Data Processing Addendum (DPA)
Last updated: 10/2026
This Data Processing Addendum ("DPA") forms part of and supplements the Terms of Service, Master Service Agreement, Order Form, Subscription Agreement, or other written agreement (the "Agreement") entered into between KuN Holding GmbH, Strohgasse 16/7, 1030 Vienna, Austria, operator of the product NebulaOne ("Processor") and the Customer ("Controller").
To the extent NebulaOne processes Personal Data on behalf of the Customer, the parties agree as follows.
1. Definitions
(1) Terms such as "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", and "Supervisory Authority" shall have the meanings assigned under the GDPR.
(2) Capitalized terms not defined herein shall have the meaning assigned in the Agreement.
(3) In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data on behalf of the Customer. Any applicable Standard Contractual Clauses shall prevail over this DPA to the extent of a conflict.
2. Scope and Roles of the Parties
(1) Customer acts as Controller with respect to Personal Data processed through the Services.
(2) NebulaOne acts as Processor on behalf of the Customer.
(3) This DPA applies whenever NebulaOne processes Personal Data on behalf of the Customer in connection with the Services.
(4) This DPA does not govern processing for which KuN Holding GmbH independently determines the purposes and means, including its own billing and contract administration. Such processing is described in the applicable Privacy Policy. Account and contact information listed in Appendix A falls within this DPA only to the extent processed on behalf of the Customer.
3. Processing of Personal Data
(1) NebulaOne shall process Personal Data solely:
- (a) to provide the Services;
- (b) in accordance with the Agreement;
- (c) in accordance with documented instructions from the Customer;
- (d) where required by applicable law.
(2) NebulaOne shall not process Personal Data for purposes unrelated to the Services.
(3) The processing covered by this DPA is limited to providing organizational needs and role assessments and generating the corresponding reports on behalf of the Customer. Candidate evaluations and candidate interviews are not part of the currently provided Services covered by this DPA.
(4) Processing shall continue for the term of the Agreement and the thirty (30) day export period following its termination or expiration, solely to the extent necessary for the purposes set out in this DPA. Earlier documented deletion instructions and applicable statutory retention obligations shall be handled in accordance with Section 13.
(5) The nature of processing comprises collecting, storing and structuring inputs, performing AI-assisted analysis, creating and making assessment reports available to the Customer, and deleting the data, in each case within the scope and purposes of this DPA and the Customer's documented instructions.
4. Customer Instructions
(1) The Customer instructs NebulaOne to process Personal Data as necessary to provide the Services.
(2) Additional documented instructions may be provided by the Customer where permitted by applicable law and the Agreement.
(3) If, in NebulaOne's opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection provisions, NebulaOne shall immediately inform the Customer and suspend implementation of the affected instruction until its lawfulness has been clarified.
5. Confidentiality
(1) NebulaOne shall ensure that persons authorized to process Personal Data are subject to confidentiality obligations.
(2) Access to Personal Data shall be limited to personnel with a legitimate business need.
6. Security Measures
(1) NebulaOne shall implement appropriate technical and organizational measures designed to protect Personal Data.
(2) NebulaOne shall implement and maintain the technical and organizational measures set out in Appendix B. These measures include:
- (a) encryption in transit;
- (b) encryption at rest;
- (c) access controls;
- (d) authentication controls;
- (e) audit logging;
- (f) security monitoring;
- (g) incident response procedures.
(3) Security measures may evolve over time provided that the overall level of protection is not materially reduced.
7. Subprocessors
(1) Customer authorizes NebulaOne to engage subprocessors for the provision of the Services.
(2) As of the Effective Date, approved subprocessors include those identified in Appendix C.
(3) NebulaOne shall impose data protection obligations on subprocessors that are substantially equivalent to those contained in this DPA.
(4) NebulaOne remains responsible for the performance of its subprocessors to the extent required by applicable law.
(5) NebulaOne shall inform the Customer in writing at least thirty (30) days before adding or replacing a subprocessor, including information about the proposed subprocessor and its processing activities. The Customer may object on reasonable data protection grounds within that notice period. NebulaOne shall consider the objection and seek a resolution with the Customer before the proposed subprocessor processes the affected Customer Personal Data.
8. International Transfers
(1) Personal Data may be transferred internationally where necessary to provide the Services.
(2) Where required, NebulaOne shall implement appropriate safeguards, including:
- (a) Standard Contractual Clauses;
- (b) adequacy decisions;
- (c) other legally recognized transfer mechanisms.
9. Data Subject Rights
(1) Taking into account the nature of the processing, NebulaOne shall reasonably assist the Customer in responding to requests from Data Subjects.
