v1.0.0 · Effective July 8, 2026

Data Processing Addendum

Incorporated into the Terms of Service. Governs our processing of personal data contained in Customer Content on your behalf, worldwide.

You are the controller. We are the processor.

GDPR Article 28 terms, the EU Standard Contractual Clauses, and the UK Addendum are incorporated here by reference. Under the CCPA we are a service provider and never a seller.

1. Roles and scope

For personal data in Customer Content, Customer is the controller (or a processor acting for a third-party controller) and we are the processor. Under the CCPA/CPRA, Customer is the business and we are a service provider. We process such data only on Customer's documented instructions, which include the Terms and Customer's configuration and use of the Service.

We will inform Customer if, in our opinion, an instruction infringes the GDPR, UK GDPR, or other applicable data-protection law, and may suspend performance of that instruction.

Subject matter: provision of the Service. Duration: the term of the Terms plus the retention periods in the Privacy Policy. Nature and purpose: hosting, storage, analysis, and transmission to provide the Service. Types of personal data: business contact details and any personal data Customer chooses to include in Customer Content. Categories of data subjects: Customer's personnel and any individuals referenced in Customer Content.

1a. GDPR Article 28 processor commitments

  • We process personal data only on documented instructions, including for international transfers, unless required otherwise by law - in which case we notify Customer first unless the law prohibits it.
  • We ensure that persons authorised to process personal data are bound by confidentiality obligations.
  • We implement the technical and organisational measures required by Art. 32, described on our Security page.
  • We engage subprocessors only under Art. 28(2) and (4), with 30 days' prior notice and a right to object.
  • We assist Customer, by appropriate measures, in fulfilling its obligation to respond to data subject rights requests under Chapter III.
  • We assist Customer with Art. 32-36 obligations: security, breach notification, data protection impact assessments, and prior consultation.
  • At Customer's election we delete or return all personal data at the end of the Service, and delete existing copies unless law requires storage.
  • We make available all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. Audits occur once per twelve months, on 30 days' notice, during business hours, subject to confidentiality, and at Customer's cost - except where an audit reveals our material non-compliance, in which case we bear the cost.

1b. International transfers and the Standard Contractual Clauses

  • The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated by reference and apply to transfers of personal data from the EEA to us in the United States. Module Two applies where Customer is a controller; Module Three applies where Customer is itself a processor.
  • For the purposes of the SCCs: Clause 7 (docking) applies; Clause 9(a) option 2 (general written authorisation) applies with a 30-day notice period; Clause 11(a) optional redress language does not apply; Clause 17 is governed by the law of Ireland; Clause 18(b) designates the courts of Ireland. Annex I is the description in section 1; Annex II is our Security page; Annex III is our Subprocessors page.
  • For transfers from the United Kingdom, the UK International Data Transfer Addendum (version B1.0) is incorporated, with Tables 1-3 completed by reference to the above and Table 4 selecting neither party as able to end the Addendum on changes.
  • For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the FADP, and with the Swiss FDPIC as competent supervisory authority.
  • We will challenge any legally-binding request for disclosure from a public authority that appears unlawful under the law of the exporting jurisdiction, and will inform Customer unless legally prohibited.

2. Service provider commitments (CCPA/CPRA § 1798.140)

  • We will not sell or share personal information.
  • We will not retain, use, or disclose personal information for any purpose other than performing the Service, or as otherwise permitted by law.
  • We will not retain, use, or disclose personal information outside the direct business relationship with Customer.
  • We will not combine personal information received from Customer with information received from another source, except as permitted to perform a business purpose.
  • We will notify Customer if we determine we can no longer meet these obligations.
  • We grant Customer the right to take reasonable steps to stop and remediate unauthorized use.

3. Confidentiality, security, and assistance

  • Personnel with access are bound by confidentiality obligations.
  • We maintain the security measures described on the Security page.
  • We assist Customer, taking into account the nature of processing, in responding to consumer rights requests.
  • We make available information reasonably necessary to demonstrate compliance.

4. Breach notification

We notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on Customer's behalf. Our notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

We provide the information reasonably available to us so that Customer can meet its own deadlines, including the 72-hour supervisory-authority deadline under GDPR Art. 33 and the equivalent under UK GDPR, the LGPD, the APPI, and the Australian Notifiable Data Breaches scheme. We do not notify Customer's supervisory authority or data subjects on Customer's behalf unless instructed.

5. Deletion and return

On termination, and at Customer's election, we delete or return personal information in Customer Content within the periods stated in the Privacy Policy, except where retention is required by law.

6. Subprocessors

Customer gives a general written authorisation for our use of the subprocessors we publish, under GDPR Art. 28(4). We give 30 days' notice before adding or replacing one. Customer may object on reasonable data-protection grounds; if we cannot accommodate the objection, Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid, unused fees.

We impose on each subprocessor the same data-protection obligations set out in this Addendum, and we remain fully liable to Customer for each subprocessor's performance.

7. Order of precedence and term

In the event of conflict, the Standard Contractual Clauses prevail over this Addendum, this Addendum prevails over the Terms, and the Terms prevail over any other document. This Addendum takes effect when Customer accepts the Terms and continues for as long as we process personal data on Customer's behalf.

Customer may request a countersigned copy of this Addendum and the SCCs, with Annexes completed, by writing to info@dssadvisorygroup.com.

Related

Other policies

Version history

What changed, and when

v1.0.0 · July 8, 2026 - First published version. Replaces the prior placeholder pages. Adds worldwide privacy rights, international transfer mechanisms, a data processing addendum, a published subprocessor list, and a commitment never to train models on Customer Content.

Contact

Questions about this policy?

DeSouza Strategic Systems LLC d/b/a DSS Advisory Group. Privacy: info@dssadvisorygroup.com. Legal: info@dssadvisorygroup.com. Security: info@dssadvisorygroup.com. Last updated July 8, 2026.

Data Processing Addendum | DSS Nexus