Nproc

Data Processing Addendum

This Data Processing Addendum (this "DPA") is incorporated into and forms part of the Terms of Service (the "Terms") for Nproc (the "Service") provided by TR-55 Inc. (the "Company", "we", or "us").

This DPA applies where you use the Service on behalf of an organization (meaning a corporation or any other body, whether or not it has legal personality). In that case, that organization is referred to as the "Customer".

Capitalized terms used but not defined in this DPA have the meaning given to them in the Terms.

If there is any conflict between this DPA and the Terms, this DPA governs with respect to the processing of personal data.

1. Definitions

"Personal data", "processing", "data subject", "controller", "processor", "subprocessor", and "supervisory authority" have the meanings given in Article 4 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"). Under other applicable laws (the UK GDPR; the California Consumer Privacy Act of 2018, Civil Code section 1798.100 et seq., including as amended by the California Privacy Rights Act of 2020 (CPRA), the "CCPA"; Japan's Act on the Protection of Personal Information (the "APPI"); and Canada's Personal Information Protection and Electronic Documents Act), the equivalent definitions under those laws apply.

2. Relationship of the Parties

This DPA governs our processing of Customer personal data on the Customer's behalf in connection with the provision of the Service. We and the Customer confirm the following split.

Workspace Layer data: the issues, documents, canvases, comments, and other content created within the Customer's workspaces by the Customer or by users the Customer has authorized. The Customer is the controller and we are the processor. This DPA covers this layer.

Account Layer data: individual user profiles, authentication records, login session history, team-membership records, the audit records, server logs, and records of usage and security monitoring that we create and keep in operating the Service, and the Customer's billing data. We are the controller and this DPA does not cover this layer. That data is handled in accordance with our Privacy Policy. We create and maintain the audit records described in section 5 as our own security measure.

The Customer represents and warrants that it has a lawful basis for disclosing Workspace Layer data to us and for instructing us to process it, and that its instructions under this DPA do not violate applicable law. Each party will comply with its respective obligations under applicable data protection laws.

3. Scope and Purposes of Processing

The Customer discloses Customer personal data to us only for the purposes listed below, and we process Customer personal data only for those purposes.

Within the scope of the purposes above, we process Customer personal data in accordance with the Customer's documented instructions (including instructions given through the Customer's configuration of the Service). Where processing is required by applicable law, we will inform the Customer of that legal requirement before processing, unless the law prohibits us from doing so.

We do not sell Customer personal data and do not share it with third parties.

We will immediately inform the Customer if, in our opinion, an instruction from the Customer infringes applicable law.

Categories of data subjects: the users the Customer has authorized (including employees, contractors, and guests) and individuals referred to in content created by the Customer.

Categories of personal data: content created by the users the Customer has authorized, the names and contact details of individuals referred to in that content, and identifiers indicating the author of and assignee for that content.

Special categories of personal data: we do not request, and do not intentionally collect, special categories of personal data in connection with the use of the Service. Because the content includes free-text fields, however, we cannot rule out the possibility that a user the Customer has authorized enters information of those categories.

Duration of processing: the period during which the Service is provided under the Terms, and any period for which retention is required by applicable law.

4. Subprocessors and Other Vendors

4.1 Subprocessors and Other Vendors

This section lists, for transparency, the vendors we engage to provide the Service, across both layers. The layer is noted per service. For services marked as Workspace Layer, the vendor handles the Customer's personal data on our instructions and is therefore a subprocessor as referred to in this DPA, and the Customer authorizes us to engage it. For services marked as Account Layer, we are the controller, the vendor is not a subprocessor under this DPA, and its processing under that service is governed by our Privacy Policy.

This list was last updated on September 14, 2026.

We enter into a contractual agreement with each vendor listed in this section imposing data protection obligations that are substantially as protective as our obligations under this DPA, to the extent applicable to the nature of the services provided by that vendor, and we remain responsible for the acts and omissions of those vendors. This list forms part of this DPA. If we change this list, we will follow the procedure in section 4.2 and publish the updated list on this page.

