CenterSync
Sign InGet Started Free

CenterSync Data Processing Addendum

Effective Date: August 1, 2026

Last Updated: August 1, 2026

This Data Processing Addendum (“DPA”) forms part of the CenterSync SaaS Terms of Service, including any Order governed by those terms, between CenterSync LLC, a Massachusetts limited liability company (“CenterSync”), and the Customer identified in the applicable Order or account registration process (“Customer”).

This DPA applies automatically when CenterSync processes Personal Data on Customer’s behalf in connection with the Service. By accepting the Terms of Service, submitting an Order, or using the Service after being presented with the Terms of Service, Customer also accepts this DPA.

Capitalized terms not defined in this DPA have the meanings given in the Terms of Service.

1. Scope and Order of Precedence

This DPA governs CenterSync’s Processing of Personal Data contained in Customer Data.

The parties agree that, for Personal Data included in Customer Data:

  • Customer acts as the Controller, Business, or other entity that determines the purposes and means of Processing; and
  • CenterSync acts as the Processor, Service Provider, Contractor, or other entity Processing Personal Data on Customer’s behalf.

If there is a conflict between this DPA and the Terms of Service concerning the Processing of Personal Data, this DPA controls.

If the parties execute a Business Associate Agreement concerning protected health information subject to HIPAA, that Business Associate Agreement controls with respect to such protected health information.

This DPA does not apply to Personal Data that CenterSync Processes independently for its own legitimate business purposes, such as account administration, billing, fraud prevention, security, legal compliance, and management of the contractual relationship. CenterSync’s Privacy Policy governs that Processing.

2. Definitions

2.1 Applicable Data Protection Law

“Applicable Data Protection Law” means any United States federal, state, or local law applicable to CenterSync’s Processing of Personal Data on Customer’s behalf, including applicable privacy, data-security, breach-notification, consumer-protection, education-record, health-information, employment-record, and children’s-privacy laws.

Applicable Data Protection Law includes, to the extent applicable, laws that use terms such as “controller,” “processor,” “business,” “service provider,” “contractor,” “consumer,” “personal data,” “personal information,” “sale,” “sharing,” or “targeted advertising.”

2.2 Consumer

“Consumer” means an individual to whom Personal Data relates, including a child, parent, guardian, employee, contractor, applicant, volunteer, teacher, caregiver, facility administrator, or other person whose Personal Data is contained in Customer Data.

2.3 Controller

“Controller” means the person or entity that determines the purposes and means of Processing Personal Data, including a “business” as defined by applicable state privacy law.

2.4 Personal Data

“Personal Data” means information contained in Customer Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual or household.

Personal Data includes “personal information,” “personal data,” “personally identifiable information,” and similar terms defined by Applicable Data Protection Law.

2.5 Process or Processing

“Process,” “Processing,” and “Processed” mean any operation performed on Personal Data, including collection, recording, organization, storage, access, use, transmission, disclosure, retrieval, consultation, modification, analysis, restriction, deletion, or destruction.

2.6 Processor

“Processor” means an entity that Processes Personal Data on behalf of a Controller, including a “service provider” or “contractor” as defined by applicable state privacy law.

2.7 Security Incident

“Security Incident” means a confirmed unauthorized access to, acquisition of, use of, disclosure of, alteration of, or destruction of Personal Data in systems under CenterSync’s control that materially compromises the confidentiality, integrity, or availability of that Personal Data.

A Security Incident does not include unsuccessful attempts or activities that do not result in unauthorized access to Personal Data, including blocked attacks, unsuccessful login attempts, network scans, pings, or denial-of-service attempts.

2.8 Subprocessor

“Subprocessor” means a third party engaged by CenterSync to Process Personal Data on Customer’s behalf in connection with the Service.

3. Processing Instructions

Customer instructs CenterSync to Process Personal Data only as necessary to:

  • provide, host, operate, maintain, secure, and support the Service;
  • perform obligations under the Terms of Service and applicable Orders;
  • provide features selected, configured, or requested by Customer;
  • facilitate Customer-authorized integrations;
  • prevent, investigate, and address fraud, abuse, security, support, and technical issues;
  • comply with Customer’s documented instructions; and
  • comply with applicable law or valid legal process.

