‍ ‍

EXHIBIT C TO NURTURESYNC TERMS OF SERVICE

‍ ‍

NURTURESYNC

DATA PROCESSING AGREEMENT‍ ‍

This Agreement is entered into between MPCT Solutions, LLC (“Processor”) and the Client identified below (“Controller”).

This DPA supplements and is incorporated into the NurtureSync Terms of Service.

‍ ‍

Controller (Client): ____________________________   Effective Date: ____________________________

‍ ‍‍ ‍

1.  DEFINITIONS‍ ‍

Controller: The Client organization that determines the purposes and means of processing personal data through the NurtureSync Service.

Processor: MPCT Solutions, LLC, which processes personal data on behalf of the Controller in connection with providing the NurtureSync Service.

Personal Data: Any information relating to an identified or identifiable individual that Controller uploads, stores, or processes through the Service, limited to the categories described in Section 2.

Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.

2.  SCOPE AND PURPOSE OF PROCESSING

Processor processes Personal Data solely to provide the NurtureSync Service as described in the Terms of Service, including hosting, storage, backup, and data export. Processor will not process Personal Data for any purpose other than as instructed by Controller or as required by applicable law.

Categories of Personal Data: Account information (names, email addresses, phone numbers), organizational data (roles, permissions), usage activity data, and uploaded content as provided by Controller.

Duration: Processing continues for the duration of Controller’s active subscription and ends upon termination, after which data is deleted or returned per the NurtureSync Cancellation and Refund Policy and Section 3 of this DPA.

3.  PROCESSOR OBLIGATIONS

3.1 Processor is responsible for:

  • Processing Personal Data only on Controller’s documented instructions and as permitted under the Terms of Service

  • Implementing and maintaining appropriate technical and organizational security measures for the Service infrastructure to protect Personal Data against unauthorized access, loss, or disclosure

  • Notifying Controller without undue delay, and where practicable within 72 hours, upon becoming aware of a Personal Data breach

  • Assisting Controller in responding to data subject rights requests to the extent reasonably practicable given the nature of the processing

  • Deleting or returning all Personal Data to Controller at the choice of Controller upon termination of the subscription, unless retention is required by applicable law

  • Ensuring that persons authorized to process Personal Data are subject to confidentiality obligations

  • Making available to Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA

3.2 Controller is responsible for:

  • Configuring its use of the Service appropriately for its needs and applicable legal requirements

  • Safeguarding its account credentials and controlling user access within its tenant

  • The lawfulness, accuracy, and appropriateness of the Personal Data it submits to the Service

  • Ensuring that Personal Data submitted to Processor is limited to the categories described in Section 2

  • Providing appropriate notices to and obtaining any required consents from data subjects whose Personal Data is submitted to the Service

4.  SUB-PROCESSOR‍ ‍

Controller authorizes Processor to engage the following sub-processors in connection with the Service: ‍

‍ ‍

Processor will notify Controller of any intended changes to sub-processors with reasonable advance notice. Controller may object to a new sub-processor within 15 days of notice; if Processor cannot reasonably accommodate the objection, either party may terminate this DPA.

5.  AUDIT RIGHTS AND COMPLIANCE DEMONSTRATION

In accordance with Colorado law, Processor will allow for and contribute to reasonable audits and inspections by Controller or Controller’s designated auditor to verify Processor’s compliance with this DPA.

Alternatively, Processor may, with Controller’s consent, arrange for a qualified and independent auditor to conduct, at least annually and at Processor’s expense, an audit of Processor’s policies and technical and organizational measures using an appropriate and accepted control standard, framework, and audit procedure. Processor will provide a copy of the resulting audit report to Controller upon request.

Any audit conducted under this Section will be carried out on reasonable advance notice, during Processor’s normal business hours, and in a manner that does not unreasonably disrupt Processor’s operations.

Processor will make available to Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA upon written request.

6.  CONTROLLER OBLIGATIONS

Controller represents and warrants that: (a) it has a lawful basis for processing and providing Personal Data to Processor; (b) it has provided appropriate notices to and obtained any required consents from data subjects; (c) its instructions to Processor comply with applicable law; and (d) the Personal Data it submits to Processor is limited to the categories described in Section 2.


7.  GOVERNING LAW AND RELATIONSHIP TO TOS

This DPA is governed by the laws of the State of Colorado, USA, including the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) and applicable data processing requirements thereunder. This DPA supplements the NurtureSync Terms of Service available at https://www.nurturesync.io/terms-of-service. In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Data, this DPA controls. All other terms of the Terms of Service remain in full force and effect. ‍

SIGNATURES

‍ ‍ ‍

‍ ‍

Document Control

Version: 2 — Designated as Exhibit C to NurtureSync Terms of Service · May be updated independently of TOS · July 8, 2026

‍ ‍


Sub-processor Purpose Data Location
DigitalOcean 

Cloud hosting and managed database

United States
DigitalOcean Spaces

File storage and CDN

United States
Resend

Transactional email delivery

United States
Google OAuth

Optional sign-in authentication

United States
Stripe

Payment processing and billing

United States

Processor — MPCT Solutions, LL

Authorized Signature

MPCT Solutions, LLC

Entity Name

____________________________

Name / Title

____________________________

Date

Controller — Client Organization

Authorized Signature

____________________________

Entity Name

____________________________

Name / Title

____________________________

Date

‍ ‍

‍ ‍