Version: 2026-10-01 · Effective date: October 1, 2026
This Data Processing Addendum (the DPA) forms part of the agreement between ForgeZen Labs LLC (DataNivra) and the customer named in the Order Form (Customer) consisting of the Terms of Service and the Order Form (together, the Agreement). Capitalised terms not defined here have the meanings given in the Terms of Service.
1. Definitions
1.1 Data Protection Laws means all data-protection and privacy laws that apply to the processing of Customer Personal Data under the Agreement, which may include the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection and US state consumer privacy laws.
1.2 Customer Personal Data means personal data contained in Control-Plane Metadata that DataNivra processes on Customer's behalf in providing the Hosted Service.
1.3 Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data processed by DataNivra.
1.4 Controller, processor, data subject, personal data, processing and supervisory authority have the meanings given in the GDPR (and the equivalent terms in other Data Protection Laws, such as business and service provider, are read accordingly). Sub-processor means a processor engaged by DataNivra to process Customer Personal Data.
2. Scope, roles and the privacy boundary
In plain English: you are the controller and we are your processor for the personal data in the metadata our hosted service stores for you. The data in your own systems is processed by software running in your environment, under your control — not by our hosted service.
2.1 Roles. Customer is the controller (or a processor acting for its own controllers) and DataNivra is the processor of Customer Personal Data. Each party will comply with the Data Protection Laws that apply to it.
2.2 Customer Source Data is outside DataNivra's processing. Customer Source Data is processed by the Customer-Resident Components in the Customer Environment, under Customer's control and on infrastructure that Customer operates. The Platform is designed so that Customer Source Data, including raw production rows, is not transmitted to, stored by or otherwise processed by DataNivra's Hosted Service. DataNivra does not act as Customer's processor for Customer Source Data merely by licensing software that Customer runs itself. If Customer grants DataNivra personnel access to the Customer Environment (for example for support), that access and any resulting processing will be agreed in writing in advance and is subject to this DPA.
2.3 Accidental transmission. If Customer Source Data or other data outside the categories in Annex 1 reaches the Hosted Service in breach of the Agreement or despite the Platform's controls, DataNivra will treat it as Customer Personal Data under this DPA, notify Customer when it becomes aware, and delete it on Customer's instructions.
2.4 DataNivra as controller. This DPA does not apply to personal data that DataNivra processes as a controller, such as website enquiries and business contact and billing data, which the Privacy Policy describes.
3. Details of processing
3.1 The subject matter, nature, purpose and duration of processing, the categories of data subjects and personal data, and the retention of Customer Personal Data are described in Annex 1.
4. DataNivra's obligations
In plain English: we follow your instructions, keep the data confidential and secure, help you with your own obligations, and tell you quickly about any breach.
4.1 Instructions. DataNivra will process Customer Personal Data only on Customer's documented instructions, which are the Agreement, this DPA and Customer's use and configuration of the Platform, unless required to do otherwise by law, in which case DataNivra will inform Customer before processing unless the law prohibits it. DataNivra will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4.2 US state privacy laws. DataNivra will not sell or share Customer Personal Data, will not retain, use or disclose it for any purpose other than providing the Platform under the Agreement, and will not combine it with personal data received from other sources except as permitted by Data Protection Laws.
4.3 Confidentiality. DataNivra will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and have access only as needed to perform the Agreement.
4.4 Security. DataNivra will implement and maintain the technical and organisational measures described in Annex 2, which are designed to protect Customer Personal Data appropriately to the risk. DataNivra may update these measures provided that the overall level of protection is not materially reduced.
4.5 Assistance with data subject requests. Taking into account the nature of the processing, DataNivra will assist Customer by appropriate technical and organisational measures in responding to requests from data subjects. If DataNivra receives such a request directly, it will refer the data subject to Customer and will not respond other than to confirm the referral, unless Customer instructs it or the law requires. Customer can manage its Users and their roles in the console; DataNivra will assist with other requests (for example access or deletion of a User's records) on Customer's written request.
4.6 Assistance with assessments. DataNivra will provide reasonable information to help Customer carry out data protection impact assessments and prior consultations with supervisory authorities relating to the Platform, to the extent Customer does not otherwise have access to the information.
5. Sub-processors
In plain English: you authorise our current sub-processors; we will tell you before adding new ones and you can object.
