Legal · Õiguslik

Data Processing Agreement · Andmetöötlusleping

This DPA forms part of the agreement between Nola (‘processor’, ‘töötleja’) and a provider using Nola (‘controller’, ‘vastutav töötleja’) under Article 28 GDPR. A provider owner accepts it once from Provider → Privacy & GDPR.

1. Subject matter · Ese

Nola processes personal data of the provider's customers (name, contact details, booking history, payment status, messages, consent records) solely to provide the Nola booking and quoting software: publishing services, taking bookings and payments, sending notifications, and running the provider's day view and reports.

2. Duration & instructions · Kestus ja juhised

This DPA runs for as long as the provider has an active Nola account. Nola processes personal data only on the provider's documented instructions, as configured through the product (services, policies, notification templates) — we do not use provider customer data for our own marketing.

3. Confidentiality & security · Konfidentsiaalsus ja turve

Access to production data is limited to staff who need it to operate the service, under confidentiality obligations. Data is encrypted in transit (TLS) and at rest by our infrastructure sub-processors. Role-based permissions (Provider → Users) let a provider limit which of their own staff can see client contact details, money, or exports.

4. Sub-processors · Alltöötlejad

The table below is generated from our live configuration (`convex/gdpr.ts`) so it always reflects who currently processes data on our behalf. We will give providers reasonable notice of a new sub-processor via Notices.

Loading sub-processor list…

5. Sub-processing & international transfers · Rahvusvahelised edastused

Where a sub-processor is located outside the EEA, transfer relies on Standard Contractual Clauses or an adequacy decision, per that sub-processor's own DPA (linked above where available).

6. Assisting the controller · Vastutava töötleja abistamine

Nola gives providers direct tools to meet their own GDPR obligations to their customers: a data-request queue, a per-client consent overview, and configurable retention, all under Provider → Privacy & GDPR after sign-in (same topics as our public Privacy policy). We will assist with a data protection impact assessment or supervisory authority enquiry on reasonable request.

7. Breach notification · Rikkumisest teavitamine

We notify affected providers without undue delay, and no later than 48 hours after becoming aware, of a personal data breach affecting their customers' data, with the information needed for the provider to meet their own 72-hour notification duty to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

8. Deletion on termination · Kustutamine lepingu lõppedes

On account closure, provider customer data is deleted or anonymised per the provider's retention policy, except financial records retained 7 years under Estonian accounting law. A provider can request an export of all their data before closing their account.