Nexusscopes — Data Processing Agreement (DPA)
Version 1.0 — Effective [DD Month YYYY]
Parties
This Data Processing Agreement ("DPA") is entered into between:
(1) Customer — the entity or individual identified in the Nexusscopes account and order confirmation, acting as Controller (or, where the Customer is itself a processor for a third party, as processor engaging Nexusscopes as sub-processor); and
(2) Noah Baumann, sole proprietor trading as Nexusscopes, [street, postal code, city], Switzerland, acting as Processor.
Each a "Party", together the "Parties".
1. Structure and precedence
1.1 This DPA forms part of and is incorporated by reference into the Nexusscopes Terms of Service (the "Agreement"). It applies automatically and without signature whenever Nexusscopes processes Personal Data on the Customer's behalf. A countersigned copy is available on request at [legal@nexusscopes.com].
1.2 In case of conflict, the order of precedence is: (i) the Standard Contractual Clauses in Annex IV where they apply, (ii) this DPA, (iii) the Agreement, (iv) any other document.
1.3 This DPA does not apply to data for which Nexusscopes is itself controller (account, billing, support, and telemetry data) — that is governed by the Privacy Policy.
2. Definitions
"Applicable Data Protection Law" means the GDPR (Regulation (EU) 2016/679), the revised Swiss Federal Act on Data Protection of 25 September 2020 ("revFADP") and its ordinance, the UK GDPR and Data Protection Act 2018 where relevant, and any national implementing or successor legislation.
"Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", "Supervisory Authority" have the meanings given in the GDPR; under the revFADP, "Processor" corresponds to Auftragsbearbeiter and "Personal Data Breach" to a breach of data security under Art. 24 revFADP.
"Customer Personal Data" means Personal Data contained in Customer Content that Nexusscopes processes on the Customer's behalf under the Agreement.
"Sub-processor" means any third party engaged by Nexusscopes to process Customer Personal Data.
"SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, including the Swiss adaptations recognised by the Federal Data Protection and Information Commissioner.
3. Roles and scope
3.1 The Customer is the Controller and Nexusscopes is the Processor in respect of Customer Personal Data. Where the Customer acts as a processor for a third-party controller, Nexusscopes acts as sub-processor and the Customer warrants it has the authority to engage Nexusscopes on these terms.
3.2 The details required by Art. 28(3) GDPR — subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects — are set out in Annex I.
3.3 The Customer determines the purposes and means of processing. Nexusscopes has no independent right to use Customer Personal Data.
4. Customer obligations and warranties
4.1 The Customer warrants that:
a) it has a valid legal basis for the processing it instructs, and has provided all required information to Data Subjects;
b) its instructions comply with Applicable Data Protection Law;
c) it holds documented authorisation over every domain, system, repository, or account it submits as a scan target;
d) it will not upload special categories of Personal Data (Art. 9 GDPR / Art. 5(c) revFADP), criminal conviction data, payment card data, or data subject to professional secrecy, unless Nexusscopes has agreed in writing in advance and appropriate additional measures are documented in Annex II;
e) it has assessed the Service as suitable for the intended processing, taking into account its security measures.
4.2 The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it acquired it.
5. Nexusscopes' processing obligations
Nexusscopes shall:
5.1 Process only on documented instructions. Process Customer Personal Data solely on the Customer's documented instructions, including the Agreement, the configuration of the Service, and any further written instruction, and for the purposes set out in Annex I — including as regards transfers to a third country — unless required to do otherwise by Union, Member State, or Swiss law. In that case, Nexusscopes will inform the Customer of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
5.2 Flag unlawful instructions. Immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend performance of that instruction until it is confirmed, amended, or withdrawn.
5.3 Ensure confidentiality. Ensure that persons authorised to process Customer Personal Data are subject to an appropriate statutory or contractual duty of confidentiality that survives the end of their engagement, and are trained in data protection.
5.4 Implement security. Implement and maintain the technical and organisational measures in Annex II, meeting Art. 32 GDPR and Art. 8 revFADP, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.
5.5 Limit access. Restrict access to Customer Personal Data to personnel who need it to perform the Agreement, on a least-privilege basis, with access logged.
