Skip to content
Nuqo

Data Processing Agreement (DPA)

Version: 2026-08-08

This version is archived and no longer the current one. It stays permanently available because signed contracts reference it by name.

Go to the current version (2026-08-10)

In the event of any conflict between the German and English versions of this Data Processing Agreement, the German version shall prevail.

1. Subject and duration

This Data Processing Agreement ("DPA") pursuant to Art. 28 GDPR supplements the Terms of Service ("Terms") between the controller ("you", "Controller") and Nuqo GmbH, Körnerstrasse 10, 13585 Berlin ("Nuqo", "Processor").

The DPA applies for the duration of the use of the Service pursuant to the Terms.

2. Nature and purpose of processing

Nuqo processes personal data on behalf of the Controller for the provision of the services described in the Terms, in particular:

  • Extraction and structuring of bills of materials and specifications from uploaded documents
  • AI-powered analysis of technical documents
  • Storage and management of quote and inquiry data
  • User account management and authentication

3. Categories of data subjects

  • Employees and agents of the Controller (user accounts)
  • Contact persons in uploaded inquiry documents (contact details in RFQs, BOMs, drawings)

4. Categories of personal data

  • Account data: name, email address, phone number, login information
  • Organisation data: company name, organisation settings
  • Document data: personal data contained in uploaded files (e.g. contact persons, contact details)
  • Usage data: IP address, session data, event logs

5. Obligations of the Processor

Nuqo undertakes to:

  • Process personal data only on documented instructions from the Controller
  • Inform the Controller without undue delay if, in Nuqo's opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions
  • Ensure that persons authorised to process have committed to confidentiality
  • Implement appropriate technical and organisational measures pursuant to Art. 32 GDPR
  • Not respond to data subject requests itself, but forward them to the Controller without undue delay, and assist the Controller in fulfilling data subject rights
  • Notify the Controller without undue delay of any personal data breach
  • Assist the Controller in complying with the obligations under Art. 32 to 36 GDPR — in particular security of processing, breach notification, data protection impact assessment and prior consultation of the supervisory authority — taking into account the nature of processing and the information available to Nuqo
  • Upon completion of the provision of the processing services, delete or return all personal data at the Controller's choice and delete existing copies, unless Union or Member State law requires storage

6. Deletion and return

The choice between deletion and return rests with the Controller. Nuqo carries it out within 30 days of receiving the instruction or of the end of the contractual relationship, and follows up with the sub-processors engaged. Backup copies are not purged individually; they expire with their retention period. If a backup copy containing already-deleted data is restored, the deletion is repeated without undue delay. On request, Nuqo confirms the deletion in text form.

Log data relating to order data — in particular the processing logs for individual inquiries — is additionally deleted on a rolling basis, no later than 61 days after it is created. Where the contractual relationship ends sooner, that period is not awaited: such data is deleted together with the remaining personal data under paragraph 1.

7. Sub-processors

The Controller grants general authorisation for the engagement of sub-processors. Nuqo announces the engagement of a new sub-processor, or the replacement of an existing one, at least 14 days in advance in text form. The Controller may object within that period. An objection does not block the change; in that case the parties will discuss a solution without undue delay. If no agreement is reached within a reasonable period, the Controller may terminate the contract for cause with respect to the affected services.

Nuqo contractually binds every sub-processor to the same data protection obligations set out in this DPA, in particular to sufficient guarantees of appropriate technical and organisational measures. Where a sub-processor fails to meet its data protection obligations, Nuqo remains liable to the Controller for that sub-processor's performance.

Current sub-processors:

ProviderPurposeLocation
Hetzner Online GmbHServer hostingGermany (Nuremberg)
Neon Inc.Database hosting (PostgreSQL)Germany (Frankfurt, aws-eu-central-1)
Cloudflare Inc.File storage (R2)EU
Mailgun Technologies Inc.Transactional emailsEU endpoint
Stripe Payments Europe, Ltd.Payment processing (subscription billing)EU / USA (SCC)
Microsoft (Azure OpenAI Service)AI document processingAzure EU Data Zone
Google (Gemini via Vertex AI)AI document processingEU multi-region (Vertex AI)
PostHog Inc.Usage analyticsEU
GlitchTip (eu.glitchtip.com)Error monitoringEU

Scope of Stripe processing: Stripe is used solely for invoicing and payment processing and receives only the customer's billing contact details and payment/bank data. Stripe receives no uploaded documents, bills of materials, drawings, quote content, calculation data, or the customer's own end-customer data — such data is never passed to Stripe.

8. Technical and organisational measures

Nuqo implements the measures required under Art. 32 GDPR. They are structured along the protection goals of Art. 32(1) GDPR:

  • Confidentiality: access restricted to authorised persons through role-based permissions, data separated by organisation, passwords hashed with Argon2id, secure session management (HttpOnly cookies, SameSite, Secure flag); all employees are bound to confidentiality in writing.
  • Integrity: encryption in transit using TLS and encryption of data at rest; changes to quote data are logged and remain traceable.
  • Availability: operation on servers in Germany, continuous monitoring with alerting, prompt security updates.
  • Resilience: the systems are designed to withstand load peaks and disruptions without data loss; incidents are detected and remedied.
  • Restorability: regular backup copies whose restoration is tested, so that availability and access can be restored promptly after an incident.
  • Regular review: the effectiveness of these measures is reviewed regularly and adjusted where necessary.

Nuqo provides a detailed description of the measures to the Controller on request.

9. International transfers

The AI-based processing of uploaded documents (BOMs, drawings, specifications) takes place exclusively via EU endpoints — the Azure EU Data Zone and Vertex AI in the EU multi-region. This content does not leave the EU.

The AI providers engaged are contractually barred from using the transmitted content to train their models; Microsoft's and Google Cloud's data protection terms apply respectively. At Microsoft, inputs and outputs are retained for up to 30 days for abuse monitoring and deleted afterwards; no storage beyond that takes place. Vertex AI does not store the transmitted content.

A transfer to third countries occurs solely in connection with payment processing via Stripe, which covers billing data exclusively and no document content. It is made on the basis of an EU Commission adequacy decision, standard contractual clauses (SCCs), or other recognised safeguards under Art. 44 ff. GDPR.

10. Audit rights

The Controller has the right to verify compliance with this DPA through appropriate measures, including audits. Nuqo will provide all necessary information and assist with inspections.

11. Contact

For questions about this DPA, please contact: [email protected]