NEVTAN ENGAGE
Data Processing Agreement (DPA)
Last Updated: June 5, 2026
This Data Processing Agreement (“DPA”) is entered into between Nevtan Inc. (“Engage”, “Processor”) and the Customer identified in the applicable subscription agreement, order form, or terms of service (“Controller”, “Customer”). This DPA forms part of, and is incorporated by reference into, the Nevtan Engage Terms and Conditions or such other written agreement between the parties (the “Services Agreement”). In the event of conflict, this DPA prevails on data protection matters.
1. Definitions
2. Roles of the Parties
2.1 Customer as Controller
Customer determines the purposes and means of processing Personal Data through the Services and is responsible for: lawful collection and transfer of Personal Data to Engage; obtaining all required consents; ensuring the lawfulness of instructions; and responding to Data Subject requests.
Where Customer itself acts as a Processor for a third-party Controller, Customer represents it has obtained all necessary authorizations to appoint Engage as a sub-processor.
2.2 Engage as Processor
Engage processes Personal Data only on documented instructions from Customer, to the extent necessary to provide the Services, and as required by Applicable Data Protection Laws.
3. Nature, Purpose, and Duration
The subject matter, nature, purpose, duration, data categories, and data subjects are set out in Schedule A of this DPA. This DPA remains in effect for the duration of the Services Agreement.
4. Security Measures
Engage implements and maintains appropriate technical and organizational measures including: TLS 1.2+ encryption in transit and AES-256 encryption at rest; multi-factor authentication and role-based access control; 24/7 security monitoring and audit logging; network segmentation and DDoS protection; encrypted backups with geographically distributed storage; and documented incident response procedures. Details are published at engage.nevtan.com/security.
5. Personal Data Breach Notification
Engage will notify Customer within 48 hours of confirming a Personal Data Breach affecting Customer's Personal Data. Notifications will include: the nature of the breach, categories of data and data subjects affected, steps taken to contain and remediate, and a designated contact for further information. Engage acknowledges that Customers may be required to notify supervisory authorities within 72 hours under GDPR; the 48-hour commitment provides Customers sufficient lead time.
6. Assistance with Data Subject Rights
Engage will provide reasonable technical assistance to enable Customer to respond to Data Subject requests for access, correction, deletion, restriction, portability, and objection. Customer remains solely responsible for responding. Where a Data Subject submits a request directly to Engage, Engage will forward it to Customer without responding independently.
7. Subprocessors
7.1 General Authorization
Customer provides general written authorization for Engage to engage Subprocessors. Engage ensures each Subprocessor is bound by equivalent data protection obligations.
7.2 Subprocessor List and Changes
Engage maintains a current Subprocessor list at engage.nevtan.com/legal/subprocessors. Engage provides at least 30 days' advance notice of new or replacement Subprocessors. Customer may object within 14 days on reasonable data protection grounds. If unresolved within 30 days, Customer may terminate the affected Services without penalty with a pro-rata refund of prepaid fees.
7.3 Engage Responsibility
Engage remains fully liable to Customer for each Subprocessor's compliance with data protection obligations.
8. International Data Transfers
Where Personal Data is transferred outside the Customer's jurisdiction, Engage relies on appropriate safeguards including: EU Standard Contractual Clauses (Module 2: Controller→Processor and Module 3: Processor→Sub-Processor) including the UK IDTA addendum where required; adequacy decisions recognized by applicable regulators; and Data Processing Agreements with equivalent protections. Executed SCCs are available at engage.nevtan.com/legal/dpa or upon request to privacy@engage.nevtan.com.
9. AI Processing
Where Customers use AI-powered features:
10. CCPA / CPRA Service Provider
To the extent Customer is subject to the CCPA/CPRA, Engage is a “Service Provider” as defined thereunder. Engage will not sell or share Personal Data; will not retain, use, or disclose Personal Data outside the direct business relationship; and will not combine Customer Personal Data with data from other sources except as permitted by law.
11. Audit Rights
No more than once per calendar year (unless a breach has occurred), Customer may request compliance verification. Engage will respond by providing security certifications, audit reports, compliance questionnaire responses, or written answers. If documentation is insufficient, Customer may commission an independent third-party audit at its own cost upon 30 days' written notice, conducted during business hours with minimal operational disruption.