A note on Stripe's role: Stripe as listed above is a vendor that processes, on our instructions, billing data for which we are the controller. Separately, to the extent Stripe uses personal data for its own purposes (selecting banking and payment method providers; monitoring, preventing, and detecting fraudulent transactions; mitigating loss, security risks, and harm; processing billing and relationship management; complying with anti-money-laundering and other legal obligations; and analyzing, improving, and developing its own products and services), Stripe acts as an independent controller and is not subject to the subprocessor obligations in this DPA. That processing is governed by Stripe's own privacy policy and data processing agreement.

4.2 Adding and Changing Vendors

The Customer agrees that, to the extent necessary to provide, improve, or operate the Service, we may add a vendor listed in section 4.1, replace such a vendor, or materially expand the scope of processing carried out by an existing vendor (for subprocessors, this constitutes the general written authorisation referred to in Article 28(2) of the GDPR). This authorisation and the procedure below apply to all vendors listed in section 4.1, in both layers.

(1) Prior notice
We will notify the Customer at least 30 days before the effective date of any addition, replacement, or material expansion of scope, by notice within the Service or to the registered email address. Where 30 days' prior notice is not practicable for urgent security or business continuity reasons, we will give notice promptly afterwards together with the reason.

(2) Objection
The Customer may object to the addition, replacement, or expansion on reasonable data protection grounds by giving us written notice (including by email) within 15 days of receiving our notice. If no objection is made within that period, the Customer is deemed not to have objected to that addition, replacement, or expansion.

(3) Handling of an objection
If we receive an objection, we and the Customer will discuss the matter in good faith to find a mutually acceptable resolution.

(4) Equivalent obligations on vendors
We will impose by contract, on any vendor resulting from an addition, replacement, or expansion, data protection obligations no less protective than those set out in this DPA.

4.3 Use of AI Services

The Service has no built-in AI features, and we do not engage AI model providers as subprocessors. There are two routes involving external AI tools, and neither creates a subprocessor relationship between us and an AI model provider.

(a) Connections made by the Customer. The Customer may, at its own discretion, connect an AI assistant that the Customer has contracted for to our API. That use is governed by the agreement between the Customer and that AI service provider. We do not use any data accessed through that route to train AI models.

(b) Fault investigation, availability monitoring, and usage analysis by our administrators. Our administrators may use AI tools to access our internal administrative tooling. That tooling is designed so that only pseudonymized identifiers and structured operational information can be read through a read-only path. The purpose of that AI tool use is limited to fault investigation, availability monitoring, and analysis of usage of the Service; we do not use it for sales, marketing, or AI model training. Free-text portions of Customer-created content (issue bodies, document bodies, note bodies, comments, the various names, table cell values, and similar) are excluded from that path regardless of whether the caller is an AI tool or one of our administrators.

However, the operational information that can be read includes error information, which may contain free text. Before sending data to an AI tool, we replace strings matching URLs, email addresses, authentication credentials, and IP addresses by pattern matching, and we truncate to a fixed number of leading characters. This replacement is a partial measure and does not guarantee the removal of strings that do not match those patterns, such as a person's name that has been included in the body of an error message.

No use for AI model training. Regardless of which route is involved, we do not use Customer personal data or Customer content to train, fine-tune, or distil AI models or to build evaluation datasets, and we do not provide it to any third party for the purpose of that third party training AI models.

5. Security Measures

We implement and maintain appropriate technical and organizational measures to protect Customer personal data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, and disclosure. Those measures include the following.

We may update these measures from time to time, provided that no update materially reduces the overall security of the Service.

6. Confidentiality

We limit the persons authorized to access Customer personal data to those who need that access to perform their work. We impose a duty of confidentiality on those persons or confirm that they are under a statutory duty of confidentiality. That duty survives the end of their employment or engagement.

