Data Processing Agreement
Applies to NimbusDash and NimbusQL, on trial, free and paid accounts
Version 1.0. Effective September 30, 2026
See also our NimbusAI Data Handling page, our Subprocessorsand our Privacy Policy.
How this DPA applies to you. It is part of the agreement you accepted for NimbusDash or NimbusQL (the Free Trial Agreement you accepted when you installed it or, as an administrator of your NetSuite account, inside the application once it offers that, the Online Subscription Agreement you accepted at checkout, or a Subscription Agreement signed with NimbusLabs), from version 1.1 of that agreement, the first to incorporate it. It binds NimbusLabs from the day you accept that agreement, in the version current on that day; you do not have to ask for it. If you are on terms older than version 1.1, it applies to you from the day you accept version 1.1 or later. If you bought online under our earlier Terms of Use, it also applies from the day an administrator of your NetSuite account accepts this DPA itself inside NimbusDash or NimbusQL, once the application offers that, which makes it part of those terms. If you signed a Subscription Agreement before version 1.1, it applies from the date of a copy or addendum signed by both parties, because that agreement can be amended only by a document both parties sign (its section 15.3). Subscription customers who need a copy signed by both parties email legal@nimbuslabs.com with their legal name, NetSuite account number and the email address for notices.
This Data Processing Agreement ("DPA") is incorporated into the agreement under which Customer uses NimbusDash or NimbusQL, whether the NimbusDash Free Trial Agreement or the NimbusQL Free Trial and Free Version Agreement accepted on installation or, by an administrator of Customer's NetSuite account, within the Services, the NimbusLabs Online Subscription Agreement accepted at checkout, or a NimbusDash or NimbusQL Subscription Agreement signed by both parties, in each case in version 1.1 or a later version that incorporates this DPA, or terms that predate version 1.1 into which this DPA has been incorporated as the next paragraph describes (each, the "Agreement"), between NimbusLabs, LLC ("NimbusLabs") and the customer that accepted it ("Customer"). It applies whenever NimbusLabs processes Personal Data on Customer's behalf in providing the Services, during a trial, a free version or a paid subscription alike, which happens when Customer uses the Included Provider described below, when Customer grants NimbusLabs Support Access, and when Customer sends NimbusLabs Support Content (section 2.5).
This DPA applies to Customer from the date Customer accepts an Agreement that incorporates it, in the version current on that date, and continues for as long as NimbusLabs processes Customer Personal Data and, for sections 2.4, 10.3, 10.4 and 12 as they concern the Monthly Allowance Summary, for as long as NimbusLabs keeps one for Customer's account. Terms that predate version 1.1 incorporate this DPA as follows: the NimbusLabs Terms of Use that governed online purchases before the Online Subscription Agreement, from the date an administrator of Customer's NetSuite account accepts this DPA within the Services, once they offer that; and a Subscription Agreement signed before version 1.1, from the date of a copy or addendum of this DPA signed by both parties, because that agreement's section 15.3 allows it to be amended only by a written instrument signed by both parties. NimbusLabs' record of that acceptance depends on the route. For a Free Trial Agreement accepted on installation it is the one NetSuite keeps for NimbusLabs: Customer's NetSuite account and company name, the bundle version installed, the installation date, and the date the Agreement's terms were most recently accepted; the version of the Agreement and of this DPA accepted is the version in force on that date, per the version history at the end of this page and on the Agreement. For a Free Trial Agreement, or this DPA itself, accepted within the Services, it is NimbusLabs' own record of that acceptance: Customer's NetSuite account and the NetSuite environment it was accepted in, the product and its version, Customer's company name, the document and version accepted and the version of this DPA then in force, the accepting administrator's NetSuite internal identifier and role, and the time. That record holds no name, email address or IP address, and the internal identifier identifies the administrator only within Customer's NetSuite account. For the Online Subscription Agreement it is the order record made at checkout, with the versions of that Agreement and of this DPA that the acceptance box named written on the order, which are the versions in force at the time of the order; for a Subscription that came under that Agreement at a renewal after notice, in place of the earlier Terms of Use, it is the order for that Subscription with the notice and the renewal date, and the version accepted is the version in force at that renewal. For a signed Subscription Agreement it is the signed agreement and its Schedule A, and the version is the one current on the date last signed; for one signed before version 1.1, it is the signed copy or addendum that incorporates this DPA, and the version it names. A move from one route to another, as when a trial converts to a subscription, is a new acceptance: the version of this DPA the later Agreement incorporates governs processing from that date, and the version accepted earlier continues to govern the processing that took place under it, without affecting either party's rights or claims about it. Publishing a new version on this page is not by itself acceptance of it. Subscription customers may also have a copy signed by both parties, by emailing legal@nimbuslabs.com with Customer's legal name, NetSuite account number and Notice Address; the signed copy does not change when this DPA applies.
