This Data Processing Addendum ("DPA") forms part of the Centro Terms of Service (the "Terms") between Centro Technologies LLC, a Florida limited liability company ("Centro"), and the organization that has accepted the Terms to use Centro ("Customer"). It applies automatically when an organization accepts the Terms and needs no separate signature. It describes how Centro processes personal data on Customer's behalf.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Terms.
- Applicable Data Protection Law means the U.S. federal and state laws that apply to the processing of Customer Personal Data under the Terms, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (the "CCPA"), the other U.S. state consumer privacy laws, the Children's Online Privacy Protection Act and its rules ("COPPA"), and state consumer health data laws such as the Washington My Health My Data Act.
- Customer Personal Data means personal data that Customer, its staff, or the people it serves submit to Centro, or that Centro collects on Customer's behalf, in providing the Services to Customer.
- Controller and business mean the party that decides why and how personal data is processed. Processor and service provider mean the party that processes personal data on the controller's behalf. These terms have the meanings given in Applicable Data Protection Law.
- Data Subject means an identified or identifiable person to whom Customer Personal Data relates.
- Personal Data Breach means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.
- Services means the Centro software and services provided under the Terms, including the Centro app, the family and player portal, registration and payment pages, Broadcasts, Centro AI, and organization websites.
- Subprocessor means a third party that Centro engages to process Customer Personal Data.
2. Roles of the parties
- Customer is the controller (business) of Customer Personal Data. Customer decides what information to collect, from whom, and why, and is responsible to the people it serves.
- Centro is a processor (service provider) of Customer Personal Data and processes it on Customer's behalf under this DPA.
- Centro is a controller of the personal data it processes for its own purposes, as described in the Centro Privacy Policy: Centro accounts and sign-in, Centro's subscription billing and transaction-fee records, legal acceptance records, privacy-request records, security, fraud, abuse and audit logs, product analytics on Centro's own app, the withcentro.com marketing site, support conversations with Centro, and Centro AI usage metering. This DPA does not apply to that data.
- Stripe processes payments made through the Services. For payment processing, bank account verification (Stripe Financial Connections) and its own fraud-prevention and legal obligations, Stripe acts as an independent controller under the Stripe Privacy Policy and its agreements with Customer, including the Stripe Connected Account Agreement.
3. Scope, subject matter and duration
- Subject matter. Centro processes Customer Personal Data to provide the Services to Customer under the Terms.
- Duration. This DPA applies for as long as the Terms are in effect and after that for as long as Centro processes Customer Personal Data, including the export, deletion and retention periods in section 13.
- Details. The nature and purpose of the processing, the categories of Data Subjects and the categories of personal data are described in Annex 1.
4. Customer instructions
- Centro processes Customer Personal Data only on Customer's documented instructions. Customer's instructions are: (a) the Terms and this DPA; (b) the way Customer and its authorized staff configure and use the Services, such as forms, permissions, payment settings, Broadcasts and website content; and (c) other reasonable written instructions from Customer that are consistent with the Terms.
- Centro may also process Customer Personal Data when required by law. In that case Centro will inform Customer before processing, unless the law prohibits it.
- Centro will tell Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Centro is not required to follow an instruction that would require it to break the law or to build features the Services do not offer.
5. Customer obligations
Customer is responsible for:
- having a lawful basis, and all notices and consents required by law, for the personal data it collects and processes through the Services and for its instructions to Centro;
- obtaining verifiable parental consent where required for children under 13, and the consent of a parent or guardian for other minors where the law or Customer's own policies require it. Children under 13 do not have Centro accounts; their information is entered by a parent or guardian or by Customer;
- obtaining any separate consent required for health information, including under state consumer health data laws, before turning on health and emergency fields in its forms;
- giving the people it serves the privacy notices required by law, including a notice that explains Customer's own use of their information;
- sending Broadcasts and other email only to contacts it has a lawful right to email, never buying or renting contact lists, and honoring unsubscribe requests;
- collecting government ID images only where needed to decide adult league eligibility, and using the review result only for that purpose;
- keeping Customer Personal Data accurate and up to date, and collecting only the information it needs;
- giving staff permissions only to people who need them, keeping sign-in credentials secure, and promptly removing staff who leave; and
- not using the Services to store medical records or protected health information under HIPAA, or other categories of data the Terms do not permit.
