Skip to main content
Nord Security Logo

NordLayer AI Scout Data Processing Agreement

Effective from: September 1, 2026

  1. Definitions
    1. Unless expressly stated in this DPA, the capitalized terms shall have the meanings indicated below:
      • Customer's Personal Data means personal data that is: (a) provided by or on behalf of Customer to Nord Security in connection with the Services; or (b) obtained, developed, produced or otherwise processed by Nord Security on behalf of the Customer for the purposes of providing the Services, in each case as described in Annex I.
      • EEA means the European Economic Area.
      • Data Protection Laws means all applicable worldwide legislation relating to data protection and privacy which applies to the respective Party in the role of processing Personal Data in question under this DPA, including, without limitation, European data protection laws: (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) (hereinafter, the "GDPR"); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; and (iii) applicable national implementations of (i) and (ii); (iii) the GDPR as it forms parts of the United Kingdom domestic law by virtue of Section 3 of the European Union (Withdrawal) Act 2018 (hereinafter, the "UK GDPR"); regulations of the United States of America, including the California Consumer Privacy Act of 2018, Cal. Civ. Code §1798.100 et. seq., and its implementing regulations (hereinafter, the "CCPA"), applicable to the processing of the Personal Data (or an analogous variation of such term); other applicable data protection and privacy laws.
      • SCCs means standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (Commission implementing decision 2021/914 of 4 June 2021) as updated or replaced from time to time. The current version of the SCCs (i.e., applicable at the time of the conclusion of this DPA) is available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
      • UK SCCs means an International Data Transfer Addendum to the SCCs approved by the UK as updated or replaced from time to time. The current version of the Addendum to the SCCs (i.e., applicable at the time of the conclusion of this DPA) is available at https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/international-data-transfer-agreement-and-guidance/.
      • Configuration means the settings, policies, roles, permissions, retention parameters and feature enablements selected by the Customer.
      1. The following lower-case terms used but not defined in this DPA, such as “personal data”, "controller", "processor", "sub-processor", "processing", "special categories of personal data", "personal data breach" and "supervisory authority" shall have the same meaning as set forth in the GDPR, irrespective of whether the GDPR applies.
        1. Terms and expressions used in this DPA and not defined herein have the meaning assigned to them in the Terms.
        2. Application of this DPA
          1. This DPA applies when Nord Security processes the Customer's Personal Data in order to provide Services under the Terms. Nord Security, as defined in this DPA, acts as the data processor, whereas the Customer acts as the data controller.
            1. The nature, purpose, subject matter, and other details of processing activities performed as part of the Services are set out in Annex I of this DPA.
            2. General Obligations
              1. Nord Security shall process the Customer's Personal Data only for the limited and specified purposes set out in the Terms and/or as otherwise lawfully instructed by the Customer in writing (as specified in the Terms) and mutually agreed by the Parties, except where otherwise required by the Data Protection Laws. Customer's Configuration of the Services constitutes a written instruction to the Service for the purposes of Clause 3.1, and the Customer is solely responsible for its Configuration. Nord Security will not process the Customer's Personal Data for any other purpose or in a way that does not comply with this DPA or the Data Protection Laws.
                1. The Customer's initial instructions to Nord Security are set forth in this DPA and its Annex I. All the instructions provided are comprehensive and reflect the Customer's will.
                  1. Nord Security shall not evaluate any instructions of the Customer, which shall be held responsible and liable for any given instructions, to be fully lawful and compliant with the applicable Data Protection Laws. If in Nord Security`s reasonable opinion, an instruction undoubtedly infringes the applicable Data Protection Laws, Nord Security shall notify the Customer. Nord Security is not responsible for compliance with any Data Protection Laws applicable to the Customer or its industry that are not generally applicable to Nord Security.
                    1. Nord Security shall not take any action that would cause the Customer to violate the Data Protection Laws.
                      1. In particular but without prejudice to the generality of the foregoing, the Customer acknowledges and agrees that it will be solely responsible for: (i) the accuracy, quality, and legality of the Customer's Personal Data and the means by which it acquired Personal Data; (ii) complying with all necessary transparency and lawfulness requirements under applicable Data Protection Laws for the collection and use of the Personal Data, including any necessary notifications, consents, and authorizations that are needed for the Customer's use of the Services; (iii) ensuring it has the right to transfer, or provide access to, the Personal Data to Nord Security for processing in accordance with the provisions of the Terms (including this DPA); and (iv) ensuring that its instructions to Nord Security regarding the processing of Personal Data comply with applicable laws, including Data Protection Laws. The Customer shall also inform Nord Security without undue delay if the Customer is not able to comply with its responsibilities under this Section.
                      2. Data Disclosure
                        1. Nord Security undertakes not to disclose the Customer's Personal Data to any third party other than through the use of other data processors as specified in this DPA, except if the Personal Data is disclosed under third parties' request of information in accordance with applicable legal acts or under legitimate requests from law enforcement or other competent authorities.
