
Nexusguard Data Protection Addendum
Last Updated: July 14, 2026
This Data Protection Addendum, including its Schedules (“DPA”), is entered into between the customer identified in the Main Agreement (“Customer”) and Nexusguard Pte. Ltd. and/or the Nexusguard affiliate identified in the Main Agreement (“Nexusguard”). This DPA forms part of the agreement that governs Customer’s purchase or use of the Services, including any master services agreement, partner agreement, service order, quotation, end-user agreement, or other written or electronic agreement (“Main Agreement”).
This DPA takes effect on the later of: (a) the effective date of the Main Agreement; (b) the date the parties sign or otherwise validly accept this DPA; or (c) the date Nexusguard first Processes Customer Personal Data on Customer’s behalf (“DPA Effective Date”). It replaces prior data processing terms between the parties for the same Processing, unless the parties expressly agree otherwise in writing.
If a person accepts this DPA for Customer, that person represents that they have authority to bind Customer.
1. SCOPE, APPLICATION, AND ORDER OF PRECEDENCE
1.1 Scope. This DPA applies only to the extent Nexusguard Processes Customer Personal Data as a Processor in providing the Services. It does not apply to information for which Nexusguard acts as an independent Controller, including business contact, account administration, billing, relationship management, website, recruitment, and similar information described in Nexusguard’s applicable privacy statement.
1.2 Services covered. “Services” includes the Nexusguard products and services ordered by Customer, which may include cloud, on-premises, and true-hybrid deployment of Application Protection, Origin Protection, DNS Protection, Network Protection, Edge Protection, Clean Pipe, Nexusguard Bastions, portals, dashboards, APIs, reporting, managed SOC, technical support, training, testing, and related professional services.
1.3 Processing depends on configuration. The categories and volume of Customer Personal Data Processed depend on the Services, deployment model, traffic-routing configuration, inspection features enabled, Customer instructions, and whether cloud diversion, managed monitoring, support access, or other optional functions are used. Schedule 1 describes the anticipated Processing and is supplemented by the applicable Order.
1.4 Order of precedence. If there is a conflict regarding the Processing or protection of Customer Personal Data, the following order applies: (a) the EU Standard Contractual Clauses or other mandatory transfer terms; (b) any jurisdiction-specific terms in this DPA; (c) this DPA; and (d) the Main Agreement. The Main Agreement otherwise remains in effect.
1.5 No reduction of mandatory rights. Nothing in this DPA limits rights or obligations that cannot lawfully be limited by contract.
2. DEFINITIONS
2.1 "Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common control with a party, for so long as that control exists. "Control" means ownership or control of more than fifty percent of the voting interests or the power to direct management.
2.2 "Applicable Data Protection Law" means any law or binding regulation applicable to the Processing of Customer Personal Data under the Main Agreement, including, where applicable: the EU GDPR; the UK GDPR, the UK Data Protection Act 2018, and the Data (Use and Access) Act 2025; the Swiss Federal Act on Data Protection; the Singapore Personal Data Protection Act 2012; the California Consumer Privacy Act, as amended by the California Privacy Rights Act; and other applicable United States state privacy laws.
2.3 "Controller" means the person or entity that determines the purposes and means of Processing. It includes "business,""organisation," and comparable terms under Applicable Data Protection Law.
2.4 "Customer Personal Data" means Personal Data that Nexusguard Processes as a Processor on behalf of Customer under the Main Agreement. Customer Personal Data does not include data that has been rendered Anonymous Data.
2.5 "Data Subject" means an identified or identifiable natural person to whom Personal Data relates. It includes a "consumer" and comparable terms under Applicable Data Protection Law.
2.6 "EU GDPR" means Regulation (EU) 2016/679.
2.7 "EU SCCs" means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced, or superseded.
2.8 "Personal Data" means information relating to an identified or identifiable natural person, household, or device, or information otherwise defined as personal data, personal information, or a comparable term under Applicable Data Protection Law.
2.9 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed by Nexusguard or its Subprocessors.
2.10 "Process" and "Processing" mean any operation performed on Personal Data, including access, receipt, routing, transmission, inspection, collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, analysis, use, disclosure, restriction, erasure, or destruction.
2.11 "Processor" means a person or entity that Processes Personal Data on behalf of a Controller. It includes "service provider,""contractor,""data intermediary," and comparable terms under Applicable Data Protection Law where the context requires.
2.12 "Restricted Transfer" means a transfer of Personal Data that requires an approved transfer mechanism under Applicable Data Protection Law.
2.13 "Security Measures" means the technical and organizational measures described in Schedule 2, as updated in accordance with this DPA.
2.14 "Subprocessor" means a third party, including a Nexusguard Affiliate, engaged by Nexusguard to Process Customer Personal Data on behalf of Customer.
2.15 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0 in force from 21 March 2022, as amended, replaced, or superseded.
2.16 "UK GDPR" has the meaning given in section 3(10) of the UK Data Protection Act 2018, as amended.
2.17 "Anonymous Data" means information that has been aggregated, de-identified, or anonymized so that it does not identify and cannot reasonably be linked to Customer, a Data Subject, a household, or a device, taking into account means reasonably likely to be used and the requirements of Applicable Data Protection Law.
