Data Processing Agreement

Nextbit256 S.L. — Standard Data Processing Agreement

Effective Date: May 2026 | Version 1.0


1. Parties

This Data Processing Agreement ("DPA") is between:

Processor: Nextbit256 S.L., incorporated under the laws of Spain, with registered address at Carrer del Moll de la Duana, s/n, Edificio Lanzadera, 46024 Valencia, Spain ("Nextbit"); and

Controller: the legal entity or individual that accesses or uses the Services ("Customer" or "Controller").

This DPA forms part of and is subject to the Nextbit Terms of Service available at https://www.nextbit256.com/docs/terms-of-service ("Terms of Service"). By using the Services to process personal data of third parties, the Controller accepts this DPA in full.


2. Definitions

Terms used in this DPA have the meanings given in Regulation (EU) 2016/679 ("GDPR") and, where applicable, Spanish Organic Law 3/2018 (LOPDGDD). Additionally:

  • "Services" means the Public API inference services provided by Nextbit, as described in the Terms of Service.
  • "Applicable Data Protection Law" means the GDPR, the LOPDGDD, and any other data protection legislation applicable to the processing described herein.
  • "Subprocessor" means any third party engaged by Nextbit to process Personal Data in connection with the provision of the Services.

3. Scope and Instructions

Nextbit processes Personal Data solely in connection with the provision of the Services, in accordance with its standard practices as described in the Privacy Policy and this DPA.

Instructions from the Controller that deviate from those standard practices are only binding on Nextbit if incorporated into a separate written agreement signed by both parties. No instruction submitted by email, support ticket, platform message, or any other channel shall modify Nextbit's obligations under this DPA or otherwise bind Nextbit absent such a signed agreement.

The Controller is solely responsible for the lawfulness of all processing performed on its behalf, including ensuring that a valid legal basis exists for each processing activity and that data subjects have received adequate privacy notices. Nextbit has no obligation to verify the Controller's compliance.


4. Nature and Purpose of Processing

FieldDetail
Subject matterAI inference: processing of inputs submitted via the Services and generation of model outputs
DurationTerm of the Terms of Service, plus applicable retention periods under Section 10
NatureAutomated processing of input and output data through AI inference infrastructure operated by Nextbit
PurposeProvision of the Services as requested by the Controller; operational maintenance and performance improvement as further described in Section 10
Types of personal dataAny personal data included by the Controller in API inputs; account and usage data; technical and operational data generated by use of the Services
Categories of data subjectsAny individuals whose personal data is included in data submitted by the Controller through the Services

5. Obligations of Nextbit

Nextbit shall:

  • Instructions. Act only on acknowledged instructions from the Controller as defined in Section 3. Where no acknowledged instruction applies, process in accordance with this DPA and the Privacy Policy.
  • Confidentiality. Ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
  • Security. Implement technical and organizational measures appropriate to the risk presented by the processing. The description of current measures is maintained in the Privacy Policy and may be updated from time to time.
  • Subprocessors. Engage Subprocessors in accordance with Section 7.
  • Data subject rights. Assist the Controller in responding to data subject rights requests under Applicable Data Protection Law, within 45 business days of receiving a written request from the Controller. Nextbit's assistance is limited to information technically available to it; the Controller remains solely responsible for responding to data subjects.
  • DPIA assistance. Provide such technical information as is reasonably available to Nextbit to assist the Controller in conducting a Data Protection Impact Assessment, if requested. The DPIA is the Controller's sole responsibility.
  • Breach notification. Notify the Controller within 48 hours of becoming aware of a personal data breach affecting the Controller's data, including: the nature of the breach, approximate categories and number of individuals affected, and measures taken or proposed. The Controller is responsible for notifying the competent supervisory authority within 72 hours and, where required, affected data subjects.
  • Data return and deletion. As described in Section 10.
  • Audit rights. As described in Section 11.

