Data Processing Agreement (DPA)
Version: 2026-10-05
This version is archived and no longer the current one. It stays permanently available because signed contracts reference it by name.
Go to the current version (2026-10-06)In the event of any conflict between the German and English versions of this Data Processing Agreement, the German version shall prevail.
1. Subject and duration
This Data Processing Agreement (“DPA”) pursuant to Art. 28 GDPR supplements the Terms of Service (“AGB”) between the customer (“you”, “Controller”) and Nuqo GmbH, Körnerstraße 10, 13585 Berlin (“Nuqo”, “Processor”). It applies for the duration of the use of the Service under the Terms and survives their termination until processing has ceased and data has been deleted or returned.
2. Nature and purpose of processing
Nuqo processes personal data on behalf of the Controller to provide the services described in the Terms, in particular:
- Extraction and structuring of bills of materials and specifications from uploaded documents
- AI-powered analysis of technical documents
- Storage and management of quote and inquiry data
- User account management and authentication
3. Categories of data subjects
- Employees and agents of the Controller (user accounts)
- Contact persons in uploaded inquiry documents (contact details in RFQs, BOMs, drawings)
4. Categories of personal data
- Account data: name, email address, phone number, login information
- Organisation data: company name, organisation settings
- Document data: personal data contained in uploaded files (e.g. contact persons, contact details)
- Usage data: IP address, session data, event logs
5. Obligations of the Processor
Nuqo undertakes to:
- Process personal data only on documented instructions from the Controller. If, in Nuqo’s opinion, an instruction infringes the General Data Protection Regulation or other Union or Member State data protection provisions, Nuqo will inform the Controller without undue delay. Nuqo is entitled to suspend the execution of the instruction in question until it has been confirmed or amended (Art. 28(3)(h) sentence 2 GDPR)
- Ensure that persons authorised to process the data have committed themselves to confidentiality
- Implement appropriate technical and organisational measures pursuant to Art. 32 GDPR; these are described in the section “Technical and organisational measures” of this DPA
- Assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests for exercising data subject rights. Where a data subject approaches Nuqo directly, Nuqo will forward the request to the Controller without undue delay and will not respond to it itself, unless the Controller instructs Nuqo to do so (Art. 28(3)(e) GDPR)
- Assist the Controller in complying with the obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to Nuqo — in particular with the security of processing, the notification of personal data breaches to the supervisory authority and to data subjects, the data protection impact assessment and the prior consultation (Art. 28(3)(f) GDPR)
- Notify the Controller of any personal data breach without undue delay and in any event within 48 hours of having become aware of it (Art. 33(2) GDPR). The notification describes the nature of the breach including the categories and approximate number of data subjects and records concerned, names a point of contact for further information, and describes the likely consequences and the measures taken or proposed. Where that information is not yet complete, Nuqo notifies what is known and provides the remainder without undue further delay
- Maintain a record of all categories of processing activities carried out on behalf of the Controller and make it available to the supervisory authority and, on request, to the Controller (Art. 30(2) GDPR)
- Upon completion of the provision of the processing services, delete or return all personal data at the Controller’s choice and delete existing copies, unless Union or Member State law requires storage
If Nuqo processes personal data in breach of the Controller’s instructions and thereby itself determines the purposes and means of the processing, Nuqo is considered a controller in respect of that processing (Art. 28(10) GDPR).
6. Obligations and rights of the Controller
The Controller is responsible for the lawfulness of the processing, in particular for having a legal basis for collecting the data and for transferring it to Nuqo. The Controller ensures that it is entitled to use the data it brings into the Service for that purpose — this includes personal data contained in inquiry documents from its own customers — and that the data subjects have been informed where required (Art. 28(3) sentence 1 GDPR).
The Controller is entitled to issue instructions to Nuqo. Use of the Service within the contractually agreed scope constitutes an instruction; instructions going beyond that are given in text form to [email protected]. Nuqo documents the instructions it receives.
On the Controller’s side, instructions may be issued by the persons it designates for that purpose; where it designates none, the administrators of its account are treated as authorised. On Nuqo’s side, instructions are received by the management and the technical lead. The parties notify each other of changes to these persons in text form (Art. 28(3)(a) GDPR).
The Controller may change or withdraw instructions at any time, verify compliance with this DPA under the “Audit rights” section, and request deletion or return of the data under the “Deletion and return” section.
7. Deletion and return
The choice between deletion and return rests with the Controller. Nuqo carries it out within 30 days of receiving the instruction or of the end of the contractual relationship, and follows up with the sub-processors engaged. Backup copies are not purged individually; they expire with their retention period. If a backup copy containing already-deleted data is restored, the deletion is repeated without undue delay. On request, Nuqo confirms the deletion in text form.
Log data relating to order data — in particular the processing logs for individual inquiries — is additionally deleted on a rolling basis, no later than 61 days after it is created. Where the contractual relationship ends sooner, that period is not awaited: such data is deleted together with the remaining personal data under paragraph 1.
Security logs — records of sign-ins, failed sign-ins and administrative actions, with the account, time and IP address — are kept by Nuqo as its own record for the security of the service (Art. 6(1)(f) GDPR). They contain no order data and are deleted automatically after 12 months.
8. Sub-processors
The Controller grants general authorisation for the engagement of sub-processors. Nuqo informs the Controller of intended changes — the engagement of a new sub-processor or the replacement of an existing one — at least 14 days in advance in text form. The Controller may object to the change within that period on important grounds relating to data protection. In the event of an objection, the Parties will first seek an amicable solution. If no such solution is reached and Nuqo cannot reasonably provide the service without the sub-processor concerned, the Controller has a right to terminate for cause with respect to the affected service (Art. 28(2) GDPR).
