This Data Processing Agreement ("DPA") applies when you use Nemi in the course of a business, profession, or organization and, in doing so, process personal data about other people through the Service. It is the written agreement required by Article 28(3) of the General Data Protection Regulation (GDPR).
The DPA is part of our Terms of Service (Section 10) and takes effect automatically when you start using the Service in that way. You do not need to sign a separate document, and we do not need to countersign one. If your organization requires a signed copy or a version on your own paper for its records, email support@nemilab.com and we will provide one.
If you use Nemi purely for your own personal or household purposes, this DPA does not apply to you; only our Terms of Service and Privacy Policy do.
Current version: 2.3, effective September 2, 2026. Version 2.3 records one addition in Annex 1: a recipient looking at one of your links that has expired can now ask you to resend it, and doing so records a note they may write and, where there is one to record, their email address. Recipients of your share links were already named as data subjects and nothing changes about who they are; what is new is that they can write something you then read. No sub-processor is added and Annex 3 is unchanged. Version 2.2 changes who runs the language model behind the assistant, which is a change to Annex 3 and to where content is processed. Baseten, Parasail, Modal and DeepInfra are removed: they ran an open-weights model, all four were in the United States, and none of them receives anything now. Microsoft is added in their place, running the model on Azure and pinned to Azure's EU data zone, so the inference itself no longer leaves the EU. OpenRouter is unchanged and remains in the United States: it receives and decrypts every request in order to route it, so the model runs in Europe while the step in front of it does not, and this Annex says both rather than the flattering half. No category of data changes and nothing new is collected. Version 2.1 extends the Annex 1 record of the assistant inside Nemi: it can now be asked to write and rearrange the account holder's own folio, so what it sends can include the whole of that page, including the contact address and the location published on it. No sub-processor is added, and nothing that was already listed changes. Version 2.0 names all four companies that may run the language model behind the assistant, where 1.8 named only the first of them. Thirteen companies offer that model and one of them is in China; we allow a closed list of four, all in the United States, so content belonging to a customer cannot reach a host this Annex does not name. Adding one is a change to this document before it is a change to a setting. Version 1.9 completes the Annex 1 record of the assistant inside Nemi that version 1.8 introduced earlier the same day: a message now also carries what the account holder had open or selected on screen when they sent it, so Annex 1 names that as well. No sub-processor is added. Version 1.8 adds OpenRouter and Baseten to Annex 3 and records the assistant inside Nemi in Annex 1: on the Max and Business plans, an account holder can ask an assistant to act for them, and answering costs sending part of the content to a model gateway and to the company running the model, outside the EU. This is the first sub-processor that receives content in order to read it rather than to store or deliver it, so Annex 1 now says which parts and on whose instruction. Version 1.7 records folios in Annex 1: a page a person publishes about themselves, which we serve publicly on their instruction and about whose visitors we record nothing beyond a count of how many times the page was opened. No sub-processor is added. Version 1.6 adds ISRG (Let's Encrypt) to Annex 3: a workspace on Creator and higher can connect a domain it owns for its public links, and serving those links over HTTPS means obtaining a certificate for that hostname. Version 1.5 corrected Annex 1: earlier versions stated that we do not process the audio, video or shared screens of a meeting at all. That is true of the live streams and untrue of a recording a participant makes on their device, which is uploaded to their workspace and stored like any other file.
Processor:GuusLab, trading as Nemi, Utrecht, the Netherlands, KVK 95954600 ("we", "us").
Controller:the account holder or organization that uses the Service and decides what personal data is uploaded to it ("you"). If you are yourself a processor for your own customers, you act as their processor, this DPA makes us your sub-processor, and everything below applies with that reading.
You determine the purposes and means of the processing of the content you upload. We process that content only to provide the Service to you. For our own processing of your account, billing, technical, and communication data we are an independent controller; that processing is described in our Privacy Policy and is not governed by this DPA.
We process personal data on your behalf only on your documented instructions, including for transfers to a third country. Your instructions are:
We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. If we are required by EU or Member State law to process personal data beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.
We do not use the content you upload for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train AI models. Where the assistant inside Nemi sends part of it to the sub-processors in Annex 3, that is your instruction rather than our purpose, and the request carries an instruction that it may not be used for training either.
Nemi is a general purpose file sharing and collaboration platform. It is not built or certified for data that requires additional safeguards. As set out in Section 7 of the Terms of Service, you must not upload, store, request, or collect through the Service:
This exclusion applies to every part of the Service, including the questions you ask in a Nemi form or through an upload link. We do not sign business associate agreements under HIPAA and we make no representation that the Service meets any sector-specific framework.
You warrant that the personal data you upload stays within these limits. If you breach this section, you remain responsible toward the people whose data it is and toward your supervisory authority, and Section 15 of the Terms of Service (indemnification) applies.
We treat the personal data we process on your behalf as confidential. Access is limited to the people who need it to provide, secure, or support the Service, and those people are bound by a duty of confidentiality that survives the end of their engagement. We do not disclose the content you upload to third parties except as described in Section 7 (sub-processors) and Section 11 (government and legal requests).
