This Data Processing Agreement governs Nuaj's processing of personal data on behalf of the Customer. It is incorporated into the Master Terms and applies automatically, without signature, whenever and to the extent that Nuaj acts as a processor for the Customer. A countersigned copy is available on request from legal@nuaj.com.
It covers every Nuaj product — but Nuaj is a processor for only one of them. Section 1 states the role per product, and it is the section to read first: NuajProtect's hosted control plane makes Nuaj a processor; NuajLens sends Nuaj nothing at all; Nexaplane sends only a licence-validation request, which Nuaj receives as a controller of its own licensing data rather than as anyone's processor. Where Nuaj is not a processor, the obligations below simply have nothing to attach to for that product — which is a stronger position for the Customer than this Agreement, not a weaker one.
Where the Customer is established in, or processes personal data of individuals in, the European Economic Area, the United Kingdom, or Switzerland, this DPA is the parties' agreement for the purposes of Article 28 of the General Data Protection Regulation. Where Canadian law applies, it is the parties' agreement for the purposes of the transfer and accountability requirements of Canadian federal and Quebec privacy legislation.
Where United States state privacy law applies to the Customer, Annex IV applies and is the parties' service-provider or processor agreement for the purposes of those laws. Annex IV is not an alternative to the terms below — it sits on top of them, and where it grants the Customer more than the body of this DPA does, Annex IV governs.
1. Definitions and Roles
"Customer Personal Data" means personal data contained in the configuration, reporting, and operational data the Customer submits to, or generates through, a Hosted Service operated by Nuaj.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR.
"Product", "Customer", "End Customer", and "Authorised User" have the meanings given in the Master Terms.
Roles, by product. The parties agree:
| Product | What reaches Nuaj | Nuaj's role |
|---|---|---|
| NuajProtect — hosted control plane | Configuration, reporting, and operational data from enrolled endpoints | Processor for the Customer. This DPA applies in full. |
| NuajProtect — self-hosted | Licensing, support, and billing data only; operational data stays on the Customer's systems | Independent Controller of that limited data; not a Processor of the operational data |
| NuajLens | Nothing. No licence key, no callback, no telemetry — see the Privacy Policy | Neither Processor nor sub-processor. Nuaj holds only the download-access request and the portal's server logs, as an independent Controller. |
| Nexaplane | A licence-validation request: installation identifier, licence or organization identifier, version, time, and source IP address | Independent Controller of that request, for licence administration. Not a Processor, and not a sub-processor in the Customer's tenant chain. |
Across all products:
- For account, billing, and security data Nuaj needs to operate its business — the identity of account holders, invoices, authentication and audit records — Nuaj is an independent Controller, and its own Privacy Policy governs. This DPA does not apply to that processing.
- For the Nuaj Threat Exchange (NuajProtect), Nuaj is an independent Controller of the technical indicators it receives. That processing rests on legitimate interests, is described in the Privacy Policy, and can be disabled by the Customer at any time.
A licence-validation request is a small payload, but it is not an empty one: a source IP address is personal data in some jurisdictions. It is enumerated above rather than described as "no personal data" for that reason.
1.1 Provider mode — where the Customer serves its own customers
Most Customers use a Product to deliver a service to third parties, and the Master Terms permit that by default. Where the Customer does so and Nuaj is a Processor — that is, for the NuajProtect hosted service — the chain has three tiers rather than two:
End Customer (Controller of its own data) → Customer (Processor for the End Customer, or Controller of its own service) → Nuaj (sub-processor).
In that arrangement:
- This DPA operates as the agreement between the Customer and Nuaj at the second link, and the obligations Nuaj owes the Customer here are the ones the Customer passes down to its End Customer.
- The Customer warrants that it has the authority to appoint Nuaj, and Nuaj's sub-processors, to process the End Customer's personal data, and that its own arrangement with the End Customer permits the processing the Product performs — including the traffic inspection that is the substance of the Product.
- The Customer's instructions are Nuaj's instructions. Nuaj acts on what the Customer configures and instructs, has no contractual relationship with the End Customer, and will not accept instructions directly from it.
- Where an End Customer's Data Subject makes a request, Nuaj directs it to the Customer, as section 7 provides. Nuaj does not undertake to identify which End Customer a given record belongs to; that mapping is the Customer's.
