Data Processing Agreement
Last updated 25 August 2026
When you store your clients' personal data in Nucle.OS, you are the controller and we are your processor. UK GDPR Article 28 requires that relationship to be written down. This is that document — it forms part of our Terms of Service and applies automatically.
Parties and scope
This agreement is between you (the Controller) and No-Code District, operating Nucle.OS (the Processor).
It applies whenever we process personal data on your behalf, and it overrides anything inconsistent in our Terms of Service. No signature is required — using the product accepts it. If your organisation needs a countersigned copy on your own paper, email us.
Subject matter, duration, nature and purpose
Subject matter. Providing the Nucle.OS platform to you.
Duration. For as long as your workspace exists, plus the short period described under Deletion below.
Nature and purpose. Hosting, storing, organising, transmitting and displaying the data you put into the product, so the product works. We process only on your documented instructions — your use of the features is that instruction.
Types of data and categories of data subject
Categories of data subject: your staff and collaborators; your clients and their staff; your prospects; anyone whose details you record in the product.
Types of personal data: names, business email addresses, telephone numbers, job titles, employer, postal addresses, correspondence and meeting content, files you upload, time and billing records, and any other personal data you choose to enter into free-text fields.
Nucle.OS is not designed for special category data, criminal offence data, or payment card numbers, and you should not put them in it. If you need to, speak to us first.
Our obligations
We will:
- Process personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case we will tell you first unless the law forbids it.
- Ensure that anyone authorised to process the data is under a duty of confidentiality.
- Implement appropriate technical and organisational security measures (see Security below).
- Not engage another processor without the notice described under Subprocessors.
- Help you respond to data subject requests, taking into account the nature of the processing.
- Help you with your obligations around security, breach notification and impact assessments.
- Delete or return personal data at the end of the agreement, as you choose.
- Make available the information needed to demonstrate compliance, and allow for and contribute to audits.
Subprocessors
You give us general authorisation to use the subprocessors listed below. We will give you at least 30 days’ notice by email before adding or replacing one, and you may object on reasonable data protection grounds — in which case we will work with you to find a solution, or you may terminate.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU |
| Vercel | Application hosting and delivery | US |
| Resend | Outbound email | US |
| Daily.co | Video meetings and recordings (if used) | US |
| Email and calendar sync (only if connected) | US / EU | |
| Apollo.io | Prospect lookup (only if used) | US |
| Giphy | GIF search in chat (only if used) | US |
AI providers are deliberately not on this list. Where a workspace enables AI features it supplies its own API key, so those prompts are sent under your own contract with that provider, not ours.
International transfers
Your database and files are held in the European Union. The application is currently served from the United States, and several subprocessors are US-based.
Where personal data leaves the UK or EEA we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with appropriate supplementary measures. Data is encrypted in transit and at rest.
Security measures
Concretely, and verifiable:
- Row-level security is enforced on every table in the database, so one workspace cannot read another’s records even if the application layer were bypassed.
- Credentials for connected third-party accounts are encrypted with AES-256-GCM before storage.
- Data is encrypted in transit (TLS) and at rest.
- Role-based access control within each workspace, with a per-action audit log.
- Rate limiting and account lockout on authentication to resist brute-force attempts.
- Production access is restricted to personnel who require it.
We hold no formal certification such as SOC 2 or ISO 27001 at this time, and we will not imply otherwise.
Personal data breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and within 72 hours of becoming aware, with the nature of the breach, the likely consequences, the measures taken, and a contact point.
Reporting to a supervisory authority and to affected individuals is your responsibility as controller. We will give you what you need to do it.
Data subject requests
If a data subject contacts us directly about data we hold on your behalf, we will not respond substantively — we will refer them to you and let you know promptly.
We will help you fulfil requests for access, rectification, erasure, restriction, portability and objection, using the product’s export and deletion features and, where those do not reach, by hand.
Deletion and return
You can delete individual records at any time; deleted items sit in Trash for 15 days and are then permanently removed, including the underlying files.
Deleting your workspace removes its data immediately and irreversibly, including stored files. Backups held by our database provider may persist briefly before rotating out.
On termination you may export your data first. Tell us if you want certified deletion confirmation and we will provide it.
Audit
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this agreement and contribute to an audit you or your appointed auditor conduct — subject to confidentiality and to not compromising other customers’ security.
Liability and precedence
Liability under this agreement is subject to the limits in our Terms of Service. Where this agreement and those terms conflict on the processing of personal data, this agreement prevails.