Back to home

Data Processing Agreement

Last updated: September 2, 2026

1. About this agreement

This Data Processing Agreement ("DPA") applies when you use Nemi in the course of a business, profession, or organization and, in doing so, process personal data about other people through the Service. It is the written agreement required by Article 28(3) of the General Data Protection Regulation (GDPR).

The DPA is part of our Terms of Service (Section 10) and takes effect automatically when you start using the Service in that way. You do not need to sign a separate document, and we do not need to countersign one. If your organization requires a signed copy or a version on your own paper for its records, email support@nemilab.com and we will provide one.

If you use Nemi purely for your own personal or household purposes, this DPA does not apply to you; only our Terms of Service and Privacy Policy do.

Current version: 2.3, effective September 2, 2026. Version 2.3 records one addition in Annex 1: a recipient looking at one of your links that has expired can now ask you to resend it, and doing so records a note they may write and, where there is one to record, their email address. Recipients of your share links were already named as data subjects and nothing changes about who they are; what is new is that they can write something you then read. No sub-processor is added and Annex 3 is unchanged. Version 2.2 changes who runs the language model behind the assistant, which is a change to Annex 3 and to where content is processed. Baseten, Parasail, Modal and DeepInfra are removed: they ran an open-weights model, all four were in the United States, and none of them receives anything now. Microsoft is added in their place, running the model on Azure and pinned to Azure's EU data zone, so the inference itself no longer leaves the EU. OpenRouter is unchanged and remains in the United States: it receives and decrypts every request in order to route it, so the model runs in Europe while the step in front of it does not, and this Annex says both rather than the flattering half. No category of data changes and nothing new is collected. Version 2.1 extends the Annex 1 record of the assistant inside Nemi: it can now be asked to write and rearrange the account holder's own folio, so what it sends can include the whole of that page, including the contact address and the location published on it. No sub-processor is added, and nothing that was already listed changes. Version 2.0 names all four companies that may run the language model behind the assistant, where 1.8 named only the first of them. Thirteen companies offer that model and one of them is in China; we allow a closed list of four, all in the United States, so content belonging to a customer cannot reach a host this Annex does not name. Adding one is a change to this document before it is a change to a setting. Version 1.9 completes the Annex 1 record of the assistant inside Nemi that version 1.8 introduced earlier the same day: a message now also carries what the account holder had open or selected on screen when they sent it, so Annex 1 names that as well. No sub-processor is added. Version 1.8 adds OpenRouter and Baseten to Annex 3 and records the assistant inside Nemi in Annex 1: on the Max and Business plans, an account holder can ask an assistant to act for them, and answering costs sending part of the content to a model gateway and to the company running the model, outside the EU. This is the first sub-processor that receives content in order to read it rather than to store or deliver it, so Annex 1 now says which parts and on whose instruction. Version 1.7 records folios in Annex 1: a page a person publishes about themselves, which we serve publicly on their instruction and about whose visitors we record nothing beyond a count of how many times the page was opened. No sub-processor is added. Version 1.6 adds ISRG (Let's Encrypt) to Annex 3: a workspace on Creator and higher can connect a domain it owns for its public links, and serving those links over HTTPS means obtaining a certificate for that hostname. Version 1.5 corrected Annex 1: earlier versions stated that we do not process the audio, video or shared screens of a meeting at all. That is true of the live streams and untrue of a recording a participant makes on their device, which is uploaded to their workspace and stored like any other file.

2. Parties and roles

Processor:GuusLab, trading as Nemi, Utrecht, the Netherlands, KVK 95954600 ("we", "us").

Controller:the account holder or organization that uses the Service and decides what personal data is uploaded to it ("you"). If you are yourself a processor for your own customers, you act as their processor, this DPA makes us your sub-processor, and everything below applies with that reading.

You determine the purposes and means of the processing of the content you upload. We process that content only to provide the Service to you. For our own processing of your account, billing, technical, and communication data we are an independent controller; that processing is described in our Privacy Policy and is not governed by this DPA.