                          1. To the fullest extent permissible under the Data Protection Laws, the Customer authorizes Nord Security to use sub-processors to fulfill its obligations as set forth in this DPA (provides general authorization) provided that Nord Security maintains a list of sub-processors and, upon receiving a written request from the Customer, provides the Customer with such list.
                            1. Nord Security shall: (i) ensure that any sub-processor is contractually bound in writing to provide at least the same level of protection as is required by this DPA and complies with the Data Protection Laws; (ii) be fully responsible and liable to the Customer for acts and omissions of any sub-processor as if they were Nord Security's own act or omission.
                              1. If required to do so by applicable Data Protection Laws, in case of a new sub-processor: (i) Nord Security will inform the Customer thereof; and (ii) Nord Security shall enable the Customer to object, by way of providing Nord Security with a reasoned, specific and written objection, to changes concerning the addition or replacement of sub-processors to the afore-mentioned list.
                                1. Where Customer configures the Services to transmit data to a destination controlled by Customer or by a third party selected by Customer, including a security information and event management system (SIEM), a webhook endpoint, or similar, that transmission is made on Customer's instruction. Such a destination is not a sub-processor of Nord Security, and Nord Security is not responsible for the processing of Customer's Personal Data after it leaves Nord Security’s systems.
                                2. Data Transfers
                                  1. The Customer shall transfer the Customer's Personal Data in accordance with the requirements of Data Protection Laws applicable to the Customer.
                                    1. The Customer acknowledges and agrees that Nord Security may access and process the Customer's Personal Data on a global basis as necessary to provide the Services in accordance with the Terms.
                                      1. The Customer's Personal Data from EEA, or UK may only be exported to or accessed by Nord Security or its sub-processors outside the EEA or the UK ("European Transfer"), as applicable:
                                        1. if the recipient or the country/territory in which it processes or accesses the Customer's Personal Data ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of Personal Data as determined by the European Commission or another regulatory body of competent jurisdiction ("Adequacy Decision"); or
                                        2. in the absence of an Adequacy Decision, the European Transfer only can take place in accordance with Annex II of this DPA.
                                    2. Data Security
                                      1. Nord Security shall make sure to take appropriate technical and organizational measures (hereinafter, the "TOMs") to protect the processed Customer's Personal Data. The TOMs must ensure an adequate level of security, taking into account:
                                        1. context, objectives, and particular risks associated with the processing of Personal Data;
                                        2. the risks to the rights and freedoms of data subjects arising from the processing of Personal Data;
                                        3. existing Nord Security's technical capabilities; and
                                        4. costs of the measures or their implementation.
                                      2. Nord Security must ensure that the TOMs used to protect the Customer's Personal Data include the following measures/requirements where appropriate:
                                        1. the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of systems and services of the Customer's Personal Data processing;
                                        2. the ability to restore the availability and access to the Customer's Personal Data in a timely manner in the event of a physical or technical incident;
                                        3. regular assessment of the efficiency of TOMs to ensure the security of the processing of Personal Data.
                                      3. Nord Security shall also ensure that persons authorized to process the Customer's Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
                                        1. The list of the current Nord Security's TOMs used to protect the Customer's Personal Data is set out in full in Annex I of this DPA. Notwithstanding any provision to the contrary, Nord Security may modify or update the TOMs at its discretion provided that such modification or update does not result in a material degradation in the protection offered by the current TOMs.
                                          1. Nord Security, having become aware of any personal data breach affecting the Customer's Personal Data shall: (i) report the breach to the Customer without undue delay, after becoming surely aware of the personal data breach; (ii) make reasonable efforts to assist the Customer in fulfilling its obligation under applicable Data Protection Laws to notify a relevant supervisory authority and/or data subjects about such personal data breach. For the avoidance of doubt, Nord Security will not notify and/or disclose any information relating to the personal data breach to any third party, including but not limited to data subjects and supervisory authority, unless required to do so by Data Protection Laws.
                                            1. The Customer is responsible for controlling access to Captured Data by Customer's own personnel through the roles and permissions made available in the Services.
                                            2. Cooperation and Data Subjects Rights
                                              1. The Customer shall process and respond to every enquiry, request, notice, question, complaint or other communication related to the processing of the Customer's Personal Data under this DPA ("Request") received from: (i) any natural person whose Personal Data is processed by Nord Security on behalf of the Customer or (ii) any supervisory authority.
                                                1. When the Customer is not able to solely process and respond to the Request, the Customer may ask Nord Security for reasonably required assistance (subject to the nature of the processing and the information available to Nord Security) to enable the Customer to:
