Skip to main content

Security

Data Processing Agreement (DPA)

GDPR-compliant DPA template. Pre-signed by Codivion, ready for your legal team's review.

For customers processing personal data of EU/UK/Switzerland residents, NookDocs offers a Data Processing Agreement (DPA) that complies with GDPR Article 28 + UK GDPR + Swiss FADP.

How to get the DPA

  1. Email accounts@codivion.com from the address on file with your NookDocs org

  2. Subject: DPA request for <Your Company>

  3. We send back a pre-signed PDF DPA + Standard Contractual Clauses (SCCs) for international transfers

  4. Your legal team reviews → countersign and return one copy

  5. Effective date = the date both parties sign

Turnaround: 48-72 hours for the pre-signed copy.

What the DPA covers

  • Roles: NookDocs is the data processor; you are the data controller

  • Subject matter: docs content, account metadata, usage telemetry, member identifiers

  • Duration: term of your NookDocs subscription + 30 days post-termination

  • Sub-processors: enumerated list (see below)

  • Security: TLS 1.2+, AES-256 at rest, RLS-enforced isolation

  • International transfers: SCCs (EU-approved 2021 set) + UK addendum + Swiss addendum

  • Breach notification: within 72 hours of discovery

  • Data subject rights: assistance with access / rectification / erasure / portability requests

  • Audit rights: customer audit on reasonable notice (max 1/year)

  • Sub-processor changes: 14-day notice + customer right to object

Current sub-processors

Sub-processorPurposeRegion
Vercel Inc.Application hosting + edge runtimeGlobal (request routing)
Supabase Inc.Database + auth + object storageus-east-1
Cloudflare Inc.TLS edge + SSL provisioning for custom domainsGlobal
Third-party LLM API gatewayAI assistant + writing-agent inference (plan-included AI)Global
Stripe Inc.Payment processingus, eu (per customer location)
GitHub Inc.Source repo storage (when using managed-repo flow)us

Adding a new sub-processor triggers a 14-day notice + the customer right to object. We never silently add sub-processors.

What's outside the DPA

  • Free-tier orgs use the same security controls but the DPA is a paid-tier deliverable. Free orgs operate under the standard Terms of Service.

  • Marketing communications (newsletter, blog) are governed by our Privacy Policy, not the DPA.

Was this page helpful?

Last updated August 9, 2026