Preparing your workspace

NexoraNow legal

Data Processing Addendum

Data protection terms for business customers using NexoraNow to process personal data.

Effective date
July 26, 2026
Version
2026-07-26

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Use between the business customer ("Customer") and NexoraNow. It applies when NexoraNow processes personal data on Customer’s behalf in providing the Services.

Customer is the controller or business, and NexoraNow is the processor or service provider, as those terms are defined by applicable data protection law. Each party will comply with its own legal obligations. Terms not defined here have the meaning in the Terms of Use or applicable law.

2. Customer instructions

NexoraNow will process personal data only to provide, secure, support, and improve the Services; comply with the agreement and documented Customer instructions; and meet legal obligations. The agreement, Customer’s configuration, and authorized use of the Services are Customer’s documented instructions.

Customer is responsible for the lawfulness of its instructions, notices, consents, and data collection. NexoraNow will notify Customer if an instruction appears to violate applicable data protection law, unless legally prohibited.

3. Processing details

  • Subject matter: operation and support of the modules, integrations, websites, automations, storage, analytics, and AI features selected by Customer.
  • Duration: the subscription term plus the period needed for deletion, return, backup cycling, dispute resolution, or legal compliance.
  • Nature and purpose: collection, hosting, organization, retrieval, transmission, analysis, generation, classification, support, security, deletion, and other processing directed through the Services.
  • Data subjects: Customer’s users, staff, drivers, customers, prospects, vendors, website visitors, contacts, invitees, and other individuals whose data Customer submits.
  • Data types: identity and contact data, account and role data, business records, messages, Slack metadata and files, images, vehicle and inspection records, maintenance data, appointments, orders, transaction metadata, website activity, support data, and AI inputs and outputs.
  • Sensitive data: not intended unless a specific feature and written agreement permit it. Customer must not submit regulated health, biometric, precise location, government identifier, financial account, or similarly sensitive data without confirming the Services are suitable and lawful for that processing.

4. Confidentiality and security

NexoraNow will ensure people authorized to process personal data are bound by confidentiality duties. NexoraNow will maintain appropriate technical and organizational measures designed to protect personal data based on the nature of processing, available technology, implementation cost, and risks to individuals.

  • Access controls and role-based permissions.
  • Encryption in transit and appropriate storage protections.
  • Tenant separation and service authentication controls.
  • Logging, monitoring, vulnerability management, backups, and recovery practices appropriate to the Services.
  • Incident response and personnel or provider confidentiality controls.
  • Periodic review of safeguards and data minimization practices.

5. Subprocessors

Customer authorizes NexoraNow to use subprocessors for hosting, databases, storage, authentication, communications, payments, support, analytics, and AI functions. NexoraNow will require subprocessors to protect personal data through written obligations appropriate to their services.

NexoraNow remains responsible for subprocessor performance to the extent required by applicable law. Customer may object to a new subprocessor on reasonable data-protection grounds by contacting us promptly after notice. The parties will work in good faith on a commercially reasonable resolution.

6. Individual rights and assistance

Taking into account the nature of processing, NexoraNow will reasonably assist Customer with requests from individuals to exercise privacy rights. If NexoraNow receives a request concerning Customer-controlled data, we may direct the requester to Customer unless law requires otherwise.

NexoraNow will provide reasonable information to help Customer complete legally required impact assessments, consultations, security reviews, and compliance inquiries, considering the information available to NexoraNow.

7. Security incidents

NexoraNow will notify Customer without undue delay after confirming unauthorized access to or acquisition, alteration, loss, or disclosure of Customer personal data for which notice is required by applicable law. Notice will include available information reasonably needed for Customer’s response and will be updated as appropriate.

Notification is not an admission of fault or liability. Customer is responsible for notifications to individuals and regulators unless law assigns that duty to NexoraNow.

8. Return and deletion

At the end of the Services, NexoraNow will delete or return Customer personal data upon Customer’s reasonable request, unless retention is required by law or permitted for security, backup, dispute, or compliance purposes. Data in backups will be protected and deleted through normal backup cycles.

9. International transfers

If Customer personal data is transferred across borders in a way that requires a transfer mechanism, the parties will use an applicable lawful mechanism, which may include standard contractual clauses and supplementary safeguards. Customer authorizes processing in locations used by NexoraNow and its approved subprocessors subject to these protections.

10. Audits

NexoraNow will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request a reasonable audit no more than once per year, or after a confirmed material security incident, subject to confidentiality, security, non-disruption, and cost-allocation terms. Third-party reports or certifications may satisfy the request where appropriate.

11. U.S. state privacy terms

Where U.S. state privacy law applies, NexoraNow acts as Customer’s service provider or processor. NexoraNow will not sell Customer personal data, share it for cross-context behavioral advertising, retain or use it outside the business purposes in the agreement, or combine it with personal data received from another source except as permitted by applicable law.

12. Order of precedence and contact

If this DPA conflicts with the Terms of Use on processing Customer personal data, this DPA controls. All other provisions of the Terms remain in effect.

Data protection questions may be sent to privacy@nexoranow.com.