This Data Processing Addendum sets out the terms governing Nomisma LLC's processing of personal data on the Customer's behalf in connection with the Actaa Service, incorporates Article 28 of the GDPR, and forms part of the Platform Terms of Service.
01 Roles and Scope
This Data Processing Addendum ("DPA") applies where Nomisma LLC ("Processor") processes personal data contained in Customer Content on behalf of the Customer ("Controller") in the provision of the Actaa Service. It forms part of, and is governed by, the Platform Terms of Service (the "Agreement"). The Controller determines the purposes and means of the processing, and the Processor processes personal data solely as set out in this DPA and the Agreement. In the event of a conflict between this DPA and the Agreement in respect of the processing of personal data, this DPA shall prevail.
02 Subject-Matter, Duration, Nature and Purpose
- Subject-matter — the processing of personal data contained in Customer Content in order to provide the Actaa Service and its Modules.
- Duration — the term of the Agreement, together with the 30-day post-deletion recovery window and any period required by applicable law.
- Nature — hosting, storage, retrieval, indexing, transmission, display, computation (including grounded AI processing on AWS Bedrock), backup, and deletion, as directed by the Controller through its use and configuration of the Service.
- Purpose — to provide, maintain, secure, and support the Service for the Controller.
03 Categories of Personal Data and Data Subjects
The categories of personal data and of data subjects are determined by the Controller through the content it elects to process within the Service, and are summarized in Annex I. They may include the Controller's personnel, contractors, applicants, clients, and other individuals whose personal data appears within the Controller's documents, messages, records, and other content.
04 Processing on Documented Instructions
The Processor shall process personal data solely on the Controller's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law, in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification. The Agreement, this DPA, the Controller's Orders, and the configuration choices made by the Controller's Administrators within the Service together constitute the Controller's complete and documented instructions. The Processor shall inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
05 Confidentiality of Personnel
The Processor shall ensure that personnel authorized to process personal data are bound by an appropriate duty of confidentiality and are granted access only on a need-to-know basis, consistent with the role-based, department-scoped access controls described in Annex II.
06 Security Measures
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing. Such measures are described in Annex II and in the Security & Compliance Overview, and include database-layer per-company isolation via Row-Level Security, AES-256-GCM encryption of stored secrets and sensitive fields, TLS with certificate validation in transit, AWS Cognito authentication with TOTP multi-factor authentication and role-based access control, action audit logging, and three-layer PII scrubbing prior to AI processing.
07 Assistance with Data-Subject Requests
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise data-subject rights under Chapter III of the GDPR (Articles 15–22). The platform directly implements Article 17 (erasure) and Article 20 (portability) through one-click export and anonymized deletion. Where the Processor receives a request directly from a data subject, it shall, where lawful, refer the request to the Controller rather than respond itself.
08 Personal-Data Breach Notification
The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Content, and shall provide the Controller with the information reasonably available to it to assist the Controller in meeting its obligations to notify supervisory authorities and data subjects. The Processor maintains processes to detect, investigate, and respond to security incidents.
09 Sub-processors
The Controller grants the Processor general written authorization to engage sub-processors in the provision of the Service. The current list of sub-processors is maintained at Sub-processors and summarized in Annex III. The Processor shall:
- Impose on each sub-processor data-protection obligations substantially equivalent to those set out in this DPA;
- Remain responsible for the performance of its sub-processors' obligations; and
- Provide the Controller with advance notice of any intended change concerning the addition or replacement of a sub-processor, so as to afford the Controller the opportunity to object on reasonable data-protection grounds.
10 International Data Transfers
The Service is hosted on AWS in the United States. Where the Processor transfers personal data on the Controller's behalf out of the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, such transfer shall be subject to appropriate safeguards. Specifically, the Processor relies on the European Commission's Standard Contractual Clauses (2021/914, controller-to-processor module, and other modules where applicable), the UK International Data Transfer Addendum, and, for Switzerland, the Swiss addendum, together with supplementary technical and organizational measures; the Service is hosted in the United States on Amazon Web Services (region us-east-1).
11 Deletion or Return of Data
At the Controller's election, the Processor shall delete or return all personal data following the end of the provision of the services relating to processing, and shall delete existing copies unless applicable law requires their storage. The Controller may export personal data at any time during the term using the platform's one-click portability capability. Following termination or upon the Controller's instruction to delete, personal data is deleted using an anonymized-deletion process with a 30-day recovery window, after which it is removed from active systems; residual copies in routine backups cycle out of retention on the Processor's standard rolling schedule, currently thirty-five (35) days.
12 Information and Audits
The Processor shall make available to the Controller the information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and this DPA, and shall allow for and contribute to reasonable audits, including inspections, conducted by the Controller or an auditor mandated by it. Audits are subject to reasonable advance notice, obligations of confidentiality, limits as to frequency and scope, and the security and operational constraints of a multi-tenant environment, and may be satisfied through the provision of documentation and, where available, third-party assessments.
13 Annexes I–III
Annex I — Parties and Description of Processing
| Data exporter / Controller | The Customer, as identified in the Agreement. Contact: the Customer's Administrator(s). Address: as set out in the applicable Order. |
| Data importer / Processor | Nomisma LLC, a Wyoming limited liability company, publisher of Actaa. Contact: info@actaa.ai. Place of formation: State of Wyoming, USA. |
| Data subjects | The Controller's personnel, contractors, applicants, clients, vendors, and other individuals whose personal data appears within Customer Content. |
| Categories of data | Identifiers and contact details; employment and HR data; the content of documents, messages, and records; and usage and audit data. Determined by the Controller. Special-category data may be processed only where the Controller elects to do so and is responsible for establishing a lawful basis. |
| Frequency | Continuous, for the duration of the Agreement. |
| Nature and purpose | Provision of the Actaa Service, as described in Section 2. |
| Duration | The term of the Agreement, together with the 30-day recovery window and any legally required retention. |
Annex II — Technical and Organizational Security Measures
- Tenant isolation — per-company isolation at the database layer via Postgres Row-Level Security (fail-closed where tenant context is absent), together with a boot-time posture check that refuses to start production where isolation is not intact, and application-layer company scoping operating as a second, redundant control.
- Encryption — AES-256-GCM encryption of stored secrets (such as third-party API keys) and sensitive fields (such as compensation), with key rotation; TLS with certificate validation for data in transit, including database connections.
- Authentication and access — AWS Cognito authentication with TOTP multi-factor authentication (RFC 6238) and step-up re-authentication for sensitive actions; role-based access control with granular, department-scoped permissions.
- Logging — database-backed action audit logging, including an AI audit trail.
- AI privacy — three-layer PII scrubbing (at ingestion, before the prompt, and on the output), with HR-sensitive content hard-blocked; AI processing operating exclusively on AWS Bedrock, which does not use your prompts or content to train its foundation models.
- Data-loss prevention — per-member no-download tiers and watermarked, metadata-stripped preview rendering for sensitive files; a Document IP Ledger providing hash-chained, tamper-evident proof-of-existence with cross-organization copy detection.
- Data rights — GDPR Article 17 (erasure) and Article 20 (portability) implemented, with anonymized deletion and a 30-day recovery window.
Annex III — Sub-processors
The Processor engages the infrastructure sub-processors listed and maintained at Sub-processors, comprising Amazon Web Services for compute, Amazon RDS (PostgreSQL, private subnet) as the primary data store, Amazon S3 for file storage, AWS Secrets Manager for secret storage, Amazon Cognito for authentication, and Amazon Bedrock for private AI inference. Changes are notified as set out in Section 9.