Data Processing Agreement

Last modified: 23 July 2026 · Version 1.0

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of and is incorporated into the Nodge Terms of Service or other agreement between you ("Customer") and CoreCubes B.V., trading as Nodge (KvK 94074542, Winklerlaan 363-41, 3571 KE Utrecht, the Netherlands) ("Nodge") (the "Agreement"). By accepting the Terms of Service, the Customer also accepts this DPA.

This DPA applies where and to the extent Nodge processes personal data on behalf of the Customer in the course of providing the Service. In that processing:

It is entered into under Article 28 of Regulation (EU) 2016/679 (the "GDPR") and applicable Netherlands data-protection law.

2. Deployment models: what Nodge actually processes

Because the Service can be deployed in different ways, the extent of Nodge's processing differs:

3. Definitions

Terms such as controller, processor, personal data, processing, data subject, personal data breach, and supervisory authority have the meanings given in the GDPR. "Customer Personal Data" means personal data that Nodge processes on behalf of the Customer under the Agreement, as described in Annex I. "Sub-processor" means a processor engaged by Nodge to process Customer Personal Data.

4. Processing on documented instructions

Nodge will process Customer Personal Data only:

Nodge will not process Customer Personal Data for its own purposes. Nodge does not use Customer Personal Data, Customer code, prompts, or agent interactions to train any model. If Nodge is required by EU or Netherlands law to process beyond the Customer's instructions, it will inform the Customer of that requirement before processing, unless the law prohibits it. If Nodge considers an instruction to infringe data-protection law, it will inform the Customer without undue delay.

5. Confidentiality

Nodge ensures that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are trained in their obligations.

6. Security

Nodge implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II and taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Nodge is certified to ISO/IEC 27001:2022. Nodge may update the measures over time, provided the level of protection is not materially reduced.

7. Sub-processors

7.1 The Customer gives Nodge general authorisation to engage sub-processors to process Customer Personal Data, subject to this Section. A current list of sub-processors is maintained at https://nodge.ai/sub-processors.

7.2 Nodge imposes on each sub-processor, by written contract, data-protection obligations equivalent to those in this DPA, and remains responsible for its sub-processors' performance.

7.3 Nodge will give the Customer at least 4 weeks' prior notice of the addition or replacement of a sub-processor, by updating the sub-processor page. The Customer may object on reasonable data-protection grounds within that period. If the Customer objects and the parties cannot agree a resolution, the Customer may terminate the affected part of the Service and receive a refund of any prepaid, unused fees for that part.

7.4 All sub-processors that process Customer Personal Data are located within the European Union / European Economic Area. Nodge does not engage sub-processors that are US-controlled or otherwise subject to third-country access laws in the runtime path of the Service.

8. Assistance to the Customer

Taking into account the nature of the processing, Nodge will assist the Customer by appropriate technical and organisational measures, insofar as possible, with:

Where the Service provides self-service tools for these tasks (for example, export and deletion), the Customer will use those tools in the first instance. Assistance beyond those tools is provided on reasonable request and within the timeframe the Customer's own legal deadline requires. Nodge may charge a reasonable fee for assistance that is unusually burdensome or that falls outside the standard self-service tools.

9. International transfers and data location

The Nodge platform (control plane). Nodge's own platform data, including account and organisation data, platform metadata, Git repositories, the container registry, logs, and platform backups, is hosted in the Netherlands (Amsterdam) and stays within the European Union. Backups are stored on an offsite target located in the EU; there is no replication of this data outside the EEA. For this platform data, Nodge does not transfer Customer Personal Data to any country outside the EEA and engages no sub-processor outside the EEA. Accordingly, no transfer mechanism under Chapter V of the GDPR (such as Standard Contractual Clauses) is required for Nodge's own processing under this DPA.

Customer-chosen cluster location. Where the Customer provisions compute, the Customer chooses the location of its cluster from the options offered by the underlying hosting provider. The default is the Netherlands. Some of these options are outside the EEA. If the Customer selects a location outside the EEA, its application data and workloads run in that location, and that placement, and any resulting transfer of personal data outside the EEA, is the Customer's decision and the Customer's responsibility as controller, not a transfer made by Nodge. The Customer is responsible for any transfer mechanism its own choice of location requires. Nodge's control plane remains in the Netherlands regardless of the cluster location the Customer chooses. From a Customer cluster, the control plane receives only a defined outbound telemetry stream (pre-aggregated metrics, alert summaries, deploy, health and pipeline events, and billing usage); raw application logs are never sent to Nodge and stay on the Customer's cluster. Backups reach Nodge only as encrypted ciphertext that Nodge cannot decrypt, as the control plane does not hold the decryption key. The control plane has no standing inbound access into the Customer cluster; the cluster ships data outbound only.

