Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between Nirvana Network Corporation, a Delaware corporation doing business as Nirvana Labs ("Nirvana"), and the customer identified in that agreement ("Customer") governing Customer's use of Nirvana's cloud infrastructure services (the "Agreement"). It applies to the extent Nirvana processes Personal Data on Customer's behalf in providing the Services.

This DPA is incorporated by reference into the Agreement. Where Customer's use of the Services is governed by Nirvana's online Terms of Service, this DPA takes effect on the date Customer first accepts those Terms. Where the parties have signed this DPA separately, it takes effect on the date of the last signature.

Version 1.0 · Effective · Published at nirvanalabs.io/dpa

1. Definitions

Capitalised terms not defined here have the meaning given in the Agreement.

  • "Account Data" means Personal Data relating to Customer's personnel and users that Nirvana collects to create and administer Customer's account, authenticate users, process payments, provide support and communicate with Customer (for example names, business email addresses, billing details and usage records).
  • "Customer Content" means all data, including Personal Data, that Customer or its end users store, run or transmit on compute, storage, network or Kubernetes resources provisioned through the Services. Customer Content resides within Customer's environment, to which Nirvana has no access.
  • "Customer Personal Data" means Personal Data contained in Customer Content.
  • "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws such as the CCPA/CPRA.
  • "EU SCCs" means the Standard Contractual Clauses approved by European Commission Decision 2021/914 of 4 June 2021.
  • "Personal Data", "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR; the equivalent terms under other Data Protection Laws (such as "business" and "service provider" under the CCPA) are read accordingly.
  • "Resource Metadata" means information about the resources Customer provisions through the Services, such as instance and volume identifiers, sizes and types, network configuration, uptime and utilisation metrics, and billing records. Resource Metadata does not include Customer Content.
  • "Services" means the cloud infrastructure services Nirvana provides to Customer under the Agreement, including bare-metal and virtual compute, block and object storage, networking, Kubernetes, and the Nirvana dashboard and API.
  • "Sub-processor" means any third party engaged by Nirvana to process Customer Personal Data in delivering the Services.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

2. Scope and roles of the parties

2.1 Customer Personal Data. For Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of its own customers) and Nirvana is a Processor (or Sub-processor). Nirvana processes Customer Personal Data only to provide the Services and only on Customer's documented instructions, as set out in section 3.

2.2 Account Data. For Account Data, Nirvana is an independent Controller. Nirvana processes Account Data in accordance with its Privacy Policy at nirvanalabs.io/privacy and Data Protection Laws, and this DPA does not apply to that processing.

2.3 Nature of the Services. The Services are infrastructure. Nirvana provisions compute, storage and network resources; Customer deploys and controls everything on them, including operating systems, applications, credentials, encryption keys and data. Nirvana has no credentials, agents, management interfaces or other means of access into Customer's environment, and cannot read, copy, decrypt or export Customer Content. Nirvana's visibility is limited to Resource Metadata and to the physical and network infrastructure on which Customer's resources run. Nirvana does not determine the purpose or means of processing of Customer Content and does not know whether Customer Content contains Personal Data.

2.4 Customer as Processor. Where Customer uses the Services to provide its own services to third parties (for example as a managed-service or bring-your-own-cloud provider), Customer warrants that it has the authority to appoint Nirvana as a Sub-processor and that its agreements with those third parties permit the processing contemplated by this DPA.

2.5 CCPA. To the extent the CCPA applies, Nirvana acts as a service provider. Nirvana will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship with Customer or for any purpose other than providing the Services, or combine it with Personal Data from other sources except as permitted by the CCPA. Nirvana certifies that it understands these restrictions.

3. Customer obligations and instructions

3.1 Instructions. Customer's complete and final instructions to Nirvana for the processing of Customer Personal Data are: (a) processing to provide the Services as described in the Agreement and the documentation; (b) processing initiated by Customer or its users through the Services; and (c) any further written instructions Customer gives that are consistent with the Agreement. Nirvana will notify Customer if it considers an instruction infringes Data Protection Laws, without any obligation to review Customer's processing for compliance.

3.2 Lawful basis. Customer is responsible for the accuracy, quality and legality of Customer Personal Data, for the means by which it was obtained, and for ensuring it has all consents, notices and legal bases required to transfer Customer Personal Data to Nirvana and to have it processed under this DPA.

