Data Processing Agreement

Version: 1.0 

Last updated: August, 2026

This Data Processing Agreement (“DPA”) may form a part of and be incorporated into any agreement (“Agreement”), including in a form of the Terms of Use, between Nevo Inc. or another legal entity within the group of companies (collectively, “Company”) and the applicable customer entity (“Customer”) (each a “Party” and together the “Parties”) that governs Customer’s use of Company’s services as defined below. This DPA is effective as of the effective date of the Agreement (the “Effective Date”).

ALLOCATION OF ROLES

1.1. For the purposes of this DPA, Company shall act as a Data Processor, the Customer shall be a Data Controller. Where the Customer acts as a Data Processor on behalf of its own Controller, the Company shall act as a Sub-processor. In such cases, the Customer warrants that its Controller has authorised the engagement of the Company as a Sub-processor and that this DPA satisfies any sub-processor requirements imposed by the Customer’s Controller. 

1.2.  The Customer acknowledges that Company may process certain Personal Data as an independent Data Controller for its own legitimate business purposes and legal grounds, including billing, invoicing, account management, fraud detection and prevention, security monitoring and service improvement. Such processing is carried out in accordance with the Privacy Notice and is not governed by this DPA.  

1.3. Where the Service is used to connect to a Slack workspace or other third-party tool, Company additionally acts as a Data Processor with respect to Personal Data of Workspace Members and other individuals whose data becomes accessible to the Service through such connection, as further described in Section 10 (THIRD-PARTY CONNECTORS AND INTEGRATIONS). The Customer, as the entity that authorised such connection, acts as the Data Controller in respect of that Personal Data and is responsible for the matters set out in Section 5.1(h).

BACKGROUND

2.1.   Company provides an AI-powered workspace platform (the “Service”) comprising, among other things: (a) a multi-model AI chat and gateway service; (b) tools for building and deploying custom AI agents, including an AI agent operable within a Customer’s Slack workspace; (c) connectors enabling integration with third-party productivity, project-management, developer, and other tools (including, without limitation, Notion, Jira, Google Calendar, and GitHub, among 100+ available connectors); (d) memory and personalisation features; and (e) content-generation tools (text, image, audio, and video). AI model inference underlying the Service is provided via Company’s affiliated AI model gateway, LLM API Inc. (“LLM API”), which in turn routes requests to independent third-party AI model providers as described in Section 9.

2.2.  In the course of providing the Service, the Company may process Personal Data on behalf of the Customer. The parties therefore enter into this DPA to govern processing in accordance with Applicable Data Protection Law.

2.3.  The parties acknowledge that the legal landscape for AI-assisted processing continues to evolve and agree to cooperate in good faith to maintain compliance with applicable law.

DEFINITIONS

3.1. The definitions in the Agreement shall be complemented or replaced with the following expressions used in this DPA:

“All Data Mode” shall mean an optional feature of the Service that the Customer may activate through their account settings, under which prompt inputs and model outputs are retained by Company for up to 90 days to enable additional functionality such as prompt analytics, semantic caching, and debugging. Activation of All Data Mode constitutes a documented processing instruction by the Customer to Company and transfers to the Customer sole responsibility for ensuring that such retention is lawful under Applicable Data Protection Law, including the identification of a valid legal basis and the provision of appropriate notice to Data Subjects. All Data Mode is disabled by default and may be deactivated, and retained content deleted, by the Customer at any time via the account dashboard.

“Applicable Data Protection Laws” shall mean all laws and regulations governing the processing of Personal Data applicable to either party, including (without limitation): EU GDPR (Regulation (EU) 2016/679); UK GDPR; the California Consumer Privacy Act (CCPA) as amended by CPRA; and other applicable US state privacy laws (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and equivalents).

Connector” shall mean a feature of the Service enabling the user or Customer to connect a third-party tool or platform (including, without limitation, Slack, Notion, Jira, Google Calendar, and GitHub) to the Service, thereby making data from that tool accessible to the Service within the scope configured by the User or Customer’s administrator.

