Data Processing Agreement

Last updated: 9 October 2026

When we work in a client’s Odoo database or receive its data, we process personal data on the client’s behalf. This Data Processing Agreement (“DPA”) forms part of every agreement between Nexus International Commerce (the “Processor”) and the client (the “Controller”) and meets the requirements of Article 28 of the EU General Data Protection Regulation (GDPR).

1. Subject matter and duration

The Processor processes personal data only to deliver the services in the agreement: implementation, data migration, customisation, hosting set-up, training, support and ongoing management of Odoo. The DPA lasts as long as the Processor processes personal data for the Controller.

2. Types of data and data subjects

Contact and business data of the Controller’s employees, customers, suppliers and other contacts as stored in Odoo, such as names, job titles, email addresses, phone numbers, addresses, order and invoice data, and, where the Controller uses Odoo HR or Payroll, employee data.

3. Processor obligations

  • Process personal data only on the Controller’s documented instructions, including the agreement and tickets or emails from authorised contacts.
  • Ensure that everyone who has access is bound by confidentiality.
  • Apply the technical and organisational measures described on our Security and Data Protection page (Article 32 GDPR).
  • Help the Controller respond to data subject requests and meet its obligations on security, breach notification and data protection impact assessments.
  • Notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting its data.
  • At the end of the services, delete or return the personal data at the Controller’s choice, unless EU or member state law requires storage.
  • Make available the information needed to demonstrate compliance and allow audits by the Controller or its auditor, with reasonable notice.

4. Sub-processors

The Controller gives general authorisation for the Processor to use sub-processors, such as hosting and communication providers. The Processor imposes the same data protection obligations on them, informs the Controller of intended changes, and the Controller may object on reasonable grounds. A current list is available on request. Where the Controller contracts Odoo S.A. or a hosting provider directly, that provider is the Controller’s own processor, not ours.

5. International transfers

Personal data is processed in the European Economic Area by default. Transfers outside it take place only with the Controller’s agreement and under an adequacy decision or the European Commission’s Standard Contractual Clauses.

6. Liability and law

Liability follows the limits in our Terms of Service, except where the GDPR provides otherwise. This DPA is governed by the laws of the Republic of Cyprus. If a client needs its own DPA template, we are happy to review and sign it.