- The Customer remains responsible for its own notices, legal bases, and records of processing towards its End Customers. Nuaj's assistance obligations run to the Customer only.
For NuajLens and Nexaplane this section does not engage: Nuaj is outside the chain entirely, because nothing about the End Customer reaches it.
2. Scope and Instructions
Nuaj shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law to which Nuaj is subject — in which case Nuaj shall inform the Customer of that requirement before processing, unless the law prohibits it.
The Master Terms, the applicable End User License Agreement, this DPA, the configuration the Customer applies through the dashboard or API, and the Customer's use of the Hosted Service together constitute the Customer's complete documented instructions.
Nuaj shall inform the Customer if, in its opinion, an instruction infringes applicable data protection law. Nuaj may suspend performance of an instruction it reasonably believes to be unlawful until the Customer confirms, modifies, or withdraws it.
Nuaj shall not sell Customer Personal Data, and shall not use it for its own purposes, for advertising, or to train models offered to third parties.
3. Details of Processing
Article 28(3) requires the subject matter, duration, nature and purpose of the processing to be stated. They are stated per product, because they are not the same for any two of them, and a description that fitted every one of them would describe none of them accurately.
3.1 NuajProtect — hosted control plane
This is the only Product for which Nuaj is a Processor, and sections 3.2 onward describe it.
Subject matter. Provision of the NuajProtect Hosted Service — network threat filtering, policy enforcement, alerting, and reporting.
Duration. For the term of the Customer's subscription, plus the deletion period in section 9.
Nature and purpose. Collection, storage, organization, analysis, transmission, retrieval, and erasure, for the purpose of operating, securing, supporting, and reporting on the Customer's protected endpoints.
3.2 NuajLens
No processing by Nuaj. NuajLens performs its scanning, analysis, and reporting entirely on the Customer's own systems and transmits nothing to Nuaj. There is no subject matter, duration, or nature of processing to state, because Nuaj processes no personal data of the Customer's through it.
Nuaj processes, as an independent Controller and not under this DPA, the download-access request and the download portal's server logs, as described in the Privacy Policy.
3.3 Nexaplane
No processing by Nuaj on the Customer's behalf. Nexaplane transmits a licence-validation request and nothing else.
Subject matter of Nuaj's own processing, as an independent Controller: verification that an installation is licensed. Duration: the retention period stated in the Privacy Policy. Nature and purpose: receipt, storage, and comparison against Nuaj's licence records, for licence administration. Types of personal data: the installation identifier, the licence or organization identifier, the software version, the time of the request, and the source IP address. Categories of Data Subjects: the Customer's administrators, to the extent the identifiers or the source address relate to an identifiable person.
No personal data of the Customer's tenants is transmitted, so Nuaj does not enter that chain.
3.4 Types of Personal Data — NuajProtect hosted service
| Category | Examples |
|---|---|
| Account identifiers | Names, business email addresses, roles, organization |
| Authentication data | Password hashes, MFA enrolment, session records, sign-in times |
| Network identifiers | Source and destination IP addresses observed at protected endpoints, ports, protocols |
| Endpoint identity | The hostname of each protected endpoint, the addresses configured on its interfaces (including private addresses), and its public egress address |
| Operational records | Block and drop events, flood and alert events, device health, configuration state, audit entries |
| Support content | Whatever the Customer includes in a support request |
| Diagnostic captures | NuajProtect service log lines and kernel messages, retrieved from an endpoint on operator request while investigating a fault |
Nuaj does not collect packet payloads from protected endpoints, and does not collect the Customer's application, system, or security logs.
To investigate a fault, an authorized Nuaj operator may request a diagnostic capture from a protected endpoint. A capture is limited to NuajProtect's own service log and the kernel message buffer; it is requested deliberately rather than taken automatically, is capped in size, is retained only for the duration of the support interaction, and is not written to durable storage. Kernel messages may incidentally contain device and address identifiers.
Categories of Data Subjects. The Customer's personnel and Authorised Users; individuals whose IP addresses are observed by the Customer's protected endpoints, including the Customer's own network users and third parties who originate traffic toward them. Where the Customer deploys the Product for an End Customer, this extends to that End Customer's personnel and network users — see section 1.1.
Special categories. The Hosted Service is not designed for and must not be used to process special categories of personal data under GDPR Article 9, or personal data relating to criminal convictions and offences under Article 10. The Customer shall not submit such data.
