Data Processing Agreement

Last updated: 2026-07-31

Summary

For customers who are themselves data controllers (e.g. a recruiting firm whose candidates are data subjects), we enter into a Data Processing Agreement (DPA) that complies with the EU GDPR Art. 28 and, where applicable, the UK GDPR.

What the DPA covers

  • Subject matter, duration, nature, and purpose of the processing.
  • Categories of data subjects and categories of personal data.
  • Controller's instructions and processor's obligations.
  • Confidential commitments by our personnel.
  • Subprocessor list (per Subprocessors) and how to object to changes.
  • Technical and organizational measures (per Security).
  • Data subject rights: assistance, deletion, return.
  • Breach notification: 72 hours of awareness.
  • Audit and inspection rights.
  • International transfers: EU SCCs where applicable.
  • Termination and data return / deletion.

How to get the full DPA

Email admin [at] nestlab [dot] tech with:

  • your legal entity name and address;
  • signatory name and role;
  • the product(s) you intend to use.

We send a counter-signed DPA within 5 business days.

For EU AI Act Scanner customers specifically

Article 10 of the EU AI Act requires data governance for high-risk AI training data. Our DPA includes a per-system data-processing schedule that documents:

  • assessment data we store (your answers, scores, generated documents);
  • audit-trail data we keep (timestamps, document versions);
  • retention windows (Art. 12 record-keeping);
  • your obligations as data controller (Art. 10 data governance).

Data residency

Default: EU data residency. Cloudflare edge, EU Polar payouts, Brevo EU transactional email. Cross-border transfers (e.g. Anthropic Claude inference) are covered by EU SCCs in our DPA.

Changelog

  • 2026-07-31 — Initial publication.