This Data Processing Addendum ("DPA") is incorporated into and subject to the terms and conditions of the agreement, terms of service, product terms, order form(s), or other written or electronic agreement between Nexio and the customer entity that is a party to such agreement (the "Agreement").
If there is any conflict between this DPA and the Agreement on matters of data protection or privacy, this DPA controls (unless Applicable Law requires otherwise).
1. Definitions
"Additional Data Protection Laws" means, as applicable, U.S. federal, state, and local privacy laws (e.g., CCPA/CPRA and implementing regulations), the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), and the Australian Privacy Act 1988 (Cth), in each case to the extent applicable to the processing of personal data under the Agreement.
"Agreement" means the governing agreement between Nexio and Customer for the Services (e.g., Terms of Service/Use, order form, merchant application, or other written/electronic agreement), as updated or amended from time to time.
"Applicable Law" means all applicable data protection and privacy laws and regulations that apply to a party's processing of Personal Data under the Agreement.
"Controller," "Processor," "Data Subject," "Personal Data," "Process/Processing," and "Supervisory Authority" have the meanings given under Applicable Law; if not defined there, the meanings given under GDPR.
"Customer Personal Data" (also called "Business Connection Data" in some frameworks) means Personal Data that is submitted to or Processed by Nexio on behalf of Customer via the Services, including data about Customer's customers, personnel, vendors, and prospects.
"DPA" means this Data Processing Addendum.
"Nexio" means Complete Merchant Solutions, LLC dba Nexio, the provider of the Services.
"Nexio Group" means Nexio and any entity that directly or indirectly controls, is controlled by, or is under common control with Nexio.
"Security Incident" means any confirmed unauthorized or unlawful access to, acquisition of, disclosure of, loss of, or alteration to Customer Personal Data on systems controlled by Nexio.
"Sensitive Data" means (a) government-issued identifiers (e.g., SSN, passport), (b) precise geolocation, financial account credentials, genetic/biometric data, or health data; (c) data revealing racial/ethnic origin, political opinions, religious/philosophical beliefs, trade union membership, sex life or sexual orientation; or (d) account passwords or authentication secrets.
"Service(s)" means the Services provided by Nexio under the Agreement, including Nexio's payment-processing services, merchant portals, websites, and online and AI-enabled tools (such as the Alan Statement Agent).
"Sub-processor" means a third party engaged by Nexio (or a Nexio Group entity) to Process Customer Personal Data on Nexio's behalf, excluding Nexio employees or individual contractors.
2. Roles and Responsibilities
2.1 Parties' Roles.
For the provision of the Services, Customer acts as a Controller (or a Processor acting on behalf of a third-party Controller) and Nexio acts as a Processor of Customer Personal Data. Nexio may act as a Controller for limited internal purposes set out in the Agreement (e.g., product improvement, security, fraud prevention, analytics, compliance, and legal obligations). When Nexio acts as Controller, it will Process Personal Data in accordance with its Privacy Policy.
2.2 Purpose Limitation and Instructions.
Nexio will Process Customer Personal Data only (a) on Customer's documented lawful instructions (as set out in the Agreement and this DPA, including Customer's configuration of settings and integrations), (b) to comply with Applicable Law, or (c) as otherwise permitted by the Agreement ("Permitted Purposes"). Processing outside these purposes requires Customer's prior written instructions.
2.3 Prohibited/Sensitive Data.
Except as expressly permitted in the Services or otherwise agreed in writing, Customer will not provide Sensitive Data or PHI (as defined under HIPAA) to Nexio for Processing under this DPA. Nexio has no liability for Sensitive Data or PHI provided in violation of this DPA.
2.4 Biometric Data (if used).
If a Service uses Biometric Data (e.g., facial verification), Customer is responsible for all required notices, consents, retention/destruction schedules, and compliance with Applicable Law. Nexio Processes Biometric Data solely as Processor.
2.5 Customer Compliance.
Customer represents and warrants that: (a) it has complied and will continue to comply with Applicable Law in its Processing of Customer Personal Data and in issuing Processing instructions to Nexio; (b) it has provided all notices and obtained all consents necessary for Nexio to Process Customer Personal Data for the Permitted Purposes; and (c) all Customer Personal Data provided is accurate, lawful, and obtained by lawful means.
2.6 Lawfulness of Instructions.
Customer's instructions will not cause Nexio to violate Applicable Law. If Nexio believes an instruction violates Applicable Law, Nexio will notify Customer (unless legally prohibited) and may suspend such Processing until the instruction is confirmed lawful or modified.
3. Sub-Processing
3.1 Authorization.
Customer authorizes Nexio to engage Sub-processors to Process Customer Personal Data in providing the Services.
3.2 Sub-processor Obligations.
Nexio will: (a) enter into written agreements with Sub-processors imposing data protection obligations at least as protective as those in this DPA; and (b) remain responsible for Sub-processors' compliance and for any acts/omissions of Sub-processors that cause Nexio to breach this DPA. Upon request and subject to confidentiality, Nexio will make available a current list of Sub-processors or otherwise provide reasonable information about Sub-processors.
4. Security
4.1 Security Measures.
Nexio will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Incidents, taking into account the state of the art, implementation costs, nature/scope/context/purposes of Processing, and the risk to individuals. Measures include, as appropriate: (a) encryption/pseudonymization; (b) ensuring ongoing confidentiality, integrity, availability, and resilience of Processing systems; (c) restoration of availability/access following incidents; and (d) regular testing and evaluation of effectiveness.