“Controller Personal Data” means any Personal Data provided to the Processor in connection with the Services under the Agreement;

“Data Controller”, “Data Processor”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processes”, “Sub-Processor”, and “Supervisory Authority” shall have the same meaning as given to them under the EU GDPR;

Memory Feature” shall mean an optional, User-controlled feature of the Service (also referred to as “Personalisation”) under which context, preferences, and working style inferred from a User’s conversations are stored to personalise future responses. The Memory Feature is subject to User consent and may be disabled, with associated data deleted, at any time via account settings.

“Restricted Transfer” means each case where a transfer of Controller Personal Data would be prohibited by Applicable Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions) in the absence of an adequacy decision issued by the EU Commission as referred to in Article 45(1) of the EU GDPR, the competent UK authority (as applicable), or of the EU SCCs and/or UK Addendum (as applicable) to be established under Section 16 below;

“Request” means a request from a Data Subject to exercise the rights under the Applicable Data Protection Laws in respect of Controller Personal Data;

“EU SCCs” means the Standard Contractual Clauses in accordance with the EU Commission Implementing Decision (EU) June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, or any other standard contractual clauses issued by the EU Commission which replace such clauses from time to time; 

“UK Addendum” means the International Data Transfer Addendum to the EU SCCs (version B1.0, in force from 21 March 2022) issued by the UK Information Commissioner’s Office under S119(A) of the UK Data Protection Act 2018, as may be amended, superseded, or replaced from time to time.

Workspace Member” shall mean an individual who is a member of a Slack workspace, or a user of another third-party tool, that a Customer or User has connected to the Service via a Connector, and whose Personal Data (including messages, files, or profile information) becomes accessible to the Service as a result, regardless of whether that individual holds an account with Company.

PROCESSING OF PERSONAL DATA

4.1.  Company shall (a) comply with its obligations under all Applicable Data Protection Laws in the Processing of Controller Personal Data; (b) process the Controller Personal Data only on behalf of the Customer and in compliance with Customer’s documented instructions, the Agreement, and/or this DPA unless Processing is required by Applicable Data Protection Laws to which Company is subject, in which case the Company shall to the extent permitted by the Applicable Data Protection Laws inform the Customer of that legal requirement before the relevant Processing of Controller Personal Data; (c) without undue delay inform the Customer if, in its opinion, their instructions infringe the Applicable Data Protection Laws.

4.2. Company processes Controller Personal Data only to the extent necessary to provide the Service. By default, the Service operates on a zero-content-retention basis for prompt inputs and model outputs: such content is transmitted to the applicable AI model provider (via LLM API gateway service) and returned to the Customer without being stored on Company’s systems beyond the time required to complete the transaction, except where the Customer has enabled All Data Mode or a Customer (its user) has enabled the Memory Feature. Any information and data provided by the Customer to Company within the performance of this DPA shall remain at all times the property of the Data Controller.

4.3. The details of the scope, purpose, and duration of the Controller Personal Data and Processing covered by this DPA are set out in Annex I of the DPA.

RESPONSIBILITIES OF THE DATA CONTROLLER

5.1.  The Customer is responsible for the use of the Services and the Personal Data submitted. By entering into this DPA, Customer confirms that they as a Data Controller: (a) has, and will maintain, a valid legal basis under Applicable Data Protection Law for each category of Personal Data submitted to the Service; (b) Data Subjects have been provided with appropriate privacy notices that disclose the use of AI-assisted processing; (c) will not submit special category Personal Data (including data revealing racial or ethnic origin, health, biometric data, or similar) or Personal Data relating to minors under the age of 16 without entering into a separate written agreement with Company; (d) where required, Controller has conducted or will conduct a Data Protection Impact Assessment in relation to the use of the Service; (e) maintain an up-to-date record of processing activities as required by applicable law; (f) is and will be solely responsible for ensuring that Personal Data submitted to the Service is adequate, relevant, and limited to what is necessary (data minimisation); (g) if Controller is a Business under the CCPA, it will not direct Company to sell or share Personal Information as those terms are defined under the CCPA; (h) where Customer or its authorised administrator connects a Slack workspace or other third-party tool to the Service, Customer is solely responsible for (i) configuring the scope of access granted to the Service consistent with the principle of data minimisation, (ii) providing Workspace Members with appropriate notice regarding the Service’s operation within the connected environment, and (iii) ensuring a valid legal basis for the resulting processing of Workspace Members’ Personal Data.

