Data Processing Agreement
Last updated: 17 September 2026 ยท Version 2.0
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions of Service (the "Terms") between Nova Data Analytics (NDA) ("Nova") and the Customer. It applies when Nova processes personal data on behalf of the Customer to provide the Services, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR"), the UK GDPR where applicable, and the French Data Protection Act.
In this DPA: "Connected Account" means an Amazon account that the Customer connects to the Services; "AI Assistant" means a third-party artificial intelligence application chosen by the Customer, such as Claude, ChatGPT or Gemini, that accesses the Services through the Nova MCP Connector; "Nova MCP Connector" means Nova's Model Context Protocol server; "Account Action" means an operation performed on a Connected Account through the Services, where this feature is available; "Customer Inputs" means the data entered by the Customer in the Services, such as cost of goods, VAT settings, fulfilment costs or product tags; "Agency" means a Customer that uses the Services for Amazon accounts owned by its clients; "Fees" means the amounts paid by the Customer for the Services. Other capitalised terms have the meaning given in the Terms.
1. Roles and scope
1.1
For the personal data contained in Customer Data ("Customer Personal Data"), the Customer is the controller, or for an Agency the processor acting for its client, and Nova is the processor, or the sub-processor.
1.2
This DPA does not apply to the personal data that Nova processes as controller for its own purposes, such as account management, billing, security, service analytics, support and marketing. That processing is described in Nova's Privacy Policy.
1.3
Amazon, from which the Customer instructs Nova to retrieve data, and the AI Assistants, data warehouses and other third-party services to which the Customer instructs Nova to send data, are not sub-processors of Nova. Nova transmits data to them on the Customer's instructions.
2. Description of the processing
- Subject matter and purposes: providing the Services under the Terms, namely retrieving data from Connected Accounts, storing it, calculating and displaying analytics, providing exports and data sharing, providing access through the Nova MCP Connector, transmitting Account Actions, providing support, securing the Services and calculating Fees.
- Nature of the processing: collection through Amazon's APIs, recording, storage, organisation, structuring, calculation, consultation, transmission at the Customer's request, and deletion.
- Duration: the term of the Terms, followed by the return and deletion periods in Section 10.
- Categories of data subjects: (a) Authorised Users and other representatives of the Customer and of its clients; (b) individuals and sole traders who operate the Connected Accounts; (c) Amazon buyers, within the limits described below; (d) individuals named in Customer Inputs, such as supplier contacts.
- Categories of personal data: (a) identification and contact data of Authorised Users, their identifiers and logs of their use of the Services, including logs of Nova MCP Connector calls and of Account Actions; (b) identifiers, store names and business performance data of Connected Accounts; (c) for Amazon buyers, order identifiers and the country of delivery of each order, which is the only buyer information Nova keeps; (d) any personal data that the Customer includes in Customer Inputs. Nova does not request Amazon's restricted buyer data, such as buyers' names, email addresses, phone numbers or addresses.
- Special categories of data: none. The Customer shall not upload special categories of personal data.
- Location: the Services are hosted in France by Scaleway, in the Paris region. Sub-processors and their locations are listed at novadata.io/subprocessors.
3. Instructions
3.1
Nova processes Customer Personal Data only on the Customer's documented instructions. These instructions consist of the Terms, this DPA, the Customer's configuration and use of the Services (including connecting accounts, exports, connections of AI Assistants and Account Actions), and any other written instruction accepted by Nova.
3.2
Nova informs the Customer if, in its opinion, an instruction infringes data protection law.
3.3
If European Union or Member State law requires Nova to process Customer Personal Data otherwise, Nova informs the Customer before the processing, unless that law prohibits it.
3.4
The Customer is responsible for the lawfulness of its instructions and of the Customer Personal Data, including the authorisations required from the owners of Connected Accounts and the information given to data subjects.
4. Confidentiality
Nova ensures that the persons it authorises to process Customer Personal Data are bound by an obligation of confidentiality and access only the data they need for their tasks.
5. Security
Nova implements the technical and organisational measures described in Annex 1, which are appropriate to the risk. Nova may update these measures provided that the overall level of security is not reduced.
6. Sub-processors
6.1
The Customer gives Nova a general authorisation to engage sub-processors. The current list, with the transfer safeguard used for each of them, is available at novadata.io/subprocessors.
6.2
Nova informs the Customer of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, by email to the account owner or through a notice in the Services, and updates the list.
