Client assurance

Data Processing Addendum Overview

Last updated: 30 September 2026

Roles and instructions

The client is controller of client data and Central Matrix is processor, except for account, security, and business-contact information processed for its own legitimate operational purposes. Processing is limited to documented client instructions, the agreement, and applicable law.

Processing details

Processing includes hosting, organizing, securing, backing up, retrieving, exporting, and deleting workspace data for the contract term and agreed retention period. Data subjects may include staff, volunteers, partners, donors, beneficiaries, applicants, vendors, and form respondents.

Safeguards

  • Tenant-scoped authorization and individual user accounts.
  • Encryption in transit and encrypted production secrets and storage.
  • Session controls, MFA, audit and security events, file validation, backups, monitoring, and incident procedures.
  • Confidentiality obligations and least-privilege operational access.

Subprocessors and transfers

The signed DPA and Order Form must list hosting, email, AI, monitoring, and integration subprocessors actually enabled for the client, their processing locations, and the transfer mechanism used where required. No optional provider should be enabled before this list is approved.

Assistance and deletion

Central Matrix will reasonably assist with data-subject requests, security inquiries, impact assessments, and breach obligations. At termination, data will be returned or deleted according to the signed agreement, subject to backup cycles and legal retention duties.

Execution required

This page is an operational overview, not a signed DPA. Clients processing personal or beneficiary data must execute a DPA containing the legal entity names, locations, governing law, breach notice period, approved subprocessors, retention schedule, and any required standard contractual clauses. Direct privacy and DPA requests to support@centralmatrix.net.