DPA
Dated:
This Data Processing Agreement ("DPA") forms part of the agreement ("Agreement") between Nusu Inc. ("Nusu", "we", "us", or "our") and the customer entity that has agreed to Nusu's Terms of Service ("Customer", "you", or "your").
This DPA applies where and to the extent that Nusu processes Personal Data on behalf of Customer as a Data Processor in the provision of the Services.
In this DPA:
"Applicable Data Protection Law" means all applicable laws and regulations relating to data protection and privacy, including without limitation the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, and the California Consumer Privacy Act ("CCPA"), as may be amended or superseded from time to time.
"Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Processing", and "Processor" shall have the meanings given to them in the GDPR, and related terms shall be construed accordingly.
"Customer Data" means any Personal Data that Nusu processes on behalf of Customer as a Processor in connection with the Services.
"Services" means the services provided by Nusu to Customer pursuant to the Agreement.
"Sub-processor" means any third party engaged by Nusu to process Customer Data on behalf of Customer.
2.1 Roles. The parties acknowledge and agree that with regard to the Processing of Customer Data:
2.2 Customer Responsibilities. Customer shall ensure that:
3.1 Processing Instructions. Nusu shall:
3.2 Purpose Limitation. Nusu shall process Customer Data solely to provide the Services in accordance with the Agreement and shall not process Customer Data for any other purpose.
3.3 Confidentiality. Nusu shall ensure that all personnel authorized to process Customer Data:
4.1 Security Measures. Nusu shall implement and maintain appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data ("Security Measures"), including without limitation:
4.2 Updates to Security Measures. Nusu may update or modify the Security Measures from time to time, provided that such updates and modifications do not materially decrease the overall protection of Customer Data.
5.1 Authorized Sub-processors. Customer agrees that Nusu may engage Sub-processors to process Customer Data on Nusu's behalf. The current list of Sub-processors is set out in Annex A.
5.2 Sub-processor Obligations. Where Nusu engages a Sub-processor:
5.3 Changes to Sub-processors. Nusu may add or replace Sub-processors by:
6.1 Assistance with Data Subject Requests. Nusu shall, taking into account the nature of the processing, provide reasonable assistance to Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
6.2 Data Subject Request Procedure. If Nusu receives a request from a Data Subject regarding Customer Data, Nusu shall:
7.1 Breach Notification. If Nusu becomes aware of a Personal Data Breach affecting Customer Data, Nusu shall:
7.2 Breach Information. Such notification shall include:
8.1 Audit Rights. Nusu shall make available to Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
8.2 Audit Procedure. Customer may exercise its audit rights by:
9.1 Data Location. Customer Data will be processed in the United States and other jurisdictions where Nusu or its Sub-processors maintain operations.
9.2 International Transfers. Where Customer Data is transferred outside of the European Economic Area, UK, or other jurisdiction with data transfer restrictions, Nusu shall ensure appropriate safeguards are in place, including:
10.1 Return or Deletion. Upon termination of the Agreement, Nusu shall, at Customer's election:
10.2 Retention. Notwithstanding the above, Nusu may retain Customer Data:
11.1 Regulatory Assistance. Nusu shall provide reasonable assistance to Customer with:
11.2 Costs. Customer shall reimburse Nusu for reasonable costs incurred in providing assistance beyond Nusu's standard support obligations.
12.1 Liability. Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Agreement.
12.2 Indemnification. Each party shall defend, indemnify, and hold harmless the other party from and against any claims, damages, losses, and expenses arising from its breach of this DPA.
13.1 Governing Law. This DPA shall be governed by the same law as the Agreement.
13.2 Modification. This DPA may only be modified by written agreement of both parties.
13.3 Severability. If any provision of this DPA is held to be unenforceable, the remaining provisions shall continue in full force and effect.
13.4 Entire Agreement. This DPA, together with the Agreement, constitutes the entire agreement between the parties regarding the processing of Customer Data.
13.5 Conflict. In the event of conflict between this DPA and the Agreement, this DPA shall control with respect to the processing of Customer Data.
The following third-party Sub-processors are authorized to process Customer Data:
| Sub-processor | Service Provided | Location | Purpose |
|---|---|---|---|
| Vercel Inc. | Infrastructure & Hosting | United States | Application hosting and content delivery |
| Neon, Inc. | Database Services | United States | Database infrastructure and storage |
| Amazon Web Services, Inc. | Cloud Infrastructure | United States | Cloud computing and storage services |
| Stripe, Inc. | Payment Processing | United States | Payment processing, subscription management, and billing |
| RudderStack Inc. | Analytics | United States | Customer data platform and analytics infrastructure |
| Resend Inc. | Email Services | United States | Transactional email delivery (authentication, notifications) |
This list may be updated from time to time in accordance with Section 5.3 of this DPA.
Categories of Data Subjects:
Categories of Personal Data:
Nature and Purpose of Processing:
Duration of Processing:
BY ACCEPTING THE TERMS OF SERVICE OR USING THE SERVICES, CUSTOMER AGREES TO BE BOUND BY THIS DATA PROCESSING AGREEMENT.
For questions about this DPA, please contact: privacy@nusu.ai
Nusu Inc.
10161 W Park Run Dr Ste 150
Las Vegas, NV 89145 United States
Phone: (+1) 844-244-4448
Fax: (+1) 844-244-4449
Email: help@nusu.ai