Data Processing Addendum

How N40 handles personal data processed on a client's behalf: scope, security, sub-processors and transfers

Last updated and effective:

Introduction

This page summarises the commitments N40 Agency, LLC (Delaware LLC, EIN 36-5172738, File No. 10548740; registered agent Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA) makes when processing personal data on behalf of a client, under Article 28 of the GDPR and equivalent obligations under other applicable law.

Engagements contracted in Ukraine are performed by ФОП Василенко Вадим Володимирович, and the same commitments apply. Details of both entities are in our Terms of Service.

This is a summary, not the contract. Where a signed DPA exists between us, that document governs and prevails over this page. Request one using the link at the end.

Roles of the parties

Controller

The Client. Determines the purposes and means of processing.

Processor

N40, or the Ukrainian entity where the engagement is contracted in Ukraine. Processes personal data solely to deliver the agreed services.

We do not process Client personal data for our own purposes, and we do not disclose it other than to the sub-processors listed below or where law requires it.

Subject matter of processing

The categories below reflect what our two services actually involve. The precise data, data subjects and duration for any engagement are fixed in the applicable agreement or Statement of Work, which takes precedence over this general description.

Activity

Data types

Data subjects

Business Audit

System inventories, report samples, process documentation. Personal data only incidentally, where it appears in the samples reviewed

Client's employees; individuals appearing in sampled records

Data & reporting integration

Sales, stock, finance and channel records; customer and counterparty identifiers; sales-representative and manager attribution

Client's employees, customers, partners and suppliers

Knowledge systems

Documents, procedures, correspondence and internal materials submitted for indexing

Client's employees; individuals named in those documents

Management dashboards

Aggregated business metrics; user accounts and access roles

Client's managers and analysts

AI-assisted analysis and decision support

Queries and their context; extracts from the consolidated dataset; generated summaries

Client's employees; individuals in the underlying data

Workflow automation

Order, task and approval records; routing and audit logs identifying the acting user

Client's employees, customers and suppliers

Contact form on n40.agency

Name, email, and optionally phone, company and enquiry details

Website visitors

We ask clients not to give us special-category data or criminal-offence data unless the engagement specifically requires it and the agreement provides for it.

Processing instructions

We process personal data only on the Client's documented instructions, including as to transfers, unless law requires otherwise. Where law requires it, we tell the Client before processing unless that law prohibits us from doing so on grounds of important public interest.

If we consider an instruction to infringe applicable data protection law, we tell the Client.

Personnel

Access to Client personal data is limited to personnel and contractors who need it to perform the agreed services. Everyone with access is bound by a confidentiality obligation, contractual or statutory, that survives the end of their engagement, and receives access only to what their task requires.

Security measures (Art. 32 GDPR)

We implement technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. Those measures include:

  • • Encryption of data in transit, and encryption at rest where the platform in use supports it.
  • • Access control on the principle of least privilege, with individual accounts and periodic review of who has access.
  • • Multi-factor authentication on administrative access where the service supports it.
  • • Logging of access and administrative actions.
  • • Backups of systems we operate, with restoration tested periodically.
  • • Secure development practice, including code review and dependency management.
  • • Separation of client environments and of production from development data.

Security is assessed for each engagement against the data involved, and the measures actually applied to a specific engagement are recorded in the signed DPA for that engagement. Where a Client requires a particular control, standard or certification, that belongs in the contract and we will say plainly whether we can meet it.

We do not hold SOC 2, ISO 27001 or any comparable certification, and we do not claim one. For a current description of our practices, contact contact@n40.agency.

Sub-processors

The Client gives general written authorisation for us to engage sub-processors. We give the Client advance notice of any new or replacement sub-processor, and a reasonable opportunity to object on data protection grounds before that sub-processor begins processing.

The providers below support our own operations. An engagement may involve additional sub-processors specific to the systems being built — those are identified in the applicable agreement rather than here.

Sub-processor

Purpose

Location

Supabase Inc.

Database and edge function behind the contact form

United States

Resend (AWS SES)

Transactional email delivery

United States

Netlify, Inc.

Website hosting and CDN

United States

Calendly, LLC

Appointment scheduling

United States

Google LLC

Tag Manager and Analytics 4, on the website only, after consent

United States

Meta Platforms, Inc.

Meta Pixel, on the website only, after consent

United States

LinkedIn Corporation

Insight Tag, on the website only, after consent

United States

Engagements are invoiced business-to-business. In Ukraine settlement is by bank transfer only, to an account at JSC "Universal Bank" (АТ «УНІВЕРСАЛ БАНК», ЄДРПОУ 21133352), trading as monobank. Outside Ukraine an invoice may also be settled by card through Stripe, Inc. as acquirer. Stripe and the receiving banks handle payment data under their own licences and regulatory obligations, as independent controllers rather than as our sub-processors.

