Where we handle personal data on your behalf — hosting your website, running your email platform, managing your CRM — you are the data controller and we are the processor. These terms set out what that means in practice.
1. Roles
You decide what personal data is collected and why. We process it only on your documented instructions, which for most engagements means the scope in the proposal plus reasonable operational necessity.
2. Scope of processing
Typical processing under our engagements covers:
- Website visitor and enquiry data held in systems we host or maintain.
- Customer records in a CRM or email platform we configure or manage.
- Order and transaction data in an e-commerce store we build or support.
3. Our obligations
As processor we commit to the following, and we will confirm any of it in writing for your own compliance records.
- Process personal data only on your instructions, and tell you if we believe an instruction is unlawful.
- Keep the data confidential and limit access to staff who need it.
- Apply appropriate technical and organisational security measures.
- Assist you in responding to data subject requests and regulator enquiries.
- Delete or return the data at the end of the engagement, at your choice.
4. Sub-processors
We use sub-processors such as hosting and email providers. We will name them on request and give you notice before adding a new one that handles your data, so you can object.
5. International transfers
Data may be processed on infrastructure outside your country. Where that happens we use providers offering appropriate safeguards. If your compliance position requires data residency in a specific region, tell us before the project starts — it is straightforward to accommodate upfront and disruptive to retrofit.
6. Breach notification
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours, with what we know and what we are doing about it.
7. Audit
On reasonable notice we will provide the information you need to demonstrate compliance, and cooperate with an audit where your regulator requires one.
Questions about this policy
If anything in this data processing agreement is unclear, email info@nexzasolutions.com or get in touch. We would rather explain it before you sign than argue about it afterwards.
Frequently Asked Questions
If we handle personal data on your behalf — hosting your site, running your email platform, managing your CRM — then yes, and most procurement teams will ask for one. We can sign it as a standalone agreement.
Questions About Our Data Processing Agreement?
If your legal or procurement team needs this signed as a standalone agreement, send it over with any changes marked. We will review and come back with what we can and cannot accept.