Data Processing Agreement

Data Processing Agreement

How Nortra handles personal data on your behalf — jurisdiction by jurisdiction, obligation by obligation.

Regulatory coverage

Frameworks this DPA covers

This addendum is designed to satisfy processor obligations across the major privacy frameworks applicable to B2B SaaS companies operating in the US and EU.

GDPR / UK GDPR

Full Article 28 processor compliance

This DPA satisfies GDPR Article 28 requirements for written contracts with processors. SCCs and the UK IDTA are incorporated for cross-border transfers. EU/UK customers may request a countersigned copy for their records.

CCPA / CPRA

Service provider agreement included

Nortra acts as a "service provider" under CCPA and does not sell or share personal information. The required contractual restrictions preventing secondary use of personal information are contained in this DPA and the Terms of Service.

Texas DPSA

Texas Data Privacy & Security Act

For Texas-based controllers, Nortra acts as a processor under the DPSA. Data processing instructions, purpose limitations, and deletion obligations align with DPSA Chapter 541 requirements.

DPA provisions

The full DPA provisions

The provisions below are legally binding and incorporate by reference into the Nortra Terms of Service. This DPA is effective from the date you first activate your Nortra account.

i

Definitions & scope

This Data Processing Addendum ("DPA") forms part of the Nortra Terms of Service and applies wherever Nortra processes personal data on your behalf as a data processor. "Personal data" has the meaning given in GDPR Article 4(1), UK GDPR, CCPA, and Texas DPSA as applicable.

ii

Roles — controller & processor

You (the customer) are the data controller. Nortra is the data processor. Nortra acts only on your documented instructions and does not sell, share for cross-context behavioural advertising, or use your customer data to train its own AI models.

iii

Nature & purpose of processing

Nortra processes personal data to deliver the platform services described in your subscription: CRM automation, AI-assisted outreach, lead management, workflow execution, analytics, and billing. Processing occurs within AWS us-east-1 (primary) and eu-west-1 (EU customers) regions.

iv

Categories of data & data subjects

Data categories include: contact identifiers (name, email, phone), behavioural data (open, click, reply events), property and transaction data, and communication logs. Data subjects are your prospective and existing clients as imported or generated within the platform.

v

Sub-processors

Nortra uses approved sub-processors including AWS (infrastructure), Twilio (SMS/voice), Stripe (billing), OpenAI (AI inference), and Resend (email delivery). A current sub-processor list is maintained at nortra.ai/sub-processors. We notify you 30 days before adding a new sub-processor.

vi

International data transfers

Transfers of EU/UK personal data to the United States are covered by the EU Standard Contractual Clauses (SCCs, 2021 edition) and UK International Data Transfer Addendum (IDTA). These are incorporated by reference into this DPA. No derogation from SCCs is claimed.

vii

Security measures (technical & organisational)

Nortra applies: AES-256 encryption at rest, TLS 1.3 in transit, SOC 2 Type II controls, role-based access with MFA enforcement, quarterly penetration testing, and annual third-party security audits. Full ISMS documentation is available on request under NDA.

viii

Data subject rights & assistance

Upon your written request, Nortra will assist you in fulfilling data subject rights requests (access, rectification, erasure, restriction, portability, objection) within 5 business days. Nortra cannot directly respond to data subjects on your behalf without your authorisation.

ix

Personal data breach notification

Nortra will notify you without undue delay, and no later than 72 hours of becoming aware, of a personal data breach affecting your data. Notifications are sent to your registered account email and include: nature of breach, categories affected, likely consequences, and remediation steps taken.

x

Return & deletion of data

Upon termination of services, Nortra will, at your election, return all personal data in JSON or CSV format or securely delete it within 30 days. Deletion is confirmed in writing. Backup copies are purged within a further 30 days. Legal hold obligations supersede this schedule.

To obtain a countersigned copy of this DPA, or to submit a formal DPA request under GDPR Article 28, email legal@nortra.io. We respond within 5 business days.

Have a legal question we did not answer here?