This Data Processing Agreement governs Nuaj's processing of personal data on behalf of the Customer. It is incorporated into the Terms of Service and applies automatically, without signature, whenever and to the extent that Nuaj acts as a processor for the Customer. A countersigned copy is available on request from legal@nuaj.com.
Where the Customer is established in, or processes personal data of individuals in, the European Economic Area, the United Kingdom, or Switzerland, this DPA is the parties' agreement for the purposes of Article 28 of the General Data Protection Regulation. Where Canadian law applies, it is the parties' agreement for the purposes of the transfer and accountability requirements of Canadian federal and Quebec privacy legislation.
"Customer Personal Data" means personal data contained in the configuration, reporting, and operational data the Customer submits to, or generates through, the Hosted Service.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR.
Capitalized terms not defined here have the meaning given in the End User License Agreement.
Roles. The parties agree:
Nuaj shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law to which Nuaj is subject — in which case Nuaj shall inform the Customer of that requirement before processing, unless the law prohibits it.
The Terms of Service, this DPA, the configuration the Customer applies through the dashboard or API, and the Customer's use of the Hosted Service together constitute the Customer's complete documented instructions.
Nuaj shall inform the Customer if, in its opinion, an instruction infringes applicable data protection law. Nuaj may suspend performance of an instruction it reasonably believes to be unlawful until the Customer confirms, modifies, or withdraws it.
Nuaj shall not sell Customer Personal Data, and shall not use it for its own purposes, for advertising, or to train models offered to third parties.
Subject matter. Provision of the NuajProtect Hosted Service — network threat filtering, policy enforcement, alerting, and reporting.
Duration. For the term of the Customer's subscription, plus the deletion period in section 9.
Nature and purpose. Collection, storage, organization, analysis, transmission, retrieval, and erasure, for the purpose of operating, securing, supporting, and reporting on the Customer's protected endpoints.
Types of Personal Data.
| Category | Examples |
|---|---|
| Account identifiers | Names, business email addresses, roles, organization |
| Authentication data | Password hashes, MFA enrolment, session records, sign-in times |
| Network identifiers | Source and destination IP addresses observed at protected endpoints, ports, protocols |
| Endpoint identity | The hostname of each protected endpoint, the addresses configured on its interfaces (including private addresses), and its public egress address |
| Operational records | Block and drop events, flood and alert events, device health, configuration state, audit entries |
| Support content | Whatever the Customer includes in a support request |
| Diagnostic captures | NuajProtect service log lines and kernel messages, retrieved from an endpoint on operator request while investigating a fault |
Nuaj does not collect packet payloads from protected endpoints, and does not collect the Customer's application, system, or security logs.
To investigate a fault, an authorized Nuaj operator may request a diagnostic capture from a protected endpoint. A capture is limited to NuajProtect's own service log and the kernel message buffer; it is requested deliberately rather than taken automatically, is capped in size, is retained only for the duration of the support interaction, and is not written to durable storage. Kernel messages may incidentally contain device and address identifiers.
Categories of Data Subjects. The Customer's personnel and authorized users; individuals whose IP addresses are observed by the Customer's protected endpoints, including the Customer's own network users and third parties who originate traffic toward them.
Special categories. The Hosted Service is not designed for and must not be used to process special categories of personal data under GDPR Article 9, or personal data relating to criminal convictions and offences under Article 10. The Customer shall not submit such data.
Nuaj shall ensure that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, are informed of the confidential nature of the data, and receive access only to the extent their duties require.
Nuaj shall implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects.
Nuaj may update those measures over time provided the level of protection is not reduced.
The Customer gives Nuaj general written authorization to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex III.
Nuaj shall inform the Customer of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. Where the Customer objects and the parties cannot agree a resolution within thirty (30) days, the Customer may terminate the affected subscription and receive a pro rata refund of prepaid fees for the remainder of the then-current period.
Nuaj shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
To receive sub-processor change notices, write to privacy@nuaj.com.
Taking into account the nature of the processing, Nuaj shall assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights.
Where Nuaj receives a request directly from a Data Subject concerning Customer Personal Data, Nuaj shall not respond to it substantively but shall, without undue delay, direct the Data Subject to the Customer and inform the Customer of the request.
The dashboard and API allow the Customer to access, export, correct, and delete Customer Personal Data directly. Where those functions are sufficient, Nuaj's assistance obligation is met by their availability.
Nuaj shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed.
Where all the required information is not available at once, Nuaj shall provide it in phases without further undue delay.
Nuaj shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Nuaj.
Notification of a breach is not an acknowledgment of fault or liability.
On termination of the Customer's subscription, the Customer may export Customer Personal Data from the dashboard for thirty (30) days, as set out in the Terms of Service.