1. Definitions
"Services" means NimbusDash and NimbusQL as licensed under the Agreement, including NimbusAI, the assistant in NimbusDash and, when offered, in NimbusQL.
"Included Provider" means the AI model service included with Customer's license. It runs on NimbusLabs' Microsoft Azure subscription and is reached through NimbusLabs' API gateway. In NimbusDash it is one of the providers NimbusAI can use; the others are providers Customer contracts with directly using its own API key ("Bring-Your-Own-Key").
"AI Content" means the content the Services send to the Included Provider and the responses it returns, as described in Annex 1.
"Usage Metadata" means the request-level records NimbusLabs keeps of calls to the Included Provider, as described in Annex 1. Usage Metadata never includes AI Content, and does not include the Monthly Allowance Summary.
"Monthly Allowance Summary" means the record NimbusLabs keeps for each account, product and calendar month of the Included Provider's use on Customer's account: Customer's NetSuite account number, the product, the month, the number of calls, the token totals and the cost total, together with the dates of the record's own creation and retirement, and containing no request identifiers and no request timestamps. NimbusLabs maintains it as its own business record under section 2.4. For an account held by a legal entity it ordinarily identifies only that entity; to the extent a Monthly Allowance Summary identifies or relates to an individual and therefore constitutes Personal Data under Data Protection Laws, sections 2.4, 10.4 and 12 apply to it.
"Customer Personal Data" means Personal Data contained in AI Content, Usage Metadata or Support Content, or in Customer's NetSuite account and reached through Support Access, that NimbusLabs processes on Customer's behalf under the Agreement.
"Support Access" means access to Customer's NetSuite account that Customer grants a named NimbusLabs person, by adding that person as a user of the account with a role Customer chooses, for installation, configuration, an update or a support request.
"Support Content" means Customer content that Customer or its users give NimbusLabs so that a support request can be diagnosed or resolved, such as a screenshot, an export or a copy of a record, whether or not Support Access is granted. The administration of the request, meaning who asked, when, about what and how it was resolved, is not Support Content; it is NimbusLabs' own record under section 2.4.
"Data Protection Laws" means all laws that apply to the processing of Personal Data under the Agreement and this DPA, whether Customer Personal Data or Personal Data in a Monthly Allowance Summary, including, where they apply, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), other United States state privacy laws, the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as incorporated into United Kingdom law ("UK GDPR"), and the Swiss Federal Act on Data Protection.
"Personal Data", "Controller", "Processor", "Data Subject", "processing" and "Personal Data Breach" have the meanings given in Data Protection Laws. "Business", "Personal Information", "Service Provider", "Sell" and "Share" have the meanings given in the CCPA. "Subprocessor" means a third party NimbusLabs engages to process Customer Personal Data, including by hosting it.
"SCCs" means the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914.
"Data Handling Page" and "Subprocessor Page" mean the pages at nimbuslabs.com/ai-data-handling and nimbuslabs.com/subprocessors, as updated from time to time.
"Notice Address" means the email address Customer gives for notices when it executes a signed copy of this DPA, names a notice contact in a signed Subscription Agreement, or otherwise notifies NimbusLabs in writing at legal@nimbuslabs.com; failing that, an email address Customer's administrator sets for notices in the Services; failing that, the email address on Customer's account, which is the company email address the Services report to NimbusLabs from Customer's NetSuite company information. An address Customer gives NimbusLabs in writing takes precedence over one set in the Services, and the Services do not overwrite it. Customer is responsible for keeping its Notice Address monitored, and keeps it current in the Services or by writing to legal@nimbuslabs.com.
2. Roles and scope
2.1 Customer is the Controller of Customer Personal Data (or, where Customer processes it for its own customers, a Processor), and NimbusLabs is its Processor and, under the CCPA, its Service Provider.
2.2 NimbusLabs processes Customer Personal Data in four ways. First, it transmits AI Content from Customer's NetSuite account through NimbusLabs' API gateway to the model service and returns the response to Customer's user; the gateway processes AI Content in transit (it verifies the request's token, applies size and output limits, disables the model service's conversation storage and forwards the request) and is configured to record no request or response bodies. Second, it records Usage Metadata. Third, during Support Access, NimbusLabs' personnel may view and work with Customer Personal Data in Customer's NetSuite account, to the extent the task requires (section 2.5). Fourth, when Customer or its users send Support Content, NimbusLabs receives it in its support email and uses it only to diagnose and resolve the request it was sent for (section 2.5).
2.3 This DPA does not cover the following:
(a) Customer's NetSuite data that stays in Customer's NetSuite account. The Services run inside that account. NimbusLabs holds no shared or service credentials for it and has no access to it or to the data in it except Support Access under section 2.5, through a named person's own login and a role Customer assigns for a task, and this DPA covers that data where NimbusLabs reaches it that way or where Customer sends it as Support Content. What the Services send NimbusLabs falls into two groups: the AI Content and Usage Metadata this DPA covers, and the account, license, acceptance and feedback information NimbusLabs processes as a Controller under section 2.4. Personal Data in AI Content or Usage Metadata is not excluded because it originated in NetSuite.