3. Our instructions

We process personal data on your behalf only on your documented instructions, including for transfers to a third country. Your instructions are:

  • This DPA and the Terms of Service.
  • Your use of the features of the Service, including the settings you choose (share links, expiry, passwords, workspace and organization membership, forms, upload links, and integrations you authorize).
  • Any further written instruction you send us, to the extent it is compatible with the Service and with applicable law.

We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. If we are required by EU or Member State law to process personal data beyond your instructions, we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

We do not use the content you upload for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train AI models. Where the assistant inside Nemi sends part of it to the sub-processors in Annex 3, that is your instruction rather than our purpose, and the request carries an instruction that it may not be used for training either.

4. Data that must not be uploaded

Nemi is a general purpose file sharing and collaboration platform. It is not built or certified for data that requires additional safeguards. As set out in Section 7 of the Terms of Service, you must not upload, store, request, or collect through the Service:

  • Special categories of personal data within the meaning of Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data used to identify a person, data concerning health, or data concerning a person's sex life or sexual orientation.
  • Personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR.
  • Patient records, medical files, or other data subject to sector-specific rules such as HIPAA, the Dutch Wgbo, NEN 7510, PCI DSS, or comparable healthcare, financial, or government security frameworks.

This exclusion applies to every part of the Service, including the questions you ask in a Nemi form or through an upload link. We do not sign business associate agreements under HIPAA and we make no representation that the Service meets any sector-specific framework.

You warrant that the personal data you upload stays within these limits. If you breach this section, you remain responsible toward the people whose data it is and toward your supervisory authority, and Section 15 of the Terms of Service (indemnification) applies.

5. Confidentiality

We treat the personal data we process on your behalf as confidential. Access is limited to the people who need it to provide, secure, or support the Service, and those people are bound by a duty of confidentiality that survives the end of their engagement. We do not disclose the content you upload to third parties except as described in Section 7 (sub-processors) and Section 11 (government and legal requests).

6. Security

We implement appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation, and the risks of the processing. The measures in force are listed in Annex 2. We may update them as the Service evolves, provided the level of protection does not decrease.

7. Sub-processors

You give us general written authorization to engage the sub-processors listed in Annex 3. Each sub-processor is bound by a written agreement that imposes data protection obligations equivalent to those in this DPA, and we remain fully liable to you for their performance.

If we intend to add or replace a sub-processor, we will announce it on this page and, where we hold your email address for the account, notify you at least 30 days before the change takes effect. You may object on reasonable data protection grounds within that period by emailing support@nemilab.com. If we cannot offer you a reasonable alternative, you may terminate your subscription with a refund of the unused prepaid portion, as your exclusive remedy.

8. Assistance with data subject rights

The Service gives you direct control over the personal data you process through it: you can view, correct, export, and delete files, documents, form responses, and workspace members yourself, at any time.

If a person exercises a right under Articles 15 to 22 GDPR against you and you cannot answer them using those tools, we will assist you with appropriate technical and organizational measures, at your request and at our reasonable cost where the effort goes beyond routine support.

If a request reaches us directly and it concerns data we process on your behalf, we will not answer it ourselves. We will forward it to you without undue delay, unless we are legally required to respond.

9. Personal data breaches

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf. The notification goes to the email address of the account owner, and to the organization owner for a Business organization.

Our notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned as far as known, the likely consequences, and the measures we have taken or propose to take. We assist you with the notification you may have to make to your supervisory authority under Article 33 and to affected people under Article 34. Reporting to your own supervisory authority remains your responsibility as the controller.

10. Data protection impact assessments

On request, we provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to us. In practice this means providing the documentation on this page and answering specific questions about how the Service processes data.

11. Government and legal requests

If a public authority requests access to personal data we process on your behalf, we will inform you before we disclose anything, unless the law prohibits it. We review each request for validity, we do not grant direct or unrestricted access to any authority, and we disclose no more than the request legally requires.

