Legal
Data processing agreement
Template version: 27 September 2026
1. Parties and roles
This agreement is between the customer named in the signature block (the Customer) and Nexugen (Nexugen). For personal data Nexugen processes in providing the service to the Customer, the Customer is the controller and Nexugen is the processor. Where the Customer is itself a processor for someone else, Nexugen is its sub-processor and the Customer passes on these terms.
2. Laws this agreement is written for
This agreement is written to meet the processor requirements of the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR and Data Protection Act 2018, and the Nigeria Data Protection Act 2023 and the rules made under it (together, Data Protection Law). Words such as personal data, processing, controller, processor, data subject and personal data breach have the meaning given in Data Protection Law.
3. What Nexugen processes
- Subject matter and purpose: building, hosting, running and supporting the Customer’s apps and workspace on Nexugen.
- Duration: for as long as the Customer uses the service, and then until deletion under section 10.
- Data subjects: the Customer’s team members, and the Customer’s own users and customers whose data the Customer’s apps hold.
- Types of personal data: names, email addresses, sign-in details, and any personal data the Customer puts in its prompts, code, files or app databases.
- Special categories: none are expected. The Customer will not put special category data in the service unless the parties agree in writing how it will be protected.
4. Nexugen’s duties
- Process personal data only on the Customer’s documented instructions, which are this agreement, the Customer’s agreement with Nexugen, and the Customer’s use of the service. Nexugen will tell the Customer if it believes an instruction breaks Data Protection Law.
- Make sure everyone at Nexugen who can access the personal data is bound to keep it confidential.
- Keep the security measures in Annex 2 in place.
- Help the Customer, as far as it reasonably can, to answer requests from data subjects, and with security, breach notification, data protection impact assessments and consultation with regulators.
- Not use the personal data to train AI models, and not sell it.
5. Subprocessors
The Customer authorises Nexugen to use the subprocessors listed in Annex 1. Nexugen binds each one to data protection terms no less protective than this agreement and stays responsible for them. Nexugen will tell the Customer at least 30 days before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that time; if the parties cannot resolve the objection, the Customer may end the affected service and receive a refund of fees prepaid for the unused period.
6. International transfers
Some subprocessors are outside the European Economic Area, the United Kingdom and Nigeria (see Annex 1). Where personal data is transferred to a country without an adequacy decision, Nexugen relies on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another transfer mechanism permitted by Data Protection Law, including the conditions for transfers under Part VIII of the Nigeria Data Protection Act 2023.
7. Personal data breaches
Nexugen will tell the Customer without undue delay, and in any case within 72 hours, after confirming a personal data breach affecting the Customer’s personal data. The notice will say what happened, what data and how many people are affected as far as known, the likely consequences, and what Nexugen is doing about it. Nexugen will add information as it learns more.
8. Audits
Nexugen will make available the information reasonably needed to show it meets this agreement, including answers to the Customer’s security questionnaire. Nexugen does not yet hold a third-party security certification or penetration test report. The Customer may audit Nexugen, or have an independent auditor do so, once a year with at least 30 days’ written notice, at the Customer’s cost, during business hours and without access to other customers’ data.
9. Data subject requests
If Nexugen receives a request from one of the Customer’s data subjects, it will pass it to the Customer and not answer it itself unless the Customer asks it to.
10. Return and deletion
When the service ends, the Customer can download its app code and ask for a copy of its other data within 30 days. After that, Nexugen deletes the Customer’s personal data. Copies in backups are deleted as the backups age out, within 14 days, and are not used in the meantime. Nexugen may keep data where the law requires it to.
11. Order of precedence
If this agreement and the Customer’s agreement with Nexugen conflict on data protection, this agreement applies. Liability under this agreement is subject to the limits in the Customer’s agreement with Nexugen.
Annex 1: Subprocessors
As listed on the trust centre on 27 September 2026.
| Company | What for | Where |
|---|---|---|
| Contabo | Server hosting for the platform, its database and the apps it runs | European Union |
| Anthropic | AI that plans, writes and reviews app code | United States |
| OpenAI | AI for some generation tasks | United States |
| Sign in with Google, and AI for some generation tasks | Global | |
| Cloudflare (R2) | File storage for uploads and app assets | Global |
| Neon | Managed Postgres databases for apps that need their own database | United States (US East) |
| GitHub | Sign in with GitHub, and code repositories when you connect one | United States |
| Vercel | Hosting for apps you choose to deploy there | Global |
| Codemagic | Building mobile apps for the app stores | Global |
| Brevo | Sending account and notification emails | European Union |
| Paystack | Card payments for Nexugen plans and credits | Nigeria |
| Stripe | Card payments for Nexugen plans | United States |
| Creem | Card payments and tax handling for Nexugen plans | Global |
| Namecheap | Registering domain names you buy through Nexugen | United States |
Annex 2: Security measures
- Traffic to Nexugen and to hosted apps is encrypted with HTTPS.
- Secrets the Customer gives Nexugen are encrypted with AES-256-GCM before they are stored.
- Passwords are hashed with bcrypt. Two-step sign-in is available, and single sign-on on Enterprise.
- Team roles limit what each person can see and do. Each team has an audit log.
- The servers accept connections only for the web and for administration over SSH.
- Apps are checked for known security problems before they go live, and apps on framework versions with known remote-code-execution flaws are not run.
- The platform database and app databases are backed up nightly and kept 14 days.
- Live apps are checked every five minutes, and their owners are told when one stops answering.
Signatures
Customer
Name:
Title:
Signature:
Date:
Nexugen
Name:
Title:
Signature:
Date: