1. Scope & Applicability
Purpose: This Data Processing Agreement (DPA) establishes terms for Nexus AI Coding ("Processor") processing personal data on behalf of the Customer/User ("Controller") in connection with the Services in the Master Terms of Service ("MSA").
Applicability: This DPA applies to the extent that the Services involve processing of personal data as defined by GDPR, CCPA, or other applicable data protection laws.
Integration: This DPA supplements the MSA at nexus-ai.nexus/terms-of-service. In case of conflict, the DPA shall prevail regarding data protection compliance and processor obligations.
2. Definitions
- Personal Data (GDPR): Any information relating to an identified or identifiable natural person.
- Data Subject: The individual to whom personal data relates.
- Processing: Any operation performed on personal data (collection, storage, use, transmission, erasure, etc.).
- Data Controller (GDPR/CCPA): Entity determining purposes, means, and scope of processing (typically the Customer/User).
- Data Processor (GDPR): Entity processing personal data on behalf of the controller (Nexus AI Coding).
- Sub-Processor: Processor engaged by main processor to process personal data.
- Sensitive Personal Information (CCPA): Personal information revealing race, religion, genetic data, health data, sex life, biometric ID, financial information, or precise geolocation.
- Breach: Unauthorized or accidental access, disclosure, alteration, loss, or destruction of personal data.
- GDPR: Regulation (EU) 2016/679 (General Data Protection Regulation).
- CCPA: California Consumer Privacy Act and California Privacy Rights Act (CPRA).
3. Roles: Controller vs. Processor
Controller Role
The Customer/User acts as the Data Controller when using Nexus AI Services. As controller, the Customer:
- Determines purposes and means of processing personal data
- Provides written processing instructions to Nexus AI
- Ensures lawful basis for processing personal data
- Ensures consent from data subjects where required
- Bears responsibility for GDPR/CCPA compliance
- Handles data subject rights requests (access, deletion, portability, etc.)
Processor Role
Nexus AI acts as the Data Processor. As processor, Nexus AI:
- Processes personal data only per documented processing instructions
- Does not determine purposes or means independently
- Implements appropriate security and confidentiality measures
- Engages sub-processors and ensures DPA compliance
- Assists with data subject rights requests
- Notifies Customer of personal data breaches
- Deletes or returns personal data upon termination
4. Lawful Basis for Processing
GDPR Lawful Basis (Article 6)
Nexus AI processes personal data on the lawful basis/bases of:
- Contractual Necessity (6(1)(b)): Processing necessary to provide Services (account management, billing, API authentication, usage tracking)
- Legitimate Interests (6(1)(f)): Fraud prevention, security, service improvement, compliance
- Legal Obligation (6(1)(c)): Tax regulations, law enforcement, payment disputes
- Consent (6(1)(a)): AI model training (opt-in), marketing (opt-out available)
CCPA Processing
Nexus AI processes personal information solely to provide the Services and fulfill collection purposes. Nexus AI does NOT sell personal information or use it outside the scope of Business Purposes.
5. Processing Details
Data Categories
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Name, email, username, IP address | Account management, authentication |
| Commercial | Subscription tier, payment history, usage | Billing, subscription management |
| Technical | Browser type, OS, access logs, API logs | Service operation, analytics, performance |
| Service Content | Prompts, code snippets, project info | Service delivery, AI improvement (opt-in) |
| Payment Data | Billing address, transaction ID, amount | Billing, refunds (NO full card numbers) |
| Usage Data | API calls, feature usage, credit consumption | Metering, analytics, improvement |
| Sensitive Data | SSN, health, financial (NOT intentionally) | None—deleted within 5 days if inadvertent |
Retention Periods
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account Data | 30 days after closure | Contractual, legal compliance |
| Transaction Records | 7 years | Tax compliance (IRS, VAT) |
| Support Communications | 3 years | Service quality, disputes |
| Usage Logs | 1 year | Security, fraud prevention |
| Backups | 90 days | Disaster recovery |
| AI Training Data | Indefinitely (anonymized) | Model improvement |
6. Data Subject Rights
GDPR Rights (Articles 15-22)
- Access: Request copy of personal data (30-day response, GDPR)
- Rectification: Correct inaccurate data (10 business days)
- Erasure: Request deletion (subject to legal retention exceptions)
- Restriction: Suspend processing (e.g., during accuracy disputes)
- Portability: Receive data in machine-readable format (CSV, JSON)
- Objection: Object to direct marketing or legitimate interest processing
- Automated Decision-Making: Right not to be subject to decisions with legal effects
CCPA Rights (Sections 1798.100-1798.125)
- Know: Request what categories/specific data we collect (45-day response)
- Delete: Request deletion (45-day response, subject to exceptions)
- Correct: Request correction of inaccurate data (45 days)
- Opt-Out of Sharing: Opt out of data sharing with advertising partners
- Limit Sensitive Data: Limit use of sensitive personal information
- Non-Discrimination: No penalty for exercising rights
Exercise of Rights
Send request to: [email protected]
Include: Account email, specific right(s), supporting documentation, proof of identity.
