Data Processing Agreement
1. Roles
Customer acts as Data Controller.
NEXXIO SA acts as Data Processor.
2. Scope of Processing
NEXXIO processes personal data on behalf of the Customer solely for the purpose of providing the Service, in accordance with the Customer's documented instructions.
3. Sub-Processors
The Customer authorizes the use of the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication | EU / US |
| Stripe | Payment processing | US / IE |
| Vercel / Cloudflare | Hosting, CDN | Global |
| OpenAI / Groq / DeepSeek | LLM inference | US / EU |
| SendGrid / Twilio | Email, SMS delivery | US |
Any change to this list will be notified at least 30 days in advance.
4. Security Measures
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Access control based on least privilege
- Multi-tenant data isolation
- Continuous monitoring and incident response
- Regular penetration testing and audits
5. Data Subject Rights
NEXXIO assists the Customer in fulfilling data subject requests (access, rectification, erasure, portability) within the legally required timeframes.
6. International Transfers
Where data is transferred outside the EU/EEA, appropriate safeguards apply (Standard Contractual Clauses, adequacy decisions, or equivalent).
7. Data Breach Notification
NEXXIO will notify the Customer without undue delay (within 72 hours maximum) after becoming aware of any personal data breach.
8. Audit Rights
The Customer may request a copy of our latest SOC 2 report or schedule an audit (subject to confidentiality and reasonable notice).
9. Termination
Upon termination, NEXXIO will delete or return all personal data within 90 days, unless a longer retention period is required by law.
10. Contact
To receive a signed DPA, email [email protected].