Version v1.0

Data Processing Agreement

Effective date: 12 July 2026 Last updated: 12 July 2026


1. Parties and scope

This Data Processing Agreement (the "DPA") forms part of, and is subject to, the agreement for the provision of the Nuvend service (the "Principal Agreement", being the Terms of Service at https://nuvend-ai.com/legal/terms or a signed order form) between:

each a "party" and together the "parties".

This DPA applies where, and only to the extent that, Nuvend processes Customer Personal Data as a processor on the Customer's behalf in the course of providing the Service. It reflects the parties' agreement on the processing of such data in accordance with the requirements of Data Protection Law, in particular Article 28(3) of the GDPR.

Where the Customer accepts the Principal Agreement, or continues to use the Service on or after the Effective Date, the Customer is deemed to have accepted this DPA. Where the Customer is an intermediary that is itself a processor acting on behalf of a third-party controller, references to "Controller" apply to that third party and the Customer warrants that it is authorised to enter into this DPA on the controller's instructions.


2. Definitions

Capitalised terms not defined here have the meaning given in the GDPR or the Principal Agreement.


3. Roles of the parties

3.1 Controller and Processor. For Customer Personal Data, the Customer is the Controller (or a processor acting for a third-party controller) and Nuvend is the Processor. Nuvend processes Customer Personal Data only to provide the Service and only in accordance with this DPA and the Customer's documented instructions.

3.2 Nuvend as independent controller. Nuvend is an independent controller for Account Data — including account, authentication, session, organisation, billing, and audit/operational data that Nuvend generates or collects to operate, secure, and account for the Service. Nuvend processes Account Data in accordance with the Privacy Policy and Data Protection Law. This DPA does not apply to Account Data. Nuvend does not derive independent purposes from Customer Personal Data.

3.3 Customer responsibilities. The Customer warrants that: (a) it has a valid lawful basis and, where required, has given all notices and obtained all consents necessary to authorise the processing of Customer Personal Data by Nuvend under this DPA; (b) its instructions comply with Data Protection Law; and (c) it is responsible for the accuracy, quality, and legality of the Customer Personal Data and the means by which it was obtained.

3.4 Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.


4. Processing on documented instructions (Art. 28(3)(a))

4.1 Nuvend processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law (or other applicable law) to which Nuvend is subject. In such a case, Nuvend will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

4.2 The Customer's documented instructions are constituted by: (a) the Principal Agreement; (b) this DPA; (c) the Customer's configuration and use of the Service (including the connections it authorises and the features it enables); and (d) any further written instructions agreed by the parties. The Service's functionality is the primary means by which the Customer instructs Nuvend.

4.3 Unlawful instructions. Nuvend will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Nuvend may (without liability) suspend performance of an instruction it reasonably believes to be unlawful until the Customer confirms, amends, or withdraws it. Nuvend will not process Customer Personal Data in a manner it believes violates applicable law, even if instructed to do so.


5. Confidentiality (Art. 28(3)(b))

5.1 Nuvend ensures that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and process the data only as necessary to perform their duties.

5.2 Nuvend limits access to Customer Personal Data to personnel who require it to provide, secure, or support the Service, on a least-privilege basis. Internal access to production data is restricted to authorised personnel, only for the purposes of providing technical support (with the Customer's consent), investigating security incidents, or complying with legal obligations, and all such access is logged.


6. Security (Art. 28(3)(c) and Art. 32)

6.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Nuvend implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in place as at the Effective Date are described in Annex II.

6.2 The Customer acknowledges that security measures are subject to technical progress. Nuvend may update the measures in Annex II from time to time provided the updates do not materially reduce the overall level of security of the Service.


7. Sub-processors (Art. 28(3)(d))

7.1 General authorisation. The Customer grants Nuvend general authorisation to engage Sub-processors to process Customer Personal Data, subject to this Section 7. Nuvend's current Sub-processors are listed in Annex III.

7.2 New Sub-processors. Nuvend will give the Customer at least 30 days' prior notice of the addition or replacement of any Sub-processor (by updating Annex III and notifying the Customer by email). Within that notice period the Customer may object on reasonable grounds relating to data protection.

7.3 Objection. If the Customer objects, the parties will work in good faith to resolve the objection. If no resolution is reached, the Customer may, as its sole and exclusive remedy, terminate the affected part of the Service by written notice. Absent objection within the notice period, the Sub-processor is deemed approved.