OBLIGATIONS OF THE DATA PROCESSOR

6.1.  Company will process Controller Personal Data only on documented instructions, as set out in this DPA and the Terms of Use, unless required to do otherwise by applicable law. Where a legal requirement exists, Company will inform Customer before processing unless prohibited by law.

6.2.  Company will ensure that all personnel authorised to process Personal Data are subject to appropriate confidentiality obligations and receive adequate data protection training.

6.3.  Company will not use Controller Personal Data, prompt inputs, or model outputs, Slack workspace data, Connector data, or Memory Feature processed under this DPA to train, fine-tune, evaluate, benchmark, or otherwise improve any AI or machine learning model, whether operated by Company, a sub-processor, or any third party. This commitment applies to the Company and its Sub-processors. With respect to AI Providers referenced in Section 9, Company’s ability to bind such providers is limited to the terms each AI Provider makes available to its customers; Customer’s attention is drawn to Section 9.2(a)-(b) regarding Customer’s own review of each AI Provider’s training/use-of-data terms.

6.4.  Acting as a Service Provider under the CCPA and as a Processor under EU/UK GDPR, Company will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than providing the Service; or (c) combine Personal Data with data from other customers or external sources, except as permitted by Applicable Data Protection Law.

6.5.  Company will, taking into account the nature of the processing and the information available to it, provide reasonable assistance to enable Data Controller to: respond to Data Subject rights requests; implement appropriate security measures; carry out Data Protection Impact Assessments; and notify supervisory authorities and Data Subjects of Security Incidents, as required by Applicable Data Protection Law.

SECURITY

7.1.  Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity for the rights of Data Subjects, Company shall in relation to the Controller Personal Data implement and maintain appropriate technical and organizational measures in relation to its Processing of Controller Personal Data so as to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the EU GDPR.

7.2.  To the extent required under the Agreement and this DPA, the Company shall implement security measures as set forth in Annex II of this DPA.

7.3.  The Customer may request evidence of the Company’s security posture at any time by contacting privacy@getnevo.ai. Company may satisfy such requests by providing a current SOC 2 Type II report, ISO/IEC 27001 certification, or a completed security questionnaire.

SUB-PROCESSORS

8.1. By entering into this DPA, the Customer as a Data Controller gives general authorisation to the Company to engage Sub-processors without any additional notification. The up-to-date list of already engaged sub-processors may be presented upon the Customer’s request and\or in Annex III of this DPA. The Company shall notify the Customer of the amendments into the respective subprocessor list by amending the “Last updated date” and, if possible, send an email to the Customer’s registered address no less than 14 days prior to the change taking effect.

8.2. With respect to each Sub-processor, Company shall (a)  carry out adequate due diligence to ensure that the Sub-processor is capable of providing the level of protection for the Controller Personal Data required by this DPA; (b) ensure that the arrangement between the Processor and the Sub-processor is governed by a written contract including terms that offer no less onerous level of protection for the Controller Personal Data as one set out in this DPA; and (c) if that arrangement involves a Restricted Transfer, ensure that the Standard Contractual Clauses are at all relevant times incorporated into the agreement between the Processor and the Sub-processor.

8.3. Notwithstanding any authorization by the Data Controller within the meaning of the preceding sections, Company shall remain fully liable to the Controller for the performance of the Sub-processor’s obligations.

8.4. The Customer may reasonably object to the engagement of the respective Sub-processor at any time by sending the respective letter to the email enshrined herein. The Company shall review objections within 30 (thirty) days and, if possible, change the Sub-processor. If the objection cannot be resolved, the Company should notify the Customer without undue delay. 