3. ROLES AND CUSTOMER INSTRUCTIONS
3.1 Roles. Customer is a Controller or Processor of Customer Personal Data. Nexusguard is a Processor or Subprocessor, as applicable. Each party shall comply with the obligations applicable to its role under Applicable Data Protection Law.
3.2 Processing details. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Schedule 1 and the applicable Order.
3.3 Documented instructions. Nexusguard shall Process Customer Personal Data only:
(a) to provide, secure, support, and maintain the Services;
(b) in accordance with the Main Agreement, this DPA, the applicable Order, Customer’s configuration of the Services, and other documented instructions agreed by the parties;
(c) to prevent, detect, analyze, mitigate, and report attacks, abuse, fraud, security threats, and service incidents affecting the Services or protected properties; and
(d) where required by applicable law, in which case Nexusguard shall inform Customer of the legal requirement before Processing unless the law prohibits that notice on important grounds of public interest.
3.4 Unlawful instructions. Nexusguard shall promptly inform Customer if, in Nexusguard’s reasonable opinion, an instruction infringes Applicable Data Protection Law. Nexusguard may suspend the affected Processing until the parties resolve the issue.
3.5 Additional instructions. If Customer requests Processing materially outside the Services or this DPA, the parties shall agree in writing on feasibility, scope, fees, and any required changes before Nexusguard is obligated to perform it.
3.6 Customer as Processor. If Customer acts as a Processor, Customer represents that the relevant Controller has authorized Customer’s instructions, Nexusguard’s appointment as a Subprocessor, the use of Subprocessors, and applicable Restricted Transfers. Customer shall make the relevant portions of this DPA available to that Controller upon request.
4. CUSTOMER RESPONSIBILITIES
4.1 Lawful basis and notices. Customer is responsible for the lawfulness, fairness, transparency, accuracy, quality, and minimization of Customer Personal Data and for providing required notices and obtaining required consents or other lawful bases.
4.2 Authority. Customer shall have all rights and permissions needed to route traffic to the Services, provide Customer Personal Data, authorize inspection and security analysis, and instruct Nexusguard to Process it.
4.3 Configuration. Customer is responsible for selecting and lawfully configuring the Services, including protected assets, routing, DNS, inspection, logging, retention, user access, integrations, data-residency options, and self-service functions.
4.4 Credentials and endpoints. Customer shall protect its credentials, endpoints, origin systems, on-premises infrastructure, and connections to the Services, and shall promptly notify Nexusguard of suspected unauthorized use.
4.5 Sensitive and regulated data. Unless expressly agreed in an Order, Customer shall not intentionally provide special-category data, highly sensitive data, payment card data, protected health information, children’s data, government-classified data, or other data subject to heightened requirements that are not reasonably necessary for the Services. Customer acknowledges that application payloads, support materials, or routed traffic may incidentally contain such data and shall configure the Services and implement safeguards accordingly.
4.6 Cooperation. Customer shall provide accurate information reasonably necessary for Nexusguard to meet its obligations and shall not instruct Nexusguard to violate law or weaken the security or integrity of the Services.
5. NEXUSGUARD PROCESSING OBLIGATIONS
5.1 Purpose limitation. Nexusguard shall not retain, use, disclose, sell, or share Customer Personal Data outside the purposes specified in Section 3 and Schedule 1, except as permitted or required by Applicable Data Protection Law.
5.2 Confidentiality. Nexusguard shall ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security training, and access Customer Personal Data only as necessary for their duties.
5.3 Security. Nexusguard shall implement and maintain the Security Measures. Nexusguard may update them to reflect technical progress, evolving threats, product development, and changes in law, provided the updates do not materially reduce the overall level of protection during the applicable Service term.
5.4 Data minimization. Nexusguard shall limit Customer Personal Data collected and retained to what is reasonably necessary for the applicable Service, security, support, legal, and contractual purposes.
5.5 Records and compliance. Nexusguard shall maintain records and information required of Processors under Applicable Data Protection Law and make relevant information available as described in Section 10.
5.6 Privacy by design. Taking into account the nature and configuration of the Services, Nexusguard shall apply appropriate data protection principles when designing and operating Processing activities, including access limitation, segregation, retention controls, and security by default where technically feasible.
5.7 Anonymous threat intelligence and service analytics. Nexusguard may create and use Anonymous Data derived from service telemetry for threat intelligence, attack trend analysis, security research, capacity planning, benchmarking, product and service improvement, and industry reporting. Nexusguard shall:
(a) use reasonable technical and organizational measures designed to prevent re-identification;
(b) not attempt to re-identify Anonymous Data;
(c) not disclose Customer as the source without Customer’s written permission; and
(d) treat the information as Customer Personal Data if it no longer meets the definition of Anonymous Data.
Nothing in this Section permits Nexusguard to sell or share Customer Personal Data or to build profiles of identified individuals for advertising.
5.8 Independent Controller activities. If Nexusguard determines the purposes and means of a separate Processing activity, Nexusguard acts as an independent Controller for that activity and shall comply with Applicable Data Protection Law. Nexusguard shall not convert Customer Personal Data into independently controlled data merely by labeling it operational, analytics, or security data.
6. PERSONAL DATA BREACH MANAGEMENT
6.1 Notification. Nexusguard shall notify Customer without undue delay after becoming aware of a Personal Data Breach and, where practicable, within 48 hours. Notification is not an admission of fault or liability.
