NevTan Engage

Features

Email MarketingSMS MarketingAutomations

Solutions

eCommerceSaaS & AppsB2B Lead GenAgencies

Resources

BlogHelp CenterDocumentationEmail TemplatesAPIFAQs

Company

AboutPricingContact

Legal

Data Processing AgreementSubprocessor ListAI & Data Usage PolicySecurity & Compliance

© 2026 NevTan Engage. All rights reserved.

Cookie Policy | Terms and Conditions | Privacy Policy

Skip to main content

Channels & Automation

Email Marketing

Beautiful campaigns that convert

SMS Marketing

Reach customers instantly

Automations

Visual drag-and-drop workflows

By Industry

eCommerce

Boost sales & reduce cart abandonment

SaaS & Apps

Onboard & retain users at scale

B2B Lead Gen

Nurture leads to conversion

Agencies

White-label for your clients

Plans & Pricing

Pricing Plans

Simple, transparent pricing

Learn & Build

Blog

Marketing tips and best practices

Email Marketing Templates

Ready-to-use campaign layouts

Documentation

Guides for every feature in Engage

API

Build custom integrations

About Us

Contact Us

LoginStart Free Trial(No card)

NEVTAN ENGAGE

Data Processing Agreement (DPA)

Last Updated: June 5, 2026


This Data Processing Agreement (“DPA”) is entered into between Nevtan Inc. (“Engage”, “Processor”) and the Customer identified in the applicable subscription agreement, order form, or terms of service (“Controller”, “Customer”). This DPA forms part of, and is incorporated by reference into, the NevTan Engage Terms and Conditions or such other written agreement between the parties (the “Services Agreement”). In the event of conflict, this DPA prevails on data protection matters.

1. Definitions

  • “Applicable Data Protection Laws” means all data protection and privacy laws applicable to the parties and the processing activities under this DPA, including the GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, and any other applicable law.
  • “Personal Data” means any information relating to an identified or identifiable individual.
  • “Controller” means the entity determining the purposes and means of processing. In this DPA, ordinarily the Customer.
  • “Processor” means the entity processing Personal Data on behalf of the Controller. In this DPA, Engage.
  • “Data Subject” means the individual to whom Personal Data relates.
  • “Personal Data Breach” means unauthorized access to, disclosure, alteration, or destruction of Personal Data.
  • “Subprocessor” means any third party engaged by Engage to process Personal Data on behalf of the Customer.
  • “Standard Contractual Clauses (SCCs)” means the clauses adopted by the European Commission under Decision 2021/914, and the UK International Data Transfer Addendum as applicable.

2. Roles of the Parties

2.1 Customer as Controller

Customer determines the purposes and means of processing Personal Data through the Services and is responsible for: lawful collection and transfer of Personal Data to Engage; obtaining all required consents; ensuring the lawfulness of instructions; and responding to Data Subject requests.

Where Customer itself acts as a Processor for a third-party Controller, Customer represents it has obtained all necessary authorizations to appoint Engage as a sub-processor.

2.2 Engage as Processor

Engage processes Personal Data only on documented instructions from Customer, to the extent necessary to provide the Services, and as required by Applicable Data Protection Laws.

3. Nature, Purpose, and Duration

The subject matter, nature, purpose, duration, data categories, and data subjects are set out in Schedule A of this DPA. This DPA remains in effect for the duration of the Services Agreement.

4. Security Measures

Engage implements and maintains appropriate technical and organizational measures including: TLS 1.2+ encryption in transit and AES-256 encryption at rest; multi-factor authentication and role-based access control; 24/7 security monitoring and audit logging; network segmentation and DDoS protection; encrypted backups with geographically distributed storage; and documented incident response procedures. Details are published at engage.nevtan.com/legal/security-compliance.

5. Personal Data Breach Notification

Engage will notify Customer within 48 hours of confirming a Personal Data Breach affecting Customer's Personal Data. Notifications will include: the nature of the breach, categories of data and data subjects affected, steps taken to contain and remediate, and a designated contact for further information. Engage acknowledges that Customers may be required to notify supervisory authorities within 72 hours under GDPR; the 48-hour commitment provides Customers sufficient lead time.

6. Assistance with Data Subject Rights

Engage will provide reasonable technical assistance to enable Customer to respond to Data Subject requests for access, correction, deletion, restriction, portability, and objection. Customer remains solely responsible for responding. Where a Data Subject submits a request directly to Engage, Engage will forward it to Customer without responding independently.

7. Subprocessors

7.1 General Authorization

Customer provides general written authorization for Engage to engage Subprocessors. Engage ensures each Subprocessor is bound by equivalent data protection obligations.

7.2 Subprocessor List and Changes

Engage maintains a current Subprocessor list at engage.nevtan.com/legal/subprocessors. Engage provides at least 30 days' advance notice of new or replacement Subprocessors. Customer may object within 14 days on reasonable data protection grounds. If unresolved within 30 days, Customer may terminate the affected Services without penalty with a pro-rata refund of prepaid fees.

7.3 Engage Responsibility

Engage remains fully liable to Customer for each Subprocessor's compliance with data protection obligations.

8. International Data Transfers

Where Personal Data is transferred outside the Customer's jurisdiction, Engage relies on appropriate safeguards including: EU Standard Contractual Clauses (Module 2: Controller→Processor and Module 3: Processor→Sub-Processor) including the UK IDTA addendum where required; adequacy decisions recognized by applicable regulators; and Data Processing Agreements with equivalent protections. Executed SCCs are available at engage.nevtan.com/legal/dpa or upon request to privacy@engage.nevtan.com.

