Skip to content
NEXERA PXM
How it works Try it Pricing
Sign in Book a demo

Core platform

PIMCentral product repository WorkflowsApproval & task automation DAMDigital asset management SyndicationMulti-channel publishing AI EnrichmentAI in your brand voice SEOCollection optimization

Quick links

How it works Pricing Customers Blog Book a demo →

Channels & marketplaces

ShopifyNative bidirectional sync Google ShoppingProduct feed automation Bol.comNL & BE marketplace Feeds & SFTPAny channel via export AmazonSP-API, all formats

Connect anything

Publish anywhere Marketplaces, retailer feeds, ERPs, if it accepts a product feed, NEXERA syncs to it. See all integrations →

Solutions

For brandsOwn-label & branded products For retailersCurated multi-brand catalog Supplier portalCollect data from suppliers

Company

CustomersWho uses NEXERA SecuritySOC 2, GDPR, encryption CareersJoin the team ContactTalk to sales
Legal · DPA

Data processing agreement

Last updated: 23 May 2026

This is a starting point. This DPA is provided as a template to accompany our standard customer agreement. We recommend having your data protection officer or counsel review it before signature.

On this page

  1. Scope
  2. Definitions
  3. Subject & duration
  4. Data & data subjects
  5. Processor obligations
  6. Security measures
  7. Sub-processors
  8. Data subject requests
  9. Breach notification
  10. Audits
  11. Return & deletion
  12. International transfers
  13. Liability
  14. Governing law

1. Scope

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer", acting as Controller) and DEED B.V. (DEED Vision division) ("we", "us", acting as Processor) for the use of the NEXERA PXM service ("Service"). It applies to all personal data we process on your behalf in connection with the Service.

2. Definitions

Terms not defined here have the meaning given in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Customer Data" means the data you provide to or upload into the Service. "Personal Data" means Customer Data that constitutes personal data under the GDPR.

3. Subject & duration

The subject of processing is the provision of the Service. Duration is the term of the underlying subscription, plus the 30-day export window described in §11 (Return & deletion).

4. Data & data subjects

Categories of data subjects: your end customers, suppliers, employees and other contacts whose personal data you choose to store in the Service.

Categories of personal data: typically name, email address, phone number, postal address, role, company, and any other personal data you choose to include in product fields, attachments or notes.

Special categories of personal data: none required for the Service. You agree not to upload special-category data (Art. 9 GDPR) unless we have agreed to it in writing.

5. Processor obligations

We will:

  • Process Personal Data only on your documented instructions, including for international transfers.
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures (see §6).
  • Assist you with data subject requests (§8) and impact assessments, where reasonably required.
  • Notify you of data breaches affecting your Personal Data without undue delay (§9).

6. Security measures

Our measures include:

  • TLS 1.2+ in transit, AES-256 at rest.
  • Row-level isolation between customer tenants in the database (Postgres RLS).
  • Principle-of-least-privilege access controls; production access limited to a small number of named engineers, MFA enforced.
  • Hashed passwords (Argon2id), short-lived JWT access tokens with rotating refresh tokens.
  • Daily encrypted backups, 30-day retention, tested restore procedures.
  • Audit logging on destructive operations and admin actions.
  • Regular dependency scanning and security patching.
  • Sub-processor SOC 2 / ISO 27001 vetting where applicable.

7. Sub-processors

You authorize us to engage the sub-processors listed below. We remain responsible to you for their performance.

Sub-processorPurposeLocation
Stripe, Inc.Subscription billingUS
Anthropic PBCAI content generation (Claude)US
OpenAI, LLCAI content generation (where opted in)US
xAI Corp.AI content generation (where opted in)US
Cloudflare, Inc.CDN, R2 object storageEU / US
Resend, Inc.Transactional emailUS
Sentry (Functional Software, Inc.)Error trackingUS

We will notify you at least 30 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if we cannot accommodate, you may terminate the affected subscription with a pro-rata refund.

8. Data subject requests

If we receive a request from one of your data subjects, we will forward it to you and not respond directly unless required by law. We will assist you, at your cost, in responding to such requests by providing reasonable technical and organizational measures.

9. Breach notification

We will notify you of a personal data breach affecting your data without undue delay, and within 72 hours of becoming aware of it where feasible. The notification will include the nature of the breach, the categories and approximate number of data subjects, likely consequences, and the measures taken or proposed.

10. Audits

You may audit our compliance with this DPA once per year on reasonable prior notice, during normal business hours, and at your cost. We may satisfy audit requests by providing independent third-party reports (e.g., SOC 2, ISO 27001) where available.

11. Return & deletion

Within 30 days of termination, you may export your Customer Data via the Service. After this period, or earlier on your written request, we will delete all Customer Data from production systems within 30 days, and from backups as they expire according to the rolling 30-day cycle.

12. International transfers

Where Personal Data is transferred outside the European Economic Area, the transfer is governed by the European Commission's Standard Contractual Clauses (Module Two: controller to processor), which are incorporated into this DPA by reference. We have additional safeguards in place including encryption and access controls.

13. Liability

Each party's liability under this DPA is subject to the limitation of liability set out in the underlying customer agreement.

14. Governing law

This DPA is governed by the laws of the Netherlands. Disputes will be brought before the competent court in Roermond, Netherlands.


Contact: privacy@nexerapxm.com

NEXERA PXM

Author your product data once. Publish it everywhere, perfectly.

A product of DEED Vision, the product studio at DEED.

Platform
PIMDAMAI enrichmentWorkflowsSyndicationSEO
Integrations
ShopifyBol.comAmazonGoogle ShoppingFeeds & SFTP
Solutions
For brandsFor retailersB2B portalsSupplier portal
Company
Try it →Why NEXERARoadmapCustomersPricingSecurityBlogCareersContact
© 2026 DEED Vision · part of DEED B.V.GDPR-ready · EU data residency · DPA available PrivacyTermsDPALegal NoticeAccessibility