For business customers
Data Processing Addendum
In short
This DPA is already in force — you do not need to sign anything. It applies automatically to every customer who accepts our Terms of Service and processes other people’s personal data through Nodes2Cloud.
It is short by the standards of the genre, because the scope of what we process on your behalf is genuinely small: your workflow designs and the credentials needed to deploy them. Your workflows’ actual data never reaches us.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between [PROPRIETOR_FULL_NAME], an individual carrying on business as a sole proprietorship under the trade name “Nodes2Cloud”, of [ADDRESS_LINE_1], [ADDRESS_LINE_2], [CITY], [STATE] [PIN_CODE], India (“Processor”, “we”) and the customer accepting those Terms (“Controller”, “you”).
No signature is required. This DPA takes effect on your acceptance of the Terms. If your procurement process requires a counter-signed copy, email legal@nodes2cloud.com and we will arrange one.
1. Scope and roles
- This DPA applies where, in using Nodes2Cloud, you process personal data relating to third parties — your customers, employees or contacts — and where that processing is subject to the GDPR, the UK GDPR, the DPDP Act or comparable law.
- You are the Controller (Data Fiduciary under the DPDP Act). You decide what personal data enters a workflow and why.
- We are the Processor (Data Processor) in respect of that data.
- We act as Controller only for your own account data — the email address, name and billing details of your users. That is governed by our Privacy Policy, not by this DPA.
- Where this DPA conflicts with the Terms of Service, this DPA prevails on data-protection matters.
An important limit on scope. Deployed workflows run in your own Cloudflare account. Personal data that a live workflow reads, writes or transmits is not processed by us at all — your relationship for that processing is with Cloudflare and with whichever services you connected, not with us. This DPA covers only the personal data that genuinely passes through or rests in our control plane.
2. Definitions
“Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Data Fiduciary”, “Data Processor” and “Data Principal” have the meanings given in the DPDP Act. “Applicable Data Protection Law” means all privacy and data-protection law applicable to the processing.
3. Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Nodes2Cloud workflow builder, compiler and deployment service. |
| Duration | For as long as your account is open, plus the retention periods in section 11. |
| Nature and purpose | Storing, versioning and compiling your workflow designs; storing and using credentials to deploy on your instruction; relaying test and debug traffic while you are in the editor. |
| Types of personal data | Whatever you place in a workflow’s configuration — typically identifiers, email addresses, message templates and field mappings. Plus credentials that may contain personal identifiers, and IP addresses and user agents of your users’ sessions. |
| Categories of data subject | Your personnel who use Nodes2Cloud, and any individuals whose data you place into a workflow configuration. |
| Special category data | Not contemplated. Do not place special category or sensitive personal data into a workflow’s static configuration. Use runtime references instead. |
4. Processing on documented instructions
- We process personal data only on your documented instructions. Your use of the service — the workflows you build and the deployments you trigger — constitutes those instructions, together with the Terms and this DPA.
- We will not process personal data for our own purposes, and specifically will not use it to train AI or machine-learning models.
- If we are legally required to process beyond your instructions, we will tell you first unless the law prohibits that notice.
- If we consider an instruction to breach Applicable Data Protection Law, we will tell you and may suspend performance of that instruction.
5. Confidentiality
Everyone we authorise to process personal data is bound by a duty of confidentiality, whether by contract or by statute, and that duty survives the end of their engagement. Access is limited to those who need it to perform the service, and — as described on our Security page — no interface exists that would let a person read a stored credential’s value.
6. Security measures
We implement appropriate technical and organisational measures under GDPR Article 32, including:
- AES-256-GCM encryption of stored credentials under per-account derived keys;
- a master key held only in the platform secret store, never in the database;
- optional client-held key wrapping, where we cannot decrypt at all;
- TLS for all data in transit;
- hashed passwords, hashed access tokens and hashed one-time codes;
- a strict Content Security Policy and origin-pinned API access;
- tenant isolation enforced at the data-access layer;
- an append-only audit log of significant actions;
- documented key rotation, backup and incident-response procedures.
The full description is on the Security page and is incorporated into this DPA by reference. We may update these measures provided the level of protection is not reduced.
7. Sub-processors
- You give general authorisation for us to engage sub-processors. The current list is published and maintained at Sub-processors.
- Each sub-processor is bound by written terms imposing data-protection obligations no less protective than those in this DPA.
- We remain fully liable to you for a sub-processor’s performance of its data-protection obligations.
- We give at least 30 days’ notice before a new sub-processor begins processing personal data. You may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected service and receive a refund of prepaid, unused fees.
