Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Agreement between MiseCentral LLC, a Delaware limited liability company ("MiseCentral," "Processor," "we," "us," or "our"), and the Customer identified in the applicable Order Form ("Customer," "Controller," or "you"). This DPA applies where MiseCentral processes Personal Data on behalf of Customer in connection with the Services. Capitalized terms not defined herein have the meanings set forth in the Agreement or the MiseCentral Legal Drafting Canon.
1. Roles and Scope
1.1. Roles. For Personal Data described in Annex I, Customer is the Controller (or Business, as applicable under U.S. state privacy laws) and MiseCentral is the Processor (or Service Provider, as applicable). Where Customer acts as a processor for its own customers, Customer is responsible for establishing lawful instructions and flow-down obligations before submitting Personal Data to the Services.
1.2. Scope. This DPA governs MiseCentral's processing of Personal Data solely to provide, maintain, secure, and support the Services, to perform Professional Services ordered under an Agreement, and as otherwise instructed by Customer in writing or through documented configuration of the Services, subject to applicable law.
1.3. Customer Data. Customer retains all right, title, and interest in Customer Data, including Personal Data contained therein. MiseCentral processes Personal Data only as a Processor on Customer's documented instructions except where required by applicable law, in which case MiseCentral will inform Customer of that legal requirement before processing unless prohibited by law.
1.4. No Sale or Sharing. MiseCentral does not sell or share Personal Data as those terms are defined under applicable U.S. state privacy laws. MiseCentral does not retain, use, or disclose Personal Data for any purpose other than performing the Services specified in the Agreement, as permitted under this DPA, or as required by law.
2. Customer Instructions
2.1. Documented Instructions. Customer instructs MiseCentral to process Personal Data to: (a) host, store, organize, transmit, display, and otherwise handle Customer Data within the Services; (b) provide Operational Intelligence, Work Intelligence, Adaptive Scheduling, Adaptive Work Execution, Operational State, notifications, and related platform capabilities; (c) generate Operational Recommendations, which are advisory outputs that do not replace Customer's operational or compliance decisions; (d) maintain Operational Evidence, audit logs, and security records; (e) provide Support Mode assistance when authorized under the Support Mode Policy; (f) enable Connected Services, Connected Devices, API Clients, and Service Accounts configured by Customer; and (g) perform other processing described in Annex I and the Documentation.
2.2. Configuration as Instruction. Customer's use of administrative settings, role assignments, integration controls, retention settings within permitted bounds, and in-product configuration constitutes documented instructions to the extent such settings are available in the Services and permitted by the Agreement.
2.3. Additional Instructions. Customer may submit additional written instructions regarding processing that are consistent with the Agreement and the nature of the Services. If MiseCentral reasonably believes an instruction infringes applicable Data Protection Laws, MiseCentral will promptly notify Customer. MiseCentral may suspend processing of the affected Personal Data until the parties agree on a compliant approach or Customer modifies the instruction.
2.4. Lawful Basis. Customer is solely responsible for determining and maintaining a lawful basis for processing Personal Data and for providing required notices to data subjects, including Authorized Users and other individuals whose Personal Data Customer submits to the Services.
3. Confidentiality
3.1. MiseCentral ensures that personnel authorized to process Personal Data are bound by confidentiality obligations consistent with this DPA and the Agreement, whether by contract or statutory duty.
3.2. MiseCentral limits access to Personal Data to personnel and Subprocessors with a need to know for purposes of performing the Services, maintaining security, or complying with law.
4. Security
4.1. MiseCentral implements and maintains appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, taking into account the nature of processing and the information available to MiseCentral.
4.2. Security measures include, as appropriate to the Services: access controls and role-based permissions; encryption in transit; encryption at rest for stored Customer Data; logging and monitoring; vulnerability management; secure development practices; incident response procedures; business continuity and disaster recovery capabilities; and personnel security training.
4.3. MiseCentral may update security measures over time provided that such updates do not materially reduce the overall protection of Personal Data.
4.4. Additional detail regarding security and privacy controls appears in the Security and Privacy Controls Overview and related policies incorporated by reference into the Agreement.