6.2 Notice contents. To the extent known and reasonably available, Nexusguard’s notice shall include:
(a) the nature of the Personal Data Breach;
(b) the categories and approximate number of affected Data Subjects and records;
(c) the likely consequences;
(d) the measures taken or proposed to contain, investigate, and remediate it;
(e) relevant indicators, timelines, and affected Services or locations; and
(f) a contact for follow-up.
6.3 Supplemental information. If all information is not available at once, Nexusguard may provide it in phases without undue further delay. Nexusguard shall provide reasonable updates until containment and material remediation are complete.
6.4 Cooperation. Nexusguard shall take reasonable steps to contain and investigate the Personal Data Breach, mitigate harm, preserve relevant evidence, and assist Customer with legally required risk assessments, regulator notices, and Data Subject communications, taking into account the nature of Processing and the information available to Nexusguard.
6.5 External communications. Nexusguard shall not notify affected Data Subjects or issue a public statement identifying Customer regarding a Personal Data Breach without Customer’s prior written approval, unless required by law. Where legally permitted, Nexusguard shall give Customer advance notice and reasonably consider Customer’s input.
6.6 Customer-caused events. Nexusguard’s obligations apply only to a Personal Data Breach within systems or Processing under Nexusguard’s or its Subprocessors’ control. Nexusguard shall nevertheless reasonably cooperate with Customer regarding security events caused by Customer systems, credentials, configurations, or personnel, subject to the Main Agreement.
7. DATA SUBJECTS, REGULATORS, AND COMPLIANCE ASSISTANCE
7.1 Data Subject requests. If Nexusguard receives a request from a Data Subject relating to Customer Personal Data, Nexusguard shall, where reasonably identifiable:
(a) promptly notify Customer;
(b) not respond substantively except on Customer’s documented instruction or as required by law; and
(c) direct the requester to Customer where appropriate.
7.2 Assistance. Taking into account the nature of Processing, Nexusguard shall provide reasonable assistance through appropriate technical and organizational measures for Customer to respond to requests for access, correction, deletion, restriction, objection, portability, opt-out, appeal, or other applicable rights.
7.3 Verification and decisions. Customer is responsible for verifying requesters, determining whether a request is valid, and responding to the Data Subject. Nexusguard may rely on Customer’s instructions without independently deciding the legal merits of the request.
7.4 Assessments and consultations. Taking into account the nature of Processing and information available, Nexusguard shall reasonably assist Customer with:
(a) data protection impact assessments, risk assessments, and prior consultations;
(b) security-of-processing obligations;
(c) Personal Data Breach notifications and communications; and
(d) reasonable inquiries from competent regulators concerning Nexusguard’s Processing.
7.5 Cost. Nexusguard shall provide standard compliance information and functionality without additional charge. If assistance is unusually burdensome, repetitive, or outside standard Service functionality, Nexusguard may charge reasonable fees agreed in advance, except where the need arises from Nexusguard’s breach of this DPA.
8. SUBPROCESSORS
8.1 General authorization. Customer generally authorizes Nexusguard to engage Subprocessors to provide the Services, subject to this Section.
8.2 Current list. Nexusguard shall maintain and make available a current list of Subprocessors that identifies their name, processing function, and country or region of Processing. Nexusguard shall provide a reasonable mechanism for Customer to subscribe to change notices.
8.3 New Subprocessors. Nexusguard shall give at least 30 days’ prior notice before a new Subprocessor begins Processing Customer Personal Data. If advance notice is impracticable because of an emergency, security risk, legal requirement, or urgent service continuity need, Nexusguard shall notify Customer as soon as reasonably practicable.
8.4 Objections. Customer may object in writing within 15 days after notice, based on reasonable and documented data protection grounds. The parties shall work in good faith to address the objection. Nexusguard may use commercially reasonable alternatives, configure the affected Service to avoid the Subprocessor, or provide supporting information.
8.5 Unresolved objections. If the parties cannot resolve a reasonable objection within 30 days and Nexusguard cannot provide the affected Service without the Subprocessor, Customer may terminate only the affected Service or Order on written notice before the Subprocessor begins the disputed Processing. Any refund is governed by the Main Agreement, except that Customer shall not be charged for Services not provided after the effective termination date.
8.6 Subprocessor terms and responsibility. Nexusguard shall enter into a written agreement with each Subprocessor imposing data protection obligations no less protective in substance than those applicable to Nexusguard for the relevant Processing. Nexusguard remains responsible to Customer for the Subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law.
9. INTERNATIONAL TRANSFERS AND DATA RESIDENCY
9.1 Processing locations. Customer authorizes Nexusguard and its Subprocessors to Process Customer Personal Data in the locations necessary to provide the ordered Services, subject to the applicable Order, agreed data-residency commitments, the Subprocessor list, and this Section.
9.2 Data-residency commitments. Where an Order specifies local or regional Processing, Nexusguard shall Process Customer Personal Data in accordance with that commitment. Nexusguard shall not materially change an agreed residency configuration without notice and, where required by the Order or Applicable Data Protection Law, Customer’s approval. Customer acknowledges that emergency cloud diversion, global attack mitigation, remote support, or integrations may involve additional locations when enabled or requested.
9.3 Transfer mechanisms. Nexusguard shall not make a Restricted Transfer unless it uses a legally valid mechanism, including an adequacy decision, approved standard contractual clauses, binding corporate rules, certification or framework recognized by the applicable authority, or another lawful safeguard.