(b) Bring-Your-Own-Key. When Customer configures NimbusAI to use a provider Customer contracts with directly, requests go from Customer's NetSuite account to that provider. NimbusLabs does not receive, process or store that content or Customer's API credentials, and that provider is not a Subprocessor of NimbusLabs.
2.4 NimbusLabs processes the following as an independent Controller, for its own purposes and under its Privacy Policy, and not as Customer's Processor under sections 3 to 11 of this DPA, except that the commitments this DPA makes specifically about the Monthly Allowance Summary, in this section and in sections 10.3, 10.4 and 12, bind NimbusLabs: account, license and billing information, including the record of Customer's acceptance of the Agreement; the business contact details of Customer's personnel, including the Notice Address and the name, email address and role a user submits with feedback from within the Services; the administration of support requests, meaning who asked, when, about what and how the request was resolved, but not Support Content (section 2.5); information about visits to NimbusLabs' website, including clicks on NimbusLabs links from within the Services; and the Monthly Allowance Summary, which NimbusLabs maintains only for account administration, reconciliation of the AI allowance it funded, accounting and cost reconciliation, and resolution of related disputes, and keeps for 24 months after the month it describes and then deletes (section 10.4).
2.5 Support Access. Where Customer grants Support Access, NimbusLabs uses it only for the installation, configuration, update or support request it was granted for, through the role Customer assigns, and processes Customer Personal Data it can reach there only to the extent that task requires. NimbusLabs exports Customer Personal Data from Customer's NetSuite account only where the task requires it, such as testing the Services' own export features, and deletes any such export when the task is complete. Support Content is Customer Personal Data to the extent it contains any, whether or not Support Access is granted: NimbusLabs processes it as Processor, only to diagnose and resolve the request it was given for, and uses it for nothing else. NimbusLabs keeps Support Content only while the request needs it, and deletes it no later than the earliest of: (a) 90 days after the request is resolved; (b) 30 days after NimbusLabs' support processing for the product the request concerned ends for Customer's account, which is when no request from the account about that product remains open and the account holds neither a paid license nor a trial for it, a move from a trial to a subscription not being an end; and (c) 30 days after Customer's written instruction to legal@nimbuslabs.com. Before deleting it, NimbusLabs returns it to Customer if Customer has asked for that. NimbusLabs keeps only the material, and only for the time, that law requires it to keep, and where the GDPR or the UK GDPR applies, only what Union or Member State law or United Kingdom law requires. NimbusLabs keeps Support Content only in its support mailbox and its staff's own mailboxes and, where a member of staff has to download a file to work on it, on that person's device, in a folder that neither synchronizes to cloud storage nor is backed up; never in cloud file storage such as OneDrive or SharePoint. Deletion covers each of those places, the support mailbox's calendar, and the deleted items in each, a download's trash included. After deletion an item may remain for a time in the email service's recoverable items, as section 10.3 describes, and NimbusLabs confirms a deletion in writing on request. The administration of a request is NimbusLabs' own under section 2.4 only while the request's email exists, and never includes Support Content: NimbusLabs keeps no separate record of support requests. Support Access lasts until Customer removes the user or the role: NimbusLabs stops using it when the task is complete, asks Customer to remove it if Customer has not, and checks that it has been removed where it can.
3. Instructions
3.1 NimbusLabs processes Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA, and Customer's configuration and use of the Services: whether NimbusAI is enabled, whether the Included Provider is selected, which users may use it, and what those users submit; for Support Access, the task Customer asks NimbusLabs to perform; and, for Support Content, the request it is sent with.
3.2 NimbusLabs does not process Customer Personal Data for its own purposes, with one exception that Customer authorizes by this DPA: NimbusLabs may derive the Monthly Allowance Summary from Usage Metadata, limited to the fields in its definition and the purposes in section 2.4, and once derived the Monthly Allowance Summary is NimbusLabs' own record under section 2.4, governed by sections 2.4, 10.3, 10.4 and 12 rather than by this section. NimbusLabs does not use AI Content to train, fine-tune or improve any model and does not authorize any Subprocessor to do so, does not Sell or Share Customer Personal Data, and does not retain, use or disclose it outside its direct business relationship with Customer or for any purpose other than the business purposes in Annex 1 and the derivation this section authorizes.
3.3 NimbusLabs will inform Customer if, in NimbusLabs' opinion, an instruction infringes Data Protection Laws. NimbusLabs is not obliged to assess Customer's compliance with those laws.
