This Global Data Processing Addendum (DPA) is entered into between Nomic, Inc., a Delaware corporation (Nomic), and Customer, and is incorporated into and governed by the terms of the Subscription Services Agreement (Agreement) between the parties.

1. Definitions

Any capitalized term not defined in this DPA has the meaning given to it in the Agreement (defined below).

  • Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control of a party. "Control," for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of a party.
  • Agreement means the Subscription Services Agreement between Customer and Nomic for the provision of the Services.
  • ANPD means the Autoridade Nacional de Proteção de Dados (Brazilian National Data Protection Authority), the supervisory authority responsible for overseeing, implementing, and enforcing compliance with the LGPD.
  • APP(s) means Australian Privacy Principles.
  • Australian Personal Information means Personal Data that is collected, held, used, or disclosed in connection with activities in Australia, or that is otherwise subject to the Australian Privacy Act.
  • Australian Privacy Act means the Privacy Act 1988 (Cth), including the APPs set out in Schedule 1 to the Australian Privacy Act, and the Notifiable Data Breaches scheme set out in Part IIIC of the Australian Privacy Act, each as amended from time to time.
  • Brazilian Personal Data means Personal Data that is: (i) processed in Brazil; (ii) processed for the purpose of offering or providing goods or services to individuals located in Brazil; or (iii) collected in Brazil, in each case as contemplated by Article 3 of the LGPD.
  • Controller means Customer, the entity which determines the purposes and means of the processing of Personal Data.
  • Customer Data means data, which may include Personal Data and the categories of data submitted, stored, sent, or received via the Services by Customer, its Affiliates, or end users.
  • Data Protection Laws means all laws and regulations applicable to the processing of Personal Data under the Agreement, in and outside of the United States, including but not limited to, the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, the Australian Privacy Act, the FADP, the LGPD, the New Zealand Privacy Act, the Privacy and the Electronic Communications Regulations 2003 (SI 2003/2426), all state data protection laws and regulations enacted and effective in the United States, and all other applicable data protection and privacy legislation in force from time to time (as may be applicable depending on the location of Customer, Data Subject and processing of the relevant Personal Data).
  • Data Subject means the identified or identifiable person to whom Personal Data relates.
  • DPA means this Global Data Processing Addendum and its schedules.
  • EEA means the European Economic Area (namely the EU, Norway, Iceland, and Liechtenstein together).
  • Eligible Data Breach has the meaning given to it in section 26WE of the Australian Privacy Act.
  • EU GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation).
  • FADP means the Swiss Federal Act on Data Protection of 1st of September 2023 as amended from time to time.
  • LGPD means Lei Geral de Proteção de Dados (Law No. 13,709/2018), the Brazilian General Data Protection Law, as amended from time to time, together with any binding regulations, resolutions, and guidance issued by the ANPD.
  • New Zealand Personal Information means Personal Data that relates to an identifiable individual and is collected, held, used, or disclosed in connection with activities in New Zealand, or that is otherwise subject to the New Zealand Privacy Act.
  • New Zealand Privacy Act means the Privacy Act 2020 (NZ), including the Information Privacy Principles (IPPs) set out in Part 3 of the New Zealand Privacy Act and the mandatory breach notification provisions in Part 6, Subpart 2, each as amended from time to time.
  • Notifiable Privacy Breach has the meaning given to it in section 112 of the New Zealand Privacy Act: a privacy breach that it is reasonable to believe has caused, or is likely to cause, serious harm to an affected individual.
  • OAIC means the Office of the Australian Information Commissioner established under the Australian Information Commissioner Act 2010 (Cth).
  • OPC means the Office of the Privacy Commissioner established under Part 5 of the New Zealand Privacy Act.
  • Personal Data means any information relating to: (i) an identified or identifiable natural person and (ii) an identified or identifiable legal entity (where such information is protected similarly as personal data or personally identifiable information under applicable Data Protection Laws), which is provided as Customer Data.
  • Processor means Nomic, the entity which processes Personal Data on behalf of Controller.
  • Restricted Transfer means: (i) where the EU GDPR applies, a transfer of Personal Data via the Services from the EEA either directly or via onward transfer, to any country or recipient outside of the EEA not subject to an adequacy determination by the European Commission; (ii) where the UK GDPR applies, a transfer of Personal Data via the Services from the United Kingdom either directly or via onward transfer, to any country or recipient outside of the UK not based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018; (iii) a transfer of Personal Data via the Services from Switzerland either directly or via onward transfer, to any country or recipient outside of the EEA and/or Switzerland not subject to an adequacy determination by the European Commission; (iv) where the Australian Privacy Act applies, a disclosure of Australian Personal Information to a recipient outside Australia that is not bound by a law, binding scheme, or contract providing comparable protection to the APPs; (v) where the LGPD applies, a transfer of Brazilian Personal Data to any country or recipient outside Brazil that has not received an adequacy determination from the ANPD and is not subject to another transfer mechanism permitted under Article 33 of the LGPD; and (vi) where the New Zealand Privacy Act applies, a disclosure of New Zealand Personal Information to a person in a foreign country, unless one of the exceptions in section 193 of the New Zealand Privacy Act applies.
  • Standard Contractual Clauses means (i) where the EU GDPR applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries and published at eur-lex.europa.eu (EU SCCs); (ii) where the UK GDPR applies the international data transfer addendum to the EU SCCs adopted pursuant to Article 46(2)(c) of the UK GDPR (UK SCCs); and (iii) where Personal Data is transferred from Switzerland to outside of Switzerland or the EEA, the EU SCCs as amended in accordance with guidance from the Swiss Data Protection Authority (Swiss SCCs); as they may be amended, superseded or replaced from time to time.
  • Sub-processor means any third party (including Nomic's Affiliates) engaged directly or indirectly by Nomic to process Personal Data under this DPA in the provision of the Services to Customer.
  • Supervisory Authority means a governmental or government-chartered regulatory body having binding legal authority over a party.
  • Services means the web subscription services provided by Nomic to the Customer pursuant to the Agreement.
  • UK GDPR means the EU GDPR as it forms part of the laws of the UK by virtue of Section 3 of the European Union (Withdrawal) Act 2018, as amended.

