Data Processing Agreement
Last updated: 6 August 2026
This Data Processing Agreement forms part of the Nucleus HQ customer terms between the customer and Nucleus HQ. It applies where Nucleus HQ processes personal data on behalf of the customer.
1. Roles
- The customer is the controller of customer personal data unless the law says otherwise.
- Nucleus HQ is the processor of customer personal data.
- Where a customer uses Nucleus HQ for its own clients, the customer is responsible for having lawful terms with those clients.
- Where the customer enables a third-party integration using the customer's own account, the customer is the controller of the data sent to that provider and of the purpose for which it is used. Those integrations are listed in Schedule B and are not Nucleus HQ subprocessors. For most of them the customer supplies its own credentials and holds the only relationship with the provider. For Google Calendar the customer connects its own Google account, and Nucleus HQ separately operates the OAuth application under Google's API terms, as Schedule B explains.
- Where the customer publishes a coded site through Nucleus HQ, Nucleus HQ serves the customer's own HTML, head content and assets. Nucleus HQ injects no analytics, tracking or third-party tooling of its own into a served coded site. Any third-party script, embed or iframe on a coded site is the customer's own choice and the customer is the controller for it, and the customer is responsible for disclosing that third party and for obtaining any consent it requires. Nucleus HQ is processor for the hosting of that site and for the lead capture it operates on the customer's behalf.
2. Subject Matter
Nucleus HQ provides CRM, lead capture, automation, support intake, chat concierge, conversations across web, email, SMS and WhatsApp, courses and learner access, bookings, files, API and agent operation, hosted funnel publishing, and hosted coded-site serving. Nucleus HQ processes customer personal data only to provide and secure those services.
3. Categories Of Personal Data
The service may process:
3.1 Contact and CRM data
- Names.
- Email addresses.
- Phone numbers if the customer imports or enters them.
- Business names and job titles.
- Lead source and campaign information.
- CRM notes, tasks, deals, pipeline data, tags, and custom fields.
- Support requests and feature suggestions.
3.2 Account, authentication and security data
- Login, API, audit, device, and IP metadata.
- Multi-factor authentication data: encrypted multi-factor secrets, multi-factor enrolment state, hashes of recovery codes, and the times at which recovery codes were consumed.
- Authentication security events, including sign-in attempts, multi-factor challenges and outcomes, and related security telemetry.
- API key records: the key hash, the last four characters of the key, its scopes, its creation time, its last use, and its revocation.
Nucleus HQ does not store multi-factor secrets or recovery codes in a readable form. Secrets are stored encrypted and recovery codes are stored as hashes.
3.3 Conversations and messages
Conversations in Nucleus HQ span four channels: web, email, SMS and WhatsApp. Message records may contain:
- Message bodies, that is the content of the message itself.
- Channel addresses, that is the email address, phone number or messaging identifier of the sender or the recipient.
- Direction, that is inbound or outbound.
- Provider message identifiers, delivery status and error information returned by the sending provider.
- Attachment metadata.
SMS and WhatsApp sending only operate where the customer has enabled that channel with the customer's own provider credentials. See Schedule B.
3.4 Chat concierge
- Chat concierge conversations between visitors and a customer's published chat widget, including any contact details a visitor submits in the chat.
- Unmatched concierge questions, that is questions the concierge could not answer.
- Widget usage analytics limited to event types, step and option identifiers, anonymous session identifiers, and timestamps. Analytics events contain no message text, no contact details and no IP addresses. Analytics collection is capped at 500 events per session, and an analytics event is deleted when the record it relates to is deleted.
3.5 Courses and learners
- Course and lesson content and attachments uploaded by the customer.
- Learner enrolments.
- Learner lesson progress.
- Hashed learner login tokens and hashed learner session tokens, used to give a learner access to a course. Nucleus HQ stores these as hashes, not in readable form.
- Course purchase data. Where a course is sold, the paid checkout reads the buyer's email address and name from Stripe, creates a CRM contact for the buyer if one does not already exist, creates an enrolment, mints an access token, and sends the buyer a receipt and an access link by email.
