Platform
The ProblemThe Neivan ApproachHow it WorksAgent TemplatesMobile AppFAQs
Resources
SecurityDocumentationAPI Reference
AboutPricing
Sign inRequest Access
The ProblemThe Neivan ApproachHow it WorksAgent TemplatesMobile AppFAQs
SecurityDocumentationAPI Reference
AboutPricingContact SalesSign in
Legal

Data Processing Addendum

Effective July 22, 2026.

Version 2.1 · Last updated July 22, 2026

On this page
  • Overview
  • Definitions
  • Roles of the parties
  • Customer instructions and compliance
  • Details of processing (Annex I)
  • Confidentiality of personnel
  • Security measures (Annex II)
  • Sub-processors
  • International transfers
  • Data subject rights and assistance
  • Personal data breach notification
  • Government and law-enforcement requests
  • CCPA / U.S. service-provider terms
  • Audit rights
  • Return and deletion
  • Liability and precedence

Overview

This Data Processing Addendum ("DPA") supplements and forms part of the Neivan Terms of Service (the "Agreement") between Neivan, Inc. ("Neivan") and the customer ("Customer"). It applies whenever Neivan processes Personal Data on behalf of Customer in connection with delivering the Services.

When you accept the Agreement, you accept this DPA. Enterprise customers may request a counter-signed copy — email [email protected]. In the event of a conflict between this DPA and the rest of the Agreement with respect to the processing of Personal Data, this DPA controls; the Standard Contractual Clauses (where they apply) prevail over this DPA on transfer issues.

Definitions

Capitalized terms not defined here have the meaning in the Agreement. "Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including the EU GDPR, the UK GDPR, the Swiss FADP, and U.S. state privacy laws (including the CCPA/CPRA). "Personal Data", "controller", "processor", "data subject", "processing", and "personal data breach" have the meanings in applicable Data Protection Laws. "Customer Personal Data" means Personal Data within Customer Content that Neivan processes on Customer’s behalf. "Sub-processor" means a third party engaged by Neivan to process Customer Personal Data. "SCCs" means the European Commission Standard Contractual Clauses (Module Two, controller-to-processor).

Roles of the parties

Customer is the controller (or, where Customer is itself a processor, the processor) of Customer Personal Data; Neivan is the processor (or sub-processor). Where Customer’s data subjects are in the EEA, UK, or Switzerland, Neivan acts as a processor under the EU GDPR, UK GDPR, and Swiss FADP. With respect to data for which Neivan is the controller (e.g., account, billing, and product-telemetry data), the Privacy Policy applies rather than this DPA.

Neivan engages the Sub-processors listed at /legal/sub-processors. Customer authorizes those Sub-processors and the addition of future ones subject to the notice procedure below.

Customer instructions and compliance

Neivan will process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement and this DPA, and as necessary to provide and secure the Services and comply with law. If Neivan is required by law to process beyond Customer’s instructions, it will inform Customer (unless legally prohibited). Neivan will notify Customer if, in its opinion, an instruction infringes Data Protection Laws (without obligation to provide legal advice).

Customer is responsible for the lawfulness of Customer Personal Data and of Customer’s instructions, including having an appropriate legal basis and providing any required notices and obtaining any required consents.

Details of processing (Annex I)

Subject matter and nature: provision of the Neivan AI orchestration platform and related support, including hosting, storage, transmission, and AI inference performed on Customer’s instructions. Purpose: to deliver, support, secure, and improve the Services per the Agreement.

Duration: the term of Customer’s subscription, plus a 30-day return/deletion window after termination (and routine backup expiry).

Categories of data subjects: Customer’s employees, contractors, and any third parties whose data Customer chooses to process through the Services.

Categories of Personal Data: authentication identifiers and account data; usage telemetry; and any Personal Data contained in Customer Content that Customer or its agents submit (which may include contact, business, and free-text data). Special categories are not required by the Services; if Customer chooses to process them, Customer does so under its own responsibility and instructions.

Frequency: continuous, for the duration of the subscription. Recipients: Neivan personnel on a need-to-know basis and the Sub-processors listed at /legal/sub-processors.

Confidentiality of personnel

Neivan ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and receive appropriate data-protection and security training, and that access is limited to those who need it to provide the Services.

Security measures (Annex II)

Neivan implements appropriate technical and organizational measures to protect Customer Personal Data, including: encryption in transit (TLS 1.3) and at rest (AES-256); role-based access control, least-privilege access, and MFA for privileged access; network protections (firewall, WAF, DDoS mitigation) and key management; immutable audit logging; vulnerability management including static analysis and dependency scanning in CI (with an independent penetration test planned before general availability); secure software-development and change-management practices; business-continuity and backup procedures; and a documented incident-response process. Detail is published at /legal/security.