7.4 Flow-down and liability. Nuvend imposes on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA (including, where relevant, the SCCs). Nuvend remains fully liable to the Customer for the performance of each Sub-processor's obligations.


8. Assistance with Data Subject rights (Art. 28(3)(e))

8.1 Taking into account the nature of the processing, Nuvend will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making).

8.2 The Service provides self-service functionality that enables the Customer to access, export (in a structured, machine-readable format such as JSON or CSV), rectify, and delete Customer Personal Data. Where a request cannot be fulfilled through self-service, Nuvend will provide reasonable assistance on the Customer's written request.

8.3 Requests received directly. If Nuvend receives a request from a Data Subject (for example, an end customer of the Customer) relating to Customer Personal Data, Nuvend will promptly notify the Customer and will not respond to the request itself, except on the Customer's documented instruction or as required by law.

8.4 Nuvend may charge a reasonable fee for assistance that is manifestly unfounded, excessive, or that exceeds the standard functionality of the Service, having first informed the Customer.


9. Assistance with security, breach, and impact assessments (Art. 28(3)(f) and Arts. 32–36)

9.1 Taking into account the nature of processing and the information available to it, Nuvend will assist the Customer in ensuring compliance with the Customer's obligations under Articles 32 to 36 of the GDPR, including security of processing, personal data breach notification, communication of breaches to Data Subjects, data protection impact assessments, and prior consultation with a Supervisory Authority.

9.2 Breach notification. Nuvend will notify the Customer without undue delay, and in any event no later than 72 hours after Nuvend becomes aware of a Personal Data Breach affecting Customer Personal Data. The notification will, to the extent known and permitted by law, describe: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it; and (d) a contact point for further information. Where Nuvend cannot provide all information at once, it may provide it in phases without undue further delay.

9.3 The clock in Section 9.2 runs from Nuvend's confirmed awareness of a qualifying Personal Data Breach, not from the first detection of an anomaly. Nuvend's notification is not an acknowledgement of fault or liability.

9.4 Sub-processor breaches. If a Sub-processor experiences a Personal Data Breach affecting Customer Personal Data, Nuvend will notify the Customer without undue delay after becoming aware, on the same basis as Section 9.2.

9.5 Shopify. Where Customer Personal Data obtained through Shopify APIs is involved in a Personal Data Breach, Nuvend will also notify Shopify within 24 hours of discovery, as required by the Shopify Partner Program Agreement.


10. Deletion or return of data (Art. 28(3)(g))

10.1 On termination or expiry of the Service, or on the Customer's earlier written request, Nuvend will, at the Customer's choice, delete or return all Customer Personal Data and delete existing copies, unless Union, Member State, or other applicable law requires continued storage.

10.2 Deletion mechanisms. Nuvend gives effect to deletion as follows (as implemented as at the Effective Date; see Annex II):

10.3 Certification. On the Customer's written request, Nuvend will certify in writing that it has completed deletion in accordance with this Section 10.

10.4 Retained data. Where Nuvend is required by law to retain some Customer Personal Data (for example, to meet tax or accounting obligations), it will retain only the minimum necessary, inform the Customer of what is retained and the legal basis, protect it in accordance with Annex II, and process it only as required for the retention purpose until deletion is possible.

10.5 Technical impracticability. Where deletion of specific copies (for example, in encrypted backups) is not immediately technically feasible, Nuvend will securely isolate and protect such data from any further processing and delete it in the ordinary course of its backup cycle.


11. Audits and information (Art. 28(3)(h))

11.1 Nuvend will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to this Section 11.

11.2 Primary means. The Customer's audit right is satisfied in the first instance by Nuvend providing, on written request no more than once in any 12-month period: (a) its then-current third-party security certifications or audit reports (such as SOC 2 Type II or ISO 27001, once obtained); and/or (b) a completed written security questionnaire of reasonable scope. Such materials are Nuvend's confidential information.

11.3 On-site audit. Where the materials in Section 11.2 are insufficient to demonstrate compliance, or where a Supervisory Authority requires it, or following a confirmed Personal Data Breach, the Customer may conduct an on-site audit, subject to: at least 30 days' prior written notice; no more than once in any 12-month period (save where required by a Supervisory Authority or following a breach); conduct during business hours without unreasonable disruption; a duly qualified, independent auditor who is not a competitor of Nuvend and who is bound by confidentiality; and no access to other customers' data, Nuvend's proprietary information beyond what is necessary, or any data that would breach Nuvend's obligations to third parties. Each party bears its own costs.


