Legal
Data Processing Addendum
Last updated: July 22, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Neximprove Private Limited ("Processor") and the Customer ("Controller") in respect of personal data processed by CLEARIE™ GETWAY on behalf of the Customer.
1. Scope and roles
Customer is the Controller. Neximprove is the Processor. Sub-processors are listed in our Privacy Policy.
2. Nature and purpose
Processing is limited to operating the Getway Service: authentication, API delivery, AI inference, billing, audit logging, and support.
3. Categories of data subjects
- Customer employees and authorised users.
- Business contacts referenced in trade documents or queries.
4. Categories of personal data
- Identification: name, work email, company role.
- Technical: IP address, device, session identifiers.
- Content submitted by Customer through APIs or UI.
- Support and billing metadata submitted by Customer or authorised users.
- Trade-dataset personal data only where present in Customer content or licensed/public source records.
5. Security measures
Neximprove implements ISO 27001-aligned controls: encryption in transit (TLS 1.2+) and at rest (AES-256), RBAC, least-privilege production access, hardware key MFA for engineers, hashed API keys, OTP verification, audit logging, annual penetration testing, vulnerability scanning, and documented incident-response procedures.
6. Sub-processors
Customer authorizes Neximprove to engage the sub-processors listed in the Privacy Policy. We will notify Customer by email at least 30 days before adding a new sub-processor; Customer may object on reasonable grounds.
7. International transfers
Personal data is primarily hosted in India. Cross-border transfers to sub-processors are protected by Standard Contractual Clauses or equivalent legal mechanisms.
8. Data subject requests
Neximprove will assist the Customer in fulfilling data-subject rights under the DPDP Act 2023, GDPR, and other applicable laws within statutory timelines. Requests may include access, correction, deletion, consent withdrawal, and grievance escalation where applicable.
9. Personal data breaches
Neximprove will notify Customer without undue delay (and in any event within 48 hours) after becoming aware of a confirmed personal-data breach affecting Customer data. Regulatory notifications are handled under applicable law and internal incident response procedures, including CERT-In reporting where required.
10. Deletion
Upon termination, Neximprove will delete or return Customer personal data within 30 days, save for copies required to be retained by law.
11. Audit
Enterprise customers may request, no more than once per year, a summary of Neximprove's most recent third-party audit reports under NDA.
12. Contact
Data Protection Officer: dpo@neximprove.com