Back to home

Data Processing Agreement

Last updated: July 31, 2026

1. About this agreement

This Data Processing Agreement ("DPA") applies when you use Nemi in the course of a business, profession, or organization and, in doing so, process personal data about other people through the Service. It is the written agreement required by Article 28(3) of the General Data Protection Regulation (GDPR).

The DPA is part of our Terms of Service (Section 10) and takes effect automatically when you start using the Service in that way. You do not need to sign a separate document, and we do not need to countersign one. If your organization requires a signed copy or a version on your own paper for its records, email support@nemilab.com and we will provide one.

If you use Nemi purely for your own personal or household purposes, this DPA does not apply to you; only our Terms of Service and Privacy Policy do.

Current version: 1.0, effective July 31, 2026.

2. Parties and roles

Processor:GuusLab, trading as Nemi, Utrecht, the Netherlands, KVK 95954600 ("we", "us").

Controller:the account holder or organization that uses the Service and decides what personal data is uploaded to it ("you"). If you are yourself a processor for your own customers, you act as their processor, this DPA makes us your sub-processor, and everything below applies with that reading.

You determine the purposes and means of the processing of the content you upload. We process that content only to provide the Service to you. For our own processing of your account, billing, technical, and communication data we are an independent controller; that processing is described in our Privacy Policy and is not governed by this DPA.

3. Our instructions

We process personal data on your behalf only on your documented instructions, including for transfers to a third country. Your instructions are:

  • This DPA and the Terms of Service.
  • Your use of the features of the Service, including the settings you choose (share links, expiry, passwords, workspace and organization membership, forms, upload links, and integrations you authorize).
  • Any further written instruction you send us, to the extent it is compatible with the Service and with applicable law.

We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. If we are required by EU or Member State law to process personal data beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

We do not use the content you upload for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train AI models.

4. Data that must not be uploaded

Nemi is a general purpose file sharing and collaboration platform. It is not built or certified for data that requires additional safeguards. As set out in Section 7 of the Terms of Service, you must not upload, store, request, or collect through the Service:

  • Special categories of personal data within the meaning of Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data used to identify a person, data concerning health, or data concerning a person's sex life or sexual orientation.
  • Personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
  • Patient records, medical files, or other data subject to sector-specific rules such as HIPAA, the Dutch Wgbo, NEN 7510, PCI DSS, or comparable healthcare, financial, or government security frameworks.

This exclusion applies to every part of the Service, including the questions you ask in a Nemi form or through an upload link. We do not sign business associate agreements under HIPAA and we make no representation that the Service meets any sector-specific framework.

You warrant that the personal data you upload stays within these limits. If you breach this section, you remain responsible toward the people whose data it is and toward your supervisory authority, and Section 15 of the Terms of Service (indemnification) applies.

5. Confidentiality

We treat the personal data we process on your behalf as confidential. Access is limited to the people who need it to provide, secure, or support the Service, and those people are bound by a duty of confidentiality that survives the end of their engagement. We do not disclose the content you upload to third parties except as described in Section 7 (sub-processors) and Section 11 (government and legal requests).

6. Security

We implement appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the risks of the processing. The measures in force are listed in Annex 2. We may update them as the Service evolves, provided the level of protection does not decrease.

7. Sub-processors

You give us general written authorization to engage the sub-processors listed in Annex 3. Each sub-processor is bound by a written agreement that imposes data protection obligations equivalent to those in this DPA, and we remain fully liable to you for their performance.

If we intend to add or replace a sub-processor, we will announce it on this page and, where we hold your email address for the account, notify you at least 30 days before the change takes effect. You may object on reasonable data protection grounds within that period by emailing support@nemilab.com. If we cannot offer you a reasonable alternative, you may terminate your subscription with a refund of the unused prepaid portion, as your exclusive remedy.

8. Assistance with data subject rights

The Service gives you direct control over the personal data you process through it: you can view, correct, export, and delete files, documents, form responses, and workspace members yourself, at any time.

If a person exercises a right under Articles 15 to 22 GDPR against you and you cannot answer them using those tools, we will assist you with appropriate technical and organizational measures, at your request and at our reasonable cost where the effort goes beyond routine support.

If a request reaches us directly and it concerns data we process on your behalf, we will not answer it ourselves. We will forward it to you without undue delay, unless we are legally required to respond.

9. Personal data breaches

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification goes to the email address of the account owner, and to the organization owner for a Business organization.

Our notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, and the measures we have taken or propose to take. We assist you with the notification you may have to make to your supervisory authority under Article 33 and to affected people under Article 34. Reporting to your own supervisory authority remains your responsibility as the controller.

10. Data protection impact assessments

On request, we provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to us. In practice this means providing the documentation on this page and answering specific questions about how the Service processes data.

11. Government and legal requests

If a public authority requests access to personal data we process on your behalf, we will inform you before we disclose anything, unless the law prohibits it. We review each request for validity, we do not grant direct or unrestricted access to any authority, and we disclose no more than the request legally requires.

12. International transfers

We store files and send email within the European Union. Where personal data is transferred outside the European Economic Area, for example to Google or Stripe in the United States, the transfer relies on an adequacy decision such as the EU-US Data Privacy Framework, or on Standard Contractual Clauses approved by the European Commission, together with supplementary measures where needed. Annex 3 lists the location of each sub-processor.

13. Deletion and return of data

You can delete files, documents, and your entire account from the Service at any time; deletion in the app is the primary way to get your data returned or erased. Exports are available in standard formats through the Service.

