Last Updated: October 7, 2025
This Data Processing Agreement ("DPA") is entered into between: (1) The Customer: The legal entity that has executed a
Service Agreement for the use of Nixi AI's services ("Data Controller"); and (2) The Provider: Nixi AI, a partnership
established under the laws of Germany, with its principal place of business at Adolfsallee 14, 65185 Wiesbaden,
Germany ("Data Processor"); (each a "Party" and together the "Parties").
A. The Data Controller and the Data Processor have entered into an agreement for the provision of the Data Processor's services (the "Service Agreement"). This DPA forms an integral part of and is subject to the Service Agreement.
B. In the course of providing the services under the Service Agreement, the Data Processor will process certain personal data on behalf of the Data Controller. Consequently, the Data Controller acts as a controller and the Data Processor acts as a processor within the meaning of the GDPR.
C. This DPA sets out the terms and conditions that govern the Data Processor's Processing of Personal Data on behalf of the Data Controller.
D. The purpose of this DPA is to ensure that the processing of personal data complies with the requirements of Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR").
E. This DPA does not exempt the Data Processor from its own direct obligations under the GDPR or any other applicable data protection laws.
1.1. This Data Processing Agreement ("DPA") consists of this main body and the following annexes, which form an integral part hereof:
1.2. In the event of any conflict between the terms of this DPA and the Service Agreement, the terms of this DPA shall prevail with regard to the subject matter of data processing.
1.3. Capitalized terms not otherwise defined herein shall have the meaning given to them in the Service Agreement.
2.1. Terms such as "Personal Data," "Processing," "Data Subject," "Personal Data Breach," and "Supervisory Authority" shall have the meanings ascribed to them in the GDPR.
2.2. In this DPA, the following terms shall have the following meanings:
The Data Processor undertakes to:
3.1. Purpose Limitation: Process Personal Data solely for the Approved Purposes and in accordance with the Data Controller's documented instructions as set out in Annex A. If the Data Processor considers an instruction to infringe Applicable Data Protection Law, it shall immediately inform the Data Controller.
3.2. Confidentiality: Ensure that all persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3. Security: Implement the appropriate technical and organisational measures specified in Annex B to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. The principles of data protection by design and by default shall be observed.
3.4. Sub-processing: Not engage any Sub-processor without the prior specific or general written authorisation of the Data Controller. The Data Processor shall ensure that any engaged Sub-processor is bound by data protection obligations that are at least as protective as those in this DPA. Approved Sub-processors are listed in Annex C.
3.5. Assistance with Data Subject Rights: Taking into account the nature of the Processing, assist the Data Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Data Controller's bligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR.
3.6. Personal Data Breach Notification: Notify the Data Controller without undue delay after becoming aware of a Personal Data Breach, providing the Data Controller with sufficient information to allow them to meet their own notification obligations under the GDPR.
3.7. Assistance with Compliance: Assist the Data Controller in ensuring compliance with its obligations pursuant to Articles 32 to 36 of the GDPR (Security of Processing, Breach Notification, and Data Protection Impact Assessments), taking into account the nature of the Processing and the information available to the Data Processor.
3.8. Data Deletion or Return: At the choice of the Data Controller, delete or return all Personal Data to the Data Controller after the end of the provision of services relating to Processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data.
3.9. Audits and Inspections: Make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR and allow for and contribute to audits, includinginspections, conducted by the Data Controller or another auditor mandated by the Data Controller.
3.10. Transfers to Public Authorities: Notify the Data Controller of any legally binding request for disclosure of the Personal Data by a law enforcement authority, unless otherwise prohibited, such as a prohibition under criminal law to preserve the confidentiality of a law enforcement investigation.
4.1. Lawfulness of Processing: The Data Controller is solely responsible for the accuracy, quality, and legality of the Personal Data and the means by which it acquired the Personal Data. The Data Controller warrants that it has a valid legal basis for the Processing of all Personal Data as contemplated by the Service Agreement and this DPA.
4.2. Documented Instructions: The Data Controller shall provide all instructions to the Data Processor in writing (including by email) and ensure such instructions are in compliance with Applicable Data Protection Law.
4.3. Processor Compliance: The Data Controller is responsible for ensuring, throughout the duration of the Processing, that the Data Processor's activities align with its instructions and the agreed-upon terms of this DPA.
4.4. Supervision and Audits: The Data Controller has the right to supervise the Processing, which includes conducting audits and inspections of the Data Processor to verify compliance with this DPA.