3.6 Bookings
- Booking data captured on a public booking page: name, email address, optional phone number, answers to the customer's custom questions, the chosen start time, the submitting IP address, a bot-verification token, and a manage token that lets the person change or cancel the booking.
- Where the booking is paid, the associated Stripe Connect checkout data.
3.7 Lead capture and enquiries
- Funnel visitor IP addresses and request metadata, processed transiently in logs and rate limiting when serving customer-published funnel pages.
- Coded-site lead capture. Where a form on a customer's coded site submits to Nucleus HQ, Nucleus HQ processes the submitted email address, name, phone number, any mapped custom values, and the submitting IP address, creates or updates a CRM contact from that submission, and stores a cleaned copy of the submission payload.
- Nucleus HQ website enquiries. Where someone enquires through the Nucleus HQ website, the name, email address, company, phone number, note, source and any chat transcript are emailed to Nucleus HQ through the email provider named in Schedule A, and may then be copied into the Nucleus HQ CRM. For that enquiry data, Nucleus HQ is the controller and its own privacy notice applies.
3.8 Files
- File metadata, held in the tenant database.
- File objects themselves, held in Cloudflare R2 object storage. The R2 bucket was created with a Western Europe location hint, so file objects are stored in Western Europe. That is a location preference rather than a contractual restriction: Nucleus HQ has not applied Cloudflare's EU jurisdiction setting to the bucket, so Cloudflare is not contractually prevented from storing the data elsewhere. Transfers are covered by the Cloudflare transfer mechanism described in section 9. Note that this differs from the databases, which are hosted in the United Kingdom.
3.9 Billing, wallet and usage
- Billing identifiers from Stripe, including customer, subscription, checkout and connected-account identifiers, and payment status.
- Communications wallet records: the wallet balance, the auto-reload configuration, off-session top-up charges taken through Stripe, and a transaction ledger.
- Metered usage records: usage debits recording the usage type, the quantity, the unit price and the associated charge identifier, for metered communications usage such as SMS and WhatsApp sending where the customer has enabled those channels.
No card number, no expiry date and no CVC ever reaches Nucleus HQ. Card details are handled by Stripe. Nucleus HQ does not store card numbers, card last four digits or card expiry dates.
3.10 Platform records
- Provisioning requests.
- Custom-domain verification records.
- Master audit events, including the acting user and the acting IP address.
- Rate-limit buckets.
The customer controls what data is entered into Nucleus HQ.
3.11 Contract documents, sending, electronic signature and signer evidence
The platform processes, on the customer instruction:
- Contract documents authored by the customer inside the platform, together with any personal data the customer chooses to include in them. Because the customer decides the contents, these documents may contain special category data as defined by Article 9 of the UK GDPR. The customer remains responsible for having an appropriate lawful basis and safeguards for any such data, as required by section 5 of the Terms.
- Rendered PDF copies of the contract document. While a contract is a draft, the customer can generate a PDF copy, and a previously generated copy remains retrievable if the contract is later voided. When a contract is completed by all signers, the platform generates a single executed PDF containing the document as signed, each signer's name, email address and signature image, and the completion timestamp. The executed PDF is generated once and is not regenerated or altered afterwards. All contract PDFs are stored as file objects in Cloudflare R2 and are therefore subject to the file object location position in section 3.8, namely a Western Europe location hint rather than an enforced jurisdiction. This differs from the databases, which are hosted in the United Kingdom. Customers whose contracts contain special category data should take this into account.
- Intended signer records: name and email address, entered by the customer.
- Signing invitations, delivered by the email subprocessor named in section 8, and the one-time access credential issued for each signer, which is stored only as an irreversible digest and expires fourteen days after issue.
- Signer download credentials: when a contract is completed, each signer is emailed, via the email subprocessor named in section 8, a private link to download the executed PDF. The credential in that link is stored only as an irreversible digest, is valid for thirty days, may be used more than once within that period, is distinguished at the database level from a signing credential so one can never be used as the other, and can be revoked by the customer instruction.
