Skip to content
Nuqo

Data Processing Agreement (DPA)

Version: 2026-10-06

Previous versions: 2026-10-05, 2026-08-31, 2026-08-10, 2026-08-08, 2026-07-08

In the event of any conflict between the German and English versions of this Data Processing Agreement, the German version shall prevail.

1. Subject and duration

This Data Processing Agreement (“DPA”) pursuant to Art. 28 GDPR supplements the Terms of Service (“AGB”) between the customer (“you”, “Controller”) and Nuqo GmbH, Körnerstraße 10, 13585 Berlin (“Nuqo”, “Processor”). It applies for the duration of the use of the Service under the Terms and survives their termination until processing has ceased and data has been deleted or returned.

2. Nature and purpose of processing

Nuqo processes personal data on behalf of the Controller to provide the services described in the Terms, in particular:

  • Extraction and structuring of bills of materials and specifications from uploaded documents
  • AI-powered analysis of technical documents
  • Storage and management of quote and inquiry data
  • User account management and authentication

3. Categories of data subjects

  • Employees and agents of the Controller (user accounts)
  • Contact persons in uploaded inquiry documents (contact details in RFQs, BOMs, drawings)

4. Categories of personal data

  • Account data: name, email address, phone number, login information
  • Organisation data: company name, organisation settings
  • Document data: personal data contained in uploaded files (e.g. contact persons, contact details)
  • Usage data: IP address, session data, event logs

5. Obligations of the Processor

Nuqo undertakes to:

  • Process personal data only on documented instructions from the Controller. If, in Nuqo’s opinion, an instruction infringes the General Data Protection Regulation or other Union or Member State data protection provisions, Nuqo will inform the Controller without undue delay. Nuqo is entitled to suspend the execution of the instruction in question until it has been confirmed or amended (Art. 28(3)(h) sentence 2 GDPR)
  • Ensure that persons authorised to process the data have committed themselves to confidentiality
  • Implement appropriate technical and organisational measures pursuant to Art. 32 GDPR; these are described in the section “Technical and organisational measures” of this DPA
  • Assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests for exercising data subject rights. Where a data subject approaches Nuqo directly, Nuqo will forward the request to the Controller without undue delay and will not respond to it itself, unless the Controller instructs Nuqo to do so (Art. 28(3)(e) GDPR)
  • Assist the Controller in complying with the obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to Nuqo — in particular with the security of processing, the notification of personal data breaches to the supervisory authority and to data subjects, the data protection impact assessment and the prior consultation (Art. 28(3)(f) GDPR)
  • Notify the Controller of any personal data breach without undue delay and in any event within 48 hours of having become aware of it (Art. 33(2) GDPR). The notification describes the nature of the breach including the categories and approximate number of data subjects and records concerned, names a point of contact for further information, and describes the likely consequences and the measures taken or proposed. Where that information is not yet complete, Nuqo notifies what is known and provides the remainder without undue further delay
  • Maintain a record of all categories of processing activities carried out on behalf of the Controller and make it available to the supervisory authority and, on request, to the Controller (Art. 30(2) GDPR)
  • Upon completion of the provision of the processing services, delete or return all personal data at the Controller’s choice and delete existing copies, unless Union or Member State law requires storage

If Nuqo processes personal data in breach of the Controller’s instructions and thereby itself determines the purposes and means of the processing, Nuqo is considered a controller in respect of that processing (Art. 28(10) GDPR).

6. Obligations and rights of the Controller

The Controller is responsible for the lawfulness of the processing, in particular for having a legal basis for collecting the data and for transferring it to Nuqo. The Controller ensures that it is entitled to use the data it brings into the Service for that purpose — this includes personal data contained in inquiry documents from its own customers — and that the data subjects have been informed where required (Art. 28(3) sentence 1 GDPR).

The Controller is entitled to issue instructions to Nuqo. Use of the Service within the contractually agreed scope constitutes an instruction; instructions going beyond that are given in text form to [email protected]. Nuqo documents the instructions it receives.

On the Controller’s side, instructions may be issued by the persons it designates for that purpose; where it designates none, the administrators of its account are treated as authorised. On Nuqo’s side, instructions are received by the management and the technical lead. The parties notify each other of changes to these persons in text form (Art. 28(3)(a) GDPR).

