Data Processing Agreement
This agreement governs how Nexus Bots B.V. processes personal data on your behalf when your bots interact with your end users. It satisfies Article 28 of the GDPR and forms part of our Terms of Service.
Effective July 28, 2026 · Last updated July 28, 2026
Registration details pending. The registered company number and office address for Nexus Bots B.V. are being finalised and will be published here. Until then, reach us at the contact addresses below.
You do not need to sign this
This agreement is incorporated into our Terms of Service and takes effect automatically when you accept them, for as long as we process end-user personal data on your behalf. Article 28(9) of the GDPR permits a processing agreement in electronic form, so no signature is required for it to bind us.
If your procurement process needs a countersigned copy, or your own template instead of ours, see section 12.
1. When this applies
This agreement applies whenever you use Nexus in a way that causes us to process personal data about your own end users — for example when you embed the website chat widget, connect a messaging channel, or deploy a bot that receives messages from other people.
It does not apply to personal data about you, such as your account details, workspace membership, or billing records. For that data we are the controller in our own right, and our Privacy Policy governs instead.
In this agreement, "GDPR" means Regulation (EU) 2016/679 and, where it applies to your use, the UK GDPR. "Controller", "processor", "personal data", "processing", and "personal data breach" have the meanings given in the GDPR.
2. Roles of the parties
You are the controller. You decide what your bots collect, from whom, and why. We are the processor, acting on your instructions.
As controller you are responsible for:
- having a lawful basis for everything your bots do with personal data;
- giving your end users the privacy information the GDPR requires, including telling them the bot exists and where their data goes — if you embed our chat widget, this means covering it in your own website privacy notice;
- obtaining and recording consent where consent is the basis you rely on, including for marketing messages;
- making sure the personal data you route through the platform is accurate and no broader than you need; and
- not sending us special-category data under Article 9, criminal-offence data under Article 10, or payment card numbers, unless we have agreed to that in writing beforehand.
We do not sell end-user personal data, do not use it for our own purposes, and do not use it to train AI models — see section 8 of the Privacy Policy.
3. Processing on your instructions
We process end-user personal data only on your documented instructions, including for transfers, unless we are required to do otherwise by EU or Member State law. If that happens we will tell you before processing, unless the law prohibits us from doing so on important grounds of public interest.
Your documented instructions consist of:
- this agreement and the Terms of Service;
- the flows, channels, schedules, and integrations you configure in the product — configuring a bot is how you instruct us; and
- any further written instruction we accept.
We will tell you if, in our opinion, an instruction infringes the GDPR. We may decline an instruction that would require us to breach the law or the terms of a platform we depend on. Instructions outside the standard functionality of the product may be chargeable, and we may decline those we cannot reasonably perform.
4. Confidentiality
We ensure that every person authorised to process end-user personal data is bound by an appropriate duty of confidentiality, and that access is limited to those who need it to deliver or support the service. Administrative access to production data is logged, and every emergency access use is recorded in an audit trail.
5. Security
We implement appropriate technical and organisational measures under Article 32, having regard to the state of the art, the cost of implementation, and the nature and risk of the processing. The measures in force are listed in Annex II. We may update them, provided the level of security is not reduced.
6. Sub-processors
You give us general authorisation to engage sub-processors. The current list is in Annex III and is maintained at /legal/subprocessors.
- We give at least 30 days' notice before a new sub-processor begins processing, by updating that page and notifying customers who have asked to be told.
- You may object on reasonable data-protection grounds within that period. We will work with you in good faith to find an alternative; if we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for the unused period.
- We impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain fully liable to you for their performance.
Providers you connect yourself — an AI provider whose API key you supply, or a messaging platform you authorise — are not our sub-processors. Those transfers happen at your direction, under your own relationship with that provider, and this agreement does not make us responsible for what they do with the data.
7. Assisting with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests under Chapter III of the GDPR — access, rectification, erasure, restriction, portability, and objection.
- The product lets you export and delete workspace and bot data yourself, which will resolve most requests without needing us.