AI MODEL PROVIDERS

9.1. AI Providers are independent third parties whose large language model inference services are made accessible through the Service via LLM API, Company’s affiliated AI model gateway. LLM API is disclosed as a Sub-processor of the Company in Annex III. AI Providers themselves are not Sub-processors of the Company. The Company does not control, direct, or take responsibility for the data processing operations of any AI Provider. Depending on the applicable AI Provider’s own terms of service, the AI Provider may act as an independent Controller in its own right, or as a processor engaged directly by the Customer.

9.2. By selecting an AI Provider through the Service, the Customer accepts sole responsibility for: (a) reviewing and agreeing to the AI Provider’s own terms of service, acceptable use policy, and data processing or privacy terms before transmitting any Personal Data; (b) entering into any data processing agreement or equivalent instrument directly with the AI Provider where required by Applicable Data Protection Law; (c) ensuring that the transmission of Personal Data to the AI Provider is lawful, including the identification of an appropriate legal basis and, where required, the implementation of a valid international transfer mechanism; (d) handling all Data Subject rights requests relating to Personal Data that has been transmitted to and processed by an AI Provider; and (e) assessing the AI Provider’s security, retention, and compliance posture independently of Company.

9.3. In relation to AI Providers, the Company and LLM API act exclusively as a technical routing layer. Company transmits the Customer’s API request to LLM API, which transmits it to the selected AI Provider and returns the resulting output to the Customer via Company. Neither Company, nor LLM API inspects, modifies, or retains the content of those requests or outputs beyond what is strictly necessary for transmission, except where the Customer and\or its user has enabled All Data Mode and Memory Feature.

9.4. Company makes no representations or warranties regarding any AI Provider’s compliance with Applicable Data Protection Law, data retention or deletion practices, security measures, sub-processing arrangements, or ability to honour Data Subject rights. To the maximum extent permitted by applicable law, Company shall have no liability to the Customer or to any Data Subject for any loss, damage, or regulatory consequence arising from the processing of Personal Data by an AI Provider, including any Data Breach, unauthorised disclosure, unlawful retention, or failure to comply with a Data Subject rights request occurring at the level of the AI Provider. 

9.5.  A list of the AI Providers currently accessible through the Service, together with links to their respective data processing terms and privacy policies, is controlled and maintained by LLM API at https://llmapi.ai/models/

9.6. Where the transmission of Controller Personal Data to an AI Provider constitutes a Restricted Transfer, Company will use commercially reasonable efforts to identify, and will make available to Customer upon request, the specific transfer mechanism (including Standard Contractual Clauses, an EU-US Data Privacy Framework certification, or equivalent) offered by that AI Provider under its own terms, to assist Customer in satisfying Customer’s obligations under Section 9.2(c)

THIRD-PARTY CONNECTORS AND INTEGRATIONS

10.1. Connectors are third-party tools and services (including, without limitation, Slack, Notion, Jira, Google Calendar, and GitHub, among 100+ available connectors) that the Customer or its users may elect to connect to the Service. Connectors are not Sub-processors of Company except where separately identified as such in Annex III.

10.2. By connecting a Connector, Customer accepts responsibility for: (a) reviewing the relevant Connector provider’s own terms of service and data processing or privacy terms; (b) configuring the scope of access granted to the Service (e.g., specific Slack channels, folders, or projects) consistent with the principle of data minimisation; (c) ensuring a valid legal basis for the processing of Personal Data of any individual whose data is made accessible via the Connector, including Workspace Members; (d) providing Workspace Members with appropriate notice of the Service’s operation within the connected environment, as further described in Section 5.1(h); and (e) handling Data Subject rights requests from Workspace Members or other third parties whose Personal Data is processed via a Connector, in accordance with Section 11.

10.3. In relation to Connectors, Company acts as a Data Processor, processing data made accessible through the Connector strictly as configured and instructed by the Customer or its authorised administrator, in accordance with Section 1.3 of this DPA.

