Data Processing Addendum
Last updated 14 August 2026 · Effective 14 August 2026
This applies when your application stores personal data about your users and you are subject to the EU GDPR, the UK GDPR, or a comparable law. In that relationship you are the controller and NukeBase is the processor. It forms part of the Terms of Service and takes effect automatically — you do not need to sign anything, though we will sign a copy on request.
1. Definitions
"Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data contained in your projects, databases and files that we process on your behalf.
2. Roles
- You are the controller of Customer Personal Data. You decide what it is, why it is collected, and how long it is kept.
- We are the processor, acting only on your documented instructions. Your use of the platform — deploying an app, calling our APIs, configuring security rules — constitutes those instructions.
- For your own account data (your email, billing records, usage measurements) we are a controller, and our Privacy Policy governs that.
- NukeBase is not a zero-knowledge or end-to-end encrypted service. We are able to access Customer Personal Data, and do so for the limited operational and abuse-investigation purposes listed in section 4. If your use case requires that your provider be technically incapable of reading your data, NukeBase is not a suitable platform for it.
3. Subject matter and details of processing
| Subject matter | Hosting and operating applications and their data on your behalf |
|---|---|
| Duration | For as long as your account is open, plus the retention periods in section 8 |
| Nature and purpose | Storage, retrieval, transmission, backup, and execution of your application code |
| Types of personal data | Whatever your application chooses to store. Typically account identifiers and email addresses; potentially any data you decide to collect |
| Categories of data subject | Your end users, and anyone else whose data your application holds |
Special category data. NukeBase is a general-purpose platform and is not certified for health, biometric or financial-regulatory data. You may store special category data only if you have your own lawful basis and appropriate safeguards. We are not currently a HIPAA business associate and do not accept protected health information.
4. Our obligations
We will:
- Process Customer Personal Data only on your documented instructions, unless required otherwise by law — in which case we will tell you first unless the law forbids it. Your instructions are deemed to include the operational access described in section 4 of the Privacy Policy: operating, maintaining, migrating, backing up and restoring the platform; diagnosing faults; providing support you request; investigating suspected breaches of the Acceptable Use Policy; and protecting the security of the platform, our customers and the public.
- Ensure people authorised to access it are bound by confidentiality.
- Apply the technical and organisational measures in section 6.
- Respect the conditions in section 5 for engaging sub-processors.
- Help you respond to data subject requests, taking into account the nature of the processing.
- Help you with security, breach notification and impact assessments, as far as is reasonable given what we know.
- Delete or return Customer Personal Data at the end of the service, as described in section 8.
- Make available the information needed to demonstrate compliance, and allow audits as described in section 9.
5. Sub-processors
You give general authorisation for us to use the sub-processors below. We remain responsible for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| OVHcloud | Servers, storage and network | United States |
| Stripe, Inc. | Payments and subscription billing (account data only) | United States |
| Mailgun (Sinch) | Transactional and sign-in email delivery | United States |
| Internet Security Research Group (Let's Encrypt) | TLS certificates for custom domains | United States |
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you; if we cannot resolve it, you may terminate the affected service and receive a refund of the unused prepaid portion.
6. Security measures
- Encryption in transit for all traffic (HTTPS/TLS).
- Per-tenant isolation: each customer's projects run under a separate operating system user with their own memory limits and disk quota, so one tenant cannot reach another's data.
- Authentication by emailed sign-in link; session tokens stored hashed, never in plaintext. Ordinary accounts have no stored password.
- Rate limiting on authentication and email endpoints.
- A configurable security-rules engine that lets you control access to your own data.
- Payment card data never reaches our infrastructure.
- Production access restricted to personnel who require it.
We may update these measures, provided the level of protection is not reduced.
7. International transfers
Our infrastructure is located in the United States in both regions. Where you or your data subjects are in the UK, EU or EEA, transfers rely on:
- the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor), incorporated into this Addendum by reference; and
- the UK International Data Transfer Addendum to those clauses, for UK transfers.
Where the clauses require details, this Addendum supplies them: you are the data exporter, we are the data importer, and sections 3, 5, 6 and 8 populate the corresponding annexes. Where this Addendum and the clauses conflict, the clauses prevail.
8. Return and deletion
- You can export your project — every file, exactly as stored — at any time from your dashboard, without asking us.
- On cancellation, projects stop and are deleted after a 30-day grace period.
- On account deletion, the account record is marked deleted immediately and purged within 30 days. The delay exists so the deletion propagates across regions and is not reversed by replication.
- Backups age out on their own cycle; data may persist there briefly after deletion, and remains subject to this Addendum until it is gone.
9. Audits
On reasonable written notice, no more than once a year (unless a regulator requires otherwise), we will provide the information reasonably necessary to demonstrate compliance with this Addendum. Where documentation is not enough, we will discuss an audit scoped so it does not compromise the security or confidentiality of other customers.
10. Personal data breach
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. We will include what we know about its nature, the likely consequences, and what we are doing about it, and will keep you updated as we learn more. Notifying your regulator and your data subjects is your responsibility as controller; we will help you do it.
11. Liability
Liability under this Addendum is subject to the limitations in the Terms of Service, except where the GDPR does not permit that.
12. Contact
Data protection queries, signed-copy requests and audit enquiries: support@nukebase.com
Anderson Web Consulting, 17834 Stony Ridge Ave, [CITY], Idaho [ZIP], USA
If you offer goods or services to people in the EU or UK and have no establishment there, you may need an Article 27 representative. [CONFIRM WHETHER AN EU/UK REPRESENTATIVE IS APPOINTED]