Nexos Data Processing Addendum

Version 2026-07-18

This Data Processing Addendum ("DPA") supplements the Nexos Terms of Service (or the separate written agreement governing the Customer's use of the Service — together, the "Agreement") between the customer identified in the applicable order form or account ("Customer") and LUKA BJELICA PR FIDERAIT ZRENJANIN, Pariske komune 28, 23000 Zrenjanin, Republic of Serbia, PIB 115208742 ("Nexos").

This DPA takes effect when it is incorporated into the Agreement by an order form, an Enterprise agreement, or another written or electronic agreement between Customer and Nexos that references it. It reflects the parties' agreement on the processing of Customer Personal Data.

1. Definitions

2. Roles and scope of processing

3. Shared responsibility — where data is processed

The Service schedules workloads onto compute nodes. What Nexos processes depends on how Customer configures its projects:

3.1 Private nodes (customer-operated hardware)

When a project is configured to run exclusively on private nodes — servers that Customer owns and operates — the following are processed on Customer's own hardware and never stored on Nexos infrastructure: source-code checkouts and git mirrors, build caches, built container images, running application containers, and application databases and their contents (including any personal data inside them). Customer is responsible for the physical security, disk handling, and disposal of that hardware.

3.2 What Nexos processes in every configuration

Even when all workloads run on private nodes, Nexos processes on its control plane:

3.3 Optional features that widen the scope

The following features are off unless Customer uses them, and each expands what Nexos stores or relays:

4. Confidentiality

Nexos ensures that persons it authorizes to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality.

5. Security

Nexos implements and maintains the technical and organizational measures described in Annex B. Nexos may update those measures from time to time, provided the updates do not materially reduce the overall security of the Service.

6. Subprocessors

7. Security Incident notification

Nexos will notify Customer of a Security Incident without undue delay, and in any case within 72 hours of becoming aware of it. The notification will describe, to the extent known: the nature of the incident, the categories and approximate volume of data and data subjects concerned, the likely consequences, and the measures taken or proposed. Nexos will provide timely updates as the investigation progresses. Notification is not an acknowledgement of fault or liability.

8. Assistance

9. Audits and reviews

10. Deletion and return

Upon termination of the Agreement, Nexos will delete Customer Personal Data within 30 days (and from backups within 90 days), unless retention is required by law. Before termination, Customer can export configuration and data through the Service. Data on Customer's private nodes is under Customer's own control at all times and is unaffected by this section.

11. International transfers

Nexos's control plane is hosted in the European Union (see Annex C) and Nexos is established in Serbia. Where a transfer of Customer Personal Data requires safeguards under Data Protection Laws, the parties rely on adequacy decisions where available or incorporate the European Commission's Standard Contractual Clauses (controller-to-processor, Module Two, or processor-to-processor, Module Three, as applicable) into this DPA by reference, with Customer as data exporter and Nexos as data importer; Serbia's standard contractual clauses under the ZZPL apply to transfers governed by Serbian law.

12. Liability and precedence

Annex A — Details of processing

Subject matterProvision of the Nexos preview-environment platform under the Agreement.
DurationThe term of the Agreement plus the deletion periods in Section 10.
Nature and purposeBuilding, deploying, running, and routing traffic to Customer's preview environments; storing configuration and deployment metadata; providing the dashboard and APIs.
Categories of data subjectsCustomer's personnel and contractors (account users); end users or other individuals whose personal data Customer includes in Customer Content (repositories, environment variables, databases, seeds, traffic).
Categories of personal dataAccount identifiers (names, usernames, email addresses); credentials and tokens supplied by Customer; any personal data Customer includes in Customer Content — determined solely by Customer. Customer should not submit special categories of data unless agreed in writing.

Annex B — Technical and organizational measures

Annex C — Subprocessors

SubprocessorPurposeLocation
Contabo GmbHCloud infrastructure hosting the Nexos control plane, database, and edgeGermany (EU)
Zoho Corporation (ZeptoMail)Transactional email delivery (verification, security notices)EU data center
GitHub, Inc.Source-code hosting, OAuth sign-in, and webhooks — engaged only through Customer's own connection of its GitHub account/repositoriesUnited States

Paddle.com Market Ltd (payments, merchant of record) processes payment data as an independent controller and is therefore not a Subprocessor; it is listed in the Privacy Policy for transparency.

Contact

LUKA BJELICA PR FIDERAIT ZRENJANIN
Pariske komune 28, 23000 Zrenjanin, Republic of Serbia
PIB: 115208742
legal@nexos.rs