Legal
NitroStack Data Processing Addendum
Effective Date: August 17, 2026
Last Updated: August 17, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Nitrostack Inc., a Delaware corporation ("NitroStack," "Processor," "we," "us," or "our"), and the customer or organization identified in the applicable Order Form, agreement, or account ("Customer," "Controller," "you," or "your").
This DPA governs NitroStack's processing of Personal Data contained in Customer Data where NitroStack processes such Personal Data on Customer's behalf and applicable Data Protection Laws require the parties to enter into a data processing agreement.
This DPA supplements the NitroStack Terms of Service, applicable Order Form, enterprise agreement, or other agreement governing Customer's use of the Services (collectively, the "Agreement").
Where NitroStack processes Personal Data for its own independent purposes, including account administration, billing, security, service operation, and other purposes described in the NitroStack Privacy Policy, NitroStack may act as an independent controller or business. Such processing is not governed by this DPA except to the extent expressly stated.
1. DEFINITIONS
Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
1.1 Applicable Data Protection Laws
"Applicable Data Protection Laws" means laws and regulations relating to privacy, data protection, data security, or the processing of Personal Data that apply to the processing of Customer Data under the Agreement, including, where applicable:
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR");
- the UK General Data Protection Regulation ("UK GDPR");
- the UK Data Protection Act 2018;
- applicable Swiss data protection law;
- applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended ("CCPA");
- applicable Indian data protection laws, including the Digital Personal Data Protection Act, 2023 and applicable rules;
- and other applicable privacy and data protection legislation.
1.2 Customer Data
"Customer Data" means data, content, code, files, documents, prompts, configurations, workflows, MCP servers, tools, resources, conversations, AI inputs and outputs, database information, API responses, credentials, tokens, and other information submitted to, stored in, transmitted through, or processed by the Services on Customer's behalf.
1.3 Personal Data
"Personal Data" means information relating to an identified or identifiable natural person, or any equivalent term under Applicable Data Protection Laws.
1.4 Processing
"Processing" has the meaning given to it under the applicable Data Protection Law and includes collecting, recording, organizing, structuring, storing, adapting, retrieving, consulting, using, transmitting, disclosing, restricting, deleting, or otherwise processing Personal Data.
1.5 Data Subject
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
1.6 Subprocessor
"Subprocessor" means a third party engaged by NitroStack to Process Customer Data on NitroStack's behalf in connection with providing the Services.
1.7 Security Incident
"Security Incident" means a confirmed breach of NitroStack's security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Data in NitroStack's possession or control.
A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Data, such as blocked intrusion attempts, port scans, unsuccessful authentication attempts, denial-of-service attempts, or similar events.
2. SCOPE AND APPLICABILITY
2.1 Applicability
This DPA applies only to the extent NitroStack Processes Personal Data contained in Customer Data on Customer's behalf.
This DPA does not apply to:
- information NitroStack processes as an independent controller or business;
- publicly available information;
- information processed by Customer independently of the Services;
- information processed directly by Third-Party Services under their own terms; or
- Personal Data that Customer instructs NitroStack to make publicly accessible.
2.2 Relationship to the Agreement
This DPA forms part of the Agreement.
Except as expressly modified by this DPA, the Agreement remains unchanged.
If there is a conflict between this DPA and the Agreement concerning the Processing of Personal Data on Customer's behalf, this DPA controls to the extent of that conflict.
If a mandatory provision of Applicable Data Protection Laws conflicts with this DPA, the mandatory legal requirement controls.
2.3 Duration
This DPA remains effective for as long as NitroStack Processes Customer Data on Customer's behalf.
The obligations concerning confidentiality, security, deletion, return, cooperation, and other provisions that by their nature should survive termination will survive termination to the extent required by Applicable Data Protection Laws or the Agreement.
3. ROLES OF THE PARTIES
3.1 Customer as Controller
For purposes of Customer Data containing Personal Data, Customer is generally the controller, business, or equivalent responsible party under Applicable Data Protection Laws.
Customer determines:
- the purposes of Processing;
- the means of Processing;
- the categories of Data Subjects;
- the categories of Personal Data;
- the retention requirements applicable to Customer Data; and
- the lawful basis for Processing.
3.2 NitroStack as Processor
NitroStack generally acts as Customer's processor, service provider, or equivalent role when Processing Personal Data contained in Customer Data solely on Customer's behalf and according to Customer's documented instructions.