10.4. Where the use of a Connector constitutes a Restricted Transfer, Company will use commercially reasonable efforts to identify, and will make available to Customer upon request, the relevant transfer mechanism offered by that Connector provider.

10.5. A current list of available Connectors is maintained within the Service dashboard. Company will notify Customer of material changes to this list in accordance with the mechanism described in Section 8.1.

DATA SUBJECT RIGHTS

11.1. Company will assist the Customer in fulfilling requests from Data Subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, objection, and opt-out of sale under the CCPA), taking into account the nature of the processing and the information available to Company.

11.2. If a Data Subject contacts Company directly to exercise a right, Company will forward the request to the Customer within five (5) business days and will not respond to the Data Subject directly without prior authorisation.

11.3. The Customer hereby acknowledges that Company’s ability to assist may be limited once Personal Data has been transmitted to a third-party AI model provider or made accessible via a Connector to a third-party tool provider. In that case, the Customer is responsible for coordinating with the relevant provider directly.

11.4. To submit a data subject rights request or to request deletion of data held under All Data Mode or Memory Feature, please contact: privacy@getnevo.ai 

PERSONAL DATA BREACH

12.1. Company shall notify the Customer within forty-eight (48) hours if it or Sub-processor becomes aware of any unauthorized or unlawful Processing of, loss of, damage to, or destruction or corruption of Controller Personal Data, providing the Customer with sufficient information to allow the Controller to meet any obligations to report to competent authorities or inform Data Subjects. Such information shall as a minimum: (a) describe the nature of the Personal Data Breach, the categories and numbers of Data Subjects concerned, and the categories and numbers of Personal Data records concerned; (b) communicate the name and contact details of the Data Processor’s data protection officer or another relevant contact from whom more information may be obtained; (c) describe the likely consequences of the Personal Data Breach; (d) describe the measures taken or proposed to be taken by the Data Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

12.2. The Company will cooperate with the Customer and take such reasonable steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

SUPERVISORY AUTHORITY INVESTIGATION

13.1. Both Parties shall cooperate and assist the other Party in the event of any measures or investigations taken by the Supervisory Authority related to any activities conducted under this DPA, including promptly notifying the other Party of the threat and commencement of such measures. The Parties shall take all reasonable measures necessary to limit the potential damage incurred to either of the Parties due to such event.

DATA DESTRUCTION

14.1. Upon termination of the Agreement or written request, Company will within 30 days: (a) cease all processing of Controller Personal Data; (b) at Controller’s election, securely delete or return all Personal Data (including copies held by sub-processors, to the extent technically feasible); and (c) provide written confirmation of deletion within 14 days of completion. 

14.2. Notwithstanding what is stated above, Company shall be entitled to retain Controller Personal Data to the extent required by Applicable Data Protection Laws and/or regulatory requirements and only to the extent and for such period as required and always provided that the confidentiality of all such Controller Personal Data is ensured.

AUDIT RIGHTS

15.1. Company shall make available to the Customer on request in a timely manner such information as is reasonably required by the Data Controller to demonstrate Data Processor’s compliance with its obligations under Applicable Data Protection Laws and this DPA.

15.2.  This shall be subject to the Customer giving the Company reasonable prior notice, but no later than 30 days in advance of such audit and/or inspection and ensuring that any auditor is subject to binding obligations of confidentiality and that such audit or inspection is undertaken so as to cause minimal disruption to Company’s business and in the narrowest applicable extent. 

15.3. Company cannot be obliged to give access to its documents and records for the purposes of such an audit or inspection: (a) to any individual unless he or she produces reasonable evidence of identity and authority; (b) outside normal business hours, unless the audit or inspection needs to be conducted on an emergency basis and the Data Controller has given notice to the Data Processor that this is the case before attendance outside those hours begins.

15.4.  The Company may satisfy audit requests by providing a current SOC 2 Type II report, ISO/IEC 27001 certification, or completion of a reasonable security questionnaire, where these cover the relevant processing activities.

