EXHIBIT C TO NURTURESYNC TERMS OF SERVICE
NURTURESYNC
DATA PROCESSING AGREEMENT
This Agreement is entered into between MPCT Solutions, LLC (“Processor”) and the Client identified below (“Controller”).
This DPA supplements and is incorporated into the NurtureSync Terms of Service.
Controller (Client): ____________________________ Effective Date: ____________________________
1. DEFINITIONS
Controller: The Client organization that determines the purposes and means of processing personal data through the NurtureSync Service.
Processor: MPCT Solutions, LLC, which processes personal data on behalf of the Controller in connection with providing the NurtureSync Service.
Personal Data: Any information relating to an identified or identifiable individual that Controller uploads, stores, or processes through the Service, limited to the categories described in Section 2.
Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
2. SCOPE AND PURPOSE OF PROCESSING
Processor processes Personal Data solely to provide the NurtureSync Service as described in the Terms of Service, including hosting, storage, backup, and data export. Processor will not process Personal Data for any purpose other than as instructed by Controller or as required by applicable law.
Categories of Personal Data: Account information (names, email addresses, phone numbers), organizational data (roles, permissions), usage activity data, and uploaded content as provided by Controller.
Duration: Processing continues for the duration of Controller’s active subscription and ends upon termination, after which data is deleted or returned per the NurtureSync Cancellation and Refund Policy and Section 3 of this DPA.
3. PROCESSOR OBLIGATIONS
3.1 Processor is responsible for:
Processing Personal Data only on Controller’s documented instructions and as permitted under the Terms of Service
Implementing and maintaining appropriate technical and organizational security measures for the Service infrastructure to protect Personal Data against unauthorized access, loss, or disclosure
Notifying Controller without undue delay, and where practicable within 72 hours, upon becoming aware of a Personal Data breach
Assisting Controller in responding to data subject rights requests to the extent reasonably practicable given the nature of the processing
Deleting or returning all Personal Data to Controller at the choice of Controller upon termination of the subscription, unless retention is required by applicable law
Ensuring that persons authorized to process Personal Data are subject to confidentiality obligations
Making available to Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA
3.2 Controller is responsible for:
Configuring its use of the Service appropriately for its needs and applicable legal requirements
Safeguarding its account credentials and controlling user access within its tenant
The lawfulness, accuracy, and appropriateness of the Personal Data it submits to the Service
Ensuring that Personal Data submitted to Processor is limited to the categories described in Section 2
Providing appropriate notices to and obtaining any required consents from data subjects whose Personal Data is submitted to the Service
4. SUB-PROCESSOR
Controller authorizes Processor to engage the following sub-processors in connection with the Service:
Processor will notify Controller of any intended changes to sub-processors with reasonable advance notice. Controller may object to a new sub-processor within 15 days of notice; if Processor cannot reasonably accommodate the objection, either party may terminate this DPA.
5. AUDIT RIGHTS AND COMPLIANCE DEMONSTRATION
In accordance with Colorado law, Processor will allow for and contribute to reasonable audits and inspections by Controller or Controller’s designated auditor to verify Processor’s compliance with this DPA.
Alternatively, Processor may, with Controller’s consent, arrange for a qualified and independent auditor to conduct, at least annually and at Processor’s expense, an audit of Processor’s policies and technical and organizational measures using an appropriate and accepted control standard, framework, and audit procedure. Processor will provide a copy of the resulting audit report to Controller upon request.
Any audit conducted under this Section will be carried out on reasonable advance notice, during Processor’s normal business hours, and in a manner that does not unreasonably disrupt Processor’s operations.
Processor will make available to Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA upon written request.
6. CONTROLLER OBLIGATIONS
Controller represents and warrants that: (a) it has a lawful basis for processing and providing Personal Data to Processor; (b) it has provided appropriate notices to and obtained any required consents from data subjects; (c) its instructions to Processor comply with applicable law; and (d) the Personal Data it submits to Processor is limited to the categories described in Section 2.
7. GOVERNING LAW AND RELATIONSHIP TO TOS
This DPA is governed by the laws of the State of Colorado, USA, including the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) and applicable data processing requirements thereunder. This DPA supplements the NurtureSync Terms of Service available at https://www.nurturesync.io/terms-of-service. In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA controls. All other terms of the Terms of Service remain in full force and effect.
SIGNATURES
Document Control
Version: 2 — Designated as Exhibit C to NurtureSync Terms of Service · May be updated independently of TOS · July 8, 2026
| Sub-processor | Purpose | Data Location |
|---|---|---|
| DigitalOcean |
Cloud hosting and managed database |
United States |
| DigitalOcean Spaces |
File storage and CDN |
United States |
| Resend |
Transactional email delivery |
United States |
| Google OAuth |
Optional sign-in authentication |
United States |
| Stripe |
Payment processing and billing |
United States |
Processor — MPCT Solutions, LL
Authorized Signature
MPCT Solutions, LLC
Entity Name
____________________________
Name / Title
____________________________
Date
Controller — Client Organization
Authorized Signature
____________________________
Entity Name
____________________________
Name / Title
____________________________
Date