← All legal documents

Data Processing Agreement (DPA)

Version 1.1 · 22 July 2026

This agreement, which forms part of the Terms of Service, governs the processing NEMO performs ON BEHALF of the user (the “Controller”) over the personal data of the visitors of their websites and links (art. 28 GDPR). NEMO acts as “Processor”.

1 · Subject matter, duration and nature

Subject matter: click measurement and attribution of leads and sales to their origin. Data processed: click identifiers, irreversibly pseudonymised IP, user-agent, referrer, and lead/sale event identifiers sent by the Controller's platforms. Data subjects: the Controller's visitors and customers. Duration: that of the service contract.

2 · Instructions

The Processor processes the data only on the Controller's documented instructions, materialised in the Service configuration (links created, integrations connected, chosen plan). It will inform the Controller if it considers an instruction to infringe the law.

3 · Confidentiality and security

The Processor ensures the confidentiality of the persons authorised to process the data and applies the measures of art. 32 GDPR, including: encryption in transit, integration credentials encrypted with AES-256-GCM, EU hosting, irreversible IP pseudonymisation (truncated hash with daily salt), per-workspace isolation (RLS) and logging of administrative access.

4 · Sub-processors

The Controller authorises the sub-processors listed in the Privacy Policy (Supabase, Vercel, Upstash, Stripe, Resend), with their locations and transfer mechanisms. The Processor will notify sub-processor changes by email with reasonable advance notice; the Controller may object on justified grounds and, absent an alternative, terminate the service.

5 · Assistance and breach notification

The Processor assists the Controller, taking into account the nature of the processing, in responding to data subject rights and in the obligations of arts. 32 to 36 GDPR. It will notify the Controller without undue delay of any personal data breach it becomes aware of, with the available information.

6 · Deletion and audit

Upon termination of the service, the Processor will delete the personal data processed on behalf of the Controller, unless the law requires its retention. The Processor will make available to the Controller the information necessary to demonstrate compliance with this agreement and will allow reasonable audits, with prior notice and without access to third-party data.

Documentary integrity and proof of consent

Every acceptance of this document is recorded with: the server date and time, the IP address it was accepted from, the browser identifier (user agent), the language it was shown to you in, its version and the SHA-256 hash of the exact text you saw. The full text of each version is kept together with its fingerprint, so it can always be proven what the document you accepted said, word for word.

That record is kept for as long as it may be needed to evidence consent and SURVIVES the closure of your account: when you delete it, the record is detached from your live identity and only the data strictly necessary for that evidence remains. This is the honest counterpart to the controller's duty to be able to demonstrate consent (art. 7.1 GDPR).

Version history

  • 1.1 (2026-07-22): añadida la cláusula de integridad documental y prueba del consentimiento (D-LEGAL-2).
  • 1.0 (2026-07-22): versión inicial.