This Data Processing Agreement ("DPA") applies when you use Nemi in the course of a business, profession, or organization and, in doing so, process personal data about other people through the Service. It is the written agreement required by Article 28(3) of the General Data Protection Regulation (GDPR).
The DPA is part of our Terms of Service (Section 10) and takes effect automatically when you start using the Service in that way. You do not need to sign a separate document, and we do not need to countersign one. If your organization requires a signed copy or a version on your own paper for its records, email support@nemilab.com and we will provide one.
If you use Nemi purely for your own personal or household purposes, this DPA does not apply to you; only our Terms of Service and Privacy Policy do.
Current version: 1.0, effective July 31, 2026.
Processor:GuusLab, trading as Nemi, Utrecht, the Netherlands, KVK 95954600 ("we", "us").
Controller:the account holder or organization that uses the Service and decides what personal data is uploaded to it ("you"). If you are yourself a processor for your own customers, you act as their processor, this DPA makes us your sub-processor, and everything below applies with that reading.
You determine the purposes and means of the processing of the content you upload. We process that content only to provide the Service to you. For our own processing of your account, billing, technical, and communication data we are an independent controller; that processing is described in our Privacy Policy and is not governed by this DPA.
We process personal data on your behalf only on your documented instructions, including for transfers to a third country. Your instructions are:
We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. If we are required by EU or Member State law to process personal data beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.
We do not use the content you upload for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train AI models.
Nemi is a general purpose file sharing and collaboration platform. It is not built or certified for data that requires additional safeguards. As set out in Section 7 of the Terms of Service, you must not upload, store, request, or collect through the Service:
This exclusion applies to every part of the Service, including the questions you ask in a Nemi form or through an upload link. We do not sign business associate agreements under HIPAA and we make no representation that the Service meets any sector-specific framework.
You warrant that the personal data you upload stays within these limits. If you breach this section, you remain responsible toward the people whose data it is and toward your supervisory authority, and Section 15 of the Terms of Service (indemnification) applies.
We treat the personal data we process on your behalf as confidential. Access is limited to the people who need it to provide, secure, or support the Service, and those people are bound by a duty of confidentiality that survives the end of their engagement. We do not disclose the content you upload to third parties except as described in Section 7 (sub-processors) and Section 11 (government and legal requests).
We implement appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the risks of the processing. The measures in force are listed in Annex 2. We may update them as the Service evolves, provided the level of protection does not decrease.
You give us general written authorization to engage the sub-processors listed in Annex 3. Each sub-processor is bound by a written agreement that imposes data protection obligations equivalent to those in this DPA, and we remain fully liable to you for their performance.
If we intend to add or replace a sub-processor, we will announce it on this page and, where we hold your email address for the account, notify you at least 30 days before the change takes effect. You may object on reasonable data protection grounds within that period by emailing support@nemilab.com. If we cannot offer you a reasonable alternative, you may terminate your subscription with a refund of the unused prepaid portion, as your exclusive remedy.
The Service gives you direct control over the personal data you process through it: you can view, correct, export, and delete files, documents, form responses, and workspace members yourself, at any time.
If a person exercises a right under Articles 15 to 22 GDPR against you and you cannot answer them using those tools, we will assist you with appropriate technical and organizational measures, at your request and at our reasonable cost where the effort goes beyond routine support.
If a request reaches us directly and it concerns data we process on your behalf, we will not answer it ourselves. We will forward it to you without undue delay, unless we are legally required to respond.
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification goes to the email address of the account owner, and to the organization owner for a Business organization.
Our notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, and the measures we have taken or propose to take. We assist you with the notification you may have to make to your supervisory authority under Article 33 and to affected people under Article 34. Reporting to your own supervisory authority remains your responsibility as the controller.
On request, we provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to us. In practice this means providing the documentation on this page and answering specific questions about how the Service processes data.
If a public authority requests access to personal data we process on your behalf, we will inform you before we disclose anything, unless the law prohibits it. We review each request for validity, we do not grant direct or unrestricted access to any authority, and we disclose no more than the request legally requires.
