Legal
Data Processing Agreement
Processor terms for the personal data in mentions that Nephia collects, stores and labels on your instructions.
Last updated: September 3, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Nephia ("we", "us") and the customer ("you"). It applies to the personal data in Mentions that we process on your instructions. Capitalised terms have the meaning given in the Terms.
1. Definitions
- Data Protection Laws — the GDPR, the UK GDPR, the CCPA/CPRA where applicable, and similar laws
- Personal Data, Processing, Data Subject, Controller, Processor and Sub-processor have their GDPR meanings
- Customer Instructions — the configuration of your Queries (terms, Sources, intervals, AI instructions, rules, mute and VIP lists), your channels, your exports, and written instructions you send us
2. Roles and scope
You are Controller and we are Processor for what you decide: which terms, names and Sources a Query watches; which authors are muted or flagged; the AI instructions, buckets and rules you write; where Mentions are delivered and to whom; what you export and what you do with Mentions after they reach you.
We are Controller for what the Services do the same way for everyone: that public Mentions are collected at all, the retention windows, AI labelling, embeddings, anonymous price observations, AI-answer runs and the removal procedure for people who appear in Mentions (Privacy Policy, sections 3, 6, 7 and 8).
3. Processing details
| Item | Description |
|---|---|
| Subject matter | Monitoring public Sources for the terms you choose and handling the Mentions found. |
| Duration | While a Query is active and for 90 days after each Mention was caught; embeddings 30 days; weekly reports 52 weeks. Deleted with the Query, and at the latest at the end of these windows. |
| Nature | Collection from public Sources; storage for 90 days; AI labelling (grouping, sentiment, sorting, summaries, agent steps) and semantic embedding on your instruction; delivery to the channels you configure; export on request; deletion. |
| Purpose | Letting you know what is said in public about the names, brands, products and topics you have a legitimate interest in. |
| Types of Personal Data | As the Sources show them (Posts and comments; Videos; Feeds; AI answers; Marketplace listings): public handles and display names, the text of public posts, public engagement counters, public profile fields shown beside a post or listing. No private messages, no content behind a login, no contact details beyond what a platform displays. |
| Data Subjects | People who posted in public on a Source and whose post matched your Query; occasionally, people mentioned in such a post; recipients you add to a channel. |
4. Our obligations as Processor
- Process Personal Data within this DPA only on Customer Instructions, and tell you if we believe an instruction breaches Data Protection Laws — for example a Query aimed at a private individual (Terms, section 5.3).
- Use your Queries, instructions and Mentions for nothing of our own beyond operating and securing the Services, and never train a model on them.
- Keep them confidential, with need-to-know access to production.
- Protect them: TLS in transit, encrypted storage at the hosting provider, hashed API keys, rate limiting and monitoring, and a no-training, no-retention policy on every AI request.
- Keep Mentions for the windows in section 3 and delete them by a scheduled sweep when they age out, or earlier when you delete the Query.
- Help with Data Subject requests, impact assessments and breach handling. A person who writes to us directly is handled under our removal procedure (Privacy Policy, section 8), which removes the Mention from every Query including yours; a person who writes to you is handled on your instruction.
5. Your obligations as Controller
- Have a lawful basis for what you watch and for what you do with the result
- Watch names, brands, products and topics — not private individuals
- Add only recipients who agreed to receive Mentions
- Treat Mentions passed to your own systems as data, never as instructions (Terms, section 7.2)
- Handle Data Subject requests for the copies you hold outside Nephia
6. Sub-processors
You authorise us to engage the Sub-processors below. The same list is on the Sub-processors page.