The Controller may change or withdraw instructions at any time, verify compliance with this DPA under the “Audit rights” section, and request deletion or return of the data under the “Deletion and return” section.

7. Deletion and return

The choice between deletion and return rests with the Controller. Nuqo carries it out within 30 days of receiving the instruction or of the end of the contractual relationship, and follows up with the sub-processors engaged. Backup copies are not purged individually; they expire with their retention period. If a backup copy containing already-deleted data is restored, the deletion is repeated without undue delay. On request, Nuqo confirms the deletion in text form.

Log data relating to order data — in particular the processing logs for individual inquiries — is additionally deleted on a rolling basis, no later than 61 days after it is created. Where the contractual relationship ends sooner, that period is not awaited: such data is deleted together with the remaining personal data under paragraph 1.

Security logs — records of sign-ins, failed sign-ins and administrative actions, with the account, time and IP address — are kept by Nuqo as its own record for the security of the service (Art. 6(1)(f) GDPR). They contain no order data and are deleted automatically after 12 months.

8. Sub-processors

The Controller grants general authorisation for the engagement of sub-processors. Nuqo informs the Controller of intended changes — the engagement of a new sub-processor or the replacement of an existing one — at least 14 days in advance in text form. The Controller may object to the change within that period on important grounds relating to data protection. In the event of an objection, the Parties will first seek an amicable solution. If no such solution is reached and Nuqo cannot reasonably provide the service without the sub-processor concerned, the Controller has a right to terminate for cause with respect to the affected service (Art. 28(2) GDPR).

Nuqo imposes on every sub-processor by contract the same data protection obligations as are set out in this DPA, in particular sufficient guarantees of appropriate technical and organisational measures. Where the sub-processor fails to fulfil its data protection obligations, Nuqo remains liable to the Controller for the performance of those obligations (Art. 28(4) GDPR).

Current sub-processors:

ProviderPurposeLocation
Hetzner Online GmbHServer hosting (application, database access, search index)Germany (Nuremberg)
Neon Inc.Database hosting (PostgreSQL)Germany (Frankfurt, aws-eu-central-1)
Cloudflare Inc.File storage (R2); proxy in front of the application (TLS termination, no storage of content)R2: EU; proxy: Cloudflare network location nearest the user
Microsoft (Azure, jobs server)Operation of supplier-catalog processingEU (Netherlands)
Mailgun Technologies Inc.Transactional emailsEU endpoint
Stripe Payments Europe, Ltd.Payment processing (subscription billing)EU / USA (SCC)
Microsoft (Azure OpenAI Service)AI document processingAzure EU Data Zone; where the Order Form names another region (see “AI-assisted processing”), also Azure US Data Zone or Azure Global
Google (Gemini via Vertex AI)AI document processingEU multi-region (Vertex AI); where the Order Form names another region, also US multi-region or global
Microsoft (Grounding with Bing Search)Web lookup, only for organisations with web lookup switched on: manufacturer part number, manufacturer, short description, category and quantity of a bill-of-materials line, or a short search term (e.g. a standard’s number); no documents or drawingsoutside Microsoft’s EU Data Boundary, including the USA
PostHog Inc.Usage analyticsEU
GlitchTip (eu.glitchtip.com)Error monitoringEU
Google Cloud EMEA Ltd. (Google Workspace)Nuqo’s email; order data only where the Controller sends it by email. Not part of the applicationEU / USA (SCC)

Scope of Stripe processing: Stripe is used solely for invoicing and payment processing and receives only the customer’s billing contact details and payment/bank data. Stripe receives no uploaded documents, bills of materials, drawings, quote content, calculation data, or the customer’s own end-customer data — such data is never passed to Stripe.

Scope of processing on the Azure jobs server: That server is used exclusively to retrieve and prepare supplier catalogs. The Controller’s order data — uploaded documents, bills of materials, drawings, quote content, and the associated processing logs — is neither stored there nor retrieved as part of that processing.

