Skip to content

Data Processing Agreement

How Nouss processes personal data on your instructions as your processor.

Last updated 5 August 2026

Roles of the parties

The merchant is the data controller and determines the purposes and means of processing. Nouss Technologies is the data processor and processes personal data only on the merchant's documented instructions. A countersigned copy of this DPA is available on request from sales@nouss.in.

Scope of processing

  • Subject matter: purchase-intent scoring and audience segmentation for the merchant's store.
  • Duration: for the term of the subscription, plus the deletion window below.
  • Categories of data subjects: visitors and customers of the merchant's store.
  • Categories of data: behavioural events, coarse device and location data, and where supplied by the merchant, customer identifiers and order history.
  • No special categories of personal data may be submitted to the service.

Security measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access control with least-privilege defaults and audit logging.
  • Network isolation, secrets management and regular dependency patching.
  • Documented incident response with notification to the controller without undue delay and within 72 hours of becoming aware of a personal data breach.
  • Confidentiality obligations for all personnel with access to personal data.

International transfers

EU and UK merchant data is stored in the EU by default. Where personal data is transferred outside the EEA or UK, transfers rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer impact assessment.

Sub-processors

Nouss uses vetted sub-processors for cloud hosting, data storage, error monitoring and transactional email, and — where the merchant enables them — the advertising and messaging platforms the merchant connects. Each sub-processor is bound by written terms no less protective than this DPA. The current list is available on request and we give notice before adding a new sub-processor, giving the merchant the right to object.

Assistance and audits

Nouss assists the controller with data subject requests, data protection impact assessments and regulator engagement, and makes available the information needed to demonstrate compliance, including reasonable audits on notice.

Data deletion and return

On termination, or on written request, Nouss deletes or returns all personal data within 30 days, except where storage is required by law. Backups age out within a further 35 days.