4.2 Confidentiality.
Nexio will ensure persons authorized to Process Customer Personal Data are bound by confidentiality obligations.
4.3 Updates.
Customer is responsible for reviewing information made available by Nexio regarding data security. Nexio may update security measures from time to time, provided such updates do not materially reduce overall security of the Services.
4.4 Security Incident Response.
Upon becoming aware of a Security Incident affecting Customer Personal Data, Nexio will: (a) notify Customer without undue delay; (b) take steps reasonably necessary to identify the cause, mitigate the effects, and remediate the issue within Nexio's control; and (c) provide Customer with information reasonably necessary to support Customer's (or its Controller's) notification obligations, subject to confidentiality and Applicable Law. Such notice is not an admission of fault. Customer is responsible for regulatory or data subject notifications unless the Agreement provides otherwise.
4.5 Customer Responsibilities.
Customer is responsible for securing its authentication credentials, securing Customer Personal Data in transit to/from the Services, using appropriate encryption and backups, and configuring the Services (including integrations with Connected Platforms) in a secure and compliant manner.
5. Security Reports and Audits
Nexio will make available information reasonably necessary to demonstrate compliance with this DPA (e.g., independent audit reports or summaries), and will respond to reasonable written questions regarding Processing and protection of Customer Personal Data. If additional audit rights are required by Applicable Law, the parties will cooperate in good faith to scope such audits (at Customer's expense) so they do not unduly disrupt Nexio's operations or compromise confidentiality/security.
6. International Transfers
6.1 Processing Locations.
Nexio Processes Customer Personal Data exclusively in the United States. Customer Personal Data is not transferred outside the United States in connection with the Services.
7. Return or Deletion of Data
Upon termination or expiration of the Agreement, Nexio will provide tools for Customer to delete or export Customer Personal Data (where available) or will delete such data, in each case within a commercially reasonable period, unless retention is required by Applicable Law, industry rules, or Nexio's backup/archival policies (in which case Nexio will securely isolate and protect such data until deletion). Certification of deletion will be provided upon written request where required by Applicable Law.
8. Data Subject Rights and Cooperation
8.1 Requests.
Considering the nature of Processing, Nexio will provide reasonable assistance to enable Customer to comply with Data Subject requests under Applicable Law. If a Data Subject submits a request directly to Nexio and the Data Subject is identifiable as Customer's, Nexio will (where legally permissible) notify Customer and direct the Data Subject to contact Customer, or will otherwise respond as required by Applicable Law.
8.2 DPIAs and Consultations.
To the extent required by Applicable Law and considering the nature of Processing and information available to Nexio, Nexio will provide reasonable assistance to Customer to conduct data protection impact assessments or prior consultations with Supervisory Authorities.
9. Jurisdiction-Specific Terms
To the extent Customer Personal Data is subject to the laws of one of the jurisdictions below, the terms in this Section 9 apply in addition to this DPA.
9.1 United States (CCPA/CPRA and other state laws).
When Processing Customer Personal Data subject to U.S. state privacy laws (e.g., CCPA/CPRA), Nexio acts as a "Service Provider" (or equivalent). Nexio will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the Permitted Purposes and performance of the Services; or (c) combine Customer Personal Data with personal data obtained from other sources, except as permitted by law (e.g., to detect security incidents or improve the Services). Nexio will provide assistance reasonably required for Customer to honor consumer rights under applicable U.S. privacy laws.
9.2 Canada (PIPEDA).
Where PIPEDA applies, the parties will comply with PIPEDA requirements for Processing and cross-border transfers. Nexio will ensure Sub-processors are subject to written terms providing at least the same level of protection as this DPA.
10. Limitation of Liability
Each party's and its Affiliates' aggregate liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set forth in the Agreement. Nothing in this DPA limits a Data Subject's non-waivable rights under Applicable Law.
11. Relationship with the Agreement
(a) This DPA remains in effect for as long as Nexio Processes Customer Personal Data on behalf of Customer or until the Agreement terminates and Customer Personal Data is deleted or returned in accordance with Section 7.
(b) This DPA replaces any prior data processing agreement between the parties for the Services.
(c) In the event of conflict, the following order of precedence applies: (i) this DPA, then (ii) the Agreement.
(d) Except as modified by this DPA, the Agreement remains unchanged.
Annex A – Details of Processing
A. Data Subjects.
Customers of Customer, Customer's employees and personnel, Customer's vendors or prospects (as determined by Customer's configuration and use of the Services).
B. Categories of Personal Data.
Personal Data submitted to or generated by the Services (e.g., names, contact details, identifiers, payment-related metadata, communications), as determined by Customer. Sensitive Data/PHI is not intended to be Processed unless explicitly permitted in writing.
C. Frequency and Duration.
Continuous, for the Term of the Agreement and this DPA, unless otherwise required by Applicable Law or the Agreement.
D. Subject Matter and Nature of Processing.
Provision of the Services (including integrations, messaging, invoicing, payment instruction transmission, fraud prevention, security, analytics) as described in the Agreement; storage, retrieval, transmission, deletion; and disclosures as compelled by law.
E. Purpose of Processing.
To provide, secure, support, and improve the Services; comply with Applicable Law; prevent fraud and abuse; and perform the Permitted Purposes set forth in this DPA and the Agreement.
F. Retention/Deletion.
As described in Section 7 of this DPA and in the Agreement's data retention section(s).