Legal

Data Processing Agreement

Effective date: August 20, 2025  ·  Last updated: August 20, 2025

This Data Processing Agreement ("DPA") applies to the processing of personal data by NowHere on behalf of users and groups who use the Service. It supplements our Privacy Policy and Terms of Service and is intended to satisfy the requirements of Article 28 of the GDPR.

1. Definitions

Unless otherwise defined here, terms used in this DPA have the meanings given in Regulation (EU) 2016/679 ("GDPR").

2. Scope and purpose

NowHere processes Personal Data solely to provide the Service as described in the Privacy Policy. Processing outside that scope may only occur on the documented instruction of the Controller or as required by law.

The categories of Personal Data processed are:

The categories of data subjects are: individual users of the NowHere application and individuals invited to groups by users.

3. Obligations of NowHere as Processor

NowHere shall:

4. Data subject rights

NowHere provides the following mechanisms to help Controllers fulfil data subject rights:

5. Security measures

NowHere maintains the following technical and organisational measures:

6. Sub-processors

NowHere has authorised the use of the following Sub-processors. By accepting this DPA (by using the Service) the Controller grants general authorisation to engage these Sub-processors:

NowHere will inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object. Objections must be raised within 14 days; continued use of the Service after that period constitutes acceptance.

7. Data breach notification

In the event of a Personal Data breach, NowHere will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The notification will include:

Notifications should be directed to privacy@nowheretasks.app.

8. International data transfers

NowHere endeavours to store and process Personal Data within the European Economic Area. Where transfers outside the EEA are necessary (e.g., for push notification delivery via Google's FCM infrastructure), NowHere relies on Standard Contractual Clauses adopted by the European Commission or other appropriate safeguards as permitted by GDPR Article 46.

9. Audit rights

Upon reasonable prior written notice (at least 30 days), NowHere will provide the Controller with information reasonably necessary to verify compliance with this DPA and, where required by applicable law, allow audits or inspections by the Controller or its appointed auditors. Audits shall not unreasonably interfere with NowHere's operations and shall be conducted at the Controller's expense.

10. Duration and termination

This DPA enters into force when the Controller first uses the Service and remains in effect until the Controller's account is deleted or the Terms of Service are terminated. Upon termination, NowHere will delete or render anonymous all Personal Data relating to the Controller's account, subject to retention obligations under applicable law.

11. Hierarchy

In the event of any conflict between this DPA and the Terms of Service or Privacy Policy regarding the processing of Personal Data, this DPA shall prevail to the extent of the conflict.

12. Contact

Data protection enquiries: privacy@nowheretasks.app
Legal: legal@nowheretasks.app