2. Purpose

a. Nomic has agreed to provide the Services to Customer in accordance with the terms of the Agreement. In providing the Services, Nomic must process Customer Data on behalf of Customer. Customer Data may include Personal Data. Nomic must process and protect such Personal Data in accordance with the terms of this DPA and the Data Protection Laws.

b. With respect to Customer Data under this DPA, the parties agree that Customer is the 'data controller' and Nomic is the 'data processor'. Customer must comply with its obligations as a Controller and Nomic must comply with its obligations as a Processor under the DPA.

c. Where a Customer Affiliate or a Customer client is the controller with respect to certain Customer Data, Customer represents and warrants to Nomic that it is authorized to instruct Nomic and otherwise act on behalf of such Customer Affiliate or a Customer client in relation to Customer Data in accordance with the Agreement and this DPA.

3. Scope

a. In providing the Services to Customer pursuant to the terms of the Agreement, Nomic must treat Personal Data as confidential and only process Personal Data on behalf of Customer, and only to the extent necessary to provide Services and in accordance with the Customer's instructions as documented in the Agreement and this DPA.

b. Nomic and Customer must take steps to ensure that any natural person acting under the authority of Customer or Nomic who has access to Personal Data does not process the Personal Data except as specified in this DPA unless required to do so by Data Protection Laws.

4. Nomic Obligations

a. Nomic may collect, process, or use Personal Data only in accordance with the scope of the Agreement, this DPA, and Customer's instructions. This DPA is Customer's complete and final documented instruction to Nomic in relation to Personal Data. Additional instructions outside the scope of this DPA (if any) require prior written agreement between Nomic and Customer, including agreement on any additional fees payable by Customer to Nomic for carrying out such instructions.

b. Nomic must ensure that all employees, agents, officers, and contractors involved in the handling of Personal Data: (i) are aware of the confidential nature of Personal Data and are contractually bound to keep Personal Data confidential; (ii) have received appropriate training on their responsibilities as a data processor; and (iii) are bound by terms materially no less restrictive than the terms of this DPA.

c. Nomic must maintain appropriate managerial, operational, and technical safeguards designed to preserve the integrity and security of Personal Data while in its possession and control under this DPA, while taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.

d. Nomic must maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate: (i) the pseudonymization and encryption of Personal Data; (ii) the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; (iii) the ability to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident; (iv) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing. In assessing the appropriate level of security, Nomic takes into account the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed, as further set forth in Schedule 2.

e. Customer agrees that, in the course of providing the Services to Customer, it may be necessary for Nomic to access Personal Data to respond to any technical problems, Customer queries, security monitoring, and to ensure the proper working of the Services. All such access by Nomic must be limited to those purposes and performed by authorized personnel.

f. Nomic must promptly inform Customer if, in Nomic's opinion, any of the instructions regarding the processing of Personal Data provided by Customer breach the Data Protection Laws.

g. Nomic must reasonably assist Customer in meeting the Customer's obligation to carry out Data Protection Impact Assessments (DPIA), taking into account the nature of processing and the information available to Nomic.

h. Customer and Nomic and, where applicable, their representatives, must cooperate, upon request, with a Supervisory Authority in the performance of their respective obligations under this DPA and Data Protection Laws.

i. Nomic must notify Customer promptly of any request or complaint regarding the processing of Personal Data, which adversely impacts Customer, unless such notification is not permitted under applicable law or a relevant court order.

j. Nomic may not (i) sell Personal Data; (ii) retain, use, or disclose Personal Data for commercial purposes other than providing the Services under the terms of the Agreement; or (iii) retain, use, or disclose Personal Data outside of the Agreement. Nomic understands these restrictions.

