Version 1.0 · Last updated July 2026
This Data Processing Addendum (this “DPA”) supplements the nova8 Cloud Platform Terms of Service and/or the nova8OS End-User License Agreement (as applicable, the “Agreement”) between nova8 Technologies LLC (“NOVA8”) and Customer. It is incorporated into and forms part of the Agreement and applies automatically to NOVA8’s processing of personal data in connection with the Services; no separate signature is required. Capitalized terms not defined here have the meanings given in the Agreement or in applicable data protection law.
1.1 Categories of Personal Data and Roles. In connection with the Services, NOVA8 processes two categories of personal data: (a) Account Data: the names, business-contact details, and credentials of Customer’s personnel used to create accounts, authenticate users, administer the Cloud Platform, bill, and secure and operate the Services; NOVA8 processes Account Data as an independent controller for those purposes, as described in its Privacy Policy; and (b) Customer Content: data that Customer or its Devices submit to the Cloud Platform, including device telemetry, configuration, and fleet-operations data; to the extent Customer Content contains personal data, NOVA8 processes it as Customer’s processor (or subprocessor) on Customer’s documented instructions.
1.2 Data Minimization. The Services are designed for device, fleet, and operational management and are not intended as a repository for personal data. Customer shall not submit special categories of personal data, protected health information, payment card data, or other high-risk regulated data as Customer Content, and shall minimize the personal data contained in Customer Content.
1.3 Subject Matter and Details. The subject matter and duration of processing are the term of the Agreement; the nature and purpose are the provision, security, and operation of the Services; the types of personal data and categories of data subjects are those described in Section 1.1 and, for any additional Customer Content, as determined and controlled by Customer.
2.1 To the extent NOVA8 processes personal data on Customer’s behalf, NOVA8 shall: (a) process such personal data only on Customer’s documented instructions, including as set out in the Agreement, unless required by law; (b) ensure that persons authorized to process the personal data are bound by confidentiality; (c) implement commercially reasonable technical and organizational measures appropriate to the risk; (d) assist Customer, taking into account the nature of processing and information available to NOVA8, with its obligations regarding security, data-subject requests, and regulator inquiries, at Customer’s reasonable expense; and (e) at Customer’s choice, delete or return personal data at the end of the applicable services, except where retention is required by law.
3.1 Customer is solely responsible for the lawfulness of any personal data it submits and for providing all required notices and obtaining all required consents. Customer shall not submit special categories of personal data, protected health information, payment card data, or other high-risk or regulated data to the Services unless expressly agreed in writing by NOVA8, and Customer shall minimize any personal data submitted to the Services.
4.1 Customer authorizes NOVA8 to engage subprocessors to support delivery of the Services. NOVA8 currently uses DigitalOcean, LLC to provide cloud hosting infrastructure for the Cloud Platform in the United States (San Francisco, California region). NOVA8 will make available its current list of subprocessors and hosting locations upon written request. NOVA8 shall impose data protection obligations on subprocessors substantially similar to those in this DPA and remains responsible for their performance. NOVA8 will provide a mechanism to notify Customer of new subprocessors and a reasonable opportunity to object on legitimate data protection grounds.
5.1 NOVA8 shall maintain the security measures described in the Agreement. If NOVA8 becomes aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data processed on Customer’s behalf, NOVA8 shall notify Customer without undue delay and in any event within seventy-two (72) hours of confirmation, and provide information reasonably available to NOVA8 to assist Customer in meeting its own notification obligations. NOVA8’s notification is not an acknowledgment of fault or liability.
6.1 The Cloud Platform is hosted in the United States (San Francisco, California). Customer is responsible for ensuring that any transfer of personal data to the United States in connection with its use of the Services complies with applicable law. To the extent personal data originating from a jurisdiction with cross-border transfer restrictions is processed, the Parties shall cooperate to put in place an appropriate transfer mechanism (for example, applicable standard contractual clauses), which are incorporated by reference to the extent required.
7.1 Each Party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, and this DPA does not increase or expand those limits. This DPA is governed by the laws of the State of Wyoming, consistent with the Agreement, except where mandatory data protection law requires otherwise. In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls to the extent of such processing.