Timelines: GDPR 30 days (extendable 60 days); CCPA 45 days.
7. Processor Obligations
Processing Instructions
Nexus AI processes personal data only in accordance with documented instructions. Processing instructions include purposes, data categories, types of processing, duration, and security measures.
Confidentiality
Staff authorized to process personal data must:
- Be committed to confidentiality or under legal duty of confidentiality
- Receive appropriate data protection training
- Sign confidentiality agreements covering term + beyond
Security Measures
- Technical: TLS/SSL encryption (transit), AES-256 (rest), MFA, access controls, intrusion detection
- Organizational: Staff training, incident response, security audits, data protection by design
- Physical: Restricted data center access, CCTV, secure disposal
- Sub-Processor: Equivalent security via DPA requirements
Audit Rights
Customer may audit compliance (annual or post-breach) with 15 days' notice. Audits limited to 5 business days, confidentiality protections apply. Remediation timelines: Critical 7 days, High 30 days, Medium 60 days.
8. Sub-Processors
Authorized Sub-Processors
| Category | Sub-Processors |
|---|---|
| Payment Processing | Stripe, PayPal, Authorize.Net, Paddle, Whop |
| Infrastructure | AWS, Google Cloud, Azure |
| Analytics | Google Analytics, Amplitude, Sentry, New Relic |
| Support | Zendesk, SendGrid, Twilio |
| Security | Cloudflare, Okta, Vanta |
Notification & Objection
- New Sub-Processors: 30-day advance notice with name, location, data access details
- Customer Objection: Submit written objection within 15 days on reasonable grounds
- Resolution: Nexus AI discusses in good faith; if unresolved, either party may terminate without penalty
- Sub-Processor DPA: All sub-processors execute equivalent DPA with security and compliance requirements
Current Sub-Processor List
View at: nexus-ai.nexus/legal/subprocessors (updated regularly)
9. International Data Transfers
Transfer Jurisdictions
Nexus AI and sub-processors operate globally. Personal data may transfer to USA, EU, and other jurisdictions. These countries may have different data protection standards than your home jurisdiction.
GDPR Transfer Mechanisms
- Standard Contractual Clauses (SCCs): EU-approved model clauses (Decision 2021/914) with Supplementary Measures per Schrems II
- Data Privacy Framework (DPF): EU-U.S., UK-U.S., Swiss-U.S. Data Privacy Frameworks for US transfers
- Adequacy Decisions: For countries deemed adequate by EU/UK
Supplementary Measures
- Encryption of data in transit (TLS) and at rest (AES-256)
- Data minimization and access restrictions
- Contractual safeguards via SCCs
- Technical security controls
- Data subject transparency in privacy notices
10. Security & Confidentiality
Certifications
- ISO 27001:2013 (Information Security Management System)
- SOC 2 Type II (System and Organization Controls)
- PCI DSS Level 1 (via payment processors)
Encryption Standards
- In Transit: TLS 1.2 or higher
- At Rest: AES-256 for sensitive data
- Key Management: Separate from encrypted data, rotated regularly
Access Control
- Role-Based Access Control (RBAC)
- Principle of Least Privilege
- Multi-Factor Authentication (MFA) for admin access
- Automatic session timeouts
Incident Response
Nexus AI maintains incident response plan: Detection → Investigation → Mitigation → Notification → Recovery → Post-Incident Review
11. Audit Rights & Compliance
Customer Audit Rights
- Frequency: Annual or post-breach, max 15 days' notice
- Access: Facilities, systems, documentation, staff
- Duration: Limited to 5 business days
- Confidentiality: Audit findings protected; NDA required
- Remediation: If non-compliance found, Nexus AI provides remediation plan
Third-Party Audits
Nexus AI undergoes SOC 2 Type II audits, ISO 27001 certifications, penetration testing, and regular vulnerability assessments. Audit reports provided upon request.
