This Data Processing Agreement (“DPA”) is incorporated into and forms part of (and if applicable, amends the current version of) the Terms of Service between Customer and/or its affiliates (“Customer”) and NEAR AI (“NEAR AI”), each a “Party” and collectively the “Parties”. This DPA applies to and takes precedence over the agreement between the Parties and any associated contractual document between the Parties, such as an order form, statement of work, or data processing agreement thereunder (collectively, the “Agreement”), to the extent of any conflict. Capitalized terms not defined herein are defined as in applicable Data Protection Laws. Customer and NEAR AI agree as follows:
For purposes of this DPA:
NEAR AI will:
NEAR AI will implement appropriate administrative, technical, physical, and organizational measures to protect Personal Data, as set forth in Schedule A, Annex II.
NEAR AI will notify Customer without undue delay of any known Security Breach resulting from NEAR AI's Processing of Personal Data on behalf of Customer. NEAR AI will comply with the Security Breach-related obligations directly applicable to it under Data Protection Laws and will provide reasonable assistance to Customer in Customer's compliance with its Security Breach-related obligations, including without limitation by:
To the extent required by applicable Data Protection Law, NEAR AI shall make available all information necessary for Customer to confirm NEAR AI's compliance with this DPA. If Customer has a reasonable basis to conclude that such information provided by NEAR AI is not satisfactory to confirm such compliance, Customer may, at Customer's sole expense, upon reasonable prior notice, conduct an audit during normal business hours and in a manner that does not disrupt NEAR AI's business of those NEAR AI systems and records relevant to NEAR AI's Processing of Personal Data on Customer's behalf. Customer shall limit its exercise of audit rights to not more than once in any twelve (12) calendar month period, unless (i) required by instruction of a Supervisory Authority; or (ii) following a Security Breach.
Except to the extent required otherwise by Data Protection Laws, upon termination or expiry of these Terms, NEAR AI will (at Customer's election and written request) delete or return all Personal Data in its possession or control as soon as reasonably practicable. Except to the extent prohibited by Data Protection Laws, NEAR AI will inform Customer if it is not able to return or delete the Personal Data.
A. List of Parties
Data exporter(s): The exporter (Controller) is Customer and Customer's contact details and signature are as provided in these Terms and the DPA.
Data importer(s): The importer (Processor) is NEAR AI and NEAR AI's contact details and signature are as provided in these Terms and the DPA.
B. Description of Transfer
Categories of data subjects whose personal data is transferred: The Personal Data transferred concerns data subjects whose information Customer makes available through its use of the services under these Terms.
Categories of personal data transferred: Any personal data provided by Customer to NEAR AI for NEAR AI to perform services under these Terms.
Sensitive data transferred (if applicable): N/A
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): On a continuous basis as needed to provide the services to Customer.
Nature of the processing: The nature of the Processing is set out in these Terms between the Parties.
Purpose(s) of the data transfer and further processing: The purposes of the data transfer is to provide the services chosen by Customer in connection with these Terms.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: The data will be retained for the time period needed to accomplish the purposes of Processing, unless otherwise required by applicable law.
For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing: Same as above to the extent that Personal Data is provided to Subprocessors for purposes of providing the services under these Terms to Customer.
C. Competent Supervisory Authority
Identify the competent supervisory authority/ies in accordance with Clause 13: The data exporter's competent supervisory authority will be determined in accordance with the GDPR, and where possible, will be the Irish Data Protection Commissioner.
NEAR AI, as Provider, will implement and maintain the following administrative, technical, physical, and organizational security measures for the Processing of Personal Data: Provider must maintain an effective Information Security Program (in line with industry standards such as ISO 27001, etc.) and security measures requirements while handling Personal Data and confidential information of the Disclosing Controller including but not limited to the below requirements.
Security policies and procedures: Provider shall maintain a management approved documented Information Security Policy and an established security risk management process to continually assess and evaluate new security risk and manage them through adequate security controls or safeguards.
Confidentiality, Integrity and Availability: Provider shall maintain confidentiality, integrity and availability of the Personal Data disclosed to it by the Disclosing Controller by identifying assets that store, process or transmit such data and deploying adequate technical and organization measures such as, but not limited to, data encryption, physical and logical access control, strong password control, malware and content protection, security vulnerability assessment and patching, secure hardening, network/data segregation controls.
Vulnerability management: Wherever applicable, Provider must ensure that any software component (such as code or API) provided to Provider is free for any security vulnerability or issues and ensure security of data processed using such component.
Incident Handling: In the event of a confirmed personal data breach (as defined by Applicable Data Protection Law), Provider must inform the Disclosing Controller about any impact to its Personal Data promptly and designate a security point of contact (POC) to interact and notify the Disclosing Controller on security matters.
Notification obligation: Any operational change that impacts the security of the Disclosing Controller's Personal Data and confidential information or systems that handles such data must be notified to the Disclosing Controller without undue delay.
Secure destruction of data: At the end of the Existing Agreement or as otherwise in accordance with Annex A (Description of Processing), on Disclosing Controller's request, the Provider must destroy all Personal Data disclosed or authorized to be collected by the Disclosing Controller in a secure manner making the Personal Data un-readable and un-recoverable. If the Personal Data cannot be deleted, the Personal Data must be archived and protected from unauthorized access, modification, and disclosure until securely deleted. The Disclosing Controller at its discretion may request for a data destruction certification that includes method of data destruction used.
Security risk management program relating to Third Parties: The Provider will ensure a similar level of security controls wherever the Personal Data disclosed or authorized to be collected by the Disclosing Controller is exchanged with a third party.
Encryption: To the extent the Personal Data disclosed by the Disclosing Controller includes sensitive data (as defined by Applicable Data Protection Laws), Provider will ensure that such Personal Data is encrypted at rest and in transit.
The Parties agree that the following list of Subprocessors are approved:
| Name of Sub-processor | Processing Activities | Location of Processing |
|---|---|---|
| Amazon Web Services, Inc. (S3) | Infrastructure | United States |
| Corvex, Inc. | Infrastructure | United States |
| OVH SAS | Infrastructure | United States |
| Google LLC | Infrastructure/LLM Provider/Authentication | United States |
| Railway Corporation | Infrastructure | United States |
| Vercel Inc. | Infrastructure | United States |
| Cloudflare, Inc. | Network/Security | Nearest data centre to end-user (global) |
| Github, Inc. | Authentication | United States |
| Plus Five Five, Inc. (Resend Email) | Email Provider | United States |
| Stripe, Inc. | Payments | Nearest data centre to end-user (global) |
| Hot Labs | Payments | Decentralized network |
| Datadog, Inc. | Observability | United States |
| PostHog, Inc. | Observability | United States |
| Anthropic PBC | Inference | United States |
| Slack Technologies Inc. | Customer Communication | United States |
| Crisp IM SAS | Customer Support | EU |
| OpenAI | LLM Provider | United States |
| Chutes Global Corp | LLM Provider | Decentralized network |
| Anthropic PBC | LLM Provider | United States |
| OpenRouter, Inc. | AI Model Routing and Inference Services | United States for OpenRouter systems; downstream model-provider locations vary by selected model/provider. |
| Brave Software, Inc. | Search | United States |