12. International transfers

12.1 Primary processing location. Nuvend hosts and processes Customer Personal Data primarily within the European Economic Area (Netherlands). Processing that remains within the EEA does not constitute a restricted transfer.

12.2 Restricted transfers. Where the provision of the Service requires a transfer of Customer Personal Data to a country outside the EEA or the UK that is not the subject of an adequacy decision (for example, to a US-based Sub-processor), the parties agree that the transfer is governed by the appropriate transfer mechanism as follows.

12.3 EU SCCs. The parties are deemed to have entered into the EU SCCs, which are incorporated into this DPA by reference and completed as follows:

12.4 UK transfers. For transfers subject to the UK GDPR, the UK Addendum applies to and amends the EU SCCs as completed above. The information required by the UK Addendum is set out in Annex IV. Following the European Commission's renewal of the UK adequacy decision in December 2025 (valid until December 2031), personal data flows freely between the EEA and the UK; the UK Addendum therefore governs onward transfers from the UK to non-adequate third countries (for example, to US-based Sub-processors).

12.5 Supplementary measures. Nuvend applies supplementary measures to protect transferred data, including encryption in transit and at rest, access controls, and transfer impact assessments, consistent with Clauses 14 and 15 of the SCCs.

12.6 Conflict. In the event of any conflict between the SCCs (as completed) and this DPA, the SCCs prevail with respect to the relevant restricted transfer.


13. Liability

13.1 Each party's liability arising out of or in connection with this DPA (including the SCCs) is subject to the limitations and exclusions of liability set out in the Principal Agreement.

13.2 Nothing in this DPA limits either party's liability to a Data Subject under the third-party-beneficiary provisions of the SCCs, or where liability may not be limited under Data Protection Law.

13.3 Each party is responsible for any administrative fine imposed on it under Article 83 of the GDPR to the extent arising from its own breach of its obligations.


14. Term, termination, and precedence

14.1 This DPA takes effect on the Effective Date and continues for as long as Nuvend processes Customer Personal Data under the Principal Agreement. Provisions that by their nature should survive termination (including Sections 10, 11, 13 and the applicable transfer mechanisms) survive.

14.2 Order of precedence. In the event of a conflict, the following order of precedence applies: (1) the SCCs (as completed) with respect to restricted transfers; (2) this DPA; (3) the Principal Agreement; (4) the Privacy Policy.

14.3 Governing law of the DPA. Except where the SCCs require otherwise (Section 12.3), this DPA is governed by the law of Ireland, and the parties submit to the exclusive jurisdiction of its courts, without prejudice to any Data Subject's or Supervisory Authority's rights under Data Protection Law.

14.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect.

14.5 Changes. Nuvend may update this DPA to reflect changes in Data Protection Law, guidance from Supervisory Authorities, or the transfer mechanisms it relies on, provided such updates do not materially reduce the protection of Customer Personal Data. Material changes will be notified in accordance with the Principal Agreement.


Annex I — Description of the processing (and SCC Annex I)

Part A — List of parties (SCC Annex I.A)

Data exporterData importer
NameThe Customer, as identified in the Principal AgreementNuVend AI Ltd, trading as Nuvend
AddressAs in the Principal AgreementBirr Technology Centre, Birr, Co. Offaly, R42 HX39
ContactThe Customer's administrator accountprivacy@nuvend-ai.com
RoleController (or processor for a third-party controller)Processor
Activities relevant to the transferUse of the Service to analyse and manage the Customer's connected-platform dataProvision of the Service (data analytics, reporting, and platform management)

For Module Three transfers, the data exporter is Nuvend (Processor) and the data importer is the relevant Sub-processor listed in Annex III, whose role is Sub-processor.