5. Customer Obligations

a. Customer represents and warrants, in its use of the Services, that: (i) it must comply with the terms of the Agreement, this DPA, and the Data Protection Laws, including any applicable requirements to provide notice to and/or obtain consent from Data Subject for processing by Nomic and its Sub-processors; and (ii) it must ensure that its use of the Services will not violate the rights of any Data Subject. All Affiliates of Customer who use the Services must comply with the obligations of Customer set out in this DPA.

b. Customer represents and warrants that, having sole responsibility for the quality, legality, and accuracy of Personal Data, it has obtained any and all necessary permissions and authorizations necessary to permit Nomic, its Affiliates, and Sub-processors to execute their rights or perform their obligations under this DPA.

c. Customer represents and warrants that its instructions comply with Data Protection Laws.

d. Customer must inform Nomic of any notice or inquiry (including any notice, investigation, complaint, or request) relating to Nomic's processing of Personal Data and provide Nomic with a copy thereof within 48 hours of receipt by Customer of such notice or inquiry. Notices should be sent to: security@nomic.ai.

6. Notification of Security Breach

a. Nomic must notify Customer without undue delay after becoming aware of (and in any event within 72 hours of discovering) any breach of security leading to accidental or unlawful destruction, loss, alteration or unauthorized disclosure or access to Customer's Personal Data (Personal Data Breach).

b. Nomic must take all commercially reasonable measures to secure Personal Data, eliminate the Personal Data Breach, and assist Customer in meeting the Customer's obligations under applicable law. In the event of a Personal Data Breach, Nomic's System Administration Team and Security Team must perform a risk-based assessment of the situation and develop appropriate strategies in accordance with Nomic incident response procedures, which include contacting Customer's primary (technical or business) point of contact or Security Operation Center to brief them on the situation and provide resolution status updates.

7. Audit

a. Nomic must make available to Customer all information reasonably necessary to demonstrate compliance with its processing obligations and allow for and contribute to audits and inspections.

b. Any audit conducted under this DPA must consist of examination of the most recent reports, certificates, and/or extracts prepared by an independent auditor. In the event that provision of the same is not deemed sufficient in the reasonable opinion of Customer, Customer may conduct a more extensive audit which must be: (i) at the Customer's expense; (ii) limited in scope to matters specific to Customer and agreed in advance; (iii) carried out during Nomic's business hours and upon reasonable notice, which must be not less than 4 weeks unless an identifiable material issue has arisen; and (iv) conducted in a way which does not interfere with Nomic's day-to-day business. Any such audit must be conducted remotely, except Customer and/or its Supervisory Authority may conduct an on-site audit at Nomic's premises if so required by the Data Protection Laws. In no event must any audit of a Sub-processor, beyond a review of reports, certifications, and documentation made available by the Sub-processor, be permitted without the Sub-processor's consent. This Section does not modify or limit the rights of audit of Customer; instead, it is intended to clarify the procedures in respect of any audit.

8. Data Subjects

a. Nomic must, to the extent legally permitted, promptly notify Customer if Nomic receives a request from a Data Subject to exercise the Data Subject's right of access, right to rectification, restriction of processing, erasure, data portability, object to the processing or any other Data Subject right, (Data Subject Request).

b. Taking into account the nature of the processing and the information available to Nomic, Nomic must assist Customer by having in place appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to a Data Subject Request under the Data Protection Laws.

c. To the extent Customer, in its use of the Services, does not have the ability to address a Data Subject Request, Nomic must upon Customer's request, and to the extent possible, provide commercially reasonable efforts to assist Customer in responding to such Data Subject Request, to the extent Nomic is legally permitted to do so and the response to such Data Subject Request is required under Data Protection Laws. To the extent legally permitted, Customer must be responsible for any costs arising from Nomic's provision of such assistance.

9. Sub-processors

a. Customer agrees that: (i) Affiliates of Nomic may be used as Sub-processors; and (ii) Nomic and its Affiliates respectively may engage Sub-processors in connection with the provision of the Services. The current list of Sub-processors is set out in the Nomic Security Center: www.nomic.ai/security. Customer authorizes Nomic to use the Sub-processors set out in the Nomic Security Center.

b. During the term of this DPA, Nomic must provide Customer with 30 days prior notification, via email, of any changes to the list of Sub-processors before authorizing any new or replacement Sub-processors to process Personal Data in connection with the provision of the Services.

c. Customer may object to the use of a new or replacement Sub-processor, by notifying Nomic promptly in writing within 10 business days after receipt of Nomic's notice. If Customer objects to a new or replacement Sub-processor, and that objection is not unreasonable, Customer may terminate the Agreement or applicable order with respect to those Services that cannot be provided by Nomic without the use of the new or replacement Sub-processor. Nomic must refund Customer any prepaid and unused fees covering the remainder of the term of the applicable order following the effective date of termination with respect to such terminated Services.

d. All Sub-processors that process Personal Data must comply with the applicable obligations of Nomic set out in this DPA. Nomic must, prior to the relevant Sub-processor carrying out any processing activities in respect of Personal Data: (i) appoint each Sub-processor under a written contract containing materially the same obligations to those of Nomic in this DPA enforceable by Nomic; and (ii) ensure each such Sub-processor complies with all such obligations.

e. Customer agrees that Nomic and its Sub-processors may make Restricted Transfers of Personal Data for the purposes of providing the Services to Customer in accordance with the Agreement. Nomic confirms that such Sub-processors: (i) are located in a third country or territory recognized by the EU Commission or a Supervisory Authority, as applicable, to have an adequate level of protection; or (ii) have entered into the applicable Standard Contractual Clauses with Nomic; or (iii) have other legally recognized appropriate safeguards in place.