5.1 Authorisation. Customer gives DataNivra general authorisation to engage Sub-processors. The current list is maintained at https://www.datanivra.com/legal/subprocessors and, at the effective date of this DPA, comprises the providers listed in Annex 3.
5.2 Obligations. DataNivra will impose data-protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for its Sub-processors' performance.
5.3 Changes and objection. DataNivra will notify Customer of any intended addition or replacement of a Sub-processor at least 30 days in advance (by updating the list and notifying subscribers, or by email). Customer may object on reasonable data-protection grounds within that period. The parties will discuss the objection in good faith; if DataNivra cannot provide a reasonable alternative, Customer may terminate the affected part of the Agreement and receive a refund of prepaid Fees for the remaining period.
6. Personal Data Breach
6.1 Notification. DataNivra will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach.
6.2 Information. The notification will describe, to the extent known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences and the measures taken or proposed. Information may be provided in phases.
6.3 Response. DataNivra will take reasonable steps to contain, investigate and mitigate the breach and will co-operate with Customer. Notification is not an acknowledgement of fault.
7. Deletion and return
7.1 On termination or expiry of the Agreement, DataNivra will make Customer Personal Data available for export and will then delete it as described in section 16 of the Terms of Service, unless the law requires retention. During the Subscription Term, audit events are purged automatically after the audit retention period configured for Customer's account. On request, DataNivra will confirm deletion in writing.
8. Audits
8.1 Information. DataNivra will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including this DPA's Annex 2, relevant security documentation and answers to reasonable security questionnaires, subject to confidentiality.
8.2 Audits. Where the information in section 8.1 is not sufficient to demonstrate compliance, or where a supervisory authority requires it, Customer (or an independent auditor bound by confidentiality and reasonably acceptable to DataNivra) may audit DataNivra's compliance on at least 30 days' written notice, no more than once in any twelve-month period (except after a Personal Data Breach), during normal business hours, at Customer's cost, and in a way that does not compromise the security of the Platform or other customers' data.
9. International transfers
9.1 DataNivra and its Sub-processors may process Customer Personal Data outside the country in which Customer is established. Where Data Protection Laws require it, the parties agree that transfers are governed by the European Commission Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), using the applicable module, together with the UK International Data Transfer Addendum or other legally valid transfer mechanism where required (for example the European Commission's Standard Contractual Clauses, Module Two or Three, with the UK addendum), which are incorporated by reference, with the details in Annex 1 and Annex 2 of this DPA completing their appendices.
10. Customer obligations
10.1 Customer is responsible for the lawfulness of its instructions and of the Customer Personal Data it provides, for providing the notices and obtaining the consents or other legal bases required, for configuring the Platform (including roles, separation of duties and audit retention), and for not placing Customer Source Data, special categories of personal data or other data outside Annex 1 in Control-Plane Metadata (for example in names, descriptions or labels).
11. General
11.1 Liability. Each party's liability under this DPA is subject to the limitations of liability in the Agreement, to the extent permitted by Data Protection Laws.
11.2 Precedence. For the processing of personal data, this DPA prevails over the Terms of Service, and the Order Form prevails over this DPA. Standard contractual clauses incorporated under section 9 prevail over this DPA where they conflict.
11.3 Duration. This DPA applies for as long as DataNivra processes Customer Personal Data.
Annex 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Hosted Service (control plane) of the DataNivra Platform |
| Nature and purpose | Hosting, storage, organisation and retrieval of Control-Plane Metadata to provide governance, orchestration, self-service, audit, usage metering and support; authentication and authorisation of Users |
| Duration | The Subscription Term plus the export and deletion periods in the Terms of Service |
| Data subjects | Customer's Users (employees and contractors authorised to use the Platform); individuals whose identifiers Customer chooses to include in Control-Plane Metadata |
| Categories of personal data | User work email address, display name, roles, account status, tenant membership, identity-provider type and subject identifier; user identifiers in audit events, job requests, approvals and policy versions; session and token-revocation identifiers; any personal data that Customer includes in names, descriptions or labels of policies, schemas, tables, columns, jobs or datasets |
| Special categories | None intended. The Platform is designed so that Customer Source Data, which may contain special categories, stays in the Customer Environment |
| Excluded data | Customer Source Data, including raw production rows and samples; credentials, secret values and key material (only secret references are stored) |
| Retention | Account and job metadata for the life of Customer's account; audit events for the configured audit retention period (365 days by default, as set in the Plan or Order Form); session revocation records until token expiry; backups up to 35 days; infrastructure logs up to 90 days |
| Processing locations | United States — specific Microsoft Azure production region to be confirmed before execution; see Annex 3 for Sub-processor locations |
Annex 2 — Technical and organisational measures (summary)
These measures describe the design of the Platform at the effective date of this DPA. They are summarised here and documented in more detail in DataNivra's security documentation, which is available to Customer on request.