4. Confidentiality
Nuaj shall ensure that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, are informed of the confidential nature of the data, and receive access only to the extent their duties require.
5. Security
Nuaj shall implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects.
Nuaj may update those measures over time provided the level of protection is not reduced.
6. Sub-processors
The Customer gives Nuaj general written authorization to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex III.
Nuaj shall inform the Customer of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. Where the Customer objects and the parties cannot agree a resolution within thirty (30) days, the Customer may terminate the affected subscription and receive a pro rata refund of prepaid fees for the remainder of the then-current period.
Nuaj shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
To receive sub-processor change notices, write to privacy@nuaj.com.
7. Data Subject Rights
Taking into account the nature of the processing, Nuaj shall assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights.
Where Nuaj receives a request directly from a Data Subject concerning Customer Personal Data, Nuaj shall not respond to it substantively but shall, without undue delay, direct the Data Subject to the Customer and inform the Customer of the request.
The dashboard and API allow the Customer to access, export, correct, and delete Customer Personal Data directly. Where those functions are sufficient, Nuaj's assistance obligation is met by their availability.
8. Personal Data Breach, Impact Assessments
Nuaj shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed.
Where all the required information is not available at once, Nuaj shall provide it in phases without further undue delay.
Nuaj shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Nuaj.
Notification of a breach is not an acknowledgment of fault or liability.
9. Deletion and Return
On termination of the Customer's subscription, the Customer may export Customer Personal Data from the dashboard for thirty (30) days, as set out in the Master Terms.
After that period Nuaj shall delete Customer Personal Data, except to the extent that storage is required by law to which Nuaj is subject. Where Nuaj retains data on that basis, it shall protect it in accordance with this DPA and process it only for the purpose requiring retention.
Backups are overwritten on their ordinary rotation cycle; data present only in backups is deleted on that cycle rather than on demand.
10. Audit
Nuaj shall make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR, including Annex II of this DPA and any third-party assessment or certification Nuaj holds.
Where that information is insufficient, Nuaj shall allow for and contribute to an audit, including an inspection, conducted by the Customer or an auditor it mandates, subject to: reasonable prior written notice of at least thirty (30) days; no more than once in any twelve-month period, except where required by a supervisory authority or following a Personal Data Breach; conduct during business hours and without unreasonable disruption; and appropriate confidentiality undertakings from the auditor. The Customer bears its own and the auditor's costs.
11. International Transfers
Customer Personal Data is stored in Canada. Certain sub-processors listed in Annex III process limited data outside Canada.
All Nuaj services are hosted in Canada unless otherwise indicated. Today there is one hosting region, Milton, Ontario. Where Nuaj operates a hosted service from an additional region, that region is named in Annex III and recorded on the affected Customer's order; it is introduced through the section 6 sub-processor process, with its thirty days' notice and right to object; and moving a Customer between regions is a material change notified in advance, preceded — where it would move personal data out of the EEA or out of Quebec — by a fresh transfer assessment. A Customer that requires its data to remain in a named region may have that recorded on its order, and Nuaj will honour it.
Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), with the Customer as data exporter and Nuaj as data importer. Annexes I, II, and III of this DPA populate the corresponding annexes of those Clauses. For the United Kingdom, the UK International Data Transfer Addendum applies. Where the Clauses conflict with this DPA, the Clauses prevail.
Canada has an adequacy decision from the European Commission in respect of commercial organizations subject to its federal privacy legislation.
Where a transfer of personal data outside Quebec is subject to Quebec's privacy legislation, Nuaj shall provide the Customer with the information the Customer reasonably requires to conduct its privacy impact assessment.
12. Liability and Precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Master Terms, except where applicable data protection law does not permit that limitation.
Where this DPA conflicts with the Master Terms, an End User License Agreement, or the Privacy Policy on a question of Nuaj's processing of Customer Personal Data as a Processor, this DPA prevails. On all other questions the order of precedence in the Master Terms applies.
13. Term
This DPA takes effect when the Customer accepts the Master Terms and continues for as long as Nuaj processes Customer Personal Data. Sections that by their nature should survive — confidentiality, deletion, liability, and precedence — survive its termination.