3.4 Customer is responsible for the lawfulness of the Customer Personal Data it causes the Services to process, for any notices to and consents from Data Subjects, and for its configuration of the Services. The Services are not designed to process special categories of Personal Data, health information subject to HIPAA, payment card data, or data subject to similar regulatory restrictions. Unless a separate agreement signed by both parties provides otherwise, Customer will not send such data to the Included Provider by any channel, or to NimbusLabs as Support Content, and will instruct its users accordingly: not in dashboards or queries whose column values or filter values contain it, not in questions or the conversation, and not in query text. The Agreement bars such data from NimbusAI on Bring-Your-Own-Key as well. Unless such an agreement provides otherwise, where Customer's NetSuite account holds such data NimbusLabs accepts Support Access only for a task that can be done without reaching it, and if NimbusLabs' personnel meet such data unexpectedly, during Support Access or in Support Content, they stop the affected work, tell Customer, and continue it only without that data. Customer's administrators choose which roles may use NimbusAI, and can disable it or switch it to Bring-Your-Own-Key at any time from the Services' settings. A change applies to requests made after it; it does not recall content already transmitted or cancel a request in progress.
4. Confidentiality
NimbusLabs ensures that personnel authorized to process Customer Personal Data are bound by obligations of confidentiality, and limits access to those who need it to provide, secure or support the Services. Neither the gateway nor NimbusLabs' licensing platform keeps a copy of AI Content: the gateway records none of it, and the licensing platform never receives it. A copy Customer chooses to send NimbusLabs with a support request is Support Content, handled under section 2.5. NimbusLabs does not enable request tracing or body logging for Customer's requests, and troubleshoots the gateway only with synthetic requests that carry no Customer data.
5. Security
NimbusLabs implements and maintains the technical and organizational measures in Annex 2, and may update them over time provided an update does not materially reduce the overall protection of Customer Personal Data.
6. Subprocessors
6.1 Customer authorizes NimbusLabs to engage the Subprocessors listed on the Subprocessor Page, which at the date of this DPA are Microsoft and Amazon Web Services (Annex 3), and to engage new or replacement Subprocessors under this section.
6.2 NimbusLabs gives notice of a new or replacement Subprocessor by email to the Notice Address of every Customer whose Agreement incorporates this DPA, and by updating the Subprocessor Page and its change history, at least 30 days before the Subprocessor first processes Customer Personal Data. The notice names the Subprocessor, its purpose, where it processes, and how to object. NimbusLabs keeps a record of each notice sent.
6.3 Customer may object to a new or replacement Subprocessor on reasonable data protection grounds by writing to legal@nimbuslabs.com within the 30 days in section 6.2. The parties will discuss the objection in good faith. If NimbusLabs cannot reasonably accommodate it, Customer may, as its sole remedy for that objection, stop using what the Subprocessor serves, by disabling the Included Provider (the Services continue to work without it, and NimbusDash's NimbusAI with Bring-Your-Own-Key) or, for a Subprocessor that serves support, by no longer sending Support Content and receiving support through Support Access alone, or terminate the affected Service on written notice, in which case NimbusLabs will refund any prepaid fees for the remainder of that Service's term.
6.4 NimbusLabs imposes on each Subprocessor data protection obligations no less protective than those in this DPA, to the extent they apply to the services the Subprocessor provides, and remains responsible for the Subprocessor's performance. Microsoft processes AI Content under Microsoft's Product Terms and Data Protection Addendum for Azure services, and hosts NimbusLabs' support email, with the Support Content it holds, under the same terms for Microsoft 365; Amazon Web Services hosts the licensing platform under the AWS Customer Agreement and its Data Processing Addendum.
7. Data Subject requests and assistance
7.1 If NimbusLabs receives a request from a Data Subject concerning Customer Personal Data, it will notify Customer without undue delay and will not respond except to refer the Data Subject to Customer, unless required by law.
7.2 Taking into account the nature of the processing, NimbusLabs will provide reasonable assistance to Customer in responding to Data Subject requests and in meeting Customer's obligations regarding security, breach notification, data protection impact assessments and prior consultation with supervisory authorities. Because neither the gateway nor the licensing platform keeps AI Content, neither holds a conversation record in which NimbusLabs could locate, correct, restrict or delete an individual Data Subject's data; NimbusLabs can act on Usage Metadata by Customer account, and on Support Content, AI Content Customer sent with a support request included, once Customer identifies the request, and will coordinate with its Subprocessors, including Microsoft in respect of its abuse-monitoring store, on requests that concern data they hold. The Data Handling Page and this DPA are NimbusLabs' standing documentation for impact assessments, and NimbusLabs may charge its reasonable costs for assistance beyond them.
8. Personal Data Breach
NimbusLabs will notify Customer without undue delay, with an initial notice as soon as practicable and no later than 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, at the Notice Address. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, its likely consequences, the measures taken or proposed, and a contact for further information, and NimbusLabs will supplement it as information becomes available rather than wait for a complete investigation. A notice under this section is not an acknowledgment of fault or liability.
