Legal
Data Processing Agreement
Version 1, effective 28 September 2026. This is the Data Processing Agreement for nineloops. It covers the personal data your organisation stores in nineloops and what PUBLSHR LTD does with it as your processor.
Parties
This Data Processing Agreement (the “DPA”) is between:
- PUBLSHR LTD (company number [company number]), a company registered in England and Wales, registered office [registered office address] (the “Processor”, “we”, “us”); and
- The customer named in the nineloops account that accepts this DPA (the “Controller”, “you”).
This DPA forms part of the nineloops Terms of Service (the “Terms”). If this DPA and the Terms disagree about the processing of personal data, this DPA wins. For everything else, the Terms win.
How this DPA is accepted
The Controller accepts this DPA by accepting the Terms when creating a workspace, or by signing it where a customer asks for a signed copy. A signed copy is available on request from hello@publshr.ae.
1. Definitions
- Data Protection Law means the UK GDPR, the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679) where it applies, and any law that replaces or supplements them.
- Personal Data, Controller, Processor, Data Subject, Processing, Personal Data Breach and Supervisory Authority have the meanings given in Data Protection Law.
- Customer Data means the content and records the Controller and its users put into nineloops, including personal data.
- Sub-processor means a third party we use to process Customer Data on the Controller's behalf.
- Service means nineloops, the web app, the desktop app, the mobile app and the related APIs.
- UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
- UK IDTA means the UK International Data Transfer Agreement issued by the Information Commissioner.
- SCCs means the standard contractual clauses approved by the European Commission in Decision (EU) 2021/914.
2. Roles
For Customer Data, the Controller is the controller and PUBLSHR LTD is the processor. Where the Controller is itself a processor for its own clients, the Controller acts as processor and PUBLSHR LTD acts as sub-processor, and the Controller confirms it has the authority to appoint us.
For account data, billing data and service logs we act as an independent controller. That processing is described in the Privacy Policy, not in this DPA.
3. Subject matter, duration, nature and purpose
- Subject matter. The Customer Data the Controller stores and works on in nineloops.
- Duration. The term of the Controller's nineloops account, plus the deletion period in section 12.
- Nature. Hosting, storage, retrieval, display, transmission, search, backup, and the AI features the Controller's users invoke.
- Purpose. To provide the Service to the Controller as described in the Terms and the product documentation, and for no other purpose.
The details are set out in Annex 1.
4. Categories of data and data subjects
Set out in Annex 1. In short: the Controller's staff, clients, contacts, candidates, suppliers and the people they correspond with, and the personal data such records normally contain.
5. Processor obligations
We will:
- Process Customer Data only on the Controller's documented instructions. The Terms, this DPA and the use of the Service by the Controller's users are those instructions. If the law requires us to process otherwise, we will tell the Controller before doing so, unless the law forbids that.
- Tell the Controller if we believe an instruction breaks Data Protection Law.
- Make sure every person we allow to access Customer Data is bound by confidentiality.
- Put in place the technical and organisational measures in Annex 2 and keep them under review.
- Help the Controller respond to requests from Data Subjects (access, correction, deletion, portability, objection) within the time Data Protection Law allows. The Service lets the Controller do most of this itself: export from Settings, Data and audit; deletion from the same page.
- Help the Controller with data protection impact assessments and consultations with a Supervisory Authority, where the help relates to the Service and the Controller cannot get the information elsewhere.
- Delete or return Customer Data at the end of the Service as set out in section 12.
- Make available the information needed to show compliance with Article 28 GDPR and allow audits as set out in section 11.
- Keep a record of the categories of processing we carry out for the Controller.
- Not sell Customer Data, use it for advertising, or use it to train AI models, and not allow any Sub-processor to do so.
6. Sub-processors
- The Controller gives general authorisation for us to use Sub-processors.
- The current list, with the purpose, the data each one handles and the data location, is published at nineloops.ae/sub-processors.
- We will give the Controller at least 30 days notice before adding or replacing a Sub-processor that will process Customer Data. Notice is given by a dated row in the changes table on the published list and by email to the owner of every workspace.
- The Controller may object on reasonable data protection grounds within that notice period. If we cannot resolve the objection, the Controller may end the affected part of the Service, and we will refund any prepaid fees for the period after the end date.
- We will put each Sub-processor under written terms that give at least the protection this DPA gives, and we remain responsible to the Controller for the Sub-processor's work.
