Compliance
This Data Processing Agreement ("DPA") forms part of the Nimbus Terms of Service and applies to the processing of personal data by Nimbus ("Processor") on behalf of any customer ("Controller") using the Nimbus service. By using Nimbus, the Controller agrees to this DPA. Customers requiring a counter-signed copy may request one at privacy@testnimbus.dev.
Terms used in this DPA have the meanings given in Article 4 of the EU General Data Protection Regulation 2016/679 ("GDPR"). "Personal Data" means data submitted by Controller or its end users to Nimbus in the course of using the service.
Subject matter: Provision of the Nimbus local Apex runtime service, including authentication, license issuance, billing, and customer support.
Duration: For as long as Controller maintains an active account, plus retention periods required by law (see Section 9).
Nimbus processes Personal Data solely to provide and improve the service. Specifically:
Nimbus shall:
Controller hereby grants Nimbus general written authorization to engage subprocessors. Nimbus maintains a current list of subprocessors at /subprocessors and will notify Controller at least 30 days in advance of changes. Controller may object to a new subprocessor by giving written notice within that period; if the parties cannot resolve the objection, Controller may terminate this DPA and the related service for that subprocessor's portion of processing.
Each subprocessor is bound by data protection obligations no less protective than those set out in this DPA.
Nimbus primarily processes Personal Data within the European Economic Area. Where transfers to third countries are necessary (e.g. via subprocessors in the United States), they are governed by the EU Standard Contractual Clauses (SCCs) Module Two (Controller-to-Processor) or equivalent transfer mechanisms. See the subprocessors page for current arrangements.
Nimbus enables Controllers and end users to exercise their rights under Articles 15–22 GDPR directly through the service:
Personal Data is retained only as long as necessary for the purposes set out above. Specific retention periods:
Upon termination of this DPA, Nimbus will delete or return all Personal Data (Controller's choice), subject to retention periods required by applicable law.
This DPA enters into force when Controller starts using the service and terminates with the underlying service agreement. Liability under this DPA is governed by the limitation of liability provisions in the Nimbus Terms of Service.
This DPA is governed by the laws of Germany. Disputes shall be resolved by the competent courts of Germany unless otherwise required by mandatory consumer protection law in the Controller's country of residence.
For all matters relating to this DPA or data protection in general, contact privacy@testnimbus.dev. Full company details are on the Impressum.
Note: This is the standard published DPA. Enterprise customers requiring a counter-signed version, additional warranties, or specific TOMs attestations may contact us — we offer a signed DPA without modification of substantive terms, plus optional addenda for specific industries.