Art. 28 GDPR terms for businesses that use Nandzz to process their customers' personal data. Part of the Terms of Service. No signature needed.
This document is also available in Italian. For consumers resident in Italy, the Italian version prevails.
This Data Processing Agreement ("DPA") is between:
It applies whenever Nandzz processes personal data on your behalf when it provides the Service, in particular data of your customers and visitors ("Customer Data"). It forms part of the Terms of Service and takes effect when you accept them. If this DPA and the Terms conflict on data protection, this DPA prevails.
Nandzz processes Customer Data only on your documented instructions. These instructions are the Terms, this DPA, and your configuration and use of the Service. The only exception is where EU or Member State law requires otherwise, in which case we will inform you unless that law prohibits it. We will tell you if we believe an instruction infringes data-protection law. We do not sell Customer Data, and we do not use it for our own purposes or to train AI models.
Anyone at Nandzz authorised to process Customer Data is bound by confidentiality. Access is limited to what is needed to provide and support the Service.
We implement the technical and organisational measures in Annex 1 (Art. 32 GDPR).
We may update these measures, but never in a way that lowers the overall level of protection.
You give us general authorisation to engage sub-processors. The current list is in Annex 2 and in our Privacy Policy. We will notify you of any intended addition or replacement at least 30 days in advance, by email or in the dashboard. You may object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected service and receive a refund of any prepaid, unused period.
Each sub-processor is bound by data-protection obligations equivalent to this DPA. We remain liable for their performance.
Taking into account the nature of the processing, we will help you:
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will include the information available to us that you need for your own notifications under Arts. 33–34 GDPR, and we will update it as we learn more.
You can delete bookings at any time. By default, customer details in bookings are anonymised 24 months after the appointment. When you close your account, we delete Customer Data within 30 days, and backups are overwritten within a further 30 days. The only exception is data we must keep by law.
Before closing your account, you can export your data from Settings.
We will make available the information needed to demonstrate compliance with Art. 28 GDPR. This includes this DPA, our security measures and our sub-processors' certifications. Where that is not enough, we will allow audits by you or an independent auditor bound by confidentiality, on 30 days' notice, at your cost, no more than once a year, unless a breach or an authority requires otherwise.
Customer Data is stored in the EU. Where a sub-processor processes it outside the EU/EEA, we ensure an adequate safeguard under Chapter V GDPR. This is an adequacy decision (including the EU–US Data Privacy Framework) or the Standard Contractual Clauses (Module 3, processor-to-processor), which we have entered into with the relevant sub-processor.
You are responsible for:
Liability under this DPA follows the Terms, without limiting either party's liability to data subjects under Art. 82 GDPR. This DPA lasts as long as we process Customer Data for you. Contact: [email protected].
| Provider | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, server functions | All account, content, booking and billing records | EU (AWS Ireland / Frankfurt) | EU hosting; SCCs for support access from the US |
| Amazon Web Services EMEA SARL (Amplify, CloudFront, SES) | Website hosting and delivery; transactional email (booking confirmations and reminders) | IP address, request metadata, email address and message content | EU/EEA | Not required (EU/EEA) |
| Twilio Inc. | WhatsApp booking reminders and replies; phone verification SMS | Phone number, message content | United States | EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| OpenAI, L.L.C. | AI agent answers and document search (embeddings) | Chat messages typed by visitors; documents uploaded by the business | United States | EU–US Data Privacy Framework and/or Standard Contractual Clauses |
| Google Ireland Ltd. / Google LLC | Sign in with Google; address autocomplete (Places) when you type an address | Google account name, email, avatar; typed address text and IP address | Ireland; United States | EU–US Data Privacy Framework and/or Standard Contractual Clauses |