Data Processing Agreement
How Nordvec processes data on behalf of your organisation, in compliance with GDPR Article 28.
Last updated: 2026-05-16
Overview
This Data Processing Agreement (DPA) forms part of the agreement between Nordvec (the Processor) and your organisation (the Controller). It governs how we process personal data on your behalf in accordance with GDPR Article 28.
Scope of Processing
Nordvec processes data solely to provide the contracted services. This includes employee names, email addresses, and the content of documents and messages your organisation connects to the platform. Documents are stored in EU data centres, generation runs in France and embeddings run in Berlin; the processors involved are listed individually in our sub-processor register.
Data Processing Activities
When your organisation connects data sources to Nordvec, document content undergoes the following processing: (1) Text extraction and normalisation from the source format, (2) Semantic chunking into structured segments for indexing, (3) Vector embedding generation via a third-party AI provider, listed in our sub-processor register together with the training commitments we have verified for it and the date of that verification, and (4) Storage of the resulting vector representations and text segments in our EU-hosted database for semantic search retrieval. The original document content is stored to enable accurate citation and source attribution in search results. Nordvec does not use document content to train AI models.
Automated Content Scanning
Nordvec performs automated pattern-based scanning of document content during ingestion to detect potential credentials and API keys (such as cloud provider access keys, authentication tokens, and private keys). This scanning is non-destructive: no content is modified or removed. Detected patterns are flagged in the system for visibility by your organisation's administrators. The purpose of this scanning is to support your organisation's security posture by providing awareness of credential exposure within synced documents. The scanning does not constitute a guarantee of detection, and your organisation remains responsible for managing sensitive content within its source systems.
Security Measures
We implement appropriate technical and organisational measures: AES-256 encryption at rest, TLS 1.3 in transit, row-level security with per-tenant data isolation, role-based access controls, regular penetration testing, and continuous monitoring. All infrastructure is hosted in ISO 27001 certified EU data centres.
Data Retention
Document content, vector embeddings, and associated metadata are retained for the duration of the service agreement. When a data source is disconnected or individual documents are deleted by your organisation, all associated data (including vector embeddings, text chunks, and stored content) is permanently removed from our systems. Deletion is cascading and includes orphaned storage objects. After termination of the service agreement, all data is deleted within 30 days unless a longer retention period is required by applicable law.
Sub-processors
Nordvec maintains a per-entity register of every sub-processor engaged to deliver the Service. For each one it records the legal name, country of incorporation, corporate parent, processing location, purpose, the categories of personal data, and the Chapter V transfer basis that applies. The register is generated from the code that reaches each provider and re-verified on every change, so a provider cannot be engaged without appearing in it. It currently covers database and object storage, AI generation and embeddings, caching, transactional email, DNS and content delivery, and error monitoring. A copy is available on request and is provided during enterprise procurement. We will notify you at least 30 days before a new sub-processor begins processing, and you have the right to object.
International Transfers
Storage, generation and embeddings run in EU data centres. Where a processor in the chain is incorporated outside the EEA, or has a parent that is, a Chapter V transfer basis applies to that processor: our sub-processor register states the basis for each entry, together with the date it was verified, so you can check it per processor rather than rely on a blanket statement here.
Data Breach Notification
We will notify you within 24 hours of detecting a personal data breach. We assist you in complying with breach notification obligations under GDPR Articles 33 and 34, including notifications to your supervisory authority and affected data subjects.
Data Subject Rights
The following rights are implemented as self-service in the Nordvec platform: Access and Data Portability (Art. 15, 20) via JSON export in Settings, Erasure (Art. 17) via account deletion with atomic cascade, Rectification (Art. 16) via profile and content editing, and Restriction (Art. 18) via source toggles and upload settings.
Deletion and Data Retention
Upon termination, all personal data is deleted within 30 days. During the agreement, deletions in your source systems propagate automatically via webhook/sync. Soft-deleted data is purged after 30 days. Upon full account deletion, all data (conversations, documents, embeddings, integration tokens) is atomically removed.
Audit Rights
You have the right to audit our compliance with this agreement. We make available: this DPA and our compliance documentation, our DPIA for AI processing, the Art. 30 processing register, and our sub-processor register with the transfer basis recorded for each processor. We hold no third-party certification today. Our controls are published individually on our trust board, each linked to the code that implements it, and exported as OSCAL so you can load them into your own audit tooling.
Contact
For DPA-related inquiries, data subject access requests, or to request the current sub-processor list, contact us at legal@nordvec.com. Data Protection Officer: dpo@nordvec.com.