This Data Processing Agreement ("DPA") forms part of the Terms of Service between Connect Globa Consults ("Processor", "we") and the tenant ("Controller", "you") for personal data of your subscribers and other end-users that we process on your behalf through the Nexvora platform. Where applicable data protection law defines these roles differently, that law's definitions control.
We process personal data on your instructions for as long as needed to provide the Service under the Terms of Service, and for a reasonable wind-down period after termination for data export.
RADIUS authentication and accounting, subscriber and voucher management, captive portal operation, billing and payment reconciliation, support ticketing, and related reporting — solely to provide the Service to you.
Your network subscribers/end-users. Data types: identifiers (username, MAC/device ID), session and usage records, contact details you collect, and payment/transaction records associated with purchases they make through your captive portal or plans.
We process personal data only on your documented instructions, including as configured by you within the platform (e.g. plan definitions, captive portal terms, retention settings), unless required otherwise by law, in which case we will inform you unless legally prohibited from doing so.
Personnel authorized to process personal data are bound by confidentiality obligations.
We maintain technical and organizational measures appropriate to the risk, including: tenant data isolation via application-level scoping, encryption in transit, access controls and audit logging on the admin panel, and a shared-secret gated RADIUS bridge. You remain responsible for the security of credentials and configuration under your control.
We use sub-processors for hosting/infrastructure and payment processing (limited to the gateways you enable for your tenant). We remain responsible for sub-processors' compliance with obligations equivalent to this DPA. Current categories of sub-processor are listed in our Privacy Policy; we will notify you of material changes.
Where a subscriber contacts us directly about their data, we will refer them to you as controller and provide reasonable assistance in responding to access, correction, or deletion requests using the tools available in the platform (e.g. subscriber record management, export).
We will notify you without undue delay after becoming aware of a personal data breach affecting your subscribers' data, and provide information reasonably available to us to help you meet your own notification obligations.
Where personal data is transferred outside the country where it was collected, we apply safeguards appropriate to the transfer consistent with applicable law.
On termination of the Service, you may export your subscriber data for a reasonable period as described in the Terms of Service, after which we will delete or anonymize remaining personal data, except where retention is required by law.
On reasonable written request, and no more than once per year absent a security incident, we will provide information reasonably necessary to demonstrate compliance with this DPA.
In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.