7. International transfers
- Today the nineloops database and file storage are in the United States (Supabase, us-west-1, Northern California). A move to London, United Kingdom (eu-west-2) is planned. The web app is served by Vercel worldwide. See Where your data lives and the Sub-processors list for the current and planned location of each Sub-processor.
- We will not transfer Customer Data outside the United Kingdom or the European Economic Area unless a lawful transfer mechanism is in place.
- For transfers from the UK, the mechanism is one of: (a) a UK adequacy regulation for the destination; (b) the UK IDTA; or (c) the SCCs with the UK Addendum. For transfers from the EEA, the mechanism is one of: (a) an EU adequacy decision; or (b) the SCCs, Module 2 (controller to processor) or Module 3 (processor to processor) as applicable.
- Where the SCCs apply between the Controller and us, the parties agree that: Module 2 applies where the Controller is a controller, and Module 3 where it is a processor; Clause 7 (docking) is included; Option 2 of Clause 9 applies with the notice period in section 6; the optional wording in Clause 11 is not included; Clause 17 uses the law of Ireland; Clause 18 uses the courts of Ireland; Annex I is Annex 1 of this DPA; Annex II is Annex 2 of this DPA; Annex III is the Sub-processors list.
- Where the UK Addendum applies, Table 1 lists the parties as above, Table 2 refers to the SCCs as completed in the previous paragraph, Table 3 refers to the Annexes of this DPA, and Table 4 gives both parties the right to end the Addendum under section 19 of it.
- For transfers to our Sub-processors in the United States, we rely on the Sub-processor's certification under the EU-US Data Privacy Framework and the UK Extension to it where the Sub-processor holds one, and on the SCCs with the UK Addendum otherwise.
- We will carry out a transfer risk assessment where Data Protection Law requires one and make a summary available to the Controller on request.
8. Security
We will keep the technical and organisational measures set out in Annex 2. We may update them, but not in a way that lowers the overall protection of Customer Data during the term.
9. Personal Data Breach
- We will notify the Controller without undue delay and in any case within 48 hours of becoming aware of a Personal Data Breach affecting Customer Data.
- The notice will go to the email address of the workspace owner, and to any other address the Controller has asked us in writing to use. It will describe, as far as we know at the time: the nature of the breach; the categories and approximate number of Data Subjects and records; the likely consequences; the measures taken or proposed; and a contact for more information. We may give the information in stages as we learn it.
- We will help the Controller meet its own obligations to notify a Supervisory Authority and Data Subjects.
- A notice under this section is not an admission of fault or liability.
10. Assistance and requests from authorities
If a court, regulator or law enforcement body asks us for Customer Data, we will tell the Controller before disclosing, unless the law forbids it, and we will disclose only what the request lawfully requires.
11. Audit
- On request, and no more than once in any 12 months unless a Personal Data Breach has occurred or a Supervisory Authority requires it, we will give the Controller the information it reasonably needs to check that we comply with this DPA. This includes this DPA, Annex 2, the Sub-processors list, and any third-party audit reports or certifications our hosting providers make available to us.
- If that is not enough to satisfy a legal requirement, the Controller may carry out an audit, itself or through an independent auditor bound by confidentiality, on at least 30 days written notice, during business hours, without disrupting the Service, and limited to the systems that process the Controller's Customer Data. The Controller bears its own costs. We may charge a reasonable fee for time beyond one working day.
- Audits of our Sub-processors are carried out through the reports and certifications those Sub-processors publish. We do not have the right to audit their premises and cannot pass on such a right.
12. Deletion and return at the end of the Service
- The Controller can export every record in the account at any time from Settings, Data and audit. The export is a ZIP with one CSV per record type and a manifest. Files the Controller uploaded are listed in it by link and are downloaded from the module they belong to; they are not packed into the ZIP.
- When the Controller deletes its account, the account is scheduled for deletion and can be recovered for 30 days. When the window closes, a scheduled job removes the Customer Data from active systems, including uploaded files, cancels any subscription and closes the accounts of members whose only organisation this was, and emails the person who asked. Each run is recorded.
- When a subscription ends and the account is not deleted, Customer Data stays in the account on the Free plan, so the Controller can export or delete it.
- Copies in routine encrypted backups are removed on their normal rotation, within 30 days of deletion from active systems.
- We may keep a minimal record where the law requires it, for example for tax or accounting, and will keep it confidential and process it only for that purpose.
13. Liability
Each party's liability under this DPA is subject to the exclusions and limits set out in the Terms. The same cap applies to the Terms and this DPA together, not to each separately. Nothing in this DPA limits a party's liability where the law does not allow it to be limited.