On termination of your account, we delete the personal data we process on your behalf. For uploaded files, deletion is immediate and permanent: file storage holds one copy, so nothing can be restored afterwards, by us or by anyone else. Residual copies in our database backups are removed within 30 days. We retain data beyond that point only where EU or Member State law requires it, for example the seven year Dutch tax retention period for billing records, and only for as long as that obligation lasts.

Free plan files are deleted automatically 30 days after upload, as described in the Terms of Service.

14. Audits and information

We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, primarily through this DPA, our Privacy Policy, and written answers to your questions.

If that is not sufficient for your compliance obligations, you may audit us, or mandate an independent auditor who is not a competitor of ours and who is bound by confidentiality. Audits take place at most once per twelve months, on at least 30 days written notice, during business hours, without disrupting the Service, and at your cost. An additional audit may take place after a personal data breach affecting your data, at our cost. We may require the auditor to sign a confidentiality agreement, and access to data belonging to other customers is never part of an audit.

15. Liability, precedence, and changes

Liability under this DPA is subject to the limitations in Section 14 of the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits the rights of data subjects or the liability that Article 82 GDPR places on us directly.

If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of personal data we handle on your behalf, this DPA prevails.

We may update this DPA to reflect changes in the Service, in our sub-processors, or in applicable law. Material changes follow the procedure in Section 17 of the Terms of Service, and sub-processor changes follow Section 7 above. The date at the top of this page shows when it was last revised.

This DPA is governed by Dutch law, and disputes go to the competent courts in the Netherlands, as set out in Section 18 of the Terms of Service.

16. Contact

For questions about this DPA, a signed copy, an audit request, or a sub-processor objection:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com

We have not appointed a Data Protection Officer: our processing does not meet the criteria of Article 37 GDPR. Data protection questions go to the address above and are handled by us directly.

Annex 1: Details of the processing

Subject matterProviding the Nemi file sharing, storage, conversion, and collaboration platform to you.
DurationFor as long as your account exists, plus the retention periods in Section 13.
Nature and purposeStorage, transmission, sharing, previewing, conversion, compression, malware scanning, collaborative editing, form collection, and back-up of the content you upload, plus the analytics we show you about your own shares.
Types of personal dataWhatever you choose to upload or collect: file and document content, form responses, names, email addresses, usernames, workspace and organization membership, share and download events, and technical data about uploads. Special categories under Article 9 GDPR and the data listed in Section 4 are excluded.
Categories of data subjectsYour employees and colleagues, your clients and customers, recipients of your share links, people who upload through your upload links or Beam, people who fill in your forms, and any person appearing in the content you upload.
FrequencyContinuous, for as long as you use the Service.

Annex 2: Technical and organizational measures

  • Encryption in transit: all traffic runs over TLS/HTTPS.
  • Encryption at rest: every object is encrypted with AES-256 by our EU based storage provider, with keys held and managed by that provider.
  • Access control: sign-in with Google, one-time email code, or passkey; role based workspace and organization permissions; least privilege for administrative access.
  • Share protection: optional link passwords, expiry dates, and download limits, plus optional password encryption of exported .nemi documents.
  • Malware scanning: uploaded files are scanned automatically and malicious files are blocked, on infrastructure we operate ourselves.
  • Data minimization in analytics: viewer IP addresses for share opens are stored only as a salted, truncated hash, and downloads are logged without IP address or browser details.
  • Segregation: customer data is separated per account, workspace, and organization by application level access control.
  • Availability: backups of the database, so accounts, workspaces, and document data survive a failure. Backups stay on infrastructure we operate in the Netherlands and roll over within 30 days. Documents and spreadsheets additionally keep version history, so earlier versions can be restored inside the Service.
  • Uploaded files are not backed up: file storage holds one copy. Deleting a file is immediate and permanent, and the Service is not intended to be your only copy of anything critical.
  • Logging: server logs are cleared on every deployment, which is usually at least once a day, and are never kept longer than 90 days.
  • Development practices: every change is reviewed before release by the maintainer, dependencies are kept up to date, and the codebase is reviewed for security issues.
  • Sub-processor control: written processing agreements with every provider in Annex 3, and EU regions selected where the provider offers them.
  • Incident response: breach detection, assessment, and the notification procedure in Section 9.

Annex 3: Sub-processors

The following sub-processors are authorized as of the date at the top of this page:

Sub-processorPurposeData location
Wasabi TechnologiesFile and document storage, AES-256 at restEU (Amsterdam)
Amazon Web Services (SES)Transactional and notification email deliveryEU (Frankfurt)
StripeSubscription payments and billingEU/US (EU-US Data Privacy Framework, SCCs)
GoogleSign-in with Google (authentication)EU/US (EU-US Data Privacy Framework, SCCs)

Wasabi, where your files are stored, is ISO 27001 certified and its data centers are SOC 2 audited, and it encrypts every object at rest with AES-256. Those are their certifications, not ours: as Section 4 says, we hold none of them, and the exclusion of Article 9 and sector-regulated data applies regardless of what our providers are certified for.

Application servers, file conversion, compression, malware scanning, and database backups run on infrastructure we operate ourselves in the Netherlands. Those functions involve no additional sub-processor, and backups never leave that infrastructure.

Third-party AI assistants that you connect through our MCP integration are not our sub-processors. They act on your instructions under their own provider's terms, only after you explicitly authorize the connection, and you can revoke it at any time in your account settings.