This Data Processing Agreement governs Nuaj's processing of personal data on behalf of the Customer. It is incorporated into the Terms of Service and applies automatically, without signature, whenever and to the extent that Nuaj acts as a processor for the Customer. A countersigned copy is available on request from legal@nuaj.com.
Where the Customer is established in, or processes personal data of individuals in, the European Economic Area, the United Kingdom, or Switzerland, this DPA is the parties' agreement for the purposes of Article 28 of the General Data Protection Regulation. Where Canadian law applies, it is the parties' agreement for the purposes of the transfer and accountability requirements of Canadian federal and Quebec privacy legislation.
1. Definitions and Roles
"Customer Personal Data" means personal data contained in the configuration, reporting, and operational data the Customer submits to, or generates through, the Hosted Service.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR.
Capitalized terms not defined here have the meaning given in the End User License Agreement.
Roles. The parties agree:
- For Customer Personal Data in the Hosted Service, the Customer is the Controller and Nuaj is the Processor.
- For account, billing, and security data Nuaj needs to operate its business — the identity of account holders, invoices, authentication and audit records — Nuaj is an independent Controller, and its own Privacy Policy governs. This DPA does not apply to that processing.
- For the Nuaj Threat Exchange, Nuaj is an independent Controller of the technical indicators it receives. That processing rests on legitimate interests, is described in the Privacy Policy, and can be disabled by the Customer at any time.
- For a self-hosted deployment, operational data never reaches Nuaj. The Customer is the Controller of it and Nuaj is not a Processor of it.
2. Scope and Instructions
Nuaj shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law to which Nuaj is subject — in which case Nuaj shall inform the Customer of that requirement before processing, unless the law prohibits it.
The Terms of Service, this DPA, the configuration the Customer applies through the dashboard or API, and the Customer's use of the Hosted Service together constitute the Customer's complete documented instructions.
Nuaj shall inform the Customer if, in its opinion, an instruction infringes applicable data protection law. Nuaj may suspend performance of an instruction it reasonably believes to be unlawful until the Customer confirms, modifies, or withdraws it.
Nuaj shall not sell Customer Personal Data, and shall not use it for its own purposes, for advertising, or to train models offered to third parties.
3. Details of Processing
Subject matter. Provision of the NuajProtect Hosted Service — network threat filtering, policy enforcement, alerting, and reporting.
Duration. For the term of the Customer's subscription, plus the deletion period in section 9.
Nature and purpose. Collection, storage, organization, analysis, transmission, retrieval, and erasure, for the purpose of operating, securing, supporting, and reporting on the Customer's protected endpoints.
Types of Personal Data.
| Category | Examples |
|---|---|
| Account identifiers | Names, business email addresses, roles, organization |
| Authentication data | Password hashes, MFA enrolment, session records, sign-in times |
| Network identifiers | Source and destination IP addresses observed at protected endpoints, ports, protocols |
| Endpoint identity | The hostname of each protected endpoint, the addresses configured on its interfaces (including private addresses), and its public egress address |
| Operational records | Block and drop events, flood and alert events, device health, configuration state, audit entries |
| Support content | Whatever the Customer includes in a support request |
| Diagnostic captures | NuajProtect service log lines and kernel messages, retrieved from an endpoint on operator request while investigating a fault |
Nuaj does not collect packet payloads from protected endpoints, and does not collect the Customer's application, system, or security logs.
To investigate a fault, an authorized Nuaj operator may request a diagnostic capture from a protected endpoint. A capture is limited to NuajProtect's own service log and the kernel message buffer; it is requested deliberately rather than taken automatically, is capped in size, is retained only for the duration of the support interaction, and is not written to durable storage. Kernel messages may incidentally contain device and address identifiers.
Categories of Data Subjects. The Customer's personnel and authorized users; individuals whose IP addresses are observed by the Customer's protected endpoints, including the Customer's own network users and third parties who originate traffic toward them.
Special categories. The Hosted Service is not designed for and must not be used to process special categories of personal data under GDPR Article 9, or personal data relating to criminal convictions and offences under Article 10. The Customer shall not submit such data.
4. Confidentiality
Nuaj shall ensure that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, are informed of the confidential nature of the data, and receive access only to the extent their duties require.
5. Security
Nuaj shall implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects.
Nuaj may update those measures over time provided the level of protection is not reduced.
6. Sub-processors
The Customer gives Nuaj general written authorization to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex III.
Nuaj shall inform the Customer of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. Where the Customer objects and the parties cannot agree a resolution within thirty (30) days, the Customer may terminate the affected subscription and receive a pro rata refund of prepaid fees for the remainder of the then-current period.
Nuaj shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
To receive sub-processor change notices, write to privacy@nuaj.com.
7. Data Subject Rights
Taking into account the nature of the processing, Nuaj shall assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights.
Where Nuaj receives a request directly from a Data Subject concerning Customer Personal Data, Nuaj shall not respond to it substantively but shall, without undue delay, direct the Data Subject to the Customer and inform the Customer of the request.
The dashboard and API allow the Customer to access, export, correct, and delete Customer Personal Data directly. Where those functions are sufficient, Nuaj's assistance obligation is met by their availability.
8. Personal Data Breach, Impact Assessments
Nuaj shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed.
Where all the required information is not available at once, Nuaj shall provide it in phases without further undue delay.
Nuaj shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Nuaj.
Notification of a breach is not an acknowledgment of fault or liability.
9. Deletion and Return
On termination of the Customer's subscription, the Customer may export Customer Personal Data from the dashboard for thirty (30) days, as set out in the Terms of Service.