The Terms of Service, Orders, Customer’s use and configuration of the Service, support requests, and other written instructions agreed by the parties constitute Customer’s documented instructions.

CenterSync will notify Customer if CenterSync reasonably believes a Customer instruction violates Applicable Data Protection Law, unless applicable law prohibits such notice. CenterSync may suspend the affected Processing while the parties address the instruction.

Customer will not instruct CenterSync to Process Personal Data in a manner that violates Applicable Data Protection Law.

4. Customer Responsibilities

Customer is responsible for:

  • determining whether and how Personal Data may lawfully be collected, used, retained, disclosed, and Processed;
  • providing all legally required privacy notices;
  • obtaining all legally required consents, authorizations, permissions, or other lawful bases;
  • ensuring that Personal Data submitted to the Service is relevant, accurate, and limited to what is reasonably necessary;
  • configuring access rights, roles, permissions, and retention settings;
  • responding to Consumers and governmental authorities concerning Customer Data;
  • determining whether federal or state health, education, employment, childcare, background-check, or other specialized confidentiality laws apply;
  • ensuring that Authorized Users comply with Customer’s policies and applicable law; and
  • not submitting Personal Data prohibited by the Terms of Service.

Customer represents and warrants that it has all rights and authority necessary to provide Personal Data to CenterSync and instruct CenterSync to Process it.

Customer is responsible for determining whether Customer is permitted to use the Service to Process:

  • children’s health, immunization, medication, allergy, accommodation, and incident information;
  • staff health and medical-clearance information;
  • background-check information;
  • employment and disciplinary records;
  • educational records; and
  • other sensitive information.

Customer must not submit protected health information subject to HIPAA unless CenterSync has expressly agreed in writing to support that Processing and the parties have executed a Business Associate Agreement.

5. CenterSync Processing Obligations

CenterSync will:

  • Process Personal Data only on Customer’s documented instructions, except where otherwise required by law;
  • ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations;
  • implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the Personal Data and risks of the Processing;
  • provide reasonable assistance to Customer in responding to Consumer requests, taking into account the nature of the Processing and information available to CenterSync;
  • provide reasonable assistance with security, breach-notification, and regulatory obligations applicable to CenterSync’s Processing;
  • notify Customer if CenterSync can no longer meet its obligations under this DPA or Applicable Data Protection Law;
  • permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized Processing; and
  • delete or return Personal Data as described in Section 11.

CenterSync will not:

  • sell Personal Data;
  • share Personal Data for cross-context behavioral advertising;
  • use Personal Data for targeted advertising;
  • retain, use, or disclose Personal Data outside the direct business relationship between Customer and CenterSync, except as permitted by Applicable Data Protection Law;
  • combine Personal Data with personal information received from another person or collected from CenterSync’s own interactions with a Consumer, except as permitted by Applicable Data Protection Law and reasonably necessary to provide the Service; or
  • attempt to re-identify information that has been de-identified, except to test whether CenterSync’s de-identification processes are effective.

CenterSync may create and use aggregated or de-identified information as permitted by the Terms of Service, provided that the information does not identify Customer or an individual and is not reasonably capable of being linked to them.

6. U.S. State Privacy-Law Terms

To the extent an applicable U.S. state privacy law governs the Processing, CenterSync agrees that it acts as Customer’s Processor, Service Provider, or Contractor.

The parties acknowledge and agree that:

  • Customer discloses Personal Data to CenterSync only for the limited and specified purposes described in this DPA, the Terms of Service, and applicable Orders;
  • CenterSync will comply with applicable obligations imposed on Processors, Service Providers, or Contractors;
  • Customer may take reasonable and appropriate steps to help ensure that CenterSync uses Personal Data consistently with Customer’s obligations under Applicable Data Protection Law;
  • CenterSync will notify Customer if CenterSync determines that it can no longer meet an applicable legal obligation;
  • after receiving such notice, Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data;
  • CenterSync will provide the same level of privacy protection required of Customer to the extent required by Applicable Data Protection Law;
  • CenterSync will not receive Personal Data as consideration for goods or services; and
  • CenterSync’s certification in this DPA is made subject to the qualifications and limitations expressly stated in the Terms of Service.

CenterSync certifies that it understands and will comply with the restrictions in this Section.

7. Sensitive Personal Data

Personal Data Processed through the Service may include sensitive information relating to children, families, and childcare personnel.

CenterSync will Process sensitive Personal Data only:

  • to provide the Service;
  • on Customer’s documented instructions;
  • to maintain security and integrity;
  • to comply with law; or
  • as otherwise expressly permitted by the Terms of Service and Applicable Data Protection Law.

CenterSync will not use sensitive Personal Data to infer characteristics about a Consumer for advertising, profiling unrelated to the Service, or other independent commercial purposes.

Customer will apply appropriate access restrictions and will limit submission of sensitive Personal Data to what is reasonably necessary for lawful childcare administration, health and safety, employment, licensing, training, inspection, or regulatory purposes.

8. Subprocessors

Customer generally authorizes CenterSync to engage Subprocessors to provide the Service.

CenterSync will maintain a current list of Subprocessors at:

https://centersync.ai/subprocessors

The list should identify, as applicable:

  • the Subprocessor’s name;
  • the services provided;
  • the categories of Personal Data Processed; and
  • the Processing location.

CenterSync will provide notice of a material new Subprocessor by updating the Subprocessor list, sending email notice, providing in-application notice, or another reasonable method.

Customer may object to a new Subprocessor on reasonable data-protection grounds within ten days after notice.

The parties will work in good faith to address the objection.

If the parties cannot resolve the objection and CenterSync cannot reasonably provide the affected Service without the Subprocessor, Customer may terminate the affected portion of the Service by written notice and receive a prorated refund of prepaid, unused fees for the terminated portion.

CenterSync will enter into a written agreement with each Subprocessor that imposes confidentiality, security, and data-protection obligations appropriate to the Subprocessor’s services and no less protective in material respects than CenterSync’s applicable obligations under this DPA.

CenterSync remains responsible for a Subprocessor’s performance of CenterSync’s obligations under this DPA to the extent required by Applicable Data Protection Law.

9. Security Measures

CenterSync will implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, acquisition, use, disclosure, alteration, loss, or destruction.

CenterSync’s safeguards will include measures appropriate to the nature of the Personal Data, the scope and context of Processing, the cost of implementation, and the likelihood and severity of potential harm.

The security measures described in Schedule 2 form part of this DPA.

CenterSync may update its safeguards from time to time, provided that the updates do not materially reduce the overall level of protection during a paid Subscription Term.

Customer acknowledges that no information system is completely secure and that CenterSync does not guarantee that a Security Incident will never occur.

10. Security Incidents

CenterSync will notify Customer without undue delay after confirming a Security Incident.

CenterSync’s notice will include information reasonably available at the time concerning:

  • the nature of the Security Incident;
  • the date or estimated date of occurrence and discovery;
  • the categories of affected Personal Data;
  • the categories or estimated number of affected Consumers, where known;
  • known or reasonably anticipated consequences;
  • containment, mitigation, and remediation measures; and
  • a contact for follow-up information.

CenterSync may provide information in phases as additional facts become available.

CenterSync will take reasonable steps to:

  • contain and investigate the Security Incident;
  • mitigate reasonably foreseeable harm;
  • remediate identified vulnerabilities within CenterSync’s control; and
  • preserve relevant evidence.

CenterSync will reasonably cooperate with Customer concerning legally required notifications, regulatory communications, and Consumer communications.

Unless Applicable Data Protection Law requires otherwise, Customer is responsible for determining whether notification is legally required and for making notifications to Consumers, regulators, licensors, or other authorities.

CenterSync will not notify Consumers or regulators about a Security Incident involving Customer Data without Customer’s authorization unless required by law.

Notification or cooperation under this Section is not an admission of fault or liability.

The parties’ liability concerning a Security Incident remains subject to the Terms of Service, including its limitation-of-liability provisions.

11. Return, Export, Retention, and Deletion

During the Subscription Term, Customer may export Customer Data using available Service tools.

After termination or expiration, CenterSync will make Customer Data available for export for 30 days, unless:

  • the applicable Order states otherwise;
  • applicable law requires a different period; or
  • security or legal restrictions require earlier suspension or deletion.

Supported export formats are CSV, PDF, and ZIP archives.

