This Data Processing Addendum ("Addendum") forms part of Agreement field: customer agreement reference ("Agreement") between nith Studio LLC, registered in Wisconsin, United States ("nith"), and Agreement field: customer legal name ("Customer"). It takes effect on To be confirmed: dpa effective date when accepted by both parties through To be confirmed: dpa acceptance method.
1. Scope definitions and roles
"Applicable Privacy Law" means privacy or data-protection law that actually applies to a party's processing under this Addendum. "Customer Personal Data" means personal information that nith processes on Customer's behalf through the services identified in Schedule 1. "Personal Data Breach" means a security breach involving accidental or unlawful loss, destruction, alteration, unauthorized disclosure of, or access to Customer Personal Data. "Subprocessor" means another processor engaged by nith for that processing. Other terms take their meaning from Applicable Privacy Law or the Agreement.
Customer determines the purposes of processing Customer Personal Data. nith acts as its processor or service provider. Where Customer is itself a processor for a client or other controller, nith acts as a subprocessor, and Customer must have authority to appoint and instruct nith. The parties' roles follow their actual activities and cannot be changed solely by a label in this Addendum.
This Addendum does not govern personal information nith processes as an independent controller for its own account administration, direct customer billing, legal obligations, security, and other specifically identified purposes in the Privacy Policy. That exclusion does not authorize nith to repurpose Customer Personal Data or treat all security, analytics, AI usage, or financial records as controller data. Schedule 1 records the allocation for those activities.
2. Instructions and permitted processing
Customer instructs nith to provide the selected services described in Schedule 1, operate the features Customer or its authorized users activate, and follow additional documented instructions agreed through To be confirmed: dpa instruction channel. Instructions include lawful configuration choices, publication, authorized recipients, and requests to correct, export, restrict, or remove data.
nith will process Customer Personal Data within those instructions. If law requires different processing, nith will notify Customer before carrying it out unless the law prohibits notice. nith will notify Customer if it believes an instruction violates Applicable Privacy Law and may suspend the affected processing while the parties resolve it. An instruction to use an unsupported service or materially change the agreed processing requires a separate agreement; this qualification does not diminish a mandatory legal duty.
nith will not use Customer Personal Data for unrelated advertising or independently train a general-purpose model on it under this Addendum. Customer does not authorize additional model-training uses by accepting a general reference to AI functionality.
Customer-selected publication, email recipients, webhooks, integrations, and external embeds are instructions to disclose information to those destinations only within the authorized feature. Customer is responsible for its selection and lawful use of those recipients. nith remains responsible for its own obligations when transmitting information or engaging its own Subprocessors.
3. Customer responsibilities
Customer is responsible for having a lawful basis and authority for the information and instructions it provides, making required notices available, obtaining required permissions, and respecting individuals' rights. It must limit submissions to data appropriate for the selected services, manage access for its users and agency relationships, and promptly tell nith about an instruction or circumstance requiring a change in processing.
Customer must not submit prohibited regulated or sensitive data unless a separate written agreement expressly authorizes the use and specifies the required safeguards. This Addendum is not a HIPAA business associate agreement. Unanticipated sensitive data in free text remains subject to applicable law and must be addressed through the incident, restriction, and deletion processes; a prohibition does not eliminate the parties' duties for data actually received.
4. Confidentiality and access
nith will limit authorized personnel's access to Customer Personal Data to their assigned service, support, security, or legal tasks and will ensure those personnel are bound by appropriate confidentiality duties. nith will maintain access controls and the administrative practices specified in Schedule 2. Customer may authorize support access through To be confirmed: support access authorization method; emergency or legally required access and its documentation are governed by To be confirmed: exceptional access procedure.
5. Security and changes
nith will maintain the agreed technical and organizational measures in Schedule 2, assessed against the nature and risks of the processing. The schedule must distinguish application controls, provider controls, and customer responsibilities. nith may update the measures provided the overall agreed protection is not materially reduced without an agreed amendment and any required notice.
No certification, particular encryption method, data residency, uptime, restoration time, or security assessment is promised unless expressly specified in a completed schedule or the Agreement.
6. Subprocessors
Customer gives To be confirmed: subprocessor authorization type authorization for the Subprocessors listed in the completed Schedule 3. Where general authorization is selected, nith will give notice of a proposed addition or replacement through To be confirmed: subprocessor notice method at least To be confirmed: subprocessor notice period before the new recipient processes Customer Personal Data. Customer may object on reasonable data-protection grounds within To be confirmed: subprocessor objection period.
