1. Parties and scope
This DPA is entered into between Nexari B.V. ("Processor", "we") and the Customer ("Controller", "you"). It applies whenever we process personal data on your behalf as part of the FoundIn.ai service and forms part of our Terms of Service. Capitalised terms not defined here have the meaning in the GDPR.
2. Subject matter, duration, nature, and purpose
- Subject matter: personal data submitted to or generated by the service.
- Duration: for the term of your subscription, plus retention periods in the Privacy Policy.
- Nature and purpose: providing the FoundIn.ai SaaS — AI-visibility monitoring, reporting, and related features.
- Categories of data subjects: Customer's authorised users, contacts entered into the product, and individuals named in monitored AI outputs.
- Categories of personal data: identifiers (name, email), authentication data, content submitted by the Customer, usage metadata.
3. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational measures (Annex A).
- Assist the Controller in responding to data-subject requests.
- Notify the Controller without undue delay of any personal data breach.
- On termination, delete or return personal data within 30 days, save where retention is required by law.
4. Sub-processors
The Controller provides general authorisation for the engagement of sub-processors. A current list is maintained at /legal/subprocessors. We will notify Customers at least 14 days before adding a new sub-processor, by email and an in-app banner. You may object on reasonable grounds.
5. International transfers
Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) and any supplementary measures required by Schrems II case law.
6. Audit rights
We make available all information necessary to demonstrate compliance and contribute to audits, including inspections conducted by the Controller or an auditor mandated by the Controller, on 30 days' written notice and subject to confidentiality. Where the Controller can rely on our existing third-party reports (e.g. ISO 27001, SOC 2) we may provide those in lieu of an on-site audit.
Annex A — Technical and Organisational Measures (TOMs)
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with mandatory 2FA for production systems.
- Centralised logging, anomaly detection, and 90-day retention of security logs.
- Vendor security review prior to onboarding any sub-processor.
- Quarterly access reviews and least-privilege enforcement.
- Documented incident response plan with 72-hour breach-notification target.
- Encrypted, geographically-redundant backups with periodic restore tests.