We implement appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the risks of the processing. The measures in force are listed in Annex 2. We may update them as the Service evolves, provided the level of protection does not decrease.
You give us general written authorization to engage the sub-processors listed in Annex 3. Each sub-processor is bound by a written agreement that imposes data protection obligations equivalent to those in this DPA, and we remain fully liable to you for their performance.
If we intend to add or replace a sub-processor, we will announce it on this page and, where we hold your email address for the account, notify you at least 30 days before the change takes effect. You may object on reasonable data protection grounds within that period by emailing support@nemilab.com. If we cannot offer you a reasonable alternative, you may terminate your subscription with a refund of the unused prepaid portion, as your exclusive remedy.
The Service gives you direct control over the personal data you process through it: you can view, correct, export, and delete files, documents, form responses, and workspace members yourself, at any time.
If a person exercises a right under Articles 15 to 22 GDPR against you and you cannot answer them using those tools, we will assist you with appropriate technical and organizational measures, at your request and at our reasonable cost where the effort goes beyond routine support.
If a request reaches us directly and it concerns data we process on your behalf, we will not answer it ourselves. We will forward it to you without undue delay, unless we are legally required to respond.
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification goes to the email address of the account owner, and to the organization owner for a Business organization.
Our notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, and the measures we have taken or propose to take. We assist you with the notification you may have to make to your supervisory authority under Article 33 and to affected people under Article 34. Reporting to your own supervisory authority remains your responsibility as the controller.
On request, we provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to us. In practice this means providing the documentation on this page and answering specific questions about how the Service processes data.
If a public authority requests access to personal data we process on your behalf, we will inform you before we disclose anything, unless the law prohibits it. We review each request for validity, we do not grant direct or unrestricted access to any authority, and we disclose no more than the request legally requires.
We store files and send email within the European Union. Where personal data is transferred outside the European Economic Area, for example to Google or Stripe in the United States, the transfer relies on an adequacy decision such as the EU-US Data Privacy Framework, or on Standard Contractual Clauses approved by the European Commission, together with supplementary measures where needed. Annex 3 lists the location of each sub-processor.
You can delete files, documents, and your entire account from the Service at any time; deletion in the app is the primary way to get your data returned or erased. Exports are available in standard formats through the Service.
On termination of your account, we delete the personal data we process on your behalf. For uploaded files, deletion is immediate and permanent: file storage holds one copy, so nothing can be restored afterwards, by us or by anyone else. Residual copies in our database backups are removed within 30 days. We retain data beyond that point only where EU or Member State law requires it, for example the seven year Dutch tax retention period for billing records, and only for as long as that obligation lasts.
On the free plan a file is deleted 30 days after it was uploaded, or 30 days after a paid plan ended, whichever is later, as described in the Terms of Service.
Two things behave differently and you should plan around them. Everything Trace recorded about a link is deleted the moment you revoke that link, so exercising a recipient's erasure request can be done by you, immediately, without asking us. And a vault folder cannot be exported by us in readable form at any point, on termination or before it: only a member holding the key can decrypt it, so make sure somebody in your organization still holds one before an account is closed.
We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, primarily through this DPA, our Privacy Policy, and written answers to your questions.
If that is not sufficient for your compliance obligations, you may audit us, or mandate an independent auditor who is not a competitor of ours and who is bound by confidentiality. Audits take place at most once per twelve months, on at least 30 days written notice, during business hours, without disrupting the Service, and at your cost. An additional audit may take place after a personal data breach affecting your data, at our cost. We may require the auditor to sign a confidentiality agreement, and access to data belonging to other customers is never part of an audit.
Liability under this DPA is subject to the limitations in Section 14 of the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits the rights of data subjects or the liability that Article 82 GDPR places on us directly.
If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of personal data we handle on your behalf, this DPA prevails.
We may update this DPA to reflect changes in the Service, in our sub-processors, or in applicable law. Material changes follow the procedure in Section 17 of the Terms of Service, and sub-processor changes follow Section 7 above. The date at the top of this page shows when it was last revised.
This DPA is governed by Dutch law, and disputes go to the competent courts in the Netherlands, as set out in Section 18 of the Terms of Service.
