This Data Processing Addendum ("DPA") forms part of the Terms of Service between Nomli (operated by AALA Solutions) and the Customer, and governs the processing of personal data that Nomli handles on the Customer's behalf in the course of providing the Service.
1. Roles
For diner and end-customer data captured through the Customer's storefront, apps, and POS (orders, contact details, delivery addresses, loyalty activity), the Customer is the controller and Nomli is the processor. For data Nomli collects to operate its own business (tenant accounts, billing records, support correspondence), Nomli is the controller as described in the privacy policy.
2. Processing instructions
Nomli processes Customer personal data only to provide, maintain, and secure the Service, to comply with law, and as otherwise documented in written instructions from the Customer. The subject matter, duration, nature, and purpose of processing, and the categories of data subjects and personal data, follow from the Service description in the Terms.
3. Security measures
Nomli applies the technical and organisational measures described on the security page, including tenant isolation, encryption in transit, hashed credentials, encrypted off-site backups, and access controls.
4. Sub-processors
The Customer authorises the sub-processors listed in the privacy policy. Nomli will give at least 30 days' notice before adding a sub-processor, during which the Customer may object on reasonable data-protection grounds.
5. Data subject requests and breach notice
Nomli will forward data subject requests it receives that concern the Customer's diners, and will provide reasonable assistance in responding. Nomli will notify the Customer of a personal data breach affecting Customer personal data without undue delay after becoming aware of it.
6. Deletion and return
On termination of the Terms, Customer Data remains available for export for 30 days, after which Nomli deletes it from live systems and lets encrypted backups expire on their rolling schedule, retaining only what law requires.
7. Transfers
Default storage is in the EU. Where personal data is transferred to a jurisdiction requiring additional safeguards, the parties rely on standard contractual clauses or the equivalent mechanism applicable in the Customer's jurisdiction.
8. Contact
Questions about this DPA: privacy@nomli.co.