3.3 Customer security. Customer is responsible for securing its own environment on the Services, including operating systems, applications, encryption of Customer Content, access credentials, firewall and network configuration, and backups. Customer will not place on the Services any Customer Personal Data that requires security measures beyond those in Annex 2 unless agreed in writing.

3.4 Restricted data. Customer will not use the Services to process protected health information under HIPAA, payment card data subject to PCI DSS, or other data subject to sector-specific regulation unless Nirvana has agreed in writing to the applicable requirements.

4. Nirvana obligations

4.1 Processing on instructions. Nirvana will process Customer Personal Data only on Customer's documented instructions under section 3.1, unless required to do otherwise by law. In that case Nirvana will inform Customer of the legal requirement before processing, unless the law prohibits doing so.

4.2 Confidentiality. Nirvana will ensure that personnel authorised to process Customer Personal Data are bound by written confidentiality obligations and receive appropriate data protection training. Nirvana limits access to Customer Personal Data to personnel who need it to perform the Services.

4.3 Assistance. Taking into account the nature of the processing and the information available to Nirvana, Nirvana will provide reasonable assistance to Customer in meeting its obligations under Data Protection Laws relating to security, breach notification, data protection impact assessments and prior consultation with Supervisory Authorities. Nirvana may charge a reasonable fee for assistance that exceeds what is customary for infrastructure services.

4.4 No access to Customer Content. Nirvana does not access Customer Content, and the Services are not designed to give Nirvana the ability to do so. Nirvana's operation, maintenance and security of the Services is performed at the infrastructure layer using Resource Metadata only. Nirvana does not use Customer Content for any purpose, including to train machine learning models. If Customer asks Nirvana to assist with a support matter that would require access to Customer's environment, Customer must grant that access expressly and may revoke it at any time; any such access is limited to the scope and duration Customer specifies.

4.5 Records. Nirvana will maintain records of its processing activities as required by Article 30 of the GDPR and make them available to a Supervisory Authority on request.

5. Security measures

5.1 Measures. Nirvana will implement and maintain the technical and organisational measures described in Annex 2 to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Nirvana may update those measures from time to time provided the updates do not materially reduce the overall level of protection.

5.2 Shared responsibility. Nirvana's measures apply to the physical infrastructure, the hypervisor and network layer, the control plane, and the Nirvana dashboard and API. Security of everything Customer deploys on the Services, including guest operating systems, applications, data encryption within Customer's environment and user access management, is Customer's responsibility.

5.3 Compliance program. Nirvana maintains a SOC 2 Type II compliance program covering the Services and will make its most recent report available to Customer under section 10.

6. Sub-processors

6.1 Current position. Nirvana does not engage any Sub-processor to process Customer Personal Data. No third party has logical access to Customer Content. Third-party data center and hosting providers have physical custody of the hardware on which the Services run but no access to, and perform no operations on, Customer Content; Nirvana does not treat them as Sub-processors. Vendors supporting Nirvana's dashboard, billing and support functions process Account Data only, for which Nirvana is the Controller, and are covered by Nirvana's Privacy Policy. Sections 6.2 to 6.4 apply if Nirvana proposes to engage a Sub-processor in the future, and Customer gives general written authorisation for that engagement subject to those sections.

6.2 Notice of changes. Nirvana will give Customer at least 30 days' written notice (by email to the account administrator or by notice in the dashboard) before authorising a new Sub-processor to process Customer Personal Data.

6.3 Objection. Customer may object to a new Sub-processor on reasonable data protection grounds by notifying Nirvana in writing within the 30-day notice period. The parties will discuss the objection in good faith. If Nirvana cannot reasonably accommodate the objection, Customer may terminate the affected Services on written notice without penalty, and Nirvana will refund any prepaid fees for the terminated Services covering the period after termination.

6.4 Sub-processor obligations. Nirvana will impose on each Sub-processor data protection obligations no less protective than those in this DPA, to the extent applicable to the services the Sub-processor provides, and remains liable to Customer for the performance of each Sub-processor's obligations.

7. Personal Data Breach notification

7.1 Notification. Nirvana will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data on Nirvana's infrastructure. Notice will be sent to the email address of Customer's account administrator.