- Signer evidence, being for each signing step the event type, its timestamp, the signer IP address, the user agent string reported by the signer browser, and the identifier of the contract content as presented. Where the signer signs, the signature image is stored as a file object.
Nature of the evidence record. The signer evidence table is append-only in normal operation: the application role holds INSERT and SELECT rights only and cannot amend or remove an individual record. Removal occurs only through deletion of the parent contract, which cascades to all associated signer records, or through the retention process in section 11, both of which require elevated database rights.
Retention and erasure. Where a contract is signed, declined or voided, the contract and all associated signer evidence are deleted six years after that date, reflecting the limitation period for a simple contract. Where a contract has been sent but has not been signed, declined or voided, no such date exists and the record is retained until the customer voids or deletes the contract. A contract that has been sent cannot be deleted through the ordinary application interface; the customer may void it, which starts the retention period. Where a customer requires earlier erasure, Nucleus HQ will act on documented instruction under section 10, including where erasure requires elevated database rights that the application itself does not hold.
No profiling or marketing use. Signer evidence is processed solely to evidence execution of the contract. It is not used for analytics, profiling, advertising or marketing. The signing surface sets no cookies and loads no analytics or advertising technology.
3.12 Forms, questionnaires, quizzes and surveys
The customer can author questionnaires, quizzes and surveys and publish each as a public page on its workspace address. Respondent submissions, comprising answers, optional name, email address and phone number where the form requests them, quiz scores and outcomes derived from the customer's own scoring rules, and submission timestamps, are stored in the customer's isolated workspace database, pinned to the published version of the form the respondent saw. The customer is the controller of respondent data; Nucleus HQ processes it on the customer's instructions. Where the customer enables contact creation and a respondent provides an email address, a submission may create or update a contact record through the same capture processing described in section 3.7. Anonymous surveys store no respondent identity fields. Respondent IP addresses are used transiently for abuse protection at submission and are not stored with responses.
4. Categories Of Data Subjects
The service may process data about:
- Customer users, that is the people the customer gives accounts to inside its workspace.
- Customer leads and contacts.
- Customer clients and prospects.
- Reseller users and their client-account users.
- Support requesters.
- Visitors to customer-published funnel pages and customer-published coded sites.
- Visitors who use a customer's published chat concierge widget.
- People who submit a form on a customer's coded site, that is form submitters. Their submission IP address is stored.
- People who book through a customer's public booking page.
- Learners. Learners are a distinct category of data subject. A learner is a person the customer enrols on a course, who signs in through a learner login rather than a workspace user account, and whose enrolment and lesson progress are recorded.
- Form respondents. A person who fills in a questionnaire, quiz or survey the customer has published. Their answers, any identity fields the form requested, and any quiz score or outcome are recorded for the customer.
- Buyers of a customer's paid course, whose name and email address are read from Stripe at checkout and who are created as a CRM contact if they are not one already.
- People whom a customer records as the intended signer of a contract prepared in the platform. Recording a person in this way does not contact them.
5. Processing Instructions
Nucleus HQ will process customer personal data only:
- To provide the service.
- To maintain security, availability, and support.
- To comply with lawful written customer instructions.
- To comply with applicable law.
Nucleus HQ will tell the customer if an instruction appears to violate applicable data protection law, unless the law prevents that notice.
6. Security Measures
Nucleus HQ will maintain appropriate technical and organisational measures, including:
- Tenant isolation, with each tenant's data held in its own database.
- Scoped API keys, stored as hashes, with recorded creation, last use and revocation.
- Role based access controls.
- Audit logging for sensitive actions.
- Encrypted secret storage outside the codebase. Secrets, credentials, connection strings and database backups are encrypted. Database backups are encrypted before transfer and are held encrypted at rest. Nucleus HQ does not claim encryption at rest of the underlying server volume, and does not represent that it is encrypted.
- Multi-factor authentication, with multi-factor secrets stored encrypted and recovery codes stored as hashes.
- HTTPS in production, with TLS and a web application firewall in front of the application.
- Server-side input validation.
- Rate limiting on public and authenticated API surfaces.
