Data Processing Addendum
Version 1.0 — Effective August 3, 2026 · NexuSphere AI, Inc. · Foster City, CA
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the agreement between NexuSphere AI, Inc. (“NexuSphere,” “Supplier,” “Processor,” or “Service Provider”) and the customer identified in the applicable Order, Terms of Service, or Master Software as a Service Agreement (as applicable, the “Agreement”) governing NexuSphere’s provision of the Services. This DPA applies to the extent NexuSphere processes Personal Data on Customer’s behalf in connection with the Services. Capitalized terms not defined in this DPA have the meaning given in the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.
1. Definitions
- “Business,” “Business Purpose,” “Consumer,” “Sell,” “Share,” and “Service Provider” have the meanings given in the CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.).
- “Controller,” “Data Subject,” “Personal Data Breach,” “Processing,” “Processor,” and “Supervisory Authority” have the meanings given in the GDPR, to the extent the GDPR applies to the processing in question.
- “Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including as applicable the CCPA/CPRA, the GDPR, and the UK GDPR.
- “Personal Data” means Customer Data that constitutes personal data, personal information, or a similarly defined term under Data Protection Laws.
- “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data processed under this DPA.
- “Sub-processor” means a third party engaged by NexuSphere to process Personal Data in providing the Services.
2. Roles of the Parties
The parties acknowledge that, with regard to the processing of Personal Data, Customer is a Business/Controller and NexuSphere is a Service Provider/Processor. NexuSphere will process Personal Data only as a Service Provider/Processor on Customer’s behalf, and not as a Business or Controller with respect to that Personal Data. This DPA does not apply to information NexuSphere collects in its own capacity as a Business/Controller (for example, authorized-user account and billing information), which is instead addressed in NexuSphere’s Privacy Policy.
3. Scope and Details of Processing
The subject matter, duration, nature and purpose of processing, categories of Data Subjects, and types of Personal Data are described in Annex 1.
4. Customer Instructions
NexuSphere will process Personal Data only on Customer’s documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by applicable law, in which case NexuSphere will inform Customer of that legal requirement before processing, unless the law prohibits doing so. NexuSphere will promptly notify Customer if, in its opinion, an instruction infringes Data Protection Laws.
5. Confidentiality
NexuSphere will ensure that personnel authorized to process Personal Data are subject to a duty of confidentiality, whether contractual or statutory.
6. Security Measures
NexuSphere will implement and maintain the technical and organizational security measures described in Annex 2, designed to protect Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of processing.
7. Sub-processors
Customer authorizes NexuSphere to engage the Sub-processors listed in Annex 3 (which corresponds to NexuSphere’s public Sub-processor List). NexuSphere will (a) impose data protection obligations substantially similar to those in this DPA on each Sub-processor, and (b) remain liable to Customer for each Sub-processor’s performance of those obligations. NexuSphere will notify Customer of any intended change to its Sub-processors by updating the Sub-processor List; Customer may object to a new Sub-processor on reasonable data protection grounds within ten (10) days of the update, in which case the parties will work in good faith to resolve the objection, including, if necessary, by Customer terminating the affected Order without penalty.
8. Assistance with Data Subject Requests
Taking into account the nature of the processing, NexuSphere will provide reasonable assistance to Customer, at Customer’s expense for anything beyond standard platform functionality, to enable Customer to respond to requests from Data Subjects or Consumers to exercise their rights under Data Protection Laws. If NexuSphere receives such a request directly, NexuSphere will not respond to it (other than to confirm receipt) and will promptly forward it to Customer, since NexuSphere does not have a direct relationship with the Data Subject or Consumer.
9. Personal Data Breach Notification
NexuSphere will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Security Incident affecting Personal Data, and will provide information reasonably requested by Customer to enable it to meet its own notification obligations under Data Protection Laws. NexuSphere will take reasonable steps to mitigate the effects of, and minimize any damage resulting from, a Security Incident.
10. AI Processing of Personal Data
Where the Services process Personal Data using AI Technology (as defined in the Agreement), NexuSphere will do so consistent with the AI terms in the Agreement, including that: (a) Personal Data will not be used to train, fine-tune, or evaluate any AI model; (b) outputs generated by AI Technology are advisory only and require human review before Customer acts on them; and (c) any Sub-processor used to provide AI-assisted features (including Google’s Gemini API) is contractually restricted from using submitted content to train its own models. See also the AI Policy for additional detail on how AI Technology is used across the Services.