10. EU/EEA and Swiss Restricted Transfers

a. The parties agree that, when the transfer of Personal Data between Customer and Nomic or from Nomic to a Sub-processor is a Restricted Transfer, it must be subject to the applicable Standard Contractual Clauses.

b. The parties agree that the EU SCCs apply to Restricted Transfers from the EEA. The EU SCCs are deemed entered into (and incorporated into this DPA by reference) and completed as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller of Personal Data and Nomic is processing Personal Data;
  • Module Three (Processor to Processor) applies where Nomic is a Processor of Personal Data and Nomic uses a Sub-processor to process Personal Data;
  • Module Four (Processor to Controller) must apply where Nomic is processing Personal Data and Customer is not subject to the EU GDPR or UK GDPR;
  • in Clause 7 of the EU SCCs, the optional docking clause will not apply;
  • in Clause 9 of the EU SCCs, Option 2 applies, and the time period for notice of Sub-processors must be as set out in Section 9.b. of this DPA;
  • in Clause 11 of the EU SCCs, the optional language does not apply;
  • in Clause 17 of the EU SCCs, Option 1 applies, the EU SCCs are governed by Irish law, and for the Swiss SCCs, Swiss law;
  • in Clause 18(b) of the EU SCCs, disputes must be resolved by: the courts of Ireland for the EU SCCs, and the courts of Switzerland for the Swiss SCCs;
  • Annex I of the EU SCCs is deemed completed with the information set out in Schedule 1 of this DPA; and
  • Annex II of the EU SCCs is deemed completed with the information set out in Schedule 2 of this DPA.

c. The parties agree that the EU SCCs, as amended in Section 10.b above, must be adjusted as set out below where the FADP applies to any Restricted Transfer:

  • The Swiss Federal Data Protection and Information Commissioner (FDPIC) must serve as the sole Supervisory Authority for Restricted Transfers exclusively subject to the FADP;
  • Restricted Transfers subject to both the FADP and the EU GDPR, must be dealt with by the EU Supervisory Authority named in Schedule 1 of this DPA;
  • The term 'member state' will not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs;
  • Where Restricted Transfers are exclusively subject to the FADP, all references to the GDPR in the EU SCCs are to be understood to be references to the FADP;
  • Where Restricted Transfers are subject to both the FADP and the EU GDPR, all references to the GDPR in the EU SCCs are to be understood to be references to the FADP insofar as the Restricted Transfers are subject to the FADP; and
  • The Swiss SCCs also protect the Personal Data of legal entities until the entry into force of the revised FADP.

d. If any provision of this DPA contradicts any Standard Contractual Clauses, the provisions of the applicable Standard Contractual Clauses prevail over this DPA.

e. If changes are made to the EU SCCs in the future, the parties must negotiate in good faith necessary amendments to the DPA and the Agreement to ensure compliance with applicable Data Protection Laws.

f. Should countries other than those in the EEA or Switzerland adopt cross-border data transfer clauses similar to the SCCs, the parties agree to execute such clauses when necessary.

11. United Kingdom Data Protection

a. This Section applies when the transfer of Personal Data between Customer and Nomic, or from Nomic to a Sub-processor, is a Restricted Transfer subject to the UK GDPR.

b. The parties agree that the UK SCCs apply to Restricted Transfers from the United Kingdom. The UK SCCs are deemed entered into (and incorporated into this DPA by reference), completed as follows: (i) Table 1 of the UK SCCs is deemed completed with the information set out in Schedule 1 of this DPA; (ii) Table 2 of the UK SCCs is deemed completed with the information set out in Schedule 2 of this DPA; (iii) Table 3 of the UK SCCs is deemed completed with the information set out in Schedules 1 and 2 of this DPA; and (iv) either party may end the UK SCCs as set out in clause 19 of the UK SCCs.

c. If any provision of this DPA contradicts the UK SCCs, the provisions of the UK SCCs prevail over this DPA with respect to Restricted Transfers from the United Kingdom.

d. If the UK SCCs are amended, superseded, or replaced by the UK government or the Information Commissioner's Office, the parties must negotiate in good faith necessary amendments to this DPA and the Agreement to ensure continued compliance with the UK GDPR.

e. For purposes of Schedule 1, Section C (Competent Supervisory Authority), the competent authority for Restricted Transfers subject to the UK GDPR is the Information Commissioner's Office (ICO).