14. General
- This DPA lasts as long as we process Customer Data for the Controller.
- If part of this DPA is found invalid, the rest stands.
- This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, the same as the Terms.
- We may update this DPA when the law or the Service changes. We will give notice of material changes. Continued use after the notice period is acceptance.
Annex 1. Details of the processing
Controller: the customer named in the nineloops account.
Processor: PUBLSHR LTD.
Categories of Data Subjects
- The Controller's employees, contractors and workspace members
- The Controller's clients, customers, leads and their staff
- Candidates and applicants (HR module)
- Suppliers and vendors (Finance module)
- Journalists, publications and press contacts (Distribute and Coverage modules)
- People who message the Controller through connected channels (WhatsApp, Instagram, Facebook, email)
- Attendees of calendar events and calls
- Any other person whose data the Controller chooses to store
Categories of Personal Data
- Identity and contact details: name, email, phone, job title, employer, social handles, addresses
- Correspondence: messages, email content and metadata, chat, comments, call metadata
- HR records: employment details, documents, leave, performance notes, and where the Controller stores them, pay, bank, tax and identity details
- Finance records: invoices, bills, payments, supplier and customer details
- CRM records: deals, notes, activity history
- Files and documents the Controller uploads
- Usage records inside the workspace: who did what and when (audit history)
Special category data
nineloops is not designed for special category data. The Controller may store some in HR records (for example sickness absence). The Controller is responsible for having a lawful basis and a condition under Article 9. Sensitive HR fields are masked and every reveal is recorded.
Frequency of processing: continuous, for the term.
Purpose of processing: to provide the Service.
Retention: the term of the account, then deletion as in section 12.
Annex 2. Technical and organisational measures
These are the measures in place on 28 September 2026.
Encryption
- TLS for all traffic between the apps and the backend, and between the backend and Sub-processors.
- Encryption at rest for the database and file storage, provided by the hosting provider.
- Tokens for connected accounts (mailboxes, Meta channels) are encrypted at rest with a key held in the backend secrets, not in the application.
- Records in the Docs vault are encrypted in the browser before storage, with a key derived from the workspace identifier. This keeps them out of ordinary reads and exports; it is not a key we cannot reach. Envelope encryption under a server-held master key is planned.
Workspace separation
- Every record belongs to a workspace. Row level security in the database stops one workspace reading or changing another's records. The rule runs on the server for every read and write.
- The service key that could bypass this never ships inside the apps.
Access control
- Eight roles, from owner to guest. Record-level visibility choices in the modules that give records an owner.
- Permissions are enforced by the database, so the app, the API and the AI get the same answer.
- Administrators can require two-step verification for every member and limit invitations to the company's own email domains.
- Sensitive HR fields are readable only through an audited call. Pay is visible only to the roles allowed to see it.
- Finance separation of duties: the person who raises a bill cannot approve it, and the approver cannot release payment.
- Staff access to production is limited to the people who operate the Service, on a least-privilege basis.
AI
- Levi runs on the sign-in of the person using it and can only read and change what that person can.
- Model providers are used under commercial API terms that prohibit training on the content sent.
- Only the content needed for the action invoked is sent, and only when a user invokes it.
Logging and audit
- An audit log of members and settings changes, and a history on records.
- Every AI action is logged with the state of the records before it, and most can be undone.
- Retention rules and legal holds on documents, enforced by the database.
Availability and backup
- The database is backed up daily by the hosting provider. Point-in-time recovery is not enabled today; enabling it is planned with the region move.
- Files sit in durable object storage at the hosting provider.
- Hosting providers run in data centres with physical access controls, redundancy and their own certifications, published on each provider's trust page.
Secure development
- Code is kept in a private repository with review on the main branch.
- Automated gates run on every change: type checks, tests, row level security checks, tenant guard checks, schema parity with production.
- Secrets are never committed. They live in the hosting providers' secret stores.
Incident response
- Incidents are investigated and notified as in section 9.
- A responsible disclosure route is published on the Security page.
Data subject rights and deletion
- Export of every record from Settings, Data and audit; uploaded files by link.
- Self-serve account deletion with a 30-day window, then removal from active systems, then backup rotation.
Personnel
- Everyone with access to Customer Data is bound by confidentiality.
Annex 3. Sub-processors
See the Sub-processors list at nineloops.ae/sub-processors. The list forms part of this DPA.
Contact
Questions about this DPA, a signed copy, or a data protection request? Email hello@publshr.ae.