NitroStack will not use Customer Data for purposes inconsistent with the Agreement, this DPA, or Customer's documented instructions, except where required by applicable law.
3.3 NitroStack as Independent Controller
Nothing in this DPA prevents NitroStack from Processing information as an independent controller or business where NitroStack independently determines the purposes and means of Processing.
Examples may include:
- account administration;
- billing;
- fraud prevention;
- platform security;
- service analytics;
- legal compliance;
- abuse prevention;
- support administration; and
- other Processing described in the NitroStack Privacy Policy.
Such Processing is governed by the NitroStack Privacy Policy and applicable law rather than this DPA.
4. CUSTOMER INSTRUCTIONS
4.1 Documented Instructions
Customer instructs NitroStack to Process Customer Data:
- to provide the Services;
- to perform NitroStack's obligations under the Agreement;
- to maintain and secure the Services;
- to provide customer support;
- to troubleshoot and resolve technical issues;
- to prevent abuse and unauthorized access;
- to perform backups and disaster recovery;
- to comply with Customer's configuration and use of the Services;
- to transmit information to Third-Party Services selected or configured by Customer;
- to comply with Customer's lawful instructions communicated through the Services; and
- as otherwise reasonably necessary to provide the Services.
Customer's use of the Services constitutes an instruction to Process Customer Data for the foregoing purposes.
4.2 Additional Instructions
Customer may provide additional documented instructions concerning the Processing of Customer Data where the Services reasonably support such instructions.
NitroStack will comply with lawful and technically feasible instructions.
If NitroStack reasonably determines that an instruction violates Applicable Data Protection Laws, NitroStack may suspend implementation of the affected instruction and notify Customer.
4.3 Instruction Changes
Changes to Processing instructions that require material modifications to NitroStack's systems, security measures, architecture, or Services may be subject to additional charges or technical limitations where agreed by the parties.
5. CUSTOMER RESPONSIBILITIES
Customer is responsible for:
- establishing an appropriate lawful basis for Processing Personal Data;
- providing legally sufficient privacy notices to Data Subjects;
- obtaining required consents and permissions;
- ensuring that its Processing instructions are lawful;
- determining whether the Services are appropriate for its intended Processing;
- ensuring that Customer Data does not violate Applicable Data Protection Laws;
- responding to Data Subject requests where Customer is the responsible controller;
- determining appropriate retention periods;
- configuring access controls appropriately;
- securing Customer's own systems and applications;
- ensuring that connected third-party systems are appropriately authorized; and
- complying with Applicable Data Protection Laws applicable to Customer's activities.
Customer will not instruct NitroStack to Process Personal Data in a manner that would cause NitroStack to violate Applicable Data Protection Laws.
6. PROCESSING DETAILS
The subject matter, nature, purpose, duration, categories of Data Subjects, and categories of Personal Data processed under this DPA are described in Schedule 1.
The parties acknowledge that the exact content of Customer Data may vary based on Customer's configuration and use of the Services.
7. CONFIDENTIALITY
7.1 Confidentiality Obligations
NitroStack will ensure that persons authorized to Process Customer Data:
- have access only where reasonably necessary;
- are subject to confidentiality obligations; and
- are appropriately instructed regarding the protection of Customer Data.
7.2 Continuing Obligation
Confidentiality obligations will continue after termination of the Agreement for so long as the information remains confidential.
8. SECURITY OF PROCESSING
8.1 Security Measures
NitroStack will maintain appropriate technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Depending on the Services and applicable infrastructure, such measures may include:
- encryption in transit;
- encryption at rest;
- authentication controls;
- access controls;
- role-based access controls;
- OAuth;
- API-key mechanisms;
- JWT-based security mechanisms;
- monitoring;
- logging;
- security controls;
- backup and recovery mechanisms; and
- organizational access restrictions.
8.2 Security Appropriate to Risk
NitroStack will maintain security measures appropriate to the nature, scope, context, and risks of the Processing.
NitroStack does not warrant that its security measures will prevent every possible security incident.
8.3 Customer Security Responsibilities
Customer remains responsible for:
- Account credentials;
- Authorized User access;
- Customer applications;
- MCP servers;
- connected systems;
- API keys;
- OAuth credentials;
- Customer-controlled integrations;
- Customer-developed code;
- security configuration under Customer's control; and
- other systems not controlled by NitroStack.