9.4 EU transfers. For a Restricted Transfer governed by the EU GDPR, the EU SCCs are incorporated by reference and completed as set out in Schedule 3. Module Two applies where Customer is a Controller and Nexusguard is a Processor. Module Three applies where Customer is a Processor and Nexusguard is a Subprocessor. The parties shall not modify the EU SCCs except as they expressly permit.
9.5 UK transfers. For a Restricted Transfer governed by UK Data Protection Law, the UK Addendum is incorporated and completed as set out in Schedule 3.
9.6 Swiss transfers. For a Restricted Transfer governed by the Swiss Federal Act on Data Protection, the EU SCCs apply with the Swiss adaptations in Schedule 3.
9.7 Singapore transfers. Where the Singapore Personal Data Protection Act applies, the terms in Schedule 5 apply and Nexusguard shall provide a standard of protection comparable to that required by the Act for transfers outside Singapore.
9.8 Transfer assessments and supplementary measures. Each party shall provide information reasonably necessary for the other to conduct a transfer impact assessment, transfer risk assessment, data protection test, or comparable assessment. Nexusguard shall implement supplementary technical, contractual, or organizational measures where reasonably necessary for the relevant transfer, taking into account the nature of the data, Service configuration, destination, and law.
9.9 Alternative mechanism. If a transfer mechanism is invalidated, replaced, or no longer available, the parties shall cooperate in good faith to implement a valid replacement. Use of a new mechanism does not reduce protections required by Applicable Data Protection Law.
10. AUDIT, ASSURANCE, AND INFORMATION RIGHTS
10.1 Compliance information. Nexusguard shall make available information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law, subject to confidentiality, security, privilege, and third-party restrictions.
10.2 Independent assurance. Nexusguard may satisfy routine audit requests by providing then-current independent audit reports, certifications, penetration-test summaries, security questionnaires, or other assurance materials relevant to the Services. Such materials may include ISO/IEC 27001, PCI DSS, and SOC 2 materials where applicable to the Services and available.
10.3 Customer audit. If the information in Section 10.2 is reasonably insufficient, Customer may conduct an audit once in any 12-month period, either itself or through an independent qualified auditor that is not a competitor of Nexusguard and is bound by confidentiality. Additional audits are permitted following a material Personal Data Breach affecting Customer Personal Data or where a competent regulator requires them.
10.4 Audit conditions. Audits shall:
(a) be limited to Processing and controls relevant to Customer Personal Data;
(b) occur on at least 30 days’ notice, unless a regulator or urgent incident requires shorter notice;
(c) occur during normal business hours;
(d) avoid unreasonable disruption and risks to other customers, systems, or confidential information;
(e) use remote review where it can reasonably satisfy the purpose; and
(f) comply with Nexusguard’s reasonable safety and security procedures.
10.5 Findings. The parties shall discuss material findings in good faith. Nexusguard shall remediate verified material noncompliance within a reasonable period proportionate to the risk.
10.6 Costs. Each party bears its own audit costs. Customer shall reimburse Nexusguard’s reasonable costs for audits that are unusually burdensome or exceed Section 10.3, unless the audit identifies material noncompliance by Nexusguard.
11. RETURN, DELETION, AND RETENTION
11.1 During the term. Customer may use available Service functionality to retrieve or delete Customer Personal Data. Where functionality is unavailable, Nexusguard shall reasonably assist upon documented request.
11.2 End of Services. At Customer’s choice, communicated before termination or within 30 days afterward, Nexusguard shall return or delete Customer Personal Data. Unless the applicable Order states otherwise, Nexusguard shall complete deletion from active systems within 90 days after termination of the affected Service.
11.3 Backups. Customer Personal Data in backups, archives, or disaster-recovery systems may remain until overwritten or deleted through ordinary cycles, provided it is protected, isolated from routine use, and not restored except for recovery, legal, or security purposes. If restored, this DPA continues to apply and the data shall be deleted again when no longer needed.
11.4 Legal retention. Nexusguard may retain Customer Personal Data to the extent required by law, legal process, or binding regulatory obligation. Nexusguard shall isolate the retained data, limit Processing to the required purpose, and delete it when the obligation ends.
11.5 Anonymous Data. Sections 11.2–11.4 do not require deletion of Anonymous Data.
12. GOVERNMENT AND THIRD-PARTY ACCESS REQUESTS
12.1 Notice. If Nexusguard receives a legally binding request from a government, law-enforcement authority, court, or other third party for Customer Personal Data, Nexusguard shall, unless prohibited by law:
(a) notify Customer before disclosure;
(b) inform the requester that Nexusguard Processes the data on Customer’s behalf where appropriate;
(c) direct the requester to Customer where lawful and practicable; and
(d) provide sufficient information for Customer to seek a protective order or other remedy.
12.2 Review and challenge. Nexusguard shall review requests for legal validity and scope and, where there are reasonable grounds, challenge unlawful, overbroad, or disproportionate requests. Nexusguard shall disclose only the minimum Customer Personal Data legally required.
12.3 Transparency. On reasonable request and where legally permitted, Nexusguard shall provide general information about relevant categories of requests and its response practices.