Nuqo imposes on every sub-processor by contract the same data protection obligations as are set out in this DPA, in particular sufficient guarantees of appropriate technical and organisational measures. Where the sub-processor fails to fulfil its data protection obligations, Nuqo remains liable to the Controller for the performance of those obligations (Art. 28(4) GDPR).
Current sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting (application, database access, search index) | Germany (Nuremberg) |
| Neon Inc. | Database hosting (PostgreSQL) | Germany (Frankfurt, aws-eu-central-1) |
| Cloudflare Inc. | File storage (R2); proxy in front of the application (TLS termination, no storage of content) | R2: EU; proxy: Cloudflare network location nearest the user |
| Microsoft (Azure, jobs server) | Operation of supplier-catalog processing | EU (Netherlands) |
| Mailgun Technologies Inc. | Transactional emails | EU endpoint |
| Stripe Payments Europe, Ltd. | Payment processing (subscription billing) | EU / USA (SCC) |
| Microsoft (Azure OpenAI Service) | AI document processing | Azure EU Data Zone |
| Google (Gemini via Vertex AI) | AI document processing | EU multi-region (Vertex AI) |
| PostHog Inc. | Usage analytics | EU |
| GlitchTip (eu.glitchtip.com) | Error monitoring | EU |
| Google Cloud EMEA Ltd. (Google Workspace) | Nuqo’s email; order data only where the Controller sends it by email. Not part of the application | EU / USA (SCC) |
Scope of Stripe processing: Stripe is used solely for invoicing and payment processing and receives only the customer’s billing contact details and payment/bank data. Stripe receives no uploaded documents, bills of materials, drawings, quote content, calculation data, or the customer’s own end-customer data — such data is never passed to Stripe.
Scope of processing on the Azure jobs server: That server is used exclusively to retrieve and prepare supplier catalogs. The Controller’s order data — uploaded documents, bills of materials, drawings, quote content, and the associated processing logs — is neither stored there nor retrieved as part of that processing.
9. Technical and organisational measures
Nuqo implements the measures required under Art. 32(1) GDPR. They are ordered along the protection goals of Art. 32(1) GDPR:
- Confidentiality — physical access control, system access control and data access control, role-based permissions, separation of data by organisation (tenant separation), encryption of data at rest and in transit (TLS), password hashing with Argon2id, written confidentiality undertakings from all employees
- Integrity — transfer control and input control, logging of changes to quote data, secure session management (HttpOnly, SameSite, Secure)
- Availability — hosting within the European Union, with the application, the database and the search index located in Germany (connections are accepted by Cloudflare’s proxy at the location nearest the user), monitoring, protection against data loss through regular backups
- Resilience — separation of the production and development environments, capacity monitoring, regular security updates
- Restorability — backups whose restoration is tested
- Regular review — annual review and updating of the measures and of the retention and deletion periods
Nuqo provides the Controller on request with a detailed description of these measures — including the systems used and their locations, the retention and deletion periods, and the control of processing carried out on instruction (Auftragskontrolle).
When the measures are updated, the agreed level of protection will not be reduced; Nuqo will inform the Controller of changes that affect the level of protection.
10. International transfers
Where sub-processors are established in third countries (e.g. the USA), the transfer is made on the basis of an adequacy decision of the EU Commission, standard contractual clauses (SCCs), or other recognised safeguards under Art. 44 et seq. GDPR.
11. AI-assisted processing
Nuqo uses AI services for the analysis of technical documents. In view of the confidentiality obligations that the Controller may owe to its own customers, the following applies:
- Processing within the EU. The content is processed exclusively via endpoints within the European Union — Microsoft via the Azure EU Data Zone, Google via Vertex AI in the EU multi-region.
- No training at the provider. The content is not used by the AI service providers to train or improve their models. This is contractually excluded under the enterprise terms of the services used.
- No storage beyond the processing itself, with one openly stated exception: Microsoft currently retains inputs and outputs at Azure OpenAI for up to 30 days, for abuse monitoring and, in multi-step AI processes such as the quote review chat or part matching, to carry a process from one step to the next. That data is used solely for these purposes and is deleted thereafter. No such storage takes place at Vertex AI.
- No disclosure to third parties other than the sub-processors named in the table above.
The confidentiality of the drawings, bills of materials and specifications transmitted — as such — is governed by Section 4 of the Terms and is not limited to personal data.
12. Audit rights
Nuqo makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections (Art. 28(3)(h) GDPR).
Compliance is demonstrated primarily by information provided, by the detailed account of the technical and organisational measures, and by current attestations, certifications or reports of independent bodies. Where those do not suffice in a given case, the Controller may request an on-site audit. It takes place after at least 30 days’ notice in text form, during normal business hours, without disrupting operations, and at most once per calendar year.
Where there is specific cause — in particular a personal data breach at Nuqo or an order of the supervisory authority — the Controller may audit beyond that; the notice period is then shortened to what is reasonable in the circumstances.
Each party bears its own costs. For the effort of an on-site audit going beyond making information available, Nuqo may charge a reasonable fee; this does not apply where the audit reveals a breach by Nuqo. Third parties instructed to carry out the audit must not be competitors of Nuqo and must be bound to confidentiality.
13. Data protection contact
The Controller directs questions on the processing and on personal data to [email protected]; the contact is the management. Nuqo has not designated a data protection officer — the conditions of Art. 37(1) GDPR and § 38(1) BDSG are not currently met. If one is designated, Nuqo will notify the Controller of their name and contact details.