Version 1.0 · Effective 1st Oct 2026 · SHA-256 of canonical text: 8ffa0edff884c53655ea138583d4e615f54513e71b43933b2f091b5520fab4ef

1. Introduction and Entry into Force

1.1 This Data Processing Addendum (“DPA”) forms part of the agreement between NOMYO LLC, 2810 N Church St, PMB 947236 Wilmington, DE 19802-4447 USA, (“NOMYO”) and the customer identified in that agreement (“Customer”) for NOMYO’s services (the “Agreement”). The Agreement is either the Terms of Service accepted by Customer or a Master Services Agreement signed by both parties.

1.2 This DPA takes effect when Customer accepts the Terms of Service, or when Customer and NOMYO sign an order form or Master Services Agreement that references it, whichever occurs first. Electronic acceptance satisfies the written-form requirement of GDPR Article 28(9).

1.3 On matters of data protection, this DPA prevails over the Agreement. Where Standard Contractual Clauses apply under Section 14, they prevail over this DPA to the extent of any conflict.

1.4 A countersigned copy of this DPA is available on request. The countersigned copy identifies the version and content hash of the text signed, and the signed text controls in case of any discrepancy with the published page.

2. Definitions

2.1 “GDPR” means Regulation (EU) 2016/679, and includes the UK GDPR where Customer is established in the United Kingdom. “Controller”, “processor”, “data subject”, “personal data”, “personal data breach”, “processing”, and “supervisory authority” have the meanings given in GDPR.

2.2 “Customer Content”, “Service Metadata”, “Account Data”, “Encrypted Inference”, “Assistant”, “aissurance”, and “Subprocessor” have the meanings given in the Data Handling Commitments (the “Commitments”).

2.3 “Customer Personal Data” means personal data contained in Customer Content, Service Metadata, Assistant conversations, or aissurance data that NOMYO processes on Customer’s behalf under the Agreement.

2.4 “Standard Contractual Clauses” or “SCCs” means the clauses adopted by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), and where applicable the UK International Data Transfer Addendum issued by the UK Information Commissioner.

3. Roles

3.1 Customer is the controller of Customer Personal Data, or acts as processor on behalf of its own customers who are the controllers. NOMYO is Customer’s processor.

3.2 NOMYO is an independent controller of Account Data, which it processes as described in the Privacy Policy. Account Data is outside this DPA.

4. Customer Obligations

4.1 Customer is responsible for the lawfulness of Customer Personal Data and of its instructions, including having a legal basis for processing and providing any notices to data subjects that the law requires.

4.2 Customer will not submit special-category personal data within the meaning of GDPR Article 9, or protected health information within the meaning of HIPAA, unless a written addendum covering that data is in place. NOMYO does not currently offer a HIPAA Business Associate Agreement.

4.3 Customer will comply with the responsibilities in Commitments Section 4.5 when using Encrypted Inference, and acknowledges that the guarantee in Commitments Section 4.2 depends on it doing so.

4.4 Customer acknowledges that when it or its users select a Remote Model in the Assistant or the Chat Router, the request is processed in plaintext by the Remote Model provider listed in the Subprocessor List, as described in Commitments Sections 6 and 7, and that Customer may restrict its use to Local Models to avoid this.

5. Processing on Instructions

5.1 NOMYO processes Customer Personal Data only on Customer’s documented instructions. The Agreement, this DPA, and Customer’s use of the services constitute the complete instructions. Additional instructions require written agreement.

5.2 NOMYO does not process Customer Personal Data for any purpose of its own. In particular, NOMYO does not use Customer Personal Data to train, fine-tune, evaluate, or improve any model, as set out in Commitments Section 11.

5.3 If NOMYO believes an instruction infringes GDPR or other applicable data protection law, it will inform Customer promptly and may suspend the affected processing until the instruction is confirmed or withdrawn.

5.4 If NOMYO is required by law to process Customer Personal Data otherwise than on Customer’s instructions, it will inform Customer of that requirement before processing, unless the law prohibits it. Under Encrypted Inference, NOMYO holds no Customer Content and therefore cannot produce it.

6. Confidentiality

NOMYO ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality, and processes it only as this DPA permits.

