nandzz
Nandzz logonandzz

Where businesses and clients connect.

PlatformGet Started
LegalTerms & ConditionsPrivacy PolicyCookie PolicyAcceptable UseData Processing AgreementLegal notice
SupportContact UsReport content

© 2026 nandzz. All rights reserved.

Nandzz - Share what you create | Product Hunt
HomeSign in
TermsPrivacyCookiesAcceptable UseDPAReport contentLegal notice

Data Processing Agreement

Art. 28 GDPR terms for businesses that use Nandzz to process their customers' personal data. Part of the Terms of Service. No signature needed.

Effective: 6 October 2026·Read in Italiano

This document is also available in Italian. For consumers resident in Italy, the Italian version prevails.

Contents

  1. Parties and scope
  2. Details of the processing
  3. Processing on documented instructions
  4. Confidentiality
  5. Security measures
  6. Sub-processors
  7. Assistance to the Controller
  8. Personal data breaches
  9. Retention, return and deletion
  10. Information and audits
  11. International transfers
  12. Your responsibilities
  13. Liability and term
  14. Annex 1: Technical and organisational measures
  15. Annex 2: Authorised sub-processors

1. Parties and scope

This Data Processing Agreement ("DPA") is between:

  • the business account holder ("Controller", "you")
  • [LEGAL NAME] S.r.l. ("Processor", "Nandzz")

It applies whenever Nandzz processes personal data on your behalf when it provides the Service, in particular data of your customers and visitors ("Customer Data"). It forms part of the Terms of Service and takes effect when you accept them. If this DPA and the Terms conflict on data protection, this DPA prevails.

2. Details of the processing

  • Subject matter and duration: providing the booking, AI agent, messaging and page features of the Service, for as long as you use them.
  • Nature and purpose:
    • collecting and storing bookings
    • showing bookings to you and your staff
    • sending confirmations and reminders by email and, with the customer's opt-in, WhatsApp
    • answering visitor questions with your AI agent
    • hosting and support
  • Data subjects: your customers, prospective customers, website visitors and staff members you add.
  • Categories of data:
    • name, phone number, email
    • address, if you enable that field
    • notes
    • appointment details
    • chat messages
    • staff names and schedules
  • Special categories: none are intended. You must not configure the Service to collect them, for example health data in booking notes, unless you have a lawful basis and have assessed the risk.

3. Processing on documented instructions

Nandzz processes Customer Data only on your documented instructions. These instructions are the Terms, this DPA, and your configuration and use of the Service. The only exception is where EU or Member State law requires otherwise, in which case we will inform you unless that law prohibits it. We will tell you if we believe an instruction infringes data-protection law. We do not sell Customer Data, and we do not use it for our own purposes or to train AI models.

4. Confidentiality

Anyone at Nandzz authorised to process Customer Data is bound by confidentiality. Access is limited to what is needed to provide and support the Service.

5. Security measures

We implement the technical and organisational measures in Annex 1 (Art. 32 GDPR).

We may update these measures, but never in a way that lowers the overall level of protection.

6. Sub-processors

You give us general authorisation to engage sub-processors. The current list is in Annex 2 and in our Privacy Policy. We will notify you of any intended addition or replacement at least 30 days in advance, by email or in the dashboard. You may object on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected service and receive a refund of any prepaid, unused period.

Each sub-processor is bound by data-protection obligations equivalent to this DPA. We remain liable for their performance.

7. Assistance to the Controller

Taking into account the nature of the processing, we will help you:

  • respond to data-subject requests (Arts. 15–22 GDPR). The dashboard lets you view, edit, cancel and delete bookings. If a request reaches us directly, we forward it to you without undue delay and do not answer it ourselves.
  • with security, breach notification, data-protection impact assessments and prior consultation (Arts. 32–36 GDPR)

8. Personal data breaches

We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will include the information available to us that you need for your own notifications under Arts. 33–34 GDPR, and we will update it as we learn more.

9. Retention, return and deletion

You can delete bookings at any time. By default, customer details in bookings are anonymised 24 months after the appointment. When you close your account, we delete Customer Data within 30 days, and backups are overwritten within a further 30 days. The only exception is data we must keep by law.

Before closing your account, you can export your data from Settings.

10. Information and audits

We will make available the information needed to demonstrate compliance with Art. 28 GDPR. This includes this DPA, our security measures and our sub-processors' certifications. Where that is not enough, we will allow audits by you or an independent auditor bound by confidentiality, on 30 days' notice, at your cost, no more than once a year, unless a breach or an authority requires otherwise.

11. International transfers

Customer Data is stored in the EU. Where a sub-processor processes it outside the EU/EEA, we ensure an adequate safeguard under Chapter V GDPR. This is an adequacy decision (including the EU–US Data Privacy Framework) or the Standard Contractual Clauses (Module 3, processor-to-processor), which we have entered into with the relevant sub-processor.

12. Your responsibilities

You are responsible for:

  • the lawfulness of the processing you instruct, including having a legal basis
  • providing privacy information to your customers
  • obtaining consent where required, for example for marketing messages
  • the accuracy of the data you enter

13. Liability and term

Liability under this DPA follows the Terms, without limiting either party's liability to data subjects under Art. 82 GDPR. This DPA lasts as long as we process Customer Data for you. Contact: [email protected].

14. Annex 1: Technical and organisational measures

  • Encryption in transit (TLS 1.2+) and at rest for databases, storage and backups
  • Database row-level security, so each business can only access its own records
  • Service-role keys kept server-side only
  • Least-privilege staff access, with multi-factor authentication on admin and provider consoles
  • Hashed passwords, and OAuth sign-in support
  • Rate limiting and abuse detection on public endpoints
  • Sandboxed rendering of user-uploaded web content, isolated from the application origin
  • Automated backups with point-in-time recovery from our database provider
  • Data minimisation: optional fields are off by default, visitor statistics are hashed daily, and automatic retention sweeps run
  • Incident response procedure and logging of administrative actions

15. Annex 2: Authorised sub-processors

Sub-processors that may process Customer Data

ProviderPurposeDataLocationTransfer safeguard
Supabase, Inc.Database, authentication, file storage, server functionsAll account, content, booking and billing recordsEU (AWS Ireland / Frankfurt)EU hosting; SCCs for support access from the US
Amazon Web Services EMEA SARL (Amplify, CloudFront, SES)Website hosting and delivery; transactional email (booking confirmations and reminders)IP address, request metadata, email address and message contentEU/EEANot required (EU/EEA)
Twilio Inc.WhatsApp booking reminders and replies; phone verification SMSPhone number, message contentUnited StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses
OpenAI, L.L.C.AI agent answers and document search (embeddings)Chat messages typed by visitors; documents uploaded by the businessUnited StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses
Google Ireland Ltd. / Google LLCSign in with Google; address autocomplete (Places) when you type an addressGoogle account name, email, avatar; typed address text and IP addressIreland; United StatesEU–US Data Privacy Framework and/or Standard Contractual Clauses