After that period Nuaj shall delete Customer Personal Data, except to the extent that storage is required by law to which Nuaj is subject. Where Nuaj retains data on that basis, it shall protect it in accordance with this DPA and process it only for the purpose requiring retention.
Backups are overwritten on their ordinary rotation cycle; data present only in backups is deleted on that cycle rather than on demand.
Nuaj shall make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR, including Annex II of this DPA and any third-party assessment or certification Nuaj holds.
Where that information is insufficient, Nuaj shall allow for and contribute to an audit, including an inspection, conducted by the Customer or an auditor it mandates, subject to: reasonable prior written notice of at least thirty (30) days; no more than once in any twelve-month period, except where required by a supervisory authority or following a Personal Data Breach; conduct during business hours and without unreasonable disruption; and appropriate confidentiality undertakings from the auditor. The Customer bears its own and the auditor's costs.
Customer Personal Data is stored in Canada. Certain sub-processors listed in Annex III process limited data outside Canada.
Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), with the Customer as data exporter and Nuaj as data importer. Annexes I, II, and III of this DPA populate the corresponding annexes of those Clauses. For the United Kingdom, the UK International Data Transfer Addendum applies. Where the Clauses conflict with this DPA, the Clauses prevail.
Canada has an adequacy decision from the European Commission in respect of commercial organizations subject to its federal privacy legislation.
Where a transfer of personal data outside Quebec is subject to Quebec's privacy legislation, Nuaj shall provide the Customer with the information the Customer reasonably requires to conduct its privacy impact assessment.
Each party's liability under this DPA is subject to the limitations and exclusions in the End User License Agreement, except where applicable data protection law does not permit that limitation.
Where this DPA conflicts with the End User License Agreement, the Terms of Service, or the Privacy Policy on a question of Nuaj's processing of Customer Personal Data as a Processor, this DPA prevails. On all other questions the order of precedence in the End User License Agreement applies.
This DPA takes effect when the Customer accepts the Terms of Service and continues for as long as Nuaj processes Customer Personal Data. Sections that by their nature should survive — confidentiality, deletion, liability, and precedence — survive its termination.
Data exporter: the Customer, as identified in its NuajProtect account. Role: Controller.
Data importer: Nuaj Company Inc., 8250 Lawson Rd., Suite 201, Milton, Ontario L9T 5C6, Canada. Contact: privacy@nuaj.com. Role: Processor.
Categories of Data Subjects, types of Personal Data, subject matter, nature, purpose, and duration: as set out in section 3 above.
Frequency of transfer: continuous, for the duration of the subscription.
Competent supervisory authority (for the Standard Contractual Clauses): the supervisory authority of the EEA Member State in which the data exporter is established or, where it is not established in the EEA, that of the Member State in which its EU representative is established or in which the Data Subjects are located.
The measures below are those actually implemented. They may be improved but not weakened.
Access control. Role-based access control with least privilege. Administrative functions are restricted to designated roles. Access is scoped to a single tenant, and cross-tenant access is prevented at the data layer, not only in the interface.
Authentication. Passwords are stored as argon2id hashes and are never stored or transmitted in plaintext. Multi-factor authentication is available and supports authenticator apps (TOTP), passkeys/WebAuthn, SMS, and email codes. Sessions have idle and absolute expiry, are bound to a token hash, and can be revoked individually.
Encryption. All traffic between browsers, protected endpoints, and the Hosted Service is encrypted in transit using TLS. Communication with protected endpoints is additionally signed with per-device Ed25519 keys; private keys never leave the device. Manufacturing and provisioning secrets are encrypted at rest with authenticated encryption; on-device credential files are root-owned with restrictive permissions.
Integrity. Agent software distributed by Nuaj is cryptographically signed and verified before installation. Acceptance of legal agreements is recorded with a cryptographic hash of the exact text accepted.
Logging and monitoring. Administrative and security-relevant actions are written to an audit log recording actor, action, target, source IP, and time. Authentication attempts are rate limited by source address.
Segregation. Customer data is logically segregated by tenant. Development and production environments are separate.
Resilience. The Hosted Service is operated from a facility in Milton, Ontario. Protected endpoints continue to enforce the policy already deployed if they lose contact with the Hosted Service, so a control-plane outage does not remove protection.
Personnel. Access to production is limited to personnel who require it, under confidentiality obligations.
Sub-processor management. Sub-processors are engaged under written terms no less protective than this DPA, and are listed in Annex III.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and billing | United States / Ireland |
| PayPal | Alternative payment processing | United States / Luxembourg |
| Google (Workspace) | Outbound email delivery for service messages | United States |
| VoIP.ms | SMS delivery for multi-factor authentication codes | Canada |
Hosting is not sub-contracted: Nuaj operates the Hosted Service from its own facility in Ontario, Canada.