Last updated 22 August 2026
Data Processing Agreement
The processor terms, accepted with every Order, that apply when Supernomial processes personal data on a customer's behalf during engagement work.
This agreement applies only where Supernomial processes personal data on your behalf: engagement work such as implementation, support and the AI Deployment Program. It is accepted with every Order, lies dormant in product operation of Managed Agents, Private Agents and TP Warehouse, where the Materials as delivered transmit no personal data to Supernomial, and switches on when our people access your environment or receive your personal data. It does not cover your AI platform vendor or your cloud provider, which process your data under your own agreements with them. This summary is for convenience; the numbered sections govern.
Version 1.0, effective 22 August 2026. This Data Processing Agreement (DPA) forms part of the agreement under which Supernomial Oy (Supernomial) provides services to the customer named in that agreement (Customer). It is accepted with every Order and applies to the extent described in section 2.
1. Definitions
- Agreement has the meaning given in the Terms of Service: the Order, the Terms of Service at supernomial.co/trust-center/terms-of-service/ and this DPA together or, where the parties sign a master agreement that incorporates the Terms of Service, that agreement together with this DPA. Order means a signed Order Form or Statement of Work that refers to the Terms of Service.
- Applicable Data Protection Law means the GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection and the national laws supplementing them, including the Finnish Data Protection Act (1050/2018).
- Customer Content has the meaning given in the Terms of Service: Customer Data, the Customer Layer, Inputs and Outputs together.
- Customer Environment means Customer's enterprise AI platform, cloud accounts, systems, tenants, repositories and communication channels, and any other environment Customer designates for an engagement.
- Customer Personal Data means personal data that Supernomial processes on Customer's behalf in the course of Engagement Services.
- Engagement Services means the AI Deployment Program; implementation, configuration and maintenance of Managed Agents, Private Agents and TP Warehouse; support; Academy workshops on Customer's real data; and any other work in which Supernomial personnel access the Customer Environment or receive personal data from Customer or on Customer's instruction.
- Materials and Plugin have the meanings given in the Terms of Service.
- SCCs means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, as amended or replaced.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Customer Personal Data.
- Sub-processor means a third party Supernomial engages to process Customer Personal Data on its behalf in the course of Engagement Services.
- UK Addendum means the UK Information Commissioner's International Data Transfer Addendum to the SCCs, as amended or replaced.
- Controller, processor, personal data, processing, data subject and supervisory authority have the meanings given in Article 4 GDPR. Updates has the meaning given in the Terms of Service.
2. Scope and roles
2.1 Product operation. The Materials run inside the Customer Environment. As delivered they contain no Supernomial endpoint, account, API key, license check or telemetry and transmit no Customer Personal Data to Supernomial. Supernomial has no access to the Customer Environment unless Customer grants it for Engagement Services. Customer's AI platform vendor and cloud provider process Customer Personal Data under Customer's agreements with them; they are not Supernomial's Sub-processors. Where Customer's platform fetches Updates from, or the Materials read public reference files in, a marketplace or repository Supernomial publishes, each fetch or read is one-directional, is logged by the hosting provider under its own terms (requesting address, client software, time, requested file and any account the host requires), and carries no Customer Content.
2.2 Engagement Services. This DPA applies whenever Supernomial personnel access the Customer Environment or receive personal data from Customer or on Customer's instruction in the course of Engagement Services. Customer is the controller (or a processor acting for its own clients) and Supernomial the processor (or sub-processor). The Order records whether personal data is expected; this DPA applies either way. Supernomial personnel work inside the Customer Environment with identities Customer issues, for the time Customer sets, under Customer's terms. Supernomial keeps no standing access, no Customer credentials and no copies of Customer Personal Data outside the Customer Environment, other than engagement and support correspondence in Supernomial's email and collaboration suite (Annex III), working notes and deliverable drafts on Supernomial-controlled laptops and in that suite, and copies Customer instructs in writing, all deleted under section 10.
2.3 Customer as processor. Where Customer acts as a processor for its own clients or another third party, Customer warrants that it has the authorizations required to appoint Supernomial as sub-processor and that its instructions reflect its controller's. Customer may attach client-specific requirements to the Order.
2.4 Controller-side processing. Supernomial processes business contact data of Customer's personnel (names, roles, work contact details) for contract management, invoicing, account communication and the security of its services as an independent controller under its Privacy Policy, outside this DPA.
2.5 Design commitment. Supernomial will not release an Update that transmits Customer Content or Customer Personal Data to Supernomial or to a Supernomial-controlled service unless the component that does so is optional, disabled by default, described in the release notes, and enabled by Customer in writing, in which case Annex I is updated.