12. Data Retention and Deletion
Account data is retained for the duration of the Services Agreement plus 90 days post-termination, during which Customer may export data. After 90 days, Customer Data is permanently deleted from production systems. Backup copies may persist for up to 90 days before purging. Upon request, Engage will provide written certification of deletion. Legal hold may extend retention for the duration of any relevant proceeding.
13. Liability
Each party's liability under this DPA is subject to the exclusions and caps in the Services Agreement. Each party is liable to Data Subjects and authorities for its own breaches of Applicable Data Protection Laws. A party paying compensation attributable to the other party's breach may recover that portion from the other party.
14. Governing Law and Severability
This DPA is governed by the law specified in the Services Agreement. To the extent required by Applicable Data Protection Laws, the mandatory provisions of such laws prevail. The SCCs in Schedule B are governed by the law specified therein. For the avoidance of doubt, the governing law of the SCCs operates independently and is not overridden by the governing law of this DPA. If any provision of this DPA is invalid, the remainder continues in full force. This DPA terminates upon expiry or termination of the Services Agreement. Sections 4, 12, 13, and 14 survive termination.
15. Schedule A — Processing Details
| Field | Details |
|---|---|
| Subject matter | Processing of Personal Data by Engage in the course of providing multi-channel marketing automation and customer engagement services. |
| Nature | Collection, storage, organization, analysis, use, transmission, delivery tracking, reporting, and deletion of Personal Data. |
| Purpose | To enable Customer to conduct marketing automation, manage customer relationships, send and track communications, and use analytics and AI features. |
| Duration | Term of the Services Agreement plus the 90-day post-termination retention period. |
A.1 Categories of Data Subjects
| Category | Description |
|---|---|
| Customers / end users | Individuals who purchase from or interact with Customer's business. |
| Prospects and leads | Individuals who have expressed interest in Customer's products or services. |
| Subscribers | Individuals subscribed to Customer's email, SMS, or other communications. |
| Website visitors | Individuals who visit Customer's website or landing pages hosted through the Services. |
| Business contacts | Contacts in Customer's B2B CRM or contact database. |
A.2 Categories of Personal Data
| Category | Examples |
|---|---|
| Identification | Full name, username, email address, phone number. |
| Contact information | Mailing address, city, region, country, postal code. |
| Marketing and preference | Communication preferences, subscription status, opt-in/opt-out records, campaign interactions. |
| Technical and device | IP address, browser type, device type, operating system, authentication logs. |
| Transactional | Purchase history, order data, customer lifecycle events. |
| Customer-defined | Any Personal Data uploaded via custom fields, CSV imports, API integrations, or form submissions. |
| AI-processed | User prompts, campaign content, and engagement metrics processed through AI features. |
A.3 Special Categories
Unless explicitly agreed in writing, Customer shall not upload or process special category Personal Data (health data, racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, sexual orientation, or criminal records) or data relating to children below the applicable age of digital consent.
A.4 Subprocessors
Current Subprocessors are listed at engage.nevtan.com/legal/subprocessors. Categories include: cloud infrastructure, email delivery, SMS/messaging delivery, WhatsApp Business, analytics, security monitoring, payment processing, AI/ML services, and customer support.
A.5 Transfer Mechanisms
| Transfer Route | Mechanism |
|---|---|
| EEA → Countries with Adequacy Decision | EU adequacy decision (Article 45 GDPR) |
| EEA → Other third countries | Standard Contractual Clauses (Module 2 / Module 3) |
| UK transfers | UK International Data Transfer Agreement (IDTA) / UK Addendum to SCCs |
| Other transfers | SCCs or equivalent lawful mechanism as applicable |
16. Schedule B — SCC Execution Instructions
Where Personal Data is transferred from the EEA or UK and SCCs are required, the parties incorporate by reference the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914 (Module 2: Controller to Processor). Key options:
For UK transfers, the parties incorporate by reference the UK International Data Transfer Addendum (Version B1.0) issued by the UK ICO. Customers may obtain countersigned SCCs at engage.nevtan.com/legal/dpa or by emailing privacy@nevtan.com.
17. Contact
Privacy Officer
Email: privacy@nevtan.com
Security Team
Email: security@nevtan.com
Legal Team
Email: legal@nevtan.com