Data Processing Agreement
How Nortra handles personal data on your behalf — jurisdiction by jurisdiction, obligation by obligation.
Frameworks this DPA covers
This addendum is designed to satisfy processor obligations across the major privacy frameworks applicable to B2B SaaS companies operating in the US and EU.
GDPR / UK GDPR
Full Article 28 processor compliance
This DPA satisfies GDPR Article 28 requirements for written contracts with processors. SCCs and the UK IDTA are incorporated for cross-border transfers. EU/UK customers may request a countersigned copy for their records.
CCPA / CPRA
Service provider agreement included
Nortra acts as a "service provider" under CCPA and does not sell or share personal information. The required contractual restrictions preventing secondary use of personal information are contained in this DPA and the Terms of Service.
Texas DPSA
Texas Data Privacy & Security Act
For Texas-based controllers, Nortra acts as a processor under the DPSA. Data processing instructions, purpose limitations, and deletion obligations align with DPSA Chapter 541 requirements.
The full DPA provisions
The provisions below are legally binding and incorporate by reference into the Nortra Terms of Service. This DPA is effective from the date you first activate your Nortra account.
Definitions & scope
This Data Processing Addendum ("DPA") forms part of the Nortra Terms of Service and applies wherever Nortra processes personal data on your behalf as a data processor. "Personal data" has the meaning given in GDPR Article 4(1), UK GDPR, CCPA, and Texas DPSA as applicable.
Roles — controller & processor
You (the customer) are the data controller. Nortra is the data processor. Nortra acts only on your documented instructions and does not sell, share for cross-context behavioural advertising, or use your customer data to train its own AI models.
Nature & purpose of processing
Nortra processes personal data to deliver the platform services described in your subscription: CRM automation, AI-assisted outreach, lead management, workflow execution, analytics, and billing. Processing occurs within AWS us-east-1 (primary) and eu-west-1 (EU customers) regions.
Categories of data & data subjects
Data categories include: contact identifiers (name, email, phone), behavioural data (open, click, reply events), property and transaction data, and communication logs. Data subjects are your prospective and existing clients as imported or generated within the platform.
Sub-processors
Nortra uses approved sub-processors including AWS (infrastructure), Twilio (SMS/voice), Stripe (billing), OpenAI (AI inference), and Resend (email delivery). A current sub-processor list is maintained at nortra.ai/sub-processors. We notify you 30 days before adding a new sub-processor.
International data transfers
Transfers of EU/UK personal data to the United States are covered by the EU Standard Contractual Clauses (SCCs, 2021 edition) and UK International Data Transfer Addendum (IDTA). These are incorporated by reference into this DPA. No derogation from SCCs is claimed.
Security measures (technical & organisational)
Nortra applies: AES-256 encryption at rest, TLS 1.3 in transit, SOC 2 Type II controls, role-based access with MFA enforcement, quarterly penetration testing, and annual third-party security audits. Full ISMS documentation is available on request under NDA.
Data subject rights & assistance
Upon your written request, Nortra will assist you in fulfilling data subject rights requests (access, rectification, erasure, restriction, portability, objection) within 5 business days. Nortra cannot directly respond to data subjects on your behalf without your authorisation.
Personal data breach notification
Nortra will notify you without undue delay, and no later than 72 hours of becoming aware, of a personal data breach affecting your data. Notifications are sent to your registered account email and include: nature of breach, categories affected, likely consequences, and remediation steps taken.
Return & deletion of data
Upon termination of services, Nortra will, at your election, return all personal data in JSON or CSV format or securely delete it within 30 days. Deletion is confirmed in writing. Backup copies are purged within a further 30 days. Legal hold obligations supersede this schedule.
To obtain a countersigned copy of this DPA, or to submit a formal DPA request under GDPR Article 28, email legal@nortra.io. We respond within 5 business days.