9. SECURITY INCIDENTS
9.1 Notification
If NitroStack becomes aware of a Security Incident affecting Customer Data, NitroStack will notify Customer without undue delay after confirming the Security Incident and to the extent required by Applicable Data Protection Laws.
Notification may be made to the contact information associated with Customer's Account or the designated security/privacy contact provided by Customer.
9.2 Incident Information
Where reasonably available and legally permissible, NitroStack's notification may include:
- the nature of the Security Incident;
- the categories of Customer Data affected;
- the categories of Data Subjects affected;
- the likely consequences;
- measures taken or proposed to address the incident; and
- other information reasonably necessary for Customer to satisfy its legal obligations.
NitroStack may provide information in phases as additional information becomes available.
9.3 Cooperation
NitroStack will take reasonable steps to:
- investigate the Security Incident;
- contain the incident;
- mitigate its effects;
- restore affected Services where reasonably practicable; and
- provide information reasonably necessary for Customer to comply with Applicable Data Protection Laws.
Customer remains responsible for determining whether it is required to notify a regulator or Data Subject.
10. SUBPROCESSORS
10.1 General Authorization
Customer provides NitroStack with general authorization to engage Subprocessors to Process Customer Data in connection with providing the Services.
NitroStack currently uses infrastructure and service providers that may include:
- Amazon Web Services (AWS) for cloud infrastructure;
- MongoDB for database infrastructure;
- OpenRouter for AI model routing and related AI processing; and
- other providers that may be added as necessary to provide and operate the Services.
NitroStack may update its Subprocessors as the Services evolve.
10.2 Subprocessor Obligations
NitroStack will require Subprocessors to enter into written agreements requiring appropriate data protection and confidentiality obligations appropriate to the nature of the Processing.
NitroStack remains responsible for the performance of its obligations under this DPA to the extent required by Applicable Data Protection Laws.
10.3 Subprocessor Changes
NitroStack may add or replace Subprocessors where reasonably necessary to provide or improve the Services.
Where Applicable Data Protection Laws require notice or an objection mechanism, NitroStack will provide such notice and mechanism.
NitroStack may provide notice through:
- its website;
- a subprocessors page;
- the Services;
- email; or
- another reasonable communication method.
10.4 Objections
Where Applicable Data Protection Laws provide Customer with a right to object to a Subprocessor, Customer may exercise that right by providing NitroStack with written notice identifying reasonable data-protection grounds for the objection.
The parties will work in good faith to address the objection.
If NitroStack cannot reasonably accommodate the objection, the parties may discuss commercially reasonable alternatives.
11. THIRD-PARTY AI MODEL PROVIDERS
11.1 AI Processing
The Services may transmit AI inputs to model providers or routing services selected or configured through the Services.
NitroStack currently uses OpenRouter for model routing.
Depending on the model and configuration, OpenRouter may transmit inputs to the applicable model provider.
11.2 Provider-Specific Practices
AI model providers may maintain their own policies concerning:
- retention;
- logging;
- training;
- abuse detection;
- security;
- geographical processing; and
- other Processing activities.
NitroStack does not represent that all model providers maintain identical practices.
Where Customer selects or enables an AI model or provider, Customer acknowledges that the applicable provider may Process the relevant AI inputs in accordance with its own terms and applicable contractual arrangements.
11.3 Customer Instructions
Customer's use of AI functionality constitutes an instruction to NitroStack to transmit the information necessary to provide the requested AI functionality.
Customer is responsible for determining whether the information it submits to an AI model is appropriate for the selected model and provider.
11.4 No Generalized Training by NitroStack
NitroStack does not use Customer Data to train generalized AI models.
This does not prevent the transmission of AI inputs to a model provider as necessary to provide the Services.
12. DATA SUBJECT RIGHTS
12.1 Requests Received by NitroStack
If NitroStack receives a request from a Data Subject relating to Customer Data for which Customer is the controller, NitroStack will not independently respond to the request except where required by Applicable Data Protection Laws.
Instead, NitroStack may direct the Data Subject to Customer.
12.2 Assistance
Taking into account the nature of the Processing, NitroStack will provide reasonable assistance to Customer, where required by Applicable Data Protection Laws, in responding to Data Subject requests.
Assistance may include:
- providing reasonably available information;
- searching Customer Data;
- correcting or deleting information through available functionality;
- restricting Processing where technically supported; and
- exporting Customer Data where supported.
