DPA

Data Processing Agreement

Nalloo's GDPR Article 28 data-processing terms for customers: roles, security measures, sub-processors and EU-only data location.

Last updated: 30 June 2026

Scope

1. Purpose and scope

This Data Processing Agreement ("DPA") forms part of the agreement between Nalloo and the customer ("Customer") and applies where Nalloo processes personal data on the Customer's behalf in connection with the Service. It reflects the requirements of Article 28 GDPR. It is a template and should be reviewed by your legal counsel before signing.

Note on Nalloo's model: Nalloo identifies companies, not individuals, and processes visitor IPs hashed without storing personal data. For that identification activity Nalloo acts as an independent controller and typically no DPA is required. This DPA governs the limited personal data Nalloo processes as a processor on the Customer's behalf (for example, account and configuration data).

Definitions

2. Definitions

"Personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR. "Sub-processor" means any processor engaged by Nalloo.

Roles

3. Roles of the parties

The Customer is the controller and Nalloo is the processor for the personal data processed on the Customer's instructions. Each party complies with its obligations under applicable data-protection law.

Details

4. Subject matter and details of processing

Obligations

5. Processor obligations

Breach

6. Personal data breaches

Nalloo will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide the information reasonably required to meet the Customer's obligations.

Sub-processors

7. Sub-processors

Nalloo uses vetted sub-processors under data-processing terms. Current categories: EU cloud hosting, web analytics and payment processing. The current list is available on request at support@nalloo.com. Nalloo will inform the Customer of intended changes and give the opportunity to object on reasonable data-protection grounds.

Security

8. Security measures (TOMs)

Transfers

9. International transfers

Personal data is hosted and processed within the EEA. Where any transfer outside the EEA is necessary, it will be made under an adequacy decision or appropriate safeguards (e.g. Standard Contractual Clauses).

Term

10. Term, deletion and audits

This DPA remains in force while Nalloo processes personal data for the Customer. On termination, Nalloo deletes or returns the data per section 5. The Customer may audit compliance on reasonable prior notice, subject to confidentiality.

Contact

11. Contact and signature

To request the signed DPA or the sub-processor list, contact support@nalloo.com. The processor is Ecofin Cloud S.L. (NIF B66585605), Av. Cerdanyola 92-94, 08173 Sant Cugat del Vallès, Barcelona, Spain.