Data Processing Agreement (DPA)

Last updated: 14 July 2026

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

  • Data Controller: The agency, freelancer, or business customer that subscribes to the NudgePort Service ("You", "Controller").
  • Data Processor: NudgePort / Nikali Ltd ("We", "Us", "Processor"), the operator of the NudgePort platform.

This DPA forms part of and is subject to the Terms of Service available at nudgeport.com/terms.

2. Definitions

For purposes of this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR.
  • "Processing" means any operation performed on Personal Data as defined in Article 4(2) GDPR.
  • "Data Subject" means the individual to whom Personal Data relates (e.g., the Controller's client contacts and team members).
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).
  • "Service" means the NudgePort client approval portal, dashboard, APIs, and related features provided to the Controller.

3. Subject Matter, Instructions, and Duration

3.1 Subject Matter

The Processor will process Personal Data on behalf of the Controller solely for the purpose of providing the Service, including (as applicable to the Controller's plan and configuration):

  • Hosting the agency dashboard and rendering the client approval portal (magic-link based, no client account required)
  • Storing project structure, phases, items, external URLs, version labels, and approval decisions
  • Recording client feedback, comments, change requests, and question answers
  • Sending transactional notification emails (portal invites, approval events, verification codes, billing events)
  • Providing exports (PDF summaries, CSV activity) where included in the plan

3.2 Instructions

The Processor shall process Personal Data only on documented instructions from the Controller, including as set out in this DPA, the Terms, and the Controller's configuration and use of the Service, unless otherwise required by applicable EU or Member State law.

3.3 Duration

This DPA remains in effect for the duration of the Controller's subscription and use of the Service, and thereafter for as long as the Processor processes Personal Data on behalf of the Controller under this DPA.

4. Categories of Data and Data Subjects

4.1 Types of Personal Data Processed

Depending on the Controller's configuration and use of the Service, the Processor may process:

  • Names of agency team members and client contacts
  • Email addresses (agency users, invited team members, client contacts)
  • Agency and project metadata (company name, project titles, descriptions, phase labels, statuses)
  • External URLs to third-party content added by the Controller (files, designs, documents hosted elsewhere)
  • Version labels, identifiers, and approval-state metadata
  • Client-submitted feedback: comments, change-request messages, question answers, approval decisions
  • Timestamps of activity (submissions, approvals, portal opens, external-link clicks)
  • Technical metadata used for security and evidencing (e.g., IP address, user agent, device fingerprint)
  • Email delivery status for transactional notifications (accepted/bounced signals where available)
  • Billing and customer identifiers, where applicable (Stripe customer/subscription IDs)

File storage: NudgePort is a link-first platform. Original files (documents, videos, designs, invoices) remain on the third-party services where they are hosted; NudgePort stores only URLs and approval metadata.

The Service is not designed to collect special categories of data (Article 9 GDPR). The Controller must not intentionally submit special category data through the Service, and must not paste passwords or credentials into item descriptions or comments.

4.2 Categories of Data Subjects

  • Agency users (Controller's account holders) and invited team members
  • Client contacts invited by the Controller to review and approve project items
  • Billing and account contacts, where applicable

5. Processor Obligations

The Processor agrees to:

5.1 Confidentiality

Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.2 Security Measures

Implement appropriate technical and organizational measures to protect Personal Data, taking into account the risks of Processing (see Section 6 and Annex 2).

5.3 Sub-processors

Respect the conditions for engaging Sub-processors (see Section 8 and Annex 1).

5.4 Assistance

Assist the Controller, taking into account the nature of Processing, by appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Controller's obligation to respond to requests for exercising Data Subject rights (Articles 12–23 GDPR).

5.5 Security and Breach Support

Assist the Controller in ensuring compliance with obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, and consultations), to the extent applicable and appropriate for the Service.

5.6 End of Processing

At the end of the provision of Services relating to Processing, delete or return Personal Data as described in Section 9 (Retention, Deletion, and Return), unless EU or Member State law requires retention.

5.7 Compliance Information

Make available to the Controller information reasonably necessary to demonstrate compliance with this DPA.

6. Security Measures (TOMs)

The Processor maintains a security program designed to protect Personal Data in accordance with Article 32 GDPR. A summary is provided below; the full Technical and Organizational Measures are set out in Annex 2 of this DPA.

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) at the infrastructure layer
  • Tenant isolation enforced via database Row-Level Security (RLS) policies
  • Role-based access control (agency users, team members, client portal visitors)
  • Hashed, single-use magic-link tokens for client portal access, plus 6-digit one-time email verification code before content is revealed
  • Service-role credentials never exposed to the browser; used only by trusted server functions
  • Audit and activity logs for approvals, comments, version changes, and portal actions
  • Immutable approval records and locked approved versions
  • Rate limiting on client-facing endpoints and the public contact form
  • Automated backups, health monitoring, and incident response procedures

7. Data Subject Rights

7.1 Controller Responsibility

The Controller is responsible for responding to Data Subject requests (Articles 15–22 GDPR) for data processed under this DPA.