- Turnstile bot verification on public lead capture, public booking and signup routes where configured.
- Watchdog checks and operational alerts.
- Backup and restore procedures, with encrypted database backups.
7. Confidentiality
Nucleus HQ will ensure that people authorised to process customer personal data are bound by confidentiality obligations or an appropriate legal duty of confidentiality.
Nucleus HQ is operated by Nucleus HQ Ltd, a company registered in England and Wales, company number 17343317. Its sole director is its only member of staff, and access to customer personal data in production is limited to that one person, who is bound by a duty of confidentiality to the customer under this agreement and the main customer terms. Where Nucleus HQ Ltd engages any further personnel or contractor, that person will be placed under a written confidentiality obligation before being given any access to customer personal data.
Each subprocessor in Schedule A is engaged under an executed written data processing agreement that binds the provider and its personnel to confidentiality. The instruments in force are the signed Article 28 data processing agreement with Contabo GmbH concluded on 14 July 2026, the data processing agreement with Stripe Payments Europe, Limited dated 18 November 2025, the Cloudflare, Inc. Data Processing Addendum v6.4 dated 3 April 2026, and the data processing agreement with Resend signed on 31 December 2025.
8. Subprocessors
The customer authorises Nucleus HQ to use the subprocessors listed in Schedule A. Those four providers are the only subprocessors Nucleus HQ engages.
Nucleus HQ will provide notice of material subprocessor changes where required by law or the customer agreement.
Each subprocessor is engaged under an executed written data processing agreement that imposes data protection obligations equivalent to those in this agreement, including confidentiality, security, breach notification, and restrictions on onward transfer. The executed instruments are:
- Contabo GmbH: signed Article 28 data processing agreement, concluded 14 July 2026.
- Stripe Payments Europe, Limited: data processing agreement in force, dated 18 November 2025, incorporated into Stripe's standard terms.
- Cloudflare, Inc.: Data Processing Addendum v6.4, dated 3 April 2026, incorporated into Cloudflare's standard terms.
- Resend: data processing agreement signed 31 December 2025.
Nucleus HQ holds a copy of each of these agreements and can produce it on the customer's reasonable request.
The integrations listed in Schedule B are not Nucleus HQ subprocessors, because none of those providers processes customer personal data on Nucleus HQ's instructions. They are enabled by the customer using the customer's own account, and the customer is the controller of the data sent to that provider. Schedule B sets out the one case, Google Calendar, where Nucleus HQ nevertheless holds its own separate relationship with the provider.
Schedule A. Subprocessors Nucleus HQ engages
| Provider | Purpose | Data it can receive | Data processing agreement and transfers |
|---|---|---|---|
| Contabo GmbH, Welfenstrasse 22, 81541 Munich, Germany (HRB 180722, Local Court Munich). The data centre is operated by Contabo UK Ltd in Portsmouth, United Kingdom. | Hosts the application, the PostgreSQL master and tenant databases, the system journal, and local backup staging. Contabo's own automated server backup is enabled, so Contabo also holds copies of the server. Hosting location: United Kingdom. | All master and tenant data categories, plus request logs. | Signed Article 28 data processing agreement, concluded 14 July 2026. Data is stored in the United Kingdom. Contabo GmbH is an EEA company whose personnel may access the systems to support the hosting service. That access relies on the United Kingdom's adequacy finding for the EEA, so no Standard Contractual Clauses are required. Contabo's own backup retention period: rolling daily whole-server backups, the ten most recent, so approximately ten days. |
| Cloudflare, Inc. | DNS, TLS, WAF, routing. Turnstile bot verification. R2 object storage for uploaded tenant files, contract documents, signer signature images and encrypted database backups. | Turnstile token and request verification data. Uploaded file objects. Encrypted backup archives. | Data Processing Addendum v6.4, dated 3 April 2026, incorporated into Cloudflare's standard terms. Transfers are governed by that addendum, including the Standard Contractual Clauses and the UK Addendum. R2 bucket location: Western Europe (location hint). Not an enforced EU jurisdiction. Uploaded file objects are therefore stored in Western Europe as a location preference, and Cloudflare is not contractually prevented from storing them elsewhere. |
