Data Processing Agreement (DPA)

Last updated: 10 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement for the use of the Odiseo platform (the "Agreement") between:

  • Nexus Generated FZ-LLC, a free zone limited liability company licensed by the Ras Al Khaimah Economic Zone (RAKEZ), License No. 5034603, with registered address at VUET1700, Compass Building - Al Hulaila, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates ("Nexus Generated", "we", the "Processor"); and
  • The client that accepts the Agreement (the "Client", the "Controller").

Contact for data protection matters: legal@odiseo.ai

This DPA applies whenever Nexus Generated processes personal data of the Client's end users — the visitors, contacts and leads who interact with the Client's AI employee — on the Client's behalf. For that data, the Client is the controller and Nexus Generated is the processor. (Data about the Client's own account, and visitors of odiseo.ai itself, is covered by our Privacy Policy, where Nexus Generated acts as controller.)

The English version of this DPA is the binding version.


1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given to them in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"). "Client Data" means personal data that Nexus Generated processes on the Client's behalf under the Agreement.

2. Subject Matter, Duration, Nature and Purpose of Processing

Subject matter. Nexus Generated provides Odiseo: AI employees that interact with the Client's visitors through a chat widget embedded in the Client's website, live voice, WhatsApp (via Twilio) and email; a knowledge base loaded by the Client; a native CRM with lead qualification; supervised actions (tickets, tasks, meetings); and an optional proactive tier (off by default, enabled by the Client).

Duration. This DPA applies for as long as Nexus Generated processes Client Data under the Agreement, and until deletion or return of that data under Section 10.

Nature and purpose. Collection, storage, structuring, analysis and generation of responses in conversations between the Client's AI employee and the Client's visitors; lead capture and qualification; and the supervised actions the Client configures. Processing is automated and includes the use of large language models to generate conversational responses.

Categories of data subjects. Visitors of the Client's website and channels; the Client's contacts and leads.

Types of personal data. Data provided by data subjects in conversations (which may include name, email, phone number, and any content the data subject chooses to share); contact and lead-qualification records; conversation transcripts and, where the Client enables voice, voice interactions; technical metadata associated with the interaction.

Special categories. Odiseo is not designed for special categories of personal data (e.g. health, biometric, political opinions). The Client agrees not to configure its AI employee to solicit such data.

3. Processing on Documented Instructions

3.1 Nexus Generated will process Client Data only on the Client's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law — in which case Nexus Generated will inform the Client of that legal requirement before processing, unless the law prohibits it.

3.2 The Agreement, this DPA, and the Client's configuration of the platform (its knowledge base, enabled channels, CRM settings, supervised actions and the proactive tier) constitute the Client's complete initial instructions. Additional instructions require written agreement.

3.3 Nexus Generated will inform the Client without undue delay if, in its opinion, an instruction infringes the GDPR, the UAE PDPL or other applicable data protection law.

3.4 No model training. Nexus Generated does not use Client Data to train machine-learning models. The Client's content — its knowledge base, its conversations, its contacts — belongs to the Client.

4. Confidentiality

Nexus Generated ensures that every person authorised to process Client Data is bound by a contractual or statutory duty of confidentiality, and that access is limited to what each person needs to operate and support the service.

5. Security Measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Nexus Generated implements appropriate technical and organisational measures to protect Client Data, including:

  • Tenant isolation. Strict separation between clients, enforced at the database layer through row-level security (RLS). Each client's data is isolated from every other client's.
  • Encryption in transit. All data in transit between the visitor, the platform and its infrastructure is encrypted using TLS.
  • Access controls. Authenticated, role-based access to the platform; administrative access limited to personnel who need it to operate the service.
  • Spend and abuse controls. Per-client usage caps that bound the activity of each AI employee.
  • Guardrails on AI output. A two-layer firewall that prevents the AI employee from giving financial, legal or medical advice; disclosure to data subjects that they are interacting with an AI (per Article 50 of the EU AI Act); and escalation paths to a human. AI disclosure is built into chat and appended server-side to every email today; voice and WhatsApp are being brought to the same standard.
  • Deletion cascade. Deletion of conversations and messages propagates through the data model (see Section 10).

Nexus Generated may update these measures over time, provided the updates do not materially reduce the overall level of protection.

6. Subprocessors

6.1 The Client gives Nexus Generated general written authorisation to engage the subprocessors listed below, which is the complete list at the date of this DPA:

Subprocessor Purpose
Anthropic Large language model (conversation generation)
Google (Gemini) Model used for message triage
ElevenLabs Voice (speech synthesis and live voice conversations)
Twilio WhatsApp and telephony connectivity
Stripe Billing and payments processing for the platform
Neon Database hosting (Postgres)
Vercel Application hosting
Clerk Authentication
Upstash Redis (caching and rate limiting)
Inngest Background job processing
Sentry Error monitoring
PostHog Product analytics
Langfuse LLM observability
Resend Transactional email

6.2 Changes. Nexus Generated will notify the Client of any intended addition or replacement of a subprocessor at least 30 days before the change takes effect. The Client may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection in good faith, the Client may terminate the affected part of the service.