After that period Nuaj shall delete Customer Personal Data, except to the extent that storage is required by law to which Nuaj is subject. Where Nuaj retains data on that basis, it shall protect it in accordance with this DPA and process it only for the purpose requiring retention.
Backups are overwritten on their ordinary rotation cycle; data present only in backups is deleted on that cycle rather than on demand.
10. Audit
Nuaj shall make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR, including Annex II of this DPA and any third-party assessment or certification Nuaj holds.
Where that information is insufficient, Nuaj shall allow for and contribute to an audit, including an inspection, conducted by the Customer or an auditor it mandates, subject to: reasonable prior written notice of at least thirty (30) days; no more than once in any twelve-month period, except where required by a supervisory authority or following a Personal Data Breach; conduct during business hours and without unreasonable disruption; and appropriate confidentiality undertakings from the auditor. The Customer bears its own and the auditor's costs.
11. International Transfers
Customer Personal Data is stored in Canada. Certain sub-processors listed in Annex III process limited data outside Canada.
Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor), with the Customer as data exporter and Nuaj as data importer. Annexes I, II, and III of this DPA populate the corresponding annexes of those Clauses. For the United Kingdom, the UK International Data Transfer Addendum applies. Where the Clauses conflict with this DPA, the Clauses prevail.
Canada has an adequacy decision from the European Commission in respect of commercial organizations subject to its federal privacy legislation.
Where a transfer of personal data outside Quebec is subject to Quebec's privacy legislation, Nuaj shall provide the Customer with the information the Customer reasonably requires to conduct its privacy impact assessment.
12. Liability and Precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the End User License Agreement, except where applicable data protection law does not permit that limitation.
Where this DPA conflicts with the End User License Agreement, the Terms of Service, or the Privacy Policy on a question of Nuaj's processing of Customer Personal Data as a Processor, this DPA prevails. On all other questions the order of precedence in the End User License Agreement applies.
13. Term
This DPA takes effect when the Customer accepts the Terms of Service and continues for as long as Nuaj processes Customer Personal Data. Sections that by their nature should survive — confidentiality, deletion, liability, and precedence — survive its termination.
Annex I — Details of Processing
Data exporter: the Customer, as identified in its NuajProtect account. Role: Controller.
Data importer: Nuaj Company Inc., 8250 Lawson Rd., Suite 201, Milton, Ontario L9T 5C6, Canada. Contact: privacy@nuaj.com. Role: Processor.
Categories of Data Subjects, types of Personal Data, subject matter, nature, purpose, and duration: as set out in section 3 above.
Frequency of transfer: continuous, for the duration of the subscription.
Competent supervisory authority (for the Standard Contractual Clauses): the supervisory authority of the EEA Member State in which the data exporter is established or, where it is not established in the EEA, that of the Member State in which its EU representative is established or in which the Data Subjects are located.
Annex II — Technical and Organizational Measures
The measures below are those actually implemented. They may be improved but not weakened.
Access control. Role-based access control with least privilege. Administrative functions are restricted to designated roles. Access is scoped to a single tenant, and cross-tenant access is prevented at the data layer, not only in the interface.
Authentication. Passwords are stored as argon2id hashes and are never stored or transmitted in plaintext. Multi-factor authentication is available and supports authenticator apps (TOTP), passkeys/WebAuthn, SMS, and email codes. Sessions have idle and absolute expiry, are bound to a token hash, and can be revoked individually.
Encryption. All traffic between browsers, protected endpoints, and the Hosted Service is encrypted in transit using TLS. Communication with protected endpoints is additionally signed with per-device Ed25519 keys; private keys never leave the device. Manufacturing and provisioning secrets are encrypted at rest with authenticated encryption; on-device credential files are root-owned with restrictive permissions.
Integrity. Agent software distributed by Nuaj is cryptographically signed and verified before installation. Acceptance of legal agreements is recorded with a cryptographic hash of the exact text accepted.
Logging and monitoring. Administrative and security-relevant actions are written to an audit log recording actor, action, target, source IP, and time. Authentication attempts are rate limited by source address.
Segregation. Customer data is logically segregated by tenant. Development and production environments are separate.
Resilience. The Hosted Service runs from a facility in Milton, Ontario operated by Halton Data Center Inc., disclosed in Annex III. Protected endpoints continue to enforce the policy already deployed if they lose contact with the Hosted Service, so a control-plane outage does not remove protection.
Personnel. Access to production is limited to personnel who require it, under confidentiality obligations.
Sub-processor management. Sub-processors are engaged under written terms no less protective than this DPA, and are listed in Annex III.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Halton Data Center Inc. | Colocation and cloud infrastructure for the Hosted Service | Milton, Ontario, Canada |
| Stripe | Payment processing and billing | United States / Ireland |
| PayPal | Alternative payment processing | United States / Luxembourg |
| Google (Workspace) | Outbound email delivery for service messages | United States |
| VoIP.ms | SMS delivery for multi-factor authentication codes | Canada |
Affiliate disclosure. Halton Data Center Inc. is a separate legal person in which Nuaj Company Inc. holds a 70% interest, operating from the same address in Milton, Ontario. Nuaj states the relationship rather than listing the company without it, because a shared owner means this supplier is not commercially independent of Nuaj, and a Customer assessing supplier concentration is entitled to weigh that.
The corresponding advantage is that data residency, physical access, and the audit rights granted by this DPA reach a facility Nuaj controls, rather than depending on a third-party landlord's cooperation or surviving its sale.
All Customer Personal Data processed by the Hosted Service is held in Canada. No other hosting is sub-contracted.