New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →

Data Processing Addendum

Last Updated: August 3, 2026

Draft — pending legal review. This document is a working draft and has not yet been reviewed by a qualified lawyer. It is not legal advice and is not binding until reviewed by counsel and finalized. Because it concerns EU personal data and cross-border transfers, counsel review is essential before you rely on it. Some items (marked in brackets) are still to be set.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you and ngris (registered form and address pending; see the Terms of Service) and governs the processing of personal data in connection with your use of our services. ngris processes personal data in the European Union, and the General Data Protection Regulation (GDPR) is the primary framework for this DPA.

1. Definitions

Terms such as "Personal Data," "Data Subject," "Data Controller," and "Data Processor" shall have the meanings defined in applicable data protection laws, primarily the General Data Protection Regulation (GDPR), and, where applicable to a given customer, other laws such as the California Consumer Privacy Act (CCPA).

2. Scope and Roles of the Parties

You are the Data Controller and Ngris is the Data Processor. This DPA outlines the terms and conditions under which Ngris processes personal data on your behalf when you use our services.

3. Security Measures

Ngris implements appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption in transit (TLS 1.3), application-layer encryption of sensitive data at rest, access controls, and least-privilege administrative access. Our current security posture is described on our Security page.

4. Data Subject Rights

Ngris will assist you in responding to requests from data subjects to exercise their rights under applicable data protection laws, including rights of access, rectification, erasure, and portability.

5. Data Residency and Location of Processing

Personal data processed by ngris on your behalf is stored and processed in the European Union. We design our processing to keep customer personal data within the EU. A limited number of sub-processors may process certain data outside the EU where their service requires it (see Section 7); the most likely such case is our payment processor, Stripe.

6. International Data Transfers

Because processing is EU-based, we do not routinely transfer personal data to a third country. Where a sub-processor necessarily processes personal data outside the EU (for example, Stripe for payment processing), any such transfer will be conducted in compliance with Chapter V of the GDPR, relying on an adequacy decision or on Standard Contractual Clauses (SCCs) together with any required supplementary measures.

7. Sub-Processors

Ngris uses a limited number of sub-processors to provide the Service. Where a sub-processor processes personal data outside the EU, it does so under the transfer safeguards described in Section 6. A current list of sub-processors is available upon request and is summarized on our Security page. We will notify you of any changes to sub-processors with reasonable advance notice.

8. Data Retention

Ngris retains personal data only for as long as necessary to fulfill the purposes outlined in this DPA and the Terms of Service. Upon account termination, data is deleted within 30 days unless otherwise required by law.

9. Contact Us

If you have any questions about this DPA, or to exercise data-subject rights, contact our data protection team at dpa@ngris.com, an actively monitored address. Privacy questions can also be sent to privacy@ngris.com.

Ask an AI to summarise this page