Customer remains responsible for determining whether a Data Subject request is legally valid and how the request should be fulfilled.
12.3 Costs
Reasonable assistance required under Applicable Data Protection Laws will be provided without additional charge where such assistance is ordinarily supported by the Services.
Where Customer requests assistance beyond NitroStack's ordinary obligations or Service functionality, including extensive custom searches, data manipulation, forensic work, or extraordinary technical assistance, NitroStack may charge reasonable fees agreed with Customer in advance.
13. DATA PROTECTION IMPACT ASSESSMENTS
Taking into account the nature of the Processing and information available to NitroStack, NitroStack will provide reasonable assistance to Customer, where required by Applicable Data Protection Laws, in connection with:
- data protection impact assessments;
- risk assessments;
- consultations with regulators; and
- other legally required privacy assessments.
Customer remains responsible for determining whether a data protection impact assessment is required for its Processing.
14. REGULATORY COOPERATION
Where required by Applicable Data Protection Laws, NitroStack will provide reasonable cooperation and information necessary for Customer to demonstrate compliance with applicable processor obligations.
NitroStack may satisfy such obligations by providing:
- security documentation;
- privacy documentation;
- technical documentation;
- subprocessors information;
- audit reports, where available;
- certifications, where available; or
- other reasonably appropriate compliance information.
NitroStack is not required to disclose information that:
- would compromise security;
- would disclose another customer's confidential information;
- would disclose trade secrets;
- is subject to a legal restriction; or
- is otherwise not reasonably necessary to demonstrate compliance.
15. AUDITS AND ASSESSMENTS
15.1 Audit Rights
Where Applicable Data Protection Laws require Customer to have audit rights, NitroStack will make available information reasonably necessary to demonstrate compliance with its processor obligations.
Customer will first use available NitroStack documentation, security materials, certifications, questionnaires, and other reasonable compliance information before requesting a physical or technical audit.
15.2 Audit Conditions
Where an audit is legally required and documentation is insufficient, Customer may conduct an audit subject to:
- reasonable prior written notice;
- reasonable business hours;
- reasonable scope;
- confidentiality obligations;
- security requirements;
- no disruption to NitroStack's operations;
- protection of other customers' information; and
- reasonable limits on frequency.
Except where prohibited by law, Customer will bear its own audit costs.
NitroStack may charge reasonable costs for extraordinary audit assistance where agreed in advance.
15.3 Independent Reports
Where available, NitroStack may satisfy audit requirements through independent assessments, security questionnaires, certifications, or audit reports rather than permitting direct access to systems.
16. RETURN AND DELETION OF CUSTOMER DATA
16.1 During the Agreement
Customer may manage, export, delete, or modify Customer Data through available Service functionality.
16.2 Upon Termination
Following termination of the Agreement, Customer will generally have 30 days to export available Customer Data, unless a different period is specified in the applicable Agreement.
Following the applicable export period, NitroStack may delete Customer Data from production systems.
16.3 Retention Exceptions
NitroStack may retain Customer Data where required or permitted by law or where reasonably necessary for:
- legal compliance;
- security;
- fraud prevention;
- dispute resolution;
- accounting;
- regulatory requirements;
- backups;
- disaster recovery; or
- establishment, exercise, or defense of legal claims.
Any retained Customer Data remains subject to the confidentiality and data-protection obligations applicable to it.
16.4 Backups
Customer Data may remain temporarily in backup systems following deletion from production systems.
Backup copies will be retained only for the applicable backup lifecycle and will not be restored except where reasonably necessary for disaster recovery, security, legal compliance, or other legitimate operational purposes.
17. INTERNATIONAL DATA TRANSFERS
17.1 General
NitroStack is a United States company and currently operates primary cloud infrastructure in the AWS us-east-2 region in the United States.
Customer Data may therefore be processed in the United States.
Customer acknowledges that NitroStack may use Subprocessors located in other jurisdictions as necessary to provide the Services.
17.2 Transfer Mechanisms
Where Customer Data is subject to restrictions on international transfers under Applicable Data Protection Laws, NitroStack will implement an appropriate lawful transfer mechanism where required.
Depending on the applicable jurisdiction, such mechanisms may include:
- an adequacy decision;
- Standard Contractual Clauses;
- the UK International Data Transfer Addendum;
- Swiss-approved contractual safeguards;
- another legally recognized transfer mechanism; or
- another lawful basis permitted by Applicable Data Protection Laws.
