Data processing agreement
The GDPR Article 28 agreement available to every customer.
If your automations handle personal data — customer names, email addresses, order details — GDPR requires a written agreement between you and any service processing that data on your behalf. That agreement is the DPA.
You are the controller: it's your data and your instructions. Nodest is the processor: we handle it only as your automations tell us to.
The DPA forms part of the Terms of Service and takes effect the moment you accept them. Read the full DPA whenever you need it.
What it covers
| Purpose and duration | Why data is processed and for how long |
| Data and data subjects | What kinds of personal data, and whose |
| Your instructions | Your automation configurations are the binding instruction |
| Security | Technical and organisational measures under Art. 32 |
| Sub-processors | Who else is involved, and your right to object |
| Data subject rights | Help with access, deletion, and correction requests |
| Breach notification | Within 72 hours of a confirmed breach |
| Deletion | What happens to your data when you leave |
| Audit rights | Your right to verify compliance |
| International transfers | No transfers outside the EEA without proper safeguards |
Sub-processors and your right to object
Changes are announced by updating the sub-processors page with a visible "last updated" date, so it's worth checking periodically.
You can object to a new sub-processor within 10 days of that update, in writing, on specific data protection grounds. If we can't reasonably accommodate the objection, either party may end the agreement.
If there's a breach
We notify you without undue delay, and within 72 hours of becoming aware of a confirmed breach affecting personal data processed under the DPA — in time for your own notification duty to a supervisory authority.
