01Scope & roles
This DPA is entered into between you ("Customer", the controller) and Nidavellir Software Private Limited ("Nidavellir", the processor) and applies where Nidavellir processes personal data on your behalf in the course of providing the Services. It supplements and is incorporated into our Terms of Service.
You determine the purposes and means of processing the personal data you submit to the Services. Nidavellir processes that data only on your documented instructions, which include the instructions expressed through your use of the Services and this DPA.
02Nature of processing
| Item | Details |
|---|---|
| Subject matter | Provision of the Nidavellir Services selected by the Customer. |
| Duration | For the term of the Customer's use of the Services, plus any retention period described in our Privacy Policy. |
| Nature & purpose | Hosting, storing and processing personal data to deliver, secure and support the Services. |
| Types of data | Account and contact details, usage and analytics data, and any content the Customer submits. |
| Categories of data subjects | The Customer's authorised users, end users and contacts. |
03Nidavellir's obligations
- Process personal data only on your documented instructions, unless required by law to do otherwise.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see our Security page).
- Assist you, taking into account the nature of processing, in responding to data subject requests.
- Assist you with data protection impact assessments and consultations with supervisory authorities where required.
- Delete or return personal data at the end of the Services, unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
04Sub-processors
You provide general authorisation for Nidavellir to engage sub-processors to support the Services. The current sub-processors are listed on our Sub-processors page. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
Payments are handled by our Merchant of Record, Paddle.com Market Limited, which acts as an independent controller for payment processing.
05Security measures
Nidavellir maintains technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. These include encryption in transit and at rest, least-privilege access controls, network isolation, logging and monitoring. A fuller description is on our Security page.
06Personal data breaches
Nidavellir will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide information reasonably available to help you meet your own notification obligations. Notifications and data protection enquiries can be sent to info@nidavellirs.com.
07International transfers
Where processing involves transferring personal data across borders, Nidavellir relies on an appropriate transfer mechanism (such as Standard Contractual Clauses or an adequacy decision) as required by applicable data protection law.
08General
This DPA is governed by the laws of India and, in the event of a conflict with the Terms of Service on the subject of data processing, this DPA prevails. To request a countersigned copy of this DPA, contact us at info@nidavellirs.com.
Questions about this policy?
Contact Nidavellir Software Private Limited at info@nidavellirs.com. Registered office: Nidavellir Software Private Limited, Chouksey Niwas, NH 12, Hoshangabad Road, Ward No. 85, Samardha, Bhopal, Madhya Pradesh 462046, India.