Data Processing Addendum
How we process personal data on your behalf when GDPR, UK GDPR, the Swiss FADP, or other Data Protection Law applies. Auto-incorporated when you accept the Terms — no separate signature required.
This Data Processing Addendum ("DPA") forms part of the NimbusNexus Terms of Service ("Terms") at /terms-of-service between Fortlab Corporation, operator of the NimbusNexus™ cloud service ("Fortlab", "we", "us"), and the customer that has accepted the Terms ("Customer", "you"). It governs Fortlab's processing of Personal Data on Customer's behalf in connection with the Service. If there is any conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA controls.
When this DPA applies
This DPA kicks in automatically if you put personal data into NimbusNexus that's protected by EU GDPR, UK GDPR, the Swiss FADP, or another data protection law that requires a written processor agreement. You don't need to sign anything separately — accepting the Terms accepts this DPA.
This DPA applies to Fortlab's processing of Personal Data on Customer's behalf where such processing is subject to (a) the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"); (b) the UK General Data Protection Regulation as it forms part of UK law ("UK GDPR") and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection ("FADP"); or (d) any other Data Protection Law (defined below) that requires a written agreement between a controller and a processor.
By accepting the Terms, Customer accepts this DPA. No separate signature is required, but Fortlab will execute a countersigned copy on Customer's reasonable request.
Definitions
In this DPA:
"Customer Data" has the meaning given in the Terms.
"Data Protection Law" means GDPR, UK GDPR, FADP, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and any other applicable law governing the processing of Personal Data.
"Personal Data" means Customer Data that is "personal data" under GDPR or UK GDPR, "personal information" under CCPA, or equivalent terms under other Data Protection Law.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
"Sub-processor" means any third party engaged by Fortlab to process Personal Data on Customer's behalf.
"SCCs" means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 of 4 June 2021 (or any successor).
"UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office under section 119A of the UK Data Protection Act 2018.
Other capitalized terms not defined here have the meanings given in the Terms or, failing that, in GDPR.
The terms "controller", "processor", "data subject", "process / processing", and "supervisory authority" have the meanings given in GDPR.
Roles of the parties
You're in charge of the personal data — you decide what goes into NimbusNexus and why. We just process it on your behalf according to your instructions and these Terms.
With respect to Personal Data:
(a) Customer is the controller (or, where Customer is itself processing on behalf of a third-party controller, a processor on behalf of that controller).
(b) Fortlab is the processor, processing Personal Data only on Customer's documented instructions.
(c) Customer's use of the Service in accordance with the Terms (including configuration choices made by Customer) constitutes Customer's documented instructions to Fortlab. Customer may issue further reasonable written instructions, which Fortlab will follow unless doing so would be unlawful or technically infeasible (in which case Fortlab will inform Customer).
(d) Customer is responsible for ensuring that its instructions, and its collection and provision of Personal Data to Fortlab, comply with Data Protection Law.
Description of processing
Here's the cloud-services-specific summary of what we do with personal data on your behalf.
Subject matter. Provision of cloud infrastructure, compute, storage, and related services as described in the Terms.
Duration. The term of the Terms plus the post-termination retention windows in §11 of the Terms (60-day export window, 30-day active deletion, 90-day backup deletion).
Nature and purpose. Hosting, transmitting, processing, and securing Personal Data as necessary to provide the Service to Customer; billing, support, and fraud detection in respect of Customer's account.
Categories of data subjects. As determined by Customer; typically Customer's end users, employees, contractors, and any other individuals whose Personal Data Customer chooses to process using the Service.
Categories of Personal Data. As determined by Customer; typically identifiers, contact details, account credentials, technical data, and any further categories Customer chooses to process using the Service.
Special category data. Customer should not provide special category data (GDPR Art. 9) or criminal-conviction data (Art. 10) to the Service unless Customer has informed Fortlab in writing in advance and Fortlab has agreed to receive it.
Frequency. Continuous for the duration of the Terms.
Fortlab's obligations as processor
We will only process personal data the way you tell us to, keep it confidential, secure it, help you respond to people exercising their rights, and tell you fast if something goes wrong.