11. CCPA/CPRA Service Provider Terms
With respect to Personal Data that is “personal information” subject to the CCPA/CPRA, NexuSphere certifies that it understands the restrictions in this Section and will comply with them. NexuSphere will not: (a) sell or share personal information; (b) retain, use, or disclose personal information for any purpose other than the specific business purpose of performing the Services under the Agreement, including retaining, using, or disclosing it for a commercial purpose other than performing the Services, except as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose personal information outside of the direct business relationship between NexuSphere and Customer; or (d) combine personal information received from or on behalf of Customer with personal information received from or on behalf of another party, except as permitted by the CCPA/CPRA. NexuSphere will notify Customer if it determines it can no longer meet its obligations as a service provider under the CCPA/CPRA. Customer may take reasonable and appropriate steps under Section 13 (Audits and Compliance Information) to ensure NexuSphere uses personal information consistent with Customer’s obligations under the CCPA/CPRA, and to stop and remediate any unauthorized use.
12. International Data Transfers
To the extent NexuSphere’s processing of Personal Data involves a transfer from the European Economic Area, the United Kingdom, or Switzerland to a country not deemed to provide an adequate level of data protection, the Standard Contractual Clauses referenced in Annex 4, or such other transfer mechanism as the parties may agree, will apply and are incorporated into this DPA.
13. Audits and Compliance Information
NexuSphere will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which it may satisfy by providing a summary upon completion of its SOC 2 report or similar third-party audit report, together with completed responses to Customer’s security questionnaire. If those materials do not reasonably address Customer’s audit obligations under Data Protection Laws, NexuSphere will allow for and contribute to an audit — including inspections — conducted by Customer or a mutually agreed independent auditor, no more than once per year (except following a Security Incident or if required by a Supervisory Authority), on at least thirty (30) days’ prior written notice, during business hours, subject to reasonable confidentiality protections, and without unreasonably disrupting NexuSphere’s operations.
14. Return or Deletion of Personal Data
Upon termination or expiration of the Agreement, NexuSphere will, at Customer’s election, delete or return all Personal Data, and delete existing copies, within the timeframe set out in the Agreement, unless applicable law requires continued retention, in which case NexuSphere will isolate and protect that Personal Data from further processing except as required by that law.
15. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Limitation of Liability section of the Agreement, provided that, consistent with the Agreement, that limitation does not apply to a breach of the Agreement’s Compliance with Laws / data protection provisions.
16. Term; Miscellaneous
This DPA remains in effect for as long as NexuSphere processes Personal Data on Customer’s behalf under the Agreement. This DPA is governed by the same governing law as the Agreement. If any provision of this DPA is held unenforceable, the remaining provisions will remain in effect.
17. Signatures (Enterprise Orders Only)
This DPA is incorporated into the Agreement by reference and does not require separate execution for Customers who accept the Terms of Service. For Customers with a negotiated Master Software as a Service Agreement, the DPA may be executed as an Exhibit to that Agreement.
Annex 1: Details of Processing
- Subject matter: NexuSphere’s provision of the Services to Customer.
- Duration: For the term of the Agreement, plus any period during which NexuSphere retains Personal Data under Section 14.
- Nature and purpose: Hosting, storage, and processing of Customer Data to provide NexuSphere’s AI-assisted retail operations platform, including operational intelligence and other AI-assisted platform capabilities enabled under the applicable Order.
- Categories of Data Subjects: Customer’s own personnel and authorized users; Customer’s customers/shoppers (to the extent their order, contact, or transaction data is processed via connected integrations); and Customer’s supplier/vendor contacts (to the extent included in EDI documents).
- Types of Personal Data: Name, contact information (email, address, phone), order and transaction history, product and inventory data, and payment or bank account identifiers (via Plaid, for reconciliation purposes only).
- Special categories of data: None are intended to be processed. Customer will not submit special category or sensitive personal data to the Services other than the financial account information described above.
Annex 2: Technical and Organizational Security Measures
- Hosting on Google Cloud Platform with encryption in transit (TLS) and at rest.
- Role-based access controls, unique credentials, and periodic access review.
- Logical segregation of Customer Data from NexuSphere’s own data and other customers’ data.
- Logging and monitoring of access to production systems.
- Annual security and privacy awareness training for personnel.
- Documented incident response procedures and a disaster recovery plan (RPO ≤15 minutes via point-in-time recovery; RTO ≤8 business hours; cross-region backup storage), currently untested pending its first scheduled test-restore drill.
- Sub-processor security oversight as described in Section 7.
Additional detail is available in NexuSphere’s Security Overview. Enterprise customers may request the full Information Security Policy at legal@nexusphere.ai.
Annex 3: Authorized Sub-processors
See NexuSphere’s public Sub-processor List, which is incorporated into this Annex by reference and updated in accordance with Section 7 above.
Annex 4: International Data Transfers
Reserved. If and when NexuSphere processes Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland, this Annex will incorporate the Standard Contractual Clauses (Module Two: Controller to Processor) issued by the European Commission, together with the UK International Data Transfer Addendum, completed with the parties’ details and the information in Annexes 1 through 3 above.
Contact
Enterprise customers requesting an executed copy of this DPA as a signed exhibit should contact legal@nexusphere.ai.