Data Processing Addendum (DPA)
Download PDFLast updated: December 4, 2025
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement governing the use of the Novara platform (the "Agreement") between the Novara customer identified in the Agreement ("Customer", "Controller") and Novara International ("Novara", "Processor").
1. Purpose and Scope
1.1 This DPA applies to Novara's Processing of Personal Data on behalf of Customer in connection with the provision of the Services under the Agreement.
1.2 The Parties intend this DPA to satisfy the requirements of applicable Data Protection Laws, including (where applicable) the EU and UK General Data Protection Regulation ("GDPR"), in respect of the Processing of Personal Data.
1.3 In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the subject matter herein.
2. Definitions
2.1 "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" have the meanings given in the GDPR.
2.2 "Data Protection Laws" means all laws and regulations relating to data protection and privacy applicable to the Processing of Personal Data under the Agreement, including, where applicable, the GDPR, the UK GDPR and Data Protection Act, and similar laws.
2.3 "Services" means the services provided by Novara to Customer under the Agreement, including the Novara sourcing and collaboration platform.
2.4 "Sub-Processor" means any third party engaged by Novara to Process Personal Data on behalf of Customer in connection with the Services.
3. Roles of the Parties
3.1 For the purposes of Data Protection Laws, Customer is the Controller and Novara is the Processor with respect to the Processing of Personal Data described in Annex 1.
3.2 Customer determines the purposes and means of Processing of Personal Data. Novara shall Process Personal Data only on behalf of Customer and in accordance with this DPA and Customer's documented instructions.
4. Customer Responsibilities
4.1 Customer is responsible for ensuring that:
- (a) it has a valid legal basis for Processing the Personal Data and for authorizing Novara to Process the Personal Data on its behalf;
- (b) the instructions it provides to Novara comply with Data Protection Laws;
- (c) Data Subjects are provided with all information required by Data Protection Laws.
4.2 Customer shall not instruct Novara to Process Personal Data in a manner that would cause Novara to breach Data Protection Laws. Novara may inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
5. Novara's Obligations
Novara shall:
5.1 Process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law. In such case, Novara shall inform Customer of that legal requirement unless the law prohibits such information.
5.2 Ensure that persons authorized to Process Personal Data are subject to appropriate confidentiality obligations.
5.3 Implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing.
5.4 Assist Customer, taking into account the nature of the Processing and the information available to Novara, in fulfilling Customer's obligations to respond to Data Subjects' requests to exercise their rights under Data Protection Laws.
5.5 Assist Customer in ensuring compliance with Customer's obligations relating to security of Processing, Personal Data Breach notifications, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the Processing and the information available to Novara.
6. Sub-processors
6.1 Customer provides general authorization for Novara to engage Sub-Processors to Process Personal Data on behalf of Customer, subject to the requirements in this section.
6.2 Novara shall maintain a list of Sub-Processors and make it available to Customer upon request.
6.3 Novara shall impose data protection obligations on any Sub-Processor that are no less protective than those in this DPA.
7. Security Measures
Novara shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate: (a) pseudonymization and encryption of Personal Data; (b) the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems; (c) the ability to restore availability and access to Personal Data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures.
8. Data Subject Rights
Novara shall, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising Data Subject rights under Data Protection Laws.
9. Data Breach Notification
9.1 Novara shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of Customer.
9.2 Such notification shall include, to the extent known: (a) the nature of the Personal Data Breach; (b) the categories and approximate number of Data Subjects and Personal Data records concerned; (c) the likely consequences of the Personal Data Breach; (d) measures taken or proposed to address the Personal Data Breach.
10. International Transfers
Where Personal Data is transferred outside the European Economic Area, UK, or Switzerland, Novara shall ensure that appropriate safeguards are in place in accordance with Data Protection Laws, such as Standard Contractual Clauses approved by the European Commission or other lawful transfer mechanisms.
11. Term and Termination
11.1 This DPA shall remain in effect for as long as Novara processes Personal Data on behalf of Customer under the Agreement.
11.2 Upon termination of the Agreement, Novara shall, at Customer's choice, delete or return all Personal Data to Customer, unless applicable law requires retention of the Personal Data.
12. Contact Information
For questions about this DPA, please contact our Data Protection Officer at:
Novara International
30 N Gould St Ste N
Sheridan, WY 82801 USA
Email: dpo@novaraint.com