1. Scope & Applicability

Purpose: This Data Processing Agreement (DPA) establishes terms for Nexus AI Coding ("Processor") processing personal data on behalf of the Customer/User ("Controller") in connection with the Services in the Master Terms of Service ("MSA").

Applicability: This DPA applies to the extent that the Services involve processing of personal data as defined by GDPR, CCPA, or other applicable data protection laws.

Integration: This DPA supplements the MSA at nexus-ai.nexus/terms-of-service. In case of conflict, the DPA shall prevail regarding data protection compliance and processor obligations.

2. Definitions

  • Personal Data (GDPR): Any information relating to an identified or identifiable natural person.
  • Data Subject: The individual to whom personal data relates.
  • Processing: Any operation performed on personal data (collection, storage, use, transmission, erasure, etc.).
  • Data Controller (GDPR/CCPA): Entity determining purposes, means, and scope of processing (typically the Customer/User).
  • Data Processor (GDPR): Entity processing personal data on behalf of the controller (Nexus AI Coding).
  • Sub-Processor: Processor engaged by main processor to process personal data.
  • Sensitive Personal Information (CCPA): Personal information revealing race, religion, genetic data, health data, sex life, biometric ID, financial information, or precise geolocation.
  • Breach: Unauthorized or accidental access, disclosure, alteration, loss, or destruction of personal data.
  • GDPR: Regulation (EU) 2016/679 (General Data Protection Regulation).
  • CCPA: California Consumer Privacy Act and California Privacy Rights Act (CPRA).

3. Roles: Controller vs. Processor

Controller Role

The Customer/User acts as the Data Controller when using Nexus AI Services. As controller, the Customer:

  • Determines purposes and means of processing personal data
  • Provides written processing instructions to Nexus AI
  • Ensures lawful basis for processing personal data
  • Ensures consent from data subjects where required
  • Bears responsibility for GDPR/CCPA compliance
  • Handles data subject rights requests (access, deletion, portability, etc.)

Processor Role

Nexus AI acts as the Data Processor. As processor, Nexus AI:

  • Processes personal data only per documented processing instructions
  • Does not determine purposes or means independently
  • Implements appropriate security and confidentiality measures
  • Engages sub-processors and ensures DPA compliance
  • Assists with data subject rights requests
  • Notifies Customer of personal data breaches
  • Deletes or returns personal data upon termination

4. Lawful Basis for Processing

GDPR Lawful Basis (Article 6)

Nexus AI processes personal data on the lawful basis/bases of:

  • Contractual Necessity (6(1)(b)): Processing necessary to provide Services (account management, billing, API authentication, usage tracking)
  • Legitimate Interests (6(1)(f)): Fraud prevention, security, service improvement, compliance
  • Legal Obligation (6(1)(c)): Tax regulations, law enforcement, payment disputes
  • Consent (6(1)(a)): AI model training (opt-in), marketing (opt-out available)

CCPA Processing

Nexus AI processes personal information solely to provide the Services and fulfill collection purposes. Nexus AI does NOT sell personal information or use it outside the scope of Business Purposes.

5. Processing Details

Data Categories

Category Examples Purpose
Identifiers Name, email, username, IP address Account management, authentication
Commercial Subscription tier, payment history, usage Billing, subscription management
Technical Browser type, OS, access logs, API logs Service operation, analytics, performance
Service Content Prompts, code snippets, project info Service delivery, AI improvement (opt-in)
Payment Data Billing address, transaction ID, amount Billing, refunds (NO full card numbers)
Usage Data API calls, feature usage, credit consumption Metering, analytics, improvement
Sensitive Data SSN, health, financial (NOT intentionally) None—deleted within 5 days if inadvertent

Retention Periods

Data Category Retention Period Legal Basis
Account Data 30 days after closure Contractual, legal compliance
Transaction Records 7 years Tax compliance (IRS, VAT)
Support Communications 3 years Service quality, disputes
Usage Logs 1 year Security, fraud prevention
Backups 90 days Disaster recovery
AI Training Data Indefinitely (anonymized) Model improvement

6. Data Subject Rights

GDPR Rights (Articles 15-22)

  • Access: Request copy of personal data (30-day response, GDPR)
  • Rectification: Correct inaccurate data (10 business days)
  • Erasure: Request deletion (subject to legal retention exceptions)
  • Restriction: Suspend processing (e.g., during accuracy disputes)
  • Portability: Receive data in machine-readable format (CSV, JSON)
  • Objection: Object to direct marketing or legitimate interest processing
  • Automated Decision-Making: Right not to be subject to decisions with legal effects

CCPA Rights (Sections 1798.100-1798.125)

  • Know: Request what categories/specific data we collect (45-day response)
  • Delete: Request deletion (45-day response, subject to exceptions)
  • Correct: Request correction of inaccurate data (45 days)
  • Opt-Out of Sharing: Opt out of data sharing with advertising partners
  • Limit Sensitive Data: Limit use of sensitive personal information
  • Non-Discrimination: No penalty for exercising rights

Exercise of Rights

Send request to: [email protected]

Include: Account email, specific right(s), supporting documentation, proof of identity.

