This Data Processing Agreement ("DPA") forms part of the Terms of Service between NexxoSync ("NexxoSync", the "Processor") and the merchant that uses the Service (the "Customer"). It applies automatically, without a separate signature, whenever NexxoSync processes personal data on the Customer's behalf.
It is drafted to meet article 28 of the GDPR and the UK GDPR, article 25 of Argentine Law 25.326, articles 37 to 39 of Brazil's LGPD and the service-provider requirements of the CCPA. If the Customer needs a countersigned copy for its records, it can request one at [email protected].
01Definitions and roles
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the GDPR, and the equivalent meaning under other applicable data protection laws ("Data Protection Laws"). "Customer Personal Data" means personal data that NexxoSync processes on the Customer's behalf in providing the Service.
- The Customer is the controller (or, where it acts for its own clients, a processor, in which case NexxoSync is its sub-processor). It decides which data is processed, for what purposes and on what legal basis.
- NexxoSync is the processor ("encargado del tratamiento" under Law 25.326 and "operador" under the LGPD; "service provider" under the CCPA).
- Data that NexxoSync processes as a controller — account, billing, support and website data — is governed by the Privacy Policy, not by this DPA.
02Subject matter, duration, nature and purpose
| Item | Description |
|---|---|
| Subject matter | Providing the Service: reading, transforming and writing data between the platforms the Customer connects, and running the AI assistants the Customer configures |
| Nature of processing | Collection through platform APIs and webhooks, transformation, transmission to the Customer's other platforms and to the AI provider the Customer selects, temporary storage, and deletion |
| Purpose | Keeping products, stock, prices, orders and customers in sync; answering the questions of the Customer's buyers and website visitors with catalog and order data; showing the Customer the history of what the Service did |
| Duration | The term of the Customer's subscription, plus the retention and deletion periods in this DPA |
| Frequency | Continuous, as triggered by the Customer's syncs, webhooks and assistants |
03Data subjects and categories of data
| Data subjects | Categories of personal data |
|---|---|
| The Customer's customers and buyers | Name, email, phone, ID or tax document number, shipping and billing addresses, order details (items, quantities, amounts, status, shipping, tracking) |
| Marketplace buyers who ask questions or open claims | Marketplace user identifier, the text of questions and claims, and related order data |
| Visitors to the Customer's website who use the chatbot | Chat messages, and the order number and email, phone or document number they provide to look up an order |
| Other people mentioned in the Customer's content | Whatever the Customer includes in its catalog, instructions or knowledge base |
Special categories of data (health, biometric, religious and similar) and children's data are neither required nor intended. The Customer agrees not to configure the Service to process them; any such data it chooses to include, for example in free text, remains its responsibility.
04The Customer's instructions
NexxoSync processes Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA and the configuration the Customer sets in the app (connections, syncs, rules and assistants) are the Customer's complete instructions. Additional instructions must be agreed in writing.
If NexxoSync is required by law to process data otherwise, it will inform the Customer before processing, unless the law prohibits it. NexxoSync will tell the Customer promptly if, in its opinion, an instruction infringes Data Protection Laws, and may suspend that processing until the instruction is confirmed or changed.
05Processor obligations
- Process Customer Personal Data only to provide the Service and in accordance with the Customer's instructions.
- Not sell or share Customer Personal Data, not use it for its own purposes (including advertising or profiling), not combine it with data from other sources except as needed to provide the Service, and not retain, use or disclose it outside the direct business relationship with the Customer, as the CCPA requires of service providers.
- Not use Customer Personal Data to train AI models.
- Process only the minimum data needed: orders and customers pass through the Service rather than being kept in a customer database of its own, and assistants receive only the text needed to answer.
- Apply the technical and organisational measures in this DPA.
- Assist the Customer with data subject requests, security, breach notification, data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available.
- Delete or return Customer Personal Data at the end of the Service, as described below.
- Make available the information reasonably needed to demonstrate compliance with this DPA.
- Notify the Customer if it can no longer meet its obligations under Data Protection Laws.
06Customer obligations
- Have a valid legal basis for the processing and for disclosing Customer Personal Data to NexxoSync.
- Inform data subjects as Data Protection Laws require, including the use of a processor and of the chatbot on its website.
- Give lawful instructions and configure the Service accordingly, including the choice of AI provider and its settings.
- Handle data subjects' requests in the first instance, since the data lives in its own platforms.
- Keep its own accounts, platforms and team access secure.
07Confidentiality
NexxoSync ensures that everyone authorised to access Customer Personal Data is bound by an appropriate duty of confidentiality, receives access only to the extent needed for their role, and accesses another workspace only for support or to keep the Service running. Each entry into a Customer's workspace by the platform administrator is recorded in an audit log.