6. Obligations of the Controller

The Controller warrants and represents that it:

  • Has a valid legal basis under Applicable Data Protection Law for all processing it causes Nextbit to perform.
  • Will not use the Services to process Special Categories of Personal Data (Article 9 GDPR) without executing a separate addendum with Nextbit prior to such processing.
  • Has provided, and will maintain, adequate privacy notices to data subjects whose data is processed through the Services.
  • Will give instructions only in writing and acknowledges that instructions are only binding on Nextbit upon Nextbit's express written acknowledgment.
  • Is solely responsible for its compliance with Applicable Data Protection Law, including its obligations as provider or deployer of AI systems under Regulation (EU) 2024/1689 (AI Act).
  • Is solely responsible for the acts and omissions of its users, agents, and end-users in connection with the Services.
  • Will indemnify Nextbit against any claims, fines, or damages arising from the Controller's failure to comply with any of the above warranties.

7. Subprocessors

The Controller grants Nextbit general written authorization to engage any Subprocessors that Nextbit determines appropriate for the provision of the Services, without restriction as to identity, number, or location. Nextbit is under no obligation to publish or maintain a public list of Subprocessors.

The Controller may request information about current Subprocessors by submitting a written request to [email protected]. Nextbit will respond at its sole discretion and without any committed timeframe.

Nextbit will notify Controllers of material Subprocessor changes (additions or replacements) by updating this DPA or the Terms of Service and publishing the revised version on its website. Continued use of the Services following such publication constitutes acceptance of the change.

If the Controller objects to a Subprocessor change, it must notify Nextbit in writing at [email protected] within 30 days of the update publication and must cease using the Services. Nextbit is not obligated to remove the Subprocessor or to continue providing the Services to an objecting Controller.

Nextbit will impose data protection obligations on Subprocessors materially equivalent to those in this DPA.


8. International Data Transfers

Nextbit may transfer or permit the processing of Personal Data outside the European Economic Area ("EEA") to the extent necessary for the provision of the Services. Such transfers are made subject to appropriate safeguards, primarily Standard Contractual Clauses ("SCCs") approved by the European Commission, and where additionally applicable, the EU–US Data Privacy Framework ("DPF") for US-based Subprocessors that have self-certified thereunder.

The Controller acknowledges that certain Subprocessors may be incorporated or operate in the United States and may be subject to US legislation, including the CLOUD Act (2018) and FISA Section 702, which may permit US authorities to compel access to data regardless of its physical location. This exposure cannot be fully excluded by contractual measures. For a full description of these risks, see the Privacy Policy and Terms of Service.

To the extent permitted by applicable law, Nextbit will notify the Controller of any governmental request for access to the Controller's data and will use reasonable efforts to challenge requests it considers disproportionate before complying.

Controllers for whom US government access represents a material risk should contact [email protected] to discuss alternative arrangements.


9. Security

Nextbit implements technical and organizational security measures appropriate to the level of risk presented by the processing, including measures to protect against unauthorized access, disclosure, alteration, or destruction of Personal Data. The description of current measures is set out in the Privacy Policy and may be updated by Nextbit from time to time without notice. No specific security commitments are made in this DPA.


10. Data Retention and Operational Processing

Technical and operational data generated by use of the Services — including usage metrics, system logs, and operational indicators associated with API calls — may be retained by Nextbit for up to 90 days and may be processed for the purposes of service maintenance, diagnostics, and improvement of service performance and reliability. The legal basis for this processing is Nextbit's legitimate interest under Article 6(1)(f) GDPR. This processing does not constitute AI model training of any kind.

Nextbit does not use Personal Data submitted by the Controller to train, fine-tune, or otherwise adapt any AI model.

Upon termination of the Terms of Service, Nextbit will delete the Controller's Personal Data within 60 calendar days, provided the Controller requests deletion in writing prior to expiry of that period. Absent a written request, Nextbit will delete the data within 60 calendar days of termination by default. Nextbit may retain anonymized or aggregated data without time limitation.

The Controller may not require deletion within a shorter timeframe. The 60-day period is the standard contractual term applicable under this DPA and is not subject to negotiation hereunder.


