Skip to content
TTermnova
ProductSecurityLegal
GitHubOpen workspace
Legal centerOverviewPrivacyTermsCookiesAcceptable useSecurityData processingSubprocessorsData rightsAccessibility

Enterprise privacy

Data Processing Terms

Baseline controller-processor terms for personal data contained in customer workspaces.

Published September 18, 2026Version 1.0
These terms are not self-executing.

This page becomes binding only when an Order Form or signed agreement expressly incorporates it. Contact Termnova for an executed DPA and any required transfer addendum before production use.

1. Scope and roles

These Data Processing Terms supplement the agreement between the customer identified in the applicable Order Form (“Customer”) and the operator of Termnova (“Processor”). They apply when Processor handles Personal Data in Customer Content on Customer’s behalf. Customer is the controller or business; Processor is the processor or service provider. Terms such as Personal Data, process, controller, processor, business, consumer, and supervisory authority have the meanings given by applicable data-protection law.

2. Processing instructions

Processor will process Personal Data only on Customer’s documented instructions: to provide, secure, support, and maintain the services; as configured by authorized users; as stated in the agreement; or as required by law. If law requires other processing, Processor will inform Customer beforehand unless legally prohibited. Processor will notify Customer if it reasonably believes an instruction violates applicable data-protection law.

3. Processing details

Subject matterHosted contract ingestion, storage, retrieval, extraction, translation, analysis, workflow, evidence, and support.
DurationThe service term plus the deletion and backup period stated in the agreement.
PurposeProviding and securing the services according to Customer instructions.
Data subjectsCustomer personnel, users, counterparties, signatories, contacts, suppliers, customers, and individuals referenced in Customer documents.
Data typesIdentity and contact data, account identifiers, employment and role data, signatures, commercial and contractual information, usage and audit records, and any other Personal Data Customer elects to submit.
Sensitive dataNot intentionally required. Customer must not submit regulated or sensitive data unless expressly authorized in the Order Form and protected by agreed safeguards.

4. Confidentiality and security

Processor will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and will maintain appropriate technical and organizational measures proportionate to risk. Current product controls are summarized in the Security Overview. Specific contractual security commitments, if any, must appear in the signed agreement.

5. Subprocessors

Customer provides general authorization for Processor to use subprocessors needed to provide the service. Processor will impose data-protection obligations appropriate to each subprocessor’s services and remains responsible for its obligations under these terms. Current providers and change information appear on the Subprocessors page. An Order Form may state an objection period and notification method; otherwise Customer may raise a reasonable data-protection objection promptly after a posted material change.

6. Individual rights

Taking into account the nature of processing, Processor will provide reasonable assistance for Customer to respond to verified requests for access, correction, deletion, portability, restriction, objection, or appeal. If Processor receives a request concerning Customer Content, it may direct the requester to Customer and will not independently respond unless authorized or legally required.

7. Security incidents

Processor will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Notice will include available information reasonably needed for Customer’s obligations and will be supplemented as facts become available. Notice is not an admission of fault. Customer is responsible for its own regulatory and individual notifications.

8. Assistance and assessments

Processor will provide information reasonably necessary to demonstrate compliance with these terms and assist, considering the nature of processing and information available, with data-protection impact assessments and regulator consultations. Audits must protect other customers, confidentiality, and system security; begin with current documentation; occur no more than annually unless required after an incident or by a regulator; and be at Customer’s cost unless material noncompliance is found.

9. Return and deletion

At the end of services and on Customer’s documented request, Processor will return or delete Customer Personal Data unless retention is required by law. Deletion may occur through the service’s governed deletion workflow and may be delayed by valid legal holds. Residual backup copies remain protected and are removed through ordinary backup rotation.

10. International transfers

Customer authorizes processing in the United States and locations where approved subprocessors operate. If a restricted transfer requires additional safeguards, the parties will incorporate the applicable standard contractual clauses or other lawful mechanism in a signed addendum. Nothing on this page alone executes standard contractual clauses.

11. U.S. state privacy terms

For Personal Data governed by U.S. state privacy laws, Processor will act as a service provider or processor; process data only for the limited and specified business purposes in the agreement; not sell or share it for cross-context behavioral advertising; not retain, use, or disclose it outside the direct business relationship except as permitted by law; and notify Customer if Processor can no longer meet these obligations. Customer may take reasonable steps to stop and remediate unauthorized use.

12. Order of precedence and contact

If these terms conflict with the agreement, the provision that provides greater protection for Personal Data controls unless the signed agreement expressly says otherwise. The agreement’s liability, governing-law, and dispute terms apply to these Data Processing Terms. Request an executable version through the operator contact form.

T
TermnovaRead the contract. Control what follows.
PrivacyTermsCookiesSecurityLegal centerSign in

Not legal advice. Material contract decisions require qualified review. © 2026 Termnova.