This document is a template for review purposes and is not yet an executed legal agreement. Company details shown in brackets are placeholders.
Data Processing Agreement
Standard DPA structure for Nulx, scoped to orchestration metadata. Bracketed fields are placeholders pending company details and legal review.
1. Parties
This Data Processing Agreement (“DPA”) is entered into between [Company legal name], [registered address] (“Processor”, “Nulx”) and the customer entity identified in the applicable order form or account registration (“Controller”). This DPA forms part of the Terms of Service between the parties.
2. Scope and subject matter of processing
Processor processes personal data limited to account and billing contact details and job metadata — file keys, durations, encoding parameters, and delivery configuration — solely to provide the video orchestration service described in the Terms of Service.
- Processor does not receive, store, or transmit the Controller's media. Media bytes remain in the Controller's own cloud storage account at all times.
- Processing duration matches the term of the service agreement, plus the retention periods described in the data retention policy.
- {"Nature and purpose": "orchestration of video encoding and playback on infrastructure controlled by the Controller."}
3. Processor obligations
Processor processes personal data only on documented instructions from the Controller, ensures that persons authorized to process the data are bound by confidentiality, and assists the Controller with data subject requests and impact assessments where reasonably required.
4. Security measures
Processor implements technical and organizational measures appropriate to the narrow scope of data it handles, including:
- Scoped IAM access limited to customer-designated storage prefixes, granted by the Controller and revocable at any time.
- Encryption in transit for all service traffic.
- Least-privilege credentials and access logging for production systems.
- Incident notification to the Controller without undue delay after becoming aware of a personal data breach.
5. Subprocessors
Processor engages the subprocessors listed on the Subprocessors page. The Controller will be notified at least 30 days before any addition or replacement takes effect and may object on reasonable data-protection grounds. Processor remains fully liable for the performance of its subprocessors.
6. Deletion and return of data
Upon termination of the service or upon the Controller's documented request, Processor deletes retained personal data — account details and job metadata — within 30 days, except where applicable law requires longer retention. Because media bytes are never in Processor's custody, no media deletion obligation arises on Processor's side.
7. Audit rights
Processor will make available the information reasonably necessary to demonstrate compliance with this DPA and will respond to reasonable written audit questionnaires. On-site inspections may be arranged where required by applicable law, subject to reasonable notice and scope.
8. Governing law and contact
This DPA is governed by the law specified in the Terms of Service, [governing law placeholder]. Data-protection inquiries: [privacy contact placeholder].