6. Centro obligations
6.1 Processing limits
Centro will:
- process Customer Personal Data only to provide the Services to Customer, on Customer's instructions and for the business purposes described in this DPA and the Terms;
- not sell Customer Personal Data or share it for cross-context behavioral advertising;
- not retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in the Terms and this DPA, including not for any commercial purpose other than providing the Services, and not outside the direct business relationship between Centro and Customer;
- not combine Customer Personal Data with personal data that Centro receives from or on behalf of another person, or collects from its own interactions with a Data Subject, except as permitted by Applicable Data Protection Law (for example, to detect security incidents, prevent fraud, or operate a person's own Centro account across the organizations they belong to);
- not use Customer Personal Data to train artificial intelligence models, and not allow its AI provider to do so;
- comply with its obligations under Applicable Data Protection Law and provide the same level of privacy protection that the law requires of Customer;
- notify Customer if it determines that it can no longer meet its obligations under Applicable Data Protection Law; and
- allow Customer, on reasonable notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.
Centro may create de-identified or aggregated information that does not identify Customer or any person, and use it to operate, secure and improve the Services. Centro will keep such information de-identified, will not attempt to re-identify it, and will require the same of anyone it shares it with.
Centro understands and will comply with the restrictions in this section 6.1.
6.2 Confidentiality of personnel
Centro will give access to Customer Personal Data only to personnel who need it to provide, support or secure the Services, and will make sure those personnel are bound by confidentiality obligations. Authorized Centro staff may open a support session to view Customer's account only to provide support, investigate a problem or keep the Services secure. Support sessions end after 15 minutes and are recorded in an audit log.
6.3 Security
Centro will maintain reasonable administrative, technical and organizational safeguards designed to protect Customer Personal Data, appropriate to the nature of the data and the risks of the processing. The current safeguards are described in Annex 2. Centro may update them over time, provided the overall level of protection is not reduced.
7. Subprocessors
- Customer authorizes Centro to use the Subprocessors listed in Annex 3.
- Centro will have a written agreement with each Subprocessor that imposes data protection obligations no less protective than those in this DPA, to the extent applicable to the service the Subprocessor provides. Centro remains responsible for its Subprocessors' performance of those obligations.
- Centro will give notice of any new Subprocessor at least 14 days before it begins processing Customer Personal Data, by email to Customer's account owner or by updating the Centro legal pages.
- Customer may object to a new Subprocessor on reasonable data protection grounds by writing to legal@withcentro.com during the notice period. The parties will discuss the objection in good faith. If Centro cannot reasonably address it, Customer may terminate the Terms by notice to Centro before the new Subprocessor begins processing Customer Personal Data, without a termination charge from Centro.
8. Assistance with Data Subject requests
- The Services give Customer tools to access, export, correct and delete Customer Personal Data, so that Customer can respond to requests from the people it serves.
- If Centro receives a request from a Data Subject about Customer Personal Data, Centro will forward it to Customer within 5 business days and will not respond to it directly, except to tell the person that the request has been forwarded or where the law requires otherwise.
- Where Customer cannot complete a request with the tools in the Services, Centro will provide reasonable assistance, taking into account the nature of the processing and the information available to Centro.
9. Assistance with security, assessments and consultations
Taking into account the nature of the processing and the information available to Centro, Centro will provide reasonable assistance to Customer in meeting its obligations under Applicable Data Protection Law relating to the security of processing, data protection or risk assessments, and consultations with regulators. Centro may meet this obligation by providing the information in this DPA, the Centro legal pages and its responses to security questionnaires.
10. Personal Data Breach
- Centro will notify Customer without undue delay, and in any event within 72 hours, after Centro confirms a Personal Data Breach affecting Customer Personal Data.
- The notice will be sent to Customer's account owner and will describe, as far as the information is then available, the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, the measures taken or proposed to address it, and a contact for more information. Centro will provide further information as it becomes available.
- Centro will take reasonable steps to contain and investigate the breach and to reduce its effects, and will cooperate with Customer as reasonably needed for Customer to meet its own notice obligations to individuals and regulators.
- Centro's notice of a breach is not an admission of fault or liability.
11. Audits and information
- Centro will make available to Customer the information reasonably necessary to demonstrate its compliance with this DPA, such as answers to security and privacy questionnaires and relevant documentation, once per year on written request to legal@withcentro.com, and also after a Personal Data Breach or when a regulator requires it.
