GDPR · Article 28
Data Processing Agreement.
Customers whose use of Nutan involves processing of personal data require a DPA under GDPR Article 28. Contact us to request execution — our team will send a countersigned DPA with 2021 Standard Contractual Clauses incorporated, typically within one business day.
Request a DPA
Email us with your organisation's legal name, jurisdiction of incorporation, and the full name and title of your authorised signer. We'll prepare and return a countersigned DPA.
What's in the DPA
Processor obligations
Full Article 28(3) enumeration — instructions, confidentiality, safeguards, sub-processor control, assistance, deletion or return.
SCCs incorporated
2021 EU Standard Contractual Clauses, Module 2 (Controller-to-Processor), for international transfers.
Security measures
Industry-standard strong encryption, immutable audit logs, standards-based OAuth — full list in the SOC 2 attestation.
Audit rights
Annual attestation reports satisfy the audit right; additional assurance available on reasonable notice.