12. International transfers

We store files and send email within the European Union. Where personal data is transferred outside the European Economic Area, for example to Google or Stripe in the United States, the transfer relies on an adequacy decision such as the EU-US Data Privacy Framework, or on Standard Contractual Clauses approved by the European Commission, together with supplementary measures where needed. Annex 3 lists the location of each sub-processor.

13. Deletion and return of data

You can delete files, documents, and your entire account from the Service at any time; deletion in the app is the primary way to get your data returned or erased. Exports are available in standard formats through the Service.

On termination of your account, we delete the personal data we process on your behalf. For uploaded files, deletion is immediate and permanent: file storage holds one copy, so nothing can be restored afterwards, by us or by anyone else. Residual copies in our database backups are removed within 30 days. We retain data beyond that point only where EU or Member State law requires it, for example the seven year Dutch tax retention period for billing records, and only for as long as that obligation lasts.

On the free plan a file is deleted 30 days after it was uploaded, or 30 days after a paid plan ended, whichever is later, as described in the Terms of Service.

Two things behave differently and you should plan around them. Everything Trace recorded about a link is deleted the moment you revoke that link, so exercising a recipient's erasure request can be done by you, immediately, without asking us. And a vault folder cannot be exported by us in readable form at any point, on termination or before it: only a member holding the key can decrypt it, so make sure somebody in your organization still holds one before an account is closed.

14. Audits and information

We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, primarily through this DPA, our Privacy Policy, and written answers to your questions.

If that is not sufficient for your compliance obligations, you may audit us, or mandate an independent auditor who is not a competitor of ours and who is bound by confidentiality. Audits take place at most once per twelve months, on at least 30 days written notice, during business hours, without disrupting the Service, and at your cost. An additional audit may take place after a personal data breach affecting your data, at our cost. We may require the auditor to sign a confidentiality agreement, and access to data belonging to other customers is never part of an audit.

15. Liability, precedence, and changes

Liability under this DPA is subject to the limitations in Section 14 of the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits the rights of data subjects or the liability that Article 82 GDPR places on us directly.

If this DPA conflicts with the Terms of Service or the Privacy Policy on the processing of personal data we handle on your behalf, this DPA prevails.

We may update this DPA to reflect changes in the Service, in our sub-processors, or in applicable law. Material changes follow the procedure in Section 17 of the Terms of Service, and sub-processor changes follow Section 7 above. The date at the top of this page shows when it was last revised.

This DPA is governed by Dutch law, and disputes go to the competent courts in the Netherlands, as set out in Section 18 of the Terms of Service.

16. Contact

For questions about this DPA, a signed copy, an audit request, or a sub-processor objection:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com

We have not appointed a Data Protection Officer: our processing does not meet the criteria of Article 37 GDPR. Data protection questions go to the address above and are handled by us directly.