- Where the providers allow it, Centro may also share its Subprocessors' own security certifications or audit reports. Those certifications belong to the Subprocessors, not to Centro.
- Centro will allow an on-site audit only where Applicable Data Protection Law requires one and the information above is not enough to meet that requirement. Any on-site audit must be agreed in advance, conducted during business hours with at least 30 days' notice, limited to Centro's own systems that process Customer Personal Data, conducted under confidentiality obligations, and carried out at Customer's expense.
- Information provided under this section is Centro's confidential information.
12. International transfers
Centro stores and processes Customer Personal Data in the United States. Centro and its Subprocessors listed in Annex 3 process Customer Personal Data in the United States. The Services are designed for organizations in the United States. If Customer is subject to data protection laws of another country, Customer is responsible for deciding whether processing in the United States meets those laws before using the Services.
13. Return and deletion
While the Terms are in effect, Customer can export Customer Personal Data with the export tools in the Services.
When Customer's owner requests closure in the Services, Customer has 30 days to export its data before Centro closes the account, and for 30 days after closure Customer may still ask Centro for an export. Centro will delete or de-identify Customer Personal Data within 90 days after closure, except for the following records, which Centro keeps for the periods shown:
- financial records (such as invoices, payments, refunds, disputes and fees): 7 years;
- payment and autopay authorizations: 3 years after they end;
- signed waivers and parental consents: until the participant turns 21 or for 4 years, whichever is later;
- records Centro must keep by law or under a legal hold: for as long as required; and
- unsubscribe and suppression records (email address, reason and date only): kept so that the person is not emailed again.
Deleted data can remain in database backups for up to 30 days until those backups expire. If a backup is ever restored, Centro reapplies completed deletions. Centro will continue to protect any Customer Personal Data it retains under this DPA for as long as it retains it.
14. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Terms.
15. Order of precedence
If this DPA conflicts with the Terms, this DPA controls with respect to the processing of Customer Personal Data. If Centro and Customer sign a separate written data processing agreement that expressly states it replaces this DPA, that agreement controls. Otherwise, the Terms control.
16. Changes to this DPA
Centro may update this DPA, for example to reflect changes in the law or in the Services. Centro will notify Customer of material changes by a method that is reasonable in the circumstances, such as by email, in the Services or on the Centro legal pages, and an update takes effect on the date stated in it or in the notice. Where applicable law requires a particular form or period of notice, Centro will follow that requirement. An update will not reduce the overall protection of Customer Personal Data unless the law requires it. Earlier versions remain available on the Centro legal pages.
17. Language
This DPA is available in English and Spanish. If the two versions conflict, the English version controls.
18. Contact
Questions about this DPA, objections to Subprocessors and audit requests can be sent to legal@withcentro.com or to Centro Technologies LLC, 1000 Brickell Avenue, Suite #715 PMB 305, Miami, FL 33131, United States.
Annex 1. Details of the processing
Nature and purpose
Centro hosts, stores, organizes, displays, transmits and deletes Customer Personal Data in order to provide the Services, including: managing members, teams, staff, schedules and leagues; running registrations, waivers, consents and eligibility review; issuing invoices and processing payments and autopay through Stripe; sending transactional email and Broadcasts; providing in-app messaging and chat; publishing Customer's website and delivering its inquiries; providing Centro AI to Customer's staff; and providing support, security, backups and troubleshooting.
Categories of Data Subjects
- Customer's staff (such as owners, administrators, directors, finance staff, coaches and team managers)
- members and players, including minors
- parents and guardians
- contacts that Customer adds or imports, such as Broadcast recipients
- visitors to Customer's website who submit an inquiry or make a purchase
- payers
Categories of personal data
- identity and contact information: names, email addresses, phone numbers, postal addresses, date of birth, gender, language preference and photos
- membership and sports information: teams, positions, jersey numbers, attendance, evaluations, development notes and schedules
- registration information and answers to Customer's custom questions
- payment information: invoices, amounts, payment status, card brand, last four digits and expiry, bank name and Stripe references (Centro does not store full card or bank account numbers)
- communications: email delivery records, Broadcast content, in-app messages and chat, and website inquiries
- documents and files that Customer or its members upload
- technical information: sign-in records, IP addresses, browser information and audit log entries
Sensitive data
The following sensitive categories are processed only when Customer uses the related features:
- children's data, entered by a parent or guardian or by Customer;
- health and emergency information, only when Customer turns on these fields in a form, with the registrant's separate consent;
- government ID images (front, optional back, and a photo of the person holding the ID), only for adult league registrations where Customer requires them. Centro runs automated document-quality and consistency checks within its own systems. Centro does not use facial recognition, does not perform face matching and does not create biometric templates. Images are deleted 30 days after Customer's staff record a decision, or 180 days after upload if never reviewed; and
- signatures on waivers, consents and payment authorizations, with the signer's name, the time, the IP address and the exact text signed.
