Data Processing Addendum (DPA)
Terms for Nubesti’s processing of personal data on behalf of customers when providing the platform and related services.
Last updated: September 21, 2026
This Data Processing Addendum (“DPA”) is part of the Terms of Service when Nubesti LLC processes personal data on behalf of a customer in connection with the services.
If there is a conflict about data-processing terms, this DPA controls.
1. Roles
Customer is the controller (or a processor acting for a controller) of Customer Personal Data submitted to the platform.
Nubesti is the processor (or sub-processor) of that Customer Personal Data.
Nubesti remains an independent controller of account, billing, website, and support data, as described in the Privacy Policy.
2. Details of processing
- Subject matter: hosting and processing data needed to operate AI red team and security-testing services
- Duration: the subscription term plus a short deletion or export window
- Nature: storage, transmission, analysis, reporting, support, and security monitoring
- Purpose: provide the services instructed by the customer
- Types of data: account identifiers, asset metadata, logs, findings, and any personal data the customer chooses to include in scope
- Data subjects: the customer’s personnel and, if present in scope, users of tested systems
The customer must not submit special-category data or children’s data unless we have agreed in writing.
3. Customer instructions
Nubesti will process Customer Personal Data only on documented instructions from the customer (including configuration in the product) unless law requires otherwise. The Terms, this DPA, and product settings are the complete instructions unless we agree to others in writing.
The customer is responsible for the lawfulness of its instructions and for notices and consents owed to data subjects.
4. Confidentiality and personnel
We restrict access to personnel who need it and who are bound by confidentiality. See the Security Overview.
5. Security
We implement appropriate technical and organizational measures, including encryption in transit, access control, logging, and vulnerability management. The customer is responsible for configuring scope, users, and integrations securely.
6. Subprocessors
The customer authorizes Nubesti to use the subprocessors listed at /legal/subprocessors/. We will impose data-protection terms no less protective than this DPA.
We will post updates to that list. If you object to a new subprocessor on reasonable data-protection grounds within 15 days, we will discuss alternatives; if none are feasible, you may terminate the affected service for a pro-rata refund of unused prepaid fees.
7. International transfers
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that the applicable Standard Contractual Clauses (and UK addendum where required) are incorporated, with Nubesti as data importer. For module 2 (controller to processor) unless the customer is itself a processor, in which case module 3 applies.
8. Assistance
Taking into account the nature of processing, we will assist the customer with data-subject requests, DPIAs, and consultations with authorities, at our standard professional-services rates if the assistance is excessive.
If we receive a request directed at Nubesti about Customer Personal Data, we will redirect the requester to the customer where allowed.
9. Breach notice
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information we can reasonably disclose to help the customer meet its own notice duties.
10. Audits
Upon written request no more than once per year (unless a regulator or incident requires more), we will provide security summaries or independent reports we have available (for example, questionnaire responses). On-site audits are available if those materials are insufficient, during business hours, subject to confidentiality and reasonable fees.
11. Return and deletion
After termination, the customer may export available reports during the published window. We will delete Customer Personal Data from production systems within 60 days, except copies retained in encrypted backups until rotation or as required by law.
12. Liability
Liability under this DPA is subject to the limitations in the Terms, except where data-protection law forbids limiting liability to data subjects.