Data Processing Agreement (DPA)
Version: 2026-08-10
Previous versions: 2026-08-08, 2026-07-08
In the event of any conflict between the German and English versions of this Data Processing Agreement, the German version shall prevail.
1. Subject and duration
This Data Processing Agreement ("DPA") pursuant to Art. 28 GDPR supplements the Terms of Service ("Terms") between the controller ("you", "Controller") and Nuqo GmbH, Körnerstraße 10, 13585 Berlin ("Nuqo", "Processor").
The DPA applies for the duration of the use of the Service pursuant to the Terms.
2. Nature and purpose of processing
Nuqo processes personal data on behalf of the Controller for the provision of the services described in the Terms, in particular:
- Extraction and structuring of bills of materials and specifications from uploaded documents
- AI-powered analysis of technical documents
- Storage and management of quote and inquiry data
- User account management and authentication
3. Categories of data subjects
- Employees and agents of the Controller (user accounts)
- Contact persons in uploaded inquiry documents (contact details in RFQs, BOMs, drawings)
4. Categories of personal data
- Account data: name, email address, phone number, login information
- Organisation data: company name, organisation settings
- Document data: personal data contained in uploaded files (e.g. contact persons, contact details)
- Usage data: IP address, session data, event logs
5. Obligations of the Processor
Nuqo undertakes to:
- Process personal data only on documented instructions from the Controller
- Inform the Controller without undue delay if, in Nuqo's opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. Nuqo is entitled to suspend execution of the instruction concerned until it has been confirmed or amended (Art. 28(3)(h) GDPR)
- Ensure that persons authorised to process have committed to confidentiality
- Implement appropriate technical and organisational measures pursuant to Art. 32 GDPR
- Not respond to data subject requests itself, but forward them to the Controller without undue delay, and assist the Controller in fulfilling data subject rights; this applies unless the Controller instructs Nuqo to respond (Art. 28(3)(e) GDPR)
- Notify the Controller without undue delay of any personal data breach
- Assist the Controller in complying with the obligations under Art. 32 to 36 GDPR — in particular security of processing, breach notification, data protection impact assessment and prior consultation of the supervisory authority — taking into account the nature of processing and the information available to Nuqo
- Upon completion of the provision of the processing services, delete or return all personal data at the Controller's choice and delete existing copies, unless Union or Member State law requires storage
6. Obligations and rights of the Controller
The Controller is responsible for the lawfulness of the processing, in particular for having a legal basis for collecting the data and for transferring it to Nuqo. The Controller ensures that it is entitled to use the data it brings into the Service for that purpose — this includes personal data contained in inquiry documents from its own customers — and that the data subjects have been informed where required.
The Controller is entitled to issue instructions to Nuqo. Use of the Service within the contractually agreed scope constitutes an instruction; instructions going beyond that are given in text form to [email protected]. Nuqo documents the instructions it receives.
The Controller may change or withdraw instructions at any time, verify compliance with this DPA under Section 11, and request deletion or return of the data under Section 7.
7. Deletion and return
The choice between deletion and return rests with the Controller. Nuqo carries it out within 30 days of receiving the instruction or of the end of the contractual relationship, and follows up with the sub-processors engaged. Backup copies are not purged individually; they expire with their retention period. If a backup copy containing already-deleted data is restored, the deletion is repeated without undue delay. On request, Nuqo confirms the deletion in text form.
Log data relating to order data — in particular the processing logs for individual inquiries — is additionally deleted on a rolling basis, no later than 61 days after it is created. Where the contractual relationship ends sooner, that period is not awaited: such data is deleted together with the remaining personal data under paragraph 1.
8. Sub-processors
The Controller grants general authorisation for the engagement of sub-processors. Nuqo announces the engagement of a new sub-processor, or the replacement of an existing one, at least 14 days in advance in text form. The Controller may object to the change within that period on important data-protection grounds. In the event of an objection, the parties will first seek an amicable solution. If no such solution is reached and Nuqo cannot reasonably provide the service without the sub-processor concerned, the Controller has a right of extraordinary termination with respect to the affected service (Art. 28(2) GDPR).