9. Audits
9.1 NimbusLabs makes available the information necessary to demonstrate compliance with this DPA: the Data Handling Page, the Subprocessor Page, Annex 2, and written answers to Customer's reasonable security and privacy questionnaires, no more than once in any 12 months, except where a Personal Data Breach has affected Customer Personal Data, where Customer has reasonable written evidence of material noncompliance with this DPA, or where a supervisory authority or Data Protection Laws require more.
9.2 Where Data Protection Laws grant Customer an audit right that the information in 9.1 does not satisfy, Customer, or an independent auditor bound by confidentiality and not a competitor of NimbusLabs, may audit NimbusLabs' compliance with this DPA once in any 12 months, on at least 30 days' written notice, during business hours, by remote review of documentation and interviews, at Customer's cost, and in a way that does not disrupt NimbusLabs' business or expose other customers' data. The once-in-12-months limit, the 30 days' notice and the remote form do not apply where a Personal Data Breach has affected Customer Personal Data, where Customer has reasonable written evidence of material noncompliance with this DPA, or where a supervisory authority or Data Protection Laws require more. Audit results are NimbusLabs' confidential information and are protected as such under the Agreement. Audits do not extend to a Subprocessor's facilities or systems; for those, the audit reports and certifications the Subprocessor makes available under its terms serve as the audit. Nothing in this section limits a right, or the assistance, that Data Protection Laws or the SCCs, where they apply, require.
10. Deletion and retention
10.1 AI Content. NimbusLabs keeps no application copy of AI Content: it passes through NimbusLabs' gateway, which records no request or response bodies, to the model service and back. Microsoft may retain AI Content selected by its abuse-monitoring process under Microsoft's current terms, which govern how long it is kept; NimbusLabs has no direct administrative access to that store and does not state a period Microsoft does not state. NimbusLabs will coordinate with Microsoft on requests concerning that store, subject to Microsoft's terms and applicable law.
10.2 Usage Metadata. When the processing service ends for an account and product, which is when Customer's license for that product ends, or becomes NimbusQL's free version, which includes no allowance, and the Included Provider stops working for it, whether or not the Agreement continues for another product, NimbusLabs deletes the Usage Metadata for that account and product within 30 days, or, at Customer's written request made before then, returns it to Customer first, except for what, and for as long as, law requires NimbusLabs to keep, and where the GDPR or the UK GDPR applies, only what Union or Member State law or United Kingdom law requires. An ordinary renewal, or a conversion from a trial to a subscription, is not an end while the processing continues. Disabling the Included Provider in the Services' settings does not by itself end the processing service, because that setting stays in Customer's NetSuite account. If Customer stops using the Included Provider while its license continues, Customer may ask in writing at legal@nimbuslabs.com for its Usage Metadata to be deleted sooner, and NimbusLabs then deletes the Usage Metadata for each calendar month that has ended within 30 days of the request, and for the month in progress within 30 days after that month ends, or sooner where Data Protection Laws require. The Monthly Allowance Summary is not deleted or returned under this section; section 10.4 governs it.
10.3 Deleted data, a Monthly Allowance Summary deleted under section 10.4 included, may persist in NimbusLabs' backups until those backups expire. Backups expire on a cycle measured from the date each is taken. A daily scheduled job deletes the copies kept on NimbusLabs' server once they are at least 15 full days old. The copies kept with its hosting provider are configured to expire at 120 days, after which that provider's storage lifecycle process deletes them, and the earlier versions it keeps, asynchronously, ordinarily within days. Backups are not restored to use except to recover the platform as a whole, in which case data due for deletion is deleted again. Gateway diagnostic logs and usage metrics expire on the periods in Annex 2, item 5. Support Content deleted from NimbusLabs' support email may remain in the email service's recoverable items until the service removes it on its own schedule, which NimbusLabs does not lengthen with holds or retention policies: Microsoft's documentation describes a recovery period of 14 days for a deleted email item and of 120 days for a deleted calendar item, after which the service removes the item on a later pass. NimbusLabs does not restore or use an item there except to meet a legal obligation. On request, NimbusLabs confirms a deletion in writing.
10.4 Monthly Allowance Summary. NimbusLabs keeps each Monthly Allowance Summary for 24 months after the month it describes, as its own record under section 2.4 and for the purposes stated there, and then deletes it from its active systems; copies in backups expire under section 10.3. Its retention does not depend on when the processing service ends, and it is not returned under section 10.2, because it is NimbusLabs' record rather than Customer's data held on Customer's behalf.
11. International transfers
11.1 NimbusLabs processes Customer Personal Data in the United States, in the locations named in Annex 1: its personnel work from the United States, its licensing platform and the Included Provider's model service run there, and Support Content is stored in mailboxes whose data location Microsoft commits to the United States. A Subprocessor may process Customer Personal Data outside the United States only where its own terms allow it and Annex 3 says so, as Microsoft's Exchange Online Protection may when it filters inbound support mail, for which Microsoft makes no location commitment. Customer authorizes that processing and any transfer required for it, which the Subprocessor's own terms govern.