11. Audit Rights

The Controller's rights under Article 28(3)(h) GDPR to obtain information demonstrating Nextbit's compliance with this DPA are exercised exclusively through written requests submitted to [email protected]. Nextbit will, at its sole discretion, determine what information, if any, to provide in response and within what timeframe. Nextbit is under no obligation to respond within any specified period or to provide any particular document or information.

Nextbit may satisfy audit requests by providing: responses to written questionnaires, third-party certifications or any other information Nextbit considers sufficient in the circumstances.

The following are expressly excluded, absent Nextbit's prior written consent on a case-by-case basis: physical access to Nextbit's premises or data centers; remote access to Nextbit's production systems; inspection of infrastructure configurations, source code, or logs; and any form of audit requiring active personnel time from Nextbit.

Controllers requiring broader audit rights should contact [email protected] before using the Services. Nextbit has no obligation to grant such rights. If no satisfactory arrangement is reached, the Controller should not use the Services.


12. Special Categories of Personal Data

The Services are not designed or intended for the processing of Special Categories of Personal Data as defined in Article 9 GDPR (including, without limitation: health data, genetic data, biometric data used for unique identification, data concerning racial or ethnic origin, political opinions, religious beliefs, or data concerning sexual orientation or sex life).

The Controller must not submit Special Categories of Personal Data through the standard Services. If the Controller's use case requires such processing, it must notify Nextbit at [email protected] and execute a separate written addendum before initiating any such processing. The Controller warrants that it holds a valid legal basis under Article 9(2) GDPR for any such processing.

The Controller shall indemnify Nextbit against any liability, fines, or costs arising from the Controller's transmission of Special Categories of Personal Data through the Services without an executed addendum.


13. AI Act

The Controller acknowledges that it acts as the provider or deployer of any AI system deployed through the Services under Regulation (EU) 2024/1689 ("AI Act"), and assumes all obligations arising from that role, including without limitation documentation requirements, conformity assessments, transparency obligations, and supervisory authority reporting. Nextbit acts solely as a technical operator of inference infrastructure and does not assume any obligations of a provider or deployer under the AI Act as a result of the Controller's use of the Services. The Controller is solely responsible for compliance with the AI Act vis-à-vis its users and competent supervisory authorities.


14. Term and Termination

This DPA is effective for the duration of the Terms of Service and terminates automatically upon termination of the Terms of Service, subject to the data retention obligations in Section 10 and the survival of confidentiality obligations for a period of three (3) years following termination.


15. Liability

The liability of each party under this DPA, including in respect of any claims under Article 82 GDPR, is subject to the limitations, exclusions, and caps set out in the Terms of Service. Nextbit's total aggregate liability under or in connection with this DPA shall not exceed the greater of €100 or the total amounts paid by the Controller to Nextbit in the six (6) months preceding the event giving rise to the claim.

Nextbit is not liable for: (i) any processing carried out on the basis of instructions that Nextbit has not expressly acknowledged; (ii) any disclosure of data to public authorities resulting from legal obligations imposed on Nextbit or its infrastructure providers under applicable law, including US federal law; or (iii) any damages arising from the Controller's breach of its warranties or obligations under this DPA or Applicable Data Protection Law.


16. Governing Law

This DPA is governed by and construed in accordance with the laws of the Kingdom of Spain. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Valencia, Spain, unless mandatory provisions of law applicable in the Controller's jurisdiction provide otherwise.


17. Contact and Acceptance

This DPA applies automatically to all Controllers who use the Services to process Personal Data of third parties. No separate signature is required for the standard terms set out herein.

Controllers who require a separately negotiated or countersigned version of this DPA may contact [email protected]. Nextbit has no obligation to negotiate or execute a customized DPA. The Controller may download and retain this document as evidence of the terms applicable at the date of use.

For all data protection queries: [email protected]


This DPA is incorporated into and forms part of the Nextbit Terms of Service (https://www.nextbit256.com/docs/terms-of-service). In case of conflict, the ToS prevails except where this DPA specifically provides greater protection for personal data.

Was this page helpful?