Data Processing Agreement
Last Updated: August 24th 2026
This Data Processing Agreement (“DPA”) is entered into by Centripetal Networks, LLC (“Centripetal”) and the Customer identified in the Order Form. This DPA governs Centripetal’s Processing of Personal Information. Capitalized terms used but not defined in this DPA have the meanings set forth in the MSA.
1. DEFINITIONS
a. “Breach” means the following: (i) any Processing of Personal Information that (a) is not authorized by Customer under the Agreements, (b) is not otherwise authorized by Customer expressly and in writing, (c) exceeds the scope of either such authorization, (d) compromises the confidentiality, integrity or availability of Personal Information, (e) is a breach of the DPA, or (f) violates Data Protection Law; (ii) any access to, use of, or activity on or in any Centripetal network, system, equipment, device, cloud, or online or offline account that is unauthorized or exceeds the scope of authority and involves Personal Information; provided that (iii) this term does not include (a) a Breach of encrypted Personal Information, as long as the decryption key also has not been compromised, or (b) the unintended or good faith Processing of Personal Information by an employee of Centripetal, or the disclosure of Personal Information by an employee of Centripetal to another employee of Centripetal, as long as the Personal Information is not otherwise further Processed without authorization, beyond the scope of authorization, or in a manner or to an extent that compromises the confidentiality, integrity or availability of the Personal Information or violates Data Protection Law.
b. “Data Protection Laws” mean all domestic and foreign laws, rules, and regulations that govern (i) a breach or security incident involving Personal Information, (ii) technological, physical, or administrative safeguards for protecting the confidentiality, integrity, or availability of Personal Information, or (iii) Processing of Personal Information; provided that (iv) this term encompasses only laws, rules, and regulations that a Party is subject to such and that govern the Personal Information at issue.
c. “Liability” has the same meaning as set forth in the MSA. With respect to a Breach of Personal Information, Liability includes the following: (i) computer, technology, and forensic investigation; (ii) attorney fees; (iii) public relations costs; (iv) notification of affected individuals and regulators; (v) credit and identity monitoring and restoration; (vi) call and email support; and (vii) investigation, inquiry, request, subpoena, other legal process, fine, penalty, settlement, judgment, claim, suit, lawsuit, action, cause of action, or other allegation issued or made by an individual, group or class of individuals, regulator, or any other third-party arising out of or related to the Breach.
d. “Process” and any derivation of that term means any operation or set of operations which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restricting, erasure or destruction.
2. ROLES
Customer is the data controller of Personal Information under Data Protection Laws. Centripetal is a data processor of Personal Information under Data Protection Laws.
3. TERM
In the event of termination of the MSA, the Parties’ obligations under this DPA will continue until Centripetal has either returned or permanently destroyed all Confidential Information and Personal Information. Once Centripetal has done so, the Parties’ obligations under this DPA terminate.
4. DETAILS OF PROCESSING
Centripetal may Process Personal Information for the purpose of performing its obligations under the Agreements, and for the duration of the Agreements. Such Processing shall include collecting, accessing, storing, altering, using, transferring and disclosing to a Sub-Processor, and deletion of Personal Information. The types of Personal Information and the categories of data subjects are those that Customer submits, or that the Products Process in providing the Services.
5. CONFIDENTIALITY
Centripetal shall maintain Confidential Information and Personal Information as strictly confidential. Centripetal shall not disclose or provide access to any third party to any Confidential Information or Personal Information without Customer authorization, except transfers and disclosures of Personal Information to a Sub-Processor permitted by the MSA. Centripetal shall not Process Confidential Information or Personal Information for any purpose other than to provide Products and Services to Customer, and any Processing shall be limited to Processing of Confidential Information or Personal Information only to the extent doing so is necessary to provide the Products and Services, unless Customer expressly authorizes additional Processing of Confidential Information or Personal Information. Nothing in this Section limits Centripetal’s Processing of Usage Data, Threat Intelligence Data, or Deidentified data as permitted by the MSA.
6. SECURITY MEASURES
Centripetal shall implement and maintain reasonable physical, technological, and administrative controls designed to safeguard the confidentiality, integrity, and availability of Personal Information.
