Nikufra Legal
Data Processing Addendum
Informative data processing terms for customers where Nikufra processes personal data on their behalf.
Last updated: August 25, 2026
1. Purpose and status
This Data Processing Addendum is published for transparency and describes the data protection terms Nikufra expects to apply when it processes personal data on behalf of a business customer. It is informative and does not by itself amend or replace a signed customer agreement. Where required, the applicable processing terms will be agreed in the customer contract.
2. Roles
For customer production, operational, support, or system data processed under a customer agreement, the customer is normally the controller and Nikufra is normally the processor. For Nikufra's own website, sales, accounting, security, and business administration data, Nikufra acts as controller.
3. Processing details
| Item | Description |
|---|---|
| Subject matter | Industrial AI, data architecture, analytical and predictive systems, implementation, support, maintenance, and related professional services. |
| Duration | For the term of the customer agreement and any post-termination period required for deletion, return, support, legal, or audit purposes. |
| Nature of processing | Access, ingestion, structuring, transformation, analysis, visualization, logging, support, troubleshooting, and deletion or return. |
| Purpose | To deliver, secure, maintain, improve, and support agreed customer services. |
| Data subjects | Customer employees, contractors, operators, administrators, support contacts, and other individuals whose data appears in customer systems. |
| Personal data categories | Business contact details, user IDs, access logs, support records, operational metadata, shift references, approval records, system logs, and other data authorized by the customer. |
| Special categories | Nikufra does not require special category data for standard services. Customers should not provide special category data unless expressly agreed and legally supported. |
4. Customer instructions
Nikufra processes customer personal data only on documented customer instructions, including the customer agreement, statement of work, support requests, authorized access procedures, and written instructions from authorized customer personnel.
5. Remote access
Some customer engagements may involve authorized remote access to systems or data. Others may be fully on-site or handled inside the customer environment without remote access. The applicable model depends on the customer agreement and the technical environment.
- Remote access should be approved by the customer before use.
- Access should be limited to the people and systems needed for the agreed work.
- Where practical, access should be logged or otherwise traceable.
- Customer credentials, VPNs, remote sessions, or support channels should follow the customer's security rules.
6. Confidentiality
Nikufra personnel who access customer data are subject to confidentiality obligations. Access to customer data is limited to people who need it to provide, secure, or support the agreed services.
7. Security measures
- Access control and least-privilege practices.
- Use of business accounts and controlled collaboration tools.
- Confidential handling of customer data and project materials.
- Technical and organizational measures appropriate to the engagement and environment.
- Support for on-premises or customer-controlled environments where agreed.
- Human review and traceability for operational decision-support workflows where applicable.
8. Subprocessors
Nikufra currently uses a limited set of service providers for hosting, analytics, email, and scheduling. The current list is published on the Subprocessors page. Nikufra does not currently appoint external subcontractors to access customer production systems unless this is agreed with the customer.
9. Customer data and model training
Unless expressly agreed in writing, Nikufra does not use customer production data, operational data, or customer personal data to train general-purpose models or unrelated third-party products.
10. Assistance
Taking into account the nature of the processing and information available to Nikufra, we will provide reasonable assistance to customers with data subject requests, security, breach assessment, data protection impact assessments, and consultations with supervisory authorities where required by applicable law and the customer agreement.
11. Security incidents
If Nikufra becomes aware of a personal data breach affecting customer personal data processed by Nikufra as processor, we will notify the customer without undue delay and provide available information reasonably needed for the customer to meet its legal obligations.
12. Return and deletion
At the end of the relevant services, Nikufra will return or delete customer personal data in accordance with the customer agreement, unless continued retention is required by law, legitimate business records, security records, or dispute-resolution needs.
13. International transfers
Where processing involves transfers outside the European Economic Area, Nikufra will rely on appropriate transfer mechanisms where required, such as adequacy decisions, Standard Contractual Clauses, or other lawful safeguards.
