Build your first automation in under 5 minutes. Sign up for free.

Data processing agreement

The GDPR Article 28 agreement available to every customer.

If your automations handle personal data — customer names, email addresses, order details — GDPR requires a written agreement between you and any service processing that data on your behalf. That agreement is the DPA.

You are the controller: it's your data and your instructions. Nodest is the processor: we handle it only as your automations tell us to.

The DPA is incorporated into the Terms of Service. If you're a business customer processing personal data through your automations, accepting the Terms accepts the DPA — there's nothing separate to sign. Read the full DPA whenever you need it.

What it covers

Purpose and durationWhy data is processed and for how long
Data and data subjectsWhat kinds of personal data, and whose
Your instructionsYour automation configurations are the binding instruction
SecurityTechnical and organisational measures under Art. 32
Sub-processorsWho else is involved, and your right to object
Data subject rightsHelp with access, deletion, and correction requests
Breach notificationWithin 72 hours of a confirmed breach
DeletionWhat happens to your data when you leave
Audit rightsYour right to verify compliance
International transfersNo transfers outside the EEA without proper safeguards

Sub-processors and your right to object

Changes are announced by updating the sub-processors page with a visible "last updated" date, so it's worth checking periodically.

You can object to a new sub-processor within 10 days of that update, in writing, on specific data protection grounds. If we can't reasonably accommodate the objection, either party may terminate the affected subscription on 30 days' written notice, without penalty.

Where a sub-processor becomes unavailable without warning, or has to be replaced immediately for legal or security reasons, we may make the change first and post it within 5 days. Your right to object still applies, running from that notice.

If there's a breach

We notify you without undue delay, and within 72 hours of becoming aware of a confirmed breach affecting personal data processed under the DPA — in time for your own notification duty to a supervisory authority.

Ready to put your workflows on autopilot?

Sign up for free and start building in minutes.

Logo