5. Subprocessing
5.1. General Authorization. Customer provides general authorization for MiseCentral to engage Subprocessors to process Personal Data, subject to the requirements of this Section 5 and the Subprocessor Policy.
5.2. Obligations. MiseCentral imposes data protection obligations on each Subprocessor by written agreement that are substantially similar to those imposed on MiseCentral under this DPA, including with respect to confidentiality, security, and restrictions on processing.
5.3. Notice and Objection. MiseCentral will maintain a current list of Subprocessors and will provide Customer with notice of intended additions or replacements through the Subprocessor Policy publication mechanism or direct notice where required by an Order Form. Customer may object to a new Subprocessor on reasonable grounds relating to data protection by notifying MiseCentral in writing within thirty (30) days after notice. If the parties cannot resolve the objection within a reasonable period, Customer may terminate the affected Services upon written notice as the sole remedy for the objection, without penalty for the terminated portion if no alternative Subprocessor is reasonably available.
5.4. Responsibility. MiseCentral remains responsible to Customer for the performance of each Subprocessor's obligations to the extent required under applicable Data Protection Laws.
6. Assistance with Data Subject Rights
6.1. Taking into account the nature of processing and the information available to MiseCentral, MiseCentral will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to requests from data subjects to exercise rights under applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making where applicable.
6.2. Customer is responsible for responding to data subject requests. If MiseCentral receives a request directly from a data subject, MiseCentral will promptly redirect the individual to Customer unless prohibited by law, and will not respond substantively except as instructed by Customer or required by law.
6.3. Where the Services provide self-service or administrative tools enabling Customer to fulfill data subject requests, Customer will use those tools as the primary mechanism before requesting manual assistance from MiseCentral.
7. Assistance with Compliance Obligations
7.1. MiseCentral will provide reasonable assistance to Customer with respect to: (a) data protection impact assessments and prior consultations with supervisory authorities, to the extent required under applicable Data Protection Laws and solely in relation to processing performed by MiseCentral; and (b) Customer's obligations to notify supervisory authorities or data subjects of a Personal Data breach, to the extent such breach occurs within MiseCentral's systems or Subprocessors engaged by MiseCentral.
7.2. MiseCentral may charge reasonable fees for assistance that exceeds standard support included in the Subscription, unless the need for assistance arises from MiseCentral's breach of this DPA.
8. Personal Data Breach Notification
8.1. MiseCentral will notify Customer without undue delay, and in any event within seventy-two (72) hours where feasible, after becoming aware of a Personal Data breach affecting Customer's Personal Data processed under this DPA.
8.2. Notification will include, to the extent then known: a description of the nature of the breach; categories and approximate number of data subjects and records concerned; likely consequences; and measures taken or proposed to address the breach. MiseCentral will provide updates as additional information becomes available.
8.3. MiseCentral will cooperate with Customer's investigation and remediation efforts and will preserve relevant evidence in accordance with the Incident Response Policy.
9. Return and Deletion of Personal Data
9.1. Upon termination or expiration of the Agreement, or upon Customer's written request, MiseCentral will, at Customer's election stated in the request or within thirty (30) days after termination, delete or return Customer Data containing Personal Data, and delete existing copies unless applicable law requires retention.
9.2. Deletion and return procedures are further described in the Data Deletion Policy and Data Retention Policy. Operational Evidence, audit logs, and backup copies may persist for limited periods as described in those policies before secure deletion or anonymization.
9.3. Aggregated Data that cannot reasonably identify Customer or any individual may be retained after termination in accordance with the Agreement.
10. Audits and Demonstration of Compliance
10.1. MiseCentral will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of security controls, third-party audit reports where available and appropriate under confidentiality restrictions, and responses to reasonable security questionnaires.
10.2. Customer may conduct an audit no more than once per twelve (12) month period, or more frequently if required by applicable Data Protection Laws or following a confirmed Personal Data breach attributable to MiseCentral, subject to: (a) at least thirty (30) days' prior written notice; (b) execution of a mutually acceptable confidentiality agreement; (c) scheduling during normal business hours in a manner that does not unreasonably disrupt MiseCentral's operations; and (d) scope limited to processing under this DPA.
10.3. Customer may satisfy audit obligations through review of an independent third-party audit report or certification accepted by MiseCentral in writing, if such report covers the relevant controls and period.
10.4. Customer bears its own audit costs unless an audit reveals a material breach of this DPA by MiseCentral, in which case MiseCentral will reimburse reasonable documented costs directly attributable to the confirming audit.
11. International Transfers
11.1. Customer acknowledges that MiseCentral and its Subprocessors may process Personal Data in the United States and other countries where MiseCentral or its Subprocessors maintain facilities.
11.2. Where Personal Data originating from the European Economic Area, Switzerland, or the United Kingdom is transferred to a country not recognized as providing an adequate level of protection, the parties agree that the transfer is subject to the Standard Contractual Clauses incorporated by reference under Section 12 and the International Transfer Statement.
11.3. Customer represents that it has authority to authorize such transfers and, where required, has provided appropriate notices and obtained necessary consents from data subjects.
12. Standard Contractual Clauses
12.1. For transfers of Personal Data from the EEA, Switzerland, or the United Kingdom to MiseCentral in a country without an adequacy decision, the EU Commission 2021 Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference into this DPA and deemed executed between the parties as of the Effective Date of the Agreement.
12.2. For purposes of the incorporated Clauses: (a) Customer is the "data exporter" and MiseCentral is the "data importer"; (b) Annex I descriptions appear in Annex I to this DPA; (c) Annex II technical and organizational measures are described in the Security and Privacy Controls Overview and Annex II to this DPA; (d) the optional docking clause is enabled for affiliates and Subprocessors as permitted under the Clauses; (e) the governing law of the Clauses for EEA transfers is the law of Ireland, unless mandatory law requires otherwise; and (f) disputes are subject to the courts of Ireland for EEA transfers, without prejudice to data subjects' rights under the Clauses.
12.3. For UK transfers, the UK International Data Transfer Addendum issued by the Information Commissioner's Office applies in combination with the Clauses as specified in the International Transfer Statement.
12.4. If the Clauses or applicable transfer mechanisms are modified, invalidated, or superseded, the parties will cooperate in good faith to implement an alternative lawful transfer mechanism.
13. CCPA/CPRA and U.S. State Privacy Laws
13.1. To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and similar comprehensive U.S. state privacy laws apply, MiseCentral processes Personal Data as a Service Provider or Processor on Customer's behalf.
13.2. MiseCentral will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than performing the Services under the Agreement, including as specified in this DPA, or as permitted by applicable law; (c) retain, use, or disclose Personal Data outside of the direct business relationship between MiseCentral and Customer; or (d) combine Personal Data received from or on behalf of Customer with Personal Data received from other sources except as permitted by applicable law or necessary to provide the Services.
13.3. MiseCentral certifies that it understands and will comply with the restrictions in Section 13.2. MiseCentral will notify Customer if it can no longer meet its obligations as a Service Provider or Processor.
13.4. Customer may take reasonable steps to ensure MiseCentral uses Personal Data consistently with Customer's obligations, including by instruction, audit rights under Section 10, and termination rights under the Agreement.
13.5. MiseCentral will assist Customer with applicable consumer rights requests to the extent described in Section 6 and as required under applicable U.S. state privacy laws.
14. Operational Recommendations and Automated Processing
14.1. The Services may analyze Customer Data to produce Operational Recommendations, alerts, and prioritized work guidance. Such outputs are advisory. MiseCentral does not make binding decisions that produce legal or similarly significant effects concerning data subjects on Customer's behalf unless Customer explicitly configures a workflow that implements Customer's own decision rules.
14.2. MiseCentral does not use Customer Data to train foundation models for unrelated customers unless Customer provides documented authorization or the data constitutes Aggregated Data that cannot reasonably identify Customer or any individual.
15. Support Mode Processing
15.1. When Customer authorizes Support Mode or Partner Support Mode under applicable policies, MiseCentral personnel or authorized Partners may access Customer Data in a temporary, ticket-bound, audited session to diagnose and resolve support issues. Support Mode is not user impersonation. Processing during Support Mode is limited to the stated reason, duration, and scope recorded in the support ticket and audit log.
16. Term and Precedence
16.1. This DPA remains in effect for so long as MiseCentral processes Personal Data on behalf of Customer under the Agreement.
16.2. In the event of conflict between this DPA and other components of the Agreement regarding Personal Data processing, this DPA controls. If an Order Form specifies additional data protection terms, those terms apply to the extent they do not reduce protections required by applicable Data Protection Laws.
17. Contact
Questions regarding this DPA or Personal Data processing may be directed to:
MiseCentral LLC Attn: Privacy 8 The Green, Suite A Dover, DE 19901 United States privacy@misecentral.com
---
Annex I — Description of Processing
A. List of Parties
B. Categories of Data Subjects
- Authorized Users and Customer personnel whose accounts, profiles, roles, and activity are managed in the Services
- Individuals identified in hospitality operational records submitted by Customer, including workforce scheduling, task assignment, and execution records where applicable
- Individuals identified in quality, food-safety, and traceability records submitted by Customer
- Customer-designated contacts for billing, administration, support, and implementation
- Individuals whose information appears in Connected Service data imported under Customer's control
C. Categories of Personal Data
- Account and identity data: name, work email, phone, job title, role assignments, authentication and session metadata
- Workforce and operational data: schedules, assignments, task completion records, facility associations, and related Operational Evidence attributable to individuals
- Quality, food-safety, and traceability records: inspection logs, corrective actions, temperature or compliance readings, supplier and lot traceability entries, and attachments referencing individuals where Customer includes such data
- Communications and support data: support tickets, in-product messages, notification preferences, and Support Mode session metadata
- Technical and audit data: access logs, configuration changes, API activity, Connected Device identifiers, and security event records linked to identifiable users
- Professional Services data: training attendance, implementation notes, and project communications
D. Special Categories of Data
Customer is instructed not to submit special categories of Personal Data (such as health data beyond what is necessary for routine workforce administration, biometric data, or data revealing racial or ethnic origin) unless required for Customer's lawful operations and permitted under applicable law. If Customer submits such data, Customer is responsible for establishing a lawful basis and appropriate safeguards. MiseCentral processes such data only on Customer's instructions.
E. Nature and Purpose of Processing
Hosting; storage; organization; retrieval; analysis for Operational Intelligence and advisory Operational Recommendations; workflow orchestration; notifications; audit logging; backup and disaster recovery; customer support including Support Mode; security monitoring; integration with Connected Services; export and migration; deletion and retention in accordance with Customer configuration and applicable policies.
F. Duration of Processing
For the Subscription Term and any applicable post-termination retention period described in the Data Retention Policy and Data Deletion Policy, unless earlier deletion is requested or required by law.
---
Annex II — Technical and Organizational Measures
MiseCentral maintains a security program that includes:
1. Governance. Security and privacy policies, risk management, vendor review for Subprocessors, and personnel training. 2. Access Control. Role-based access, least-privilege principles, multi-factor authentication for administrative and Support Mode access, and periodic access review. 3. Encryption. TLS for data in transit; encryption at rest for Customer Data stored in production environments. 4. Logging and Monitoring. Audit trails for administrative actions, Support Mode sessions, and security-relevant events; monitoring for anomalous activity. 5. Secure Development. Change management, code review, dependency management, and pre-production testing. 6. Resilience. Backups, disaster recovery procedures, and business continuity planning as described in applicable Support policies. 7. Incident Response. Documented procedures for identifying, containing, investigating, and notifying Personal Data breaches. 8. Physical and Cloud Infrastructure. Use of reputable cloud infrastructure providers with physical and environmental controls appropriate to hosted SaaS operations.
Detailed descriptions appear in the Security and Privacy Controls Overview. MiseCentral may update measures provided overall protection is not materially reduced.
---
Annex III — Subprocessors
The current list of Subprocessors, including identity, location, and processing activities, is maintained in the Subprocessor Policy published at the location specified in the Agreement or Documentation. Customer acknowledges that infrastructure, communications, monitoring, and professional services vendors may process Personal Data as Subprocessors.
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.