6.3 Nexus Generated imposes on each subprocessor data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Client for the performance of each subprocessor's obligations.

6.4 Client's own Stripe. Where the Client connects its own Stripe payment link so that its visitors can pay the Client directly, that payment flow runs on the Client's own Stripe account: Nexus Generated does not process or hold those payments and is not a party to them.

7. International Transfers

Some subprocessors process data outside the United Arab Emirates and outside the European Economic Area. Where Client Data of EU data subjects is transferred to a country without an adequacy decision, Nexus Generated will ensure the transfer is covered by appropriate safeguards under Chapter V of the GDPR (such as the EU Standard Contractual Clauses) and, for data subject to the UAE PDPL, by the transfer conditions of that law.

For transfers from the EEA/UK, the parties incorporate the EU Standard Contractual Clauses (Module 2: controller→processor) by reference, with this DPA serving as the description of processing for Annexes I–II. An executed copy of the Clauses is available to Clients on request.

8. Assistance with Data Subject Requests

8.1 Taking into account the nature of the processing, Nexus Generated will assist the Client through appropriate technical and organisational measures in fulfilling the Client's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection) under the GDPR and the UAE PDPL.

8.2 If a data subject contacts Nexus Generated directly about data processed on the Client's behalf, Nexus Generated will forward the request to the Client without undue delay and will not respond on the merits except on the Client's instruction or where required by law.

8.3 Nexus Generated will also assist the Client, to the extent reasonable and taking into account the information available to it, with the Client's obligations regarding security, breach notification, data protection impact assessments and prior consultation with supervisory authorities (GDPR Articles 32–36 and their PDPL equivalents).

9. Personal Data Breach Notification

9.1 Nexus Generated will notify the Client without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Client Data, preserving the Client's own 72-hour window under GDPR Article 33.

9.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point. Information may be provided in phases as the investigation progresses.

9.3 Nexus Generated will cooperate with the Client and take reasonable steps to contain, investigate and mitigate the breach. Notifying the Client is not an admission of fault.

10. Deletion and Return on Termination

10.1 On termination or expiry of the Agreement, Nexus Generated will, at the Client's choice, delete or return all Client Data, and delete existing copies, unless applicable law requires continued storage — in which case the retained data stays protected under this DPA and is processed for no other purpose. The Client may export Client Data during the export window provided in the Terms of Service (30 days after the effective date of termination); deletion under this Section follows the close of that window.

10.2 Deletion is implemented through the platform's erasure cascade (aligned with GDPR Article 17): deletion of a conversation propagates to its messages and associated records, so that Client Data does not survive in orphaned form.

10.3 Default retention: Client Data is retained while the Client's account is active and deleted within 30 days after account closure, through the erasure cascade described in Section 10.2, unless applicable law requires continued storage.

11. Audit Rights

11.1 Nexus Generated will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, subprocessor lists, and available third-party reports or certifications relating to the infrastructure providers it relies on.

11.2 Audits are reports-based: the Client's audit rights are satisfied first through the documentation described in 11.1. Where the Client reasonably demonstrates that this documentation is insufficient to establish compliance, or where a supervisory authority requires it, the Client may request a further audit, which will be conducted at reasonable intervals, on reasonable prior written notice, during business hours, without disrupting the service, subject to confidentiality obligations, and at the Client's expense unless the audit reveals a material breach of this DPA.

12. Regulatory Alignment

This DPA is drafted to satisfy Article 28(3) of the GDPR for Client Data relating to EU data subjects, and the processor obligations of the UAE PDPL (Federal Decree-Law No. 45 of 2021). If a mandatory provision of either law requires more than this DPA provides, that provision prevails for the data within its scope.

13. General

13.1 Order of precedence. If this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails.

13.2 Liability. The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where applicable data protection law does not permit such limitation.

13.3 Governing law and disputes. This DPA is governed by the laws of the Emirate of Ras Al Khaimah and the applicable federal laws of the United Arab Emirates. Disputes are finally resolved by binding arbitration seated in the United Arab Emirates, administered by the Dubai International Arbitration Centre (DIAC) under its rules in force, before a single arbitrator, with proceedings conducted in English.

13.4 Accuracy of AI output. The AI employee generates responses automatically and may make mistakes; nothing in this DPA is a warranty of accuracy of AI output or of any business outcome. The Client remains responsible for reviewing material outputs and for the lawfulness of the instructions it gives.