11.2 Where the GDPR, the UK GDPR or Swiss law applies to a transfer of Customer Personal Data to NimbusLabs, the transfer requires the SCCs, using Module Two where Customer is a Controller and Module Three where Customer is a Processor, together with, as applicable, the International Data Transfer Addendum issued by the United Kingdom Information Commissioner and the adaptations required for transfers subject to Swiss law, with their annexes completed from Annexes 1, 2 and 3 of this DPA, executed by both parties before the transfer begins. Customer will not enable the Included Provider for such data, grant Support Access to an account holding it, or send such data as Support Content, until they are executed, and NimbusLabs will execute them promptly on Customer's written request to legal@nimbuslabs.com. Once executed, the SCCs prevail over this DPA where they conflict.
12. California
Where the CCPA applies, NimbusLabs is a Service Provider to Customer, and: (a) NimbusLabs processes Customer Personal Data only for the business purposes described in Annex 1, in providing the Services under the Agreement, and for the derivation section 3.2 authorizes; (b) NimbusLabs will not Sell or Share Customer Personal Data, retain, use or disclose it for any purpose other than those business purposes or outside its direct business relationship with Customer, or combine it with Personal Data it receives from others except as the CCPA permits a Service Provider to do; (c) NimbusLabs will comply with the CCPA and provide the level of privacy protection it requires, will notify Customer if it determines it can no longer meet its obligations under the CCPA, and grants Customer the right, on reasonable notice, to take reasonable and appropriate steps to ensure that NimbusLabs uses Customer Personal Data in a manner consistent with Customer's obligations under the CCPA, and to stop and remediate unauthorized use of Customer Personal Data; and (d) NimbusLabs certifies that it understands and will comply with these restrictions. To the extent a Monthly Allowance Summary contains Personal Information that NimbusLabs collected in its capacity as Customer's Service Provider, NimbusLabs uses that Personal Information only for account administration, reconciliation of the AI allowance NimbusLabs funded, accounting and cost reconciliation, and resolution of related disputes, within its direct business relationship with Customer, and does not Sell or Share it, use it for advertising or profiling, or use it for any unrelated commercial purpose. Paragraphs (b) and (c) apply to that Personal Information as they apply to Customer Personal Data, with the business purposes in Annex 1 read, for a Monthly Allowance Summary, as the purposes in section 2.4: NimbusLabs does not combine it with Personal Information it receives from others except as the CCPA permits a Service Provider to do, retains it only for the period in section 10.4, discloses it only as those purposes require, and grants Customer the same rights to ensure consistent use and to stop and remediate unauthorized use.
13. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, and each party's liability under the Agreement and this DPA together counts against the same aggregate limits in the Agreement, once. Nothing in the Agreement or this DPA limits or excludes liability in a manner that contradicts or undermines the SCCs where they apply, including liability to Data Subjects under them, or limits liability to the extent it cannot be limited under Data Protection Laws. As between the parties, the aggregate limits apply to the fullest extent the SCCs and Data Protection Laws permit.
14. General
14.1 This DPA prevails over the Agreement where they conflict on its subject, and the SCCs prevail over this DPA where they apply. The Agreement is otherwise unchanged. The Data Handling Page and the Subprocessor Page describe the Services and NimbusLabs' Subprocessors; they do not amend this DPA, which prevails over them.
14.2 This DPA is governed by the law governing the Agreement, except where the SCCs provide otherwise.
14.3 NimbusLabs may publish revised versions of this DPA. A revised version applies to Customer when Customer accepts an Agreement that incorporates it, or accepts the revised version itself in writing or, through an administrator of Customer's NetSuite account, within the Services, except that under an Agreement signed by both parties a revised version applies only by a document both parties sign; until then, the version Customer accepted governs, and NimbusLabs does not apply a revised version retroactively. Where an Agreement provides for a new version of that Agreement to take effect at a renewal after notice, as the Online Subscription Agreement does, a revised version of this DPA that Customer has not accepted earlier under this section takes effect for that Customer in the same way, at the same renewal and on the same notice, and not before. Publishing a revised version on this page is not by itself notice to Customer or acceptance by Customer. Subprocessor changes are made under section 6, and updates to Annex 2 under section 5, without a new version.
14.4 If any provision of this DPA is held unenforceable, the rest remains in effect.
14.5 Notices to NimbusLabs under this DPA go to legal@nimbuslabs.com; notices to Customer go to the Notice Address.
Annex 1: Description of the processing
Subject matter. The Included Provider within the Services, Support Access, and Support Content.
Duration. While the Included Provider is enabled for Customer's account during the term of the Agreement, plus the retention of Usage Metadata under section 10.2; and, for Support Access, while Customer's grant of it lasts; and, for Support Content, until it is deleted under section 2.5.
