Bearings · Legal · Template

Data Processing Addendum (Template)

Version 1.0Last updated 2026-08-07Effective 2026-08-14
This is a template. Enterprise customers who require a countersigned DPA before starting a subscription should request one from legal@nerdrums.com — Nerdrums will return a filled-and-signed copy of this template on the customer's own paper if needed. The text below states what Nerdrums commits to under a countersigned DPA. Customers on the standard monthly plan are governed by the Terms and Privacy Addendum without executing this DPA separately.

1. Definitions

  • Agreement — the Bearings order form or subscription that references this DPA.
  • Customer Data — content the Customer uploads to a Bearings workspace and the artifacts derived from it (extracted text, chunks, embeddings, entities, Navigator turns, audit rows).
  • Controller, Processor, Sub-processor, Personal Data, Data Subject, Processing — as defined in applicable data-protection law (GDPR / UK GDPR / CCPA / state analogues), as applicable.

2. Roles + scope

Customer is the Controller of Customer Data. Nerdrums acts as Processor and processes Customer Data on Customer's documented instructions solely to provide the Bearings service (as described in the Agreement, the Privacy Addendum, and this DPA). Any additional processing outside this scope requires Customer's written instruction.

3. Confidentiality

Nerdrums personnel with access to Customer Data are subject to written confidentiality obligations at least as protective as those in the Agreement, and access is limited to individuals with a business need.

4. Security measures

Nerdrums maintains the technical and organizational security measures documented in the Privacy Addendum §8 and the Portolan Security page. Highlights:

  • Encryption at rest for all Customer Data using Nerdrums-managed CMEK backed by Google KMS.
  • TLS 1.2+ for all data in transit.
  • Row-Level Security in Postgres + workspace-filtered Cypher in Neo4j + workspace-scoped collections in Qdrant.
  • ClamAV malware scan on every evidence upload prior to any downstream processing.
  • Immutable audit ledger for every mutation, retained per the workspace's configured retention window (default 7 years).
  • Nine boot-time gates that fail the API pod closed if any Bearings-critical secret or dependency is missing in production.

5. Sub-processors

Nerdrums engages the sub-processors listed in the Privacy Addendum §6 (Google Cloud Platform, Anthropic, OpenAI, Neo4j Aura, Qdrant, Stripe). Nerdrums will notify Customer at least 30 days before adding a new sub-processor with access to Customer Data. Customer may object in writing on reasonable, data-protection-related grounds; the parties will negotiate in good faith to address the objection, or Customer may terminate the affected workspace with a prorated refund of prepaid fees.

5a. Anthropic (Navigator LLM)

Nerdrums is enrolled in Anthropic's Zero-Data-Retention (ZDR) program for Claude Sonnet 5. Under ZDR, Customer Data included in inference prompts and completions is not retained by Anthropic beyond the inference transaction and is not used to train any model. Nerdrums will maintain ZDR enrollment for as long as it uses Anthropic as a Navigator provider under this DPA and will notify Customer if the enrollment status changes.

5b. OpenAI (embedding)

Nerdrums operates under OpenAI's no-training-on-API-data commitment for enterprise API traffic. Embedding inputs are not retained by OpenAI beyond the inference transaction and are not used to train any OpenAI model.

6. International transfers

All Customer Data is processed in the United States (GCP region us-central1) at MVP. For Customers subject to international-transfer rules (EU/UK GDPR, Swiss FADP), Nerdrums will execute the current EU Standard Contractual Clauses (Module 2, Controller-to-Processor) as an appendix to this DPA on request. The Clauses take precedence over any inconsistent term in this DPA to the extent of the inconsistency.

7. Data-subject requests

Nerdrums will, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as this is possible, to respond to requests by Data Subjects to exercise their rights. Where Customer directs, Nerdrums will export, rectify, or delete Customer Data on Customer's behalf within a reasonable time (typically 30 days for deletion; sooner where technically feasible).

8. Personal-data breach notification

Nerdrums will notify Customer without undue delay, and in any event within 72 hours of confirmation, upon becoming aware of a confirmed personal-data breach affecting Customer Data, and will provide the information reasonably required for Customer to meet its own notification obligations. Notification is delivered to the workspace Owner via email and to the DPA notice address named in the order form (if any).

9. Audits

Nerdrums makes available to Customer, on written request no more than once every 12 months, the most recent Bearings security-posture packet and independent audit reports applicable to the service (as available). Customer may request a written response to a reasonable audit questionnaire; on-site audits require prior written agreement, at Customer's expense, and are subject to Nerdrums' security policies.

10. Deletion at end of provision of services

On termination of the Agreement or on Customer's written request during the term, Nerdrums will delete Customer Data from active systems within 30 days, subject to (i) audit rows already archived to a WORM bucket, which remain until their retention expiry per the Privacy Addendum §5, and (ii) any legal-hold obligations under applicable law, in which case the affected data remains subject to confidentiality and security obligations under this DPA until deleted.

11. Precedence

This DPA supplements the Agreement and prevails in the event of conflict on data-protection matters. Nothing in this DPA reduces protections that would otherwise apply to Data Subjects under applicable law.

Bearings is not FedRAMP-authorized at launch and cannot represent FedRAMP or CMMC coverage. Do NOT include Controlled Unclassified Information, Controlled Defense Information, ITAR-controlled technical data, or classified material in Customer Data. See the Acceptable Use Policy for the full posture.

12. Contact

DPA execution + amendment — legal@nerdrums.com. Data-subject and privacy correspondence — privacy@nerdrums.com. Security disclosures — security@nerdrums.com.