12. Australian Privacy Act

a. This Section applies when Customer or any of its Affiliates is subject to the Australian Privacy Act, or when Nomic processes Australian Personal Information in the course of providing the Services.

b. Nomic acknowledges that, under APP 8 of the Australian Privacy Act, Customer may be accountable for Nomic's handling of Australian Personal Information as if Customer had committed any act or practice that would breach the APPs. Nomic must handle all Australian Personal Information in a manner consistent with the APPs.

c. Before disclosing Australian Personal Information to any Sub-processor located outside Australia, Nomic must take reasonable steps to ensure that the Sub-processor does not act or engage in a practice that would breach the APPs in relation to that information. At a minimum, Nomic must bind each such Sub-processor under a written agreement containing data protection obligations that are substantially similar to the APPs with respect to Australian Personal Information.

d. If Nomic becomes aware of an Eligible Data Breach involving Australian Personal Information, Nomic must notify Customer as soon as practicable and, in any event, no later than the timeframe specified in Section 6.a of this DPA, whichever is shorter. Nomic must provide Customer with sufficient detail to enable Customer to: (i) conduct an assessment under section 26WH of the Australian Privacy Act; and (ii) comply with its notification obligations to the OAIC and affected individuals under Part IIIC of the Australian Privacy Act.

e. Nomic must assist Customer in responding to any request by an individual to access their Australian Personal Information under APP 12, or to correct that information under APP 13, to the extent the request relates to Personal Data processed through the Services. Section 8 of this DPA governs the process for handling such requests.

f. To the extent that a cross-border disclosure of Australian Personal Information is not governed by the Standard Contractual Clauses described in Sections 10 and 11 (because Australia has not adopted equivalent transfer clauses), the parties agree that Nomic's compliance with this Section and the data protection obligations in this DPA constitutes the appropriate safeguard for such disclosure.

g. If Australia adopts a binding cross-border data transfer mechanism comparable to the Standard Contractual Clauses, the parties must negotiate in good faith to incorporate that mechanism into this DPA within 90 days of its effective date.

h. For purposes of Schedule 1, Section C (Competent Supervisory Authority), the competent authority for Australian Personal Information is the OAIC.

13. Brazilian General Data Protection Law (LGPD)

a. This Section applies when Customer or any of its Affiliates is subject to the LGPD, or when Nomic processes Brazilian Personal Data in the course of providing the Services.

b. Nomic must process Brazilian Personal Data only on documented instructions from Customer, in accordance with Articles 37 through 40 of the LGPD. Nomic must maintain a record of the processing operations it carries out on behalf of Customer involving Brazilian Personal Data, as required by Article 37 of the LGPD.

c. Any transfer of Brazilian Personal Data to a recipient outside Brazil must be carried out in accordance with one of the transfer mechanisms permitted under Article 33 of the LGPD, including: (i) transfer to a country or international organization that provides an adequate level of protection as determined by the ANPD; (ii) the ANPD-approved standard contractual clauses (Cláusulas Contratuais Padrão) adopted under ANPD Resolution CD/ANPD No. 19/2024, as updated from time to time; (iii) binding corporate rules approved by the ANPD; or (iv) another mechanism expressly authorized under Article 33 of the LGPD. If the parties have not executed the ANPD-approved standard contractual clauses and no other transfer mechanism under Article 33 applies, the parties must negotiate in good faith to put an appropriate mechanism in place within 60 days of either party identifying the gap.

d. If Nomic becomes aware of a security incident involving Brazilian Personal Data that may qualify as a reportable incident under the LGPD, Nomic must notify Customer as soon as practicable and no later than 48 hours after becoming aware of the incident. Nomic must provide Customer with sufficient detail to enable Customer to: (i) assess whether the incident qualifies as a security incident of relevant magnitude under Article 48 of the LGPD; and (ii) comply with its notification obligations to the ANPD within 3 business days and to affected data subjects within the timeframes established by ANPD Resolution CD/ANPD No. 15/2024, as amended from time to time.

e. Nomic must assist Customer in responding to data subject requests exercised under Article 18 of the LGPD, including requests for: (i) confirmation of the existence of processing; (ii) access to the data; (iii) correction of incomplete, inaccurate, or outdated data; (iv) anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the LGPD; (v) portability of data to another service provider; (vi) deletion of data processed with the data subject's consent; and (vii) information about public and private entities with which data has been shared. Section 8 of this DPA governs the process for handling such requests.

f. Nomic must cooperate with Customer in the preparation of any data protection impact assessment (Relatório de Impacto à Proteção de Dados Pessoais, or RIPD) that the ANPD may require Customer to produce under Article 38 of the LGPD, to the extent the RIPD relates to processing carried out by Nomic under this DPA.

g. Nomic must designate a data protection officer (encarregado) where required by Article 41 of the LGPD and make the identity and contact details of the encarregado available to Customer and to the ANPD upon request.

h. When engaging a Sub-processor to process Brazilian Personal Data, Nomic must ensure that the Sub-processor is bound by written obligations that are no less protective than those set out in this Section. Nomic remains fully liable to Customer for the acts and omissions of any Sub-processor with respect to Brazilian Personal Data, consistent with Article 39 of the LGPD.

i. If the ANPD updates or replaces its standard contractual clauses or adopts new binding transfer mechanisms, the parties must negotiate in good faith to incorporate the updated mechanism into this DPA within 90 days of its effective date.

j. For purposes of Schedule 1, Section C (Competent Supervisory Authority), the competent authority for Brazilian Personal Data is the ANPD.

