Data Processing Agreement

Last updated: July 28, 2026

This agreement (the DPA) applies only when you use Nomos as a business or professional and, in doing so, upload personal data relating to third parties (for example, your employees, clients, or the contact persons named in a tender file). In that case you are the controller and Nomos acts as your processor under Art. 28 GDPR. If you use Nomos as an individual for your own purposes, this DPA does not apply and the Privacy Policy governs instead.

1. Parties and Acceptance

The processor is DETERMOS, operator of the Nomos platform, with address at Avenida de Gibraltar 3, 28903 Getafe (Madrid), España and contact address nomos.servicedesk@gmail.com. The controller is the business or professional customer who accepts the Terms and Conditions.

This DPA forms an integral part of the Terms and Conditions and is accepted together with them. No separate signature is required; if you need a signed copy for your records, write to the address above and we will provide one.

2. Subject Matter, Duration, Nature and Purpose

  • Subject matter: the processing of personal data contained in the content the controller uploads to or generates on the platform.
  • Duration: for as long as the controller's account remains active, plus the period strictly necessary to complete deletion or return of the data.
  • Nature: storage, structuring, automated analysis, generation of derived documents, transcription, translation, and deletion.
  • Purpose: exclusively to provide the contracted features of the platform. Nomos does not use the controller's content for its own purposes, does not sell it, and does not use it to train its own AI models.

3. Types of Data and Categories of Data Subjects

The controller determines what it uploads. Typically: identification and contact details, professional and employment data, and any other data included in the documents processed.

Categories of data subjects: the controller's staff, its clients or suppliers, and third parties named in the documents processed.

Excluded data. The platform is not designed or enabled for special categories of data under Art. 9 GDPR or for data relating to criminal convictions and offences (Art. 10 GDPR). The controller undertakes not to upload them. If it does so regardless, it assumes sole responsibility for that decision.

4. Nomos's Obligations as Processor

Nomos undertakes to:

  • Process the data only on the controller's documented instructions. Use of the platform's features constitutes such instructions. Where a legal obligation requires processing beyond them, Nomos will inform the controller in advance unless the law prohibits it.
  • Ensure that anyone authorized to process the data is bound by a duty of confidentiality.
  • Apply the technical and organizational measures set out in section 7.
  • Not engage another processor without complying with section 5.
  • Assist the controller, taking into account the nature of the processing, in responding to data subjects exercising their rights.
  • Assist the controller with security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to Nomos.
  • At the controller's choice, delete or return the data at the end of the service, in accordance with section 9.
  • Make available the information necessary to demonstrate compliance with these obligations, in accordance with section 10.
  • Inform the controller without undue delay if, in its opinion, an instruction infringes data protection law.

5. Sub-processors

The controller grants general authorization for Nomos to engage the sub-processors listed in section 4 of the Privacy Policy, which is kept up to date and forms part of this DPA: infrastructure and authentication, AI processing, payment processing, frontend hosting, transactional email, and analytics.

Nomos imposes on each sub-processor data protection obligations equivalent to those in this DPA and remains fully liable to the controller for their performance. Before adding or replacing a sub-processor, Nomos will update that list with reasonable advance notice; the controller may object on reasonable data protection grounds and, if no solution is found, terminate the service with a refund of the proportional amount paid for any unused purchased credits.

6. International Transfers

Some sub-processors are located outside the European Economic Area. Those transfers are made under the safeguards described in section 5 of the Privacy Policy — the EU-U.S. Data Privacy Framework and/or the Standard Contractual Clauses approved by the European Commission. Nomos will not transfer the controller's data to a third country under any other basis without informing the controller.

7. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature and risk of the processing, Nomos applies at least the following measures (Art. 32 GDPR):

  • Encryption in transit (TLS) and at rest, provided by the infrastructure.
  • Authentication managed by Firebase Authentication, with verified email and per-account credentials.
  • Logical isolation of each account's and each workspace's data, enforced by access rules at database level.
  • Access to production data limited to the platform's operator, on a need-to-know basis.
  • Data at rest hosted in European data centres, as detailed in the Privacy Policy.
  • Activity logging for operations that consume credits and for security-relevant events.
  • Backups and restore capability provided by the managed infrastructure.

Nomos is operated by a small team and does not hold ISO 27001 or SOC 2 certification. The measures above reflect what is actually implemented, not an aspiration. They may evolve, but never below the level described here.

8. Personal Data Breaches

Nomos will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, providing the information available at that time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where the information cannot be provided all at once, it will be supplied in phases as it becomes available. Notification to the supervisory authority and, where applicable, to data subjects is the controller's responsibility.

9. Return or Deletion of Data

On termination of the service, and at the controller's choice, Nomos will delete or return the personal data processed on its behalf, and will delete any existing copies, unless European Union or Spanish law requires their retention. The controller may export its generated documents from the platform at any time while the account remains active. If the controller does not express a choice, Nomos will proceed to delete the data once the retention periods described in the Privacy Policy have elapsed.

10. Information and Audits

Nomos will make available to the controller the information necessary to demonstrate compliance with Art. 28 GDPR. The controller may audit compliance, by itself or through an auditor it appoints, with reasonable advance notice, during business hours, no more than once a year — except where a breach has occurred or a supervisory authority so requires — and without disrupting the service or compromising the confidentiality of other customers. Audits requested beyond that frequency are at the controller's expense.

11. Controller's Obligations

  • Ensure it has a valid legal basis for the data it uploads and that it has complied with its information duties towards the data subjects.
  • Issue instructions that comply with data protection law.
  • Not upload the categories of data excluded in section 3.
  • Review the documents generated by the platform before using them, as set out in the Terms and Conditions.

12. Liability and Order of Precedence

Each party is liable for the damage caused by processing that infringes the GDPR in accordance with Art. 82 thereof. In the event of a conflict between this DPA and the Terms and Conditions in matters of personal data protection, this DPA prevails. In all other respects the Terms and Conditions apply, including their governing law and jurisdiction clause.