Subprocessor Policy
This Subprocessor Policy describes how MiseCentral LLC ("MiseCentral," "we," "us," or "our") engages third-party subprocessors to process Personal Data on behalf of Customers in connection with the Services. This policy supplements the Data Processing Agreement ("DPA") and is incorporated by reference into the Agreement where the DPA applies.
1. Purpose and Scope
1.1. MiseCentral uses Subprocessors to provide hosting, infrastructure, communications, security, analytics, customer support tooling, and related services necessary to operate the Services.
1.2. This policy applies to Subprocessors that process Personal Data contained in Customer Data on MiseCentral's behalf. It does not describe Customer's own third-party systems connected through Connected Services, which Customer selects and governs independently.
2. Subprocessor Obligations
2.1. MiseCentral enters written agreements with Subprocessors imposing data protection, confidentiality, and security obligations substantially similar to those in the DPA.
2.2. MiseCentral evaluates Subprocessors based on security practices, privacy commitments, geographic processing locations, and contractual assurances appropriate to the nature of processing.
2.3. MiseCentral remains responsible to Customer for Subprocessor performance to the extent required under applicable Data Protection Laws.
3. General Authorization
3.1. Customer provides general authorization for MiseCentral to engage and replace Subprocessors as described in Section 5 of the DPA and this policy.
3.2. Enterprise Customers may request additional contractual requirements for specific Subprocessors through their Order Form where available.
4. Current Subprocessors
4.1. MiseCentral maintains the current list of Subprocessors below. The list identifies the Subprocessor, primary processing location, and general processing activity.
4.2. Additional Subprocessors engaged for specific Professional Services, implementation partners under MiseCentral governance, or newly adopted tooling will be added to this list before or concurrently with engagement as required by the DPA.
4.3. MiseCentral may use affiliates as Subprocessors subject to the same obligations in the DPA.
5. Notice of Changes
5.1. MiseCentral will update this policy when Subprocessors are added or replaced.
5.2. Customer may subscribe to subprocessor change notifications through the administrative portal or by contacting privacy@misecentral.com.
5.3. Unless an Order Form specifies a different notice period, MiseCentral will provide at least thirty (30) days' notice before a new Subprocessor begins processing Personal Data, except where replacement is required for security or operational emergency, in which case MiseCentral will notify Customer as soon as practicable.
6. Objection Rights
6.1. Customer may object to a new Subprocessor on reasonable grounds relating to data protection by notifying MiseCentral at privacy@misecentral.com within thirty (30) days after notice.
6.2. Upon objection, the parties will discuss the concern in good faith. If no resolution is reached within a reasonable period, Customer may terminate the affected Services as described in Section 5.3 of the DPA.
7. International Transfers by Subprocessors
7.1. Subprocessors may process Personal Data in the United States and other jurisdictions. Where required, MiseCentral implements appropriate transfer mechanisms, including Standard Contractual Clauses, as described in the International Transfer Statement and DPA.
8. Contact
MiseCentral LLC Attn: Privacy 8 The Green, Suite A Dover, DE 19901 United States privacy@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.