                                                  1. comply with (and demonstrate compliance with) its obligations under the Data Protection Laws (including, but not limited to data protection impact assessments, reporting to and consulting with supervisory authorities); and
                                                  2. respond to, comply with, or otherwise resolve the Request. In the event that any such Request under this Section is made directly to Nord Security, Nord Security shall promptly inform the Customer by providing full details of such Request. For the avoidance of doubt, Nord Security will not respond to any Requests, unless Nord Security is legally compelled to do so.
                                              2. Right to Carry Out an Audit
                                                1. When reasonably necessary, the Customer shall have the right to take the measures necessary to verify Nord Security's compliance with this DPA.
                                                  1. The Customer shall also have a right to request an audit performed by the independent, accredited, and reputable third-party audit firm agreed by both Parties. For the avoidance of doubt, neither the Customer nor the appointed auditor shall be a competitor of Nord Security's business and, under no circumstances may the Customer, or the selected auditor, have access to Nord Security's confidential information, information of Nord Security's other clients, nor to any information of third parties to whom Nord Security owes a duty of confidentiality. Before conducting the audit, the Customer and auditor must execute a written confidentiality agreement acceptable to Nord Security or otherwise be bound by a statutory confidentiality obligation.
                                                    1. This audit will only take place where there is a specific and well-founded suspicion of misuse of the Customer's Personal Data, and only after the Customer has requested and assessed similar existing reports from Nord Security and has made reasonable arguments to justify an audit being initiated by the Customer. For the avoidance of doubt, such an audit can be justified only if similar reports (that Nord Security has available) provide insufficient or inconclusive answers regarding compliance with this DPA by Nord Security.
                                                      1. An audit shall take place during regular business hours in a manner that is not disruptive to Nord Security's business, upon reasonable no less than two (2) month advance notice to Nord Security (unless mandatory applicable Data Protection Laws or the supervisory authority requires a shorter notice) and subject to a maximum capacity of confidentiality undertaking as provided below. Before the commencement of any such audit, the Parties shall mutually agree upon the timing, duration, and scope of an audit, which shall not involve physical access to the servers from which the Customer's Personal Data processing is provided.
                                                        1. The Customer shall notify Nord Security regarding any non-compliance discovered during the course of an audit. The Customer may not audit Nord Security more than once during any consecutive twelve (12) month period. The Customer is responsible for all costs and fees related to such audit, including all costs and fees for any and all time Nord Security expends for any such audit.
                                                          1. All information discovered in the course of an audit shall be treated as "Confidential Information" and shall be subject to the "Confidentiality" Section of the Terms.
                                                          2. Term
                                                            1. This DPA shall apply as long as the Services are provided to the Customer as set out in the Terms unless the Parties terminate the Terms and/or this DPA earlier on the grounds provided therein.
                                                              1. Following termination of the DPA, Nord Security shall delete or return the Customer's Personal Data to the Customer at its choice. The Customer's Personal Data shall be deleted as determined in the Terms. Customer acknowledges that (i) any return of data will be provided in the export formats made available by the Services; and (ii) residual copies may persist in the Service’s routine backups until expiry of the applicable backup cycle, during which period such copies shall remain subject to this DPA and shall not be accessed or processed for any purpose other than backup integrity, disaster recovery, or as required by law.
                                                              2. Liability
                                                                1. Nord Security's liability, taken together in the aggregate, arising out of or related to this DPA, whether contractual, tort or under any other theory of liability, shall be subject to the limitations and exclusions set out in the Terms. Liability of Nord Security shall mean the aggregate liability of Nord Security under the Terms and this DPA together.
                                                                2. Other Provisions
                                                                  1. All notices between the Parties shall be given following the provisions of the Terms.
                                                                    1. Nord Security shall have the right to any reimbursement of reasonable expenses, costs, and fees which were incurred as a result of Customer's (i) inaccurate, incomplete, or unlawful instructions; and/or (ii) requests for cooperation which are unfounded, excessive, and/or impose unreasonably disproportionate costs to Nord Security.
                                                                      1. This DPA shall be governed and any disputes or claims arising from this DPA shall be settled according to the provisions of the Terms.
                                                                        1. Notwithstanding anything to the contrary in the Terms, in the event of any conflict or inconsistency between the terms of this DPA and the Terms, the provisions of this DPA shall prevail.
                                                                          1. ePHI and HIPAA. The Customer shall not, and shall not permit any Members to, upload to the Services or use the Services to process any electronic protected health information ("ePHI") governed by the Health Insurance Portability and Accountability Act, as amended ("HIPAA"). The Service does not support HIPAA compliance.