After the export period, CenterSync will delete Personal Data from active production systems within:

30 days

CenterSync will delete or render inaccessible Personal Data in routine backups within:

90 days

Deletion is subject to:

  • legal-retention requirements;
  • valid preservation obligations;
  • technical limitations of routine backup systems;
  • security and audit requirements; and
  • the continued retention of data that has been aggregated or de-identified.

CenterSync may retain limited account, billing, transaction, security, audit, support, and legal records where reasonably necessary to comply with law, maintain security, resolve disputes, enforce agreements, or establish, exercise, or defend legal claims.

Any retained Personal Data remains subject to applicable confidentiality and security obligations.

Customer is responsible for exporting Customer Data before the export period ends.

12. Consumer Requests

Customer is responsible for receiving, verifying, and responding to requests from Consumers concerning Personal Data contained in Customer Data.

If CenterSync receives a request directly from a Consumer concerning Customer Data, CenterSync will:

  • notify Customer where reasonably practicable;
  • direct the Consumer to Customer; and
  • not independently respond to the substance of the request unless Customer instructs CenterSync to do so or Applicable Data Protection Law requires a direct response.

Taking into account the nature of the Processing and information available to CenterSync, CenterSync will provide reasonable assistance to Customer in responding to verified requests concerning:

  • access;
  • correction;
  • deletion;
  • portability;
  • restriction;
  • objection;
  • withdrawal of consent; and
  • appeal rights recognized under Applicable Data Protection Law.

CenterSync may charge reasonable fees for assistance that requires substantial custom engineering, non-standard data retrieval, or other work beyond functionality ordinarily included in the Service, provided the parties agree to those fees in advance.

13. Regulatory Inquiries and Assessments

CenterSync will provide reasonable assistance to Customer concerning:

  • privacy or security inquiries from regulators;
  • investigations relating to CenterSync’s Processing;
  • data-protection assessments or similar risk assessments required by Applicable Data Protection Law; and
  • consultations concerning high-risk Processing performed through the Service.

CenterSync’s assistance is limited to information reasonably available to CenterSync and relevant to CenterSync’s Processing.

Customer remains responsible for its own legal analysis, compliance determinations, notices, assessments, and filings.

14. Audits and Compliance Information

Upon reasonable written request, CenterSync will provide information reasonably necessary to demonstrate compliance with this DPA.

CenterSync may satisfy this obligation by providing:

  • security summaries;
  • policy excerpts;
  • completed security questionnaires;
  • independent audit reports or certifications, if available;
  • penetration-test summaries, if available and appropriate;
  • Subprocessor information; or
  • other relevant documentation.

If the information provided is not reasonably sufficient to demonstrate compliance, Customer may request an audit.

Any audit must:

  • be limited to CenterSync’s Processing of Customer Data;
  • occur no more than once in any 12-month period, unless required by law or following a confirmed Security Incident materially affecting Customer Data;
  • be conducted during normal business hours;
  • provide at least 30 days’ advance written notice;
  • avoid unreasonable disruption to CenterSync’s operations;
  • be conducted by an independent auditor that is not a competitor of CenterSync;
  • be subject to appropriate confidentiality obligations; and
  • comply with CenterSync’s reasonable security and access requirements.

The audit may not provide access to:

  • another customer’s information;
  • systems that would create a security risk;
  • source code;
  • privileged material;
  • penetration-test details that could facilitate misuse; or
  • information CenterSync is legally or contractually prohibited from disclosing.

Customer will bear audit costs unless the audit identifies a material breach of this DPA by CenterSync, in which case CenterSync will reimburse Customer’s reasonable audit costs directly attributable to confirming that breach.

15. Government and Legal Requests

If CenterSync receives a subpoena, court order, warrant, or other legally binding request for Customer Data, CenterSync will, where legally permitted:

  • notify Customer promptly;
  • provide Customer with reasonably available information concerning the request;
  • direct the requesting authority to Customer where appropriate; and
  • reasonably cooperate, at Customer’s expense, with Customer’s efforts to seek confidential treatment, narrow the request, or obtain a protective order.

CenterSync may disclose Customer Data where legally required.

CenterSync will disclose only the information reasonably necessary to comply with the valid legal request.