5.6 No further use. Not use Customer Personal Data for its own purposes, not disclose it to third parties except as permitted here, not sell it, and not use it to train or fine-tune AI or machine-learning models, unless the Customer opts in to a feature that expressly and separately provides for this.
5.7 Aggregation. Nexusscopes may create aggregated, irreversibly anonymised statistics that cannot be attributed to the Customer or any Data Subject. Once anonymised, such data is no longer Personal Data and falls outside this DPA.
6. Sub-processors
6.1 The Customer grants Nexusscopes general written authorisation to engage Sub-processors, subject to this Section.
6.2 The Sub-processors authorised at the effective date are listed at /legal/subprocessors and summarised in Annex III.
6.3 Change notice. Nexusscopes will notify the Customer of any intended addition or replacement of a Sub-processor at least [30] days in advance, by e-mail to the Customer's notification address and/or via the subscription mechanism on the sub-processor page. Customers should subscribe to that mechanism; failure to do so does not extend the objection period.
6.4 Objection. The Customer may object on reasonable, documented data-protection grounds within [30] days of notice. The Parties will work in good faith to resolve the objection — for example by offering an alternative configuration or region. If no resolution is found within [30] days, the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid, unused fees.
6.5 Flow-down and liability. Nexusscopes will impose on each Sub-processor, by written contract, data protection obligations materially no less protective than those in this DPA, and remains fully liable to the Customer for the Sub-processor's performance of its obligations.
7. Assistance to the Customer
7.1 Data Subject requests. Taking into account the nature of the processing, Nexusscopes will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests for the exercise of Data Subject rights under Chapter III GDPR and Art. 25 ff. revFADP. The Service includes self-service access, export, and deletion functions that will usually be sufficient.
7.2 Redirection. If Nexusscopes receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively, will refer the Data Subject to the Customer, and will inform the Customer without undue delay.
7.3 DPIAs and prior consultation. Nexusscopes will provide reasonable assistance with data protection impact assessments (Art. 35 GDPR / Art. 22 revFADP) and prior consultation with a Supervisory Authority (Art. 36 GDPR), taking into account the nature of processing and the information available to it.
7.4 Charges. Assistance is provided free of charge where it is routine or covered by the Service's built-in functionality. For extensive or repeated assistance beyond that, Nexusscopes may charge reasonable documented costs at [CHF ___/hour], notified in advance.
8. Personal Data Breach
8.1 Nexusscopes will notify the Customer without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate adverse effects, and a contact point for further information. Where information is not available at once, it will be provided in phases without further undue delay.
8.3 Nexusscopes will assist the Customer in meeting its own notification duties to Supervisory Authorities (Art. 33 GDPR — 72 hours; Art. 24 revFADP — as soon as possible to the FDPIC) and to Data Subjects (Art. 34 GDPR).
8.4 Nexusscopes will not notify any third party of a breach on the Customer's behalf without the Customer's prior written consent, unless legally required.
8.5 Notification or assistance is not an admission of fault or liability.
9. Audits and evidence of compliance
9.1 Nexusscopes will make available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR.
9.2 Primary route. The Customer's audit right is satisfied in the first instance by Nexusscopes providing, on request and no more than once per year: the current security overview, the sub-processor list, a completed security questionnaire, and any third-party audit report or certification then held ([SOC 2 / ISO 27001 — state honestly which, if any]).
9.3 On-site audit. Where the above is genuinely insufficient, or following a Personal Data Breach, or where a Supervisory Authority requires it, the Customer or a mandated independent auditor may conduct an audit, subject to: [30] days' prior written notice, a mutually agreed scope and date, normal business hours, a signed confidentiality undertaking, no access to other customers' data or to systems that would compromise it, and no more than once per year except for cause.
9.4 The Customer bears its own audit costs and Nexusscopes' reasonable documented costs for on-site audits, except where the audit reveals a material breach of this DPA by Nexusscopes.
9.5 The auditor must not be a competitor of Nexusscopes.
10. International transfers
10.1 Nexusscopes will not transfer Customer Personal Data outside Switzerland or the EEA except in accordance with this Section.
