Data Processing Addendum
LAST MODIFIED: JUNE 3, 2026This Data Processing Addendum (“DPA”) forms an integral part of the software licensing agreement and Terms of Service between the client (“Customer”) and NextOnus Software (“NextOnus”). This DPA governs the processing of customer personal data by NextOnus.
1. Roles & Scope
For the purposes of the GDPR, CCPA, and DPDP acts:
- Customer: Acts as the Data Controller (the entity determining the purposes and means of processing personal data).
- NextOnus: Acts as the Data Processor (the entity processing personal data solely on behalf of, and on the documented instructions of, the Controller).
2. Approved Sub-processors
Customer authorizes NextOnus to engage sub-processors to perform hosting, payment, and database replication services. A current list of approved sub-processors is maintained below:
| Sub-processor | Service Type | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure & Databases | US East / West / EU Central |
| Vercel Inc. | Edge Routing & UI Hosting | Global Edge Nodes |
| Stripe Inc. | Payment Processing Runtimes | United States |
3. Technical & Organizational Security Measures
NextOnus implements high-grade physical and logical security measures to protect customer data:
- Encryption: AES-256 block encryption at rest, TLS 1.3 encryption in transit.
- Vulnerability Management: Continuous dependency audits and automated static analysis scans.
- Incident Reporting: We commit to notifying customers within 48 hours of detecting any verified data breach affecting Customer personal data.
4. Data Subject Rights Assistance
NextOnus provides API hooks and platform configurations (like isolated data deletion triggers) to assist the Customer in fulfilling data subject access, portability, and deletion requests under applicable regional privacy statutes.