7. OBLIGATIONS PURSUANT TO DATA PROTECTION LAWS
a. Customer’s Compliance with Data Protection Laws. Customer shall comply with all Data Protection Laws governing Processing of Personal Information by Centripetal, including, but not limited to: (i) ensuring all instructions given by it to Centripetal in respect of the Processing of Personal Information comply with Data Protection Laws; (ii) providing all notices and obtaining all consents required by Data Protection Laws for Centripetal’s Processing of Personal Information under the MSA; and (iii) addressing all requests made by individuals to assert any right afforded under Data Protection Laws. Customer shall be liable to Centripetal for Liability arising out of or related to any breach of this provision.
b. Centripetal’s Compliance with Data Protection Laws. Centripetal shall comply with all Data Protection Laws governing the Processing of Personal Information. Centripetal shall not sell, share, or otherwise disclose Personal Information to any third party (except for transfers or disclosure to a Sub-Processor permitted by the MSA or this DPA), or Process Personal Information by, for, or on behalf of any third party. Centripetal shall Process Personal Information as specified in the MSA, unless additional processing is authorized expressly and in writing by Customer. When Centripetal engages a Sub-processor, Centripetal shall contractually obligate such Sub-Processor to comply with terms that are comparable to the terms in this DPA governing Centripetal’s Processing of Personal Information. Centripetal shall only retain Sub-Processors that are capable of appropriately protecting the privacy, confidentiality and security of Personal Information.
c. Centripetal Employees. Centripetal will ensure that employees engaged in the Processing of Confidential Information and Personal Information are informed of the confidential nature of such information, have received appropriate training on their responsibilities concerning such information, and are contractually required to maintain the confidentiality of such information. Centripetal shall ensure that such obligations survive the termination of employment. Centripetal will ensure that Centripetal’s access to Personal Information is limited to those personnel who require such access to perform the Services under the DPA.
d. Privacy Rights. Centripetal shall provide reasonable assistance to Customer with respect to Customer’s compliance with Data Protection Laws.
e. Data Transfers. To the extent Centripetal transfers Personal Information outside the country from which it was originally delivered or made available to Centripetal, or from which Centripetal otherwise accessed or obtained it, Centripetal shall comply with applicable privacy laws and implement a data transfer mechanism in accordance with Data Protection Laws to the extent required for such cross-border transfer.
8. USE OF ARTIFICIAL INTELLIGENCE
To the extent any artificial intelligence or algorithmic analysis tools (“AI”), including AI developed, owned, or managed by Centripetal (“Centripetal AI”), or AI developed, owned or managed by third parties but utilized by Centripetal (“Third-Party AI”) are: (i) offered to Customer by Centripetal as part of the Products (“Customer Use”); or (ii) used or relied upon by Centripetal to materially provide or support the provision of Products to Customer (“Centripetal Use”), Centripetal shall comply with the requirements set forth in the AI Addendum attached as Addendum A to this DPA (“AI Addendum”).
9. SECURITY OR PRIVACY BREACH NOTIFICATION
Centripetal will notify Customer of a Breach of Personal Information within three business days after Centripetal confirms that such Breach occurred. At the time of such initial notification and continuing thereafter, Centripetal will disclose to Customer non-privileged information that Centripetal has or receives concerning such Breach, including, but not limited to, the following: (i) names and other information available about individuals affected by the breach; (ii) the nature and scope of information compromised or potentially compromised in the breach or as a result of the breach; (iii) timing, manner, and cause of the breach; and (iv) acts taken in response to the breach. Centripetal will provide Customer with assistance and cooperation reasonably requested by Customer related to such Breach, and shall follow and comply with reasonable requests made by Customer related to such breach. Unless otherwise required by applicable law, Centripetal shall not disclose to any person, other than its attorneys and other agents, information related to such Breach without express written authorization from Customer, including by not notifying any individual affected or potentially affected by the breach, any local, state, or federal government authority or agency, any media outlet, or any other person or entity.