12.4 Emergency disclosure. Nexusguard may disclose Customer Personal Data where it reasonably and in good faith believes disclosure is necessary to prevent imminent death or serious physical harm. Nexusguard shall notify Customer as soon as legally permitted.
13. UNITED STATES STATE PRIVACY TERMS
If Customer Personal Data is subject to the California Consumer Privacy Act or another applicable United States state privacy law, Schedule 4 applies. To the extent of a conflict, Schedule 4 controls for that Customer Personal Data.
14. CHANGES TO THIS DPA
14.1 Nexusguard may update this DPA to reflect changes in law, regulatory guidance, Services, security, or business operations. Nexusguard shall provide reasonable advance notice of a material change that reduces Customer’s contractual rights or materially expands Nexusguard’s Processing of Customer Personal Data.
14.2 An update required to comply with law, replace an invalid transfer mechanism, address an urgent security issue, or implement a regulator’s binding direction may take effect sooner, but Nexusguard shall provide notice as soon as reasonably practicable.
14.3 Except for updates permitted by this Section or changes to referenced mandatory legal instruments, amendments must be agreed in writing by authorized representatives of both parties.
15. GENERAL
15.1 Term. This DPA remains effective for as long as Nexusguard Processes Customer Personal Data.
15.2 Liability. Liability arising from this DPA is subject to the exclusions and limitations in the Main Agreement, except to the extent Applicable Data Protection Law or the EU SCCs prohibit that limitation.
15.3 Governing law and forum. The governing law and forum in the Main Agreement apply to this DPA, except where mandatory transfer terms or Applicable Data Protection Law require otherwise.
15.4 No third-party beneficiaries. Except for rights expressly granted to Data Subjects under the EU SCCs or other mandatory law, this DPA creates no third-party beneficiary rights.
15.5 Severability. If a provision is invalid or unenforceable, it shall be interpreted or modified to the minimum extent necessary to make it enforceable, and the remaining provisions remain in effect.
15.6 Notices. Notices under this DPA shall be sent using the notice method in the Main Agreement. Operational privacy and security communications may also be sent to the contacts designated by the parties.
15.7 Entire agreement on Processing. This DPA and the Main Agreement constitute the parties’ agreement regarding Nexusguard’s Processing of Customer Personal Data and supersede prior terms on that subject.
SCHEDULE 1 — DETAILS OF PROCESSING
A. SUBJECT MATTER
Nexusguard Processes Customer Personal Data to provide the Services ordered by Customer. Depending on configuration, this may include protecting applications, websites, APIs, servers, networks, connectivity, DNS infrastructure, and other digital assets against distributed denial-of-service attacks, application attacks, abuse, and related security threats.
B. DURATION
Processing continues for the term of the affected Service and any period necessary for return, deletion, backup cycling, incident investigation, legal retention, or transition as permitted by this DPA and the Main Agreement.
C. NATURE AND PURPOSES
Processing may include:
• receiving, routing, transmitting, diverting, inspecting, filtering, cleansing, and returning network, application, and DNS traffic;
• collecting and analyzing flow records, packet and protocol attributes, DNS queries and records, HTTP or API attributes, logs, alerts, attack indicators, and security telemetry;
• detecting, classifying, investigating, mitigating, and reporting attacks, vulnerabilities, abuse, and service incidents;
• establishing traffic baselines, applying detection and mitigation policies, reputation data, WAF rules, rate controls, challenges, and other security measures;
• operating scrubbing centers, Bastions, cloud, on-premises, and hybrid infrastructure;
• providing portals, dashboards, APIs, reports, notifications, account access, multi-tenant administration, and audit logs;
• providing managed SOC, technical support, troubleshooting, maintenance, service optimization, training, testing, and professional services;
• maintaining availability, resilience, backups, disaster recovery, capacity, and Service security;
• complying with documented Customer instructions and applicable legal obligations; and
• creating Anonymous Data as permitted by Section 5.7.
D. CATEGORIES OF DATA SUBJECTS
Customer Personal Data may relate to:
• Customer personnel, contractors, administrators, authorized users, and support contacts;
• Customer’s affiliates, partners, resellers, communications service providers, and downstream customers;
• visitors and users of Customer’s protected websites, applications, APIs, networks, and DNS services;
• subscribers, customers, employees, or other persons using protected connectivity or digital services;
• persons whose information appears in routed traffic, packet payloads, DNS queries, logs, alerts, reports, tickets, or support materials; and
• suspected attackers, security researchers, abuse reporters, and other persons associated with network or security events.
E. CATEGORIES OF PERSONAL DATA
Depending on the Service and configuration:
• identifiers and contact data, including names, usernames, business contact details, account IDs, and customer or tenant identifiers;
• authentication and authorization data, including credentials or tokens in protected traffic, portal access records, roles, and audit trails;
• network and device identifiers, including IP addresses, MAC addresses where available, ports, protocols, autonomous system numbers, device or session identifiers, and inferred approximate location;
• traffic and connection data, including timestamps, source and destination information, flow records, bandwidth, packet and protocol attributes, routing data, GRE or BGP-related configuration, and connection behavior;
• DNS data, including queries, responses, domain names, zones, records, resolver and authoritative-server information;
• application and web data, including URLs, request methods, query parameters, headers, cookies, user agents, API attributes, and limited payload or content where routed, logged, or inspected by configured features;
• security data, including attack indicators, reputation information, detected threats, WAF events, mitigation actions, alerts, baselines, and incident records;
• configuration data, including protected IP ranges, domains, policies, allowlists, blocklists, thresholds, integrations, and notification settings;
• support and professional-services data, including tickets, messages, diagnostic files, screenshots, packet captures, data dumps, logs, and recordings supplied by Customer; and
• other Personal Data contained incidentally in traffic or materials Customer makes available.