| Stripe Payments Europe, Limited | Subscription checkout and billing portal. Stripe Connect commerce, including paid bookings and paid courses. Wallet off-session top-ups and auto-reload. Webhook and billing identifiers. | Billing identifiers, customer and subscription identifiers, checkout and connected-account data, payment status. No card number, expiry or CVC ever reaches Nucleus HQ. | Data processing agreement in force, dated 18 November 2025, incorporated into Stripe's standard terms. Transfers are governed by that agreement, including its UK Addendum and the Standard Contractual Clauses where they apply. Stripe also acts as an independent controller for its own legal, fraud-prevention and regulatory compliance purposes. |
| Resend | Platform and tenant transactional email, workspace invites, website enquiry notifications, course purchase and learner access email, and campaign email. | Recipient address, name, subject, HTML body, reply-to, delivery metadata. | Data processing agreement signed 31 December 2025. Transfers are governed by that agreement. |
Schedule B. Customer-enabled integrations
Of these, two are enabled today: tenant-supplied Cloudflare Turnstile keys, on one tenant's public form, and a tenant-supplied Resend sending key, on one tenant. No other integration listed, including Google Calendar, is enabled by any tenant. Each is enabled by the customer, using the customer's own account, and the customer is the controller of the data sent to that provider and of the purpose it is used for. None of them is a Nucleus HQ subprocessor, because none of them processes that data on Nucleus HQ's instructions.
For Twilio, the Meta WhatsApp Cloud API, OpenAI and Anthropic, and for tenant-supplied Cloudflare Turnstile keys and tenant-supplied Resend sending keys, the customer supplies its own credentials and that use does not run on Nucleus HQ's account. Cloudflare and Resend separately remain Schedule A subprocessors for the platform's own use. Google Calendar differs: the customer connects its own Google account, but Nucleus HQ registers and operates the OAuth application through which that connection is made, and is bound by Google's API terms for operating it.
| Integration | Enabled how | Data exchanged on activation |
|---|---|---|
| Twilio | Customer supplies credentials and enables SMS. | Destination phone, message body, sender, provider status and message ID. |
| Meta WhatsApp Cloud API | Customer supplies credentials and enables WhatsApp. | Destination identifier, message body, provider status and message ID. |
| OpenAI | Customer supplies their own API key and enables AI features. | Selected CRM context and visitor message text. |
| Anthropic | Same customer-owned key model as OpenAI. | Selected CRM context and visitor message text. |
| Google Calendar | Customer completes OAuth. | Account and calendar metadata, encrypted OAuth tokens held by Nucleus HQ, availability and appointment context. |
| Cloudflare Turnstile (tenant-supplied keys) | Customer supplies their own Turnstile site and secret keys. | Turnstile token and request verification data for that customer's forms, exchanged with Cloudflare under the customer's own account. |
| Resend (tenant-supplied sending key) | Customer supplies their own Resend API key for their workspace's email. | Recipient address, name, subject, HTML body, reply-to and delivery metadata for that workspace's email, exchanged with Resend under the customer's own account. |
9. International Transfers
Personal data processed under this DPA is stored in the United Kingdom. The hosting provider is Contabo GmbH, Welfenstrasse 22, 81541 Munich, Germany, and the data centre holding the data is operated by Contabo UK Ltd in Portsmouth, United Kingdom. Nucleus HQ concluded a signed Article 28 data processing agreement with Contabo GmbH on 14 July 2026.
Contabo GmbH is established in Germany, and its personnel may access the systems in order to provide and support the hosting service. Germany is within the European Economic Area, which the United Kingdom recognises as providing an adequate level of protection. That access therefore relies on UK adequacy for the EEA and does not require Standard Contractual Clauses.
Contabo's own automated server backup is enabled, so Contabo holds its own copies of the server in addition to the backups Nucleus HQ takes. Contabo keeps a rolling set of the ten most recent daily backups, so approximately the last ten days. Because these are whole-server images, they include the databases. This means that when data is deleted from the live system, a copy can persist in Contabo's own server backups for up to about ten days before it ages out.
