Skip to content

Terms & Policies

EU GDPR P2P Data Processing Addendum

Independent Software Vendors - Nitro Sign Enterprise Verified & Identity Services

Effective: September 18, 2025

FOR INDEPENDENT SOFTWARE VENDORS (“ISV” or “Processor”)

THIS DATA PROCESSING ADDENDUM APPLIES IF YOU HAVE SIGNED UP FOR PROVIDING NITRO SERVICES AS AN ISV UNDER AN INDEPENDENT SOFTWARE VENDOR AGREEMENT (AS DEFINED IN SECTION 2 BELOW).

1. SCOPE; ROLES OF THE PARTIES

Nitro will receive and process Personal Data on behalf of the ISV when providing the Services, according to the instructions and purposes defined in the Data Processing Details. By means of this Data Processing Addendum, Parties wish to lay down their specific agreements in respect to processing Personal Data within the framework of the Agreement.

By default, Nitro shall act as a Sub-Processor and the ISV shall act as a Processor in respect of the Services provided by Nitro to the ISV. Nitro acknowledges that the ISV acts on behalf of the Controller for the processing of Personal Data. This Data Processing Addendum supersedes and replaces all previous agreements made (if any) in respect of processing Personal Data and data protection between the Parties related to the Services offered by Nitro under the Agreement.

This Data Processing Addendum supplements and forms part of the Agreement, and together the Agreement and this Data Processing Addendum constitute a single legal agreement between the Parties. In case of discrepancies or contradictions between this Data Processing Addendum and the Agreement, the Data Processing Addendum will prevail.

2. DEFINITIONS

“Agreement” means the Independent Software Vendor Agreement, any Schedules attached thereto, the Nitro ISV Order Form(s) and any information incorporated by reference herein from the Nitro Partner Portal (if applicable); 

“Annex” means any annex to the present Data Processing Addendum;

“Controller” means the customer of the Processor (which is considered to be the End Customer in relation to the Agreement) to which the Processor (i.e. the ISV) provides the Integrated Solution (which includes Services provided by Nitro to the Processor);

“Data Processing Details” means Annex 1 to the present Data Processing Addendum which includes more details on the Controller’s instructions on the processing of Personal Data, conveyed by the Processor to Nitro, such as the purpose, object and nature of processing and the kind of Personal Data being processed;

“EU GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);

“Nitro sub-processor List” refers to the list of Nitro sub-processors as made available online by Nitro that includes the Nitro sub-processors engaged by Nitro for the provisioning of the Services and the fulfillment of Nitro’s obligations under the Agreement in general. Nitro may update the Sub-processor List from time to time as per the process set out in this Data Processing Addendum;

“Nitro sub-processor” means any third party processor engaged by Nitro for the processing of Personal Data related to the provisioning of the Services to the Processor;

“Personal Data” means personal data as defined under EU GDPR that Nitro processes on behalf of the Processor when providing the Services according to the instructions and purpose defined in the Data Processing Details;

“Processor” refers to the ISV as identified in the Agreement and/or the corresponding Nitro ISV Order Form;

“Sub-Processor” means Nitro Software Belgium NV, supplier of Services to the Processor;

All other terms and definitions written with capital letters and which are not defined expressly in this Data Processing Addendum, are defined as set out in the applicable data protection legislation or the Agreement.


3. OBJECT OF THIS DATA PROCESSING ADDENDUM

3.1  This Data Processing Addendum determines the conditions of the processing by Nitro of Personal Data on behalf of the Processor in the context of the Agreement. The nature and purpose of the processing, a list and the kind of Personal Data as well as the categories of the Data Subjects are listed in the Data Processing Details (Annex 1).

3.2  The processing will take place on behalf of the Processor who acts on behalf of the Controller and for the purposes defined in the Data Processing Details. Nitro shall immediately inform the Processor if, in its opinion, an instruction infringes the applicable (data protection) legislation. Nitro will only process the Personal Data according to the documented instructions of the Controller, conveyed to Nitro by the Processor, as set out in this Data Processing Addendum and will not use these Personal Data for its own purpose, unless as explicitly permitted in the Terms of Service. If Nitro is legally obliged to proceed with any processing of Personal Data, Nitro will, unless this would violate applicable mandatory rules, inform the Processor of such obligation. The Processor may transmit such information to the Controller.