7.2 Content. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Nirvana may provide this information in phases as it becomes available.

7.3 Scope. Nirvana's obligation under this section applies to breaches of Nirvana's own systems and controls. Incidents arising within Customer's environment on the Services (for example a compromised guest operating system or leaked Customer credentials) are Customer's responsibility to detect and report, though Nirvana will provide reasonable assistance on request.

7.4 No admission. Notification of a breach is not an acknowledgement by Nirvana of fault or liability.

8. Data Subject requests and assistance

8.1 Requests. Nirvana has no access to Customer Content and cannot identify, retrieve, correct or delete any particular Personal Data within it. Customer is solely responsible for responding to Data Subject requests to access, correct, delete, restrict or port Customer Personal Data, using the tools within its own environment.

8.2 Redirection. If Nirvana receives a request from a Data Subject relating to Customer Personal Data, Nirvana will not respond except to direct the Data Subject to Customer, unless required by law. Nirvana will notify Customer of the request without undue delay where it can identify Customer from the request.

8.3 Assistance. Where Customer cannot fulfil a request using the Services alone, Nirvana will provide reasonable assistance on written request, taking into account the nature of the processing.

8.4 Government requests. If a law enforcement or government authority requests Customer Personal Data from Nirvana, Nirvana will direct the authority to Customer and will notify Customer before responding, unless legally prohibited. Nirvana has no ability to selectively produce Customer Content and will not attempt to do so. Nirvana will disclose only what it is legally compelled to disclose, limited to Resource Metadata or Account Data where possible, and will challenge requests it considers unlawful or overly broad.

9. Data location and international transfers

9.1 Location. Nirvana hosts the Services exclusively in data centers located in the United States. Customer Personal Data is stored and processed in the United States. Customer acknowledges that use of the Services involves a transfer of Customer Personal Data to the United States.

9.2 EU transfers. Where Customer Personal Data is subject to the EU GDPR and transferred to Nirvana in the United States, the EU SCCs are incorporated into this DPA and apply as follows:

  • Module Two (controller to processor) applies where Customer is a Controller; Module Three (processor to processor) applies where Customer is a Processor.
  • Clause 7 (docking clause) applies.
  • Clause 9, Option 2 (general written authorisation) applies, with the notice period in section 6.2.
  • Clause 11(a), the optional language, does not apply.
  • Clause 13: the Supervisory Authority is that of the EU member state in which Customer (or Customer's controller) is established.
  • Clause 17, Option 1: the governing law is the law of Ireland. Clause 18: the courts of Ireland.
  • Annex I.A: Customer is the data exporter; Nirvana is the data importer. Annex I.B is completed by Annex 1 of this DPA. Annex II is completed by Annex 2. Annex III is completed by Annex 3.

9.3 UK transfers. Where Customer Personal Data is subject to the UK GDPR, the UK Addendum is incorporated and applies to the EU SCCs as completed above. For Tables 1 to 3 of the UK Addendum, the parties, selected modules and annexes are as set out in section 9.2 and the Annexes. For Table 4, either party may end the UK Addendum as set out in section 19 of it.

9.4 Swiss transfers. Where Customer Personal Data is subject to the Swiss FADP, the EU SCCs apply with the following amendments: references to the GDPR are read as references to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent Supervisory Authority; and Data Subjects in Switzerland may enforce their rights in Switzerland.

9.5 Alternative mechanism. If a transfer mechanism in this section is invalidated or replaced, the parties will cooperate in good faith to adopt a replacement mechanism. If Nirvana later certifies under the EU-U.S. Data Privacy Framework, that certification will apply in addition to the EU SCCs.

9.6 Precedence. If the EU SCCs or UK Addendum conflict with this DPA, the EU SCCs or UK Addendum prevail for the transfers they govern.

10. Audits, certifications and reports

10.1 Reports. On written request, and no more than once per year, Nirvana will provide Customer with its most recent SOC 2 Type II report (or, if the report is not yet issued, the auditor's engagement letter or bridge letter) and responses to a reasonable security questionnaire. These materials are Nirvana's Confidential Information and are provided subject to the confidentiality terms of the Agreement.