- Emergency replacements may be made immediately where necessary for security or continuity, with notice as soon as practicable.
8. Assisting with data subject requests
- Taking account of the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to requests to exercise data subject rights.
- Most requests you can satisfy yourself: the editor lets you view, edit, export and delete your workflows and their configuration without involving us.
- If a data subject contacts us directly about data we process on your behalf, we will not respond substantively; we will refer them to you and tell you promptly.
- Assistance beyond what is reasonably necessary may be charged at our standard rates, agreed in advance.
9. Personal data breach notification
- We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed on your behalf.
- The notification will describe the nature of the breach, the categories and approximate number of records affected, likely consequences, and the measures taken or proposed.
- Where full information is not immediately available, we will provide it in phases as it is established rather than delaying the initial notice.
- We will reasonably assist you in meeting your own notification obligations to supervisory authorities and data subjects.
- We will not notify a supervisory authority or a data subject about a breach on your behalf unless you instruct us to.
10. Impact assessments and prior consultation
We will provide reasonable assistance with data protection impact assessments and prior consultations under GDPR Articles 35 and 36, to the extent they relate to processing we carry out and taking account of the information available to us. Our Security and Sub-processors pages are intended to answer most such questions without needing to contact us.
11. Deletion and return of data
- You may export your workflows as a standalone project at any time and without asking us. That is the primary return mechanism, and it does not depend on our cooperation.
- On termination, we delete personal data processed on your behalf as described in section 12 of the Privacy Policy: credentials and personal content are purged; the user record is anonymised so that records we must keep remain internally consistent.
- We may retain personal data where legally required — invoices and transaction records for 8 years under Indian tax law — and will keep it protected and process it only for that purpose.
- Resources deployed into your own Cloudflare account are not ours to delete. Removing them is your responsibility, and your controller obligations in respect of them continue.
12. Audits
- We will make available the information necessary to demonstrate compliance with GDPR Article 28, primarily through our published Security, Sub-processors and Privacy pages, and through written responses to reasonable questions.
- Where that is insufficient, you may request an audit no more than once in any twelve months, on at least 30 days’ written notice, at reasonable times and without unreasonable disruption. More frequent audits are permitted following a personal data breach affecting your data.
- Audits must be conducted under confidentiality obligations, must not access other customers’ data, and are at your cost unless a material non-compliance is found.
- We do not currently hold SOC 2 or ISO 27001 certification, and we will not represent otherwise.
13. International transfers
- Personal data may be transferred to and processed in countries outside the EEA, the UK and India, as set out at Sub-processors.
- For transfers subject to the GDPR, the parties adopt the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller-to-processor), which are incorporated into this DPA by reference. This DPA populates their annexes: Annex I from section 3, Annex II from section 6, Annex III from our published sub-processor list. The governing law and forum are those in section 16.
- For transfers subject to the UK GDPR, the parties adopt the UK International Data Transfer Addendum to those clauses.
- Under the DPDP Act, transfers outside India are permitted except to countries restricted by notification of the Central Government, and we will comply with any such notification.
14. Additional terms under India’s DPDP Act, 2023
Where the DPDP Act applies, we act as a Data Processor and undertake to:
- process personal data only under this DPA and your instructions;
- implement reasonable security safeguards to prevent personal data breaches, as described in section 6;
- notify you of any personal data breach so that you can meet your obligations to the Data Protection Board of India and to affected Data Principals;
- erase personal data on your instruction or on termination, subject to legal retention requirements; and
- assist you in responding to Data Principal requests and grievances.
Obtaining valid consent, and giving the notice required by DPDP §5 to the individuals whose data you place into a workflow, remain your responsibility as Data Fiduciary.
15. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in section 14 of the Terms of Service. Nothing in this DPA limits a data subject’s rights under Applicable Data Protection Law, or either party’s liability to a supervisory authority.
16. General
- Term. This DPA runs for as long as we process personal data on your behalf.
- Governing law. the laws of India, with the courts identified in the Terms — the competent courts at [CITY], [STATE], India — save that where the Standard Contractual Clauses apply, their own governing law and forum provisions apply to them.
- Changes. We may update this DPA to reflect changes in law or in the service, provided the level of protection is not reduced. Material changes are notified to account holders by email at least 30 days in advance.
- Severability. If a provision is invalid, the remainder continues in force.
- Contact. privacy@nodes2cloud.com for data-protection matters, or legal@nodes2cloud.com for contractual ones.