3.3  The Processor warrants that this Data Processing Addendum reflects the arrangements between the Processor and the Controller and the Processor also warrants on an ongoing basis that the Controller has authorized the Processor's engagement of Nitro as a Sub-Processor and Nitro's engagement of Nitro sub-processors as described in Section 10.


4.  TERM

4.1  This Data Processing Addendum is applicable to all processing of Personal Data executed in the context of the provisioning of the Services to the Processor by Nitro and applies as long as Nitro processes Personal Data on behalf of the Processor in the context of the Agreement. This Data Processing Addendum supplements the Agreement and is meant to ensure the Parties’ compliance with the requirements imposed by the applicable data protection laws and regulations.

4.2  This Data Processing Addendum ends automatically upon termination of the Agreement (or at the moment the processing by Nitro is terminated). The provisions of this Data Processing Addendum that are either expressly or implicitly (given their nature) intended to have effect after termination of the Data Processing Addendum shall survive the end of the Agreement with regard to the Personal Data processed on behalf of the Processor in the context of the Agreement.

5. TECHNICAL AND ORGANIZATIONAL MEASURES

5.1  Nitro offers adequate guarantees with regard to the implementation of appropriate technical and organizational measures (“TOMs”) to ensure secure processing of Personal Data and so the protection of the Data Subject's rights is guaranteed. The TOMs implemented by Nitro are set out in the Data Processing Details. The TOMs may be updated by Nitro from time to time, however Nitro will ensure not to downgrade the overall security it has implemented at the moment of the Data Processing Addendum’s execution. The Processor acknowledges the TOMs to be providing an adequate level of security appropriate to the risk for the processing of Personal Data on behalf of the Processor at the moment of signing or accepting this Data Processing Addendum.

5.2  Nitro shall take all appropriate technical and organizational measures as referred to in article 32 EU GDPR to ensure an adequate level of security appropriate to the risk.

5.3  If Nitro would be required to process sensitive Personal Data as referred to in articles 9 and 10 EU GDPR in the context of the Agreement, the Processor will notify Nitro thereof in writing via privacy@gonitro.com.

5.4  In case the Processor (or the Controller) is requesting specific technical and organizational measures to be implemented by Nitro (which Nitro has not implemented by default), the Processor will reimburse Nitro for implementing such additional measures according to Section 14 “Costs” of this Data Processing Addendum.

5.5  Adherence by Nitro to an approved code of conduct as referred to in article 40 EU GDPR, or an approved certification mechanism as referred to in article 42 EU GDPR may be used as an element of proof of sufficient guarantees as referred to in EU GDPR.


6. RETENTION

6.1  Nitro will not keep Personal Data any longer than required for processing of such Personal Data in the context of the Agreement. The Processor will not instruct Nitro to store any Personal Data longer than necessary. The applicable retention period is set out in the Data Processing Details.

6.2  At the choice of the Processor, Nitro shall delete or return all Personal Data to the Processor after the end of the provisioning of Services and shall delete existing copies unless Union or Member State law requires storage of the Personal Data, which may then be transmitted to the Controller by the Processor. The Processor acknowledges the Services might include download functionalities at the disposal of the Controller to enable Controller to download its data. To the extent such functionalities are available, the Processor shall ensure that the Controller uses such functionalities to extract or delete its data.

7. CONFIDENTIALITY

7.1  Parties have agreed on a confidentiality clause in the Agreement which applies to the processing of Personal Data in the context of the Agreement.

7.2  Nitro acknowledges and agrees that only those employees, contractors or agents of Nitro who are involved in the processing of Personal Data may be informed about the Personal Data and only to the extent as reasonably necessary for the performance of the Agreement. Nitro ensures that persons authorized to process the Personal Data are committed to confidentiality by contract or are under an appropriate statutory obligation of confidentiality.