10.2 Audit rights. Customer accepts that the materials in section 10.1 satisfy its right to audit under Data Protection Laws except where (a) a Supervisory Authority requires an audit, (b) a Personal Data Breach affecting Customer Personal Data has occurred, or (c) the report reveals a material deficiency relevant to Customer. In those cases Customer or an independent auditor bound by confidentiality may audit Nirvana's relevant controls on 30 days' written notice, during business hours, no more than once per year, and at Customer's cost. Audits may not access other customers' data or Nirvana's facilities without Nirvana's consent.

10.3 Third-party providers. Nirvana's data center, hosting and control-plane vendors are assessed through Nirvana's vendor management program, including review of their SOC 2, ISO 27001 or equivalent reports. Nirvana does not disclose the identity of those vendors in this DPA and will share their assurance reports only where its agreements with them permit and Customer has a demonstrated need.

11. Deletion and return of Customer Personal Data

11.1 During the term. Customer may retrieve, modify and delete Customer Content at any time through the Services. Deletion of a storage volume, instance or object through the Services results in the data being made unrecoverable to Customer immediately and overwritten on Nirvana's storage systems in the ordinary course.

11.2 On termination. Customer is responsible for exporting Customer Content before the Agreement ends. Nirvana will delete all Customer Content, including Customer Personal Data, within 30 days after termination or expiry of the Agreement, unless retention is required by law. Nirvana does not provide a data-return service beyond the retrieval tools available through the Services.

11.3 Backups and logs. Customer Personal Data held in Nirvana's system backups or operational logs will be deleted in accordance with Nirvana's retention schedule, no later than 90 days after termination, and will not be restored except as required to meet a legal obligation.

11.4 Certification. On written request, Nirvana will confirm in writing that deletion under this section has been completed.

12. Liability, term, precedence and general

12.1 Liability. Each party's liability arising out of or related to this DPA, including the EU SCCs and UK Addendum, is subject to the exclusions and limitations of liability in the Agreement. Nothing in this section limits liability to Data Subjects under the EU SCCs or liability that cannot be limited by law.

12.2 Term. This DPA remains in effect for as long as Nirvana processes Customer Personal Data under the Agreement and until all Customer Personal Data has been deleted under section 11.

12.3 Precedence. If this DPA conflicts with the Agreement, this DPA prevails as to the processing of Customer Personal Data. Section 9.6 governs conflicts with the EU SCCs and UK Addendum.

12.4 Changes. Nirvana may update this DPA to reflect changes in Data Protection Laws or the Services by publishing a revised version at nirvanalabs.io/dpa with at least 30 days' notice. Changes will not materially reduce the protections in this DPA.

12.5 Governing law. Except as required by the EU SCCs or UK Addendum, this DPA is governed by the governing law of the Agreement. If the Agreement specifies none, the laws of the State of Delaware apply, excluding its conflict-of-laws rules.

12.6 Severability. If any provision of this DPA is held invalid, the remaining provisions continue in effect and the invalid provision will be replaced by a valid one that most closely reflects the parties' intent.

12.7 Contacts. Notices to Nirvana under this DPA, including security, privacy and Personal Data Breach matters, are addressed to Nirvana's Chief Operating Officer and submitted through the security contact form at nirvanalabs.io/contact or by post to the address on the signature page. Where the parties have signed this DPA separately, the email address stated on the signature page may also be used. Notices to Customer are sent to the email address of Customer's account administrator unless Customer designates a different contact in writing.

Annex 1 — Details of processing

This Annex completes Annex I.B of the EU SCCs and Table 3 of the UK Addendum.

Details of processing
ItemDescription
Subject matterProvision of cloud infrastructure services (compute, storage, networking, Kubernetes) on which Customer runs its own workloads.
DurationThe term of the Agreement plus the deletion period in section 11.
Nature of processingStorage and transmission of Customer Content on infrastructure Nirvana operates, without access to its contents. Nirvana's processing is limited to provisioning, running, networking and physically hosting the resources Customer uses. Nirvana does not read, access, analyse or use Customer Personal Data.
PurposeTo provide the Services to Customer in accordance with the Agreement.
Categories of Data SubjectsDetermined by Customer. May include Customer's end users, customers, employees, contractors and suppliers, and any other individuals whose data Customer places on the Services.
Categories of Personal DataDetermined by Customer. Any Personal Data Customer chooses to store or process on the Services. Nirvana does not control or monitor the categories.
Sensitive dataCustomer may not place sensitive or special-category data on the Services unless Customer applies encryption and access controls within its environment appropriate to that data. See section 3.4.
FrequencyContinuous for the duration of the Services.
RetentionNone. See section 11.
Sub-processor transfersSee Annex 3. Nature and duration are the same as for Nirvana's own processing.
Competent Supervisory AuthorityDetermined under section 9.2 (Clause 13).