14. New Zealand Privacy Act

a. This Section applies when Customer or any of its Affiliates is subject to the New Zealand Privacy Act, or when Nomic processes New Zealand Personal Information in the course of providing the Services.

b. Nomic must handle all New Zealand Personal Information in a manner consistent with the Information Privacy Principles (IPPs) set out in Part 3 of the New Zealand Privacy Act, to the extent those principles apply to Nomic's processing activities under this DPA.

c. Before disclosing New Zealand Personal Information to any Sub-processor or other recipient located outside New Zealand, Nomic must ensure that at least one of the following conditions is met: (i) the recipient is located in a country with privacy laws that provide comparable safeguards to the New Zealand Privacy Act; (ii) the recipient is subject to binding obligations (whether by contract, binding corporate rules, or another enforceable instrument) that provide comparable safeguards to the IPPs with respect to that information; (iii) the individual concerned has been expressly informed that the recipient may not be required to protect the information in a way that provides comparable safeguards to the IPPs, and the individual has authorized the disclosure; or (iv) another exception under section 193 of the New Zealand Privacy Act applies.

d. If Nomic becomes aware of a privacy breach involving New Zealand Personal Information that Nomic reasonably believes is, or is likely to be, a Notifiable Privacy Breach, Nomic must notify Customer as soon as practicable and no later than the timeframe specified in Section 6.a of this DPA, whichever is shorter. Nomic must provide Customer with sufficient detail to enable Customer to: (i) assess whether the breach meets the "serious harm" threshold under section 112 of the New Zealand Privacy Act; and (ii) comply with its notification obligations to the OPC and affected individuals under Part 6, Subpart 2 of the New Zealand Privacy Act.

e. Nomic must assist Customer in responding to any request by an individual to access their New Zealand Personal Information under IPP 6, or to correct that information under IPP 7, to the extent the request relates to Personal Data processed through the Services. Section 8 of this DPA governs the process for handling such requests.

f. When engaging a Sub-processor to process New Zealand Personal Information, Nomic must bind the Sub-processor under a written agreement containing data protection obligations that provide comparable safeguards to the IPPs with respect to that information. Nomic remains liable to Customer for the acts and omissions of any Sub-processor with respect to New Zealand Personal Information.

g. If New Zealand adopts a binding cross-border data transfer mechanism comparable to the Standard Contractual Clauses, the parties must negotiate in good faith to incorporate that mechanism into this DPA within 90 days of its effective date.

h. For purposes of Schedule 1, Section C (Competent Supervisory Authority), the competent authority for New Zealand Personal Information is the OPC.

15. Liability

a. The parties agree that Nomic is liable for any breaches of this DPA caused by the acts and omissions of its Sub-processors to the same extent Nomic would be liable if performing the services of each Sub-processor directly under the terms of this DPA.

b. The parties agree that Customer is liable for any breaches of this DPA caused by the acts and omissions of its Affiliates and users as if such acts and omissions had been committed by Customer itself.

c. The limitations of liability in the Agreement apply to all claims related to or arising under this DPA.

16. Term and Termination

Nomic must only process Personal Data for the term of this DPA. The term of this DPA coincides with the beginning of the Agreement and this DPA must automatically terminate upon the termination of the Agreement.

17. Deletion and Return of Personal Data

a. Nomic must, upon written request and at the choice of Customer, either: (i) make the Services available to Customer for the return of Personal Data to Customer at the expiration of the order within the time periods set out in the termination section of the Agreement, or (ii) securely delete all Personal Data. Nomic must securely delete all Personal Data after such time period, unless law applicable to Nomic prevents destruction of Personal Data; and upon request, provide a certification of deletion of Personal Data.

b. Where any Personal Data is retained beyond termination of this DPA, Personal Data must be treated as Confidential Information and must no longer be actively processed.

18. General

a. This DPA sets out the entire understanding of the parties, and supersedes all prior and contemporaneous agreements and understandings, with regards to the subject matter. No modification or waiver of any term in this DPA is effective unless both parties sign it.

b. Should any provision of this DPA be found to be invalid or become invalid, the legal effect of the other provisions must be unaffected. A valid provision is deemed to have been agreed upon, which comes closest to what the parties intended commercially and must replace the invalid provision. The same must apply to any omissions.

c. To the extent of any conflict or inconsistency, the following order of precedence applies: the applicable Standard Contractual Clauses, followed by the Agreement, and then this DPA, provided that, in all instances, the disclaimer of damages and limitation of liability in the Agreement applies. Subject to the amendments in this DPA, the Agreement remains in full force and effect.

d. Customer may send any questions or concerns regarding this DPA to: security@nomic.ai.