7. Data Subject Rights

If we receive a request directly from a data subject relating to Customer personal data, we will not respond to it ourselves, except where we are required by law to do so, and we will promptly notify the Customer.

Taking into account the nature of the processing, we will provide the Customer with reasonable assistance, by appropriate technical and organizational measures, so that the Customer can fulfil its obligation to respond to data subject requests for access, rectification, erasure, restriction of processing, data portability, and objection.

8. Personal Data Breach Notification

Where we become aware of a personal data breach affecting Customer personal data, we will notify the Customer without undue delay. That notification will include, to the extent known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the mitigation measures taken or proposed.

We will provide the Customer with information that becomes available after that notification without undue delay.

9. Data Protection Impact Assessments

Taking into account the nature of the processing and the information available to us, we will provide the Customer with reasonable assistance so that the Customer can fulfil its obligation to carry out data protection impact assessments and to consult supervisory authorities in advance.

10. International Transfers

In operating the Service, personal data may be transferred outside Japan and processed there. Depending on the type of data, the actual processing locations span Japan and the United States (the Cloudflare D1 and storage services), the Cloudflare global edge network (Durable Objects and similar), and the Asia Pacific region (internal audit records). We carry out transfers subject to the following safeguards.

A copy of the safeguards is available on request. Where a data subject asks us for information about the framework for provision from Japan to a third party located in a foreign country, we respond ourselves, in both layers, as set out in our Privacy Policy, because it is we who provide the data to the third party located in a foreign country. The referral procedure in section 7 does not apply to that request.

Of the transfers described in this section, those concerning Workspace Layer data constitute documented instructions of the Customer, given through this DPA. Transfers concerning Account Layer data are carried out by us as controller and are not based on the Customer's instructions.

11. Audits and Provision of Information

(1) Provision of information
We will make available to the Customer the information necessary to demonstrate compliance with the obligations set out in this DPA. Where we hold a third-party audit report or certification, we may satisfy this obligation by providing that report or certification subject to confidentiality.

(2) Customer audits
The Customer may carry out an audit to verify compliance with the obligations set out in this DPA. The audit is conducted by an auditor that has entered into a confidentiality agreement, and its start date, scope, duration, and security controls are as mutually agreed between us and the Customer. An audit may not be carried out more than once in any 12-month period, unless there are indications of non-compliance or a supervisory authority requires it.

(3) Costs
The Customer bears the costs of an audit, except that we bear the costs of an audit required by law and of an audit arising from a personal data breach.

(4) Use of results
The Customer may use the results of an audit only for the purposes of the Customer's regulatory compliance and of confirming compliance with this DPA.

12. Deletion and Return of Customer Personal Data

In this section, the "end of provision of the Service" means that we cease to provide the Service to the Customer's Team, and includes where the Customer deletes the Team, where, under the Terms, we suspend the Customer's use of the Service or terminate the Customer's registration, or where we discontinue the provision of the Service. Cancellation of the paid plan and other changes of plan are not included, because provision of the Service continues.

(1) Choice
Before the end of provision of the Service, the Customer may choose deletion or return of Workspace Layer data. Where the Customer deletes the Team, that deletion constitutes the Customer's choice of deletion.

(2) Return
The Customer can obtain a copy of the Workspace Layer data in electronic form using the export features of the Service before the end of provision of the Service (where the Customer deletes the Team, before that deletion). Return is effected by this means.

(3) Deletion
The Customer may delete Workspace Layer data using the deletion features of the Service. Where the Customer instructs deletion, we will delete that data within a reasonable period. We do not provide restoration of deleted data.

(4) What remains after deletion
The following remain after deletion under the preceding paragraph.

13. Additional Terms for California, United States

This section applies where the Customer is a "business" as defined in the CCPA. In that case we act as a "service provider" as defined in the CCPA. In this section, "personal information" means personal information as defined in the CCPA.

14. Contact

For questions about this DPA, please contact us at the contact point set out in the Terms.

Effective date: September 14, 2026