Timelines: GDPR 30 days (extendable 60 days); CCPA 45 days.

7. Processor Obligations

Processing Instructions

Nexus AI processes personal data only in accordance with documented instructions. Processing instructions include purposes, data categories, types of processing, duration, and security measures.

Confidentiality

Staff authorized to process personal data must:

  • Be committed to confidentiality or under legal duty of confidentiality
  • Receive appropriate data protection training
  • Sign confidentiality agreements covering term + beyond

Security Measures

  • Technical: TLS/SSL encryption (transit), AES-256 (rest), MFA, access controls, intrusion detection
  • Organizational: Staff training, incident response, security audits, data protection by design
  • Physical: Restricted data center access, CCTV, secure disposal
  • Sub-Processor: Equivalent security via DPA requirements

Audit Rights

Customer may audit compliance (annual or post-breach) with 15 days' notice. Audits limited to 5 business days, confidentiality protections apply. Remediation timelines: Critical 7 days, High 30 days, Medium 60 days.

8. Sub-Processors

Authorized Sub-Processors

Category Sub-Processors
Payment Processing Stripe, PayPal, Authorize.Net, Paddle, Whop
Infrastructure AWS, Google Cloud, Azure
Analytics Google Analytics, Amplitude, Sentry, New Relic
Support Zendesk, SendGrid, Twilio
Security Cloudflare, Okta, Vanta

Notification & Objection

  • New Sub-Processors: 30-day advance notice with name, location, data access details
  • Customer Objection: Submit written objection within 15 days on reasonable grounds
  • Resolution: Nexus AI discusses in good faith; if unresolved, either party may terminate without penalty
  • Sub-Processor DPA: All sub-processors execute equivalent DPA with security and compliance requirements

Current Sub-Processor List

View at: nexus-ai.nexus/legal/subprocessors (updated regularly)

9. International Data Transfers

Transfer Jurisdictions

Nexus AI and sub-processors operate globally. Personal data may transfer to USA, EU, and other jurisdictions. These countries may have different data protection standards than your home jurisdiction.

GDPR Transfer Mechanisms

  • Standard Contractual Clauses (SCCs): EU-approved model clauses (Decision 2021/914) with Supplementary Measures per Schrems II
  • Data Privacy Framework (DPF): EU-U.S., UK-U.S., Swiss-U.S. Data Privacy Frameworks for US transfers
  • Adequacy Decisions: For countries deemed adequate by EU/UK

Supplementary Measures

  • Encryption of data in transit (TLS) and at rest (AES-256)
  • Data minimization and access restrictions
  • Contractual safeguards via SCCs
  • Technical security controls
  • Data subject transparency in privacy notices

10. Security & Confidentiality

Certifications

  • ISO 27001:2013 (Information Security Management System)
  • SOC 2 Type II (System and Organization Controls)
  • PCI DSS Level 1 (via payment processors)

Encryption Standards

  • In Transit: TLS 1.2 or higher
  • At Rest: AES-256 for sensitive data
  • Key Management: Separate from encrypted data, rotated regularly

Access Control

  • Role-Based Access Control (RBAC)
  • Principle of Least Privilege
  • Multi-Factor Authentication (MFA) for admin access
  • Automatic session timeouts

Incident Response

Nexus AI maintains incident response plan: Detection → Investigation → Mitigation → Notification → Recovery → Post-Incident Review

11. Audit Rights & Compliance

Customer Audit Rights

  • Frequency: Annual or post-breach, max 15 days' notice
  • Access: Facilities, systems, documentation, staff
  • Duration: Limited to 5 business days
  • Confidentiality: Audit findings protected; NDA required
  • Remediation: If non-compliance found, Nexus AI provides remediation plan

Third-Party Audits

Nexus AI undergoes SOC 2 Type II audits, ISO 27001 certifications, penetration testing, and regular vulnerability assessments. Audit reports provided upon request.

Regulatory Cooperation

Nexus AI cooperates with data protection authorities, law enforcement (with legal process), and judicial proceedings. Customer notified unless legally prohibited.