Neivan has implemented controls aligned to SOC 2 Type II and audits them internally; an independent audit has not yet been engaged. Once an independent report is issued, Neivan will make it available to Customer under NDA. Neivan reviews and updates its measures over time and will not materially reduce the overall level of security during the term.

Sub-processors

Current Sub-processors are listed at /legal/sub-processors. Neivan imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA and remains responsible for each Sub-processor’s performance of its obligations.

Neivan provides at least 30 days’ advance notice before engaging a new Sub-processor (by updating the page and emailing account owners who subscribe to the notification list). Customer may object in writing during the notice period on reasonable data-protection grounds; Neivan will use commercially reasonable efforts to provide an alternative, and if none is feasible, Customer may terminate the affected Services without penalty.

International transfers

Where transfers of Customer Personal Data leave the EEA, UK, or Switzerland to a country without an adequacy decision, Neivan relies on the SCCs (Module Two, controller-to-processor), the UK International Data Transfer Addendum to the SCCs, and the Swiss addendum, as applicable, each incorporated into this DPA by reference. Where Neivan is itself acting as a processor exporting to a Sub-processor, the relevant SCC module applies.

For the purposes of the SCCs: the data-export/import details are as set out in "Details of processing (Annex I)"; the technical and organizational measures are as set out in "Security measures (Annex II)"; and the supervisory authority and governing law are as determined under the SCCs. EU/UK data residency options are on the Enterprise roadmap.

Data subject rights and assistance

Taking into account the nature of the processing, Neivan provides functionality enabling Customer to access, correct, delete, restrict, and export Personal Data from within the Services (Settings → Privacy), and will provide reasonable assistance where Customer cannot address a request itself. If a data subject contacts Neivan directly regarding Customer Personal Data, Neivan will, without undue delay, redirect them to Customer and not respond except on Customer’s instruction or as required by law.

Neivan will also provide reasonable assistance with Customer’s obligations regarding data-protection impact assessments and prior consultation with supervisory authorities, taking into account the information available to Neivan.

Personal data breach notification

Neivan notifies affected Customers without undue delay (target: within 72 hours of confirmation) of any personal data breach affecting Customer Personal Data, with information sufficient to meet Customer’s notification obligations (including under GDPR Art. 33–34) where applicable, and will take reasonable steps to mitigate and remediate. Neivan’s notification is not an acknowledgment of fault or liability.

Government and law-enforcement requests

If Neivan receives a legally binding request from a public authority for Customer Personal Data, Neivan will, unless legally prohibited, notify Customer, and will challenge requests that are unlawful or overbroad, disclosing only the minimum amount of data legally required. Neivan does not grant any government authority direct or unfettered access to Customer Personal Data.

CCPA / U.S. service-provider terms

To the extent the CCPA applies, Neivan acts as Customer’s "service provider" (or "processor") and processes Customer Personal Data only to perform the Services and for the business purposes in the Agreement. Neivan will not sell or share Customer Personal Data; will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the Services; and will not combine it with personal information from other sources except as permitted by the CCPA. Neivan certifies that it understands and will comply with these restrictions.

Audit rights

Neivan makes available all information reasonably necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by Customer or an auditor it mandates. Neivan’s security documentation — and, once issued, its SOC 2 Type II report — normally satisfies this obligation; on-site audits require reasonable advance notice, occur during business hours no more than once per year (absent a regulator requirement or a breach), and are subject to a confidentiality agreement and Neivan’s security and access policies.

Return and deletion

Upon termination or expiration of the Agreement, Neivan will, at Customer’s choice, return or delete all Customer Personal Data within 30 days, except where retention is required by law (e.g., financial records and immutable audit logs retained for 7 years) and routine backups that expire on the normal cycle, which Neivan will isolate from active processing until deleted.

Liability and precedence

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the same law and subject to the same dispute-resolution and venue provisions as the Agreement, except to the extent required otherwise by Data Protection Laws or the SCCs.

See also:Privacy PolicyTerms of ServiceSecurityContact us

The intelligence layer for what's next — built for teams who want AI that remembers, coordinates, and improves.

Platform
  • Agent Network
  • Memory & Knowledge
  • Workflows
  • Decision Engine
  • Security
  • Pricing
Trust
  • Trust Center
  • Security
  • Privacy
  • DPA
  • Sub-processors
Company
  • About
  • Docs
  • Help & Support
  • Contact
  • Careers
  • Changelog
Private preview··Your privacy rights·Acceptable Use
© 2026 Neivan, Inc. — All rights reserved.
Privacy·Terms·SLA·Cookies