7. Security

7.1 NOMYO implements the technical and organisational measures described in the version of the Commitments identified in Annex II, which the parties agree are appropriate to the risk, taking into account the state of the art and the nature of the data.

7.2 NOMYO may publish new versions of the Commitments. A new version applies to this DPA automatically only if it does not reduce the level of protection provided by the version in Annex II. Any change that would reduce that level is treated as a Subprocessor change under Section 8, with the same notice and objection rights.

8. Subprocessors

8.1 Customer gives general written authorisation for NOMYO to engage the Subprocessors listed in the Subprocessor List identified in Annex III.

8.2 NOMYO gives Customer at least 30 days’ notice before adding or replacing a Subprocessor, by updating the Subprocessor List and emailing Customer’s registered contact.

8.3 Customer may object in writing within that period on reasonable data protection grounds. If the parties cannot resolve the objection within 30 days, Customer may terminate the affected service without penalty and receive a pro-rated refund of any prepaid fees for the remaining term.

8.4 NOMYO imposes on each Subprocessor data protection obligations no less protective than those in this DPA, and remains liable to Customer for the Subprocessor’s performance.

8.5 Remote Model providers under Commitments Sections 6 and 7 are engaged only when Customer or its users select a model they serve. That selection is Customer’s instruction to engage the provider for that request.

9. Data Subject Rights

9.1 NOMYO assists Customer, by appropriate technical and organisational measures and insofar as possible, in responding to requests by data subjects to exercise their rights.

9.2 If NOMYO receives a request directly from a data subject, it will forward it to Customer without undue delay and will not respond except to direct the data subject to Customer, unless the law requires otherwise.

9.3 Customer acknowledges that under Encrypted Inference NOMYO holds no Customer Content and under the Chat Router it retains none by policy, so in both cases it cannot access, correct, or produce it; requests concerning that content are fulfilled by Customer from its own systems. NOMYO’s assistance extends to Service Metadata, Assistant conversations, and aissurance data.

10. Assistance with Compliance

NOMYO assists Customer in meeting its obligations under GDPR Articles 32 to 36, taking into account the nature of the processing and the information available to NOMYO. This includes providing the information in the Commitments and answering reasonable written requests in support of a data protection impact assessment. NOMYO may charge reasonable fees for assistance that exceeds what the Commitments already provide.

11. Personal Data Breach

11.1 NOMYO notifies Customer of a personal data breach affecting Customer Personal Data without undue delay.

11.2 The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. NOMYO provides further information as it becomes available.

11.3 Customer acknowledges that under Encrypted Inference a breach of NOMYO’s systems cannot expose Customer Content, as described in Commitments Section 15.

12. Deletion and Return

12.1 On termination or expiry of the Agreement, NOMYO deletes Customer Personal Data within the periods set out in Commitments Section 14, unless the law requires retention, in which case NOMYO retains only what the law requires and continues to protect it under this DPA.

12.2 Before deletion, Customer may export Assistant conversations and aissurance data using the export functions of those services, or may request an export in a commonly used format.

12.3 NOMYO confirms deletion in writing on request.

13. Audit

13.1 NOMYO makes available the information necessary to demonstrate compliance with this DPA. The Commitments, the Subprocessor List, and the hardware attestation delivered with every maximum-tier response are the primary evidence.

13.2 On request, and no more than once in any twelve-month period unless a supervisory authority requires otherwise or a personal data breach has occurred, NOMYO answers a written security questionnaire.

13.3 Customer, or an independent auditor it appoints who is bound by confidentiality, may audit NOMYO’s compliance on site at the Hosting Facility on at least 30 days’ written notice, during normal business hours, no more than once in any twelve-month period unless a supervisory authority requires otherwise or a personal data breach has occurred, and subject to reasonable confidentiality and safety conditions. Customer bears its own costs and reimburses NOMYO’s reasonable costs for audits exceeding two business days.

14. International Transfers

14.1 Customer Personal Data is hosted and processed at the Hosting Facility in Germany, operated by the Hosting Entity identified in Annex III, and, under Encrypted Inference, is never accessible from outside it.

