Data Processing Agreement

Data Processing Agreement

The terms for Noema's processing of customer personal data, including instructions, confidentiality, security, subprocessors, and deletion.

September 26, 2026

September 26, 2026

1. Parties, scope, and precedence

This Data Processing Agreement ("DPA") forms part of the service agreement between [customer legal entity] ("Customer") and [Noema legal entity] ("Noema") once accepted through [agreed execution mechanism]. It applies when Noema processes personal data on the Customer's behalf to provide the service. The Customer acts as controller or as a processor authorized by its controller; Noema acts as processor or sub-processor, respectively.


This DPA takes priority over conflicting service terms concerning that processing. Any applicable mandatory transfer clauses take priority over conflicting provisions of this DPA. Applicable data protection law means [laws applicable to the processing].


2. Processing details and instructions

Noema processes personal data only on the Customer's documented instructions, including those in the service agreement and authorized workspace configuration, unless legally required otherwise. Where permitted, Noema will inform the Customer before legally required processing. Noema will promptly notify the Customer if it believes an instruction infringes applicable data protection law.


The subject matter is the provision of organizational-intelligence services. Processing may include receiving, storing, indexing, retrieving, generating responses from, and deleting authorized workplace content. The agreed purposes, duration, data categories, and data subjects must be completed in Schedule 1. Noema will not process customer personal data for its own model-training purposes without a separately established lawful arrangement.


3. Customer responsibilities

The Customer is responsible for establishing a lawful basis, providing required notices, obtaining any necessary permissions, and ensuring its instructions are lawful. It determines which sources and data are connected, who has access, and whether the service is appropriate for its intended processing. Special-category or otherwise sensitive data is permitted only as expressly documented in Schedule 1 and supported by agreed safeguards.


4. Confidentiality and security

Noema will ensure that personnel authorized to process customer personal data are bound by confidentiality obligations and have access only as needed for their duties. Noema will implement and maintain the technical and organizational measures documented in Schedule 2, appropriate to the risks of the processing. Security changes must not materially reduce the agreed overall level of protection.


5. Sub-processors

The Customer grants [specific or general written authorization] for the sub-processors listed in Schedule 3. Under general authorization, Noema will give [notice period] before adding or replacing a sub-processor and allow objections on reasonable data-protection grounds through [objection procedure and resolution terms].


Noema will impose data-protection obligations on sub-processors that provide the protection required by this DPA and applicable law. Noema remains responsible for its sub-processors' performance of those obligations as required by applicable law.

6. Assistance with rights and compliance

Taking account of the nature of processing, Noema will assist the Customer with requests to exercise data-subject rights through appropriate technical and organizational measures insofar as possible. Noema will forward requests received directly to [customer privacy contact] and will not respond substantively except on instructions or where required by law.


Taking account of the information available to it, Noema will also assist with security obligations, breach notifications, data protection impact assessments, and regulator consultations as required by applicable law. [Specify the assistance process and any permissible charges without restricting mandatory assistance.]


7. Personal data breaches

Noema will notify the Customer without undue delay after becoming aware of a personal data breach affecting customer personal data, using [customer incident contact and agreed notification channel]. The notice will include available information about the nature of the breach, affected data and people, likely consequences, mitigation measures, and a contact for follow-up. Information may be supplied in stages as it becomes available.


Noema will take reasonable steps to contain, investigate, and remediate the breach and cooperate with the Customer's response. The Customer remains responsible for controller notifications to regulators and affected individuals unless applicable law requires otherwise.


8. International transfers

Noema will transfer customer personal data internationally only on documented instructions and with safeguards required by applicable law. Schedule 4 must identify relevant locations, importers, transfer mechanisms, and any supplementary measures. Where standard contractual clauses or a UK addendum are needed, the parties must incorporate and complete the applicable instruments and annexes; this page does not replace them.


9. Information and audits

Noema will make available the information needed to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by the Customer or its mandated auditor as required by applicable law. The parties will agree reasonable confidentiality, security, scheduling, and scope arrangements that do not prevent statutory audit rights. [Specify the evidence-request process and any permissible audit costs.]


10. Return, deletion, and duration

This DPA remains in effect while Noema processes customer personal data. At the end of the services, Noema will, at the Customer's choice, return or delete that data and delete existing copies unless law requires retention. Schedule 1 must state the return format, request window, deletion deadline, and backup-expiry period. Data awaiting backup expiry must remain protected and isolated from further use except as legally required or necessary for recovery under the agreed safeguards.

BEGIN

Give your company a Memory

Give your company a Memory

Give your company a Memory

Connect your first source in the next ten minutes. Ask the question you've been meaning to ask.

One essay a month

No product spam. Unsubscribe anytime.

No product spam. Unsubscribe anytime.

One essay a month

No product spam. Unsubscribe anytime.

Product

Company

Resources

Legal

The system of record for what your company knows.

The system of record for what your company knows.

© 2026 Noema Systems B.V. All rights reserved.

All systems operational

X

LinkedIn

GitHub

RSS

Create a free website with Framer, the website builder loved by startups, designers and agencies.