Data Processing Agreement (DPA)
Last updated
Draft - needs lawyer review. This document describes how Nomisly actually works but has not yet been reviewed by a lawyer for the operating entity and each jurisdiction.
Roles
The customer is the controller of personal data about its leads and customers; Nomisly processes it on the customer's documented instructions (the Terms, product settings and support requests).
Scope
Categories: contact details, messages, booking details, lead qualification answers, consent records. Data subjects: the customer's leads, customers and staff. Purpose: providing the Service.
Security measures
Encryption in transit (TLS) and of stored secrets; database row-level security per tenant; role-based access; two-step verification; append-only audit log; PII redaction in logs; backups; incident response.
Sub-processors
Listed on the sub-processors page. We give notice of new sub-processors and customers may object.
Transfers
Where personal data leaves the EEA/UK, transfers rely on Standard Contractual Clauses or another valid mechanism.
Breach notification
We notify affected customers without undue delay, and in any case within 72 hours of becoming aware of a personal data breach, with the information they need for their own notifications (including under India's DPDP Rules).
Deletion and return
Customers can export data at any time. After the customer closes the account, data is deleted after notice, except where law requires retention.
Audits
We provide reasonable information to demonstrate compliance, including our security documentation.