Draft for review by counsel — not yet in effect.

Data Processing Addendum

This addendum forms part of the Terms of Service between No Hustle, Inc. (“Nymbrink”, the processor) and the business customer (the controller). It applies where Nymbrink processes personal data on the customer’s behalf, and is written to meet Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Subject matter

Providing the Nymbrink service: monitoring the public declarations of AI agents the customer chooses, recording what was observed, and alerting the customer and the people it names.

2. Duration

For as long as the customer has an account, and afterwards only for the deletion period in section 10.

3. Nature and purpose

Storage, retrieval, comparison and transmission of account data, only to provide the service and only on the customer’s documented instructions. The Terms, this addendum and the customer’s use of the service’s settings are those instructions. Nymbrink will tell the customer if it believes an instruction breaks data protection law. Nymbrink does not use customer data to train AI models.

4. Categories of data subjects and data

  • Data subjects: the customer’s team members, and people the customer names as alert recipients.
  • Personal data: names and email addresses; alert destinations; sign-in and activity records; notes and decisions that may name people.
  • Special categories: none are required, and the customer agrees not to enter them.

5. Confidentiality

Everyone at Nymbrink who can access customer data is bound by confidentiality. A customer’s lists, rules and decisions are never visible to any other customer.

6. Subprocessors

The customer authorises the subprocessors listed on the subprocessors page. Nymbrink will give at least 30 days’ notice before adding or replacing one, by email and on that page. The customer may object on reasonable data protection grounds; if the parties cannot resolve it, the customer may end the affected service and receive a refund of prepaid fees for the unused period. Nymbrink binds each subprocessor to data protection terms no less protective than these and remains responsible for it.

7. Security

Nymbrink maintains the technical and organisational measures described on the security page, including encryption in transit, row-level access control on every table, EU hosting, and a signing key held outside the application database. Nymbrink may improve these measures but will not reduce the overall level of protection.

8. Assistance and audits

Nymbrink will help the customer answer data subjects’ requests and carry out impact assessments, as far as the service allows. It will make available the information needed to show compliance with this addendum and, once a year or after a personal data breach, allow an audit by the customer or an independent auditor it appoints, on 30 days’ notice, during business hours, under confidentiality, and at the customer’s cost. Nymbrink may first offer written answers or third-party reports where these cover the question.

9. Personal data breaches

Nymbrink will notify the customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the customer’s data. The notice will say what happened, the data and people likely affected, the likely consequences, and what Nymbrink is doing about it, adding details as they become known.

10. Deletion on termination

When the account ends, the customer may export its data. Nymbrink then deletes the customer’s personal data within 30 days, including from backups when they expire, unless the law requires it to keep some. Signed stamps already issued about public passports are not customer personal data and remain valid records.

11. International transfers

Customer data is stored in the EU. Where a subprocessor in the United States receives personal data (currently for email delivery), or Nymbrink accesses data from the United States, the transfer is covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914, Module 2 controller-to-processor and Module 3 processor-to-processor as applicable), with the UK Addendum for UK data, or by the EU-US Data Privacy Framework where the recipient is certified. The Standard Contractual Clauses are incorporated into this addendum by reference.

12. Order of precedence

If this addendum conflicts with the Terms, this addendum wins on data protection. If it conflicts with the Standard Contractual Clauses, the Clauses win.

Contact

privacy@nymbrink.com for data protection; legal@nymbrink.com for a countersigned copy.