Data Processing Agreement
Where you enter personal data about your own customers, you are the controller and NEXOGEN S.R.L. is your processor (GDPR Art. 28). It forms part of the Terms of Service.
Version 1.0Effective August 15, 2026
About this agreement
This Data Processing Agreement forms part of the Terms of Service and governs NEXOGEN S.R.L.'s processing of personal data on your behalf as your processor. It applies for as long as we process that data for you. Where it conflicts with the Terms on a data-protection matter, this DPA prevails.
1. Roles and subject-matter
You (the customer) are the controller and NEXOGEN S.R.L. (Societate cu Răspundere Limitată (S.R.L.)), Bucureşti Sectorul 6, Calea Giulești, Nr. 42, camera 2, Bl. 8, Scara c, Etaj 3, Ap. 81, RO (reg. J2026025947001), is the processor. We process personal data to provide NEXOGEN to you, for the duration of your agreement with us. This DPA prevails over the Terms on data-protection matters.
2. Nature, purpose and data
- Nature and purpose: hosting, storing and processing your business records so the features you enable (CRM, communications, scheduling, and similar) operate.
- Data subjects: the people whose data you choose to store — typically your customers, contacts, leads and staff.
- Personal data: identifiers such as name, email and phone, communications content, and other fields you configure. You may store special-category data (for example clinical or health-related notes in patient-oriented verticals); you are responsible for having a valid Art. 9 condition and lawful basis for it.
3. Processing on your instructions
We process personal data only on your documented instructions, which include your configuration and use of the service and this DPA, unless the law requires otherwise (in which case we tell you, unless prohibited). We inform you if, in our opinion, an instruction infringes data-protection law.
4. Confidentiality
People we authorise to process your personal data are bound by appropriate confidentiality obligations.
5. Security (Art. 32)
- Tenant isolation enforced in the database (row-level security), not in the interface.
- Least-privilege access; sensitive operations run under controlled, server-side privileges.
- Append-only audit logging of security-relevant actions.
- Encryption of personal data in transit; private storage for uploaded files.
- Signed application releases and managed secrets.
6. Subprocessors
You give a general authorisation to the subprocessors listed on the Subprocessors page, who process on our behalf under equivalent data-protection obligations. We give you notice of an intended addition or replacement so you can object on reasonable data-protection grounds before it takes effect.
7. Assisting with data-subject requests
Taking account of the nature of processing, we assist you to respond to data-subject requests. We provide tooling to export and to erase personal data. Some records are erased by overwriting identifiers; consent and opt-out records are retained as evidence of lawfulness and to honour suppression; and certain free-text, AI-conversation, uploaded-document and bulk-import stores are removed through retention schedules rather than per-record deletion. We describe these behaviours so your responses to data subjects are accurate.
8. Personal-data breach
We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations (Art. 33–34).
9. Deletion or return
On termination you can export your data. At your choice we then delete or return your personal data, except where the law requires retention. Backup snapshots are provider-managed and expire on their own schedule, so they cannot be selectively erased before then.
10. Audits and information
We make available the information reasonably needed to demonstrate compliance with Art. 28. We allow for and contribute to audits at most once in any twelve-month period, on at least 30 days' written notice, during business hours and without disrupting the service, and subject to reasonable confidentiality and security conditions — or more often if a supervisory authority requires it or following a personal-data breach affecting your data. Where available, a current independent report or certification may be provided to satisfy an audit request.
11. International transfers
We and our subprocessors process your data in the European Union where configured. Where a subprocessor processes personal data outside the European Economic Area, the transfer relies on an appropriate safeguard under Chapter V GDPR — normally the European Commission's standard contractual clauses (the controller-to-processor module, or the module applicable to the subprocessor), incorporated by reference and completed with the parties' details, together with a transfer risk assessment where required. AI features do not process real customer data until those safeguards are confirmed with the provider.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA increases a party's liability beyond those limits, except to the extent GDPR or other mandatory law requires otherwise (including Art. 82 liability towards data subjects).