Nuqo contractually binds every sub-processor to the same data protection obligations set out in this DPA, in particular to sufficient guarantees of appropriate technical and organisational measures. Where a sub-processor fails to meet its data protection obligations, Nuqo remains liable to the Controller for that sub-processor's performance.
Current sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting (application, database access, search index) | Germany (Nuremberg) |
| Neon Inc. | Database hosting (PostgreSQL) | Germany (Frankfurt, aws-eu-central-1) |
| Cloudflare Inc. | File storage (R2) | EU |
| Microsoft (Azure, jobs server) | Operation of supplier-catalog processing | EU (Netherlands) |
| Mailgun Technologies Inc. | Transactional emails | EU endpoint |
| Stripe Payments Europe, Ltd. | Payment processing (subscription billing) | EU / USA (SCC) |
| Microsoft (Azure OpenAI Service) | AI document processing | Azure EU Data Zone |
| Google (Gemini via Vertex AI) | AI document processing | EU multi-region (Vertex AI) |
| PostHog Inc. | Usage analytics | EU |
| GlitchTip (eu.glitchtip.com) | Error monitoring | EU |
Scope of Stripe processing: Stripe is used solely for invoicing and payment processing and receives only the customer's billing contact details and payment/bank data. Stripe receives no uploaded documents, bills of materials, drawings, quote content, calculation data, or the customer's own end-customer data — such data is never passed to Stripe.
Scope of processing on the Azure jobs server: That server is used exclusively to retrieve and prepare supplier catalogs. The Controller's order data — uploaded documents, bills of materials, drawings, quote content, and the associated processing logs — is neither stored there nor retrieved as part of that processing.
9. Technical and organisational measures
Nuqo implements the measures required under Art. 32 GDPR. They are structured along the protection goals of Art. 32(1) GDPR:
- Confidentiality: access restricted to authorised persons through role-based permissions, data separated by organisation, passwords stored only as hashes using state-of-the-art algorithms, secure session management; all employees are bound to confidentiality in writing.
- Integrity: encryption in transit using TLS and encryption of data at rest; changes to quote data are logged and remain traceable.
- Availability: operation on servers in the European Union; the application, the database, and the search index are located in Germany. Continuous monitoring with alerting, prompt security updates.
- Resilience: the systems are designed to withstand load peaks and disruptions without data loss; incidents are detected and remedied.
- Restorability: regular backup copies whose restoration is tested, so that availability and access can be restored promptly after an incident.
- Regular review: the effectiveness of these measures is reviewed regularly and adjusted where necessary.
Nuqo provides a detailed description of the measures to the Controller on request.
10. International transfers
The AI-based processing of uploaded documents (BOMs, drawings, specifications) takes place exclusively via EU endpoints — the Azure EU Data Zone and Vertex AI in the EU multi-region. This content does not leave the EU.
The AI providers engaged are contractually barred from using the transmitted content to train their models; Microsoft's and Google Cloud's data protection terms apply respectively. At Microsoft, inputs and outputs are retained for up to 30 days for abuse monitoring and deleted afterwards; no storage beyond that takes place. Nuqo is pursuing an exemption from this (Zero Data Retention) and will inform the Controller once it is in place. Vertex AI does not store the transmitted content.
A transfer to third countries occurs solely in connection with payment processing via Stripe, which covers billing data exclusively and no document content. It is made on the basis of an EU Commission adequacy decision, standard contractual clauses (SCCs), or other recognised safeguards under Art. 44 ff. GDPR.
11. Audit rights
The Controller has the right to verify compliance with this DPA through appropriate measures, including audits. Nuqo will provide all necessary information and assist with inspections.
12. Contact
For questions about this DPA, please contact: [email protected]