Data Processing Agreement
Last updated: 29 July 2026
This Data Processing Agreement (the DPA) forms part of the agreement between the client (the Controller) and Nashua B.V. and Nashua Cloud B.V. (together Nashua, we, us or our), private limited companies incorporated under the laws of the Netherlands, with their registered office at Lichttoren 32, 5611 BJ Eindhoven, the Netherlands, registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under number [KvK number] and VAT number [BTW number] (the Processor) and applies wherever Nashua processes Personal Data on the Controller's behalf, including through the Nashua 360 Enterprise Platform and our managed services. It gives effect to Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR). Terms used here have the meaning given in the GDPR.
1. Subject matter and roles
The Processor processes Personal Data solely to provide the agreed services to the Controller. In respect of that Personal Data the Controller is the controller and Nashua is the processor. Each party complies with its own obligations under applicable data-protection law. The details of the processing, the categories of data subjects and types of Personal Data are set out in Annex A.
2. Processing on documented instructions
The Processor processes Personal Data only on the documented instructions of the Controller, including the agreement and this DPA, and as necessary to provide the services, unless required to process by Union or Member State law, in which case it informs the Controller first unless that law prohibits it. The Processor informs the Controller if, in its opinion, an instruction infringes data-protection law.
3. Confidentiality
The Processor ensures that persons authorised to process the Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed. Access is limited to personnel who need it to provide the services.
4. Security of processing
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. These measures are described in Annex B and reflect an information-security programme aligned to ISO/IEC 27001 and the SOC 2 Trust Services Criteria, and take account of the Processor's obligations under DORA and NIS2 as implemented in Dutch law. The Processor may update the measures provided the level of protection is not diminished.
5. Sub-processors
The Controller gives the Processor general authorisation to engage sub-processors to provide the services, including the hosting and infrastructure providers listed in Annex C. The Processor imposes on each sub-processor, by contract, data-protection obligations equivalent to those in this DPA, and remains fully liable to the Controller for the performance of each sub-processor. The Processor informs the Controller of intended changes to sub-processors, giving the Controller a reasonable opportunity to object on reasonable data-protection grounds.
6. International transfers
The Processor does not transfer Personal Data outside the European Economic Area without an adequacy decision or appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses together with any supplementary measures required. By default the Personal Data is hosted within the Netherlands and the EEA.
7. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligations to respond to requests from data subjects exercising their rights, and assists the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security, breach notification, data-protection impact assessments and prior consultation, taking into account the information available to the Processor.
8. Personal data breach notification
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's Personal Data, and provides the information the Controller reasonably needs to meet its own notification obligations to supervisory authorities and data subjects. The Processor documents breaches and the remedial action taken.
9. Return and deletion
On termination of the services, and at the Controller's choice, the Processor deletes or returns all Personal Data and deletes existing copies, unless Union or Member State law requires storage. On request the Processor confirms in writing that it has done so.
10. Audits and inspections
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. The Processor may satisfy audit requests by providing current certifications and attestations, such as an ISO/IEC 27001 certificate or a SOC 2 report, and audits are conducted on reasonable notice, during business hours, subject to confidentiality and without unreasonable disruption to the Processor's operations.
11. Liability
Each party's liability under this DPA is subject to the limitations of liability agreed in the main agreement, to the extent permitted by mandatory law. Nothing in this DPA limits a data subject's rights under the GDPR or either party's liability towards a supervisory authority.
12. Term and governing law
This DPA takes effect together with the agreement and remains in force for as long as the Processor processes Personal Data on the Controller's behalf. It is governed by the laws of the Netherlands, and disputes are subject to the jurisdiction agreed in the main agreement. In the event of conflict between this DPA and the main agreement on data-protection matters, this DPA prevails.
Annex A: Details of the processing
Subject matter and duration: the provision of the agreed services for the term of the agreement. Nature and purpose: hosting, storage, processing, analysis, support and the operation of the Nashua 360 Enterprise Platform and related services, as instructed by the Controller. Categories of data subjects: as determined by the Controller, which may include the Controller's employees, customers, suppliers and contacts. Types of Personal Data: as determined by the Controller through its use of the services, which may include identity, contact, contractual, financial, employment and transactional data. The Controller does not instruct the processing of special categories of Personal Data unless expressly agreed and covered by appropriate additional measures.
Annex B: Technical and organisational measures
The Processor maintains measures appropriate to the risk, including: an information-security management system aligned to ISO/IEC 27001 and the SOC 2 Trust Services Criteria; role-based access control and least privilege with multi-factor authentication; encryption of Personal Data in transit and at rest; network segmentation and perimeter controls; centralised logging, monitoring and alerting; secure software development, code review and change management; vulnerability management and penetration testing; backup and tested disaster recovery aligned to agreed recovery objectives; supplier and sub-processor risk management; business continuity and operational resilience in line with DORA; personnel screening, confidentiality obligations and security awareness training; and a documented incident-management and breach-notification process. The current, detailed measures are available to the Controller on request.
Annex C: Sub-processors
The Processor engages a limited set of sub-processors to provide the services, principally for hosting and infrastructure within the Netherlands and the EEA, and for communication and support tooling. A current list of sub-processors, with their role and location, is available to the Controller on request, and the Processor notifies the Controller of intended additions or replacements in accordance with clause 5.