F. SPECIAL OR HIGHLY REGULATED DATA
The Services do not require Customer intentionally to submit special-category or highly regulated data unless expressly agreed. Such data may nevertheless appear incidentally in encrypted or unencrypted application traffic, payloads, logs, DNS data, or support materials. Customer controls the sources and configuration and is responsible for identifying additional legal requirements. Where the parties expressly agree that Nexusguard will intentionally Process such data, the applicable Order shall identify it and any additional safeguards.
G. FREQUENCY AND VOLUME
Processing may be continuous for always-on Services, event-driven for on-demand mitigation, periodic for monitoring and reporting, or occasional for support and professional services. Volume depends on Customer traffic, protected assets, attack activity, and Service configuration.
H. PROCESSING LOCATIONS AND SUBPROCESSORS
Processing locations are determined by the applicable Order, deployment and data-residency configuration, routing and mitigation decisions, support model, and current Subprocessor list.
I. CONTROLLER RIGHTS AND OBLIGATIONS
Customer retains the rights and obligations of a Controller described in the Main Agreement and Applicable Data Protection Law, including the right to issue lawful documented instructions and obtain the information and assistance described in this DPA.
SCHEDULE 2 — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Nexusguard shall maintain a documented security program proportionate to the nature of the Services, Customer Personal Data, and risks. The controls below apply as relevant to the Service and deployment model.
A. SECURITY GOVERNANCE AND RISK MANAGEMENT
• Assigned information-security roles and responsibilities.
• Documented security policies, standards, and procedures reviewed periodically.
• Risk assessments addressing confidentiality, integrity, availability, resilience, and privacy.
• Asset inventory and classification appropriate to systems that Process Customer Personal Data.
• Change management and exception management.
• Periodic review by management and independent assurance where applicable.
B. PERSONNEL SECURITY
• Confidentiality obligations for personnel with access to Customer Personal Data.
• Appropriate pre-employment screening where lawful and proportionate.
• Role-based privacy and security training at onboarding and periodically thereafter.
• Prompt removal or adjustment of access when roles change or employment ends.
• Disciplinary processes for violations of security policy.
C. PHYSICAL AND ENVIRONMENTAL SECURITY
• Physical access controls for Nexusguard-controlled facilities based on authorization and business need.
• Logging or monitoring of access to sensitive processing areas where appropriate.
• Environmental protections, power, fire detection or suppression, and redundancy appropriate to the facility.
• Contractual and assurance controls for third-party data centers.
D. IDENTITY AND ACCESS MANAGEMENT
• Unique user identities and role-based access.
• Least privilege and need-to-know principles.
• Multi-factor authentication for privileged or remote administrative access where technically supported.
• Strong authentication and credential-management controls.
• Periodic review of privileged and other sensitive access.
• Controlled emergency and service accounts.
• Session timeout, lockout, and logging controls appropriate to the system.
E. NETWORK AND INFRASTRUCTURE SECURITY
• Layered network controls, segmentation, firewalls, filtering, and restricted administrative interfaces.
• Hardened configurations and secure management protocols.
• DDoS detection, mitigation, routing, scrubbing, and traffic-policing controls relevant to the Services.
• Protection of management planes and separation from customer traffic where appropriate.
• Monitoring for anomalous activity, unauthorized access, abuse, and attack.
• Resilient architecture, redundancy, and capacity management appropriate to the Service.
F. ENCRYPTION AND KEY MANAGEMENT
• Encryption of Customer Personal Data in transit over public networks using industry-accepted protocols where technically feasible.
• Encryption at rest for Customer Personal Data stored in systems where appropriate to risk and technically supported.
• Protection, restricted access, rotation, and lifecycle management of cryptographic keys and secrets.
• Secure certificate and protocol configuration practices.
Customer acknowledges that Nexusguard may need to inspect unencrypted traffic, decrypt traffic using Customer-provided keys, or receive packet data in clear text where required by the configured security Service.
G. SECURE DEVELOPMENT AND CHANGE CONTROL
• Secure software-development practices appropriate to Nexusguard-developed software.
• Code review, dependency management, testing, and controlled deployment.
• Separation of development, test, and production environments where appropriate.
• Change authorization, testing, rollback planning, and recording.
• Measures designed to prevent unauthorized code or configuration changes.
H. VULNERABILITY AND PATCH MANAGEMENT
• Vulnerability scanning and assessment based on system risk.
• Risk-based prioritization and remediation of security vulnerabilities.
• Patch and update management for supported systems.
• Penetration testing or comparable technical assessment periodically and after material changes where appropriate.
• Processes to receive, evaluate, and address reported vulnerabilities.
I. LOGGING, MONITORING, AND DETECTION
• Logging of relevant administrative access, security events, configuration changes, and system activity.
• Protection of logs against unauthorized access and alteration.
• Time synchronization appropriate to investigation and correlation.
• Monitoring and alerting for suspicious or anomalous activity.
• Retention of logs for periods appropriate to operational, security, contractual, and legal requirements.
