to Process Personal Information are subject to appropriate confidentiality obligations. Central provides security awareness training to personnel with access to Personal Information.

    (c) Incident Response. Central maintains an incident response plan designed to enable timely identification, investigation, containment, and remediation of Incidents.

    (d) Vendor Management. Central maintains a process for evaluating the security practices of Subprocessors prior to engagement and on an ongoing basis as commercially reasonable.


  2. Technical Measures

    (a) Access Controls

    • Multi-factor authentication (MFA) required for all user accounts

    • Role-based access control (RBAC) limiting access based on principle of least privilege

    • Unique user credentials for all personnel (no shared accounts)

    • Automatic session timeout consistent with Mercury’s security policies

    • Regular access reviews to remove unnecessary access

    (b) Encryption

    • In Transit. Central encrypts Personal Information in transit over public networks using industry-standard transport encryption protocols.

    • At Rest. Central encrypts Personal Information at rest using industry-standard encryption algorithms.

    (c) Network and Infrastructure Security

    • Network controls, including firewalls and network segmentation, designed to protect from unauthorized access.

    • Monitoring. Central maintains logging and monitoring capabilities designed to detect unauthorized access.

    • Vulnerability Management. Central maintains a vulnerability management process designed to identify, evaluate, and remediate security vulnerabilities.

    • Penetration Testing. Central engages qualified third parties to conduct penetration testing of systems used to Process Personal Information on a periodic basis.

    (d) Application Security

    • Secure Development. Central maintains secure software development practices designed to identify and remediate security vulnerabilities.

    (e) Data Protection

    • Segregation. Central implements logical controls designed to segregate your Personal Information from the data of other customers.

    • Backup and Recovery. Central maintains backup procedures designed to support the availability and recoverability of Personal Information. Backups are protected by security controls consistent with those applied to production data.

    • Secure Disposal. Central implements procedures for the secure deletion or destruction of Personal Information and media containing Personal Information when no longer required, in accordance with the DPA.

    (f) Physical Security.

    To the extent Central controls the physical facilities in which Personal Information is Processed, Central implements physical access controls designed to restrict access to authorized personnel. Where Central uses third-party data center providers, Central relies on the physical security controls maintained by such providers.

    (g) Business Continuity.

    Central maintains business continuity and disaster recovery plans designed to support the availability and resilience of systems used to Process Personal Information.

    Central may update these measures from time to time, provided that any such update does not materially diminish the overall level of protection afforded to Personal Information.

    1. s

Appendix 3
Additional Provisions for Certain Jurisdictions

The provisions below may apply to the extent you have Data Subjects located in the identified jurisdictions. You shall inform Central when Data Subjects are located in any jurisdiction listed below.

  1. Canada

    1. Central shall provide a level of protection for Personal Information originating in Canada that is comparable to the protection such information would receive under PIPEDA.

  2. Quebec, Canada

    1. Upon request, Central shall provide you with the following information to enable you to conduct a privacy impact assessment: (i) the jurisdictions in which Personal Information is Processed; (ii) a description of applicable security measures; (iii) the identity and location of Subprocessors; and (iv) information regarding the legal framework in the destination jurisdiction.

    2. Personal Information originating in Quebec shall be deleted upon expiry or termination of the Terms, as required by the Quebec Privacy Law, subject to any retention required by applicable law or by a Subprocessor’s own retention obligations, as described in Section 10(b).

    3. Central shall notify your designated person in charge of the protection of Personal Information without delay of any violation or attempted violation of any confidentiality obligation concerning Personal Information originating in Quebec.

  3. Brazil

    1. To the extent legally required for transfers of Personal Information from Brazil, the Parties agree to the Standard Contractual Clauses approved by Resolution CD/ANPD No. 19/2024 (“Brazilian SCCs), which are incorporated into this DPA by reference and completed as follows:

      1. The Parties shall be Exporter (You) and Importer (Central), with details per Appendix 1.

      2. For Controller-to-Processor transfers, the Parties select Option A. For Processor-to-Sub-Processor transfers, the Parties select Option B.

      3. Schedule III of the Brazilian SCCs is completed with the information in Appendix 2 (Security Measures) of this DPA.

  4. Other Jurisdictions

    1. Where Personal Information originates from a jurisdiction not otherwise addressed in this Appendix 3 (including but not limited to India, Australia, Singapore, Japan, and other countries with data protection frameworks), Central shall process such Personal Information consistent with the requirements applicable to processors, data intermediaries, or equivalent roles under the applicable Data Protection Laws of such jurisdiction, as applicable.  Where a specific data transfer mechanism or cross-border restriction is required by applicable law, the Parties shall in good faith execute such additional documentation as may be reasonably required.

Contact

support@central.inc

Click to copy

  • free founders

Contact

support@central.inc

Click to copy

free founders

Contact

support@central.inc

Click to copy

  • free founders