- Customer-resident processing and zero raw-production-data egress by design. Row-level processing runs only in the Customer-Resident Components in the Customer Environment. Every field that crosses the boundary to the Hosted Service is classified as control metadata, aggregate metric, evidence metadata or secret reference; fields classified as prohibited raw data cannot be serialised into control-plane messages.
- Egress and ingress guards. The Agent's egress guard allow-lists message types, applies content detectors (for example for email addresses, national identifiers, card and account numbers, dates of birth, addresses and encoded values) and size limits, and rejects suspicious messages locally without sending the payload. The Hosted Service applies the same detectors on receipt and rejects without echoing values. Small counts in discovery reports are suppressed. These detectors are heuristic and reduce, rather than eliminate, the risk of personal data in identifier names.
- Tenant isolation. Every tenant-scoped database table is protected by PostgreSQL row-level security keyed to the requesting tenant. Cross-tenant requests return not-found responses so that the existence of other tenants' objects is not revealed.
- Encryption in transit. External traffic uses HTTPS (TLS) with HTTP Strict Transport Security; the database requires TLS 1.2 or later; the Agent connects outbound over HTTPS only.
- Encryption and protection at rest. Data is stored in managed cloud database and key-management services with provider-managed encryption at rest; the database is reachable only over private networking.
- Secrets. Credentials and keys are held in secret managers (for example Azure Key Vault or Customer's own vault). The Platform stores secret references, never secret values; pseudonymisation keys remain under Customer's control.
- Access control and separation of duties. Role-based access control with defined roles (for example organisation owner, security administrator, data administrator, TDM engineer, auditor and read-only). Separation of duties prevents the author of a policy from approving it and separates dataset requester, reviewer and provisioner. Sign-in uses the Customer's OpenID Connect (OIDC) identity provider; access tokens are short-lived and revoked on sign-out.
- Audit logging. Privileged actions create append-only audit events chained with SHA-256 hashes so that alteration or deletion is detectable; database permissions and triggers prevent updates and deletions by the application. Audit events contain identifiers and codes, not data values.
- Logging without values. Application logs use an allow-list of fields and exclude request bodies, headers, tokens, query strings, SQL parameters and exception messages. Logs never contain secret values.
- Network and edge protection. The Hosted Service is served through a web application firewall at the edge and refuses traffic that bypasses it; rate limits protect authentication and public endpoints.
- Resilience. Managed database backups (up to 35 days) and infrastructure monitoring.
- Secure development. Dependency locking and scanning, secret scanning, container scanning, automated privacy and security test suites (including checks that synthetic canary values never reach control-plane storage, logs or responses) and a documented incident-response process for suspected raw-data egress.
- Synthetic data in development. Development, testing and demonstrations use synthetic data only.
DataNivra does not claim third-party certification of these measures unless an Order Form expressly identifies one.
Annex 3 — Sub-processors (at the effective date of this DPA)
The authoritative list is at https://www.datanivra.com/legal/subprocessors (last updated September 29, 2026).
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting of the control plane, database, key management, edge network, firewall, logging and monitoring | United States — specific Microsoft Azure production region to be confirmed before execution |
| Vercel | Hosting and delivery of the console web application | United States and other locations used by Vercel's global infrastructure — counsel/owner to confirm current contracted processing locations |
| Email delivery provider (SMTP), when configured | Delivery of service emails | TBD — select the transactional email provider and confirm its contracted processing location before execution |
Payment processors (for example Stripe) process billing data for DataNivra as a separate controller or as DataNivra's processor for DataNivra's own billing; they do not receive Customer Personal Data from Control-Plane Metadata. Customer's identity provider is selected and contracted by Customer and is not a Sub-processor of DataNivra.