Fortlab will:
(a) Process on instructions only. Process Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Fortlab will inform Customer of that legal requirement before processing, unless that law prohibits such notice).
(b) No sale or unauthorized use. Not sell Personal Data, not "share" it for cross-context behavioral advertising, and not use Personal Data for any purpose other than providing the Service to Customer. Specifically, Fortlab will not use Personal Data to train or improve any machine-learning model. For the avoidance of doubt, the use of automated systems to detect fraud, abuse, and security threats in connection with the operation of the Service is part of providing the Service and is permitted under this DPA; the categories of automated processing and the role of human review are described in the Privacy Policy.
(c) Confidentiality. Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
(d) Security. Implement and maintain the technical and organizational measures described in Schedule 2 (Security Measures), taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
(e) Assistance with data subject requests. Taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligations to respond to data subject requests under Data Protection Law. Where a data subject contacts Fortlab directly with a request relating to Customer's processing, Fortlab will, unless legally prohibited, redirect the data subject to Customer and inform Customer of the request.
(f) Assistance with controller obligations. Provide reasonable assistance to Customer in fulfilling its obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Fortlab.
(g) Breach notification. Notify Customer of a Personal Data Breach affecting Customer's Personal Data without undue delay, and in any event within seventy-two (72) hours of confirmation. The notification will include the information required by GDPR Art. 33(3) to the extent then known, and Fortlab will provide updates as further information becomes available.
(h) Return or deletion. At the end of the provision of services, return or delete Personal Data in accordance with §11 of the Terms (60-day export, 30-day active deletion, 90-day backup deletion), unless Data Protection Law requires further storage.
(i) Records. Maintain a written record of processing activities carried out on behalf of Customer in accordance with GDPR Art. 30(2).
Sub-processors
We use a small number of vendors to help run NimbusNexus. The current list is at /sub-processors. We'll give you 30 days' notice before adding a new one, and you can object.
(a) General authorization. Customer grants Fortlab a general authorization to engage Sub-processors for the processing of Personal Data, subject to this §6.
(b) Current list. A current list of Sub-processors is published at /sub-processors, including each Sub-processor's name, location, and processing activity.
(c) Notification of changes. Fortlab will notify Customer at least thirty (30) days before adding or replacing a Sub-processor that processes Personal Data, by updating the published list and (for Customers who have subscribed to notifications) sending an email notification.
(d) Objection. Customer may object to a new Sub-processor on reasonable data-protection grounds by notice to [email protected] within thirty (30) days of notification. The parties will discuss the objection in good faith. If the parties cannot resolve the objection within a further thirty (30) days, Customer's sole remedy is to terminate the affected portion of the Service for convenience.
(e) Sub-processor obligations. Fortlab will impose on each Sub-processor written obligations that are no less protective than those set out in this DPA, and will remain liable to Customer for the performance of each Sub-processor's obligations.
International data transfers
When personal data leaves the EEA, UK, or Switzerland to come to Fortlab in the US (or to our sub-processors elsewhere), we use the legal transfer mechanisms required by your law — mainly the Standard Contractual Clauses.
(a) Adequacy first. Where a transfer of Personal Data is to a country recognized as providing an adequate level of protection by the European Commission, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner, the transfer occurs under that adequacy decision.
(b) EU SCCs. For transfers from the EEA to a country without an adequacy decision, the parties incorporate the SCCs into this DPA as set out in Schedule 1 (SCCs and UK Addendum), with Customer as data exporter and Fortlab as data importer, Module 2 (controller-to-processor) applying. Where Customer is itself a processor, Module 3 (processor-to-processor) applies.
(c) UK Addendum. For transfers from the United Kingdom, the UK Addendum applies to the SCCs as set out in Schedule 1.
(d) Switzerland. For transfers from Switzerland, the SCCs apply with the modifications described in Schedule 1, including references to the FADP in place of GDPR where applicable, and the Swiss Federal Data Protection and Information Commissioner as the supervisory authority.
(e) Sub-processor transfers. Fortlab will ensure that any onward transfer by a Sub-processor is subject to a valid transfer mechanism under Data Protection Law.
(f) Transfer impact assessments. Fortlab will provide reasonable cooperation and information to allow Customer to conduct a transfer impact assessment.
Audits
You can verify our compliance through documentation we make available — our security program summary, responses to security questionnaires, and SOC 2 reports once they're issued. For deeper audits, we'll cooperate where reasonable, with notice.
(a) Standard audit materials. Fortlab makes available to Customer (subject to confidentiality) a summary of its information security program, responses to standard security questionnaires (such as CAIQ or SIG Lite), and any SOC 2 reports as and when they are issued. Together these are intended to demonstrate compliance with this DPA without the need for an on-site audit in most cases.
(b) Additional audits. Where the standard audit materials are insufficient to demonstrate compliance with a specific obligation, Customer may request additional information by written notice. The parties will agree in good faith on the scope, timing, and confidentiality of any further audit, which:
• will be conducted no more than once per twelve-month period (except where required by a supervisory authority or following a Personal Data Breach);
• will be conducted on at least thirty (30) days' written notice;
• will be conducted during business hours and in a manner that does not unreasonably interfere with the Service;
• will be at Customer's expense, except where the audit reveals a material breach of this DPA, in which case Fortlab bears the reasonable costs.
(c) Supervisory authority cooperation. The parties will cooperate as required to respond to inquiries or audits by supervisory authorities.
CCPA-specific terms (California)
California treats us as a "service provider," not a seller. We don't sell or share your data, and we honor your customers' California rights.
With respect to Personal Data subject to the CCPA, Fortlab is a "service provider" as defined in the CCPA. Fortlab will:
(a) not sell or share Personal Data;
(b) not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in this DPA and the Terms, including not retaining, using, or disclosing Personal Data outside the direct business relationship between Fortlab and Customer;
(c) not combine Personal Data received from Customer with personal information received from any other source, except as permitted by CCPA Reg. § 7050(b);
(d) provide reasonable assistance to Customer in responding to verifiable consumer requests under CCPA;
(e) notify Customer if Fortlab determines it can no longer meet its obligations under the CCPA, and allow Customer to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data.
Fortlab certifies that it understands and will comply with these restrictions.
Other Data Protection Laws
The parties acknowledge that the following laws may apply to specific Customers and that Fortlab will, where applicable:
• Other US state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, and successor laws): Fortlab acts as a "processor" / "service provider" under these laws and will provide the equivalent contractual commitments required by each.
• Japan APPI: Fortlab will provide reasonable cooperation in Customer's compliance with the Act on the Protection of Personal Information.
• South Korea PIPA: same as above for the Personal Information Protection Act.
• Singapore PDPA: same as above for the Personal Data Protection Act.
• India DPDPA: same as above for the Digital Personal Data Protection Act 2023.
If a Data Protection Law applicable to Customer requires terms that are not addressed in this DPA, the parties will negotiate in good faith and execute a written addendum to address them.
Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms. Nothing in this DPA limits liability that cannot be limited under Data Protection Law (including any direct liability of a processor to a data subject under GDPR Art. 82).
Term, termination, and survival
This DPA takes effect on the later of (a) Customer's acceptance of the Terms or (b) the Effective Date set out above, and continues for the duration of the Terms. Sections 5(b), 5(g), 5(h), 7, 8, 9, 11, and this §12 survive termination of the Terms to the extent and for as long as Fortlab continues to hold Personal Data.
Order of precedence
In case of any conflict, the order of precedence is: (1) the SCCs as incorporated by Schedule 1; (2) this DPA; (3) the Terms; (4) any other agreement between the parties.
Schedule 1 — SCCs and UK Addendum
Part A: EU Standard Contractual Clauses. The parties incorporate the SCCs (Commission Decision 2021/914) into this DPA, with the following selections:
• Module: Module 2 (Transfer controller to processor) where Customer is a controller. Module 3 (Transfer processor to processor) where Customer is itself a processor on behalf of a third-party controller.
• Clause 7 (Docking clause): Included.
• Clause 9 (Sub-processors): Option 2 (general written authorization) selected, with the notice period set out in §6 of this DPA.
• Clause 11 (Redress): The optional language permitting independent dispute resolution by data subjects is not included.
• Clause 17 (Governing law): The SCCs are governed by the law of Ireland.
• Clause 18 (Choice of forum and jurisdiction): Disputes arising from the SCCs will be resolved by the courts of Ireland.
• Annex I.A (List of parties): Data Exporter — Customer, as identified in its account registration. Data Importer — Fortlab Corporation, registered office in Sheridan, WY, United States. Contact: [email protected].
• Annex I.B (Description of transfer): As set out in §4 of this DPA.
• Annex I.C (Competent supervisory authority): Determined in accordance with Clause 13 of the SCCs.
• Annex II (Technical and organizational measures): As set out in Schedule 2 of this DPA.
• Annex III (List of Sub-processors): The list published at /sub-processors, as updated from time to time in accordance with §6.
Part B: UK International Data Transfer Addendum. For transfers from the United Kingdom, the parties incorporate the UK Addendum (issued by the ICO under section 119A of the Data Protection Act 2018, in the version dated 2 February 2022 or its successor), with: Table 1 (Parties) as specified in Annex I.A above; Table 2 (Selected SCCs, Modules, and Selected Clauses) as specified in Part A above; Table 3 (Appendix Information) — Annexes I.A, I.B, II, and III as specified above; Table 4 (Ending the Addendum when the Approved Addendum changes) — either party may end the UK Addendum as set out in Section 19 of the UK Addendum.
Part C: Switzerland. For transfers from Switzerland, the SCCs apply with the following modifications:
• References to GDPR include the FADP where the data is subject to the FADP.
• The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
• The term "EU member state" is interpreted to include Switzerland for the purpose of allowing data subjects in Switzerland to bring proceedings in their place of habitual residence.
Schedule 2 — Technical and Organizational Measures
Fortlab implements and maintains the following measures, which may be updated from time to time provided that the level of protection is not reduced.
Information security program. Fortlab maintains a written information security program based on industry standards (including ISO 27001 control areas and the SOC 2 Trust Services Criteria). Fortlab is implementing the controls necessary for SOC 2 Type I attestation, with Type II attestation to follow over the subsequent observation period. Reports will be made available to Customer under NDA on request as and when they are issued.
Encryption. AES-256 encryption at rest for Customer Data stored on Fortlab's persistent storage. TLS 1.3 (or, where TLS 1.3 is not supported by the client, TLS 1.2 with strong cipher suites) for data in transit.
Access controls. Role-based access control with least-privilege principles. Multi-factor authentication required for all Fortlab personnel with access to systems processing Personal Data. Access reviewed at least quarterly. Logging of administrative access.
Network security. Network segmentation between production and non-production environments. Intrusion detection and DDoS protection at network ingress. Regular vulnerability scanning of production infrastructure.
Personnel. Background checks for personnel with access to Personal Data, to the extent permitted by applicable law. Confidentiality obligations binding all personnel. Mandatory security awareness training on hire and annually thereafter.
Physical security. Production infrastructure operates from data centers with SOC 2 / ISO 27001 / equivalent certifications, with physical access restricted to authorized personnel and monitored 24/7.
Resilience. Geographically redundant infrastructure. Documented business continuity and disaster recovery procedures, tested at least annually.
Incident response. Documented incident response plan covering detection, containment, eradication, recovery, and notification. 24/7 on-call security coverage. Defined Personal Data Breach notification procedure consistent with §5(g) of this DPA.
Vendor management. Risk-tiered review of Sub-processors before onboarding. Contractual data-protection obligations no less protective than this DPA.
Data minimization and retention. Customer Data retained only for the periods set out in the Terms and Privacy Policy. Deletion procedures applied to active and backup systems.
Schedule 3 — Sub-processors
A current list of Fortlab's Sub-processors is maintained at /sub-processors. The list includes for each Sub-processor: legal name, location of processing, and a description of the processing activity.
Customers may subscribe to email notifications of changes by emailing [email protected].