Annex I — Details of Processing
Data exporter: the Customer, as identified in its Nuaj account. Role: Controller — or Processor for its own End Customers, where section 1.1 applies, in which case Nuaj is a sub-processor and Module Three of the Standard Contractual Clauses applies in place of Module Two.
Data importer: Nuaj Company Inc., 8250 Lawson Rd., Suite 201, Milton, Ontario L9T 5C6, Canada. Contact: privacy@nuaj.com. Role: Processor.
Categories of Data Subjects, types of Personal Data, subject matter, nature, purpose, and duration: as set out in section 3 above, for the Product in use. Where the Product is NuajLens or Nexaplane, Nuaj is not a Processor and these Clauses do not engage.
Frequency of transfer: continuous, for the duration of the subscription.
Competent supervisory authority (for the Standard Contractual Clauses): the supervisory authority of the EEA Member State in which the data exporter is established or, where it is not established in the EEA, that of the Member State in which its EU representative is established or in which the Data Subjects are located.
Annex II — Technical and Organizational Measures
The measures below are those actually implemented. They may be improved but not weakened.
Access control. Role-based access control with least privilege. Administrative functions are restricted to designated roles. Access is scoped to a single tenant, and cross-tenant access is prevented at the data layer, not only in the interface.
Authentication. Passwords are stored as argon2id hashes and are never stored or transmitted in plaintext. Multi-factor authentication is available and supports authenticator apps (TOTP), passkeys/WebAuthn, SMS, and email codes. Sessions have idle and absolute expiry, are bound to a token hash, and can be revoked individually.
Encryption. All traffic between browsers, protected endpoints, and the Hosted Service is encrypted in transit using TLS. Communication with protected endpoints is additionally signed with per-device Ed25519 keys; private keys never leave the device. Manufacturing and provisioning secrets are encrypted at rest with authenticated encryption; on-device credential files are root-owned with restrictive permissions.
Integrity. Agent software distributed by Nuaj is cryptographically signed and verified before installation. Acceptance of legal agreements is recorded with a cryptographic hash of the exact text accepted.
Logging and monitoring. Administrative and security-relevant actions are written to an audit log recording actor, action, target, source IP, and time. Authentication attempts are rate limited by source address.
Segregation. Customer data is logically segregated by tenant. Development and production environments are separate.
Resilience. The Hosted Service runs from a facility in Milton, Ontario operated by Halton Data Center Inc., disclosed in Annex III. Protected endpoints continue to enforce the policy already deployed if they lose contact with the Hosted Service, so a control-plane outage does not remove protection.
Personnel. Access to production is limited to personnel who require it, under confidentiality obligations.
Sub-processor management. Sub-processors are engaged under written terms no less protective than this DPA, and are listed in Annex III.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Halton Data Center Inc. | Colocation and cloud infrastructure for the Hosted Service | Milton, Ontario, Canada |
| Stripe | Payment processing and billing | United States / Ireland |
| PayPal | Alternative payment processing | United States / Luxembourg |
| Google (Workspace) | Outbound email delivery for service messages | United States |
| VoIP.ms | SMS delivery for multi-factor authentication codes | Canada |
Affiliate disclosure. Halton Data Center Inc. is a separate legal person in which Nuaj Company Inc. holds a 70% interest, operating from the same address in Milton, Ontario. Nuaj states the relationship rather than listing the company without it, because a shared owner means this supplier is not commercially independent of Nuaj, and a Customer assessing supplier concentration is entitled to weigh that.
The corresponding advantage is that data residency, physical access, and the audit rights granted by this DPA reach a facility Nuaj controls, rather than depending on a third-party landlord's cooperation or surviving its sale.
All Customer Personal Data processed by the Hosted Service is held in Canada, at the facility named above. No hosting is sub-contracted to any party other than the one listed here, and any additional hosting region or provider is added to this Annex through the section 6 process before it is used.
NuajLens and Nexaplane have no sub-processors, because Nuaj processes nothing on the Customer's behalf through either of them. The providers listed above serve Nuaj's own account, billing, and communications functions across all products.
Annex IV — United States State Privacy Addendum
This Annex applies where the Customer is subject to a United States state privacy law, and only to personal information governed by that law. It is dormant for any Customer that is not. Where it applies, it prevails over the body of this DPA on any question arising under those laws.
Laws covered. The California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, and any other United States state privacy law imposing equivalent obligations on the parties (together, "US State Privacy Laws").