10.2 Transfers are made only where: (a) the destination benefits from an adequacy decision — including the European Commission's confirmation of Swiss adequacy and, for certified US recipients, the EU-US and Swiss-US Data Privacy Frameworks; (b) the SCCs in Annex IV apply, with the Swiss adaptations recognised by the FDPIC; or (c) another valid transfer mechanism under Art. 46 GDPR / Art. 16–17 revFADP is in place.
10.3 Where the SCCs apply, they are incorporated by reference as set out in Annex IV, with Module Two (Controller to Processor) applying where the Customer is a controller and Module Three (Processor to Processor) where the Customer is itself a processor.
10.4 Nexusscopes carries out and documents transfer impact assessments and applies supplementary measures, including encryption in transit and at rest and a policy of challenging disproportionate government access requests.
10.5 Government access. Nexusscopes will notify the Customer of any legally binding request from a public authority for disclosure of Customer Personal Data unless prohibited, will challenge requests it considers unlawful or excessive, and will disclose only the minimum required.
11. Deletion and return
11.1 On termination or expiry of the Agreement, and at the Customer's choice, Nexusscopes will delete or return all Customer Personal Data and delete existing copies, unless Union, Member State, or Swiss law requires storage.
11.2 In practice: Customer Content remains available for self-service export for [30] days after termination; it is then deleted from production systems; and it is purged from backups within a further [90] days in line with backup rotation. Data retained under a legal obligation is isolated, access-restricted, and processed only for the purpose of that obligation.
11.3 On request, Nexusscopes will confirm deletion in writing.
12. Liability
12.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Applicable Data Protection Law does not permit such limitation.
12.2 Nothing in this DPA limits or excludes: (a) a Data Subject's rights under Art. 82 GDPR; (b) either Party's liability towards a Supervisory Authority; or (c) liability for intent or gross negligence under Art. 100(1) of the Swiss Code of Obligations.
12.3 If one Party pays compensation for damage caused by processing, it may claim back from the other Party the part corresponding to that Party's responsibility, per Art. 82(5) GDPR.
13. Term, governing law, and jurisdiction
13.1 This DPA takes effect when the Customer accepts the Agreement and continues until all Customer Personal Data has been deleted or returned under Section 11. Sections 5.3, 8, 11, and 12 survive.
13.2 This DPA is governed by Swiss law, excluding conflict-of-laws rules, and the place of jurisdiction is [Zurich], Switzerland, subject to any mandatory jurisdiction rule and to the governing law and forum provisions of the SCCs where those apply.
13.3 If a provision of this DPA is invalid, the remainder stays in force and the invalid provision is replaced by a valid one closest to its purpose.
Annex I — Details of processing (Art. 28(3) GDPR)
Subject matter: provision of the Nexusscopes data-compliance discovery and assessment service.
Duration: the term of the Agreement, plus the deletion periods in Section 11.
Nature of processing: collection, storage, structuring, retrieval, analysis (including automated and AI-assisted analysis), report generation, transmission, erasure.
Purpose: performing compliance scans, assessments, and monitoring requested by the Customer, and generating findings and reports.
Categories of Data Subjects (as determined by the Customer's content):
the Customer's employees, contractors, and authorised users
the Customer's own customers, clients, and end users
website visitors and app users of the systems scanned
business contacts and other individuals named in documents the Customer uploads
Types of Personal Data (as determined by the Customer's content):
identifiers: names, e-mail addresses, usernames, user IDs
online identifiers: IP addresses, cookie IDs, device identifiers
professional data: job title, employer, department
content data: text and metadata in uploaded documents, policies, records of processing, configurations
technical data: log entries, tracker inventories, data-flow records
any other Personal Data the Customer chooses to submit
Special categories: none permitted by default. Prohibited unless separately agreed in writing under Section 4.1(d), in which case the additional safeguards are recorded here: [___].
Frequency: continuous for the duration of the Agreement.
Retention: as set out in Section 11 and the Customer's own configuration.
Sub-processor processing: as described in Annex III.
Annex II — Technical and organisational measures (Art. 32 GDPR / Art. 8 revFADP)
Complete honestly. This annex is a contractual commitment.
