0. Definitions and order of precedence
"Customer Personal Data" means personal data that we process on your behalf under the services. "UK Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and any UK secondary legislation or binding ICO guidance in force from time to time. Capitalised terms not defined here have the meaning given in the main agreement or in UK Data Protection Law.
This DPA applies solely to our processing of Customer Personal Data as a processor. In the event of any conflict between this DPA and the main agreement, this DPA prevails to the extent of the conflict and only in respect of data protection matters. In the event of any conflict between this DPA and the platform terms of a third-party channel you connect (including Meta's Business Terms, WhatsApp Business Solution Terms, or Google's API Services User Data Policy), the applicable platform terms prevail as between you and that platform, and this DPA continues to govern the processing we carry out as your processor.
1. Roles
In respect of Customer Personal Data, you are the data controller and NUVENAR LTD (company number 17240693, registered office 128 City Road, London, EC1V 2NX; ICO registration ZC228344) is the data processor. Where we process data for our own purposes (including billing, account administration, service security, fraud prevention, aggregated product analytics, and any statutory record-keeping), we act as an independent controller for that limited processing, as described in our privacy policy. You are solely responsible for establishing the lawful basis for all Customer Personal Data you route through the services and for obtaining and maintaining any consents required from data subjects.
2. Subject matter, duration, nature and purpose
Subject matter: personal data submitted to, or generated by, your use of the services.
Duration: for the term of your subscription or statement of work, plus the return or deletion window in section 12.
Nature and purpose: hosting, storage, transmission, analysis, backup, and support of the services you have subscribed to, including delivery of messages across the channels you connect (WhatsApp, Instagram, Messenger, email, SMS, voice), workflow automation, and AI-assisted features you enable.
3. Types of personal data and categories of data subjects
Data subjects: your customers, prospects, staff, contacts and other individuals whose data you upload or route through the services.
Categories of data: contact identifiers (name, phone, email, social handles), conversation content (messages, call recordings and transcripts where enabled, email bodies), commercial data (bookings, invoices, deal history), technical identifiers (IP, device, cookies for the services you host), and any additional fields you add to your CRM. No special category data (UK GDPR Article 9) or criminal offence data unless we agree in writing in advance.
4. Documented instructions
We process Customer Personal Data only on your documented instructions, including as to transfers outside the UK. The main agreement, this DPA, and your configuration and use of the services together constitute your complete and final documented instructions to us for the term. Additional or alternative instructions must be agreed with us in writing and, where they materially change the nature or scope of processing, may be subject to reasonable additional charges or a change to the services. We are not obliged to review your instructions for legal compliance; where an instruction is, in our reasonable opinion, manifestly infringing of UK Data Protection Law, we may notify you and (without further liability) suspend the affected processing pending clarification.
5. Confidentiality
Staff and contractors authorised by us to access Customer Personal Data are bound by written confidentiality obligations, or an appropriate statutory duty of confidence, that survive the end of their engagement.
6. Security (Article 32)
We implement and maintain technical and organisational measures appropriate to the risk, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. Current measures are summarised in our security overview and include TLS in transit, encryption at rest for the primary datastore, role-based access with multi-factor authentication for staff, hardened production hosts, automated backups with tested restores, centralised logging, vulnerability scanning, and a written incident response plan. We may update these measures at any time, provided the overall level of protection is not materially reduced. You are responsible for using the security features made available to you (including staff access controls, IP restrictions, retention settings, and audit logs).
7. Sub-processors
You give us general written authorisation to appoint sub-processors to assist in providing the services. The current list of authorised sub-processors is published in our privacy policy and includes, without limitation, Stripe, Resend, Cloudflare, Hetzner, Anthropic, OpenAI, Twilio, Telnyx, Meta Platforms Ireland (for WhatsApp, Messenger and Instagram, where you connect them), and Google Ireland (for Google Sign-In, where you use it). Each sub-processor is engaged under written terms that impose data protection obligations substantially equivalent to those set out in this DPA in respect of the processing they carry out.
We will give notice of any intended addition or replacement of a sub-processor by updating the published list at least 15 days before the change takes effect (or such shorter period as is reasonable where the change is required for security, legal or regulatory reasons). You may object in writing within that notice period on reasonable data protection grounds. If we cannot, in our reasonable discretion, address the objection, your sole remedy is to terminate the affected services on written notice. Termination in these circumstances does not entitle you to a refund of paid fees or to damages. A change of control, corporate restructure, or replacement of a sub-processor with an affiliate providing the same service does not constitute a new sub-processor for the purposes of this section.
8. International transfers
The services are operated from data centres inside the UK and EEA wherever practicable. Where Customer Personal Data is transferred to, or accessed from, a country outside the UK, we rely on one or more of the following transfer mechanisms, as we determine appropriate for the transfer in question:
- a UK adequacy regulation in force at the time of transfer (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is validly certified);
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to the EU Commission's 2021 Standard Contractual Clauses; or
- any other lawful safeguard permitted under UK Data Protection Law.
Where required, we complete a transfer risk assessment before the transfer and put in place any supplementary measures we consider appropriate. You are responsible for satisfying yourself that your own use of the services (including the countries from which you and your users access it) is compatible with your controller obligations.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification will be made to the administrative contact on file for your account and will include, to the extent then known and permitted by law: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Our notification does not constitute an acknowledgement of fault or liability. You are solely responsible for assessing the breach against your own reporting obligations to the ICO or affected data subjects and for making any required notifications.