Self-hosted and air-gapped deployments. The Service runs entirely within the Customer's own environment and Nodge does not process Customer Personal Data at all after installation (Section 2). Air-gapped deployments do not phone home: no metadata or telemetry reaches Nodge. Data location is determined entirely by the Customer.

If, in future, Nodge proposes any processing on its own part that would involve a transfer outside the EEA, it will notify the Customer in advance under Section 7 and will not proceed without a valid Chapter V transfer mechanism and the Customer's ability to object.

Note: the Customer's own choice of LLM model provider is outside this DPA. If the Customer configures a non-EEA model provider using its own LLM Keys, that provider is the Customer's vendor and any resulting transfer is the Customer's responsibility, not Nodge's.

10. Audits and information

Nodge will make available to the Customer the information necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To satisfy this obligation Nodge will in the first instance provide its ISO 27001:2022 certificate and Statement of Applicability, an independent penetration-test report, and its documented security pack (available under NDA). On-site audits may be conducted no more than once per year, on reasonable prior notice, during business hours, subject to confidentiality, and at the Customer's cost unless an audit reveals a material breach.

11. Personal data breaches

Under the GDPR, notification of a personal data breach to the supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens) is the controller's responsibility. Nodge, as processor, does not make notifications to the supervisory authority; instead Nodge informs the Customer correctly, in time, and in full about relevant incidents, so that the Customer as controller can meet its own legal obligations. To assess whether an incident is a personal data breach, Nodge uses the GDPR and the Dutch policy rules on the data-breach notification duty (Beleidsregels meldplicht datalekken) as guidance.

Notification to the Customer. When Nodge has a security incident or data breach, the Customer will hear about it as soon as possible after it becomes known to Nodge, and in any event within 48 hours of Nodge's discovery. A breach at a sub-processor is notified in the same way, with Nodge acting as the Customer's point of contact. The Customer is expected to assist Nodge where relevant.

The Customer's own deadline. The GDPR requires a breach to be notified "without undue delay" and, where feasible, no later than 72 hours after the controller becomes aware of it. The Customer must itself assess whether the incident is a personal data breach and whether notification to the supervisory authority or to data subjects is required. That 72-hour period for the Customer starts once Nodge has informed it.

Information, progress, and measures. Nodge aims to give the Customer all the information needed for any notification to the supervisory authority or to affected data subjects, and keeps the Customer informed of progress and of the measures Nodge takes, including when the situation changes or further information becomes available. Nodge notifies the contact person designated for the account; the Customer is responsible for keeping that contact person, and any additional breach-notification contacts, up to date. Nodge maintains a documented incident-response runbook.

12. Return or deletion on termination

On termination of the Agreement, and at the Customer's choice, Nodge will delete or return Customer Personal Data held in the EU cloud, and delete existing copies, unless EU or Netherlands law requires storage. The Customer may export Customer Personal Data in standard formats before deletion, and Nodge keeps it available for export for 30 days after termination, matching the Terms. For self-hosted deployments, Customer Personal Data remains in the Customer's environment and this Section does not apply to it. Backups containing Customer Personal Data are purged within the backup retention cycle described in Annex II after the data is deleted from the live Service.

13. Liability and precedence

The liability provisions of the Agreement apply to this DPA. In case of conflict between this DPA and the rest of the Agreement regarding the processing of personal data, this DPA prevails.

Annex I: Description of the processing

Annex II: Technical and organisational measures (Article 32)

These measures reflect the platform as described at https://nodge.ai/security and https://nodge.ai/sovereignty.

Access control and governance

Encryption

Data residency and isolation

Network and abuse protection

Supply-chain security

Backup and recovery

Organisational

Annex III: Sub-processors

The current list of sub-processors, their purpose, and their location is maintained at https://nodge.ai/sub-processors and forms part of this DPA. All are located within the EU/EEA.

Contact

CoreCubes B.V. (Nodge), Winklerlaan 363-41, 3571 KE Utrecht, the Netherlands. KvK 94074542 · BTW NL866626402B01. Reach us at info@nodge.ai.