Data Processing Addendum
Effective 25 June 2026
This document has not yet had a qualified-counsel legal review and should not be treated as legal sign-off. The company details and product description below are accurate as of the effective date above.
This Data Processing Addendum ("DPA") forms part of the Normproof Terms of Service. It applies wherever Customer Data you submit to the Service includes personal data, and sets out how Nomad Crow s.r.o. processes it on your behalf under Article 28 of the GDPR.
1. Roles
Where Customer Data includes personal data, you are the controller and Nomad Crow s.r.o. is the processor. We process personal data only on your documented instructions, which include the instructions built into how the Service works (for example, generating a dossier from the data you connect) and any further written instructions you give us.
2. Subject matter, duration, nature and purpose
- Subject matter: hosting and processing Customer Data to provide the Service.
- Duration: for as long as your account is active, plus any post-termination export period described in the Terms of Service.
- Nature of processing: storage, transmission, and computation — including SBOM generation, vulnerability scanning, and technical-documentation/dossier generation.
- Purpose: providing, securing, and supporting the Service for you.
3. Categories of data and data subjects
Personal data processed is typically limited to names, work email addresses, and roles of your organisation’s own personnel, and — where present in the Customer Data you connect — the same for individuals referenced in your product’s source, build, or support-contact metadata. We do not require or expect special categories of personal data (GDPR Art. 9) to operate the Service, and you should not submit any.
4. Our obligations
We will: process personal data only on your instructions, including regarding international transfers, unless required to do otherwise by EU or member-state law; ensure that people authorised to process the data are bound by confidentiality; and implement the technical and organisational security measures described in our Privacy Policy (Section 8), including per-organisation tenant isolation, encryption in transit, hashed credentials, role-based access control, and audit logging.
5. Sub-processors
You authorise the sub-processors listed in our Privacy Policy (Section 5) — currently Google Cloud (EU-region hosting, database, and object storage), Stripe (payment processing), and our email provider (transactional email). We will give reasonable notice before adding a new sub-processor so you can object on legitimate data-protection grounds; if we cannot resolve your objection, you may terminate the affected part of the Service.
6. Assistance
We will give you reasonable assistance to respond to data-subject requests concerning Customer Data, and to meet your own obligations relating to the security of processing, breach notification, data-protection impact assessments, and consultation with supervisory authorities, taking into account the nature of the processing and the information available to us.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data, and provide the information reasonably available to us to help you meet your own notification obligations.
8. Deletion or return
On termination, we will delete or return Customer Data in line with the Terms of Service and Privacy Policy, except where we are required to retain specific records (for example invoices) by law.
9. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits — including inspections — conducted by you or a mutually agreed independent auditor, no more than once per year absent a security incident affecting your Customer Data, on reasonable notice and subject to confidentiality.
10. International transfers
Where a sub-processor transfers personal data outside the EEA, that transfer is covered by an applicable adequacy decision or Standard Contractual Clauses, which are incorporated into this DPA by reference.
11. Liability and precedence
Liability under this DPA is governed by the limitation of liability in the Terms of Service. If this DPA conflicts with the Terms of Service on a matter of personal-data processing, this DPA controls.
12. Contact
Nomad Crow s.r.o., Astrová 43, 900 41 Rovinka, Slovakia (company no. 51320304, VAT SK2120677383). Data-protection enquiries: privacy@normproof.com.
Questions? See the Privacy Policy and Terms of Service, or contact support@normproof.com.