• Access to logs limited based on role and need.
J. INCIDENT RESPONSE
• Documented incident-response and escalation procedures.
• Personnel assigned to investigate, contain, eradicate, recover from, and communicate incidents.
• Preservation of relevant evidence and maintenance of incident records.
• Testing or exercising of incident-response processes periodically.
• Post-incident review and corrective-action tracking.
• Customer notification and cooperation as described in Section 6.
K. AVAILABILITY, CONTINUITY, AND RECOVERY
• Redundancy and failover appropriate to the applicable Service.
• Backup and restoration controls for stored Customer Personal Data and critical configurations where applicable.
• Business-continuity and disaster-recovery planning.
• Periodic testing of restoration or recovery capabilities.
• Monitoring of capacity, availability, and critical dependencies.
L. DATA LIFECYCLE AND MEDIA
• Retention and deletion procedures aligned with the Services and Section 11.
• Secure disposal or sanitization of media and systems before reuse or retirement.
• Restrictions on removable media and local storage appropriate to risk.
• Controls designed to prevent unauthorized copying, export, or disclosure.
• Procedures for legal holds and required retention.
M. TENANT AND PURPOSE SEPARATION
• Logical segregation of customer accounts, configurations, reports, and stored data in multi-tenant systems.
• Authorization checks designed to prevent cross-customer access.
• Separation of data and functions by role, tenant, module, or purpose where appropriate.
• Controlled use of production data in non-production environments.
N. SUPPLIER AND SUBPROCESSOR SECURITY
• Risk-based due diligence before onboarding relevant Subprocessors.
• Written security and privacy obligations.
• Ongoing review proportionate to the service and risk.
• Incident-notification and cooperation requirements.
• Termination and data-return or deletion controls.
O. ASSURANCE AND CONTINUOUS IMPROVEMENT
• Internal review and independent audit or certification appropriate to the Services.
• Corrective-action processes for material findings.
• Security program updates based on threat intelligence, incidents, testing, legal change, and technical development.
• Upon appropriate request and subject to confidentiality, relevant then-current assurance information, which may include ISO/IEC 27001, PCI DSS, and SOC 2 materials where applicable.
P. SHARED RESPONSIBILITY FOR ON-PREMISES AND HYBRID SERVICES
For Customer-controlled, partner-controlled, or on-premises infrastructure, Customer is responsible for physical security, local network security, identity administration, system connectivity, supported hardware environment, Customer-managed keys and certificates, Customer configurations, and other controls allocated to Customer in the Documentation or Order. Nexusguard is responsible for the controls within the components and activities it controls. Remote management, managed SOC, cloud diversion, support, and telemetry may extend Nexusguard’s Processing beyond the on-premises environment as configured or ordered.
SCHEDULE 3 — INTERNATIONAL TRANSFER TERMS
A. EU STANDARD CONTRACTUAL CLAUSES
1. Application. The EU SCCs apply to Restricted Transfers governed by the EU GDPR when no adequacy decision or other lawful transfer mechanism covers the transfer.
2. Modules.
• Module Two applies to transfers from a Controller to a Processor.
• Module Three applies to transfers from a Processor to a Subprocessor.
• If more than one role applies, each applicable Module applies to the relevant Processing.
3. Elections.
• Clause 7 (Docking Clause) applies.
• Clause 9, Option 2 (general written authorization) applies. The notice period is the period stated in Section 8.3 of this DPA.
• The optional language in Clause 11 does not apply.
• Under Clause 17, Option 1 applies. The governing law is the law of the EEA country in which the data exporter is established, provided that law permits third-party beneficiary rights. If it does not, Irish law applies.
• Under Clause 18, disputes shall be resolved by the courts corresponding to the governing law selected under Clause 17; if Irish law applies, the courts of Ireland apply.
4. Annex I.A — List of parties.
Data exporter: Customer and any authorized Customer Affiliate exporting Customer Personal Data. Its name, address, contact details, activities, and role are stated in the Main Agreement, applicable Order, and Schedule 1.
Data importer: Nexusguard Pte. Ltd. and/or the Nexusguard affiliate identified in the Main Agreement or applicable Order. Contact: the privacy contact published by Nexusguard or otherwise designated in writing.
Signature and date: The parties’ execution or valid electronic acceptance of the Main Agreement or this DPA constitutes signature and dating of the EU SCCs.
5. Annex I.B — Description of transfer. Schedule 1 describes the categories of Data Subjects, categories of Personal Data, sensitive data and safeguards, frequency, nature, purposes, duration, retention, and subject matter. Transfers to Subprocessors are described by the current Subprocessor list and applicable Order.
6. Annex I.C — Competent supervisory authority. The competent supervisory authority is determined under Clause 13 of the EU SCCs.
7. Annex II — Security Measures. Schedule 2 forms Annex II of the EU SCCs.
8. Annex III — Subprocessors. The current Subprocessor list made available under Section 8 forms Annex III for Module Three.
9. Conflict. If this DPA conflicts with the EU SCCs, the EU SCCs control for the Restricted Transfer.
B. UNITED KINGDOM
1. The UK Addendum applies to Restricted Transfers governed by UK Data Protection Law where the EU SCCs are used as the underlying approved clauses.
2. Table 1. The parties, contacts, and signature details are those in Part A.4 above, adapted so that “data exporter” and “data importer” have the meanings in the UK Addendum.
