This Data Processing Agreement ("DPA") applies to the processing of personal data by NowHere on behalf of users and groups who use the Service. It supplements our Privacy Policy and Terms of Service and is intended to satisfy the requirements of Article 28 of the GDPR.
1. Definitions
Unless otherwise defined here, terms used in this DPA have the meanings given in Regulation (EU) 2016/679 ("GDPR").
- "Controller" — the user or organisation that determines the purposes and means of processing personal data by using NowHere.
- "Processor" — NowHere, which processes personal data on behalf of the Controller.
- "Personal Data" — any information relating to an identified or identifiable natural person processed in connection with the Service.
- "Sub-processor" — a third party engaged by NowHere to assist in processing Personal Data.
- "Service" — the NowHere mobile application and backend services at nowheretasks.app.
2. Scope and purpose
NowHere processes Personal Data solely to provide the Service as described in the Privacy Policy. Processing outside that scope may only occur on the documented instruction of the Controller or as required by law.
The categories of Personal Data processed are:
- Account identifiers — email address, display name, hashed password.
- Application data — saved places (names, coordinates, radii), tasks, group names, shared list contents.
- Device data — FCM tokens, platform, app version, last-seen timestamp.
- Operational data — server access logs (anonymised, 30-day retention), crash reports (sanitised, 90-day retention).
The categories of data subjects are: individual users of the NowHere application and individuals invited to groups by users.
3. Obligations of NowHere as Processor
NowHere shall:
- Process Personal Data only on the documented instructions of the Controller (which are the Terms of Service and the functions provided by the App), unless required to do so by Union or Member State law.
- Ensure that persons authorised to process Personal Data are committed to confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as described in Section 8 of the Privacy Policy.
- Not engage a Sub-processor without prior written authorisation (general authorisation is provided in Section 6 of this DPA; the list of current Sub-processors is published there).
- Assist the Controller in responding to requests from data subjects exercising their rights under GDPR, taking into account the nature of processing.
- Assist the Controller in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments, and prior consultation.
- At the choice of the Controller, delete or return all Personal Data upon termination of the Service, and delete existing copies unless Union or Member State law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow and contribute to audits conducted by the Controller or a mandated auditor, with reasonable prior notice.
- Promptly inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
4. Data subject rights
NowHere provides the following mechanisms to help Controllers fulfil data subject rights:
- Access and portability — users can export their places and tasks in JSON format from within the App (Settings → Export). Additional data can be provided upon written request to privacy@nowheretasks.app.
- Rectification — users can update their email, name, and all application data directly in the App.
- Erasure — users can delete their account in-app (Settings → Privacy → Delete Account) or via the Delete Account web page. Deletion is immediate and permanent for application data; anonymised log entries may persist up to 30 days.
- Restriction and objection — requests may be submitted to privacy@nowheretasks.app and will be processed within 30 days.
5. Security measures
NowHere maintains the following technical and organisational measures:
- Encryption in transit (TLS 1.2 or higher) for all communications between the App and our servers.
- Passwords stored as one-way bcrypt hashes.
- Short-lived JWT access tokens paired with rotating refresh tokens, stored in device secure storage (Keychain on iOS, Keystore on Android).
- Database and application services running in isolated Docker containers; the database has no direct public network access.
- Automated purging of expired tokens, verification codes, and invitations.
- Error report sanitisation removing email addresses, passwords, tokens, and user content before transmission.
- Access logs that record only anonymous user identifiers, never personal content.
6. Sub-processors
NowHere has authorised the use of the following Sub-processors. By accepting this DPA (by using the Service) the Controller grants general authorisation to engage these Sub-processors:
- Google LLC (Firebase Cloud Messaging) — push notification delivery. Data transferred: FCM device tokens and notification type identifiers. Google Privacy Policy.
- SMTP provider — transactional email delivery (verification codes, password resets, group invitations). Data transferred: recipient email address and message content.
- Hosting / infrastructure provider — cloud server hosting for the backend API, database, and supporting services.
NowHere will inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller the opportunity to object. Objections must be raised within 14 days; continued use of the Service after that period constitutes acceptance.
7. Data breach notification
In the event of a Personal Data breach, NowHere will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The notification will include:
- the nature of the breach and the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach.
Notifications should be directed to privacy@nowheretasks.app.
8. International data transfers
NowHere endeavours to store and process Personal Data within the European Economic Area. Where transfers outside the EEA are necessary (e.g., for push notification delivery via Google's FCM infrastructure), NowHere relies on Standard Contractual Clauses adopted by the European Commission or other appropriate safeguards as permitted by GDPR Article 46.
9. Audit rights
Upon reasonable prior written notice (at least 30 days), NowHere will provide the Controller with information reasonably necessary to verify compliance with this DPA and, where required by applicable law, allow audits or inspections by the Controller or its appointed auditors. Audits shall not unreasonably interfere with NowHere's operations and shall be conducted at the Controller's expense.
10. Duration and termination
This DPA enters into force when the Controller first uses the Service and remains in effect until the Controller's account is deleted or the Terms of Service are terminated. Upon termination, NowHere will delete or render anonymous all Personal Data relating to the Controller's account, subject to retention obligations under applicable law.
11. Hierarchy
In the event of any conflict between this DPA and the Terms of Service or Privacy Policy regarding the processing of Personal Data, this DPA shall prevail to the extent of the conflict.
12. Contact
Data protection enquiries: privacy@nowheretasks.app
Legal: legal@nowheretasks.app