9. Technical and organisational measures

Nuqo implements the measures required under Art. 32(1) GDPR. They are ordered along the protection goals of Art. 32(1) GDPR:

  • Confidentiality — physical access control, system access control and data access control, role-based permissions, separation of data by organisation (tenant separation), encryption of data at rest and in transit (TLS), password hashing with Argon2id, written confidentiality undertakings from all employees
  • Integrity — transfer control and input control, logging of changes to quote data, secure session management (HttpOnly, SameSite, Secure)
  • Availability — hosting within the European Union, with the application, the database and the search index located in Germany (connections are accepted by Cloudflare’s proxy at the location nearest the user), monitoring, protection against data loss through regular backups
  • Resilience — separation of the production and development environments, capacity monitoring, regular security updates
  • Restorability — backups whose restoration is tested
  • Regular review — annual review and updating of the measures and of the retention and deletion periods

Nuqo provides the Controller on request with a detailed description of these measures — including the systems used and their locations, the retention and deletion periods, and the control of processing carried out on instruction (Auftragskontrolle).

When the measures are updated, the agreed level of protection will not be reduced; Nuqo will inform the Controller of changes that affect the level of protection.

10. International transfers

Where sub-processors are established in third countries or process data there (e.g. the USA), the transfer is made on the basis of an adequacy decision of the EU Commission, standard contractual clauses (SCCs), or other recognised safeguards under Art. 44 et seq. GDPR.

11. AI-assisted processing

Nuqo uses AI services for the analysis of technical documents. In view of the confidentiality obligations that the Controller may owe to its own customers, the following applies:

  • Processing region. The content is processed in the region named in the Order Form; where none is named, EU applies:
    • EU — exclusively via endpoints within the European Union: Microsoft via the Azure EU Data Zone, Google via Vertex AI in the EU multi-region.
    • EU and USA — additionally the Azure US Data Zone and Vertex AI in the US multi-region. For each processing step, Nuqo uses whichever of the two regions is faster, cheaper or available at that moment.
    • No restriction — additionally Azure Global Standard and the global endpoint of Vertex AI; processing may then take place in any data centre of the respective provider.
    The region applies to all users of the Controller, including the storage at Microsoft described below. Uploaded files, the database and the search index remain in the EU in every case; transfers to the USA and other third countries are governed by the section “International transfers”. Excepted is the web lookup via Microsoft (Grounding with Bing Search) where it is switched on for the Controller: the search details listed in the table above are processed outside the EU, whatever the named region.
  • No training at the provider. The content is not used by the AI service providers to train or improve their models. This is contractually excluded under the enterprise terms of the services used.
  • No storage beyond the processing itself, with one openly stated exception: Microsoft currently retains inputs and outputs at Azure OpenAI for up to 30 days, for abuse monitoring and, in multi-step AI processes such as the quote review chat or part matching, to carry a process from one step to the next. That data is used solely for these purposes and is deleted thereafter. No such storage takes place at Vertex AI.
  • No disclosure to third parties other than the sub-processors named in the table above.

The confidentiality of the drawings, bills of materials and specifications transmitted — as such — is governed by Section 4 of the Terms and is not limited to personal data.

12. Audit rights

Nuqo makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections (Art. 28(3)(h) GDPR).

Compliance is demonstrated primarily by information provided, by the detailed account of the technical and organisational measures, and by current attestations, certifications or reports of independent bodies. Where those do not suffice in a given case, the Controller may request an on-site audit. It takes place after at least 30 days’ notice in text form, during normal business hours, without disrupting operations, and at most once per calendar year.

Where there is specific cause — in particular a personal data breach at Nuqo or an order of the supervisory authority — the Controller may audit beyond that; the notice period is then shortened to what is reasonable in the circumstances.

Each party bears its own costs. For the effort of an on-site audit going beyond making information available, Nuqo may charge a reasonable fee; this does not apply where the audit reveals a breach by Nuqo. Third parties instructed to carry out the audit must not be competitors of Nuqo and must be bound to confidentiality.

13. Data protection contact

The Controller directs questions on the processing and on personal data to [email protected]; the contact is the management. Nuqo has not designated a data protection officer — the conditions of Art. 37(1) GDPR and § 38(1) BDSG are not currently met. If one is designated, Nuqo will notify the Controller of their name and contact details.