NetNodes Policy

Go back

Data Processing Agreement (DPA)

Version 1.1 - Last Updated: December 2025

This Data Processing Agreement (“DPA”) forms part of any contract, order form, subscription agreement, master services agreement, or terms governing the provision of services (“Agreement”) between:

Customer (the Data Controller)
and
NetNodes Limited, trading as DoorFlow and PassFlow (“NetNodes”, the Data Processor).

This DPA applies where NetNodes processes Personal Data on behalf of the Customer in delivering the Services.

1. Definitions

“Applicable Data Protection Laws”
Means all laws relating to the processing of Personal Data, including:

“Customer Data”
Means any Personal Data that the Customer provides, uploads, transmits, or stores within the Services.

“Sub-processor”
Means any third party engaged by NetNodes to process Personal Data on behalf of the Customer.

“Services”
Means the DoorFlow and/or PassFlow software platforms, APIs, infrastructure, and related services.

All other GDPR-defined terms (e.g., “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”) carry their standard meaning.

2. Roles of the Parties

NetNodes will process Customer Data strictly on documented instructions.

3. Scope of Processing

3.1 Nature and Purpose of Processing

NetNodes processes Customer Data only as needed to:

3.2 Categories of Personal Data

Depending on Customer configuration:

3.3 Categories of Data Subjects

3.4 Duration

This DPA applies for the duration of the underlying Agreement, and thereafter until all Customer Data is deleted.

4. Customer Instructions

NetNodes will process data only:

  1. On documented instruction from the Customer
  2. As required to provide the Services
  3. As required by law

If NetNodes believes an instruction violates data protection law, NetNodes will notify the Customer.

5. Security Measures

NetNodes will implement and maintain industry-standard technical and organisational safeguards including, at minimum:

A high-level security overview is available upon request.

6. Sub-processors

6.1 Authorised Sub-processors

Customer authorises NetNodes to engage Sub-processors necessary to provide the Services, including cloud hosting, email delivery, and support services.

A current list is available at: https://policy.netnodes.net/subprocessors

6.2 Sub-processor Obligations

NetNodes will:

Customer may object to a new sub-processor where reasonable, and NetNodes will work in good faith to resolve the objection.

7. International Data Transfers

Where Customer Data is transferred outside the UK/EEA:

NetNodes will not engage in any transfer that violates Applicable Data Protection Laws.

8. Data Subject Rights

NetNodes will assist the Customer in responding to:

NetNodes will not respond to Data Subject requests directly unless legally required.

9. Personal Data Breach Notification

NetNodes will:

Customer is responsible for notifying authorities or Data Subjects unless otherwise agreed.

10. Audit Rights

Upon reasonable notice:

Audits must not interfere with NetNodes’ operations or security posture.

11. Data Deletion and Return

Upon termination of Services:

NetNodes may retain minimal information necessary for legal, audit, or accounting obligations.

12. Confidentiality

NetNodes will ensure that employees and authorised personnel:

13. Assistance with DPIAs & Compliance

NetNodes will cooperate as reasonably required with:

Reasonable administrative fees may apply for excessive or complex requests.

14. CCPA/CPRA Supplemental Terms (US Customers)

For US customers subject to the California Consumer Privacy Act:

15. Liability

Liability is governed by the underlying Agreement.
Nothing in this DPA limits statutory rights under GDPR or CCPA.

16. Termination

This DPA terminates automatically when the underlying Agreement terminates and all Customer Data is deleted.

17. Governing Law

Where the underlying Agreement does not specify:

18. Order of Precedence

If this DPA conflicts with other terms of the Agreement, this DPA prevails to the extent required by data protection law.

19. Signatures

This DPA may be executed electronically or incorporated by reference into an online agreement.

Cookies

You can find out about cookies and how we use them here.

Specifically, we monitor how people use our site to find out how well it's doing, and to look for ways to improve it. We would like your permission to do that, but we understand if you'd prefer not.