Annex 1: Details of the processing

Subject matterProviding the Nemi file sharing, storage, conversion, and collaboration platform to you.
DurationFor as long as your account exists, plus the retention periods in Section 13.
Nature and purposeStorage, transmission, sharing, previewing, conversion, compression, malware scanning, collaborative editing, form collection, and back-up of the content you upload, plus the analytics we show you about your own shares. Where you switch on Trace for a share link, that additionally includes engagement analytics about the people who open it, described in Section 3.10 of our Privacy Policy: we record and present it on your instruction, and you decide whether to use it and against whom. Where you put a share under review, it includes the comments, pins and approval decisions your reviewers leave. For Nemi Meet we additionally connect meeting participants to one another and store the meeting chat and attendance record; we do not process the live audio, video, or shared screens themselves, which travel directly between participants and are never received by us in a form we could store. Where a participant uses Meet's device-side recording, their browser produces a video file of the call as they received it and uploads it to their workspace, and we then process that file as we process any other file content: it is stored, and it is not deleted when the meeting is. For a direct Beam transfer we introduce two devices to each other and process nothing else: the file never reaches us. For a vault folder we store ciphertext we are not able to decrypt, so our processing of its contents is limited to storing and returning bytes we cannot read. Where a person publishes a folio, we serve that page and its media to whoever opens it, on their instruction, and the only thing we record about a visit is a counter on the page itself: no address, no location, no device and no per visit record. Where an account holder on a plan that includes it uses the assistant inside Nemi, we send their message, that conversation, and the results of the actions the assistant took, to the sub-processors in Annex 3 that run the language model, so that it can answer and act. This happens per message and only on that instruction; it is the only processing in this Annex in which content leaves the European Union in order to be read rather than stored or delivered. We send every such request with an instruction that it may only be served by a host that does not retain it and may not be used to train a model, and the conversation itself is stored in Nemi on that account until they delete it.
Types of personal dataWhatever you choose to upload or collect: file and document content, form responses, names, email addresses, usernames, workspace and organization membership, share and download events, technical data about uploads, and, for meetings, the display names, attendance times, and chat messages of participants together with the network addresses their browsers exchange in order to connect. Where you switch on Trace, it also includes hashed IP addresses, coarse location derived from them, device, browser and operating system, referring page, and estimated reading time per page or per scene, for each person who opens the link. Where you use review rounds, it includes the names, optional email addresses and comments of your reviewers. Where a recipient asks you to resend a link of yours that has expired, it includes the note they write, if they write one, and an email address where there is one to record. For Gallery it includes the photographs themselves, the camera metadata read out of them, and a numeric vector of picture content computed on the uploader's device. Where the assistant inside Nemi is used, it includes whatever the requested action returns, which may be the text of a document, the cells of a spreadsheet, the answers to a form, the details of an event or a photograph, or, where they ask it about their folio, the whole of that page including the contact address and location they publish on it, together with the account holder's display name, the name of the workspace they have open, and what they had open or selected on screen when they asked: the title of the document, spreadsheet, canvas or form in front of them, the folder they were in, and the name, type and size of the files they had selected or were previewing. Special categories under Article 9 GDPR and the data listed in Section 4 are excluded.
Categories of data subjectsYour employees and colleagues, your clients and customers, recipients of your share links, people who open a link you have switched Trace on for, people who comment on or approve a review round, people who upload through your upload links or Beam, people who fill in your forms, people who join your meetings, and any person appearing in the content you upload.
FrequencyContinuous, for as long as you use the Service.

