Legal
Data processing addendum
ntail's role as a GDPR processor, and how the two of us agree on it.
Our role: processor
When you send data through your own ntail cluster — the records, events and messages your applications produce and consume — you are the data controller for any personal data in that stream, and Factual Tech AB acts as your data processor under Article 28 of the GDPR. We process that data only on your documented instructions, for the purpose of providing the service, and never use it for our own purposes.
This is distinct from account, billing and contact data, where we act as controller — covered in our privacy policy, not here.
What a data processing addendum covers
A DPA is the contract required by GDPR whenever a controller uses a processor to handle personal data. It sets out, at minimum:
- The subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects involved.
- That we process data only on your instructions, and treat it as confidential.
- The security measures we apply — see security for detail on encryption, EU hosting and access control.
- The conditions under which we may engage sub-processors.
- Our support for your obligations to respond to data subject requests and to notify data breaches.
- Deletion or return of data at the end of the contract.
- Terms for international transfers, where applicable — see below.
International transfers
ntail hosts customer data in the EU by default. Where a sub-processor or a customer-requested region sits outside the EU/EEA, transfers rely on an adequacy decision or the EU Standard Contractual Clauses, as applicable.
Getting a signed DPA
Our DPA is incorporated into every customer contract as standard — there is no separate opt-in and no extra charge. If you need a standalone signed copy for your own records or vendor-review process, contact us and we'll send it over.
Contact
Questions about this addendum, or about a specific processing activity: info@ntail.io.