08Security measures
NexxoSync implements and maintains the following technical and organisational measures ("TOMs"), which may be improved over time but not reduced below this level:
| Area | Measure |
|---|---|
| Encryption in transit | HTTPS/TLS for all traffic to the website, the app, the APIs and webhooks |
| Encryption at rest | Platform credentials, AI provider keys and other secrets encrypted with AES-256-GCM, with the key held outside the database |
| Backups | Encrypted with a separate key stored outside the server; no plaintext dumps kept |
| Tenant isolation | Every query scoped to the workspace that makes it |
| Access control | Role-based access within each workspace; only the platform administrator can enter other workspaces, for support |
| Authentication | Passwords hashed with bcrypt and subject to a minimum strength policy; session tokens stored only as hashes; sessions can be reviewed and revoked; two-step verification on infrastructure and platform accounts |
| Logging and audit | Activity log per workspace with IP address; audit log of every administrative change and every entry into another workspace, with secrets redacted |
| Data minimisation and retention | No customer database of its own; automatic deletion of run history (90 days), failed jobs (30/90 days), chatbot conversations (7 days) and audit logs (365 days) |
| Application security | Webhook signatures verified; rate limits on public endpoints; chatbot order lookups require order number plus matching contact details and are rate-limited per visitor |
| Separation of environments | Development and test stores and installations kept separate from production |
| Incident response | Documented procedure: detect and record, contain, assess, notify, recover and review |
| Secrets management | Keys only in the server environment with restricted permissions and in a password manager; never in source code |
09Subprocessors
The Customer gives NexxoSync a general authorisation to engage subprocessors. The current list, with each subprocessor's function, data and location, is published at Subprocessors and is deemed approved.
- NexxoSync will notify the Customer of any intended addition or replacement at least thirty (30) days in advance, by email to the account address and by updating that page.
- The Customer may object on reasonable data protection grounds within that period by writing to [email protected]. The parties will try in good faith to resolve the objection; if they cannot, the Customer may terminate the affected Service without penalty and receive a refund of prepaid fees for the unused period.
- NexxoSync imposes on each subprocessor, by written contract, data protection obligations no less protective than those in this DPA, and remains liable to the Customer for its subprocessors' performance.
The platforms the Customer connects (such as Mercado Libre, Shopify, WooCommerce, Tiendanube, Odoo and Producteca) and the AI provider the Customer configures with its own account are not NexxoSync's subprocessors: the Customer chooses them and their processing is governed by the Customer's own agreements with them.
10Data subject requests
If NexxoSync receives a request from a data subject relating to Customer Personal Data, it will not answer it directly (other than to say it has been passed on) and will forward it to the Customer without undue delay. NexxoSync will assist the Customer, through the Service's features or on request, to access, correct, delete or export the data it holds, within the time limits that apply to the Customer.
NexxoSync processes the privacy notifications that connected platforms send to apps where it has implemented them (currently Tiendanube's store/redact, customers/redact and customers/data_request) and assists the Customer with any others.
11Personal data breaches
NexxoSync will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it and, in any event, aims to do so within seventy-two (72) hours, so the Customer can meet its own notification duties. The notice will be sent to the account email and will describe, to the extent then known:
- the nature of the breach, the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed to contain it and mitigate its effects;
- a contact point for more information.
Where information is not yet available, it will be provided in phases. NexxoSync will also inform the affected platforms when the data was obtained through their APIs, and will cooperate with the Customer and with the competent authorities. Notifying a breach is not an admission of fault or liability.
12Deletion and return at the end of the Service
When the Customer deletes a connection, its stored credentials are deleted immediately. When the Service ends, NexxoSync will delete Customer Personal Data within thirty (30) days, unless the Customer asks, before that date, for an export of the data it can obtain through the Service. Data in encrypted backups is removed when those backups are overwritten on a rolling basis, within [30] days, and is not restored except to recover from an incident.
NexxoSync may retain data only where Data Protection Laws or other laws require it, in which case it remains protected by this DPA and is used only for that purpose. Data the Service wrote to the Customer's platforms stays there, under the Customer's control. NexxoSync will confirm deletion in writing on request. The deletion process is described in Data deletion.
13Audits
Audits are documentation-first. On written request, no more than once every twelve months (or after a personal data breach, or when a supervisory authority requires it), NexxoSync will answer a reasonable security questionnaire and provide the documentation needed to demonstrate compliance with this DPA, such as descriptions of its measures and policies.
If the documentation is not sufficient to demonstrate compliance, the Customer may conduct, or appoint an independent auditor bound by confidentiality to conduct, an on-site or remote audit, with at least thirty (30) days' notice, during business hours, without access to other customers' data and without compromising the security of the Service. The Customer bears the cost of the audit unless it reveals a material breach of this DPA by NexxoSync.
14International transfers
NexxoSync and its subprocessors may process Customer Personal Data outside the country where the Customer or the data subjects are located. Any such transfer will rely on a mechanism recognised by Data Protection Laws: an adequacy decision; the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), which are incorporated into this DPA by reference — Module Two (controller to processor) or Module Three (processor to processor), as applicable — together with the UK International Data Transfer Addendum and the Swiss amendments where relevant; the model clauses approved by the AAIP for transfers from Argentina; or the ANPD's standard contractual clauses for transfers from Brazil.
For the Standard Contractual Clauses: the optional docking clause applies; the general authorisation in this DPA applies to subprocessors, with the notice period stated above; the governing law and forum are those of an EU Member State that allows third-party beneficiary rights, as set out in the clauses; and Annexes I and II are completed by the descriptions and the security measures in this DPA. In case of conflict, the Standard Contractual Clauses prevail.
15Liability, term and precedence
Each party's liability arising from this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Laws do not allow liability to be limited.
This DPA remains in force for as long as NexxoSync processes Customer Personal Data. If it conflicts with the Terms, this DPA prevails in matters of data protection. NexxoSync may update it to reflect changes in law or in the Service, without reducing the overall level of protection, and will notify material changes thirty (30) days in advance.