10. Assistance with your obligations
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you meet your obligations under UK GDPR Articles 32 to 36 and to respond to data subject rights requests under Chapter III (access, rectification, erasure, restriction, portability, objection). Assistance is provided by making available the self-service tools and documented processes within the services. Where you request assistance beyond that (including custom data extractions, drafting of responses to data subjects, participation in DPIA workshops, or engagement with a supervisory authority on your behalf), we may recover our reasonable costs at our then-current professional-services rates. We are not responsible for the accuracy or legal sufficiency of any response you give to a data subject or regulator.
11. Audits
We will make available to you the information reasonably necessary to demonstrate compliance with the obligations in Article 28. In the ordinary course, this is satisfied by the security overview, sub-processor list, DPA, and any then-current third-party audit reports or certifications we hold.
Where the information above is not sufficient, you may request an audit once per rolling 12-month period, on at least 60 days' written notice, subject to the following: the audit is desk-based unless we agree otherwise; the auditor is not a competitor of ours and is bound by written confidentiality obligations equivalent to those in the main agreement; the audit is limited to information directly relevant to the processing of your Customer Personal Data; the scope, timing and location are agreed with us in advance; the audit does not disrupt the services or expose the confidential information of other customers; and you bear all costs, including our reasonable costs of participation. Audit findings are confidential and may not be disclosed to third parties without our prior written consent, save as required by law or regulator. This section does not entitle you to access any information the disclosure of which would breach a duty owed by us to a third party.
12. Return or deletion at end of contract
On the effective date of termination or expiry of the services, and provided you have paid all outstanding fees, you may request within 30 days (a) the return of a copy of Customer Personal Data in the format we then make available for export, or (b) its deletion. If we receive no request within that period, we will delete Customer Personal Data from active production systems within 90 days after termination. Copies held in backups, disaster-recovery snapshots, or immutable audit logs will be deleted in accordance with our standard backup and retention schedules and, until then, remain subject to this DPA. We are entitled to retain Customer Personal Data to the extent required by law, to establish, exercise or defend legal claims, or in aggregated and anonymised form that can no longer be associated with an identifiable individual.
13. Aggregated and anonymised data
We may generate and use aggregated, statistical, de-identified or anonymised data derived from Customer Personal Data to operate, improve, secure and develop the services and our business, including for benchmarking, research and product analytics, provided such data does not identify you or any data subject and cannot be reasonably re-identified. Such data is not Customer Personal Data and is not subject to this DPA.
14. Channel-specific flow-downs
Where you connect a third-party channel to the services (including WhatsApp Business Platform, Instagram, Messenger, Google Sign-In, or any other channel we support from time to time), you acknowledge that:
- your use of that channel is governed by the platform's own terms and policies (including Meta's Business Terms, WhatsApp Business Solution Terms, WhatsApp Business Messaging Policy, Instagram Platform Policy, Messenger Platform Policy, the Google API Services User Data Policy, and any successor terms), and you are responsible for compliance with them;
- data made available to us by that platform is processed by us only for the purpose of operating the connected features you have enabled, and in line with the applicable platform terms;
- the platform may act as an independent controller or joint controller of the data as between it and you, and this DPA does not purport to modify those platform-to-customer relationships;
- you are responsible for obtaining and maintaining any consents required from data subjects to receive messages, calls, or automated communications through the connected channel; and
- we may be required by the platform to suspend or restrict features, disable message templates, or delete data on receipt of a platform direction, and we may act on such directions without further liability to you.
15. Regulator cooperation and third-party requests
Each party will cooperate in good faith with the ICO or any other competent supervisory authority in the performance of its tasks. Where we receive a communication from a supervisory authority, or a legally binding request from a public authority, that relates to Customer Personal Data, we will notify you promptly unless legally prohibited from doing so, and will where lawful redirect the request to you to handle in the first instance. We are not obliged to challenge the validity of any such request, but we will not disclose Customer Personal Data beyond what is required by the request or by applicable law.
16. Records of processing
We maintain the records of processing activities required by UK GDPR Article 30(2) and will make them available to the ICO on request.
17. Liability
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the main agreement (including any aggregate cap on liability), and for these purposes all claims under or in connection with this DPA are treated as claims under the main agreement. Nothing in this DPA excludes or limits either party's liability to a data subject under UK GDPR Article 82 or any liability that cannot lawfully be excluded or limited. As between the parties, each party is responsible for its own acts and omissions and those of its personnel, and (subject to Article 82(4)) neither party is liable for the acts or omissions of the other.
18. Governing law and jurisdiction
This DPA is governed by the laws of England and Wales. Any dispute arising out of or in connection with this DPA is subject to the exclusive jurisdiction of the English courts.
19. Changes to this DPA
We may update this DPA from time to time to reflect changes in law, ICO guidance, sub-processor arrangements, or the services. Where a change materially reduces your rights, we will give at least 30 days' notice by email to the administrative contact on file or by an in-app notice, and the change takes effect at the end of that period. Continued use of the services after the effective date constitutes acceptance.
20. Contact
Data protection enquiries: support@nuvenar.com. We are not required to appoint a statutory Data Protection Officer under UK GDPR Article 37(1). The named contact above is our data protection lead for the purposes of this DPA.