Nature and purpose. Transmitting AI Content from Customer's NetSuite account, through NimbusLabs' gateway, to a language model hosted in NimbusLabs' Azure subscription, and returning the response to the user; recording Usage Metadata to enforce the monthly allowance and the gateway's rate and protective limits, operate and secure the Services, and investigate abuse and request failures. Through Support Access, installing, configuring, updating and supporting the Services in Customer's NetSuite account at Customer's request. Processing Support Content to diagnose and resolve the support request it was given for. The Monthly Allowance Summary that NimbusLabs derives from Usage Metadata under the authorization in section 3.2, for its own allowance and cost reconciliation, accounting and resolution of related disputes, is NimbusLabs' own record under sections 2.4 and 10.4 and is not processing on Customer's behalf under this Annex.
Data Subjects. Users of the Services in Customer's account; and individuals whose information appears in the NetSuite records that Customer's dashboards and queries draw on (for example customers, vendors, employees and contacts), to the extent it appears in AI Content or Support Content, or is reached through Support Access.
Categories of Personal Data in AI Content. Whatever Personal Data is contained in the following, and in the model's response to it:
- NimbusDash: the user's question; the recent conversation with the assistant (the text of earlier questions and replies, which can contain values from earlier answers, including ones given on Bring-Your-Own-Key, but never the data context of an earlier request); the dashboard's structure, such as its column names and types; the current grid state, including filter values; and, for each column, its most frequent values and their counts. The Services never attach the dashboard's rows on the Included Provider; values still travel in filter values, in each column's most frequent values, and in whatever the user types.
- NimbusQL, when its NimbusAI assistant is offered: the user's question; the catalog of record types and fields that NimbusQL harvests from Customer's account to describe its data model; and the current query and its state, including any literal values in the query text. Query results are never attached on the Included Provider.
Categories of Personal Data in Usage Metadata. Customer's NetSuite account number, the product and environment, the model deployment used, request and call identifiers, request status, token counts, computed cost, and request timestamps. The Monthly Allowance Summary (the account number, the product, the month, the number of calls, the token totals and the cost total, with the record's own creation and retirement dates and no request identifiers and no request timestamps) is defined in section 1, is NimbusLabs' own record under section 2.4, and is not Usage Metadata.
Categories of Personal Data reached through Support Access. Whatever Personal Data the records and settings a task requires contain, within what the role Customer assigns can reach. NimbusLabs works with it in Customer's NetSuite account and exports it only as section 2.5 allows.
Categories of Personal Data in Support Content. Whatever Personal Data is contained in what Customer or its users choose to send: typically the names, roles and contact details of Customer's users, and the individuals appearing in the NetSuite records shown in a screenshot or export.
Special categories. None intended (section 3.4).
Frequency. Continuous, each time a user submits a request while the Included Provider is enabled. Support Access and Support Content: occasional, at Customer's request.
Retention. Section 10; for an export made during Support Access and for Support Content, section 2.5.
Subprocessors and locations. Microsoft and Amazon Web Services, as set out in Annex 3. Processing region for the model service: United States (Azure US Data Zone); primary Azure resource region: West US 3. NimbusLabs' API gateway: West US; its telemetry: West US 3. NimbusLabs' licensing platform, which holds Usage Metadata: hosted with Amazon Web Services in us-west-2 (Oregon), United States. Support Access involves no Subprocessor: it takes place in Customer's NetSuite account, by NimbusLabs personnel in the United States. Support Content is held in NimbusLabs' support email, which Microsoft hosts in Microsoft 365 in the United States.
Competent supervisory authority (where the SCCs apply). Where Customer is established in the EEA, the authority of Customer's member state; otherwise as determined under Clause 13 of the SCCs.
Annex 2: Technical and organizational measures
- Architecture and access. The Services execute inside Customer's NetSuite account. NimbusLabs does not require or hold shared customer credentials and reaches Customer's NetSuite account only through Support Access: a customer-authorized role assigned to a named NimbusLabs person, who signs in with that person's own NetSuite login, limited to the permissions of that role, and lasting until Customer removes the user or the role. NimbusLabs stops using it when the task is complete, asks Customer to remove it, and checks that it has been removed where it can. Access to NimbusLabs' Azure subscription is limited to authorized NimbusLabs personnel and protected by multi-factor authentication on every privileged account. Administrative access to NimbusLabs' licensing platform is over SSH with public-key authentication only, password authentication disabled, from allowlisted source addresses, and is limited to authorized NimbusLabs personnel on a need-to-know basis. Direct administrative access to the platform's database is by password, over connections the database requires to be encrypted with TLS, from allowlisted source addresses, and is limited in the same way.
- Encryption in transit. Every connection between Customer's NetSuite account, NimbusLabs' gateway, the model service and NimbusLabs' licensing platform uses TLS.