Annex 2 — Technical and organisational measures

This Annex completes Annex II of the EU SCCs. The measures below apply to Nirvana's infrastructure, control plane and corporate systems. Customer is responsible for equivalent measures within its own environment on the Services.

Physical security. The Services run on infrastructure hosted in United States data centers through a third-party infrastructure provider. Nirvana relies on the provider's controls for physical and environmental security and reviews the provider's SOC 2 Type II or equivalent certification under its vendor management program. The provider has no logical access to Customer Content.

Tenant isolation. Customer workloads run on dedicated bare-metal servers or in hypervisor-isolated virtual machines. Storage volumes are logically isolated per tenant. Network traffic is segmented per customer using VLANs or equivalent, and customers cannot reach other customers' resources.

Encryption. Data in transit to and within the Nirvana dashboard and API is encrypted with TLS 1.2 or higher. Storage systems support encryption at rest; Customer is responsible for encrypting Customer Content within its environment where its risk assessment requires it.

Access control. Access to production infrastructure and the control plane is limited to named engineers on a least-privilege basis, authenticated with single sign-on and hardware-backed multi-factor authentication, and reviewed at least quarterly. Shared accounts are prohibited. Access is revoked on the day of role change or departure.

Logging and monitoring. Administrative actions on production systems and the control plane are logged centrally and retained for at least 12 months. Security events are monitored with automated alerting, and intrusion detection is enabled on cloud control-plane components.

Vulnerability management. Production systems and application dependencies are scanned continuously for vulnerabilities. Critical and high vulnerabilities are remediated within defined SLAs. Dependency updates on application repositories are automated.

Change management. Changes to production code and infrastructure configuration go through version control, peer review and automated testing before deployment. Emergency changes are documented and reviewed after the fact.

Endpoint security. Nirvana-issued devices are managed through mobile device management with full-disk encryption, automatic screen lock, endpoint protection and enforced OS updates.

Personnel. All personnel complete background screening where legally permitted, sign confidentiality agreements, and complete security awareness training at onboarding and annually.

Business continuity. Control-plane databases are backed up daily with point-in-time recovery on a managed database service. Nirvana maintains an incident response plan and a business continuity plan. Backup and recovery of Customer Content within Customer's environment is Customer's responsibility.

Vendor management. Sub-processors and other vendors are risk-tiered and reviewed before onboarding and at least annually, including review of their SOC 2 or equivalent reports and data protection terms.

Assurance. Nirvana maintains a SOC 2 Type II program with continuous control monitoring. The current report is available under section 10.

Annex 3 — Sub-processors

This Annex completes Annex III of the EU SCCs and Table 3 of the UK Addendum.

Sub-processors: none. Nirvana does not engage any third party to process Customer Personal Data. Customer Content resides on infrastructure to which only Nirvana's authorised personnel have logical access, and Nirvana itself has no access to the content of Customer's environment (section 2.3).

Third-party data center and hosting providers supply physical facilities, racks, power and network connectivity in the United States. They have physical custody of hardware but no logical access to any system or data, and are not Sub-processors. Vendors supporting the Nirvana dashboard, authentication, billing and support process Account Data only and are listed in Nirvana's Privacy Policy at nirvanalabs.io/privacy.

If Nirvana engages a Sub-processor in the future, it will be notified under section 6.2 and added to this Annex.

Signature page

This signature page is used only where the parties execute this DPA as a standalone document. Where Customer accepts Nirvana's online Terms of Service, this DPA is incorporated by reference and no signature is required.

Signature page
Nirvana Network CorporationCustomer
Legal nameNirvana Network Corporation
Signature
Name
TitleCOO
Date
Address for noticesNirvana Network Corporation, 201 N Illinois St Ste 1600, Indianapolis, IN 46204-4218, United States
Email for noticesAttn: Chief Operating Officer — [email inserted in signed copies only]