Skip to content
Nidus
ProductsSolutionsPricingContact
Book a Demo →
ProductsSolutionsPricingContactBook a Demo →
All legal documents

Prepared 20 September 2026

Data Processing Agreement

Draft data-processing terms for customer workspace data and commissioned services, with schedules to complete before use.

On this page
Status, parties and rolesProcessing only on documented instructionsConfidentiality and securitySubprocessorsAssistance to the customerInternational transfersInformation, audits and inspectionsReturn and deletion at the end of the servicesAnnex A: details of processingAnnexes B and C: mandatory completion items

On this page

Status, parties and rolesProcessing only on documented instructionsConfidentiality and securitySubprocessorsAssistance to the customerInternational transfersInformation, audits and inspectionsReturn and deletion at the end of the servicesAnnex A: details of processingAnnexes B and C: mandatory completion items

Status, parties and roles

This Data Processing Agreement (DPA) forms part of the agreement between the customer and the Nidus entity named in the agreement. It applies only when Nidus processes Personal Data on the customer's behalf in providing the services. For that processing, the customer is the controller and Nidus is the processor, unless the parties document another role allocation for a specific activity.

The customer confirms that its documented instructions are lawful and that it has given affected people the information and obtained the permissions or other lawful basis required for the processing. This DPA does not prevent either party from complying with its own direct legal obligations.

If the customer is itself a processor, it confirms that it has the relevant controller’s authorisation to appoint Nidus as a subprocessor and to give these instructions. The same downstream protections apply. Each party acts independently as controller for its own necessary business administration, subject to its privacy notice.

In this DPA, data-protection law means the UK GDPR and the Data Protection Act 2018, as amended, and other data-protection law applicable to the agreed processing. Personal Data, controller, processor, processing and personal data breach have their legal meanings. Customer Personal Data is personal data processed by Nidus on the customer’s behalf. For data-protection matters, this DPA takes priority over inconsistent Service Terms or order terms; mandatory international-transfer clauses take priority over this DPA.

Processing only on documented instructions

Nidus will process Personal Data only on the customer's documented instructions, including as necessary to provide the services under the agreement and this DPA, unless applicable law requires other processing. If law requires Nidus to process other than on the customer's instructions, Nidus will inform the customer before doing so unless law prohibits that information.

Nidus will promptly tell the customer if, in its opinion, an instruction infringes applicable data-protection law. The customer may provide further documented instructions during the term, subject to the agreement and any agreed change control.

Instructions do not authorise Nidus to sell Customer Personal Data or use it to train general-purpose AI models for its own purposes. Any different processing purpose requires a separate lawful role assessment and agreement before it begins.

Confidentiality and security

Nidus will ensure that people authorised to process Personal Data are bound by confidentiality obligations or are under an appropriate statutory duty of confidentiality. Nidus will implement appropriate technical and organisational measures required by Article 32 UK GDPR, taking account of the nature, scope, context and purposes of processing and the risk to individuals.

The actual measures must be completed in Annex B and verified against the live service before this DPA is used. Do not claim encryption, hosting geography, backup, recovery, certification, penetration testing, incident-response timing or access-control measures unless they are current and evidenced.

Subprocessors

The customer gives general written authorisation for Nidus to use the subprocessors listed in Annex C. Before adding or replacing a subprocessor that will process Personal Data, Nidus will give the customer prior written notice and a reasonable opportunity to object on data-protection grounds. The final DPA must state the notice channel, notice period and the practical resolution where an objection cannot reasonably be resolved.

Nidus will bind each authorised subprocessor by written obligations that provide an equivalent level of data protection to the obligations in this DPA, and remains responsible to the customer for the performance of those obligations.

Assistance to the customer

Taking account of the nature of processing, Nidus will assist the customer by appropriate technical and organisational measures, where possible, to respond to requests from individuals exercising their rights under applicable data-protection law. Nidus will promptly forward to the customer any such request it receives in relation to Customer Personal Data, unless prohibited by law, and will not respond except on the customer's documented instruction or where law requires it.

