Legal
Data Processing Addendum
Last updated August 10, 2026
This addendum governs the processing of personal data that [Company Legal Name] carries out on behalf of a customer as a processor. It forms part of the Terms of Service.
1. Scope and roles
This Data Processing Addendum (the DPA) applies where [Company Legal Name] (the Processor) processes Personal Data on behalf of the Customer (the Controller) in the course of providing ITAD CRM (the Services). It forms part of, and is subject to, the Terms of Service. Where applicable data protection law requires a signed agreement, the Customer may request one at legal@nextus.ai.
2. Definitions
Applicable Data Protection Law means all privacy and data protection laws that apply to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended (CCPA/CPRA). Personal Data, processing, controller, processor, and data subject have the meanings given in Applicable Data Protection Law. Customer Personal Data means Personal Data contained in Customer Data that the Processor processes on the Controller's behalf.
3. Processing details
The subject matter, nature, and purpose of the processing, the duration, the types of Personal Data, and the categories of data subjects are described in Annex I. The Processor will process Customer Personal Data only to provide the Services and only in accordance with the Controller's documented instructions, including as set out in the Terms, this DPA, and the Controller's use of the Services.
4. Controller instructions and responsibilities
The Controller is responsible for the accuracy and legality of Customer Personal Data and for having a valid legal basis to collect and process it — including the lead and prospect data it imports. The Controller instructs the Processor to process Customer Personal Data as necessary to provide the Services. The Processor will inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
5. Confidentiality
The Processor ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only on instruction.
6. Security measures
The Processor implements and maintains appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II, taking into account the state of the art, the costs of implementation, and the risks to data subjects.
7. Sub-processors
The Controller authorizes the Processor to engage the sub-processors listed in Annex III to process Customer Personal Data. The Processor imposes data protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance. The Processor will give the Controller reasonable notice of any intended addition or replacement of a sub-processor; the Controller may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection.
8. Data subject requests
Taking into account the nature of the processing, the Processor will assist the Controller with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. Where the Processor receives such a request directly, it will refer the data subject to the Controller.
9. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Controller meet its own notification obligations.
10. Data protection impact assessments
The Processor will provide the Controller with reasonable assistance, taking into account the nature of the processing and the information available to it, with data protection impact assessments and prior consultations with supervisory authorities.
11. Return and deletion
On termination of the Services, the Processor will, at the Controller's choice, make Customer Personal Data available for export for a limited period and thereafter delete or de-identify it, unless retention is required by law.
12. Audits
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice, during business hours, subject to confidentiality, and no more than once per year unless required by a supervisory authority.
13. International transfers
Where the Processor transfers Customer Personal Data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, such transfers are governed by the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this DPA by reference.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
Annex I — Details of processing
- Subject matter and duration: processing of Customer Personal Data for the term of the Services and the retention period described in section 11.
- Nature and purpose: hosting, storing, organizing, deduplicating, routing, enriching (on Controller trigger), and displaying lead and pipeline data to provide the Services.
- Categories of data subjects: the Controller's leads, prospects, clients, and business contacts, and the Controller's own members and users.
- Types of Personal Data: names, business email addresses, phone numbers, job titles, company names, and engagement and pipeline metadata submitted by or on behalf of the Controller. The Services are not intended for special categories of Personal Data.
Annex II — Technical and organizational measures
- encryption of Personal Data in transit (TLS) and at rest;
- multi-tenant isolation enforced at the database layer (row-level security), so a workspace can access only its own data;
- role-based access controls and least-privilege administrative access;
- authentication with hashed credentials and session management;
- audit logging of administrative actions;
- regular backups and a documented restore capability;
- use of reputable infrastructure providers with recognized security certifications;
- logical separation of production data and controlled change management.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, backend hosting | United States |
| Vercel | Application hosting and content delivery | United States |
| Stripe | Payment processing and subscription billing | United States |
| Resend | Transactional email delivery | United States |
| Clay | Data enrichment (triggered by the Controller) | United States |
Contact
For questions about this DPA or to request a signed copy, contact legal@nextus.ai.