The parties will work to address a timely objection by restricting the affected processing, using an appropriate alternative, or implementing agreed safeguards. If no solution is available, the affected services may be terminated under To be confirmed: subprocessor termination and prepaid fee treatment. The procedure must provide a meaningful opportunity to object before the new processing begins; posting an updated list alone is not deemed notice unless the agreed mechanism lawfully provides that notice.
nith will impose relevant written data-protection obligations on each Subprocessor, including appropriate confidentiality, security, use restrictions, assistance, and deletion obligations. nith remains responsible for its Subprocessors' performance to the extent required by Applicable Privacy Law and this Addendum.
7. Requests assistance and records
nith will notify Customer of a request concerning Customer Personal Data from an individual or regulator, unless prohibited, and will direct the individual to Customer or act on Customer's documented instructions as appropriate. nith will not independently decide the outcome of Customer's rights request except as law requires.
Taking account of the processing and information available to it, nith will assist Customer with access, correction, restriction, deletion, portability, and other applicable rights; security and breach obligations; and required impact assessments and regulator consultations. The parties will use To be confirmed: privacy operations channel and cooperate in time to meet applicable deadlines.
Any charges for exceptional assistance must be agreed in advance under To be confirmed: dpa assistance fee rule, subject to Applicable Privacy Law. Charges, scheduling, and technical limitations must not defeat a mandatory duty or a protected right. Routine self-service functions, if any, do not replace assistance required for data those functions cannot reach.
8. Personal Data Breaches
nith will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, using the incident contact in Schedule 1. Any additional contractual initial-notice target is To be confirmed: optional incident notice target.
The notification will include available information needed to understand the incident, such as its nature, affected data and people where known, likely consequences, steps taken or planned, and a contact for follow-up. nith may provide information in stages as the investigation develops and will cooperate with Customer's response and required notifications. nith will take appropriate containment and remediation measures and preserve relevant evidence.
An unsuccessful attempt that does not compromise Customer Personal Data is not automatically a Personal Data Breach, but any separate legal or contractual reporting duty still applies. Notice is not an admission of fault. Customer generally decides notifications concerning its own processing, without restricting nith's independent legal duties or the parties' duty to coordinate accurate communications.
9. Return deletion and retention
At the end of the relevant services, or on an authorized instruction, Customer may elect return or deletion of Customer Personal Data under Schedule 4. The schedule specifies export format and access, active-system deletion, backups and provider copies, time periods, exceptions, and evidence of completion.
If law requires nith to retain specified information, nith will identify the applicable category and reason to Customer unless prohibited and limit further use to that purpose. Any retention as an independent controller must be separately justified and disclosed; an internal label such as "financial" or "audit" is not, by itself, a lawful basis for indefinite retention.
Copies awaiting permitted backup expiry remain protected and are not used for ordinary business processing. If a backup is restored, applicable deletion instructions must be reapplied. Customer-directed publication or delivery to independent recipients can require Customer to seek removal from those recipients; nith will assist where required and within its control.
10. Information audits and inspections
nith will make information reasonably necessary to assess its compliance with this Addendum available to Customer, including agreed descriptions of controls and relevant assessment results. Where required, nith will permit and contribute to audits or inspections by Customer, its qualified independent auditor, or the competent authority.
The parties may agree reasonable notice, confidentiality, scope, timing, and safeguards for other customers' information. To be confirmed: audit cost allocation. No frequency limit, report substitution, confidentiality term, or fee will prevent an audit or disclosure that Applicable Privacy Law requires, including following a material incident or credible compliance concern.
11. International transfers
nith will process Customer Personal Data only in the locations and under the transfer arrangements recorded in Schedule 3 and Schedule 5, including remote access locations where relevant. It will not begin a restricted transfer until the required mechanism is completed and applicable safeguards are in place.
Where required, the parties will execute the appropriate official transfer clauses or other valid instrument and complete their annexes. An applicable transfer instrument prevails over inconsistent terms in this Addendum or the Agreement. A general promise to use safeguards, a provider's published DPA, or a United States business address does not itself complete a transfer mechanism for this relationship.
12. Applicable United States processor terms
This section applies only to Customer Personal Data covered by a US privacy law requiring these processor, service-provider, or contractor restrictions. nith will not sell that information or share it for cross-context behavioral advertising; will use and disclose it only for the specified business purposes and permitted instructions; and will not combine it with information from other customers or its own direct interactions except as the applicable law permits.
nith will provide the level of protection required for its role, notify Customer if it can no longer meet those obligations, and allow Customer to take appropriate steps to verify compliance and stop or remediate unauthorized use. nith understands and will comply with these restrictions and will flow applicable requirements to authorized Subprocessors. This clause does not make nith a covered business under a law whose applicability criteria it does not meet.