7.2 Processor Assistance

The Processor will provide reasonable assistance to the Controller for Data Subject requests relating to the Service, including through available product functionality and/or support channels, taking into account the nature of Processing.

7.3 Direct Requests to Processor

If the Processor receives a request directly from a Data Subject regarding the Controller's data, the Processor will (where legally permitted) refer the Data Subject to the Controller and notify the Controller where appropriate.

8. Sub-processors

8.1 General Authorization

The Controller provides general authorization for the Processor to engage Sub-processors as necessary to provide the Service.

8.2 Sub-processor Obligations

  • Sub-processors are bound by data protection obligations substantially similar to those in this DPA
  • The Processor remains responsible for the performance of Sub-processors to the extent required by GDPR Article 28

8.3 Sub-processor Updates

The Processor will maintain an up-to-date list of Sub-processors (see Annex 1) and will notify the Controller of any intended changes (additions or replacements) at least 30 days in advance via email or dashboard notice.

8.4 Right to Object

The Controller may object to a new or replacement Sub-processor within 14 days of receiving notice. If an objection is raised, the parties will work in good faith to resolve the concern. If the matter cannot be resolved, the Controller may terminate the affected Service component by providing written notice, without penalty, effective at the end of the current billing period.

9. Retention, Deletion, and Return

9.1 Retention (Project and Approval Records)

Project data, items, versions, approval decisions, comments, and activity logs are retained for the duration of the Controller's subscription. The Controller may delete individual projects, items, or client contacts at any time from within the dashboard.

9.2 End of Service

Upon termination of the Controller's subscription or upon Controller request (where applicable), the Processor will delete or return Personal Data within a reasonable period (typically within 30 days), unless:

  • Retention is required by applicable law, or
  • Retention is necessary to establish, exercise, or defend legal claims, or
  • Retention is required for security/fraud prevention and integrity of the Service.

Personal Data retained in encrypted backups is deleted in accordance with the normal backup lifecycle.

9.3 Account and Billing Records

This DPA governs project and client-approval data processed on behalf of the Controller. The Processor may retain certain account and billing records as a separate controller (e.g., for accounting/tax compliance), as described in the Privacy Policy.

10. Data Breach Notification

In the event of a Personal Data breach affecting Personal Data processed under this DPA, the Processor will:

  • Notify the Controller without undue delay and, where feasible, within 72 hours of confirming the breach
  • Provide information reasonably necessary for the Controller to meet its obligations under GDPR Article 33, to the extent such information is available to the Processor
  • Cooperate with the Controller in containment and remediation steps appropriate to the Service
  • Conduct a post-incident review and, where appropriate, provide the Controller with a summary report

11. International Transfers

Personal Data is intended to be processed primarily within the EEA. Where Processing involves transfers outside the EEA, the Processor will ensure appropriate safeguards are in place, such as:

  • European Commission adequacy decisions, and/or
  • Standard Contractual Clauses (SCCs), Controller-to-Processor module (Module 2) as applicable, and/or
  • EU-US Data Privacy Framework (DPF) certification, where the Sub-processor participates, and/or
  • Supplementary technical measures (e.g., encryption, pseudonymization) where required by risk assessment

12. Audit Rights

12.1 Information and Reviews

Upon reasonable request, the Processor will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA.

12.2 On-site Audits

Where the Controller requests an audit beyond documentation review, the parties will cooperate in good faith to agree scope, timing, and safeguards to protect confidentiality and security. Any on-site audit must:

  • Be conducted no more than once per 12 months (unless required by a supervisory authority or due to a confirmed breach),
  • Occur with reasonable advance notice, and
  • Not unreasonably interfere with the Processor's operations.

The Controller bears its own audit costs and may be responsible for the Processor's reasonable costs incurred in supporting the audit.

13. Governing Law

This DPA shall be governed by and construed in accordance with Bulgarian law, and the GDPR, without prejudice to mandatory GDPR provisions.

14. Contact

For questions regarding this DPA, please contact:

NudgePort / Nikali Ltd

Registration Number (UIC): 207724645

VAT Number: BG207724645

Address: 8 Belite Borove St., Gorna Banya, Sofia, Bulgaria

Email: support@nudgeport.com

Website: nudgeport.com

15. Controlling Language

This Agreement is provided in English. The English version is the controlling version. Any translations are for convenience only and have no legal effect.