Part B — Description of the transfer (SCC Annex I.B)

ItemDetail
Categories of Data SubjectsThe Customer's own customers and contacts whose data appears in the connected platforms (e.g. purchasers, leads, support contacts, marketing subscribers), and the Customer's personnel where they appear in that data.
Categories of Personal DataDepending on the platforms connected: names; email addresses; telephone numbers; postal, billing and shipping addresses; order and transaction details; marketing-consent status; customer tags and notes; support-ticket contents; and other fields contained in the raw records provided by the connected platform's API.
Special categories of dataNone intended or requested. The Customer must not use the Service to process special-category data (Art. 9) unless separately agreed in writing.
Nature and purpose of processingAccessing, syncing, storing, organising, structuring, analysing, displaying, and (where the Customer enables it) writing back data to the connected platforms, in order to provide unified analytics, reporting, and management features, including AI-assistant features that are integral to the Service.
DurationFor the duration of the connection and the Principal Agreement, plus the retention/deletion periods in Section 10 and the Privacy Policy.
FrequencyContinuous / on an ongoing basis (periodic sync and real-time webhooks).
Subject matterProvision of the Nuvend Service.

Part C — Competent Supervisory Authority (SCC Annex I.C)

For Module Three transfers where Nuvend is the exporter, the competent authority is the Irish Data Protection Commission (DPC), as Nuvend is established in Ireland. For Module Two transfers, Nuvend is the data importer, not the exporter, and the competent authority is that of the Customer's (exporter's) place of establishment in the EEA. Where the Customer is established outside the EEA, the competent authority is determined under Clause 13(a)–(c) of the SCCs.

Note — establishment, not hosting. Nuvend's legal entity (NuVend AI Ltd) is established in Ireland (an EEA member state), so Irish law and the Irish DPC apply as above. This is distinct from where infrastructure is hosted (Railway's EU region, the Netherlands); the hosting region does not change the governing-law or competent-authority allocation.


Annex II — Technical and organisational measures (and SCC Annex II)

These measures describe the technical and organisational controls in place as at the Effective Date. Nuvend keeps these measures under review and may update them from time to time, provided that any update does not materially reduce the overall level of security.

Encryption

Access control and tenant isolation

Audit logging

Data minimisation, deletion, and resilience

Infrastructure and organisational measures

Measures for Sub-processor transfers (SCC Annex II, Module Three)

For transfers to Sub-processors, Nuvend requires, by contract, technical and organisational measures no less protective than those above, encryption in transit, and processing limited to the purposes in Annex III.


Annex III — Sub-processors (and SCC Annex III)

This Annex lists only Sub-processors that process Customer Personal Data (the data Nuvend handles as processor). Third parties that process only Account Data — for which Nuvend is an independent controller (Section 3.2) — fall outside this DPA and are disclosed in the Privacy Policy; they are listed separately below for transparency. As at the Effective Date:

Active Sub-processors of Customer Personal Data (SCC Annex III)

Sub-processorPurposeCategories of Customer Personal DataLocationTransfer mechanism
Railway (Railway Corporation)Application and database hosting (PostgreSQL, ClickHouse, Redis, Electric sync)All Customer Personal Data processed by the ServiceEU (Netherlands) primaryProcessing within the EEA; SCCs + UK Addendum in the Railway DPA for any non-EEA processing
Anthropic (Anthropic PBC)AI inference for the AI assistantUser queries and business data retrieved during AI interactions (may include Customer Personal Data)United StatesEU SCCs (Module Three) + UK Addendum; zero data retention for inference; no training
Langfuse (Langfuse GmbH)AI quality monitoring and observabilityAI conversation traces, prompts, completions (may include Customer Personal Data)EU (Germany)Processing within the EEA

Account-Data processors (outside this DPA — governed by the Privacy Policy)

These process only Account Data (Nuvend as controller), not Customer Personal Data, and are therefore not Sub-processors under this DPA. Listed for completeness:

ProviderPurposeDataStatus
Resend (Plus Five Five, Inc.)Transactional / invitation emailRecipient email, names, organisation namesActive
Autumn (useautumn.com)Billing and subscription managementOrganisation identifiers, name, email, usage dataActive — no published DPA/SCCs/DPF; DPA + SCCs to be requested (security@useautumn.com). Payment data remains in Nuvend's own Stripe account.
Stripe (Stripe, Inc.)Payment processingPayment method, billing address, organisation identifiersActive — DPF (certified)

Annex IV — UK Addendum details

Where the UK Addendum applies (Section 12.4), the parties complete its tables as follows:


This Data Processing Agreement was last updated on 12 July 2026.