Preamble & Binding Scope of DPA
Effective Date: March 16, 2026. This Data Processing Addendum (“DPA”) supplements the NexFyla Terms of Service between Nexfyla LLC (“Processor” or “NexFyla”) and the customer agreeing to these terms (“Controller” or “Customer”). This DPA governs the processing of Personal Data in compliance with Article 28 of the General Data Protection Regulation (EU GDPR), UK GDPR, Swiss FADP, and applicable U.S. data privacy legislation.
1. Scope, Purpose & Processing Instructions
NexFyla processes Personal Data solely on behalf of and in accordance with the documented instructions of the Customer, specifically for the execution of U.S. company formation filings, IRS tax submissions, registered agent representations, and portal account management.
2. Technical & Organizational Security Measures (TOMs)
NexFyla implements and maintains robust technical and organizational measures designed to protect Personal Data against unauthorized access, destruction, loss, or disclosure:
- Industry-standard encryption of data at rest (AES-256) and data in transit (TLS 1.3).
- Role-based access authorization, multi-factor authentication (MFA), and audit logging.
- System redundancy, automated daily backups, and disaster recovery procedures.
- Confidentiality agreements executed by all personnel and sub-processors with data access.
3. Sub-Processors
Customer provides general authorization for NexFyla to engage qualified third-party sub-processors to assist in delivering the Services (including cloud hosting via AWS/Supabase, payment processing via Stripe, and transactional communications). NexFyla imposes equivalent data protection obligations on all sub-processors.
4. Cross-Border Data Transfers
Where personal data originating in the EEA, UK, or Switzerland is transferred to the United States or other third countries without an adequacy decision, the parties agree to be bound by the European Commission's Standard Contractual Clauses (SCCs) (Module 2: Controller to Processor).
5. Security Incident Notification
In the event of a confirmed personal data breach affecting Customer data, NexFyla will notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach) and provide reasonable assistance in fulfilling statutory regulatory notification obligations.
6. Data Deletion & Return
Upon termination of the Services, NexFyla shall, at Customer's choice, delete or return all Personal Data, unless applicable European Union, United States federal, or state law mandates retention of corporate and tax filing records.