6.3
The Customer may object to the change on reasonable grounds relating to data protection, by writing to [email protected] within that period. The parties will look for a solution in good faith. If no solution is found, the Customer may terminate the affected Services and obtain a refund of the prepaid Fees for the remaining period.
6.4
Nova imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA, and remains responsible to the Customer for their performance.
7. International transfers
7.1
Where a sub-processor processes Customer Personal Data outside the European Economic Area, Nova ensures that the transfer relies on an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for certified recipients, or on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, with supplementary measures where required.
7.2
For personal data subject to the UK GDPR, transfers rely on the UK adequacy regulations or on the UK International Data Transfer Addendum.
8. Assistance
8.1 Data subject requests.
Nova informs the Customer without undue delay of any request it receives from a data subject concerning Customer Personal Data, does not answer it except to direct the person to the Customer, and assists the Customer by appropriate technical and organisational measures, taking into account the nature of the processing.
8.2 Other obligations.
Taking into account the nature of the processing and the information available to it, Nova assists the Customer with its obligations regarding security, personal data breach notification, data protection impact assessments and prior consultation of supervisory authorities.
8.3 Costs.
Assistance that goes beyond the standard features of the Services may be invoiced at a reasonable cost agreed in advance.
9. Personal data breaches
9.1
Nova notifies the Customer of any personal data breach affecting Customer Personal Data without undue delay, and no later than forty-eight (48) hours after becoming aware of it.
9.2
The notification describes, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases.
9.3
Nova takes reasonable measures to contain the breach and limit its effects. A notification is not an admission of fault or liability.
10. Return and deletion
10.1
The Customer can export its data during the Subscription and at the end of the Services using the export features of the Services, as described in the Terms.
10.2
Nova deletes Customer Personal Data no later than thirty (30) days after the end of a Trial Period that is not followed by a Subscription, and no later than sixty (60) days after the end of a Subscription, unless the Customer has asked for more time to export its data or European Union or Member State law requires storage. Copies in backups are deleted as the backups are overwritten on their normal cycle.
10.3
Nova confirms the deletion in writing on request.
11. Audits
11.1
Nova makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including answers to reasonable security questionnaires.
11.2
If this information is not sufficient, if a supervisory authority requires it, or after a personal data breach, the Customer may carry out an audit. Unless a supervisory authority requires it or a breach has occurred, audits are limited to one per twelve (12) months, require thirty (30) days' written notice, take place during business hours without disrupting Nova's operations, and are carried out by an independent auditor who is not a competitor of Nova and is bound by confidentiality. The Customer bears the costs of the audit. An audit does not give access to other customers' data or to information that would compromise the security of the Services.
12. Liability, precedence and governing law
12.1
Each party's liability under this DPA is subject to the limitations set out in the Terms, to the extent permitted by the GDPR.
12.2
In case of conflict, this DPA prevails over the Terms for the processing of personal data, and the Standard Contractual Clauses, where they apply, prevail over this DPA.
12.3
This DPA is governed by the law and subject to the jurisdiction set out in the Terms.
13. Signed copy and contact
A countersigned PDF of this DPA is available to any Nova customer on request. Email [email protected] and we will return a signed copy within five (5) business days.
Annex 1. Technical and organisational measures
- Hosting: application and databases hosted by Scaleway in the Paris region, France. Network traffic protected by Cloudflare (proxy and web application firewall).
- Encryption: data encrypted in transit. Application database encrypted at rest. Analytics warehouse hosted on dedicated servers in France.
- User authentication: passwords stored in hashed form with a unique salt, email verification before the first password login, limits on login attempts, and sign-in with Google available.
- Amazon access: authorisation through Amazon's own consent flows. Nova never receives Amazon passwords and does not request Restricted Data Tokens.
- Nova MCP Connector: access through OAuth authentication or personal access tokens stored in hashed form and revocable, and rate limiting of requests.
- Access log: log of access to Customer Data through the Nova MCP Connector.
- Monitoring: error monitoring and infrastructure monitoring.
- Backups: regular backups of the databases, including an off-site copy of the analytics database in Western Europe.
- Access management: access to production data limited to authorised team members who need it, bound by confidentiality obligations.
- Incident management: breach handling and notification process described in Section 9.
- Sub-processor management: contractual data protection obligations and transfer safeguards for every sub-processor.