NimbusThe Salesforce dev toolchain
Run locally →Execute Apex and its surrounding platform services on your machine.
Run Apex testsTest dataFlow testing
Understand failures →Find the cause, measure the risk, and see what a change can reach.
Failure intelligenceCode coverageDependency graph
Ship safely →Use the same local evidence to gate releases and Salesforce deployment.
Deploy and releaseRelease managementAssurance console
Work in your tools →Keep the local runtime close to the editor, terminal, and agents you use.
VS Code extensionJetBrains pluginDev UI
All featuresCompareChangelog
DocsPricingSign inTry it free

Compliance

Data Processing Agreement

Version 1.0 · Effective 2026-04-27

This Data Processing Agreement ("DPA") forms part of the Nimbus Terms of Service and applies to the processing of personal data by Nimbus ("Processor") on behalf of any customer ("Controller") using the Nimbus service. By using Nimbus, the Controller agrees to this DPA. Customers requiring a counter-signed copy may request one at privacy@testnimbus.dev.

1. Definitions

Terms used in this DPA have the meanings given in Article 4 of the EU General Data Protection Regulation 2016/679 ("GDPR"). "Personal Data" means data submitted by Controller or its end users to Nimbus in the course of using the service.

2. Subject matter and duration

Subject matter: Provision of the Nimbus local Apex runtime service, including authentication, license issuance, billing, and customer support.
Duration: For as long as Controller maintains an active account, plus retention periods required by law (see Section 9).

3. Nature and purpose of processing

Nimbus processes Personal Data solely to provide and improve the service. Specifically:

  • Authenticate users and maintain account sessions
  • Issue and validate software licenses tied to a user identity
  • Process payments and generate invoices
  • Track machine activations to enforce license terms
  • Respond to support requests
  • Comply with legal obligations (e.g. tax records)

4. Categories of data subjects

  • Controller's authorized end users (developers using Nimbus)
  • Controller's billing contacts and admins

5. Categories of personal data

  • Identifying data: email address, name (if provided)
  • Account data: hashed password or OAuth identifier, sign-in history
  • Billing data: address, VAT ID, card last 4, transaction history
  • Technical data: IP address, user agent, machine fingerprint, hostname
  • Consent records: timestamps, IP, content of disclosures shown to users

6. Processor obligations

Nimbus shall:

  • Process Personal Data only on documented Controller instructions, including the use of the service
  • Ensure persons authorized to process Personal Data are bound by confidentiality
  • Implement appropriate technical and organizational measures (TOMs) per Section 8
  • Assist Controller in responding to data subject rights requests
  • Notify Controller without undue delay of any Personal Data breach (within 72 hours)
  • Make available all information necessary to demonstrate compliance with this DPA
  • Allow audits by Controller or an independent auditor (subject to reasonable notice and confidentiality)

7. Subprocessors

Controller hereby grants Nimbus general written authorization to engage subprocessors. Nimbus maintains a current list of subprocessors at /subprocessors and will notify Controller at least 30 days in advance of changes. Controller may object to a new subprocessor by giving written notice within that period; if the parties cannot resolve the objection, Controller may terminate this DPA and the related service for that subprocessor's portion of processing.

Each subprocessor is bound by data protection obligations no less protective than those set out in this DPA.

8. Technical and organizational measures (TOMs)

  • Encryption in transit: All HTTP traffic uses TLS 1.2 or higher
  • Encryption at rest: Databases and file storage encrypted at rest (AES-256)
  • Access control: Personal Data access limited to authorized personnel; service-role keys used only by trusted server-side functions, never exposed to browsers
  • Row-level security: Database access controls ensure users can only read their own data
  • Audit logging: Consent records, billing changes, and account modifications are logged with IP and user agent
  • Backups: Daily encrypted backups; tested restore procedures
  • Incident response: Documented breach notification procedure (72-hour notification window)
  • Personnel training: All staff with data access trained in GDPR basics and confidentiality obligations

9. International transfers

Nimbus primarily processes Personal Data within the European Economic Area. Where transfers to third countries are necessary (e.g. via subprocessors in the United States), they are governed by the EU Standard Contractual Clauses (SCCs) Module Two (Controller-to-Processor) or equivalent transfer mechanisms. See the subprocessors page for current arrangements.

10. Data subject rights

Nimbus enables Controllers and end users to exercise their rights under Articles 15–22 GDPR directly through the service:

  • Access (Art. 15): Self-serve JSON export from the user portal
  • Rectification (Art. 16): Account fields editable in the portal
  • Erasure (Art. 17): Self-serve account deletion (anonymization with retained tax records as legally required)
  • Restriction & objection (Art. 18, 21): Contact privacy@testnimbus.dev
  • Portability (Art. 20): JSON export is in a machine-readable format

11. Retention and deletion

Personal Data is retained only as long as necessary for the purposes set out above. Specific retention periods:

  • Account data: until deletion request
  • Subscription records: 10 years after account closure (German § 147 AO tax compliance)
  • Invoices: 10 years (Stripe holds these per the same obligation)
  • Consent records: 3 years after last related transaction
  • Operational logs: 90 days

Upon termination of this DPA, Nimbus will delete or return all Personal Data (Controller's choice), subject to retention periods required by applicable law.

12. Liability and term

This DPA enters into force when Controller starts using the service and terminates with the underlying service agreement. Liability under this DPA is governed by the limitation of liability provisions in the Nimbus Terms of Service.

13. Governing law and jurisdiction

This DPA is governed by the laws of Germany. Disputes shall be resolved by the competent courts of Germany unless otherwise required by mandatory consumer protection law in the Controller's country of residence.

14. Contact

For all matters relating to this DPA or data protection in general, contact privacy@testnimbus.dev. Full company details are on the Impressum.


Note: This is the standard published DPA. Enterprise customers requiring a counter-signed version, additional warranties, or specific TOMs attestations may contact us — we offer a signed DPA without modification of substantive terms, plus optional addenda for specific industries.

Nimbus

Built for the Salesforce developer community

ProductAll featuresDocsQuickstartHow-to guidesApex errorsChangelogUse CasesCompareFAQOur Story
FeaturesDeploy & ReleaseRelease ManagementAssurance ConsoleDependency GraphFailure IntelligenceCode CoverageTest DataLocal App HostingVS Code ExtensionJetBrains PluginDev UIDebuggerWatch ModeDaemonLanguage ServerMutation TestingBenchmarkingAnalytics & TracesHeadless 360
Apex CoverageFlow TestingGovernor LimitsManaged PackagesWhy PostgreSQLWhy Source-DrivenAI & Agentic
Setup & OpsConfigurationCI/CD IntegrationDoctorLocal ServerSecurity
CommunitySlackGitHubSupport
ImpressumPrivacyTermsWithdrawalDPASubprocessorsEULA

© 2026 Nimbus Solutions. All rights reserved.