8. DATA SUBJECT RIGHTS

8.1  Taking into account the nature of the processing, Nitro shall use all reasonable efforts, by taking appropriate technical and organizational measures, to assist the Controller, at the Processor's request, in the fulfillment of the Controller's obligation to respond to requests from Data Subjects.

8.2  For all assistance performed by Nitro in the context of the treatment of such requests from Data Subjects, the Processor will reimburse Nitro in accordance with Section 14 “Costs” of this Data Processing Addendum. Such reimbursement by the Processor shall not apply (i) in case the Data Subject is invoking its rights because of a Personal Data Breach proven attributable to Nitro or (ii) in case such assistance by Nitro does not exceed four (4) hours of work during the term of the Agreement.

9. DUTY TO NOTIFY

9.1  Upon becoming aware of a Personal Data Breach, Nitro shall notify the Processor thereof without undue delay by contacting the contact person indicated in the Agreement (or alternatively via the Processor's Notification Email Address included in the Nitro ISV Order Form or the email address the Processor has shared in the Nitro Partner Portal). Nitro’s contact person for any data protection related matters can be contacted per email: privacy@gonitro.com.

9.2. At the request of the Processor, Nitro will inform the Processor of any new developments with regard to any Personal Data Breach and of the measures taken to limit its consequences and to prevent the repetition of such Personal Data Breach. It is the responsibility of the Processor to transmit the information received from Nitro to the Controller to enable the Controller to comply with its obligation to report any Personal Data Breach to the Supervisory Authority or the Data Subject(s), as required.

10. SUB-PROCESSING

10.1  The Processor warrants that Nitro is expressly authorized to engage Nitro sub-processors for the processing of Personal Data for the performance of the Agreement and to facilitate the provisioning of the Services in general. To this extent, the Processor grants a general written authorization to Nitro to decide with which Nitro sub-processor(s) Nitro cooperates for the fulfilment of its obligations under the Agreement. Nitro publishes a Nitro sub-processor List referring to the Nitro sub-processors.

10.2  Nitro will inform the Processor of any intended changes concerning the addition or replacement of Nitro sub-processors via the Processor's contact person indicated in the Agreement (or alternatively via the Processor's Notification Email Address included in the Nitro ISV Order Form or the email address the Processor has shared in the Nitro Partner Portal). The Processor will have the right to object to the addition or replacement by addressing Nitro in writing where the Controller would object to such addition or replacement. Parties will in such case discuss the addition, replacement or alternative in good faith and as soon as reasonably possible after the Processor's written notice of objection.

10.3  Where Nitro engages a Nitro sub-processor for carrying out specific processing activities, the same or similar data protection obligations as set out in this Data Processing Addendum shall be imposed on that Nitro sub-processor by way of a written agreement, in particular providing sufficient guarantees to implement appropriate technical and organizational measures (and complying with the relevant technical and organizational measures). Where a Nitro sub-processor fails to fulfil its data protection obligations, Nitro shall remain fully liable to the Processor for the performance of such Nitro sub-processor’s obligation.


11. INTERNATIONAL DATA TRANSFERS

11.1  The Processor authorizes international transfers of Personal Data for the purposes of providing the Services. Such international data transfers are considered an instruction of the Controller, conveyed to Nitro by the Processor. The Processor acknowledges that Nitro sub-processors authorized under Section 10 may also process Personal Data in third countries. The Processor permits such transfers, subject to Nitro taking all steps necessary to ensure such transfers comply with the provisions of Chapter V of the EU GDPR and other applicable data protection laws.

11.2  In case the transfer of Personal Data to a third country or an international organization is mandatory under applicable EU or Member State law to which Nitro is subject, Nitro shall be allowed to perform such transfer and shall inform the Processor of that legal requirement before such Processing, unless that law prohibits such information on important grounds of public interest. The Processor may transmit such information to the Controller.

12. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION

12.1  If the Controller performs a Data Protection Impact Assessment (“DPIA”) (article 35 EU GDPR) or a prior consultation (article 36 EU GDPR) linked to the processing of Personal Data in the context of the performance of the Agreement, Nitro, at the Processor's written request, shall reasonably assist the Controller. The Processor will reimburse Nitro for assistance provided according to Section 14 “Costs” of this Data Processing Addendum. Such reimbursement of costs shall not apply in case (i) the assistance requested from Nitro is less than four (4) working hours during the term of the Agreement, or (ii) the DPIA or prior consultation is triggered by a Personal Data Breach proven attributable to Nitro.


13. AUDIT RIGHT

13.1  At the Processor's request, Nitro shall permit audits by the Processor regarding the compliance by Nitro with its obligations under this Data Processing Addendum and the applicable data protection legislation. Nitro shall use its reasonable efforts to cooperate with such audits and to make available all information necessary to prove its compliance with its obligation. The Processor shall notify Nitro of such audit at least one (1) month prior to the date on which the audit will be performed, by given written notice to Nitro via privacy@gonitro.com.

13.2  In case an audit is being performed, all parties involved shall first sign a specific non-disclosure agreement issued by Nitro with respect to such audit and the audit results before the start of the audit. Upon the performance of any such audit, the confidentiality obligations of the Parties with respect to third parties must be taken into account. Both the Parties and their auditors must keep the information collected in connection with an audit secret and use it exclusively to verify its compliance with this Data Processing Addendum and the applicable laws and regulations in respect of data protection. The Processor has the option to perform the audit itself or to assign an independent auditor, however such independent auditor must duly sign the non-disclosure agreement referred to in this Section. The Controller has the same audit rights as the Processor under this Clause.

13.3  Both Parties and where applicable their representatives, shall reasonably cooperate, upon request, with the Supervisory Authority in the performance of its tasks.

13.4  The Processor will reimburse Nitro for the assistance provided by Nitro in relation to audit(s) in accordance with Section 14 “Costs” of this Data Processing Addendum. It being understood, such reimbursement shall not apply in case (i) the audit is a result of a Personal Data Breach proven attributable to Nitro or, (ii) in case Nitro’s assistance does not exceed four (4) working hours during the term of the Agreement.


14. COSTS

14.1  The assistance to be performed under this Data Processing Addendum for which Nitro may charge the Processor, will be charged on the basis of the hours worked and the applicable standard hourly rates of Nitro (195 EUR/hour taxes excluded). Nitro will invoice these amounts on a monthly basis but also has the right to request an upfront retainer fee.

14.2  The payment by the Processor to Nitro for the assistance and professional services provided by Nitro under this Data Processing Addendum will take place in accordance with the provisions in the Agreement.


15. LIABILITY

15.1  Subject to the maximum extent permitted under applicable law, the provisions of the Agreement concerning limitation of liability also apply to this Data Processing Addendum and the damages arising out of it


16. MISCELLANEOUS

16.1  The provisions of the Agreement concerning changes, entire agreement, severability, applicable law and competent courts are applicable to this Data Processing Addendum.

 

 

ANNEX 1 – DATA PROCESSING DETAILS

 

1. SUBJECT MATTER OF THE PROCESSING OF THE PERSONAL DATA

The subject matter is determined by the Processor as set out in the Agreement (and/or the relevant Nitro ISV Order Form).

2. THE NATURE AND PURPOSE OF THE PROCESSING OF PERSONAL DATA

The nature and the purposes of processing are determined by the Processor as set out in the Agreement (and/or the relevant Nitro ISV Order Form).

By default, such processing shall have as purpose to make available the Services including all its features and functionalities to the Processor (who will make those available to the Controller) and more in general to permit Nitro to fulfil its contractual obligations under the Agreement. Such purpose can be making available the Services via (API) integrations (for example but without limitation making available the customer electronic signing services, or identification services etc.) as well as the provisioning of Support.

The nature of processing shall, among other instructions given by the Processor in the Agreement (and/or relevant Nitro ISV Order Form), include the processing, collection, storage, communication and transfer of Personal Data.