17.3 EU Standard Contractual Clauses
For transfers of Personal Data from the European Economic Area to a country that does not benefit from an applicable adequacy decision, the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 of June 4, 2021 ("EU SCCs") will apply where required.
The applicable module will be determined based on the parties' roles:
- Module Two — Controller to Processor, where Customer is a controller and NitroStack is a processor;
- Module Three — Processor to Processor, where Customer is a processor and NitroStack acts as a subprocessor.
The EU SCCs are incorporated into this DPA by reference to the extent applicable.
If the EU SCCs conflict with this DPA, the EU SCCs control to the extent of the conflict.
17.4 UK International Transfers
For restricted transfers subject to UK data protection law, the applicable UK transfer mechanism will apply.
Where appropriate, the UK International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner's Office, will apply to the relevant transfer.
If the UK transfer mechanism conflicts with this DPA, the applicable mandatory transfer mechanism controls.
17.5 Switzerland
For transfers subject to Swiss data protection law, the EU SCCs will apply with the necessary modifications required under applicable Swiss law, unless another lawful transfer mechanism applies.
18. GOVERNMENT AND LAW ENFORCEMENT REQUESTS
If NitroStack receives a legally binding request from a governmental authority or law enforcement agency for Customer Data, NitroStack may disclose the requested information where legally required.
Where legally permitted and reasonably practicable, NitroStack will:
- notify Customer of the request;
- provide sufficient information to allow Customer to seek protective measures;
- reasonably limit disclosure to the information legally required; and
- cooperate with Customer's lawful efforts to challenge or limit the request.
NitroStack may withhold notice where prohibited by law or where the request concerns an emergency involving potential harm to persons or other circumstances where notice is legally restricted.
19. SENSITIVE DATA
Customer is responsible for determining whether its intended Processing involves:
- special categories of Personal Data;
- health information;
- financial information;
- biometric information;
- children's information;
- government identifiers;
- employment information;
- highly sensitive Personal Data; or
- other specially regulated information.
Unless expressly agreed in writing, NitroStack does not undertake to provide Services specifically designed to satisfy sector-specific requirements applicable to highly regulated information.
Where Customer intends to Process Sensitive Data through the Services, Customer should ensure that the Services and applicable contractual arrangements are appropriate for that Processing.
20. CALIFORNIA DATA PROTECTION TERMS
To the extent NitroStack Processes Personal Information subject to the California Consumer Privacy Act, as amended ("CCPA"), and acts as a service provider or contractor to Customer:
- NitroStack will Process Personal Information only for the limited and specified purposes permitted under the CCPA and the Agreement;
- NitroStack will not sell Personal Information;
- NitroStack will not share Personal Information for cross-context behavioral advertising;
- NitroStack will not retain, use, or disclose Personal Information outside the direct business relationship with Customer except as permitted by the CCPA;
- NitroStack will not combine Personal Information received from Customer with Personal Information received from another customer except as permitted by applicable law;
- NitroStack will provide reasonable assistance to Customer in responding to applicable consumer requests;
- NitroStack will notify Customer if NitroStack determines that it can no longer meet its obligations under applicable CCPA requirements; and
- Customer may take reasonable and appropriate steps to ensure that NitroStack uses Personal Information consistently with Customer's obligations under applicable law.
Nothing in this section prevents NitroStack from Processing information as an independent business for purposes expressly permitted under applicable law, including security, fraud prevention, legal compliance, and other purposes permitted for service providers or contractors.
21. INDIA DATA PROTECTION TERMS
To the extent the Digital Personal Data Protection Act, 2023 or other applicable Indian data protection laws apply to the Processing:
- Customer remains responsible for determining the lawful purpose and means of Processing Personal Data;
- NitroStack will Process Personal Data in accordance with Customer's lawful instructions;
- NitroStack will maintain appropriate safeguards appropriate to the Processing;
- NitroStack will provide reasonable assistance required under applicable law;
- NitroStack will comply with applicable obligations imposed directly on processors or service providers; and
- the parties will cooperate in satisfying applicable statutory requirements.
Where applicable Indian law imposes requirements that cannot be addressed through this DPA, those mandatory requirements will apply.
22. DATA MINIMIZATION
NitroStack will Process Customer Data only to the extent reasonably necessary for:
- providing the Services;
- fulfilling Customer's instructions;
- maintaining security;
- preventing abuse;
- complying with law; and
- performing obligations under the Agreement.