For questions about this DPA, a signed copy, an audit request, or a sub-processor objection:
GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com
We have not appointed a Data Protection Officer: our processing does not meet the criteria of Article 37 GDPR. Data protection questions go to the address above and are handled by us directly.
| Subject matter | Providing the Nemi file sharing, storage, conversion, and collaboration platform to you. |
| Duration | For as long as your account exists, plus the retention periods in Section 13. |
| Nature and purpose | Storage, transmission, sharing, previewing, conversion, compression, malware scanning, collaborative editing, form collection, and back-up of the content you upload, plus the analytics we show you about your own shares. Where you switch on Trace for a share link, that additionally includes engagement analytics about the people who open it, described in Section 3.10 of our Privacy Policy: we record and present it on your instruction, and you decide whether to use it and against whom. Where you put a share under review, it includes the comments, pins and approval decisions your reviewers leave. For Nemi Meet we additionally connect meeting participants to one another and store the meeting chat and attendance record; we do not process the live audio, video, or shared screens themselves, which travel directly between participants and are never received by us in a form we could store. Where a participant uses Meet's device-side recording, their browser produces a video file of the call as they received it and uploads it to their workspace, and we then process that file as we process any other file content: it is stored, and it is not deleted when the meeting is. For a direct Beam transfer we introduce two devices to each other and process nothing else: the file never reaches us. For a vault folder we store ciphertext we are not able to decrypt, so our processing of its contents is limited to storing and returning bytes we cannot read. Where a person publishes a folio, we serve that page and its media to whoever opens it, on their instruction, and the only thing we record about a visit is a counter on the page itself: no address, no location, no device and no per visit record. Where an account holder on a plan that includes it uses the assistant inside Nemi, we send their message, that conversation, and the results of the actions the assistant took, to the sub-processors in Annex 3 that run the language model, so that it can answer and act. This happens per message and only on that instruction; it is the only processing in this Annex in which content leaves the European Union in order to be read rather than stored or delivered. We send every such request with an instruction that it may only be served by a host that does not retain it and may not be used to train a model, and the conversation itself is stored in Nemi on that account until they delete it. |
| Types of personal data | Whatever you choose to upload or collect: file and document content, form responses, names, email addresses, usernames, workspace and organization membership, share and download events, technical data about uploads, and, for meetings, the display names, attendance times, and chat messages of participants together with the network addresses their browsers exchange in order to connect. Where you switch on Trace, it also includes hashed IP addresses, coarse location derived from them, device, browser and operating system, referring page, and estimated reading time per page or per scene, for each person who opens the link. Where you use review rounds, it includes the names, optional email addresses and comments of your reviewers. Where a recipient asks you to resend a link of yours that has expired, it includes the note they write, if they write one, and an email address where there is one to record. For Gallery it includes the photographs themselves, the camera metadata read out of them, and a numeric vector of picture content computed on the uploader's device. Where the assistant inside Nemi is used, it includes whatever the requested action returns, which may be the text of a document, the cells of a spreadsheet, the answers to a form, the details of an event or a photograph, or, where they ask it about their folio, the whole of that page including the contact address and location they publish on it, together with the account holder's display name, the name of the workspace they have open, and what they had open or selected on screen when they asked: the title of the document, spreadsheet, canvas or form in front of them, the folder they were in, and the name, type and size of the files they had selected or were previewing. Special categories under Article 9 GDPR and the data listed in Section 4 are excluded. |
| Categories of data subjects | Your employees and colleagues, your clients and customers, recipients of your share links, people who open a link you have switched Trace on for, people who comment on or approve a review round, people who upload through your upload links or Beam, people who fill in your forms, people who join your meetings, and any person appearing in the content you upload. |
| Frequency | Continuous, for as long as you use the Service. |
The following sub-processors are authorized as of the date at the top of this page:
| Sub-processor | Purpose | Data location |
|---|---|---|
| Wasabi Technologies | File and document storage, AES-256 at rest | EU (Amsterdam) |
| Amazon Web Services (SES) | Transactional and notification email delivery | EU (Frankfurt) |
| Stripe | Subscription payments and billing | EU/US (EU-US Data Privacy Framework, SCCs) |
| Sign-in with Google (authentication) | EU/US (EU-US Data Privacy Framework, SCCs) | |
| OpenRouter | Routes a request from the assistant inside Nemi to the company running the language model. Receives the message, the conversation, and the results of the actions the assistant took. Only on plans that include the assistant, and only when it is used. | US (Standard Contractual Clauses) |
| Microsoft (Azure) | Runs the language model itself and receives the same request through OpenRouter. The only host: the request pins Azure's EU data zone and forbids the router from using any other company. We route only to a host that does not retain what it is sent, and we do not permit training on it. | EU (Azure EU data zone) |
| ISRG (Let's Encrypt) | TLS certificates for a custom domain you connect. Receives the hostname only, and no personal data. | US (certificate authority) |
Wasabi, where your files are stored, is ISO 27001 certified and its data centers are SOC 2 audited, and it encrypts every object at rest with AES-256. Those are their certifications, not ours: as Section 4 says, we hold none of them, and the exclusion of Article 9 and sector-regulated data applies regardless of what our providers are certified for.
Application servers, file conversion, compression, malware scanning, and database backups run on infrastructure we operate ourselves in the Netherlands. Those functions involve no additional sub-processor, and backups never leave that infrastructure.
Third-party AI assistants that you connect through our MCP integration are not our sub-processors. They act on your instructions under their own provider's terms, only after you explicitly authorize the connection, and you can revoke it at any time in your account settings. The assistant inside Nemi is the opposite case and is why OpenRouter and Microsoft appear above: there we choose the provider, so they are our sub-processors and we remain liable to you for them.