This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the Customer (“Controller”) and Nodara GmbH (“Processor”) when the Customer processes personal data of individuals located in the EU, UK, or Switzerland while using the Service.
This DPA is automatically accepted at signup for accounts with an EU billing address, and available on request to any other customer. To countersign a paper version, email legal@nodara.host.
1. Roles
The Customer is the Controller of personal data processed on Nodara infrastructure. Nodara is a Processor acting on the Customer's documented instructions. Nodara does not determine the purposes or means of processing customer content.
2. Nature and purpose of processing
- Nature: hosting, storage, and network transport of data that the Customer places on Nodara instances.
- Duration: for the lifetime of each instance, plus up to 30 days for post-destruction backups.
- Types of data: whatever the Customer places on the instance. Nodara does not inspect content.
- Categories of data subjects: end users of the Customer's application(s).
3. Sub-processors
Nodara uses the sub-processors listed on the legal hub. Customer approves each of them on signature of this DPA. Nodara will give at least 30 days' notice before engaging a new sub-processor, and Customer may object during that period. Objection means Customer may terminate the affected portion of the Service and receive a prorated refund.
4. Technical and organizational measures
- Encryption at rest: AES-256-XTS on all NVMe volumes, keys managed by our KMS with per-tenant scoping.
- Encryption in transit: TLS 1.3 for the control plane, WireGuard between our datacenters, IPsec for inter-region private networking.
- Access control: role-based, SSO-only for employees, hardware key required for production access, quarterly access reviews.
- Logging: all admin access is logged and reviewed weekly. Logs are retained 90 days, then aggregated.
- Certifications: SOC 2 Type II, ISO 27001, GDPR compliance audit annually.
5. Assistance to the Controller
Nodara will assist the Controller with responding to data-subject requests (Articles 12-23 GDPR) and with security-incident notification under Article 33. Standard assistance is included; specific requests that require significant engineering effort will be quoted.
6. International transfers
For transfers of personal data from the EU/EEA/UK/Switzerland to Nodara Systems, Inc. (US), the parties rely on the EU-US Data Privacy Framework certification and, as a fallback, the 2021 Standard Contractual Clauses (Module 3, Processor-to-Processor) which are hereby incorporated.
7. Return or deletion at termination
On termination, Customer can export all data via the dashboard or API for 30 days. After that, all data is deleted from primary storage within 7 days and from backups within 30 days. Nodara will certify deletion in writing on request.
8. Audits
Customer may audit Nodara's compliance with this DPA once per year, on 30 days' written notice. In practice, our SOC 2 Type II report satisfies this obligation for most customers — request it from legal@nodara.host under NDA.