Data Processing Agreement
Pursuant to Art. 28 GDPR โ Effective: June 2026
This Data Processing Agreement ("DPA") is concluded between NMA Venture Capital GmbH ("Processor"), residing at Am Sandtorkai 27, 20457 Hamburg, Germany, and the Customer using the GRID Platform ("Controller"), and forms part of the Terms of Service.
1. Subject Matter and Duration
The Processor processes personal data on behalf of the Controller in the context of providing the GRID Platform SaaS platform (as described in the Service Description). The duration of this DPA corresponds to the duration of the main contract (Terms of Service).
2. Nature and Purpose of Processing
The Processor processes personal data solely for the purpose of providing the contractually agreed services, including:
- User account management and authentication
- Storage and processing of uploaded documents and task specifications
- AI-powered agent orchestration and data retrieval
- Delivery of transactional notification emails
- Payment and subscription management
3. Categories of Data Subjects and Personal Data
Data subjects
Employees and representatives of the Controller; target contacts and team members whose data is uploaded or processed via agent tasks.
Categories of personal data
- Contact details (name, email address)
- Operational data (task configurations, target site credentials, scraping outputs)
- Usage logs (IP addresses, request parameters, execution metrics)
4. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorized to process personal data are bound by confidentiality agreements
- Implement appropriate technical and organizational security measures (Art. 32 GDPR)
- Assist the Controller in responding to data subject rights requests
- Delete or return all personal data upon termination of the contract
- Provide all necessary information to demonstrate compliance with Art. 28 GDPR
5. Sub-processors
The Controller hereby grants general authorization for the use of sub-processors. Current sub-processors include:
- UpCloud Ltd (Finland) โ Primary server nodes (EU only)
- Mollie B.V. (Netherlands) โ Payment processing (EU only)
- Resend Inc. (USA/EU) โ Transactional email delivery (Standard Contractual Clauses basis)
- Cloudflare Inc. (USA) โ CDN, DNS, and WAF security (Standard Contractual Clauses basis)
- Google Ireland Ltd. (Ireland) โ Sub-processor infrastructure (EU datacenters)
The Processor will notify the Controller of any intended changes concerning additions or replacements of sub-processors, giving the Controller the opportunity to object to such changes.
6. Technical and Organizational Measures (TOMs)
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Access control and principle of least privilege
- Regular security assessments and system trace audits
- Incident response and breach notification procedures
- Regular staff training on data protection
7. Transfers to Third Countries
Where personal data is transferred to sub-processors in third countries (e.g. the USA), such transfers are made on the basis of the EU-U.S. Data Privacy Framework adequacy decision, or Standard Contractual Clauses (SCC) adopted by the EU Commission.
8. Contact
For DPA-related inquiries: [email protected]