Customer is responsible for determining what Personal Data is necessary for its intended Processing and should avoid submitting unnecessary Personal Data.
23. AGGREGATED AND ANONYMIZED INFORMATION
Nothing in this DPA prevents NitroStack from creating and using information that has been aggregated or anonymized so that it no longer reasonably identifies Customer, a Data Subject, or an individual.
Such information may be used for:
- service analytics;
- security;
- reliability;
- performance measurement;
- product improvement;
- feature development;
- benchmarking; and
- other legitimate business purposes.
NitroStack will not use identifiable Customer Data as a substitute for properly aggregated or anonymized information under this section.
24. AI MODEL TRAINING
NitroStack does not use Customer Data to train generalized AI models.
For avoidance of doubt, this restriction does not prevent:
- Processing Customer Data to provide the Services;
- transmitting AI inputs to applicable model providers;
- processing information necessary to generate AI outputs;
- security and abuse monitoring;
- service operation;
- troubleshooting;
- use of properly aggregated or anonymized information; or
- Processing otherwise permitted under the Agreement or Applicable Data Protection Laws.
Customer acknowledges that independent AI model providers may have their own contractual and data-handling practices.
25. DATA PROTECTION CONTACT
Privacy and data-protection matters concerning this DPA may be directed to:
Nitrostack Inc.
16192 Coastal Highway
Lewes, Delaware 19958
United States
Privacy: privacy@nitrostack.ai
Legal: legal@nitrostack.ai
Customer should ensure that its privacy and security contact information associated with the Services remains current.
26. NO SALE OF CUSTOMER DATA
NitroStack does not sell Customer Data for monetary or other valuable consideration.
NitroStack will not use Customer Data for targeted advertising or cross-context behavioral advertising.
This provision does not restrict:
- Processing necessary to provide the Services;
- use of subprocessors;
- processing by Third-Party Services selected by Customer;
- legally required disclosures; or
- processing otherwise permitted under Applicable Data Protection Laws.
27. ORDER OF PRECEDENCE
In the event of a conflict:
- mandatory Applicable Data Protection Laws control;
- applicable EU SCCs, UK transfer mechanisms, or other mandatory transfer mechanisms control with respect to international transfers;
- this DPA controls with respect to the Processing of Customer Data;
- the applicable enterprise agreement or Order Form controls for commercial matters;
- the NitroStack Terms of Service apply to matters not specifically addressed above.
28. LIMITATION OF LIABILITY
The parties' respective liability under this DPA is subject to the liability limitations contained in the Agreement unless:
- Applicable Data Protection Laws prohibit such limitation;
- the applicable EU SCCs require otherwise; or
- the parties expressly agree otherwise in writing.
Nothing in this DPA limits liability that cannot legally be limited.
29. MODIFICATIONS TO THIS DPA
NitroStack may update this DPA where reasonably necessary to:
- reflect changes in Applicable Data Protection Laws;
- address changes in the Services;
- address changes in Subprocessors;
- implement new transfer mechanisms;
- reflect regulatory guidance; or
- maintain compliance with applicable legal requirements.
NitroStack will provide notice of material changes where required by law or the Agreement.
Changes will not materially reduce Customer's rights under Applicable Data Protection Laws.
30. GENERAL
30.1 No Waiver of Statutory Rights
Nothing in this DPA is intended to waive or limit a statutory right or obligation that cannot legally be waived or limited.
30.2 Severability
If any provision of this DPA is invalid or unenforceable, the remaining provisions remain effective.
30.3 Entire Agreement
This DPA, together with the Agreement and applicable Order Forms, constitutes the parties' agreement concerning NitroStack's Processing of Customer Data on Customer's behalf.
30.4 Electronic Acceptance
The parties may enter into this DPA electronically.
Where Customer accepts an agreement incorporating this DPA, the DPA will become effective without requiring a separate physical signature unless applicable law requires otherwise.
SCHEDULE 1
DETAILS OF PROCESSING
1. Subject Matter
NitroStack Processes Personal Data contained in Customer Data in connection with providing:
- NitroStack Studio;
- NitroStack Cloud/NitroCloud;
- NitroChat;
- NitroStack Composer;
- MCP development and deployment functionality;
- AI functionality;
- workflows;
- integrations;
- application hosting;
- testing and debugging;
- monitoring and support; and
- related Services.