16. Processing Location and International Transfers

CenterSync will host and Process Customer Data in the United States.

Customer will not use or configure the Service to transfer Customer Data outside the United States unless CenterSync expressly agrees in writing.

This DPA does not authorize international transfers of Personal Data.

If the parties later agree to international Processing or transfers, they must enter into any additional data-transfer terms required by applicable law before that Processing begins.

17. Artificial Intelligence and Automated Processing

To the extent CenterSync uses automated or artificial-intelligence-supported features to Process Customer Data, CenterSync will use those features only to:

  • provide functions requested or enabled by Customer;
  • organize, summarize, classify, or retrieve Customer Data;
  • generate reminders, tasks, reports, or recommendations;
  • maintain security and prevent misuse; or
  • improve the Service using aggregated or de-identified information.

CenterSync will not use identifiable Customer Data to train a general-purpose artificial intelligence model unless:

  • Customer expressly authorizes that use in writing;
  • the use is clearly described to Customer; and
  • the Processing complies with Applicable Data Protection Law.

Customer acknowledges that automated outputs may be incomplete or inaccurate and remains responsible for reviewing outputs before using them for licensing, employment, health, safety, disciplinary, regulatory, or other consequential decisions.

18. Term and Termination

This DPA begins when Customer accepts the Terms of Service or otherwise enters into an Order and continues for as long as CenterSync Processes Personal Data on Customer’s behalf.

Termination of the Terms of Service or all applicable Orders terminates this DPA, except that provisions concerning confidentiality, security, deletion, retained information, audits relating to the active Processing period, liability, and legal compliance survive for as long as CenterSync retains Personal Data.

19. Liability

Each party’s liability arising from or relating to this DPA is subject to the exclusions, limitations, disclaimers, and liability cap in the Terms of Service.

Nothing in this DPA increases either party’s liability beyond the liability agreed in the Terms of Service unless Applicable Data Protection Law expressly prohibits that limitation.

20. Changes to This DPA

CenterSync may update this DPA from time to time.

For a material change, CenterSync will provide reasonable advance notice through email, the Service, or another reasonable method.

A change required by law, regulation, court order, or governmental authority may take effect on shorter notice where necessary.

If a material change materially and adversely reduces Customer’s data-protection rights during a paid Subscription Term, Customer may object within 30 days after notice.

The parties will work in good faith to address the objection. If the parties cannot resolve it, Customer may terminate the affected Service and receive a prorated refund of prepaid, unused fees for the terminated portion.

21. Contact Information

Questions or notices concerning this DPA should be directed to:

CenterSync LLC

Address: 145 Great Rd Ste 6 Farm Hill Plaza #1026, Acton, MA 01720

Privacy contact: privacy@centersync.ai

Security contact: security@centersync.ai

Legal notices: legal@centersync.ai

Website: https://centersync.ai

SCHEDULE 1

Details Of Processing

1. Subject Matter

CenterSync’s provision, hosting, operation, maintenance, security, support, and improvement of childcare management software for Customer.

2. Duration

The applicable Subscription Term, any post-termination export period, and any additional retention period permitted by this DPA, the Terms of Service, or applicable law.

3. Nature of Processing

Processing may include:

  • collection;
  • recording;
  • organization;
  • structuring;
  • storage;
  • retrieval;
  • consultation;
  • access;
  • transmission;
  • display;
  • analysis;
  • reporting;
  • generation of reminders and recommendations;
  • restriction;
  • export;
  • deletion; and
  • destruction.

4. Purposes of Processing

The purposes include:

  • facility administration;
  • enrollment and attendance management;
  • staff administration;
  • licensing and regulatory recordkeeping;
  • inspections and corrective-action tracking;
  • health and safety recordkeeping;
  • training and qualification tracking;
  • incident documentation;
  • document storage and retrieval;
  • reporting and analytics;
  • communications and reminders;
  • account administration;
  • customer support;
  • security and fraud prevention; and
  • other purposes configured or directed by Customer through the Service.

5. Categories of Consumers

Consumers may include:

  • enrolled or prospective children;
  • parents and guardians;
  • emergency contacts;
  • authorized pickup persons;
  • employees;
  • applicants;
  • contractors;
  • volunteers;
  • teachers;
  • caregivers;
  • center directors;
  • administrators;
  • facility owners;
  • regulatory or licensing contacts; and
  • other persons whose information Customer lawfully submits.

