Data processing agreement
The GDPR Article 28 agreement available to every customer.
If your automations handle personal data — customer names, email addresses, order details — GDPR requires a written agreement between you and any service processing that data on your behalf. That agreement is the DPA.
You are the controller: it's your data and your instructions. Nodest is the processor: we handle it only as your automations tell us to.
The DPA is incorporated into the Terms of Service. If you're a business customer processing personal data through your automations, accepting the Terms accepts the DPA — there's nothing separate to sign. Read the full DPA whenever you need it.
What it covers
| Purpose and duration | Why data is processed and for how long |
| Data and data subjects | What kinds of personal data, and whose |
| Your instructions | Your automation configurations are the binding instruction |
| Security | Technical and organisational measures under Art. 32 |
| Sub-processors | Who else is involved, and your right to object |
| Data subject rights | Help with access, deletion, and correction requests |
| Breach notification | Within 72 hours of a confirmed breach |
| Deletion | What happens to your data when you leave |
| Audit rights | Your right to verify compliance |
| International transfers | No transfers outside the EEA without proper safeguards |
Sub-processors and your right to object
Changes are announced by updating the sub-processors page with a visible "last updated" date, so it's worth checking periodically.
You can object to a new sub-processor within 10 days of that update, in writing, on specific data protection grounds. If we can't reasonably accommodate the objection, either party may terminate the affected subscription on 30 days' written notice, without penalty.
Where a sub-processor becomes unavailable without warning, or has to be replaced immediately for legal or security reasons, we may make the change first and post it within 5 days. Your right to object still applies, running from that notice.
If there's a breach
We notify you without undue delay, and within 72 hours of becoming aware of a confirmed breach affecting personal data processed under the DPA — in time for your own notification duty to a supervisory authority.