2. Nature of Processing
Processing may include:
- collection;
- transmission;
- storage;
- organization;
- retrieval;
- hosting;
- analysis;
- modification;
- display;
- execution;
- routing;
- synchronization;
- deletion;
- backup;
- security monitoring;
- troubleshooting;
- support; and
- other Processing reasonably necessary to provide the Services.
3. Purpose of Processing
The purposes of Processing are to:
- provide the Services;
- execute Customer instructions;
- operate Customer applications;
- provide AI functionality;
- operate MCP servers and connected tools;
- provide hosting and deployment;
- provide support;
- maintain security;
- prevent abuse;
- troubleshoot;
- maintain backups;
- comply with legal obligations; and
- perform other activities expressly permitted under the Agreement.
4. Duration
Processing will continue for the duration of Customer's use of the Services and for any additional period required for:
- deletion;
- backup expiration;
- legal compliance;
- security;
- dispute resolution;
- fraud prevention;
- accounting; or
- other legitimate retention purposes.
Following termination, Customer will generally have 30 days to export available Customer Data before deletion begins, subject to the Agreement and this DPA.
5. Categories of Data Subjects
Depending on Customer's use of the Services, Data Subjects may include:
- Customer employees;
- Customer contractors;
- Customer users;
- Customer customers;
- Customer prospects;
- application end users;
- website users;
- developers;
- organization administrators;
- Authorized Users;
- business contacts;
- individuals whose information is contained in Customer Data; and
- other individuals whose Personal Data Customer chooses to process through the Services.
6. Categories of Personal Data
Depending on Customer's configuration and use of the Services, Personal Data may include:
- names;
- email addresses;
- usernames;
- account identifiers;
- IP addresses;
- device information;
- authentication information;
- account information;
- organization information;
- communication information;
- application data;
- source code containing Personal Data;
- prompts;
- conversation content;
- AI inputs;
- AI outputs;
- files and documents;
- database information;
- API responses;
- identifiers;
- credentials or authentication information;
- information contained in connected systems;
- usage information;
- technical information; and
- other Personal Data submitted by or on behalf of Customer.
Customer determines which categories of Personal Data are submitted to the Services.
7. Sensitive Personal Data
Customer may be technically capable of processing Sensitive Personal Data through the Services.
Unless expressly agreed otherwise in writing, Customer is responsible for determining whether the Services are appropriate for such Processing and for satisfying any additional legal requirements applicable to that Processing.
8. Frequency of Processing
Processing may occur:
- continuously;
- periodically;
- on demand;
- automatically;
- in response to Customer actions; or
- as otherwise necessary to provide the Services.
SCHEDULE 2
TECHNICAL AND ORGANIZATIONAL MEASURES
NitroStack maintains technical and organizational measures appropriate to the nature of the Services and risks associated with Processing.
The measures may include the following.
1. Access Control
NitroStack maintains controls designed to limit access to Customer Data to authorized personnel and systems.
Access may be managed through:
- authentication;
- role-based permissions;
- access controls;
- administrative controls; and
- other applicable security mechanisms.
2. Encryption
NitroStack uses encryption mechanisms designed to protect data:
- in transit; and
- at rest,
where supported by the applicable infrastructure and Service.
3. Authentication
NitroStack may support:
- account authentication;
- OAuth;
- API keys;
- JWT-based authentication; and
- other authentication mechanisms.
4. Authorization
NitroStack maintains access controls designed to restrict access to resources based on applicable roles and permissions.
5. Monitoring
NitroStack uses operational monitoring and logging to:
- detect operational issues;
- identify suspicious activity;
- troubleshoot problems;
- maintain system reliability; and
- support security investigations.
6. Incident Management
NitroStack maintains processes designed to identify, investigate, contain, and remediate security incidents.
7. Data Retention
NitroStack maintains retention practices appropriate to different classes of information.
Standard operational logs are currently retained for approximately 14 days, subject to applicable exceptions.
Customer Data may be retained for longer periods based on Customer configuration, Service functionality, legal requirements, backups, or other legitimate purposes.
8. Backup and Recovery
NitroStack may maintain backups and recovery mechanisms designed to support service continuity and recovery from operational failures.
Backup retention may differ from production-data retention.
9. Personnel Confidentiality
Personnel authorized to access Customer Data are subject to appropriate confidentiality obligations.
10. Security of Subprocessors
NitroStack requires applicable Subprocessors to maintain appropriate security and data-protection measures appropriate to their role.