Schedule 1

List of Parties, Description of Processing and Transfer of Personal Data, Competent Supervisory Authority

A. List of Parties

The Exporter
Exporter[Customer's full legal entity name]
AddressAs set out for Customer in the Agreement.
Contact person's name, position and contact detailsAs provided by Customer in its account and used for notification and invoicing purposes.
Activities relevant to the data transferred under the SCCsUse of the Services.
Signature and dateBy entering into the Agreement, the Exporter is deemed to have signed the SCCs incorporated into this DPA and including their Annexes.
RoleController.
Name of Representative (if applicable)Any UK or EU representative named in the Exporter's privacy policy.
The Importer
ImporterNomic, Inc.
AddressAs set out for Nomic in the Agreement.
Contact person's name, position and contact detailsAs provided by Nomic in its account and used for notification and invoicing purposes.
Activities relevant to the data transferred under the SCCsThe provision of cloud computing solutions to the Exporter under which the Importer processes Personal Data upon the instructions of the Exporter in accordance with the terms of the Agreement.
Signature and dateBy entering into the Agreement, the Importer is deemed to have signed the SCCs, incorporated into this DPA, including their Annexes.
RoleProcessor.

B. Description of Processing and Transfers

Categories of Data Subject
  • Prospects, customers, business partners, and vendors of the Controller (who are natural persons).
  • Controller's users authorized by the Controller.
Categories of Personal DataUser account identifiers (name, email address, profile image URL); authentication credentials and session tokens (managed via SSO/SAML or delegated identity provider); user activity logs (queries submitted, files accessed, workflow actions, timestamps); IP addresses and browser metadata collected in the course of platform access; organization membership and role assignments (admin, member).
Sensitive DataNo sensitive data must be processed or transferred by the Processor, and sensitive data may not be contained in the content of or attachments to emails processed by the Processor.
The frequency of the processing and transferContinuous basis for the duration of the Agreement.
Nature of the processingNomic processes Personal Data to the extent necessary to perform the Services under the Agreement, as further instructed by Customer pursuant to this DPA.
Purpose(s) of the data transfer and further processingPersonal Data is transferred to Sub-processors who need to process some of Personal Data in order to provide their services to the Processor as part of the Services provided by the Processor to the Controller. Controller directs Processor to use the Personal Data to improve the Services and its associated systems, as Processor needs to improve the Services and systems on a regular basis to maintain the performance of the Services and the systems.
The period for which Personal Data must be retainedUnless agreed otherwise in writing, for the duration of the Agreement, subject to Section 17 (Deletion and Return of Personal Data) of this DPA.
For transfers to (Sub-)processorsThe Sub-processor list set forth in the Nomic Security Center (www.nomic.ai/security) sets out Personal Data processed by each Sub-processor and the services provided by each Sub-processor.

C. Competent Supervisory Authority

  • Where the EU GDPR applies, the Data Protection Authority in Ireland.
  • Where the UK GDPR applies, the UK Information Commissioner's Office (ICO).
  • Where the FADP applies, the Swiss Federal Data Protection and Information Commissioner (FDPIC).
  • Where the Australian Privacy Act applies, the Office of the Australian Information Commissioner (OAIC).
  • Where the LGPD applies, the Autoridade Nacional de Proteção de Dados (ANPD).
  • Where the New Zealand Privacy Act applies, the Office of the Privacy Commissioner (OPC).

Schedule 2

Technical and Organizational Security Measures

Below is a description of the technical and organizational measures implemented by the Processor(s) / Data Importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

Full details of the Processor's/Data Importer's technical and organizational security measures used to protect Personal Data is available at https://www.nomic.ai/security.

Where applicable, this Schedule 2 must serve as Annex II to the SCCs.

