Data Processing Agreement
Summary
For customers who are themselves data controllers (e.g. a recruiting firm whose candidates are data subjects), we enter into a Data Processing Agreement (DPA) that complies with the EU GDPR Art. 28 and, where applicable, the UK GDPR.
What the DPA covers
- Subject matter, duration, nature, and purpose of the processing.
- Categories of data subjects and categories of personal data.
- Controller's instructions and processor's obligations.
- Confidential commitments by our personnel.
- Subprocessor list (per Subprocessors) and how to object to changes.
- Technical and organizational measures (per Security).
- Data subject rights: assistance, deletion, return.
- Breach notification: 72 hours of awareness.
- Audit and inspection rights.
- International transfers: EU SCCs where applicable.
- Termination and data return / deletion.
How to get the full DPA
Email admin [at] nestlab [dot] tech with:
- your legal entity name and address;
- signatory name and role;
- the product(s) you intend to use.
We send a counter-signed DPA within 5 business days.
For EU AI Act Scanner customers specifically
Article 10 of the EU AI Act requires data governance for high-risk AI training data. Our DPA includes a per-system data-processing schedule that documents:
- assessment data we store (your answers, scores, generated documents);
- audit-trail data we keep (timestamps, document versions);
- retention windows (Art. 12 record-keeping);
- your obligations as data controller (Art. 10 data governance).
Data residency
Default: EU data residency. Cloudflare edge, EU Polar payouts, Brevo EU transactional email. Cross-border transfers (e.g. Anthropic Claude inference) are covered by EU SCCs in our DPA.
Changelog
- 2026-07-31 — Initial publication.