We impose data protection obligations on our sub-processors no less protective than those we owe the Client, and we remain liable to the Client for their performance.

Assisting with data subject rights

Taking into account the nature of the processing, we assist the Client by appropriate technical and organisational measures in responding to requests under Chapter III of the GDPR — access, rectification, erasure, restriction, portability and objection.

We act on the Client's instruction and within a timeframe that allows the Client to meet its own statutory deadline, which we agree per engagement. Where a request reaches us directly, we do not respond to it on the merits; we forward it to the Client without undue delay, because the controller decides the response.

We do not delete or alter Client data except on the Client's instruction or where law requires it.

Personal data breaches (Art. 33)

On becoming aware of a personal data breach affecting Client data, we notify the Client without undue delay. That duty applies to every such breach; unlike the controller's duty to a supervisory authority, it is not filtered by a risk threshold. Our notification will describe, so far as we know it at the time:

  • • The nature of the breach and, where possible, the categories and approximate number of data subjects and records concerned.
  • • The likely consequences.
  • • The measures taken or proposed, including any mitigation.

Where we cannot provide everything at once, we provide it in phases as it becomes available, and we assist the Client under Art. 28(3)(f) with its obligations under Articles 32 to 36.

The Client, as controller, decides on and makes any notification to a supervisory authority under Art. 33 and to affected data subjects under Art. 34. We do not notify authorities or data subjects on the Client's behalf unless the Client instructs us to in writing.

Information and audit (Art. 28(3)(h))

We make available to the Client the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by the Client or an auditor it mandates.

Audits require reasonable prior written notice, take place during normal business hours, are limited to what is relevant to the processing, and are subject to confidentiality. Costs are borne by the Client unless the audit reveals a material breach on our part. Where the Client's purpose can be met by documentation we already hold, we may offer that first.

International transfers (Chapter V GDPR)

Our personnel are located in Ukraine and the United States, and the sub-processors above are established in the United States. Processing Client data therefore involves transfers outside the EEA.

The transfer mechanism is determined per recipient and per data flow, not by a single blanket instrument:

  • Adequacy. Where the recipient is covered by a European Commission adequacy decision — including a US entity holding a current certification under the EU–US Data Privacy Framework, which remains in force — that decision is the mechanism and no additional safeguard is required. We confirm certification for the specific legal entity and data category rather than assuming it from a corporate group.
  • Standard Contractual Clauses. Where the recipient is not covered by an adequacy decision, we rely on the Clauses adopted by Commission Implementing Decision (EU) 2021/914, using the module appropriate to the parties' roles, with a documented transfer assessment and any supplementary measures it identifies.
  • Ukraine. Ukraine is not covered by an adequacy decision. Access to Client data from our Kyiv operations is a restricted transfer and is governed by the Standard Contractual Clauses. Ukraine is a party to Council of Europe Convention 108. Ukrainian operations are conducted under martial law, currently extended by the Verkhovna Rada, and we will discuss the implications with any Client whose risk assessment requires it.

We keep a current record of each recipient and the mechanism relied on for it, and make it available to Clients on request. We monitor developments affecting these mechanisms, including the pending appeal against the EU–US adequacy decision before the Court of Justice, and will move a flow onto an alternative safeguard if the position changes.

Where Standard Contractual Clauses apply, they are annexed to the signed DPA.

Return and deletion (Art. 28(3)(g))

On expiry or termination, at the Client's choice, we return the personal data or delete it:

  • • Return in a standard format (JSON, CSV or another agreed format) within an agreed period, ordinarily 30 days from the request.
  • • Deletion from active systems within the same period.
  • • Backup copies are removed on the normal backup expiry cycle; until then they remain protected and are not processed for any other purpose.
  • • Written confirmation on request.

We may retain data where law requires it, and will identify the applicable requirement if asked.

AI processing

Where an engagement involves AI-assisted analysis, personal data in Client systems may be submitted to a model provider engaged as a sub-processor for that engagement and identified in the applicable agreement. We configure such processing so that Client data is not used to train the provider's models, and we confirm that position per provider.

Deliverables are designed so that actions with material business impact require approval from an authorised person on the Client's side. Whether any resulting processing constitutes a decision based solely on automated processing under Art. 22 GDPR is a matter for the Client as controller, and we assist with the assessment.

Request a signed DPA

This page is a summary. For a binding agreement — including the Standard Contractual Clauses annex where transfers require them — request a signed DPA and we will send a draft.

Request Signed DPA

Questions about your data? Contact us or email contact@n40.agency.

We use cookies for analytics, only with your consent. See our Cookie Policy.