6.1. General Authorization. The Data Controller provides a general written authorization for the Data Processor to engage the Sub-processors listed in Annex C.
6.2. Sub-processor Obligations. The Data Processor shall enter into a written agreement with each Sub-processor that imposes data protection obligations that are at least as protective as those set out in this DPA. The Data Processor shall ensure that the Sub-processor provides sufficient guarantees to implement appropriate technical and organisational measures in compliance with the GDPR.
6.3. Changes to Sub-processors. The Data Processor shall inform the Data Controller of any intended changes concerning the addition or replacement of Sub-processors at least thirty (30) days in advance, thereby giving the Data Controller the opportunity to object to such changes. If the Data Controller objects, the Parties shall discuss in good faith a commercially reasonable resolution.
6.4. Onward Liability. The Data Processor shall remain fully liable to the Data Controller for the performance of a Sub- processor's data protection obligations.
General Principle
7.1. Personal Data shall only be processed within the European Economic Area (EEA) or a jurisdiction deemed adequate by the European Commission, except where a valid transfer mechanism is in place.
Transfer Mechanism
7.2. For any transfer of Personal Data from the Data Processor to an approved Sub-processor located in a third country not recognized as adequate (a "Restricted Transfer"), such transfer shall be governed by the Standard Contractual Clauses (SCCs).
Mandate to Execute SCCs
7.3. The Data Controller hereby grants the Data Processor a mandate to enter into the Standard Contractual Clauses, specifically Module Three (Processor to Sub-processor), with any approved Sub-processor on the Data Controller's behalf to legitimize a Restricted Transfer.
Continued Liability
7.4. The use of SCCs does not relieve the Data Processor of its obligations under this DPA. The Data Processor remains fully liable to the Data Controller for the performance of the Sub-processor's obligations as specified in Section 6.4.
8.1. Controller's Responsibility. The Data Controller is solely responsible for providing information to Data Subjects regarding the Processing of their Personal Data and for managing requests to exercise their rights.
8.2. Processor's Assistance. The Data Processor shall, taking into account the nature of the Processing, assist the Data Controller by appropriate technical and organisational measures with fulfilling its obligation to respond to requests from Data Subjects. If a Data Subject sends a request directly to the Data Processor, the Data Processor shall promptly forward the request to the Data Controller's designated contact person.
9.1. General Commitment. The Data Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures shall ensure a level of security appropriate to the risk.
9.2. Specific Measures. The Data Processor undertakes to implement, at a minimum, the technical and organisational measures set out in Annex B. The Data Processor reserves the right to update these measures, provided that such updates do not result in a material degradation of the overall security of the Services.
10.1. Notification. In the event of a Personal Data Breach, the Data Processor shall notify the Data Controller without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of it. The notification shall be sent to the Data Controller's designated contact person.
10.2. Information Provided. The notification shall, as far as possible, include: The nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned; The likely consequences of the Personal Data Breach; The measures taken or proposed to be taken by the Data Processor to address the breach and mitigate its possible adverse effects; and The name and contact details of the Data Processor's point of contact for more information.
10.3. Cooperation. The Data Processor shall provide the Data Controller with reasonable cooperation and assistance required to fulfil the Data Controller's own data breach notification obligations under the GDPR.
11.1. Requests for Disclosure. The Data Processor shall promptly notify the Data Controller of any legally binding request from a law enforcement or other governmental authority for the disclosure of Personal Data, unless prohibited by law. If legally permissible, this notification shall be provided to the Data Controller before the Data Processor discloses any Personal Data.
11.2. Legally Mandated Retention. If the Data Processor is required by applicable law to retain any Personal Data where it would otherwise be required to be deleted or returned under Section 3.8, it shall notify the Data Controller of this retention requirement. The obligations of confidentiality and security as set out in Section 9 shall continue to apply to such retained Personal Data.
12.1. The liability of each Party under this DPA shall be subject to the limitations and exclusions of liability set out in the Service Agreement. For the avoidance of doubt, any reference to liability in the Service Agreement shall be interpreted to include liability under this DPA.
This Annex forms part of the DPA and describes the details of the Processing of Personal Data by the Data Processor on behalf of the Data Controller.
Additional Processing Notes:
Pursuant to Article 32 of the GDPR, the Data Processor shall implement and maintain the following technical and organisational measures to ensure a level of security appropriate to the risk of the Processing.
The Data Controller provides general authorization for the Data Processor to engage the sub-processors listed below, in accordance with the terms of the DPA.