NEI Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the NEI Terms of Service and is accepted together with them. It is subject to change as described in Section 9.
1. Roles and scope
- For personal data contained in content you submit to the Platform about third parties ("Submitted Data"), you are the controller (or a processor for another controller) and NEI is your processor under GDPR Art. 28.
- For all other personal data (your account, NEI's contact database, audit logs, platform operations), NEI is controller and the NEI Privacy Policy applies - that processing is outside this DPA.
2. Details of processing (Art. 28(3))
- Subject matter / purpose: hosting and making Submitted Data available to transaction participants via the Platform.
- Duration: the term of your Platform relationship plus the retention periods in the retention schedule.
- Nature: storage, display, transmission to authorized counterparties, backup.
- Categories of data subjects: individuals referenced in deal documentation - e.g. counterparties' personnel, advisors, shareholders.
- Categories of data: identification and professional data, contact details, and whatever the submitted documents contain. No special categories are expected; do not submit them.
3. NEI's obligations as processor
NEI will:
- Process Submitted Data only to operate the Platform per the Terms and your use of the Platform's controls (documented instructions), unless required by law. NEI may use Submitted Data in aggregated or de-identified form to maintain, secure, improve and develop the Platform, for NEI's internal purposes only; for such use NEI acts as an independent controller of the aggregated or de-identified data.
- Ensure persons processing the data are bound by confidentiality.
- Implement the technical and organizational measures in Section 6.
- Engage subprocessors only per Section 5.
- Taking into account the nature of processing, assist you with data-subject requests, security, breach notification, and DPIAs (Art. 32-36) as reasonably needed.
- Notify you without undue delay after becoming aware of a personal-data breach affecting Submitted Data.
- At end of provision, delete or return Submitted Data per the retention schedule, unless law requires retention. Note: deleted files may persist in versioned backup storage up to 5 years and rolling database backups up to 7 days before final erasure.
- Make available information necessary to demonstrate compliance with this DPA, in the first instance through written responses to reasonable audit questionnaires (no more than once per year) and NEI's available security documentation. Where that information is demonstrably insufficient to show compliance, or a supervisory authority requires it, NEI will additionally allow an audit or inspection - subject to reasonable prior notice, normal business hours, confidentiality undertakings, no more than once per year, and at your cost unless the audit reveals a material breach of this DPA.
4. Your obligations as controller
You warrant that you have a lawful basis and any required notices and permissions to submit third-party personal data to the Platform, and that your instructions comply with data-protection law.
5. Subprocessors
Current list (authorized on acceptance):
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (Google LLC) | Hosting, database, file storage, logging | United States / EU |
| Google Workspace | Email transmission | United States / EU |
NEI will give 30 days' notice of intended subprocessor changes on the Platform and by email to your account contact; the current list is the one in this DPA, updated with each change. You may object on reasonable data-protection grounds, in which case the parties will discuss in good faith.
Environment disclosure: data, potentially including Submitted Data, may be processed in access-restricted development environments, under the same confidentiality and security controls.
6. Technical and organizational measures (Art. 32)
See the NEI Security Measures page. In summary: invitation-only accounts; two-step sign-in verification (single-use emailed codes) with session idle expiry; role- and stage-based access control on documents; passwords never stored (salted one-way hashes only); integration tokens encrypted at rest; TLS in transit; provider-managed encryption at rest; least-privilege database roles; rate limiting and WAF; access logging for security monitoring; automated backups with deletion protection on the production database.
7. International transfers
Where processing involves transfer outside the EEA/UK, the parties rely on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses (Module 2 or 3, as applicable) incorporated by reference.
8. Liability
This DPA in no way alters the limitations of liability or other legal terms set out in the NEI Terms of Service.
9. Changes to this DPA
This DPA is versioned together with the NEI Terms of Service. Material changes are announced on the Platform and require re-acceptance; the version you accepted remains available to you.