Pseudonymisation and encryption
TLS 1.2+ for all data in transit; HSTS enforced
AES-256 encryption at rest for databases, object storage, and backups
scan credentials and API tokens held in a dedicated encrypted secrets vault, decrypted only at point of use
pseudonymisation applied in logs and analytics where feasible
Confidentiality — access control
role-based access control on least-privilege principles
multi-factor authentication mandatory for all administrative and production access
unique named accounts; no shared credentials
production access limited to [named roles], reviewed [quarterly]
physical security delegated to certified hosting providers ([ISO 27001 / SOC 2] certified data centres in [Switzerland/EU])
Integrity
input validation and output encoding; protection against OWASP Top 10 classes
change management with peer code review before production deployment
separation of development, staging, and production environments
audit logging of administrative actions and data access, retained [12] months, protected against tampering
Availability and resilience
automated encrypted backups [daily], retained [30] days, with [quarterly] restore testing
monitoring and alerting on availability, error rates, and anomalous access
documented disaster recovery plan with RTO [__] hours and RPO [__] hours
Regular testing and evaluation
automated dependency and vulnerability scanning in the build pipeline
[annual] penetration test by an independent third party [if applicable]
[annual] review of these measures and of the risk assessment
Organisational measures
confidentiality undertakings and data protection training for all personnel with access
documented incident response plan with defined roles and escalation
Record of Processing Activities maintained under Art. 30 GDPR / Art. 12 revFADP
sub-processor due diligence before onboarding and on [annual] review
data protection by design and by default in the product development process
secure deletion and media disposal procedures
Annex III — Authorised Sub-processors
Current as of [DD Month YYYY]. The authoritative list is at /legal/subprocessors.
| Sub-processor | Service provided | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| [Hosting provider] | Infrastructure hosting | All Customer Personal Data | [CH / EU] | Adequacy / n/a |
| [Payment provider] | Billing | Customer contact and billing data | [EU / US] | Adequacy (DPF) / SCCs |
| [E-mail provider] | Transactional e-mail | Recipient e-mail and message content | [EU] | n/a |
| [Support desk] | Support ticketing | Ticket content | [EU] | n/a |
| [Error monitoring] | Diagnostics | Log data, limited identifiers | [EU] | n/a |
| [Analytics] | Product analytics | Pseudonymised usage data | [EU] | n/a |
| [AI/model provider] | AI-assisted analysis | Content submitted for analysis | [EU / US] | SCCs + no-training commitment |
Annex IV — Standard Contractual Clauses
IV.1 EU transfers. Where Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the SCCs (Implementing Decision (EU) 2021/914) are incorporated by reference and completed as follows:
Module: Module Two (Controller → Processor) where the Customer is a controller; Module Three (Processor → Processor) where the Customer is a processor.
Clause 7 (docking): applies.
Clause 9 (sub-processors): Option 2 — general written authorisation, notice period [30] days (Section 6.3).
Clause 11 (redress): the optional independent dispute resolution language does not apply.
Clause 17 (governing law): the law of [Ireland].
Clause 18(b) (forum): the courts of [Ireland].
Annex I.A (parties): as identified in the account and Section "Parties" above.
Annex I.B (description of transfer): as set out in Annex I of this DPA.
Annex I.C (competent supervisory authority): the authority determined under Clause 13, being [the Irish Data Protection Commission].
Annex II (security measures): as set out in Annex II of this DPA.
Annex III (sub-processors): as set out in Annex III of this DPA.
IV.2 Swiss transfers. For transfers subject to the revFADP, the SCCs apply with the adaptations recognised by the FDPIC:
references to the GDPR are read as references to the revFADP;
the competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC) where the transfer is governed exclusively by Swiss law, or both the FDPIC and the EU authority where the transfer is governed by both;
"Member State" is not interpreted to exclude Data Subjects in Switzerland from suing for their rights in their place of habitual residence;
until the revFADP's protection of legal entities lapsed, references to Personal Data also covered data of legal entities; under the revFADP now in force, only data of natural persons is covered.
IV.3 UK transfers. Where the UK GDPR applies, the UK International Data Transfer Addendum (version B1.0) to the SCCs applies, with Tables 1–4 completed by reference to the annexes above.