The other three subprocessors are engaged under executed data processing agreements that carry their own transfer mechanisms:
- Stripe Payments Europe, Limited, under its data processing agreement dated 18 November 2025, which includes the UK Addendum and the Standard Contractual Clauses where they apply.
- Cloudflare, Inc., under its Data Processing Addendum v6.4 dated 3 April 2026, which includes the Standard Contractual Clauses and the UK Addendum.
- Resend, under its data processing agreement signed 31 December 2025.
Customer files uploaded to Nucleus HQ, together with coded-site assets, course attachments, contract documents, signer signature images and encrypted database backups, are held in Cloudflare R2 object storage, in a bucket created with a Western Europe location hint. Those files are therefore stored in Western Europe. This is a location preference rather than a contractual restriction: Nucleus HQ has not applied Cloudflare's EU jurisdiction setting to the bucket, so Cloudflare is not contractually prevented from storing the data elsewhere. Transfers are covered by the Cloudflare Data Processing Addendum version 6.4, dated 3 April 2026, which includes the Standard Contractual Clauses and the UK Addendum.
These are two distinct locations and both are stated as they are. The databases are hosted in the United Kingdom (Portsmouth, Contabo UK Ltd). The uploaded files are stored in Western Europe (Cloudflare R2).
Where personal data is transferred outside the United Kingdom other than as set out above, Nucleus HQ will use an appropriate transfer mechanism under UK data protection law.
10. Data Subject Requests
Nucleus HQ will provide reasonable assistance for customer responses to data subject access, correction, deletion, restriction, objection, and portability requests where the customer cannot reasonably fulfil the request through the service.
11. Retention, Deletion And Return
Nucleus HQ retains customer personal data according to the schedule below. Where Nucleus HQ can give a fixed period, it gives it. Where the period depends on how long the customer keeps using the service, Nucleus HQ states what determines the period instead of quoting a number it does not hold itself to. The customer can delete its data at any time, and can ask Nucleus HQ to delete it.
| Data | Retention |
|---|---|
| Concierge sessions and messages | Retained while your workspace is active. Deleted when you delete the session or the bot, and when workspace data is deleted on request. |
| Concierge widget analytics events | Capped at 500 events per session. Deleted when the record they relate to is deleted. |
| Unmatched concierge questions | Retained while your workspace is active. Deleted when workspace data is deleted on request. |
| Form submissions | Retained for the life of the linked contact record. Deleted when you delete that contact. |
| Bookings | 6 years. |
| Contracts and signer evidence | 6 years after the contract is signed, declined or voided. A contract that has been sent but never concluded is retained until the customer voids or deletes it. |
| API audit records | Retained while your workspace is active. Deleted when workspace data is deleted on request. |
| Authentication security events | Retained while your account is active. Deleted when account data is deleted on request. |
| Billing events, wallet ledger, usage events | 6 years, statutory financial record retention. |
| Platform monitoring checks | 30 days. |
| Security and access logs | Rotated automatically on a rolling storage limit. In practice they are held for a matter of days, not months, and are never kept beyond 90 days. |
| Encrypted database backups, routine | 30 days remote, 7 days local. |
| Encrypted database dumps taken before a significant change or before a workspace is removed | Held on Nucleus HQ's own servers only, never copied to remote storage, and deleted automatically after 30 days. |
| Hosting provider's automated whole-server backups | Rolling daily whole-server backups, the ten most recent, so approximately ten days. |
| Tenant CRM data after workspace closure | Retained while the workspace is deactivated, so it can be restored if you reactivate. Deleted on request. |
| Platform account data after closure | Retained until you ask us to delete it. Financial records are kept for 6 years because we are required to keep them. |
In addition:
- The customer can export its account data at any time during an active subscription.
- When a workspace is deactivated, Nucleus HQ retains that tenant's CRM data so the workspace can be restored if the customer reactivates it. Nucleus HQ deletes that data on the customer's request, unless the law requires Nucleus HQ to retain it or a legal hold applies.
