Legal

Data processing agreement

Template version: 27 September 2026

This is a template. It takes effect only when signed by the customer and by Nexugen, and forms part of the customer’s agreement with Nexugen. To sign it, email hello@nexugen.app. It is not legal advice; your own counsel should review it.

1. Parties and roles

This agreement is between the customer named in the signature block (the Customer) and Nexugen (Nexugen). For personal data Nexugen processes in providing the service to the Customer, the Customer is the controller and Nexugen is the processor. Where the Customer is itself a processor for someone else, Nexugen is its sub-processor and the Customer passes on these terms.

2. Laws this agreement is written for

This agreement is written to meet the processor requirements of the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, and the Nigeria Data Protection Act 2023 and the rules made under it (together, Data Protection Law). Words such as personal data, processing, controller, processor, data subject and personal data breach have the meaning given in Data Protection Law.

3. What Nexugen processes

  • Subject matter and purpose: building, hosting, running and supporting the Customer’s apps and workspace on Nexugen.
  • Duration: for as long as the Customer uses the service, and then until deletion under section 10.
  • Data subjects: the Customer’s team members, and the Customer’s own users and customers whose data the Customer’s apps hold.
  • Types of personal data: names, email addresses, sign-in details, and any personal data the Customer puts in its prompts, code, files or app databases.
  • Special categories: none are expected. The Customer will not put special category data in the service unless the parties agree in writing how it will be protected.

4. Nexugen’s duties

  • Process personal data only on the Customer’s documented instructions, which are this agreement, the Customer’s agreement with Nexugen, and the Customer’s use of the service. Nexugen will tell the Customer if it believes an instruction breaks Data Protection Law.
  • Make sure everyone at Nexugen who can access the personal data is bound to keep it confidential.
  • Keep the security measures in Annex 2 in place.
  • Help the Customer, as far as it reasonably can, to answer requests from data subjects, and with security, breach notification, data protection impact assessments and consultation with regulators.
  • Not use the personal data to train AI models, and not sell it.

5. Subprocessors

The Customer authorises Nexugen to use the subprocessors listed in Annex 1. Nexugen binds each one to data protection terms no less protective than this agreement and stays responsible for them. Nexugen will tell the Customer at least 30 days before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that time; if the parties cannot resolve the objection, the Customer may end the affected service and receive a refund of fees prepaid for the unused period.

6. International transfers

Some subprocessors are outside the European Economic Area, the United Kingdom and Nigeria (see Annex 1). Where personal data is transferred to a country without an adequacy decision, Nexugen relies on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another transfer mechanism permitted by Data Protection Law, including the conditions for transfers under Part VIII of the Nigeria Data Protection Act 2023.

7. Personal data breaches

Nexugen will tell the Customer without undue delay, and in any case within 72 hours, after confirming a personal data breach affecting the Customer’s personal data. The notice will say what happened, what data and how many people are affected as far as known, the likely consequences, and what Nexugen is doing about it. Nexugen will add information as it learns more.

8. Audits

Nexugen will make available the information reasonably needed to show it meets this agreement, including answers to the Customer’s security questionnaire. Nexugen does not yet hold a third-party security certification or penetration test report. The Customer may audit Nexugen, or have an independent auditor do so, once a year with at least 30 days’ written notice, at the Customer’s cost, during business hours and without access to other customers’ data.

9. Data subject requests

If Nexugen receives a request from one of the Customer’s data subjects, it will pass it to the Customer and not answer it itself unless the Customer asks it to.

10. Return and deletion

When the service ends, the Customer can download its app code and ask for a copy of its other data within 30 days. After that, Nexugen deletes the Customer’s personal data. Copies in backups are deleted as the backups age out, within 14 days, and are not used in the meantime. Nexugen may keep data where the law requires it to.

11. Order of precedence

If this agreement and the Customer’s agreement with Nexugen conflict on data protection, this agreement applies. Liability under this agreement is subject to the limits in the Customer’s agreement with Nexugen.

Annex 1: Subprocessors

As listed on the trust centre on 27 September 2026.

CompanyWhat forWhere
ContaboServer hosting for the platform, its database and the apps it runsEuropean Union
AnthropicAI that plans, writes and reviews app codeUnited States
OpenAIAI for some generation tasksUnited States
GoogleSign in with Google, and AI for some generation tasksGlobal
Cloudflare (R2)File storage for uploads and app assetsGlobal
NeonManaged Postgres databases for apps that need their own databaseUnited States (US East)
GitHubSign in with GitHub, and code repositories when you connect oneUnited States
VercelHosting for apps you choose to deploy thereGlobal
CodemagicBuilding mobile apps for the app storesGlobal
BrevoSending account and notification emailsEuropean Union
PaystackCard payments for Nexugen plans and creditsNigeria
StripeCard payments for Nexugen plansUnited States
CreemCard payments and tax handling for Nexugen plansGlobal
NamecheapRegistering domain names you buy through NexugenUnited States

Annex 2: Security measures

  • Traffic to Nexugen and to hosted apps is encrypted with HTTPS.
  • Secrets the Customer gives Nexugen are encrypted with AES-256-GCM before they are stored.
  • Passwords are hashed with bcrypt. Two-step sign-in is available, and single sign-on on Enterprise.
  • Team roles limit what each person can see and do. Each team has an audit log.
  • The servers accept connections only for the web and for administration over SSH.
  • Apps are checked for known security problems before they go live, and apps on framework versions with known remote-code-execution flaws are not run.
  • The platform database and app databases are backed up nightly and kept 14 days.
  • Live apps are checked every five minutes, and their owners are told when one stops answering.

Signatures

Customer

Name:

Title:

Signature:

Date:

Nexugen

Name:

Title:

Signature:

Date: