This Data Processing Addendum ("DPA") forms part of the Master Services Agreement or Terms of Service (the "Agreement") between Nomisma LLC ("Nomisma", "we", "us") and the entity agreeing to these terms ("Customer", "you") for the provision of Actaa AI services.
---
01 Definitions
1.1 Defined Terms
| Term | Definition |
|---|---|
| AI Services | Actaa's artificial intelligence features including chat, retrieval, summarization, and content generation capabilities. |
| Customer Data | Any data, content, or information uploaded, submitted, or created by Customer or its Authorized Users within the Actaa platform. |
| Personal Data | Any information relating to an identified or identifiable natural person as defined under applicable Data Protection Laws. |
| Processing | Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion. |
| Data Protection Laws | All applicable laws relating to data protection and privacy, including GDPR, CCPA, and other relevant regulations. |
| Sub-processor | Any third party engaged by Nomisma to process Customer Data on behalf of Customer. |
| Data Controller | The entity that determines the purposes and means of processing Personal Data. |
| Data Processor | The entity that processes Personal Data on behalf of the Data Controller. |
| Authorized Users | Customer's employees, contractors, or agents authorized to access Actaa services. |
| Security Incident | Any unauthorized access, acquisition, use, or disclosure of Customer Data. |
1.2 Roles and Responsibilities
- Customer is the Data Controller for Customer Data
- Nomisma is the Data Processor for Customer Data when providing AI Services
- LLM Providers are Sub-processors engaged by Nomisma
---
02 Scope of Processing
2.1 Purpose of Processing
Nomisma processes Customer Data solely to provide AI Services as described in the Agreement, including:
| Processing Activity | Purpose | Data Categories |
|---|---|---|
| Query Processing | Respond to user questions and commands | Query text, user identifiers |
| Context Retrieval | Find relevant information to answer queries | Task content, project data, documents, wiki pages |
| Embedding Generation | Create vector representations for semantic search | Text content from indexed items |
| Response Generation | Generate AI-powered responses | Retrieved context, conversation history |
| Usage Metering | Track token consumption for billing | Query/response tokens, timestamps |
| Quality Assurance | Monitor and improve service quality | Anonymized usage patterns, error logs |
2.2 Categories of Data Subjects
- Customer's employees and contractors
- Customer's clients or customers (if data is stored in Actaa)
- Any individuals referenced in Customer Data
2.3 Duration of Processing
Processing continues for the duration of the Agreement plus:
- 30 days for data deletion after termination
- 7 years for anonymized billing records (legal requirement)
- Immediate removal from AI index upon data deletion
---
03 Customer Controls
3.1 Data Source Configuration
Customer administrators control which data sources are accessible to AI:
| Data Source | Default State | Admin Control |
|---|---|---|
| Tasks & Projects | Enabled | Can disable |
| Documents & Files | Disabled | Opt-in |
| Wiki Pages | Disabled | Opt-in |
| Meeting Notes | Disabled | Opt-in |
| Time-Off Records | Disabled | Opt-in (restricted) |
| Performance Data | Disabled | Opt-in (restricted) |
Access: Settings → AI → Data Sources
3.2 User Permissions
Customer can configure AI access at the user level:
- Enable/Disable AI for individual users
- Restrict to Open Mode (no company data access)
- Set conversation retention periods
- View usage per user
3.3 Conversation History
Customer controls conversation data retention:
| Setting | Options | Default |
|---|---|---|
| Retention Period | 30, 60, 90, 180, 365 days | 90 days |
| User Self-Delete | Enable/Disable | Enabled |
| Export Conversations | Enable/Disable | Enabled |
3.4 Data Deletion Rights
Customer may request deletion of:
- All AI conversation history
- All embedded vectors
- All usage logs (except billing records)
Process: Submit request via Settings → AI → Data Management or email info@actaa.ai
---
04 Nomisma's Obligations
4.1 Processing Instructions
Nomisma shall:
- Process Customer Data only in accordance with Customer's documented instructions
- Not process Customer Data for any purpose other than providing AI Services
- Not sell, rent, or share Customer Data with third parties for their own purposes
- Promptly inform Customer if any instruction violates Data Protection Laws
4.2 Confidentiality
Nomisma shall:
- Ensure all personnel processing Customer Data are bound by confidentiality obligations
- Limit access to Customer Data to personnel who require access to perform AI Services
- Maintain access logs for audit purposes
4.3 Security Measures
Nomisma implements the following technical and organizational measures:
Technical Controls:
- Encryption at rest (AES-256-GCM for API keys, cloud provider encryption for databases)
- Encryption in transit (TLS 1.2+)
- Multi-tenant data isolation
- Automatic PII scrubbing (3-layer defense)
- Regular security assessments
Organizational Controls:
- Employee background checks
- Security awareness training
- Incident response procedures
- Access control policies
- Vendor security assessments
4.4 Audit Rights
Upon reasonable notice (minimum 30 days), Customer may:
- Request SOC 2 Type II reports
- Submit security questionnaires
- Request evidence of compliance controls
- Conduct remote security assessments (Enterprise plans)
On-site audits available for Enterprise customers by separate agreement.
4.5 Data Subject Requests
Nomisma shall:
- Assist Customer in responding to data subject access requests (DSARs)
- Provide self-service tools for data export and deletion
- Respond to Customer requests within 30 days
- Not respond directly to data subjects without Customer authorization
4.6 Security Incident Notification
In the event of a Security Incident affecting Customer Data:
| Timeline | Action |
|---|---|
| Within 48 hours | Notify Customer of incident discovery |
| Within 72 hours | Provide preliminary incident details |
| Within 7 days | Provide full incident report |
| Ongoing | Updates until incident is resolved |
Notification includes:
- Nature and scope of the incident
- Categories of data affected
- Likely consequences
- Measures taken or proposed
---
05 Sub-processors
5.1 Authorized Sub-processors
Customer authorizes Nomisma to engage the following Sub-processors:
| Sub-processor | Purpose | Data Location | Data Processed |
|---|---|---|---|
| Amazon Web Services — Amazon Bedrock | AI model inference (Anthropic Claude family of models) | USA (us-east-1) | AI inputs and outputs (transient inference only; not retained beyond the request, not used to train models) |
| Amazon Web Services — infrastructure (RDS, S3, EC2, Cognito, SES, KMS, CloudFront, CloudTrail) | Hosting, storage, compute, identity, outbound email, encryption, content delivery, audit logging | USA (us-east-1) | All Customer Data |
| Stripe, Inc. | Payment processing | USA | Billing contact and charge metadata only (card numbers stored by Stripe, not by Nomisma) |
5.2 Sub-processor Obligations
Nomisma ensures each Sub-processor:
- Is bound by data protection obligations no less protective than this DPA
- Implements appropriate technical and organizational security measures
- Processes data only as necessary to provide their specific service
- Deletes or returns data upon termination of their engagement
5.3 Sub-processor Changes
Notification Process:
- Nomisma will notify Customer at least 30 days before engaging a new Sub-processor
- Notification via email to Customer's designated contact and in-app notice
- Customer may object to new Sub-processors within 14 days
Objection Process:
- If Customer objects, parties will discuss concerns in good faith
- If concerns cannot be resolved, Customer may terminate AI Services without penalty
- Objection must be based on reasonable data protection grounds
5.4 Current Sub-processor List
The current list of Sub-processors is maintained at:
Subscribe to updates: Settings → Legal → Sub-processor Notifications
---
06 Data Deletion
6.1 During Subscription
Customer may delete AI data at any time:
| Data Type | Deletion Method | Timeline |
|---|---|---|
| Single conversation | User self-service | Immediate |
| All user conversations | Admin dashboard | Within 24 hours |
| All company AI data | Support request | Within 7 days |
| Source data | Standard deletion | Removed from AI index within 24 hours |
6.2 Upon Termination
Upon termination or expiration of the Agreement:
| Action | Timeline |
|---|---|
| AI Services disabled | Immediate |
| Conversation history deleted | Within 30 days |
| Embedded vectors purged | Within 30 days |
| Usage logs anonymized | Within 30 days |
| Billing records retained | 7 years (legal requirement) |
6.3 Deletion Certification
Upon request, Nomisma will provide written certification of data deletion within 45 days of the deletion deadline.
6.4 Exceptions
The following data may be retained beyond deletion timelines:
- Data required by law or legal process
- Anonymized and aggregated statistics
- Backup data (purged within standard backup rotation, maximum 90 days)
---
07 Security Measures
7.1 Technical Measures
Access Control:
- Role-based access control (RBAC)
- Multi-factor authentication for all systems
- Unique user credentials
- Automatic session timeouts
- Privileged access management
Encryption:
- TLS 1.2+ for all data in transit
- AES-256-GCM for API key encryption
- Cloud provider encryption for data at rest
- Key management with rotation policies
Network Security:
- Web Application Firewall (WAF)
- DDoS protection
- Network segmentation
- Intrusion detection systems
- Regular penetration testing
Application Security:
- Secure development lifecycle (SDLC)
- Code reviews for all changes
- Dependency vulnerability scanning
- Input validation and sanitization
- Output encoding
7.2 Organizational Measures
Personnel Security:
- Background checks for employees with data access
- Confidentiality agreements
- Security awareness training (annual)
- Role-based access provisioning
- Prompt deprovisioning on termination
Incident Management:
- 24/7 security monitoring
- Documented incident response plan
- Regular incident response drills
- Post-incident reviews
Business Continuity:
- Regular data backups
- Disaster recovery procedures
- Geographic redundancy
- Recovery time objectives (RTO) < 4 hours
- Recovery point objectives (RPO) < 1 hour
7.3 Compliance Certifications
Nomisma's current compliance posture:
| Framework | Status | Notes |
|---|---|---|
| SOC 2 Type II | Not certified — controls mapped, in preparation | No audit has been completed; no report is available |
| ISO 27001 | Not certified | — |
| GDPR | Self-attested; data-subject-rights tooling (data export and erasure) implemented | DPA (this document) |
| CCPA | Self-attested | Privacy Policy |
Note: the underlying AWS infrastructure Nomisma runs on is independently certified by AWS (SOC 1/2/3, ISO/IEC 27001/27017/27018, PCI DSS); those are AWS's certifications, not Nomisma's.
---
08 International Transfers
8.1 Data Location
Customer Data is processed and stored in:
- Primary: United States (AWS us-east-1)
- Backups: United States
8.2 Transfer Mechanisms
For transfers of Personal Data from the EEA, UK, or Switzerland to the United States, Nomisma relies on:
Standard Contractual Clauses (SCCs):
- EU Commission approved SCCs (Module 2: Controller to Processor)
- UK International Data Transfer Addendum
- Swiss Federal Data Protection Act addendum
The SCCs are incorporated by reference and available upon request.
8.3 Additional Safeguards
In addition to SCCs, Nomisma implements:
- Encryption of Personal Data in transit and at rest
- Data minimization (only necessary data transferred)
- Access controls limiting who can access Personal Data
- Regular review of data access requests
- Transparency reports regarding government requests
8.4 Government Access Requests
Nomisma's policy on government access:
- We do not voluntarily provide government agencies access to Customer Data
- We will challenge requests that appear unlawful or overbroad
- We will notify Customer unless legally prohibited
- We publish transparency reports annually
To date, Nomisma has received zero government requests for Customer Data.
---
09 Liability and Indemnification
9.1 Liability
Each party's liability under this DPA is subject to the limitations set forth in the Agreement.
9.2 Indemnification
Nomisma shall indemnify Customer against third-party claims arising from Nomisma's:
- Material breach of this DPA
- Violation of Data Protection Laws attributable to Nomisma
- Actions of Sub-processors within Nomisma's control
Customer shall indemnify Nomisma against claims arising from:
- Customer's unlawful processing instructions
- Customer's violation of Data Protection Laws
- Inaccurate or incomplete data provided by Customer
---
10 General Provisions
10.1 Order of Precedence
In case of conflict between this DPA and the Agreement:
- This DPA takes precedence for data protection matters
- The Agreement takes precedence for all other matters
10.2 Amendments
Nomisma may update this DPA to:
- Reflect changes in Data Protection Laws
- Add new Sub-processors (subject to Section 5.3)
- Improve security measures
- Clarify existing provisions
Notification: Material changes communicated 30 days in advance via email and in-app notice.
10.3 Term
This DPA remains in effect for the duration of the Agreement and until all Customer Data is deleted in accordance with Section 6.
10.4 Severability
If any provision of this DPA is found unenforceable, the remaining provisions remain in effect.
10.5 Governing Law
This DPA is governed by the laws specified in the Agreement, except that Data Protection Laws applicable to the Customer's data subjects shall apply to the relevant data protection obligations.
---
11 Contact Information
Data Protection Inquiries:
- Email: info@actaa.ai
- Address: Nomisma LLC, Fremont, California, United States
Data Protection Officer:
- Email: info@actaa.ai
Security Inquiries:
- Email: info@actaa.ai
Legal Inquiries:
- Email: info@actaa.ai
---
Appendix A: Technical and Organizational Measures
A.1 Summary of Security Controls
| Control Category | Measures Implemented |
|---|---|
| Access Control | RBAC, MFA, SSO, session management |
| Encryption | TLS 1.2+, AES-256-GCM, key rotation |
| Network Security | WAF, DDoS protection, IDS/IPS |
| Application Security | SDLC, code review, vulnerability scanning |
| Data Protection | PII scrubbing, data minimization, retention limits |
| Monitoring | 24/7 SOC, logging, alerting |
| Incident Response | Documented procedures, regular drills |
| Business Continuity | Backups, DR site, RTO/RPO targets |
| Vendor Management | Security assessments, contractual controls |
| Personnel | Background checks, training, NDAs |
A.2 AI-Specific Controls
| Control | Description |
|---|---|
| Tenant Isolation | Each company's data is logically separated |
| Query Sanitization | PII patterns removed from queries before LLM |
| Response Filtering | AI responses scanned for leaked sensitive data |
| Context Boundaries | AI cannot access data outside authorized sources |
| Intent Guard | Blocks requests for employment decisions (AEDT compliance) |
| Audit Logging | All AI interactions logged with user attribution |
| Token Metering | Usage tracked per company for billing accuracy |
---
Appendix B: Standard Contractual Clauses
The EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) are incorporated by reference.
Module 2 (Controller to Processor) applies where:
- Customer is the Data Controller
- Nomisma is the Data Processor
Full text: Commission Implementing Decision (EU) 2021/914, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
---
By using Actaa AI Services, Customer acknowledges and agrees to this Data Processing Addendum.
Document ID: DPA-2026.02.01
Revision History: Initial release