Data processing agreement
This document has been updated on July 22nd 2026.
Between: Nembol Inc. (“Processor,” “Nembol,” “we”) and the User entering into Nembol’s Terms of Use (“Controller,” “User,” “you”), collectively the “Parties.”
This Data Processing Agreement (“DPA”) is incorporated into and forms part of Nembol’s Terms of Use and applies wherever Nembol processes Personal Data on the User’s behalf as part of the Services, including in particular buyer and order data received through e-commerce and social channels the User connects to Nembol.
Order of Precedence: In the event of any conflict or inconsistency between this DPA and the Terms of Use with respect to the processing of Personal Data, the terms of this DPA shall prevail to the extent of the conflict.
1. Definitions
Terms such as “Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given to them in the GDPR, UK GDPR, and Swiss FADP, as applicable (“Data Protection Laws”).
2. Subject matter and duration
Nembol processes Personal Data on the User’s behalf for the duration of the User’s subscription to the Services, and thereafter only as necessary to comply with the deletion/return obligations in Section 9.
3. Nature and purpose of processing
Nembol processes Personal Data to provide the Services to the User, specifically: receiving, storing, and displaying order and buyer data transmitted by e-commerce and social channels the User connects to Nembol; enabling the User to view, manage, and fulfill orders; and related technical support functions the User requests.
4. Categories of data subjects
Customers and buyers of the User who place orders through e-commerce or social channels connected to Nembol.
5. Types of personal data
The specific categories of Personal Data processed depend on which e-commerce or social channel the User connects to Nembol, and the level of access and data-sharing authorization the User has granted Nembol within that channel’s own settings. Depending on these factors, the Personal Data processed may include some or all of the following: order data, products ordered, and buyer contact and delivery details such as name, address, email address, and phone number. Nembol processes only the data categories that the connected channel actually makes available to Nembol for a given User and order.
6. Nembol’s obligations as processor
Nembol shall:
6.1 Process only on instructions. Process Personal Data only on the User’s documented instructions, including with regard to transfers to a third country, unless required to do otherwise by applicable law, in which case Nembol will inform the User of that legal requirement before processing, unless prohibited from doing so. For the purposes of this DPA, the User’s documented instructions consist of: (i) this DPA and the Terms of Use; and (ii) the User’s configuration of the Services, including the connection of e-commerce or social channels and any associated data-sharing settings, each as may be updated by the User from time to time.
6.2 Confidentiality. Ensure that any person authorized to process the Personal Data is subject to a duty of confidentiality, whether contractual or statutory.
6.3 Security. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, in accordance with Article 32 GDPR.
6.4 Sub-processors. Not engage another processor (“sub-processor”) without the User’s authorization. The User hereby grants Nembol general written authorization to engage sub-processors performing the categories of functions described in Section 7, the specific identities of which are available to Users as set out in that Section. Nembol will notify Users of the specific identity of any new or replacement sub-processor, giving the User the opportunity to object on reasonable data protection grounds within 14 days of such notice. If the User reasonably objects, Nembol will work with the User in good faith to address the objection, which may include providing an alternative sub-processor or not proceeding with the intended change. If the Parties are unable to reach a resolution within a reasonable time, the User may terminate the Services affected by the objected-to sub-processor, without penalty for the portion of the Services so affected. Where Nembol engages a sub-processor, it shall impose data protection obligations on that sub-processor equivalent to those set out in this DPA, and shall remain fully liable to the User for the sub-processor’s performance.
6.5 Assistance with Data Subject rights. Taking into account the nature of the processing, assist the User by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the User’s obligation to respond to requests for exercising Data Subjects’ rights under Data Protection Laws.
6.6 Assistance with compliance. Assist the User in ensuring compliance with its obligations under Articles 32–36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority), taking into account the nature of processing and the information available to Nembol.
6.7 Personal Data Breach notification. Notify the User without undue delay, and where feasible within 48 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA, providing information reasonably available to Nembol to assist the User in meeting its own breach notification obligations under applicable Data Protection Laws.
6.8 Deletion or return of data. At the User’s choice, delete or return all Personal Data to the User after the end of the provision of the Services, and delete existing copies unless applicable law requires storage of the Personal Data.
6.9 Audits and information. Make available to the User, on reasonable request and no more than once per calendar year, documentation reasonably necessary to demonstrate compliance with this DPA — such as summaries of technical and organizational measures, relevant certifications held by Nembol or its sub-processors (e.g., ISO 27001, SOC 2, or equivalent), and responses to reasonable written security questionnaires. Where such documentation does not reasonably address the User’s compliance concerns, or following a Personal Data Breach or a binding request from a Supervisory Authority, Nembol shall additionally allow for and contribute to an on-site or remote audit, including inspection, conducted by the User or an auditor mandated by the User, subject to: (i) at least 30 days’ prior written notice; (ii) reasonable confidentiality safeguards; (iii) the audit being conducted during business hours in a manner that minimizes disruption to Nembol’s operations; and (iv) the User bearing its own costs of the audit, unless the audit reveals a material breach of this DPA by Nembol, in which case Nembol shall bear its reasonable costs of cooperation.
7. Current sub-processors
Nembol engages the sub-processors necessary to provide the Services, including for hosting/infrastructure, customer support tooling, email deliverability, product analytics, and bot/security protection. A current list identifying Nembol’s specific sub-processors, including their function and location, is available to Users upon request at hello@nembol.co.uk. Nembol will provide any notice required under this DPA, including notice of a new or replacement sub-processor as described in Section 6.4, by email to the User’s registered account email address, and, where technically feasible, by an additional in-app notification. Notice periods (including the objection period in Section 6.4) run from the date such email notice is sent.
8. International transfers
Where Nembol or a sub-processor transfers Personal Data outside the EU/EEA, UK, or Switzerland, Nembol shall ensure such transfer is subject to appropriate safeguards under Data Protection Laws, such as Standard Contractual Clauses, an adequacy decision, or, where applicable, a recognized certification framework such as the EU-U.S. Data Privacy Framework (once Nembol’s certification is confirmed by the U.S. Department of Commerce). For example, Nembol’s sub-processor Cloudflare, Inc. (used for bot protection) maintains recognized safeguards, such as Standard Contractual Clauses or a certification framework, for transfers of Personal Data outside the EU/EEA, UK, and Switzerland.
9. Return or deletion of data at termination
Upon termination or expiry of the User’s subscription, Nembol shall, per Section 6.8 and the retention periods set out in Nembol’s Privacy Policy, delete or anonymize Personal Data within the periods specified there, except for data Nembol is required to retain by law.
10. Liability
Each Party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Use.
11. Governing Law
This DPA is governed by the same governing law and jurisdiction provisions set out in the Terms of Use.
Subscribe for a free trial
No credit card required