12. Data Subject Requests

Request Types

  • Access (GDPR 15, CCPA §1798.100): 30 days (GDPR), 45 days (CCPA)
  • Deletion (GDPR 17, CCPA §1798.105): 30 days (GDPR), 45 days (CCPA), subject to legal holds
  • Correction (GDPR 16, CCPA §1798.110): 10 business days (GDPR), 45 days (CCPA)
  • Portability (GDPR 20): Machine-readable format, 30 days (extendable 60 days)
  • Restriction (GDPR 18): Suspend processing, 10 business days
  • Objection (GDPR 21, CCPA §1798.120): Stop processing, 10 business days

Cooperation & Assistance

Nexus AI will assist by providing personal data, implementing requested actions, providing evidence of compliance, and forwarding requests to sub-processors.

13. Breach Notification

Breach Definition

Unauthorized or accidental access, disclosure, alteration, loss, or destruction of personal data.

Notification Timeline

  • Immediate (24 Hours): Notify Customer by email with preliminary breach details
  • Detailed (72 Hours): Full breach report: scope, affected data, data subjects, consequences, remediation
  • Cooperation: Assist with notification, preserve evidence, provide updates, regular remediation progress

Mitigation

Nexus AI takes immediate steps to contain breach, preserve evidence, assess scope, restore services, implement remediation, and prevent recurrence.

Liability

Governed by DPA and MSA limitation of liability provisions, applicable data protection laws (GDPR fines, CCPA penalties), and cyber liability insurance.

14. Data Deletion & Return

Upon Termination

  • Timeline: 30 days for return/deletion
  • Method: Secure cryptographic destruction or certified erasure
  • Verification: Certificate of destruction provided
  • Backups: Deleted within 90 days, not accessible after deletion

Customer Election

  • Return: Export all data in machine-readable format within 30 days
  • Deletion: Secure deletion with certificate of destruction within 60 days

Legal Retention Exceptions

Personal data retained for:

  • Tax records (7 years)
  • Legal proceedings (pending/threatened)
  • Regulatory obligations
  • Fraud prevention (limited data)

Retained data encrypted, segregated, access-restricted, and deleted upon legal expiration.

15. Term & Termination

  • Effective Date: November 3, 2025
  • Duration: Life of MSA + 30 days for data return/deletion
  • Surviving Provisions: Liability, indemnification, confidentiality (indefinite)
  • Severability: Invalid provisions severed without affecting rest
  • Amendment: 30 days' notice for compliance/sub-processor changes

16. Liability & Indemnification

Liability Cap

  • Higher of: (A) total fees paid in 12 months preceding breach, or (B) $100 USD
  • GDPR Fines Exception: Liable for GDPR administrative fines up to €20M or 4% global revenue (per GDPR Article 83)
  • Insurance: Cyber liability insurance covering data breaches

Indemnification

  • Nexus AI indemnifies Customer: From third-party claims arising from Nexus AI's data protection law breach
  • Customer indemnifies Nexus AI: From claims arising from Customer's unlawful processing instructions or failure to obtain consent

17. Governing Law & Disputes

Governing Law

  • Primary: GDPR (EU/UK) and UK Data Protection Act 2018
  • Secondary: CCPA and other applicable privacy laws
  • Tertiary: State of California law (without conflict of law)

Dispute Resolution

  • Informal Resolution (30 Days): Good-faith negotiation
  • Escalation: Executive meeting (15 days)
  • Formal Dispute: Arbitration per MSA (AAA, San Francisco/virtual)
  • Data Protection Authority: Either party may submit to competent DPA

18. Signature & Acceptance

DPA Acceptance

By creating an account or accessing the Services, Customer acknowledges that they:

  • Have read this DPA in its entirety
  • Understand Controller and Processor roles
  • Agree to comply with this DPA and applicable data protection laws
  • Authorize Nexus AI to process personal data per this DPA
  • Have authority to enter into this DPA

Binding Effect

This DPA is incorporated into and made part of the MSA. In case of conflict, the DPA shall prevail regarding data protection compliance.

Contact

Privacy & Compliance Team
Email: [email protected]
Website: nexus-ai.nexus/legal/dpa

DPA ACKNOWLEDGMENT & ACCEPTANCE

By clicking "I Accept," creating an account, or accessing the Services, you acknowledge and agree that you:

  • Have read this DPA and all integrated compliance documents in their entirety
  • Understand your obligations as Data Controller
  • Have authority to enter into this agreement
  • Authorize Nexus AI to process personal data per this DPA
  • Accept all limitations of liability and indemnification terms

Effective Date: November 3, 2025
Last Updated: November 4, 2025
Version: 1.0 (HTML Cinematic)
Compliance Status: ✓ GDPR • CCPA • VCDPA • CPA • CTDPA • UCPA • Multi-Processor

This DPA is provided as a legal document for customer sign-off, regulatory submission, and payment processor pre-approval. For compliance guidance specific to your jurisdiction, consult qualified legal counsel.

Related Documents:
Terms of ServicePrivacy PolicyRefund PolicyEULASub-Processors