CROSS-BORDER TRANSFERS 

16.1. RESTRICTED TRANSFER. The Parties agree that when the transfer of Controller Personal data from the Customer (as “data exporter”) to Company (as “data importer”) is a Restricted Transfer and Data Protection Laws require that appropriate safeguards are put in place, the transfer will be subject to the EU SCCs, which are deemed incorporated into and form a part of this DPA, as follows:

  1. In relation to transfers of Controller Personal Data protected by the EU GDPR, the EU SCCs will apply, completed as follows:
  • Module Two will apply;
  • in Clause 7, the optional docking clause should not apply;
  • in Clause 9, Option 2 will apply, and the time period for prior notice of Sub-processor changes will be as set out in Clause 8.4 of this DPA;
  • in Clause 11, the option will not apply;
  • in Clause 17, Option 1 will apply, and the EU SCCs will be governed by Irish law;
  • in Clause 18(b), disputes will be resolved before the courts of Ireland;
  • Annex I of the EU SCCs is deemed completed with the information set out in Annex I to this DPA, and the competent supervisory authority will be determined in accordance with the EU GDPR and Clause 13 of the EU SCCs;
  • subject to Section 7 of this DPA, Annex II of the EU SCCs is deemed completed with the information set out in Annex II to this DPA;
  • subject to section 8 of this DPA, Annex III of the EU SCCs is deemed completed with the information set out in Annex III to this DPA; and
  • Annex IV (if applicable) to this DPA provides additional safeguards agreed upon between the Parties as supplementary measures to the EU SCCs.
  1. In relation to transfers of Personal Data protected by UK Data Protection Laws, the EU SCCs: (i) apply as completed in accordance with Clauses 15.1 above; and (ii) are deemed amended as specified by the UK Addendum, which is deemed executed by the Parties and incorporated into and form an integral part of this DPA. In addition, Tables 1 to 3 in Part 1 of the UK Addendum are deemed completed respectively with the information set out in Sections 7, 8, and 15 of this DPA, as well as Annex I, Annex II, and Annex III of this DPA; Table 4 in Part 1 is deemed completed by selecting “neither party”. Any conflict between the terms of the EU SCCs and the UK Addendum will be resolved in accordance with Sections 10 and 11 of the UK Addendum.

16.2. US TRANSFER. Where the Customer is a Business under the CCPA or subject to equivalent US state privacy laws, the following terms apply in addition to the main DPA:

  1. Company acts as Service Provider under the CCPA and certifies it understands and will comply with the applicable Service Provider restrictions.
  2. Company will not sell, share, retain, use, or disclose Personal Information outside the direct business relationship or for any purpose other than those specified in Annex I.
  3. Company will not combine Personal Information received from the Customer with Personal Information from other sources except as permitted by applicable law.
  4. Company will assist the Customer in responding to verifiable consumer requests (access, deletion, correction, opt-out of sale/sharing, limit use of sensitive personal information) within CCPA-required timeframes.
  5. The Customer hereby retains the right to take reasonable steps to ensure Company uses Personal Information consistently with the given obligations, and to notify Company if it believes it is no longer able to meet its CCPA obligations.
  6. For Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and equivalent laws: Company agrees to act as a Processor, process data only on the respective instructions, maintain appropriate security, assist with consumer rights requests, delete or return data on the Customer request, and provide information necessary for data protection assessments.

TERM AND TERMINATION 

17.1  This DPA takes effect when the Customer first accepts the Terms of Use and continues for as long as the Company processes Personal Data on the behalf of the Customer. This DPA terminates automatically upon termination of the Agreement.

17.2. The Company may update this DPA by posting a revised version at the website by changing the version and “Last updated” date. Material changes to this DPA shall be communicated to the Customer in writing in advance. 

LIABILITY

18.1. Each party is liable for its own breach of this DPA and Applicable Data Protection Law.

18.2  Company’s aggregate liability under this DPA is subject to the limitations and exclusions set out in the Terms of Use, except where mandatory applicable law prohibits such limitation.