- If we receive a request directly from one of your end users, we will not respond to its substance. We will tell them to contact you and, where we can identify you, let you know.
- Where you need help we cannot provide through the product, contact us and we will assist within a reasonable period. Assistance beyond the standard functionality may be chargeable at our then-current rates.
We also assist you, taking into account the information available to us, with your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments, and prior consultation.
8. Personal data breaches
We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting end-user personal data we process for you. The notification will describe, to the extent known:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures we have taken or propose to take, including to mitigate adverse effects; and
- a contact point for further information.
Where we cannot provide all of that at once, we will provide it in phases without further undue delay. Notifying you is not an admission of fault. As controller, deciding whether to notify a supervisory authority under Article 33 or affected individuals under Article 34 is your call, and we will give you the information you reasonably need to make it.
9. International transfers
Where you transfer personal data to us in a country outside the European Economic Area without an adequacy decision and a Chapter V transfer mechanism is required, that transfer is governed by the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor). Those Clauses are incorporated into this agreement by reference and completed as follows:
- Clause 7 (docking) applies.
- Clause 9: Option 2, general written authorisation, with the notice period in section 6.
- Clause 11: the optional independent dispute resolution body does not apply.
- Clause 17: the Clauses are governed by the law of the Netherlands.
- Clause 18(b): disputes are resolved before the competent courts of Amsterdam, the Netherlands.
- Annexes I, II, and III of the Clauses are populated by the corresponding Annexes below.
Where we make an onward transfer to a sub-processor outside the European Economic Area without an adequacy decision, we enter into Module Three (processor to processor) with that recipient or use another lawful Chapter V safeguard. Your general authorisation and right to object remain governed by section 6.
For transfers of UK personal data, the UK International Data Transfer Addendum applies to those Clauses. We carry out a transfer impact assessment for each such transfer, and rely on the EU–US Data Privacy Framework where a recipient is certified under it.
10. Audits
We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
- In the first instance we will respond to a reasonable written security questionnaire and provide the documentation we hold.
- Where that is insufficient, you may audit no more than 1 time per year, on at least 30 days' written notice, during business hours, in a manner that does not disrupt the service or compromise the confidentiality of other customers' data.
- You may audit more frequently following a confirmed personal data breach affecting your data, or where a supervisory authority requires it.
- Each party bears its own costs, and any auditor you mandate must not be a competitor of ours and must be bound by confidentiality.
11. Return and deletion
You may export your data at any time from Account settings, and delete bots, workspaces, and your account yourself. Deleting a workspace removes its bots, flows, connections, and conversation state immediately.
At the end of the provision of services we delete the end-user personal data we hold for you within 90 days, unless EU or Member State law requires us to keep it. Data already deleted persists in rolling backups until those cycle out, and is not restored into production. Retention periods during the term are set out in section 11 of the Privacy Policy.
12. General
- This agreement forms part of the Terms of Service. Where it conflicts with them on the processing of end-user personal data, this agreement prevails.
- Our liability under this agreement is subject to the limitations and exclusions in the Terms of Service, except where the GDPR does not permit that limitation.
- We may update this agreement to reflect changes in law, guidance, or the service, provided the change does not reduce your protection. Material changes follow the notice process in the Terms.
- This agreement ends automatically when we stop processing end-user personal data for you, save for provisions that by their nature survive.
If you need a signed copy
Email huseyinmelihcelik@gmail.com with your entity name and registered address and we will return an executed PDF of this agreement. We will also review your own DPA template, though we may propose this one instead where the terms are equivalent. Ask at the same address to be added to the sub-processor change notification list.