14.2 NOMYO LLC is established in the United States. To the extent that NOMYO LLC personnel in the United States access Service Metadata, Assistant conversations, that access is a transfer to a third country, and the parties enter into the SCCs, Module Two, which are incorporated by reference. For the purposes of the SCCs: Customer is the data exporter; NOMYO LLC is the data importer; Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) applies with the notice period in Section 8.2; Clause 11 optional language does not apply; Clause 13 applies as determined by Customer’s establishment; Clause 17 option 1 & Clause 18 applies with the courts of US; Annex I of the SCCs is Annex I of this DPA; Annex II of the SCCs is Annex II of this DPA; Annex III of the SCCs is Annex III of this DPA.

14.3 Where Customer is established in the United Kingdom, the UK International Data Transfer Addendum applies to the SCCs, with the parties’ details as in Annex I and the option to end the Addendum when the ICO issues a revised version available to both parties.

14.4 Transfers to a Remote Model provider under Commitments Sections 6 and 7 rely on the transfer mechanism stated for that provider in the Subprocessor List.

14.5 If a transfer mechanism relied on under this Section becomes invalid, the parties will cooperate in good faith to implement an alternative, and NOMYO will suspend the affected transfers until one is in place.

15. Liability

15.1 Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement.

15.2 Nothing in this DPA limits either party’s liability to data subjects under GDPR Article 82.

16. Term and Survival

This DPA remains in force for as long as NOMYO processes Customer Personal Data under the Agreement. Sections 6, 12, and 15 survive termination.

17. Governing Law

This DPA is governed by the law governing the Agreement, except that the SCCs are governed by the law stated in Section 14.2, and except to the extent that the mandatory data protection law of the country in which Customer is established requires otherwise.


Annex I: Description of Processing

A. List of parties

Data exporter (Customer) Data importer (NOMYO)
Name The entity that accepted the Agreement NOMYO LLC
Address As stated in the Agreement or Customer’s account 2810 N Church St, PMB 947236 Wilmington, DE 19802-4447 USA
Contact Customer’s registered contact ichi@nomyo.ai
Activities relevant to the transfer Use of NOMYO services under the Agreement Provision of NOMYO services
Role Controller (or processor on behalf of its own controllers) Processor

B. Description of the processing

Element Description
Subject matter Provision of the NOMYO services selected by Customer under the Agreement
Duration The term of the Agreement plus the deletion periods in Commitments Section 14
Nature of the processing As described in the Commitments for each product Customer uses: Section 4 (Encrypted Inference), Sections 5 and 6 (Assistant), Section 7 (Chat Router), Section 9 (aissurance). Under Encrypted Inference, NOMYO processes content it cannot read and retains only Service Metadata.
Purpose of the processing Providing the services on Customer’s instructions; no other purpose
Categories of data subjects As determined by Customer’s use of the services. Typically Customer’s employees, contractors, customers, and end users, and other persons whose data Customer submits
Categories of personal data As determined by Customer’s use of the services. Under Encrypted Inference NOMYO cannot know the categories because it cannot read the content. Service Metadata contains account identifiers and IP addresses only
Sensitive data None, unless a written addendum applies. Customer warrants under Section 4.2 that it will not submit special-category data or protected health information otherwise
Frequency of the transfer Continuous for the term of the Agreement
Retention period As set out in Commitments Section 10 (Service Metadata), Sections 5 and 6 (Assistant), Section 9 (aissurance), and Section 14 (deletion)
Transfers to Subprocessors As set out in Annex III, for the purpose, nature, and duration stated there

C. Competent supervisory authority

The supervisory authority of the EU member state in which Customer is established, or, where Customer is not established in the EU, the authority determined under SCC Clause 13.

For an engagement under a Master Services Agreement, a completed Annex I specific to that engagement may replace this Annex I by reference in the order form.

Annex II: Technical and Organisational Measures

The Data Handling Commitments, version 1.0, effective 1st Oct 2026, SHA-256 04ab85adfc974939b3a92070dcea58921ffb722396339bca4ede4b1df83a6b7d, Sections 3 to 16.

Annex III: Subprocessors

The Subprocessor List, version 1.0, effective 1st Oct 2026.


Version History

Version Effective Change
1.0 1st Oct 2026 Initial release