MeasureDescription
Measures of pseudonymization and encryption of personal dataPersonal Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Encryption keys are managed via AWS KMS with access restricted to authorized personnel under Nomic's Encryption and Key Management Policy.
Measures for ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and servicesAccess to systems and Personal Data is governed by role-based access control under Nomic's Access Control and Termination Policy, applying least privilege and need-to-know principles. Within the platform, two roles are enforced: Admin and Member; Nomic enforces and inherits the Customer's existing access controls from connected document systems and does not override or expand Customer-defined rights. Authentication is via SAML/OIDC single sign-on (managed through WorkOS) with multi-factor authentication enforced through the Customer's identity provider. Administrators may opt for alternative preferred authentication methods besides SSO.
Measures for ensuring the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incidentNomic maintains automated backups of customer-facing systems on AWS, encrypted using AWS KMS-managed keys. A Business Continuity and Disaster Recovery Policy governs restoration of services after a disaster or disruption, and is exercised at least annually through tabletop or equivalent testing of backup integrity and recovery procedures.
Processes for regularly testing, assessing and evaluating the effectiveness of technical and organizational measuresNomic completes an annual SOC 2 Type II audit covering security trust services criteria and engages a qualified third party to conduct annual network and application penetration testing of the production environment. Vulnerability scanning runs continuously on production infrastructure, with findings remediated under documented SLAs. SOC 2 reports and penetration test executive summaries are available to Customer upon request under NDA.
Measures for user identification and authorizationUser access to the Services is authenticated via SAML 2.0 or OIDC single sign-on, managed through WorkOS and compatible with Azure AD, Okta, and other enterprise identity providers. Multi-factor authentication is enforced through the Customer's identity provider configuration. Provisioning and deprovisioning flow through the identity provider on the Customer side. All authentication events are logged.
Measures for the protection of data during transmissionData in transit between Customer systems, end users, the Nomic platform, and authorized sub-processors is encrypted using Transport Layer Security (TLS) version 1.2 or higher. Transport security controls are tested as part of annual third-party penetration testing.
Measures for the protection of data during storagePersonal Data at rest is encrypted using AES-256. Primary infrastructure is hosted on Amazon Web Services in the United States by default, with alternative regions available on request. Customer Data is logically separated from data of other Nomic customers within the platform's storage and indexing layers.
Measures for ensuring physical security of locations at which personal data are processedNomic does not operate physical data centers; all primary infrastructure is hosted on Amazon Web Services, which maintains physical access controls including authorized-personnel approval, CCTV monitoring, electronic access controls, and intrusion detection at its facilities.
Measures for ensuring events loggingNomic maintains an immutable audit log of user and system events, including authentication, file access, workflow execution, integration changes, and administrative actions. Each entry records actor, action type, target object, and UTC timestamp. Audit logs are accessible to Customer organization administrators in the platform admin panel, retained for at least one year, and exportable as CSV.
Measures for ensuring system configuration, including default configurationSystem configurations are governed by Nomic's Configuration and Asset Management Policy and applied through infrastructure-as-code and automated tooling. Changes are governed by Nomic's Change Management Policy, which requires changes to be documented, tracked, tested, and approved by at least one independent reviewer prior to production deployment.
Measures for internal IT and IT security governance and managementNomic maintains a documented information security program governed by an Information Security Policy, with security responsibilities formally assigned within engineering and leadership. The information security team meets at least quarterly to review risks, controls, changes, and audit results. Vendor risk is managed under Nomic's Vendor Risk Management Policy, including review of vendor SOC 2 reports or equivalent at least annually.
Measures for certification/assurance of processes and productsNomic holds SOC 2 Type II certification (Johanson Group) and will maintain such certification, or a substantially similar or equivalent attestation, for the term of the Agreement. Nomic utilizes third-party data centers (Amazon Web Services) that maintain current SOC 2 attestation and ISO 27001 certification. Customer may request a copy of the most recently completed SOC 2 Type II report and the executive summary of its most recent third-party penetration test, at security.nomic.ai treated as Confidential Information under the Agreement.
Measures for ensuring data minimizationNomic processes Personal Data only as necessary to provide the Services and in accordance with Customer's documented instructions. Personal Data within Nomic's operational systems (such as audit logs and platform telemetry) is limited to fields required for the relevant function, typically account identifiers, role, action type, and timestamp. Customer file content is not transmitted to monitoring or analytics sub-processors.
Measures for ensuring data qualityCustomer Data and Personal Data are provided by, or designated by, the Customer. Nomic does not independently assess the accuracy or quality of Customer-provided data. Nomic provides reporting and audit tools within the platform admin panel that allow Customer administrators to review usage, activity, and AI consumption associated with Customer Data.
Measures for ensuring limited data retentionNomic retains Customer Data only as necessary to deliver the Services. Cached documents are retained for up to 30 days; user-generated content (conversations, reports, annotations, indexes) is retained for the subscription term unless deleted by Customer; usage metadata is retained for audit and platform operations under Nomic's Data Retention and Disposal Policy. Customer Data transmitted to AI inference sub-processors (Anthropic and Google Cloud Vertex AI) is processed ephemerally under contractual zero data retention agreements and is not retained by those sub-processors. Customer Data is not used to train, fine-tune, or improve any shared foundation model. On expiration or termination, Customer Data is deleted within 30 days using secure erasure methods.
Measures for ensuring accountabilityInformation security policies are reviewed by management at least annually, and personnel re-acknowledge applicable policies annually. All employees with access to Customer Data complete security awareness training at onboarding and annually thereafter, and are subject to documented disciplinary action for policy violations. Background checks are performed for all employees with access to Customer Data.
Measures for allowing data portability and ensuring erasureCustomer organization administrators may export user-generated content, audit logs (CSV), and usage data from the platform admin panel at any time during the term. Upon expiration or termination of an Order, Nomic will, at Customer's election, return Customer Data in a commercially reasonable format and/or delete it within 30 days using secure erasure methods. Data subject access requests are processed within one month of receipt in line with GDPR requirements, on Customer's documented instruction unless legally required otherwise.
Measures to be taken by the Sub-processor to provide assistance to the ControllerNomic engages sub-processors only as necessary to provide the Services and only under written contracts that impose data protection obligations no less protective than those set out in this DPA. The current list of sub-processors is set out in Nomic Security Center (www.nomic.ai/security). AI inference sub-processors operate under contractual zero data retention agreements. For Restricted Transfers, Nomic relies on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and other applicable transfer mechanisms as set out in this DPA.