We store files and send email within the European Union. Where personal data is transferred outside the European Economic Area, for example to Google or Stripe in the United States, the transfer relies on an adequacy decision such as the EU-US Data Privacy Framework, or on Standard Contractual Clauses approved by the European Commission, together with supplementary measures where needed. Annex 3 lists the location of each sub-processor.
You can delete files, documents, and your entire account from the Service at any time; deletion in the app is the primary way to get your data returned or erased. Exports are available in standard formats through the Service.
On termination of your account, we delete the personal data we process on your behalf. For uploaded files, deletion is immediate and permanent: file storage holds one copy, so nothing can be restored afterwards, by us or by anyone else. Residual copies in our database backups are removed within 30 days. We retain data beyond that point only where EU or Member State law requires it, for example the seven year Dutch tax retention period for billing records, and only for as long as that obligation lasts.
Free plan files are deleted automatically 30 days after upload, as described in the Terms of Service.
We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, primarily through this DPA, our Privacy Policy, and written answers to your questions.
If that is not sufficient for your compliance obligations, you may audit us, or mandate an independent auditor who is not a competitor of ours and who is bound by confidentiality. Audits take place at most once per twelve months, on at least 30 days written notice, during business hours, without disrupting the Service, and at your cost. An additional audit may take place after a personal data breach affecting your data, at our cost. We may require the auditor to sign a confidentiality agreement, and access to data belonging to other customers is never part of an audit.
Liability under this DPA is subject to the limitations in Section 14 of the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits the rights of data subjects or the liability that Article 82 GDPR places on us directly.
If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of personal data we handle on your behalf, this DPA prevails.
We may update this DPA to reflect changes in the Service, in our sub-processors, or in applicable law. Material changes follow the procedure in Section 17 of the Terms of Service, and sub-processor changes follow Section 7 above. The date at the top of this page shows when it was last revised.
This DPA is governed by Dutch law, and disputes go to the competent courts in the Netherlands, as set out in Section 18 of the Terms of Service.
For questions about this DPA, a signed copy, an audit request, or a sub-processor objection:
GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com
We have not appointed a Data Protection Officer: our processing does not meet the criteria of Article 37 GDPR. Data protection questions go to the address above and are handled by us directly.
| Subject matter | Providing the Nemi file sharing, storage, conversion, and collaboration platform to you. |
| Duration | For as long as your account exists, plus the retention periods in Section 13. |
| Nature and purpose | Storage, transmission, sharing, previewing, conversion, compression, malware scanning, collaborative editing, form collection, and back-up of the content you upload, plus the analytics we show you about your own shares. |
| Types of personal data | Whatever you choose to upload or collect: file and document content, form responses, names, email addresses, usernames, workspace and organization membership, share and download events, and technical data about uploads. Special categories under Article 9 GDPR and the data listed in Section 4 are excluded. |
| Categories of data subjects | Your employees and colleagues, your clients and customers, recipients of your share links, people who upload through your upload links or Beam, people who fill in your forms, and any person appearing in the content you upload. |
| Frequency | Continuous, for as long as you use the Service. |
The following sub-processors are authorized as of the date at the top of this page:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Wasabi Technologies | File and document storage, AES-256 at rest | EU (Amsterdam) |
| Amazon Web Services (SES) | Transactional and notification email delivery | EU (Frankfurt) |
| Stripe | Subscription payments and billing | EU/US (EU-US Data Privacy Framework, SCCs) |
| Sign-in with Google (authentication) | EU/US (EU-US Data Privacy Framework, SCCs) |
Wasabi, where your files are stored, is ISO 27001 certified and its data centers are SOC 2 audited, and it encrypts every object at rest with AES-256. Those are their certifications, not ours: as Section 4 says, we hold none of them, and the exclusion of Article 9 and sector-regulated data applies regardless of what our providers are certified for.
Application servers, file conversion, compression, malware scanning, and database backups run on infrastructure we operate ourselves in the Netherlands. Those functions involve no additional sub-processor, and backups never leave that infrastructure.
Third-party AI assistants that you connect through our MCP integration are not our sub-processors. They act on your instructions under their own provider's terms, only after you explicitly authorize the connection, and you can revoke it at any time in your account settings.