11. Physical Security
NitroStack relies on infrastructure providers, including AWS, that maintain physical and environmental security controls for the underlying infrastructure.
12. Vulnerability Management
NitroStack maintains reasonable processes for identifying and addressing vulnerabilities appropriate to its Services and infrastructure.
13. Security Testing
NitroStack may conduct security testing and assessments appropriate to the Services.
NitroStack does not represent that it currently maintains a specific security certification, including SOC 2 or ISO 27001, unless expressly stated in a separate written agreement or security documentation.
SCHEDULE 3
SUBPROCESSOR CATEGORIES
NitroStack may engage the following categories of Subprocessors:
| Category | Purpose |
|---|---|
| Cloud infrastructure | Hosting, compute, storage, networking |
| Database infrastructure | Storage and retrieval of application data |
| AI/model routing | Routing AI inputs and outputs |
| Security and monitoring | Security, reliability, diagnostics and operational monitoring |
| Communications | Service-related communications |
| Payment providers | Billing and payment processing |
| Customer support | Customer support and service operations |
| Other infrastructure providers | Services reasonably necessary to operate NitroStack |
Current known infrastructure includes:
Amazon Web Services (AWS)
Purpose: Cloud infrastructure and hosting
Primary region currently used by NitroStack: us-east-2
MongoDB
Purpose: Database infrastructure
OpenRouter
Purpose: AI model routing and related AI processing
NitroStack may update its Subprocessors as the Services evolve.
SCHEDULE 4
INTERNATIONAL TRANSFER MECHANISM
Where applicable, the parties agree that the following mechanisms will apply.
European Economic Area
For transfers subject to the EU GDPR and requiring a transfer mechanism, the 2021 EU Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 will apply.
Where Customer is a controller and NitroStack is a processor:
Module Two — Controller to Processor applies.
Where Customer is a processor and NitroStack acts as a subprocessor:
Module Three — Processor to Processor applies.
United Kingdom
For restricted transfers subject to UK GDPR, the applicable EU SCCs will be supplemented by the UK International Data Transfer Addendum where required.
Switzerland
For transfers subject to Swiss data protection law, the applicable EU SCCs will be interpreted and supplemented as required by applicable Swiss law.
Alternative Mechanisms
The parties may rely on another lawful transfer mechanism where permitted by Applicable Data Protection Laws.
SCHEDULE 5
CUSTOMER INSTRUCTIONS
For purposes of the applicable data protection legislation, Customer instructs NitroStack to Process Personal Data:
- to provide the Services;
- to host and store Customer Data;
- to transmit and route Customer Data;
- to process AI inputs and outputs where AI functionality is enabled;
- to operate MCP servers, tools, workflows, and connected systems;
- to authenticate and authorize Authorized Users;
- to maintain security;
- to monitor and troubleshoot the Services;
- to provide customer support;
- to perform backups and disaster recovery;
- to prevent fraud and abuse;
- to comply with Customer's configuration and instructions;
- to delete Customer Data in accordance with the Agreement;
- to comply with applicable legal requirements; and
- to perform other Processing reasonably necessary to provide the Services.
Customer may provide additional lawful instructions consistent with the Services and this DPA.
SCHEDULE 6
CALIFORNIA SERVICE PROVIDER TERMS
To the extent applicable under California law, NitroStack is a service provider or contractor with respect to Personal Information processed on behalf of Customer.
NitroStack will:
- process Personal Information only for the limited and specified purposes described in the Agreement;
- not sell Personal Information;
- not share Personal Information for cross-context behavioral advertising;
- not retain, use, or disclose Personal Information outside the direct business relationship except as permitted by applicable law;
- provide reasonable assistance with applicable consumer requests;
- notify Customer if NitroStack determines that it can no longer meet applicable service-provider obligations;
- permit Customer to take reasonable steps to ensure appropriate use of Personal Information;
- permit reasonable monitoring or audits where required by law; and
- require applicable Subprocessors to comply with equivalent obligations appropriate to their Processing.
Customer may take reasonable and appropriate steps to ensure that NitroStack uses Personal Information consistently with Customer's obligations under California law.
END OF DATA PROCESSING ADDENDUM
Nitrostack Inc.
16192 Coastal Highway
Lewes, Delaware 19958
United States
Privacy: privacy@nitrostack.ai
Legal: legal@nitrostack.ai