Health information and government ID images are not used for analytics, are not sent to Centro AI and are not included in Broadcasts.
Frequency and retention
Processing is continuous for as long as Customer uses the Services. Retention follows the Terms, the Centro Privacy Policy and section 13.
Annex 2. Security measures
- Encryption in transit: connections to the Services use TLS.
- Encryption at rest: data is stored with providers that encrypt it at rest.
- Access control: role-based permissions within each organization, with least-privilege access for Customer staff and Centro personnel. Each organization's data is logically separated, and access checks are scoped to the organization.
- Private storage for sensitive files: government ID images, medical clearances and member documents are stored privately and are never available at public addresses. Viewing a government ID image is limited to staff with registration permissions and is recorded in an audit log.
- Audit logging: security-relevant and administrative actions are recorded in audit logs.
- Centro staff access: access by Centro personnel is limited to authorized staff, protected by sign-in controls, and recorded. Support sessions expire after 15 minutes and are audit-logged.
- Payment data: card and bank account numbers are collected and stored by Stripe, not by Centro.
- Secure development: code review, automated testing and controlled deployments before changes reach production.
- Backups: database backups with point-in-time recovery of up to 30 days.
- Vulnerability management: dependencies and the platform are kept up to date, and security issues are prioritized and remediated.
- Abuse protection: rate limiting on sensitive actions and bot protection on public forms.
- Monitoring: error and performance monitoring and alerting, with personal data removed from error reports.
- Data minimization: health information and government ID images are excluded from analytics, Centro AI and Broadcasts.
Annex 3. Subprocessors
| Subprocessor | Purpose | Customer Personal Data processed | Location |
|---|---|---|---|
| Vercel | Hosting of the Services and websites, serverless functions and file storage | All categories, including uploaded files | United States |
| Neon | Primary database and backups | All categories stored in the database | United States |
| Clerk | Sign-in and account authentication | Names, email addresses, phone numbers, sign-in and session information, IP addresses | United States |
| Stripe | Payment processing, saved payment methods, bank account verification and autopay. Stripe acts as an independent controller for payment processing. | Payer names and email addresses, payment method details, amounts and payment records | United States |
| Resend | Delivery of transactional email and Broadcasts | Recipient names and email addresses, email content and delivery events | United States |
| Anthropic | Centro AI assistant and AI writing and translation help for staff | Staff questions and the organization data needed to answer them; never government ID images, payment credentials or health information | United States |
| Sentry | Error monitoring | Technical error data, with personal data removed | United States |
| PostHog | Product analytics | Pseudonymous identifiers and product usage events; masked session replays on a few public pages | United States |
| Google (Google Analytics 4) | Usage measurement, only under each user's analytics choice | Pseudonymous identifiers and usage events | United States |
| Upstash | Rate limiting and processing locks | Technical identifiers such as account IDs and IP addresses, kept for short periods | United States |
| Cloudflare (Turnstile) | Bot protection on public forms | IP address and browser signals | United States |
| Pusher | Real-time delivery of in-app updates and messages | Update and message events, delivered in transit and not stored | United States |
| Quo | Centro's business phone | Organization owners' names, phone numbers and conversations with Centro (owner contact only) | United States |
Tools that Centro uses only for its own marketing on withcentro.com do not receive Customer Personal Data and are described in the Centro Privacy Policy and Cookie Policy.
Who we are and how to reach us
Centro Technologies LLC, a Florida limited liability company
Mail: 1000 Brickell Avenue, Suite #715 PMB 305, Miami, FL 33131, United States
Legal and privacy: legal@withcentro.com
Support: support@withcentro.com
Phone: (786) 464-5364