← Back to Trust Center

GDPR · Article 28

Data Processing Agreement.

Customers whose use of Nutan involves processing of personal data require a DPA under GDPR Article 28. Contact us to request execution — our team will send a countersigned DPA with 2021 Standard Contractual Clauses incorporated, typically within one business day.

Request a DPA

Email us with your organisation's legal name, jurisdiction of incorporation, and the full name and title of your authorised signer. We'll prepare and return a countersigned DPA.

What's in the DPA

Processor obligations

Full Article 28(3) enumeration — instructions, confidentiality, safeguards, sub-processor control, assistance, deletion or return.

SCCs incorporated

2021 EU Standard Contractual Clauses, Module 2 (Controller-to-Processor), for international transfers.

Security measures

Industry-standard strong encryption, immutable audit logs, standards-based OAuth — full list in the SOC 2 attestation.

Audit rights

Annual attestation reports satisfy the audit right; additional assurance available on reasonable notice.