13. Priority and general terms
This Addendum controls for a conflict concerning Customer Personal Data; a mandatory transfer instrument or Applicable Privacy Law controls over both. Commercial liability, remedies, and governing law remain subject to To be confirmed: dpa liability and priority rule in the Agreement, without limiting rights that cannot lawfully be limited. The parties may not use a liability cap or contractual instruction to override a mandatory transfer-clause remedy or statutory duty.
The obligations concerning protected retained data survive termination for as long as that data remains held. Amendments require To be confirmed: dpa amendment method and cannot be made effective merely by changing a provider list contrary to section 6.
Schedule 1 Processing description and contacts
| Item | Processing details |
|---|---|
| Customer and role | Agreement field: customer legal name, Agreement field: customer address, acting as Agreement field: customer controller or processor role for To be confirmed: represented controllers if applicable. |
| nith contact | nith Studio LLC, To be confirmed: registered address; privacy To be confirmed: privacy contact; incident To be confirmed: security contact. |
| Customer contacts | Authorized instruction contact Agreement field: customer instruction contact; incident contact Agreement field: customer incident contact; rights contact Agreement field: customer privacy contact. |
| Subject and duration | Hosting and operating the selected nith sites and workspaces during To be confirmed: service term plus the agreed return/deletion period in Schedule 4. |
| Operations | Receipt, storage, organization, retrieval, display, publication when instructed, access control, transmission to authorized recipients, generation/evaluation when enabled, and deletion or return. |
| Individuals | Customer's users and staff, site visitors, enquirers, buyers, clients, contract signers, and other people lawfully included in submitted content, to the extent involved in the selected services. |
| Ordinary data | Contact details, account/member references, submitted content and media, enquiries, bookings, orders, invoices, signatures and signing evidence, and technical/usage information needed for the selected functions. |
| Sensitive data | Not authorized by default. Any separately permitted category, purpose, legal condition, and enhanced safeguards: To be confirmed: authorized sensitive data schedule. Unexpected disclosures are addressed under To be confirmed: unexpected sensitive data procedure. |
| AI instructions | To be confirmed: authorized ai features and context; To be confirmed: automatic screening instructions; To be confirmed: authorized ai recipients. |
| Analytics allocation | To be confirmed: analytics purposes roles and configuration. |
| Independent purposes | To be confirmed: nith controller purposes and data boundaries. |
| Frequency | Continuing as the selected services are used, with specific events such as submission, publication, upload, email delivery, and requested AI tasks. |
Schedule 2 Technical and organizational measures
The agreed measures are incorporated as To be confirmed: approved security schedule reference. That schedule sets out the parties' arrangements for authentication and staff access, tenant separation, transmission and storage protection, key management, vulnerability handling, logging and monitoring, incident response, personnel training and confidentiality, vendor review, backups and restoration, deletion, and periodic review.
Customer responsibilities include managing its authorized users, lawful data collection, selected integrations, publication settings, and endpoints it controls. Customer responsibilities do not displace nith's own security obligations.
Schedule 3 Authorized recipients and locations
The authorized recipients, services, purposes, roles, locations, and transfer arrangements are set out in the customer-specific version of the provider schedule, dated To be confirmed: subprocessor schedule version, incorporated into this Addendum.
Schedule 4 Return and deletion
| Item | Agreed arrangement |
|---|---|
| Data covered | Customer Personal Data, including applicable AI conversations and files, analytics, email records, contracts, bookings, media, and related records. |
| Return | To be confirmed: export format and method; To be confirmed: export availability period. |
| Active-system removal | To be confirmed: active system deletion period. |
| Backups | To be confirmed: backup expiry and restore procedure. |
| Provider copies | To be confirmed: provider deletion process. |
| Lawful retention | To be confirmed: lawful retention exceptions and durations. |
| Requests outside self-service controls | To be confirmed: manual deletion request process. |
| Completion evidence | To be confirmed: deletion confirmation method. |
Schedule 5 Regional terms and transfers
Applicable regional terms: To be confirmed: applicable regional terms.
Transfer mechanism: To be confirmed: transfer mechanism selection.
Official transfer instrument and annexes: To be confirmed: completed transfer instrument and annexes.
Applicable modules and role allocation: To be confirmed: transfer modules and roles.
Governing law, forum, and supervisory authority for that instrument: To be confirmed: transfer law forum and authority.
Supplementary measures and applicable assessment: To be confirmed: transfer assessment and measures.
UK or Swiss provisions where applicable: To be confirmed: uk and swiss transfer provisions.
Acceptance for Customer: Agreement field: customer authorized signatory and date
Acceptance for nith: To be confirmed: nith authorized signatory and date