Nextelio
Consulting
AMP CompilerWhatsApp SuiteEasy AMP4Email
Agentic MarketingJournal
Contact
Consulting

Products

AMP CompilerWhatsApp SuiteEasy AMP4Email
Agentic MarketingJournalLegal
Contact →

Legal

The paperwork, done properly.

Privacy PolicyTerms of ServiceAcceptable Use PolicyData Processing AddendumSub-processorsData DeletionSecurity overview

For requests under GDPR, write to privacy@nextelio.io.

DPA

Data Processing Addendum

Updated 2026-08-11

This Data Processing Addendum (“DPA”) forms part of the agreement between Nextelio SAS (the “Processor”) and the customer (the “Controller”) that governs use of Nextelio products. It applies where the Processor processes personal data on behalf of the Controller within the meaning of the General Data Protection Regulation 2016/679 (“GDPR”) and analogous laws.

1. Roles and scope

The Controller determines the purposes and means of processing personal data. The Processor acts on documented instructions of the Controller. The subject matter, duration, nature and purpose of processing, the types of personal data and categories of data subjects are set out in Annex A below.

2. Processor obligations

The Processor will:

  • Process personal data only on documented instructions from the Controller, including with regard to transfers outside the EEA, unless required to do so by Union or Member State law.
  • Ensure that persons authorised to process personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. Current measures are summarised in Annex B and on our Security overview.
  • Assist the Controller in responding to requests from data subjects, subject to reasonable notice and cost.
  • Assist the Controller in complying with obligations under Article 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor.
  • Return or delete personal data at the end of provision of services in line with the retention terms of our Privacy Policy.
  • Make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR.

3. Sub-processing

The Controller grants a general authorisation for the Processor to engage sub-processors listed on our Sub-processors page. The Processor will impose data protection terms on each sub-processor that are no less protective than this DPA and will remain responsible for their performance. The Processor will give the Controller at least 30 days’ notice of intended additions or replacements, during which the Controller may object on reasonable grounds.

4. International transfers

Where personal data is transferred outside the EEA, the parties will rely on the European Commission’s Standard Contractual Clauses (Module Two, Controller to Processor) as incorporated by reference. Additional supplementary measures may apply where required by the recipient jurisdiction.

5. Personal data breach

The Processor will notify the Controller of a personal data breach without undue delay, and in any case within 48 hours of becoming aware of it. The notification will include the information required under Article 33 GDPR to the extent then known, with updates as more becomes available.

6. Audits

Once per twelve month period, and on reasonable notice, the Controller may audit the Processor’s compliance with this DPA during business hours and without disruption. The Processor may satisfy this obligation by providing recent third party audit reports, security certifications or written responses to a security questionnaire.

7. Return and deletion

On termination of the underlying agreement, the Processor will, within 30 days, return or delete all personal data processed on behalf of the Controller, unless retention is required by Union or Member State law. Certified deletion is available on written request.

8. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions set out in the underlying agreement, save that nothing limits liability where limitation is prohibited by law (including under GDPR Article 82).


Annex A — Details of processing

Subject matter and duration

Provision of the Nextelio products (including Nextelio WhatsApp Suite, AMP Compiler and Easy AMP4Email) for the term of the underlying agreement.

Nature and purpose

Hosting, storing, transmitting and displaying Customer Content; integrating with third party platforms (Salesforce Marketing Cloud, Meta’s WhatsApp Business Cloud API); operational analytics, support and security.

Types of personal data

  • Contact identifiers of the Controller’s users (name, email, role).
  • End recipient identifiers as embedded in Customer Content (typically phone numbers for WhatsApp).
  • Content of templates, code and creative composed by users.
  • Access tokens for third party platforms.

Categories of data subjects

  • Controller’s employees and contractors.
  • End recipients of the Controller’s marketing communications.

Annex B — Security measures

See our Security overview for the current summary. In short: encryption in transit (TLS 1.2 or above) and at rest (AES 256 GCM for secrets and tokens), least privilege access, audit logging, workspace isolation, and documented incident response.

Sign block

For enterprise agreements, we sign this DPA on request. Ask privacy@nextelio.io.

Nextelio

The engineering behind remarkable marketing. Paris, since 2024.

Products

AMP CompilerWhatsApp SuiteEasy AMP4Email

Legal

PrivacyTermsDPASecurityAll legal
Contact

contact@nextelio.io

© 2026 Nextelio SAS · Paris, FranceMade for teams that measure twice.