- Authentication of requests. The gateway accepts a request only when it carries a token issued to Customer's account by NimbusLabs' licensing platform on license validation. Production tokens are issued with a ten-minute lifetime and are bound to Customer's account and product. Any provider API key supplied by a caller is discarded, and the gateway's own credential to the model service never leaves NimbusLabs' Azure subscription.
- Data minimization. For the Included Provider the Services send the categories in Annex 1 and nothing else: AI Content to the model service and Usage Metadata to NimbusLabs' licensing platform. What they send that platform for NimbusLabs' own records, such as license validation and acceptance, is set out in section 2.4 and the Privacy Policy. On the Included Provider no dashboard rows or query results are attached, whatever the account's configuration, and no structured row context is carried across a provider switch: the conversation history sent is the text of earlier questions and replies, never the data context of an earlier request, though that text can itself contain values, including values from an earlier answer given on Bring-Your-Own-Key. Requests to the model service are sent with conversation storage disabled, are limited in size, and are limited in the length of the response.
- Logging and telemetry. The gateway is configured to record no request or response bodies and no client IP addresses, and NimbusLabs does not enable request tracing or body logging for Customer's requests, troubleshooting the gateway only with synthetic requests that carry no Customer data. The gateway's diagnostic logs are configured for 30-day retention, in the Log Analytics workspace and in each Application Insights table the gateway uses, with immediate purge at 30 days; no data export rules and no additional diagnostic destinations are configured for the workspace, the gateway, Application Insights or the model resource. Azure Monitor usage metrics, keyed by account and product, are retained by Azure Monitor for 93 days. From Included Provider requests, NimbusLabs' licensing platform receives Usage Metadata only.
- Isolation at the model service. The model service is the Microsoft Azure service named in Annex 3, in NimbusLabs' own Azure subscription. Content is not used to train models and is not available to OpenAI or to other Microsoft customers. Content selected by Microsoft's abuse-monitoring process is held in a store isolated to NimbusLabs' resource, accessible only to authorized Microsoft personnel, under Microsoft's terms.
- Abuse limits. The gateway and NimbusLabs' licensing platform enforce per-account rate limits and a monthly allowance, which limit the volume of AI Content an account can send and the effect of a compromised account.
- Change control and patching. Changes to the Services and to the gateway configuration are made through version-controlled, reviewed changes. The gateway, the model service and the telemetry store are Microsoft-managed services that Microsoft patches and operates. NimbusLabs keeps its licensing platform's software current with security updates.
- Monitoring and incident response. NimbusLabs monitors gateway errors and each account's usage against its allowance, and handles security incidents under section 8.
- Support email. Support requests arrive in a private Microsoft 365 group mailbox whose owners are the NimbusLabs staff who provide support, in a tenant with Microsoft's security defaults enabled, which require every user to register for multi-factor authentication and block legacy authentication. Mailbox content is stored in the United States. Support Content is kept only where section 2.5 allows, never in cloud file storage, and is deleted as that section provides; exports made during Support Access are deleted when the task is complete.
- Customer controls. Customer's administrators enable and disable NimbusAI, choose its provider, and choose which roles may use it, from within the Services, and grant and remove Support Access through NetSuite roles. Each change applies to requests made after it; it does not recall content already transmitted or cancel a request in progress.
Annex 3: Subprocessors
The Subprocessor Page at nimbuslabs.com/subprocessors is the current list and governs. At the date of this DPA it contains three entries:
Microsoft Azure / Azure OpenAI (Microsoft Foundry), Microsoft Corporation. Purpose: AI model inference, the API gateway that carries requests to it, and that gateway's telemetry. Processing region: United States (Azure US Data Zone). Primary Azure resource region: West US 3.
Microsoft 365 (Exchange Online), Microsoft Corporation. Purpose: hosting NimbusLabs' email, including the support mailbox that receives support requests. Data processed: Support Content and the correspondence it arrives with. Data location: United States, Microsoft's committed geography for Exchange Online data at rest; inbound mail is filtered by Exchange Online Protection, currently in the United States, without a location commitment.
Amazon Web Services, Amazon Web Services, Inc. Purpose: hosting NimbusLabs' licensing platform and its usage ledger. Data processed: Usage Metadata and other platform data; AI Content is not routed to this platform. Hosting region: United States, us-west-2 (Oregon).
Version history
Version 1.0, effective September 30, 2026: first version. Each version is dated, and the version that applies to a customer is the one in force on the date the customer accepted the Agreement that incorporates it, or accepted this DPA itself (section 14.3).
Signatures (for a signed copy)
| NimbusLabs, LLC | Customer | |
|---|---|---|
| Legal name | NimbusLabs, LLC | |
| NetSuite account number | ||
| Notice Address | legal@nimbuslabs.com | |
| Signed by (name, title) | ||
| Signature | ||
| Date |