← Home

Data Processing Agreement

Last updated: 2026-07-27

Because we process personal data on your behalf, GDPR Article 28 requires a written agreement between us. This page is that agreement. It applies automatically to every organisation using the service, alongside our Terms of Service.

1. Parties and roles

This agreement is between your organisation (the "Controller") and NI2SFill (the "Processor"). You decide what personal data goes into the service and why. We process it only to provide the service, and only on your instructions.

2. Subject matter and duration

We process personal data for as long as your organisation has an active account, plus the retention periods set out in our Privacy Policy. When the account ends, so does the processing.

3. Nature and purpose of processing

  • Storing your account and organisation records.
  • Storing questionnaires, uploaded documents and the answers you write.
  • Generating text embeddings so questions can be matched to your stored answers.
  • Generating draft answers using an AI language model.
  • Producing filled Excel/Word files and PDF reports at your request.

4. Categories of data and data subjects

Data subjects are typically your employees who use the service, and any individuals named in the documents you upload (for example a security contact named in a questionnaire).

Categories are: identification and contact data, employment role, and whatever personal data appears in the content you choose to upload. You agree not to upload special categories of personal data (GDPR Articles 9 and 10) without a prior written agreement with us.

5. Our obligations

  • We process personal data only on your documented instructions, and we tell you if we believe an instruction breaches data-protection law.
  • We keep personal data confidential and ensure everyone with access is bound by confidentiality.
  • We implement appropriate technical and organisational measures - encryption in transit and at rest, database-level tenant isolation (Row-Level Security), hashed passwords, and least-privilege access to production.
  • We assist you in responding to data-subject requests, and in your data-protection impact assessments and regulator consultations, as far as is reasonable.
  • We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach affecting your data, with the information you need for your own notification duties.
  • On termination we delete or return personal data, subject to the retention periods in the Privacy Policy and to any legal obligation to retain it.

6. Sub-processors

You give us general authorisation to engage the sub-processors listed on our Sub-processors page. We impose data-protection obligations on each of them that are no less protective than those in this agreement, and we remain responsible to you for their performance.

We will notify account administrators at least 30 days before adding or replacing a sub-processor, so you have the opportunity to object on reasonable grounds.

7. International transfers

Application data is stored in the EU. Some sub-processors (notably OpenAI, and Vercel as a US-established company) process data outside the EU. For those transfers we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU, US Data Privacy Framework, together with the transfer safeguards in each provider's Data Processing Addendum.

8. Audits

You may ask us to demonstrate our compliance with this agreement. We will respond to reasonable written questions and provide available documentation. On-site or third-party audits may be requested no more than once per year, on 30 days' written notice, at your cost, subject to confidentiality and to not disrupting the service or other customers. Contact dev.app.nis2@gmail.com.

9. Liability and precedence

The liability limits in our Terms of Service apply to this agreement. If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.