10. SECURITY OR PRIVACY BREACH LIABILITY
Centripetal is liable to Customer for Liability arising out of or related to a Breach of Personal Information within the possession, custody, or control of Centripetal that is not caused by an act or omission of Customer, any sub-processor of Customer, or any of their respective employees, agents, representatives, or sub-processors (“Centripetal Breach”). Customer is liable to Centripetal for Liability arising out of or related to a Breach of Personal Information within the possession, custody, or control of Centripetal that is caused by an act or omission of Customer, any sub-processor of Customer (excluding Centripetal), or any of their respective employees, agents, representatives, or sub-processors (“Customer Breach”). Centripetal’s total Liability to Customer arising out of or related to all Centripetal Breaches shall not exceed $500,000, and Customer’s total Liability to Centripetal arising out of or related to all Customer Breaches shall not exceed $500,000. Each party shall maintain cyber liability insurance sufficient to support its obligations under this Section. Centripetal’s policy shall be primary coverage and Customer’s policy shall be secondary coverage for a Centripetal Breach. Customer’s policy shall be primary coverage and Centripetal’s policy shall be secondary coverage for a Customer Breach.
11. AUDIT
Upon Customer’s reasonable request, and subject to the confidentiality obligations in this DPA and the MSA, Centripetal will provide to Customer non-privileged information evidencing Centripetal’s compliance with its obligations in this DPA.
12. RETURN OF INFORMATION
On the expiration or termination of the MSA, Centripetal shall return to Customer or destroy all Personal Information within sixty (60) days after the expiration or termination of the MSA; provided that Centripetal may retain such Personal Information on backup media as long as such media is periodically erased or overwritten, and such retained Personal Information shall remain subject to the DPA for as long as Centripetal retains it. If Customer terminates or ceases to use any individual Product while the MSA remains in effect, then upon Customer’s written request Centripetal will, within sixty (60) days after the later of such termination or the request, delete Personal Information that Centripetal Processes solely for that Product and that is not required for any Product that remains in effect. This obligation is subject to the same backup-media retention allowance stated in this Section and to any retention required by applicable law or legal hold, and is in addition to, and does not limit, Centripetal’s return-or-destruction obligations under this Section on expiration or termination of the MSA.
Addendum A - AI Addendum
To the extent Centripetal AI or Third-Party AI are used for Customer Use or Centripetal Use, Centripetal shall comply with the following:
1. CENTRIPETAL AI FOR CENTRIPETAL USE
To the extent Centripetal utilizes Centripetal AI for Centripetal Use, Centripetal will comply with AI Use Principles (“AUP”) 1 through 10 set forth in Section 5 of this AI Addendum.
2. THIRD-PARTY AI FOR CENTRIPETAL USE
To the extent Centripetal utilizes Third-Party AI for Centripetal Use, Centripetal will comply with the AUPs 1 through 12 set forth in Section 5 of this AI Addendum.
3. CENTRIPETAL AI FOR CUSTOMER USE
To the extent Centripetal offers Centripetal AI for Customer Use, Centripetal will comply with AUP 1, 6, 8, 9 and 10 set forth in Section 5 of this AI Addendum.
4. THIRD-PARTY AI FOR CUSTOMER USE
To the extent Centripetal offers Third-Party AI for Customer Use, Centripetal will comply with AUPs 1, 6, 8, 9, 11 and 12 set forth in Section 5 of this AI Addendum.
5. AI USE PRINCIPLES (AUPS)
AUP 1. Compliance with Laws. Centripetal will ensure that its development, use and deployment of AI complies with all applicable laws and regulations, including Data Protection Laws.
AUP 2. AI Acceptable Use Policy. Centripetal will maintain a policy that describes how Centripetal implements and uses AI for Centripetal Use, the purposes and uses for which Centripetal permits AI to be used, the Centripetal employees permitted to use AI, and the mechanisms that Centripetal has implemented to address the risks posed by the use of AI (“AI Acceptable Use Policy”).
AUP 3. Oversight, Fairness, and Non-Discrimination. Centripetal will maintain human oversight over the inputs, use and outputs of AI in connection with Centripetal Use, and will implement internal governance processes to ensure the ethical, fair, and responsible use of AI. Centripetal will monitor and mitigate any risk of algorithmic bias, discrimination, and other adverse outcomes, and will promptly notify Customer if it becomes aware of any issue that could materially affect the fairness, reliability, or safety of the Products.