Annex I — Description of the processing
| Item | Detail |
|---|---|
| Parties | Controller: the customer identified by the Nexus account. Processor: Nexus Bots B.V.. |
| Subject matter | Provision of the Nexus bot platform — flow execution, message delivery and receipt, conversation state, and the integrations the controller configures. |
| Duration | The term of the Terms of Service, plus the deletion window in section 11. |
| Nature and purpose | Collection, recording, storage, retrieval, transmission, and erasure of end-user personal data, for the purpose of operating the bots the controller builds. |
| Categories of data subjects | End users who interact with the controller’s bots — website visitors using the chat widget, and users of Telegram, Discord, Slack, WhatsApp, Messenger, Instagram, Twitch, SMS, and voice channels the controller connects. |
| Types of personal data | Message content; platform user identifiers, usernames, and display names; phone numbers for SMS and voice; conversation state and variables the flow stores; images and files sent to a bot; execution logs and timestamps; IP address and user agent for the web chat widget. |
| Special categories | None expected. The controller must not route Article 9 or Article 10 data through the platform without prior written agreement. |
| Frequency | Continuous, for as long as the controller’s bots are deployed and receiving messages. |
| Retention | Conversation state for as long as the bot is deployed; raw run records 7 days on Free, 30 days on Pro, 90 days on Team; then deletion as set out in section 11. |
| Competent supervisory authority | Determined by the controller’s own establishment. For processing under our responsibility, the authority in our country of establishment. |
Annex II — Technical and organisational measures
The measures below are in force. They are the same measures described in section 12 of the Privacy Policy, and under this agreement they are contractual commitments rather than description.
- Transport encryption (TLS) for all traffic to the application and to third-party APIs.
- Integration credentials and OAuth tokens encrypted at rest with a dedicated application key, separate from the database.
- Passwords stored using bcrypt; optional two-factor authentication with recovery codes.
- Workspace-scoped access control on every data path, with tenant isolation enforced server-side rather than in the UI.
- Signed, expiring state for OAuth flows; signed webhook verification for inbound platform traffic; rate limiting on authentication and webhook endpoints.
- Public media served from a separate, cookie-free origin, with uploads validated by magic bytes and SVG never hosted.
- Audit logging of administrative actions, including every emergency access use.
- Operational alerting on error spikes, dead-lettered jobs, and quota thresholds.
Measures for sub-processor transfers are those the relevant sub-processor maintains under its own agreement with us, which we require to be no less protective than these.
Annex III — Authorised sub-processors
| Recipient | Purpose | Data involved | Role |
|---|---|---|---|
| Vercel | Application hosting, edge network, and request logs for the web app | Request metadata, IP address, account identifiers | Processor |
| Fly.io | Hosting for the durable execution worker | Queued job payloads, bot message content in transit | Processor |
| Managed PostgreSQL provider | Primary database for all account, workspace, and bot data | All stored account, flow, conversation, and billing records | Processor |
| S3-compatible object storage | Media uploaded to, or generated by, bot flows | Images and files, with derived object keys | Processor |
| Stripe | Subscription billing, tax calculation, and marketplace payouts | Billing contact, payment references, payout and tax details | Independent controller and processor |
| Resend | Transactional email (verification, password reset, alerts) | Email address, message content | Processor |
| OpenAI (flow generator) | Generating and modifying flows in the builder, on our own OpenAI account, and evaluating how well that feature works | The prompt you write, the flow you submit for modification, and the generated result | Processor |
| OpenAI, Anthropic, or Google (AI nodes at run time) | Running an AI node inside a deployed flow, using the API key from a connection you configured | Prompt text and the conversation context your flow passes in | At your direction |
| Google (Sheets, Calendar, Gmail, YouTube) | The Google integrations you explicitly connect | The spreadsheet, calendar, message, or live-chat data covered by the scopes you granted | At your direction |
| Meta (WhatsApp, Messenger, Instagram) | Delivering and receiving messages on channels you connect | Message content, platform user IDs, delivery receipts | At your direction |
| Telegram, Discord, Slack, Twitch | Delivering and receiving messages on channels you connect | Message content, platform user IDs | At your direction |
| Twilio | SMS and voice channels you connect | Phone numbers, message and call content | At your direction |
| HubSpot | CRM integration you connect | Contact records your flow reads or writes | At your direction |
Entries marked "at your direction" are not our sub-processors — they receive data because you connected them. The authoritative, current list is at /legal/subprocessors.
Standard Contractual Clauses: Commission Implementing Decision (EU) 2021/914