(2) Where NebulaOne receives a request directly from a Data Subject concerning Personal Data processed on behalf of the Customer, NebulaOne shall forward the request to the Customer without undue delay. NebulaOne shall respond substantively only in accordance with the Customer's documented instructions, unless otherwise required by applicable law.
10. Assistance Obligations
NebulaOne shall reasonably assist the Customer in relation to:
- (a) security obligations;
- (b) breach notifications;
- (c) data protection impact assessments;
- (d) regulatory inquiries;
- (e) compliance obligations arising under applicable privacy laws.
Assistance shall be provided without undue delay, taking into account the urgency of the request and applicable statutory deadlines.
KuN Holding GmbH shall inform the Customer of authority requests received by KuN concerning Customer Personal Data. Information may be provided after the relevant action only to the extent permitted by applicable law. Where Union or Member State law requires KuN to process Customer Personal Data, KuN shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Where notification is legally prohibited, KuN shall notify the Customer without undue delay once that prohibition ceases to apply. This provision does not restrict an authority from contacting the Customer directly.
11. Security Incidents
(1) NebulaOne maintains procedures designed to detect, investigate, and respond to Security Incidents.
(2) NebulaOne shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Such notification shall be sent to the data protection or security contact designated by the Customer.
(3) Notifications may include information reasonably available at the time regarding:
- (a) nature of the incident;
- (b) categories of affected information;
- (c) mitigation measures undertaken.
12. Audits and Information Rights
(1) Upon reasonable request, NebulaOne shall make available information reasonably necessary to demonstrate compliance with this DPA.
(2) NebulaOne shall initially provide relevant existing documentation and evidence of compliance. NebulaOne shall allow for and contribute to audits, including on-site inspections, conducted by the Customer or an auditor mandated by the Customer where necessary to verify compliance with this DPA and applicable data protection law. Existing documentation shall not preclude such audits where further verification is necessary.
(3) Audits shall be coordinated to minimize unnecessary disruption to NebulaOne's operations and protect the personal data and confidential information of other customers, without preventing the Customer from exercising its applicable statutory audit rights.
13. Return and Deletion of Data
(1) Following termination or expiration of the Services, NebulaOne shall make the Customer’s assessments and reports available for export for thirty (30) days, unless the Customer instructs earlier deletion.
(2) At the end of this period, NebulaOne shall delete Customer Personal Data processed on behalf of the Customer, including copies, unless applicable law requires continued storage. Any legally required retention shall be limited to the data and period required by law, and the retained data shall remain protected under this DPA.
(3) The Customer may instruct return or deletion of Customer Personal Data before the end of the thirty-day period. NebulaOne shall comply with such documented instructions, subject to applicable legal retention obligations.
14. Liability
(1) Liability arising under this DPA shall be governed by the liability provisions contained in the Agreement.
(2) Nothing in this DPA limits liability where such limitation is prohibited by applicable law.
Appendix A – Categories of Personal Data
NebulaOne may process:
- Customer account information
- Contact information
- Information about employees' tasks, roles and responsibilities, insofar as the employees are directly or indirectly identifiable, including from their role, department or organizational context even where names are omitted
- Assessment responses
- Responses provided during organizational needs and role assessments
- Organizational assessment data
- Audio recordings
- Video recordings
- Transcripts
- Usage information
- Security logs
Data Subjects may include:
- Customer personnel
- Contractors
- Consultants
- Employees
- Assessment participants
Appendix B – Technical and Organizational Measures
NebulaOne maintains security measures including:
- Encryption in transit
- Encryption at rest
- Role-based access controls
- Authentication controls
- Audit logging
- Security monitoring
- Vendor oversight
- Incident response procedures
- Backup and recovery procedures
- Access management controls
Appendix C – Approved Subprocessors
As of the Effective Date:
Amazon Web Services (AWS)
Purpose: Cloud Infrastructure and Hosting
Hosting region: Frankfurt am Main, Germany.
Under the AWS standard terms for an Austrian customer account, the contracting entity is Amazon Web Services EMEA SARL, Luxembourg. The AWS Service Terms incorporate the AWS Data Processing Addendum and, for relevant transfers to countries outside the EEA without an adequacy decision, the applicable Standard Contractual Clauses, including processor-to-processor clauses where KuN acts as a processor. Hosting in Frankfurt does not exclude transfers permitted under those terms.
OpenAI
Purpose: AI Processing Services
Configured region: Europe. Under OpenAI's standard DPA for customers based in the EEA, the contracting entity is OpenAI Ireland Ltd. For onward transfers of EEA personal data outside the EEA or Switzerland, the DPA provides for Standard Contractual Clauses or an applicable adequacy decision. European regional storage and processing remain subject to the supported services and configuration; the selected region does not constitute a guarantee that all processing occurs exclusively in the EEA.
NebulaOne may update this list from time to time in accordance with applicable law and contractual requirements.