                                                                          Description and Instructions for Processing

                                                                          • (a) Members;
                                                                          • (b) Monitored Individuals;
                                                                          • (c) Third parties whose personal data appears within Captured Data. These are natural persons whose personal data is captured because it appears in a prompt written by a Monitored Individual, in a file or directory read by Monitored AI Service, or in the output of a command executed by such a tool.
                                                                          • (a) Interaction Content. The content of a monitored interaction, such as the prompt a Monitored Individual submits to a Monitored AI Service, the output that service returns, the steps and operations it performs in the course of responding, and the files, selections and other material supplied into its context.
                                                                          • (b) Interaction Metadata. The metadata of a monitored interaction, such as the data about the Monitored AI Service and interaction timestamps.
                                                                          • (c) Detection Data. The results of data detection applied to a monitored interaction, such as the classification, confidence and position of each detection, as well as the matched data (if enabled).
                                                                          • (d) AI Environment and Adoption Data. Information describing Monitored AI Service configured on a Device and its use, such as the identity, location, configuration state and usage of the Monitored AI Service.
                                                                          • Customer’s Personal Data is encrypted in transit using TLS (industry-standard protocols and cipher suites).
                                                                          • Customer’s Personal Data is encrypted at rest using strong, industry-standard algorithms (e.g., AES-256).
                                                                          • Encryption keys are managed using Key Management Service (KMS) with restricted access and rotation practices.
                                                                          • Access to Customer’s Personal Data is granted strictly on a need-to-know and least-privilege basis, limited to personnel who require it to perform their functions.
                                                                          • Role-based access control (RBAC) is enforced across systems and infrastructure, where possible.
                                                                          • Multi-factor authentication (MFA) is enforced for access to systems containing Customer’s Personal Data.
                                                                          • Single Sign-On (SSO) with centralized identity management is used for provision and de-provision access.
                                                                          • Administrative privileges to production infrastructure are restricted to a limited number of authorized personnel and are regularly reviewed.
                                                                          • Remote access to infrastructure is performed only through secured, controlled channels (e.g., Zero Trust Network Access).
                                                                          • Production infrastructure is hosted on data centers that maintain SOC 2 and ISO 27001 certifications or match the requirements of these attestations/certifications.
                                                                          • The environment is protected by firewalls, security groups, and network segmentation.
                                                                          • Infrastructure is deployed and managed using infrastructure-as-code and configuration management with a role-based policy engine.
                                                                          • A data center / vendor security assessment is performed before onboarding a new infrastructure provider.
                                                                          • Security-relevant events, access, and system activity are logged.
                                                                          • Logs are monitored, and alerting mechanisms are in place to detect anomalous or unauthorized activity.
                                                                          • Audit logs are retained in accordance with applicable policies.
                                                                          • Periodic penetration testing of applications and infrastructure is performed by qualified security professionals and/or independent third parties.
                                                                          • Automated vulnerability scanning is performed on infrastructure and applications.
                                                                          • Identified vulnerabilities are triaged and remediated based on risk and severity.
                                                                          • A secure software development lifecycle (SDLC) is followed, including peer code review prior to deployment.
                                                                          • Changes are deployed through controlled CI/CD pipelines with appropriate approvals.
                                                                          • Customer’s Personal Data is logically segregated to ensure that data belonging to one customer is isolated from that of other customers in the multi-tenant environment.
                                                                          • Encrypted back-up copies of Customer’s Personal Data and critical information are maintained to enable restoration in the event of a physical or technical incident.
                                                                          • Back-ups are stored in physically separate locations and their integrity is periodically verified.
                                                                          • Business continuity and disaster recovery plans are maintained to ensure the ongoing availability and resilience of the Services.
                                                                          • Recovery capabilities are periodically reviewed and tested.
                                                                          • An inventory of employee devices is maintained, and the ability to detect and block unauthorized (rogue) devices is in place.
                                                                          • An inventory of employee software is maintained, and unauthorized software can be detected.
                                                                          • Company-provided devices are managed via mobile device management (MDM), ensuring timely software updates, disk encryption, anti-malware protection, and remote data wipe in the event of loss or theft.
                                                                          • Personnel are bound by confidentiality obligations (e.g., NDAs) with respect to Customer’s Personal Data.
                                                                          • Background screening is performed for relevant personnel where legally permitted.
                                                                          • All employees undergo information security awareness training, during onboarding and on a recurring basis.
                                                                          • Physical and environmental security is ensured for the data centers hosting Customer Data, including access-controlled premises and surveillance.
                                                                          • Employees must store any physical documents and data files securely.
                                                                          • A documented incident response process is maintained, covering detection, escalation, investigation, and remediation of security incidents.
                                                                          • Upon becoming aware of a personal data breach affecting Customer’s Personal Data, the Company will notify the Customer without undue delay and provide reasonable assistance as set out in this DPA.
                                                                          • The Company assesses the security practices of sub-processors prior to onboarding and reviews them periodically thereafter, relying on questionnaires and where available on independent assurance (e.g., SOC 2 Type II reports, ISO 27001 certification).

                                                                          The SCCs and European Transfers Agreement

                                                                          CCPA Data Protection Addendum