Skip to content

Legal

Data Processing Addendum

How Nerve processes personal data on a customer’s behalf.

Effective [Effective date]

1. Scope and roles

This addendum forms part of the Terms of Service between you (the controller) and [Nerve legal entity name] (the processor) and applies when we process personal data in Customer Data on your behalf under data protection law, including the GDPR and UK GDPR where they apply.

The subject matter is providing Nerve; the duration is the term of the agreement; the data subjects are your customers, leads, staff and users; the data types are those you put into Nerve; the nature is hosting, storing and processing to deliver the service.

2. Instructions

We process personal data only on your documented instructions, which are the agreement and your use and configuration of the service, unless the law requires otherwise, in which case we will tell you unless prohibited. We will tell you if we believe an instruction breaks the law.

3. Confidentiality and security

People who process personal data for us are bound by confidentiality. We maintain appropriate technical and organizational measures, including encryption in transit, access control and least privilege, workspace isolation, audit logging, vulnerability management and backup and recovery, as described on the Security page.

4. Subprocessors

You authorize the subprocessors listed on the Subprocessors page. We bind them to equivalent obligations and remain responsible for them. We will give at least 30 days’ notice of additions or replacements; you may object on reasonable data protection grounds, and if we cannot resolve it you may terminate the affected service.

5. Assistance

We will help you, taking into account the nature of processing, to respond to data subject requests and to meet your obligations on security, breach notification, impact assessments and prior consultation.

6. Personal data breaches

We will notify you without undue delay after becoming aware of a breach affecting your personal data, with the information we have to help you meet your own obligations.

7. International transfers

We transfer personal data out of the EEA, UK or Switzerland only under an adequacy decision or the standard contractual clauses (and the UK addendum), which are incorporated here and apply as processor-to-subprocessor or controller-to-processor as relevant.

8. Return and deletion

On termination you can export your data for 30 days; afterwards we delete it as set out in the Terms of Service, unless the law requires retention.

9. Audits

We will provide information needed to show compliance and allow audits, including by a mutually agreed independent auditor, on reasonable notice, no more than once a year unless required by a regulator or after a breach, at your cost and subject to confidentiality.

10. Contact

Data protection questions: [privacy@your-domain].

See also: Terms of Service · Privacy Policy · Cookie Policy · Acceptable Use Policy · Subprocessors