| Provider | Purpose | What it receives | Location |
|---|---|---|---|
| OVH SAS | Hosting: servers, database, queues, backups. | Everything we store, at rest: account data, mentions and their AI labels, embeddings, reports, usage ledger, application logs in transit to the log provider. | France (EU) |
| Cloudflare, Inc. | DNS, content delivery, TLS termination and denial-of-service protection in front of the website, dashboard and API. Turnstile bot check on the sign-in form, when enabled. | Traffic in transit — Cloudflare terminates TLS, so it decrypts and re-encrypts each request — your IP address and request metadata. Nothing at rest beyond short-lived caches and security logs. | Global edge network; US company with EU points of presence |
| OpenRouter, Inc. | AI processing: grouping, sentiment, sorting, summaries, weekly reports, agent steps and semantic embeddings. | The content of mentions (text, titles, public handles) and the instructions you give a Query. Every request is routed only to model hosts that neither train on nor retain the content; OpenRouter itself keeps request metadata for billing. | United States (routing); the model host varies per request and is bound by the same policy |
| Resend, Inc. | Transactional email, and the email delivery channel. | Your email address, sign-in links and account notices. When you route a channel to email, the digests and reports it sends — which contain mentions — and the recipient addresses you configured. | United States |
| Google LLC | Sign in with Google, only when you choose it. | Email address, name, Google account id, profile picture if your account has one. | United States |
| PostHog, Inc. | Product analytics on the website and dashboard, only after you accept analytics cookies. | Page views, feature events and a visitor identifier. No mention content, no email address. Cookieless counting if you decline. | EU (Frankfurt) |
| Better Stack | Application logs and uptime monitoring. | Request metadata, account and Query identifiers, error messages. Kept 3 days. | EU (Frankfurt) |
| Sentry (Functional Software, Inc.) | Error reporting for the API and the worker. | Stack traces, request identifiers and, when an upstream response fails to parse, the fragment that failed. No account email. | EU (Frankfurt) |
| Creem | Payments, as merchant of record, once paid plans open. | Nothing during the public beta: no purchase is possible and Creem is not called. When purchases open: your email, billing identifiers, plan and invoices — stated here before the first sale. | Not active during the beta |
| Source access and network infrastructure providers | Reaching public Sources on our behalf. | The public search terms of a Query and the public content the Source returns. They receive no account data and nothing about you; we do not name them publicly, and provide the named list to a customer on written request under NDA. | Varies; each is bound by a data-processing agreement with us |
- Changes. We add a Sub-processor to the page before it receives any data and email account holders when the new provider will receive Mention content or account data. You may object within fourteen (14) days on reasonable data-protection grounds. If we cannot accommodate the objection, you may end the Services and export your data first.
- Each Sub-processor is bound by written terms at least as protective as this DPA, and we remain responsible for their performance.
7. International transfers
Personal Data is stored in France. Where a Sub-processor processes it outside the EEA or the UK, we rely on the EU–US Data Privacy Framework where the provider is certified, on Standard Contractual Clauses (and the UK IDTA where applicable) otherwise, and on supplementary technical measures.
8. Security incidents
We notify you without undue delay, and where feasible within forty-eight (48) hours, after becoming aware of a Personal Data breach affecting data in this DPA, with what we know of its nature, scope, likely consequences and the measures taken.
9. Audits
We make available the information reasonably necessary to demonstrate compliance with this DPA — this page, the Privacy Policy’s retention table, the Sub-processors list and answers to written questions. An audit beyond that requires thirty (30) days’ notice, must not unreasonably disrupt operations, and is at your expense unless it reveals a material breach by us. Findings are confidential.
10. Deletion and return
- Return: at any time, export Mentions with their labels as CSV or through the Product API (Terms, section 9).
- With the Query: deleting a Query deletes its Mentions, labels, embeddings and reports.
- By age: at the latest 90 days after a Mention was caught, whatever you do.
- With the Account: within 30 days of closure, after the 30-day export window, except where law requires us to keep related logs.
11. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where Data Protection Laws prohibit such limitation.
12. Term
This DPA applies while we process Personal Data on your instructions and, for confidentiality, deletion and liability, after that.
13. Contact
DPA and privacy enquiries, and requests for the named Source-access list: [email protected]