Data processing agreement
1. Scope
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer", acting as Controller) and DEED B.V. (DEED Vision division) ("we", "us", acting as Processor) for the use of the NEXERA PXM service ("Service"). It applies to all personal data we process on your behalf in connection with the Service.
2. Definitions
Terms not defined here have the meaning given in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Customer Data" means the data you provide to or upload into the Service. "Personal Data" means Customer Data that constitutes personal data under the GDPR.
3. Subject & duration
The subject of processing is the provision of the Service. Duration is the term of the underlying subscription, plus the 30-day export window described in §11 (Return & deletion).
4. Data & data subjects
Categories of data subjects: your end customers, suppliers, employees and other contacts whose personal data you choose to store in the Service.
Categories of personal data: typically name, email address, phone number, postal address, role, company, and any other personal data you choose to include in product fields, attachments or notes.
Special categories of personal data: none required for the Service. You agree not to upload special-category data (Art. 9 GDPR) unless we have agreed to it in writing.
5. Processor obligations
We will:
- Process Personal Data only on your documented instructions, including for international transfers.
- Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures (see §6).
- Assist you with data subject requests (§8) and impact assessments, where reasonably required.
- Notify you of data breaches affecting your Personal Data without undue delay (§9).
6. Security measures
Our measures include:
- TLS 1.2+ in transit, AES-256 at rest.
- Row-level isolation between customer tenants in the database (Postgres RLS).
- Principle-of-least-privilege access controls; production access limited to a small number of named engineers, MFA enforced.
- Hashed passwords (Argon2id), short-lived JWT access tokens with rotating refresh tokens.
- Daily encrypted backups, 30-day retention, tested restore procedures.
- Audit logging on destructive operations and admin actions.
- Regular dependency scanning and security patching.
- Sub-processor SOC 2 / ISO 27001 vetting where applicable.
7. Sub-processors
You authorize us to engage the sub-processors listed below. We remain responsible to you for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Subscription billing | US |
| Anthropic PBC | AI content generation (Claude) | US |
| OpenAI, LLC | AI content generation (where opted in) | US |
| xAI Corp. | AI content generation (where opted in) | US |
| Cloudflare, Inc. | CDN, R2 object storage | EU / US |
| Resend, Inc. | Transactional email | US |
| Sentry (Functional Software, Inc.) | Error tracking | US |
We will notify you at least 30 days before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if we cannot accommodate, you may terminate the affected subscription with a pro-rata refund.
8. Data subject requests
If we receive a request from one of your data subjects, we will forward it to you and not respond directly unless required by law. We will assist you, at your cost, in responding to such requests by providing reasonable technical and organizational measures.
9. Breach notification
We will notify you of a personal data breach affecting your data without undue delay, and within 72 hours of becoming aware of it where feasible. The notification will include the nature of the breach, the categories and approximate number of data subjects, likely consequences, and the measures taken or proposed.
10. Audits
You may audit our compliance with this DPA once per year on reasonable prior notice, during normal business hours, and at your cost. We may satisfy audit requests by providing independent third-party reports (e.g., SOC 2, ISO 27001) where available.
11. Return & deletion
Within 30 days of termination, you may export your Customer Data via the Service. After this period, or earlier on your written request, we will delete all Customer Data from production systems within 30 days, and from backups as they expire according to the rolling 30-day cycle.
12. International transfers
Where Personal Data is transferred outside the European Economic Area, the transfer is governed by the European Commission's Standard Contractual Clauses (Module Two: controller to processor), which are incorporated into this DPA by reference. We have additional safeguards in place including encryption and access controls.
13. Liability
Each party's liability under this DPA is subject to the limitation of liability set out in the underlying customer agreement.
14. Governing law
This DPA is governed by the laws of the Netherlands. Disputes will be brought before the competent court in Roermond, Netherlands.
Contact: privacy@nexerapxm.com