Trust center
Privacy Notice
Last updated: 30 September 2026
Who this notice covers
Central Matrix provides workspace software to organizations and individual users. The service operator is the Central Matrix entity identified in your Order Form. For client-controlled program, employee, donor, and beneficiary records, the client is the data controller and Central Matrix acts as its processor.
Our data commitment
Your data stays yours
Central Matrix does not sell, rent, trade, advertise with, or make client data public. We process it only to provide and secure the service, carry out documented client instructions, support authorized users, and comply with applicable law.
Access is limited
Tenant and role controls separate workspaces and limit records to authorized users.
Disclosure is controlled
Data is disclosed only as authorized, as needed by approved service providers, or when legally required.
Protection is continuous
Secure sessions, private storage, backups, monitoring, audit records, and incident procedures protect the service.
No online service can promise zero risk. Our commitment is to minimize risk, restrict access, respond responsibly, and communicate material incidents according to the client agreement and applicable law.
Data we process
We process account and contact information, workspace content you submit, authentication and security records, device and request metadata, support communications, and configuration for integrations you enable. We do not sell personal information.
Why we process it
- Provide, secure, support, and improve the service.
- Authenticate users, enforce permissions, prevent abuse, and investigate incidents.
- Deliver requested notifications and connect services selected by workspace administrators.
- Meet contractual and legal obligations.
Sensitive and beneficiary data
Clients must collect only data they are legally entitled to process, configure appropriate access, and avoid unnecessary sensitive information. AI features and external integrations remain disabled unless separately configured by an administrator. Do not submit emergency, life-critical, or classified information.
When data may be disclosed
Client data is not disclosed to other clients or the public. Access is limited to authorized workspace users; Central Matrix personnel who need it to operate, secure, or support the service; approved subprocessors and integration providers needed for requested functionality; or recipients required by law. Hosting location, subprocessors, cross-border safeguards, and client-specific instructions are documented in the applicable Order Form and Data Processing Addendum.
Retention and your rights
Workspace administrators control most records and should receive requests for access, correction, export, restriction, or deletion. Cancellation ends paid and write access immediately, while authorized workspace administrators retain a 30-day export window. Cancellation does not automatically delete stored data. Account, security, backup, and legal records may be retained for the periods documented in the client agreement and retention schedule. For unresolved privacy requests, email support@centralmatrix.net.
Security is a priority
We use tenant and role-based access controls, encryption in transit, secure server-managed sessions, private object storage, audit and security records, verified backups, monitoring, and documented incident procedures. We continually review these safeguards and limit operational access to legitimate service, support, and security purposes. Material notice changes will be communicated through the service or the registered account contact.