6. Categories of Personal Data

Personal Data may include:

  • names;
  • dates of birth;
  • contact information;
  • addresses;
  • photographs, where enabled;
  • enrollment information;
  • attendance information;
  • classroom or program assignments;
  • parent, guardian, and emergency-contact relationships;
  • authorized-pickup information;
  • employment and role information;
  • training and certification records;
  • professional credentials;
  • facility and licensing identifiers;
  • inspection and corrective-action records;
  • background-check status and related records;
  • account identifiers;
  • authentication and access information;
  • device, log, audit, and usage information;
  • communications;
  • uploaded forms and documents; and
  • other information Customer chooses to submit consistent with the Terms of Service.

7. Sensitive Personal Data

Sensitive Personal Data may include:

  • children’s health information;
  • immunization records;
  • allergy information;
  • medication information;
  • accommodation information;
  • dietary information;
  • injury, illness, accident, or incident information;
  • staff health information;
  • medical-clearance information;
  • background-check information;
  • disciplinary information;
  • identity-verification information; and
  • other information treated as sensitive under Applicable Data Protection Law.

Customer must not submit the prohibited categories identified in the Terms of Service unless CenterSync expressly authorizes the Processing in writing.

8. Frequency

Processing occurs on an ongoing basis as Customer and Authorized Users access and use the Service.

9. Processing Location

United States only.

10. Retention

Personal Data is retained during the Subscription Term, for the 30-day post-termination export period, and for the deletion periods stated in Section 11.

SCHEDULE 2

Security Measures

CenterSync will maintain reasonable safeguards appropriate to its size, resources, Processing activities, and the nature of the Personal Data.

The following measures apply to the extent appropriate to the Service and CenterSync’s operations.

1. Security Governance

CenterSync will maintain written security policies and assign responsibility for information-security oversight.

2. Access Controls

CenterSync will use access controls designed to limit Personal Data access to authorized personnel and systems with a legitimate business need.

CenterSync will review and revoke access when it is no longer required.

3. Authentication

CenterSync will use reasonable authentication safeguards for administrative and production-system access.

4. Encryption

CenterSync will use encryption for Personal Data transmitted over public networks.

CenterSync will use encryption at rest for Customer Data stored in production systems where commercially reasonable and appropriate.

5. Logging and Monitoring

CenterSync will maintain reasonable logging and monitoring designed to detect unauthorized access, suspicious activity, system failures, and security events.

6. Vulnerability and Patch Management

CenterSync will maintain reasonable processes to identify, assess, prioritize, and remediate material vulnerabilities in systems under its control.

7. Secure Development and Change Management

CenterSync will use reasonable development, testing, review, and deployment controls for material changes to the Service.

8. Malware Protection

CenterSync will use reasonable measures designed to prevent, detect, and respond to malware and malicious code.

9. Backup and Recovery

CenterSync will maintain reasonable backup and recovery procedures appropriate to the Service.

Backups will be protected against unauthorized access.

10. Incident Response

CenterSync will maintain procedures for identifying, escalating, investigating, containing, mitigating, and remediating Security Incidents.

11. Personnel Security

Personnel with access to Personal Data will be subject to confidentiality obligations and receive security and privacy guidance appropriate to their roles.

12. Subprocessor Oversight

CenterSync will conduct reasonable diligence before authorizing a Subprocessor to Process Personal Data and will impose written data-protection obligations.

13. Physical Security

CenterSync will use cloud and infrastructure providers with physical-security controls appropriate to the services provided.

14. Data Minimization and Segregation

CenterSync will use reasonable measures designed to limit Processing to information necessary for the Service and to prevent unauthorized access between customer environments.

15. Secure Disposal

CenterSync will use reasonable procedures to delete or render Personal Data inaccessible when retention is no longer required, subject to backup cycles, legal obligations, and the Terms of Service.

16. Business Continuity

CenterSync will maintain reasonable procedures designed to support continuity and recovery of material Service operations following a disruption.

CenterSync

© 2026 CenterSync. All rights reserved.

TermsPrivacyDPASubprocessorsSign InSign Up