3. Table 2. The selected EU SCCs, Modules, clauses, and options are those in Part A above.
4. Table 3. The Appendix Information is in Schedule 1, Schedule 2, and the current Subprocessor list.
5. Table 4. Either party may end the UK Addendum as permitted by its mandatory clauses if the UK Information Commissioner issues revised approved terms.
6. The mandatory clauses of Part 2 of the UK Addendum are incorporated without modification. References to UK Data Protection Law include amendments made by the Data (Use and Access) Act 2025 and any successor legislation.
C. SWITZERLAND
For Restricted Transfers governed by the Swiss Federal Act on Data Protection:
• references in the EU SCCs to the GDPR are interpreted as references to the Swiss Federal Act on Data Protection to the extent necessary;
• “personal data” and “data subject” have the meanings under Swiss law;
• references to a Member State or the Union include Switzerland where appropriate;
• the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
• the applicable law and courts shall be Switzerland where required for Swiss-law rights, without preventing Data Subjects in Switzerland from bringing claims in Switzerland;
• the EU SCCs protect data of legal persons only to the extent Swiss law requires; and
• the parties shall apply any adaptations recognized or required by the Swiss Federal Data Protection and Information Commissioner.
D. SUPPLEMENTARY MEASURES
Where a transfer assessment identifies a material risk that the transfer mechanism alone does not provide the required protection, Nexusguard shall apply reasonable supplementary measures appropriate to the Service. These may include encryption, pseudonymization, data minimization, access controls, localization, split processing, transparency, government-request review, or contractual safeguards.
SCHEDULE 4 — UNITED STATES STATE PRIVACY TERMS
A. ROLES AND PURPOSES
1. Where an applicable United States state privacy law uses the concepts of business and service provider, controller and processor, or contractor, Customer is the business or controller and Nexusguard is the service provider, processor, or contractor for Customer Personal Data.
2. The limited and specified purposes for Processing are the Services and activities described in Section 3 and Schedule 1. The parties agree that those purposes are reasonably necessary and proportionate to provide, secure, support, maintain, and improve the Services as permitted by law.
B. RESTRICTIONS
Nexusguard shall not:
• sell or share Customer Personal Data;
• retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the limited and specified purposes;
• combine Customer Personal Data with Personal Data received from another person or collected from Nexusguard’s own interaction with a Data Subject, except as expressly permitted for a service provider or processor by applicable law;
• use Customer Personal Data for cross-context behavioral advertising or targeted advertising; or
• attempt to re-identify data that meets the applicable legal standard for de-identified or aggregate data.
C. REQUIRED COMMITMENTS
1. Nexusguard shall comply with applicable obligations imposed on service providers, processors, and contractors and provide the same level of privacy protection required by the applicable state privacy law for the relevant Processing.
2. Nexusguard shall notify Customer if Nexusguard determines it can no longer meet its obligations.
3. Customer may take reasonable and appropriate steps to help ensure consistent Processing and to stop and remediate unauthorized use, including through the information and audit rights in Section 10.
4. Nexusguard shall provide reasonable assistance with authenticated consumer requests as described in Section 7 and shall not respond directly except as permitted by law or instructed by Customer.
5. Nexusguard shall require each relevant Subprocessor to comply with equivalent restrictions.
6. The parties acknowledge that Customer discloses Customer Personal Data to Nexusguard only for the limited and specified business purposes in this DPA and that Nexusguard receives no Personal Data as consideration for Services.
D. CCPA REFERENCES
For California Personal Data, references to the California Consumer Privacy Act include amendments made by the California Privacy Rights Act and applicable regulations. The business purposes include detecting security incidents, resisting malicious or illegal actions, maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments where ordered, providing analytics limited to the Services, maintaining quality and safety, and other purposes permitted for a service provider or contractor.
SCHEDULE 5 — SINGAPORE PERSONAL DATA PROTECTION ACT TERMS
A. ROLE
Where Nexusguard Processes Customer Personal Data on behalf of Customer under the Singapore Personal Data Protection Act 2012 (“Singapore PDPA”), Nexusguard acts as a data intermediary and Customer acts as the organization engaging it, unless a separate Processing activity makes Nexusguard an organization in its own right.
B. DATA INTERMEDIARY OBLIGATIONS
Nexusguard shall:
• make reasonable security arrangements to protect Customer Personal Data against unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks;
• cease retention or anonymize Customer Personal Data when it is reasonable to assume the purpose is no longer served and retention is no longer necessary for legal or business purposes, subject to Section 11;
• notify Customer without undue delay after Nexusguard has credible grounds to believe a Personal Data Breach has occurred, in accordance with Section 6; and
• reasonably assist Customer with its assessment and notification obligations.
C. OVERSEAS TRANSFERS
For a transfer of Customer Personal Data outside Singapore, Nexusguard shall ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the Singapore PDPA, unless another exception or lawful basis applies. The protections in this DPA are intended to provide those enforceable obligations.
D. CUSTOMER RESPONSIBILITY
Customer remains responsible for its obligations as an organization under the Singapore PDPA, including accountability, notification, consent or other authorization, purpose limitation, accuracy, access and correction, and determining whether a breach is notifiable.
END OF DPA
Enhance Government Cybersecurity with Nexusguard Bastions