9. AI Processing

Where Customers use AI-powered features:

  • (a) Customer retains full ownership of all Customer Data;
  • (b) Customer Data is not used to train publicly available AI models without express written opt-in;
  • (c) one Customer's data is never used to train AI systems for another Customer;
  • (d) Customer Data is not sold to or shared with AI vendors for unrelated purposes;
  • (e) AI inference is processed under zero data retention agreements with providers.

10. CCPA / CPRA Service Provider

To the extent Customer is subject to the CCPA/CPRA, Engage is a “Service Provider” as defined thereunder. Engage will not sell or share Personal Data; will not retain, use, or disclose Personal Data outside the direct business relationship; and will not combine Customer Personal Data with data from other sources except as permitted by law.

11. Audit Rights

No more than once per calendar year (unless a breach has occurred), Customer may request compliance verification. Engage will respond by providing security certifications, audit reports, compliance questionnaire responses, or written answers. If documentation is insufficient, Customer may commission an independent third-party audit at its own cost upon 30 days' written notice, conducted during business hours with minimal operational disruption.

12. Data Retention and Deletion

Account data is retained for the duration of the Services Agreement plus 90 days post-termination, during which Customer may export data. After 90 days, Customer Data is permanently deleted from production systems. Backup copies may persist for up to 90 days before purging. Upon request, Engage will provide written certification of deletion. Legal hold may extend retention for the duration of any relevant proceeding.

13. Liability

Each party's liability under this DPA is subject to the exclusions and caps in the Services Agreement. Each party is liable to Data Subjects and authorities for its own breaches of Applicable Data Protection Laws. A party paying compensation attributable to the other party's breach may recover that portion from the other party.

14. Governing Law and Severability

This DPA is governed by the law specified in the Services Agreement. To the extent required by Applicable Data Protection Laws, the mandatory provisions of such laws prevail. The SCCs in Schedule B are governed by the law specified therein. For the avoidance of doubt, the governing law of the SCCs operates independently and is not overridden by the governing law of this DPA. If any provision of this DPA is invalid, the remainder continues in full force. This DPA terminates upon expiry or termination of the Services Agreement. Sections 4, 12, 13, and 14 survive termination.

15. Schedule A — Processing Details

FieldDetails
Subject matterProcessing of Personal Data by Engage in the course of providing multi-channel marketing automation and customer engagement services.
NatureCollection, storage, organization, analysis, use, transmission, delivery tracking, reporting, and deletion of Personal Data.
PurposeTo enable Customer to conduct marketing automation, manage customer relationships, send and track communications, and use analytics and AI features.
DurationTerm of the Services Agreement plus the 90-day post-termination retention period.

A.1 Categories of Data Subjects

CategoryDescription
Customers / end usersIndividuals who purchase from or interact with Customer's business.
Prospects and leadsIndividuals who have expressed interest in Customer's products or services.
SubscribersIndividuals subscribed to Customer's email, SMS, or other communications.
Website visitorsIndividuals who visit Customer's website or landing pages hosted through the Services.
Business contactsContacts in Customer's B2B CRM or contact database.

A.2 Categories of Personal Data

CategoryExamples
IdentificationFull name, username, email address, phone number.
Contact informationMailing address, city, region, country, postal code.
Marketing and preferenceCommunication preferences, subscription status, opt-in/opt-out records, campaign interactions.
Technical and deviceIP address, browser type, device type, operating system, authentication logs.
TransactionalPurchase history, order data, customer lifecycle events.
Customer-definedAny Personal Data uploaded via custom fields, CSV imports, API integrations, or form submissions.
AI-processedUser prompts, campaign content, and engagement metrics processed through AI features.

A.3 Special Categories

Unless explicitly agreed in writing, Customer shall not upload or process special category Personal Data (health data, racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, sexual orientation, or criminal records) or data relating to children below the applicable age of digital consent.

A.4 Subprocessors

Current Subprocessors are listed at engage.nevtan.com/legal/subprocessors. Categories include: cloud infrastructure, email delivery, SMS/messaging delivery, WhatsApp Business, analytics, security monitoring, payment processing, AI/ML services, and customer support.

A.5 Transfer Mechanisms

Transfer RouteMechanism
EEA → Countries with Adequacy DecisionEU adequacy decision (Article 45 GDPR)
EEA → Other third countriesStandard Contractual Clauses (Module 2 / Module 3)
UK transfersUK International Data Transfer Agreement (IDTA) / UK Addendum to SCCs
Other transfersSCCs or equivalent lawful mechanism as applicable

16. Schedule B — SCC Execution Instructions

Where Personal Data is transferred from the EEA or UK and SCCs are required, the parties incorporate by reference the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914 (Module 2: Controller to Processor). Key options:

  • Clause 9 — General written authorization; 30 days' notice of Subprocessor changes.
  • Clause 17 — Governing law: the law of the EU Member State in which the Customer is established, or Ireland if Customer is not established in the EEA.
  • Clause 18 — Choice of forum: courts of the applicable EU Member State, or Ireland.
  • Annex I.B — Description of Transfer: as set out in Schedule A of this DPA.
  • Annex II — Technical and organizational measures: as described at engage.nevtan.com/security.

For UK transfers, the parties incorporate by reference the UK International Data Transfer Addendum (Version B1.0) issued by the UK ICO. Customers may obtain countersigned SCCs at engage.nevtan.com/legal/dpa or by emailing privacy@nevtan.com.

17. Contact

Privacy Officer
Email: privacy@nevtan.com

Security Team
Email: security@nevtan.com

Legal Team
Email: legal@nevtan.com