Data Processing Addendum
Last Updated: August 3, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you and ngris (registered form and address pending; see the Terms of Service) and governs the processing of personal data in connection with your use of our services. ngris processes personal data in the European Union, and the General Data Protection Regulation (GDPR) is the primary framework for this DPA.
1. Definitions
Terms such as "Personal Data," "Data Subject," "Data Controller," and "Data Processor" shall have the meanings defined in applicable data protection laws, primarily the General Data Protection Regulation (GDPR), and, where applicable to a given customer, other laws such as the California Consumer Privacy Act (CCPA).
2. Scope and Roles of the Parties
You are the Data Controller and Ngris is the Data Processor. This DPA outlines the terms and conditions under which Ngris processes personal data on your behalf when you use our services.
3. Security Measures
Ngris implements appropriate technical and organizational measures to protect personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption in transit (TLS 1.3), application-layer encryption of sensitive data at rest, access controls, and least-privilege administrative access. Our current security posture is described on our Security page.
4. Data Subject Rights
Ngris will assist you in responding to requests from data subjects to exercise their rights under applicable data protection laws, including rights of access, rectification, erasure, and portability.
5. Data Residency and Location of Processing
Personal data processed by ngris on your behalf is stored and processed in the European Union. We design our processing to keep customer personal data within the EU. A limited number of sub-processors may process certain data outside the EU where their service requires it (see Section 7); the most likely such case is our payment processor, Stripe.
6. International Data Transfers
Because processing is EU-based, we do not routinely transfer personal data to a third country. Where a sub-processor necessarily processes personal data outside the EU (for example, Stripe for payment processing), any such transfer will be conducted in compliance with Chapter V of the GDPR, relying on an adequacy decision or on Standard Contractual Clauses (SCCs) together with any required supplementary measures.
7. Sub-Processors
Ngris uses a limited number of sub-processors to provide the Service. Where a sub-processor processes personal data outside the EU, it does so under the transfer safeguards described in Section 6. A current list of sub-processors is available upon request and is summarized on our Security page. We will notify you of any changes to sub-processors with reasonable advance notice.
8. Data Retention
Ngris retains personal data only for as long as necessary to fulfill the purposes outlined in this DPA and the Terms of Service. Upon account termination, data is deleted within 30 days unless otherwise required by law.
9. Contact Us
If you have any questions about this DPA, or to exercise data-subject rights, contact our data protection team at dpa@ngris.com, an actively monitored address. Privacy questions can also be sent to privacy@ngris.com.