Roles. For personal information Nuaj processes on the Customer's behalf, the Customer is the Business or Controller and Nuaj is the Service Provider, Contractor, or Processor, as those terms are used in the applicable law. Terms used in this Annex and not defined in this DPA have the meaning given in the applicable US State Privacy Law. "Personal information" here has the meaning that law gives it.
IV.1 Nuaj's undertakings as a Service Provider or Processor
Nuaj shall:
- Process personal information only for the business purposes set out in section 3 of this DPA and on the Customer's documented instructions — the same instructions that govern under section 2.
- Not sell personal information, and not share it for cross-context behavioural advertising, as "sell" and "share" are defined in the CCPA. Nuaj does not do this for any Customer, under any product, and receives no consideration of any kind for personal information.
- Not retain, use, or disclose personal information for any purpose other than the business purposes specified, including for a commercial purpose other than those purposes, and not outside the direct business relationship between the parties.
- Not combine personal information received from or on behalf of the Customer with personal information it receives from another source, except as the applicable law expressly permits a service provider to do.
- Not use personal information to build or improve a profile of any consumer outside the Customer's own service, and not to develop, train, or improve any product offered to third parties. This restates section 2 and is repeated here because the CCPA requires it in terms.
- Comply with the obligations that the applicable law places on a service provider, contractor, or processor, and provide the same level of privacy protection the law requires of the Customer.
Nuaj certifies that it understands the restrictions in this Annex and will comply with them.
IV.2 Sensitive personal information
The products are not designed for, and must not be used to process, sensitive personal information as defined by the applicable law. Nuaj does not collect it, does not use it to infer characteristics about a consumer, and applies no further-use exceptions to it.
IV.3 Notification and remediation
Nuaj shall notify the Customer promptly, and in any event without undue delay, if it determines that it can no longer meet its obligations under an applicable US State Privacy Law.
The Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information by Nuaj. On the Customer's written notice of such a use, Nuaj shall cooperate to stop it and to remediate its effects.
IV.4 Monitoring compliance
The Customer may take reasonable and appropriate steps to confirm that Nuaj uses personal information in a manner consistent with the Customer's obligations under the applicable law. Section 10 of this DPA — the information Nuaj makes available, and the audit right and its conditions — is the mechanism, and satisfies the assessment and audit obligations of the Virginia, Colorado, Connecticut, and Texas statutes.
IV.5 Sub-processors and subcontractors
Every sub-processor Nuaj engages is bound by a written contract imposing obligations no less protective than this Annex, as section 6 requires. Section 6's thirty (30) days' advance notice, right to object, and termination with refund apply to a Customer under this Annex, and satisfy the sub-processor-objection requirements of the Colorado and Connecticut statutes.
IV.6 Consumer rights
Nuaj shall assist the Customer in responding to consumer requests to know, access, correct, delete, obtain a portable copy of, opt out of the sale or sharing of, and limit the use of personal information, as section 7 provides. Where a consumer contacts Nuaj directly about personal information Nuaj processes for the Customer, Nuaj shall direct the consumer to the Customer and inform the Customer of the request.
Where the Customer instructs deletion of a consumer's personal information, Nuaj shall delete it and shall notify its sub-processors to do the same, except where the law permits retention.
IV.7 Deidentified data
Where Nuaj creates deidentified or aggregate data from personal information, it shall take reasonable measures to ensure the data cannot be associated with a consumer or household, shall maintain and use it only in deidentified form, shall not attempt to reidentify it, and shall bind any recipient of it to the same restrictions.
IV.8 Security and breach
Section 5 (security, with Annex II) and section 8 (breach notification within seventy-two hours) apply to personal information governed by this Annex. They meet or exceed what the US State Privacy Laws require of a service provider or processor, and nothing in this Annex reduces them.
IV.9 Deletion and return
Section 9 applies. On termination, personal information is deleted after the export window except where the law requires retention.
IV.10 What this Annex does not do
It does not make Nuaj a Business or Controller of the Customer's personal information; Nuaj is a Business only in respect of its own account, billing, and security data, as section 1 states. It does not create obligations for Nuaj under a law to which the Customer is not subject. And it does not displace the GDPR terms in the body of this DPA for a Customer to whom both apply — where the two differ, whichever gives the individual more protection governs that question.