18.3  Nothing in this DPA excludes or limits either party’s liability for: (a) fraud or fraudulent misrepresentation; (b) death or personal injury caused by negligence; or (c) any other liability that cannot be excluded or limited by law.

MISCELLANEOUS

19.1. Except as otherwise required by the Section 16, this DPA shall be governed by the governing law set out in the Agreement.

19.2. If any provision is found invalid or unenforceable, the remainder continues in full force, and the parties will replace the invalid provision with a valid one that achieves the original intent.

19.3. In the event of conflict, the order of precedence is: (1) mandatory Applicable Data Protection Law; (2) the SCCs or UK Addendum (where applicable); (3) this DPA; (4) the Terms of Use.

19.4. For all data protection enquiries, please contact: privacy@getnevo.ai 

ANNEX I

DETAILS OF THE PROCESSING OF CONTROLLER PERSONAL DATA

SUBJECT MATTERProvision of the NEVO AI workspace platform, including AI chat and gateway services, custom and Slack-based AI agents, third-party connectors/integrations, memory and personalisation features, and content-generation tools, as set out in the Agreement and this DPA.
DURATION OF PROCESSINGThis DPA shall be in force for so long as the Processing of Controller Personal Data continues.
NATURE OF PROCESSINGAutomated routing of chat/API requests to third-party AI model providers via LLM API; operation of AI agents within a connected Slack workspace and other connected tools, within the scope configured by the Customer or its administrator; storage of Memory Feature data (opt-in); storage of agent configurations, Knowledge Base content, and generated content; storage of request metadata for billing and analytics. No human decision-making by Company on the content of requests, outputs, or connected workspace/connector data.
PURPOSE OF PROCESSINGProviding AI inference, agent, and connector services as directed by the Customer; enabling AI agent functionality within connected tools; billing and cost analytics; service reliability and caching (if enabled); memory-based personalisation (where enabled by the User).
PERSONAL DATA CATEGORIESDetermined by the Customer. May include: names, email addresses, user-generated text, conversation history, Slack messages, files, and profile data, Connector data from third-party tools (e.g., Notion, Jira, Google Calendar, GitHub), professional information, agent configuration data, generated content, or other data included in requests or made accessible via a Connector. Special category data and children’s data must not be submitted without prior written agreement.
DATA SUBJECTSDetermined by the Customer. May include: end users of the Customer’s products or services; employees or contractors of the Customer; Workspace Members of a connected Slack workspace; any other individuals whose Personal Data is made accessible to the Service via a Connector or included in requests.
SENSITIVE DATANone, unless separately agreed in writing by the Company.
FREQUENCY OF PROCESSINGContinuous / on-demand, triggered by the Customer’s use of the Service, including monitoring of connected Slack channels or other Connector data within the scope configured by the Customer.
RETENTION PERIODThe period of the Agreement and such additional period as (a) is specified in any provisions of the Agreement or this DPA regarding data retention; and (b) is required for compliance with Applicable Data Protection Laws.
SUB-PROCESSINGWhere Company engages Sub-processors, it will do so in compliance with the terms of this DPA. The subject matter, nature, and duration of the Processing activities carried out by the Sub-processor will not exceed the subject matter, nature, and duration of the Processing activities hereunder. The Processor will maintain agreements with all Sub-processors requiring technical and organizational measures no less onerous than those maintained by the Processor under this DPA.

ANNEX II

SECURITY MEASURES

Company maintains a comprehensive written information security program designed to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. This program includes the following safeguards:

Governance and certificationCompany has implemented an information security management system conforming to ISO/IEC 27001:2022 and SOC 2 Type II.
Encryption in transitTLS 1.2 or higher on all Service endpoints; HTTPS enforced; no unencrypted transmission of Personal Data.
Encryption at restAES-256 encryption for sensitive data stored on AWS infrastructure.
Access controlRole-based access control; least-privilege principle; unique user IDs issued to all personnel; shared accounts prohibited; multi-factor authentication for all administrative and remote access; monthly access reviews; access revoked promptly upon termination or role change; Controller Personal Data logically separated from other customer data.
API key / OAuth token managementAPI keys and Connector OAuth tokens stored in hashed or encrypted form only; never stored or logged in plaintext; key/token rotation supported; tokens revocable by Customer at any time via the account dashboard.
Zero data retention (default)Technical controls prevent persistent storage of prompt inputs and outputs by default, absent Customer instruction to enable All Data Mode or a User’s enablement of the Memory Feature or other opt-in feature.
InfrastructureHosted on AWS Frankfurt (eu-central-1). AWS holds ISO/IEC 27001, SOC 1, SOC 2, and PCI DSS certifications. Remote access to production systems requires a secure VPN with multi-factor authentication. Firewalls are maintained to protect all networks hosting Controller Personal Data. Anti-malware software is deployed and automatically updated. Systems are kept current with security patches in accordance with defined patch management SLAs.
Vulnerability managementRegular automated vulnerability scanning; annual penetration testing by independent third parties; defined patch management SLAs.
Incident responseDocumented incident response plan; 48-hour Customer notification commitment.
Personnel securityBackground checks for personnel with access to Personal Data where legally permissible; mandatory annual security awareness training; confidentiality agreements; access limited to those with a legitimate business need-to-know.
Data DeletionWhen storage media is retired or repurposed, data is securely deleted in accordance with NIST SP 800-88 Rev.1 or successor standards, rendering data irrecoverable.
Business continuityAutomated backups; defined RTO and RPO; disaster recovery plan.
Audit loggingComprehensive logging of access to Personal Data; anomaly detection and alerting; logs retained for 90 days minimum.

ANNEX III

LIST OF SUB-PROCESSORS

Last updated: 25 August 2026

Sub-processorProcessing ActivityData LocationTransfer Mechanism
LLM API Inc. AI model gateway / routing backend for AI inference requests (text, image, audio, video) to third-party AI Providers. Does not include the AI Providers themselves — see Section 9.US / EU (per LLM API’s own infrastructure)Intra-group transfer; SCCs as supplementary mechanism where applicable.
Amazon Web Services, Inc.Cloud hosting/storage/infrastructure only (Company’s own systems).Frankfurt, Germany (eu-central-1)EU adequacy / AWS SCCs as supplementary mechanism.
Stripe, Inc.Payment and billing processing (account metadata only; no prompt content).USAEU–US DPF certified.
ChargebeePayment processing (account metadata only; no prompt content).USAEU–US DPF certified / SCCs as supplementary mechanism.
PostHog, Inc.Product analytics (aggregated / anonymised usage data).EU (self-hosted on AWS eu-central-1)N/A — processed in EU.
HubSpot, Inc.CRM and account communications (business contact data only).USAEU–US DPF certified; SCCs as supplementary mechanism.
Google Cloud Storage (GCP)Optional object storage — Vertex AI batch staging only (activated per customer request).EU region (europe-west)EU–US DPF / SCCs as supplementary mechanism.
Google LLC (OAuth2 / Google Workspace)Authentication and identity — Google OAuth2 login, optional Google Workspace SSO; also available as a Connector — see Section 10.USAEU–US DPF certified; SCCs as supplementary mechanism.
GitHub, Inc. (GitHub OAuth2)Authentication — GitHub OAuth2 login; also available as a Connector — see Section 10.USASCCs.
Microsoft Azure MonitorObservability — infrastructure monitoring, alerting, diagnostics.EU region (West Europe / North Europe)EU–US DPF / SCCs as supplementary mechanism.
Juro LtdContract lifecycle management — storage and processing of commercial agreements (business contact data of signatories).United KingdomUK adequacy decision applies; SCCs for onward EEA transfers.
Cloudflare, Inc.Content delivery network (CDN), DDoS protection, WAF, DNS resolution — processes IP addresses and HTTP request metadata of end users.Global (including EU nodes); data processed at edge closest to userEU–US DPF certified; SCCs for non-adequate country transfers.
Sign Up