- Platform account data, meaning the records Nucleus HQ holds about the customer as an account holder, is retained until the customer asks Nucleus HQ to delete it. Financial records are kept for six years because Nucleus HQ is required by law to keep them.
- Deletion works through to backups on the backup cycle. Nucleus HQ's own routine encrypted database backups are held for 30 days remote and seven days local. Separately, one-off encrypted database dumps taken before a significant change or before a workspace is removed are held on Nucleus HQ's own servers only and deleted automatically after 30 days. The hosting provider's automated whole-server backups are held for approximately ten days. So data the customer deletes can persist in a backup for those periods before the backup itself expires.
- Contabo, the hosting provider, takes its own automated backup of the whole server, separately from the encrypted database backups Nucleus HQ takes. Contabo keeps a rolling set of the ten most recent daily backups, so approximately the last ten days. Because these are whole-server images, they include the databases.
12. Personal Data Breach
Nucleus HQ will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. The notice will include the known facts, the likely consequences, and the mitigation steps taken or proposed, so far as they are known at the time, and Nucleus HQ will update the customer as more becomes known.
Nucleus HQ Ltd is a single-director company with no other staff, so the detection, escalation and notification path is short. Automated watchdog checks and operational alerts surface incidents, and the director is the person who assesses them and notifies the customer. Nucleus HQ will give the customer the information and reasonable assistance the customer needs to meet its own obligations to the Information Commissioner's Office and to affected data subjects.
Each subprocessor in Schedule A is required, under its executed data processing agreement, to notify Nucleus HQ of a personal data breach without undue delay: Contabo GmbH under the signed Article 28 data processing agreement concluded 14 July 2026, Stripe Payments Europe, Limited under its data processing agreement dated 18 November 2025, Cloudflare, Inc. under Data Processing Addendum v6.4 dated 3 April 2026, and Resend under its data processing agreement signed 31 December 2025. Nucleus HQ will pass any such notification on to the affected customer without undue delay.
13. Audit Rights
Nucleus HQ will provide the customer with the information reasonably needed to demonstrate compliance with this agreement. That information is:
- This agreement, including the Schedule A subprocessor list and the Schedule B integration list.
- The executed data processing agreements Nucleus HQ holds with each subprocessor: Contabo GmbH (signed Article 28 data processing agreement, 14 July 2026), Stripe Payments Europe, Limited (data processing agreement, 18 November 2025), Cloudflare, Inc. (Data Processing Addendum v6.4, 3 April 2026), and Resend (data processing agreement, 31 December 2025). Nucleus HQ holds each of these and can evidence that it is in force.
- The technical and organisational measures set out in section 6, and the retention schedule set out in section 11.
- Any compliance documentation Nucleus HQ can obtain from a subprocessor, which Nucleus HQ will request on the customer's reasonable request. Nucleus HQ does not hold, and does not claim to hold, an independent security certification of its own.
Any direct audit must be requested with reasonable notice, must be scoped, reasonable and confidential, and must not disrupt the service or expose the data of other tenants.
14. Customer Responsibilities
The customer is responsible for:
- Having a lawful basis for the data it enters or imports.
- Providing privacy notices to its own contacts, users, learners, booking attendees and form submitters.
- Using permissions correctly.
- Keeping user accounts secure, including multi-factor enrolment and recovery codes.
- Not uploading prohibited data unless the service terms expressly permit it.
- Honouring opt-outs and deletion requests in its own business processes.
- Ensuring content it publishes through the service, including hosted funnel pages, coded sites and course content, is lawful and does not infringe third-party rights.
- Any third-party script, embed or iframe it places on a coded site, and any notices, consent and cookie disclosure that script requires.
- Its own account and credentials with any integration provider it enables under Schedule B, and its own controller obligations for the data sent to that provider.
- Providing any notices required to visitors of its published pages, including for third-party content it embeds.
15. Liability And Order Of Precedence
Liability, caps, exclusions, and order of precedence follow the main Nucleus HQ customer terms. Where this agreement and the customer terms conflict on the processing of personal data, this agreement prevails.