Taking account of the nature of processing and information available, Nidus will assist the customer with its obligations relating to security, personal-data-breach notification, communication of a breach to individuals, data-protection impact assessments and prior consultation with the supervisory authority. The processing schedule must identify the customer’s incident contact and any additional notification arrangements; these do not postpone the notification duty below.

Nidus will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. It will provide the information available about the nature of the breach, affected people and records, likely consequences, contact point and mitigation, and supplement that information as it becomes available. Assistance and further timing arrangements do not postpone this notification duty.

International transfers

Nidus will not make a restricted transfer of Personal Data outside the United Kingdom except on the customer's documented instructions or where necessary to use an authorised subprocessor, and only where the transfer is permitted by applicable data-protection law. The applicable transfer mechanism, country or territory, receiving entity and supplementary measures must be recorded in Annex C before publication.

Where a transfer mechanism requires further contractual terms, the parties will enter into the required data-transfer terms and will complete any risk assessment or other steps required by applicable law.

Information, audits and inspections

Nidus will make available the information reasonably necessary to demonstrate compliance with this DPA and Article 28, and will allow for and contribute to audits and inspections by the customer or its independent auditor. The final DPA should define reasonable confidentiality, notice, frequency, scope, security and cost arrangements for audits, without removing the customer's Article 28 audit right.

Nidus will notify the customer if it believes an audit instruction conflicts with applicable law, exposes another customer's confidential information, or creates a material security risk, and the parties will work in good faith to agree a lawful alternative method of assurance.

Return and deletion at the end of the services

On termination or expiry of the applicable services, and at the customer's choice, Nidus will return or delete Customer Personal Data and delete existing copies, unless applicable law requires storage. The final DPA must specify the method, export format, time allowed for a return request, deletion timeframe and treatment of backups and archives.

Where immediate deletion from a backup is not technically practicable, the data must be put beyond use, protected under this DPA and deleted in accordance with the verified backup-deletion cycle. The current materials do not establish that cycle, so no duration should be published until it is confirmed.

Annex A: details of processing

Subject matter and duration: provision of the Nidus services and professional services for the term of the applicable Order, plus any verified return/deletion period. Nature and purpose: hosting, access, configuration, support, integration and other processing necessary to provide the agreed services and follow the customer's documented instructions.

Types of Personal Data: to be completed by the customer and may include account, contact, customer-relationship, project, time, invoice, supplier, marketing, document, communication and other data submitted or connected by the customer. Categories of individuals: to be completed by the customer and may include its users, staff, customers, prospects, suppliers and other people whose data the customer chooses to process. The customer must identify any special-category or criminal-offence data and may not submit it unless expressly agreed in writing with appropriate safeguards.

Controller rights and obligations: the customer determines the purposes and means of Customer Personal Data, remains responsible for lawful instructions and notices, and may exercise the audit, assistance, subprocessor-objection and return/deletion rights stated in this DPA.

Annexes B and C: mandatory completion items

Annex B must list only verified technical and organisational measures. Annex C must list each subprocessor, its processing purpose, processing location, applicable transfer mechanism and current URL or contact for change notices. Neither annex can be completed accurately from the public website alone.

Before signature or publication, confirm the Nidus legal entity, hosting and storage locations, support access locations, current subprocessors, connected-provider role allocation, security measures, incident contacts, retention/deletion cycle, export method and any restricted-transfer safeguards.

  • Annex B — access and authorisation controls; staff confidentiality and training; encryption where implemented; service resilience, backups and restore testing; monitoring and incident handling; security assessment and testing; deletion and export procedures. Record evidence and review date for each agreed measure.
  • Annex C — for each subprocessor: legal name, service, data handled, processing and support-access countries, transfer mechanism and safeguard reference. Identify which connected providers are appointed directly by the customer instead.
  • Operating schedule — customer and Nidus privacy/incident contacts; subprocessor change notice method and period; objection resolution; export format and return/deletion timing, including backups. Complete this schedule with the order before processing.

Questions? [email protected]

Privacy & CookiesWebsite Terms of UseService TermsAcceptable Use Policy
Nidus
ProductsSolutionsPricingContact

© Nidus. All rights reserved.

Privacy & CookiesWebsite TermsService TermsAcceptable UseData Processing