Regulatory Cooperation
Nexus AI cooperates with data protection authorities, law enforcement (with legal process), and judicial proceedings. Customer notified unless legally prohibited.
12. Data Subject Requests
Request Types
- Access (GDPR 15, CCPA §1798.100): 30 days (GDPR), 45 days (CCPA)
- Deletion (GDPR 17, CCPA §1798.105): 30 days (GDPR), 45 days (CCPA), subject to legal holds
- Correction (GDPR 16, CCPA §1798.110): 10 business days (GDPR), 45 days (CCPA)
- Portability (GDPR 20): Machine-readable format, 30 days (extendable 60 days)
- Restriction (GDPR 18): Suspend processing, 10 business days
- Objection (GDPR 21, CCPA §1798.120): Stop processing, 10 business days
Cooperation & Assistance
Nexus AI will assist by providing personal data, implementing requested actions, providing evidence of compliance, and forwarding requests to sub-processors.
13. Breach Notification
Breach Definition
Unauthorized or accidental access, disclosure, alteration, loss, or destruction of personal data.
Notification Timeline
- Immediate (24 Hours): Notify Customer by email with preliminary breach details
- Detailed (72 Hours): Full breach report: scope, affected data, data subjects, consequences, remediation
- Cooperation: Assist with notification, preserve evidence, provide updates, regular remediation progress
Mitigation
Nexus AI takes immediate steps to contain breach, preserve evidence, assess scope, restore services, implement remediation, and prevent recurrence.
Liability
Governed by DPA and MSA limitation of liability provisions, applicable data protection laws (GDPR fines, CCPA penalties), and cyber liability insurance.
14. Data Deletion & Return
Upon Termination
- Timeline: 30 days for return/deletion
- Method: Secure cryptographic destruction or certified erasure
- Verification: Certificate of destruction provided
- Backups: Deleted within 90 days, not accessible after deletion
Customer Election
- Return: Export all data in machine-readable format within 30 days
- Deletion: Secure deletion with certificate of destruction within 60 days
Legal Retention Exceptions
Personal data retained for:
- Tax records (7 years)
- Legal proceedings (pending/threatened)
- Regulatory obligations
- Fraud prevention (limited data)
Retained data encrypted, segregated, access-restricted, and deleted upon legal expiration.
15. Term & Termination
- Effective Date: November 3, 2025
- Duration: Life of MSA + 30 days for data return/deletion
- Surviving Provisions: Liability, indemnification, confidentiality (indefinite)
- Severability: Invalid provisions severed without affecting rest
- Amendment: 30 days' notice for compliance/sub-processor changes
16. Liability & Indemnification
Liability Cap
- Higher of: (A) total fees paid in 12 months preceding breach, or (B) $100 USD
- GDPR Fines Exception: Liable for GDPR administrative fines up to €20M or 4% global revenue (per GDPR Article 83)
- Insurance: Cyber liability insurance covering data breaches
Indemnification
- Nexus AI indemnifies Customer: From third-party claims arising from Nexus AI's data protection law breach
- Customer indemnifies Nexus AI: From claims arising from Customer's unlawful processing instructions or failure to obtain consent
17. Governing Law & Disputes
Governing Law
- Primary: GDPR (EU/UK) and UK Data Protection Act 2018
- Secondary: CCPA and other applicable privacy laws
- Tertiary: State of California law (without conflict of law)
Dispute Resolution
- Informal Resolution (30 Days): Good-faith negotiation
- Escalation: Executive meeting (15 days)
- Formal Dispute: Arbitration per MSA (AAA, San Francisco/virtual)
- Data Protection Authority: Either party may submit to competent DPA
18. Signature & Acceptance
DPA Acceptance
By creating an account or accessing the Services, Customer acknowledges that they:
- Have read this DPA in its entirety
- Understand Controller and Processor roles
- Agree to comply with this DPA and applicable data protection laws
- Authorize Nexus AI to process personal data per this DPA
- Have authority to enter into this DPA
Binding Effect
This DPA is incorporated into and made part of the MSA. In case of conflict, the DPA shall prevail regarding data protection compliance.
Contact
Privacy & Compliance Team
Email: [email protected]
Website: nexus-ai.nexus/legal/dpa