For Relying Parties
Legal
This DPA forms part of the Agreement between NEXIEL LIMITED and Customer. It governs NEXIEL’s processing of Customer Personal Data on behalf of Customer in connection with the Services.
Effective date: 03 January 2026
Last updated: 03 January 2026
NEXIEL LIMITED — VENTURE HUB, 136 CAPEL STREET, DUBLIN, D01 T2C9, IRELAND
This DPA is entered into by and between: (1) Customer (Controller) and (2) NEXIEL LIMITED (Processor). It is incorporated into the Terms of Service / Master Services Agreement and any Order Form(s) (together, the “Agreement”).
Processor: NEXIEL LIMITED, VENTURE HUB, 136 CAPEL STREET, DUBLIN, D01 T2C9, IRELAND. Privacy contact: dpo@nexiel.ie Legal notices: legal@nexiel.ie.
Terms not defined here have the meaning in GDPR and/or the Agreement. This DPA prevails over the Agreement for data protection terms; SCCs prevail for Transfers where applicable.
Customer is the Controller. NEXIEL is the Processor and will act only on documented instructions.
NEXIEL will maintain confidentiality, implement appropriate security (Annex 1), assist with Data Subject requests and DPIAs, notify without undue delay after becoming aware of a Personal Data Breach, provide compliance information (subject to Section 9), and return/delete Customer Personal Data at end of Services unless law requires retention.
Customer warrants lawful basis, notices/consents, minimisation, compliant instructions, and configuration to avoid unnecessary sensitive data.
General authorisation with 30 days’ notice for new/changed Subprocessors; names required. Objection process and termination right for substantiated data protection objections. Flow-down terms; NEXIEL remains responsible. Current Subprocessor: Stripe (billing/payments) — https://stripe.com/ie/privacy.
Core hosting in the EU/EEA. Stripe may transfer per its DPA/transfer addendum. Where required, SCCs (Module 2/3) and supplementary measures will be used based on transfer risk assessment.
Annual audit right (or more in specific cases), with notice, scope, and confidentiality/security conditions; Customer bears costs unless material non-compliance is found.
NEXIEL will respond to reasonable written requests for processing information, subject to confidentiality/security constraints.
NEXIEL will inform Customer if instructions appear unlawful, unless prohibited by law.
Delete within 30 days of termination (after export), subject to backups lifecycle and legal retention. Residual backups are protected and deleted per lifecycle unless law requires retention.
Subject to the Agreement’s liability terms (and SCCs where applicable).
Effective while NEXIEL processes Customer Personal Data under the Agreement; relevant clauses survive.
May be accepted electronically and in counterparts. Acceptance is recorded in the customer compliance panel.
Stripe (billing, invoicing, and payment processing): https://stripe.com/ie/privacy
As described in Section 4. Customer may further specify details in an Order Form, DPIA, or written instructions, consistent with the Agreement and Applicable Law.
Questions about this DPA? Email dpo@nexiel.ie or legal@nexiel.ie.