3. PERSONAL DATA PROCESSED

Depending on the functionalities used within the Services (e.g. signing methods, identification means, audit trails, etc.), Nitro processes different categories of Personal Data. In general, the category of Personal Data processed by Nitro when using the Services will include different types of identification, contact and location data of all users and signers having access to the Services via the Controller. A detailed overview of the kind of Personal Data being processed when using the Services is available via our Trust Center: https://www.gonitro.com/trust-center/data-protection/processing-of-personal-data.

For Nitro Sign Enterprise Verified only and in addition to the above: depending on the documents uploaded for signing, additional categories of Personal Data will be processed based upon the content of such documents and these may include identification details, personal characteristics, physical characteristics, living habits or characteristics, consumption habits, location data, images, financial details, professional data, data on education, data relating to nationality, data relating to health, sexual orientation, religion or belief, political preferences, memberships of trade unions, genetic data, national register numbers, biometric data, credit scoring.

4. CATEGORY OF DATA SUBJECTS

The following Data Subjects are by default in scope:

 All users (initiators, approvers, signers, receivers, persons to be identified, etc.) having access to the Services via the Controller.
 All Data Subjects whose Personal Data is included in the documents uploaded for signing (Nitro Sign Enterprise Verified only).

The Processor confirms those Data Subjects will by default be considered one of the following categories:

 Users of the Services,
 Processor's customers.


5.  NITRO SUB-PROCESSORS

Nitro engages Nitro sub-processors for ensuring all functionalities are available within the Services. Which Nitro sub-processors are applicable depends on the functionalities and set-up requested by the Processor or the Controller. A detailed listing of the Nitro sub-processors engaged by Nitro (including the procedure we apply when engaging new Nitro sub-processors) is available via our Trust Center: https://www.gonitro.com/trust-center/data-protection/subprocessors-and-subcontractors.

6.  TECHNICAL AND ORGANIZATIONAL MEASURES

Nitro implements appropriate technical and organizational measures to ensure adequate security when using the Services. We are continuously updating such measures. A detailed overview of the measures taken is available via our Trust Center on our Security section: https://www.gonitro.com/security-compliance/security and in our Information Security Policy. Our Trust Center also lists the certifications Nitro holds in the Compliance section: https://www.gonitro.com/security-compliance/compliance

7.  RETENTION PERIOD

Nitro Sign Enterprise Verified: Nitro will not store Personal Data any longer than necessary for the provisioning of the Services. Depending on the Services and the functionalities the Processor or the Controller is using, the applicable retention period(s) might differ. The Processor, acting on behalf of the Controller, can request Nitro to configure specific retention periods on their Nitro Sign Enterprise Verified environment (e.g. auto-deletion). Additionally, the Service includes functionalities enabling the deletion of signed documents at any moment in time (e.g. manually or via API call). In case no specific retention periods were configured, Personal Data will by default be stored by Nitro until deletion by the Processor or the Controller or until termination of the agreement between Nitro and the Processor (plus maximum 30 days), whichever of both situations comes first. A detailed overview of the retention periods is available via our Trust Center: https://www.gonitro.com/trust-center/data-protection/processing-of-personal-data.

Nitro Identity Services: Nitro will not store Personal Data any longer than necessary for the provisioning of the Services. Depending on the Services and the functionalities you are using as a Customer, the applicable retention period(s) might differ. Personal Data will by default be stored by Nitro until (i) deletion of the session or (ii) until the auto-deletion process starts (default is set at 15 minutes). 

See what Nitro can do for you

Take the next step to digital success today.

Icon-48px-Rapid Support

Contact sales

Talk to our experts about your business needs, and explore cost-effective options for Nitro's world-class PDF and eSign solutions.
Get in touch
Icon-48px-Smart signing

Free trial

Try Nitro’s PDF and eSign solutions to edit, sign, and organize documents effortlessly—free for 14 days!
Start your free trial
icon of people with a plus sign

Become a partner

Learn about our exciting partner opportunities for Nitro's trusted document solutions.
Partner with Nitro today