Browse legal documents

Data Processing Agreement (Template)

Last updated: 8/3/2026

Data Processing Agreement (Template)

Last updated: 2026-07-19

Status and Incorporation

This document is a conditional template. It is effective only when expressly incorporated into a signed business contract (such as the Business Terms, a separate Services Agreement, or an Order Form) between Nesktop and a customer who is a legal entity or organization. By itself, this template creates no binding obligations.

1. Parties and roles

1.1 Nesktop (as described in the Terms of Service) is the data processor when it processes personal data on behalf of the customer who is the data controller.

1.2 Customer (the organization or entity that agrees to these terms) is the data controller when it determines the purposes and means of processing.

1.3 Roles may vary depending on how the customer uses the Service. If the customer uses Nesktop solely to provide a service to its own end users, Nesktop is typically a processor. If the customer uses Nesktop for its own internal business operations, Nesktop may be an independent controller for certain processing. The parties shall agree on the applicable role based on the specific use case.

2. Instructions and purpose

2.1 Nesktop shall process personal data only on documented instructions from the customer, unless required otherwise by applicable law.

2.2 The initial instructions are set out in the main agreement between the parties and this DPA. The customer may issue additional written instructions that are consistent with the Service's functionality.

3. Details of processing

3.1 Purpose: Processing in connection with providing the Nesktop Service to the customer, including account management, synchronization, layout management, organization features, and support.

3.2 Data subjects: Customer's authorized users (members, administrators, owners) and, where applicable, end users who interact with content published by the customer.

3.3 Categories of personal data: Account information (name, email, account preferences), content saved by users, usage and device information, authentication tokens, and communication data, as further described in the Privacy Policy.

4. Confidentiality

Nesktop shall ensure that its personnel authorized to process personal data are subject to appropriate confidentiality obligations (whether contractual or statutory).

5. Security

Nesktop shall implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

Measures include encryption in transit (HTTPS/TLS), access controls, and use of operating-system secure storage where available. Nesktop does not claim compliance with specific security certifications (such as ISO 27001 or SOC 2) and has not obtained independent certification of such standards.

6. Subprocessors

6.1 The customer consents to Nesktop's engagement of subprocessors as listed in the Subprocessors page. A current list is maintained at the Subprocessors page and may be updated in accordance with the change notice provisions.

6.2 Nesktop shall impose data protection obligations on subprocessors that are at least as protective as those in this DPA.

7. Assistance

7.1 Nesktop shall assist the customer in ensuring compliance with its obligations under applicable data protection law, including responding to data subject requests, conducting data protection impact assessments, and consulting with supervisory authorities, taking into account the nature of processing and the information available to Nesktop.

8. Data subject rights

8.1 Nesktop shall, to the extent legally permitted, promptly notify the customer of any request it receives directly from a data subject. Nesktop shall not respond to the request without the customer's prior written authorization, unless required by law.

9. Personal data breach

9.1 Nesktop shall notify the customer without undue delay after becoming aware of a personal data breach involving customer data processed under this DPA. Nesktop shall provide reasonable assistance to the customer in meeting its breach notification obligations.

10. Deletion and return

10.1 Upon termination or expiry of the agreement between the parties, Nesktop shall, at the customer's option, delete or return all personal data processed on behalf of the customer, subject to applicable legal retention requirements. Deletion of customer-account data is described in the Privacy Policy and Terms of Service.

11. Audits

11.1 Upon reasonable notice (not less than 30 days) and no more than once per calendar year, the customer may request an audit of Nesktop's processing activities relevant to this DPA, conducted by a mutually agreed independent third-party auditor at the customer's expense. Nesktop shall cooperate with reasonable audit requests that do not disrupt normal operations or compromise the security or privacy of other customers.

11.2 If the customer is a public authority or is subject to regulatory audit obligations, alternative audit arrangements may be agreed in writing.

12. International transfers

12.1 Personal data may be transferred to and processed in countries other than the customer's country of residence, including Türkiye (where Nesktop is operated) and countries where subprocessors operate. For transfers from the EEA, UK, or Switzerland to countries without an adequacy decision, Nesktop relies on Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms.

12.2 The parties agree to enter into SCCs or equivalent transfer mechanisms if required by applicable law.

13. Liability and order of precedence

13.1 This DPA is subject to the liability limitations set out in the Terms of Service.

13.2 In the event of a conflict between this DPA and the main agreement between the parties, this DPA shall prevail with respect to data processing matters, unless the main agreement expressly states otherwise.

14. No certification

This document is a template. It is not signed, certified, or registered with any supervisory authority. The parties may execute a separate data processing agreement with signatures if required by applicable law or the customer's compliance requirements.

15. Contact

Questions about this DPA: nesktopinfo@gmail.com.