Annex 2: Technical and organizational measures

  • Encryption in transit: all traffic runs over TLS/HTTPS.
  • Encryption at rest: every object is encrypted with AES-256 by our EU based storage provider, with keys held and managed by that provider.
  • Access control: sign-in with Google, one-time email code, or passkey; role based workspace and organization permissions; least privilege for administrative access. A correction, effective August 9, 2026: until that date the workspace role was enforced on some paths and not on others, so a person invited to a workspace in a view-only role could in practice still change what was in it. The role is now checked on every path that writes. Reading was never affected, and nothing outside the workspace was ever reachable this way, but the permission did not do what this measure said it did and we are recording that rather than quietly rewriting it.
  • Share protection: optional link passwords, expiry dates, and download limits, plus optional password encryption of exported .nemi documents.
  • Malware scanning: uploaded files are scanned automatically and malicious files are blocked, on infrastructure we operate ourselves. Vault files are excluded, because we cannot read them.
  • End to end encryption for vault folders: contents and file names are encrypted in the browser under a key generated on the member's device and never transmitted to us in usable form. We hold ciphertext only and cannot decrypt it, including in response to a legal request. Access is granted by re-encryption on an existing member's device; we route the result and cannot add ourselves.
  • Data minimization in analytics: viewer IP addresses are never stored raw. Share opens keep only a salted, truncated hash, under a salt held as configuration rather than written in our source code, and where that salt is not configured they keep no viewer identifier at all. A correction, effective August 9, 2026: that salt previously had a fallback value present in our source code, which made the stored hashes reversible by anyone holding it, so they were not the pseudonymous values this measure described. Section 3.6 of our Privacy Policy sets it out in full. Where you switch on Trace, the same hashing applies to viewing sessions and downloads, and the key that groups a returning viewer is scoped to one link so it cannot follow anyone between links or between customers. That grouping key is derived from a server secret that never had a published fallback and was not affected.
  • Peer to peer transfers: direct Beam transfers and Meet media travel between browsers and are not received by us. Where a relay is needed, it forwards encrypted traffic it cannot read and stores nothing.
  • On device photo indexing: Gallery search by picture content is computed in the uploader's browser. Photographs are stored by us as part of the Service, but they are not sent anywhere for analysis and are not processed by us or by any sub-processor for that purpose. Of the indexing itself we hold only the resulting numeric vector, described in Section 3.8a of our Privacy Policy, from which the photograph cannot be reconstructed.
  • Segregation: customer data is separated per account, workspace, and organization by application level access control.
  • Availability: backups of the database, so accounts, workspaces, and document data survive a failure. Backups stay on infrastructure we operate in the Netherlands and roll over within 30 days. Documents and spreadsheets additionally keep version history, so earlier versions can be restored inside the Service.
  • Uploaded files are not backed up: file storage holds one copy. Deleting a file is immediate and permanent, and the Service is not intended to be your only copy of anything critical.
  • Logging: server logs are cleared on every deployment, which is usually at least once a day, and are never kept longer than 90 days.
  • Development practices: every change is reviewed before release by the maintainer, dependencies are kept up to date, and the codebase is reviewed for security issues.
  • Sub-processor control: written processing agreements with every provider in Annex 3, and EU regions selected where the provider offers them.
  • Incident response: breach detection, assessment, and the notification procedure in Section 9.

Annex 3: Sub-processors

The following sub-processors are authorized as of the date at the top of this page:

Sub-processorPurposeData location
Wasabi TechnologiesFile and document storage, AES-256 at restEU (Amsterdam)
Amazon Web Services (SES)Transactional and notification email deliveryEU (Frankfurt)
StripeSubscription payments and billingEU/US (EU-US Data Privacy Framework, SCCs)
GoogleSign-in with Google (authentication)EU/US (EU-US Data Privacy Framework, SCCs)
OpenRouterRoutes a request from the assistant inside Nemi to the company running the language model. Receives the message, the conversation, and the results of the actions the assistant took. Only on plans that include the assistant, and only when it is used.US (Standard Contractual Clauses)
Microsoft (Azure)Runs the language model itself and receives the same request through OpenRouter. The only host: the request pins Azure's EU data zone and forbids the router from using any other company. We route only to a host that does not retain what it is sent, and we do not permit training on it.EU (Azure EU data zone)
ISRG (Let's Encrypt)TLS certificates for a custom domain you connect. Receives the hostname only, and no personal data.US (certificate authority)

Wasabi, where your files are stored, is ISO 27001 certified and its data centers are SOC 2 audited, and it encrypts every object at rest with AES-256. Those are their certifications, not ours: as Section 4 says, we hold none of them, and the exclusion of Article 9 and sector-regulated data applies regardless of what our providers are certified for.

Application servers, file conversion, compression, malware scanning, and database backups run on infrastructure we operate ourselves in the Netherlands. Those functions involve no additional sub-processor, and backups never leave that infrastructure.

Third-party AI assistants that you connect through our MCP integration are not our sub-processors. They act on your instructions under their own provider's terms, only after you explicitly authorize the connection, and you can revoke it at any time in your account settings. The assistant inside Nemi is the opposite case and is why OpenRouter and Microsoft appear above: there we choose the provider, so they are our sub-processors and we remain liable to you for them.