AUP 4. Attribution. Centripetal will identify any Deliverable, work-product, and output substantially generated using AI.
AUP 5. Awareness and Training. Centripetal will train all personnel that use AI for Centripetal Use or who are involved in the development of AI for Customer Use. Such training will include, at a minimum, the following: (i) purposes, capabilities, and limitations of such AI; (ii) risks related to bias, discrimination, and data misuse; (iii) applicable Data Protection Laws; (iv) monitoring, escalation, and human oversight; (v) reporting AI-related incidents, malfunctions, and complaints; and (vi) the AI Acceptable Use Policy. Centripetal will refresh such training periodically and as necessary in response to any substantive change to the AI Acceptable Use Policy or Centripetal’s use of such AI.
AUP 6. AI Impact Assessment. Centripetal will conduct not less than annually an AI impact assessment that will include, at a minimum, the following with respect to Centripetal Use: (i) actual and foreseeable use cases for AI, with an explanation of how such use is limited to activities necessary to fulfill legitimate business purposes; (ii) inventory of Centripetal personnel authorized to use or access such AI, ensuring that access is restricted to only those individuals whose roles require such use; (iii) evaluation of outcomes yielded by AI to ensure accuracy, reliability, and legitimacy; (iv) evaluation of any known or foreseeable risk of harm to individuals or businesses, including risks related to discrimination, misinformation, or violations of privacy; (v) description of steps taken to mitigate such risks, including safeguards such as monitoring, auditing, and human oversight; (vi) description of technical, administrative, and organizational controls implemented to safeguard information Processed using AI; (vii) summary of any material complaint, incident, or adverse outcome related to the use of AI, along with any corrective or remedial measure; and (viii) written report documenting the AI Impact Assessment, including findings and recommendations. Upon Customer’s request, Centripetal will provide Customer with a non-privileged summary of its most recent AI Impact Assessment.
AUP 7. Notice and Transparency. Upon Customer’s request, Centripetal will provide Customer with a description of any Centripetal Use, including: (i) the AI being used; (ii) the purposes for such Centripetal Use; and (iii) any known limitation, constraint, or risk that is reasonably likely to materially affect the accuracy, fairness, or reliability of the Products.
AUP 8. Confidentiality. Centripetal will not Process any Confidential Information or Personal Information through Centripetal AI or Third-Party AI, unless specifically authorized in writing by Customer; provided that Customer may choose to Process such information for Customer Use. If Customer consents or chooses to Process such information through Centripetal AI or Third-Party AI, Centripetal will ensure that any such information is Processed only to the extent necessary for the purpose of providing Services to Customer under the Agreement. Notwithstanding the foregoing, Centripetal may Process Deidentified Data, Usage Data and Threat Intelligence Data through Centripetal AI or Third-Party AI, in each case to the extent such data does not contain Personal Information.
AUP 9. Model Training. Centripetal will ensure that any Confidential Information or Personal Information Processed through Centripetal AI or Third-Party AI is not used to train, retrain, or otherwise improve the performance or functionality of Centripetal AI or Third-Party AI, unless expressly authorized in writing by Customer. Notwithstanding the foregoing, Centripetal may use Deidentified Data, Usage Data and Threat Intelligence Data for model training, in each case to the extent such data does not contain Personal Information.
AUP 10. Termination Obligations for Centripetal AI. Upon termination or expiration of the MSA, Centripetal will ensure that all Confidential Information and Personal Information is not stored or retained within Centripetal AI.
AUP 11. Termination Obligations for Third-Party. Upon termination or expiration of the MSA, Centripetal will use commercially reasonable efforts, to the extent within its reasonable control, to ensure that any Confidential Information and Personal Information that was Processed through Third-Party AI is no longer retained, stored, or accessible by such Third-Party AI provider, including by taking reasonable steps to cause such data to be deleted from the provider’s systems, and will, upon Customer’s request, provide such confirmation of deletion as Centripetal is reasonably able to obtain from the provider.
AUP 12. Appropriate Agreements. Centripetal will use commercially reasonable efforts to ensure that each Third-Party AI provider is contractually bound by terms consistent with those imposed on Centripetal under the DPA and this AI Addendum, to the extent such terms are reasonably obtainable from the provider.