Annex 1: Authorized Sub-processors

The following Sub-processors are authorized to process Personal Data on behalf of the Controller as part of the Service. Changes are communicated in accordance with Section 8.3–8.4.

Sub-processorPurposeLocationTransfer basis
Supabase Inc.Database hosting, authentication, storage, backend functionsEEA (Frankfurt) / USSCCs (Module 2) + DPF
Resend Inc.Transactional email delivery (portal invites, verification codes, notifications)USSCCs (Module 2) + DPF
Stripe Inc.Subscription payments and invoicing (no project or client-approval PII shared)US / EEASCCs (Module 2) + DPF
Cloudflare, Inc.Application hosting on Cloudflare Workers, CDN delivery, DNS, and edge securityUS / Global edge networkSCCs (Module 2) + DPF
LovableApplication build and deployment platformEEA / USSCCs (Module 2) + DPF

Each Sub-processor's own DPA/privacy documentation is available on their respective websites.

Annex 2: Technical and Organizational Measures (TOMs)

The following measures describe the security controls maintained by the Processor as referenced in Section 6 of this DPA. These measures are reviewed and updated periodically to reflect changes in technology, risk landscape, and regulatory requirements.

A. Encryption

  • In transit: All data transmitted between users, the Service, and infrastructure components is encrypted using TLS 1.2 or higher. HTTPS is enforced on all endpoints with no fallback to unencrypted connections.
  • At rest: All database storage, including backups, is encrypted using AES-256. Encryption keys are managed by the infrastructure provider and are not accessible to application-level code.
  • Secrets management: API keys, webhook secrets, and other credentials are stored in encrypted vaults and are never exposed in client-side code or logs.

B. Access Control

  • Role-Based Access Control (RBAC): The platform distinguishes agency owners, team members, and client portal visitors. Roles are enforced server-side and cannot be escalated from the client.
  • Row-Level Security (RLS): All database tables containing Personal Data enforce row-level security policies at the database engine level. Each agency can access only its own data.
  • Client portal verification: Client portal access requires both a hashed magic-link token and a 6-digit one-time code delivered to the client's email before any content is revealed.
  • Session management: Sessions have defined timeouts. Portal verification cookies are scoped and expire automatically.
  • Rate limiting: Portal actions and the public contact form are rate-limited per IP to mitigate abuse and enumeration.

C. Logging and Audit Trails

  • Activity log: Approvals, change requests, comments, question answers, version changes, portal opens, and external-link clicks are recorded with actor, timestamp, and target.
  • Authentication events: Successful and failed authentication attempts on the agency dashboard are logged.
  • Portal verification events: Verification code issuance and validation events are recorded for forensic analysis.
  • Immutable approval records: Approval decisions and locked approved versions cannot be silently altered.

D. Data Retention and Deletion

  • Project data: Retained for the duration of the Controller's subscription. Controllers may delete projects, items, or client contacts at any time from the dashboard.
  • Portal verification codes: Expired codes are purged automatically via scheduled cleanup.
  • Account deletion: Upon account termination, Personal Data is deleted within a reasonable period (typically within 30 days), except where retention is required by law.
  • Backups: Encrypted backups follow the infrastructure provider's normal lifecycle.

E. Backups and Availability

  • Automated backups: Managed database backups (point-in-time recovery) are provided by the infrastructure provider, encrypted at rest.
  • Redundancy: The Service is hosted on cloud infrastructure with built-in redundancy and edge distribution.
  • Health monitoring: Automated checks monitor availability and error rates; anomalies trigger alerts to the operations team.

F. Incident Response

  • Detection: Security events, anomalous access patterns, and email-delivery anomalies are monitored.
  • Notification: Confirmed Personal Data breaches are notified to affected Controllers without undue delay and, where feasible, within 72 hours of confirmation, with the details necessary for the Controller's own Article 33 obligations.
  • Containment: The platform supports session revocation, portal link revocation, and account suspension to contain active threats.
  • Post-incident review: Confirmed incidents are followed by a root-cause analysis and, where appropriate, a summary report to affected Controllers.

G. Tenant Isolation

  • Database layer: Row-Level Security policies scoped by agency_id prevent cross-tenant data access independently of application logic.
  • Application layer: Server functions verify caller identity and agency membership before returning any project or client data.
  • Defense in depth: Ownership checks are enforced at multiple layers (database policy, server-function membership check, portal token scoping) so that no single failure exposes another tenant's data.

H. Sub-processor Security (Stripe)

  • PCI-DSS Level 1 certification for cardholder data
  • Independent breach notification obligations to NudgePort as its customer
  • Encryption and access controls on all payment data processed through Stripe's infrastructure
  • No project or client-approval PII (client names, emails, comments) is shared with Stripe — Stripe only processes billing and payment information related to the agency's subscription

Annexes last reviewed: 14 July 2026.