Data Processing Agreement
Last updated: May 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and NAND Solutions LLC ("Processor") for use of the NAND Inventory Management System. It applies where the processing of personal data is subject to the EU General Data Protection Regulation (GDPR) or equivalent data protection laws.
This DPA is incorporated by reference into the Terms of Service. By using the service, you agree to this DPA. If you require a signed DPA for your compliance documentation, email privacy@nandsolutions.com and we'll send a countersigned copy within 5 business days.
1. Scope
This DPA governs NAND Solutions' processing of personal data on your behalf in connection with the IMS service. "Personal data" means any information relating to an identified or identifiable natural person that you store or process via the service — typically employee names, vendor contacts, and user account details associated with your inventory operations.
2. Roles
You are the Controller. You determine what personal data is entered into the IMS, for what purpose, and you're responsible for ensuring you have a lawful basis for any personal data you process.
NAND Solutions is the Processor. We process personal data only as directed by you — to operate the service. We do not use your data for our own purposes, to train models, or to share with third parties beyond what's necessary to run the service.
3. Processing instructions
We process personal data only on your documented instructions. Your use of the service (including configuration choices and data inputs) constitutes such instructions.
If we're required by law to process data beyond your instructions, we'll notify you unless prohibited from doing so. If we believe an instruction violates applicable law, we'll notify you promptly.
4. Sub-processors
We use a limited number of sub-processors to deliver the service. The current list is maintained at /trust/sub-processors. By agreeing to this DPA, you provide general authorization for us to engage sub-processors, subject to the conditions in this section.
We will notify you of any intended additions or replacements to our sub-processor list at least 30 days before the change takes effect. If you object, you may terminate the service before the change takes effect. All sub-processors are bound by contractual obligations at least as protective as this DPA.
5. Security measures
We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure. Current measures include AES-256 encryption at rest, TLS 1.3 in transit, role-based access control with row-level security, daily encrypted backups, and comprehensive audit logging. A detailed description is available at /trust/security.
6. Data subject rights
As Controller, you're responsible for responding to data subject requests (access, correction, deletion, portability). We'll assist you in fulfilling these requests as required by applicable law. Most requests can be fulfilled through the IMS admin portal. For requests requiring our direct involvement, contact privacy@nandsolutions.com. We'll respond within 72 hours.
7. International transfers
Our primary infrastructure is hosted in the United States. If you're located in the EU or UK and require data to remain in-region, contact us — we can discuss configuration options. Where personal data is transferred from the EU/UK to the US, we rely on Standard Contractual Clauses (SCCs) as the legal transfer mechanism. Contact privacy@nandsolutions.com to request a copy of the applicable SCCs.