3. Instructions
3.1 Supernomial processes Customer Personal Data only on Customer's documented instructions: this DPA, the Agreement, the Order, and written instructions from the contacts Customer names in the Order (email suffices), including instructions on transfers. The exception is where Union or Member State law to which Supernomial is subject requires otherwise; in that case Supernomial informs Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest.
3.2 If an instruction in Supernomial's opinion infringes Applicable Data Protection Law, Supernomial immediately informs Customer and may suspend the affected processing until the instruction is confirmed or changed.
3.3 Supernomial does not use Customer Personal Data for its own purposes, including to train or improve models, agents, playbooks or knowledge bases that serve anyone other than Customer.
3.4 Customer is responsible for the lawfulness of the processing it instructs, including a legal basis and the information owed to data subjects; gives instructions that comply with Applicable Data Protection Law; and is responsible for its own obligations under Articles 32 to 36 GDPR, with Supernomial's assistance as section 8 provides.
4. Personnel and confidentiality
4.1 Supernomial limits access to Customer Personal Data to the personnel who need it for the engagement: its employees and individual contractors working under Supernomial's instruction on Supernomial-controlled laptops, each bound by written confidentiality obligations that survive the engagement. Supernomial names the engagement team on request.
4.2 Inside the Customer Environment, Supernomial personnel follow the Customer Environment's rules of use and the security and acceptable-use policies Customer communicates.
4.3 Supernomial engages subcontractors for work in the Customer Environment only with Customer's consent, under written confidentiality terms and on Supernomial's responsibility.
5. Security
5.1 Supernomial implements and maintains the technical and organizational measures in Annex II and may update them provided the overall level of protection does not decrease.
5.2 Because Engagement Services run inside the Customer Environment, Customer remains responsible for its security configuration (identity provider, multi-factor authentication, logging, retention, data-loss prevention). Supernomial works within those controls and reports gaps it notices.
6. Sub-processors
6.1 Customer gives general written authorization for the Sub-processors in Annex III. Supernomial engages no other Sub-processor for Customer Personal Data unless the Order lists it or this section has been followed.
6.2 Supernomial gives at least 30 days' notice of an addition or replacement, by email to the contact Customer names in the Order and by updating the published list at supernomial.co/trust-center/. Customer may object within the notice period on reasonable data-protection grounds; the parties then discuss in good faith. If no solution is found within 30 days of the objection, Customer may terminate the affected Engagement Services without penalty and Supernomial refunds prepaid fees for services not rendered; no damages are owed for that termination. Where a Sub-processor must be replaced at short notice for security reasons or insolvency, Supernomial gives the shortest practicable notice and the objection right runs from it.
6.3 Supernomial binds each Sub-processor in writing to obligations no less protective than this DPA and remains fully liable for its performance.
6.4 Customer's AI platform vendor, cloud provider and any tooling Customer chooses and contracts are not Sub-processors, even where Supernomial operates them on Customer's instruction.
7. International transfers
7.1 Supernomial processes Customer Personal Data in the EEA and, through the Sub-processors in Annex III, where that Annex states; for engagements so scoped, inside the Customer Environment wherever Customer locates it. Supernomial personnel work from Finland and Germany. Other than the correspondence, working notes and deliverable drafts described in section 2.2 and Annex I, Supernomial copies no Customer Personal Data to its own systems unless instructed in writing.
7.2 Transfers outside the EEA rely on the EU-US Data Privacy Framework where the recipient is certified and on the European Commission's Standard Contractual Clauses in all cases, with the UK and Swiss equivalents. Supernomial follows the court and regulator decisions on these mechanisms and will switch safeguards if needed.
7.3 Supernomial is established in Finland and processes Customer Personal Data in the EEA; the provision of Customer Personal Data by Customer to Supernomial needs no transfer safeguard under the GDPR, the UK GDPR or Swiss law. Where Supernomial transfers Customer Personal Data to a Sub-processor in a country outside the EEA, Supernomial relies on the EU-US Data Privacy Framework where the Sub-processor is certified and, in every case, on the SCCs (Module Three, Supernomial as data exporter) entered into with that Sub-processor, so that the SCCs remain in place if an adequacy decision falls away; Customer authorizes those transfers on that basis. For UK and Swiss data the UK Addendum and the adjustments Swiss law requires apply to those onward transfers. If Supernomial itself ever processes Customer Personal Data from outside the EEA, the SCCs apply between the parties and are incorporated by reference: Module Two where Customer is a controller, Module Three where Customer is a processor; Clause 7 included; Clause 9 option 2 with 30 days' notice; the optional wording in Clause 11 not selected; Clause 13 as its rules provide; Clauses 17 and 18: Finnish law and courts; SCC Annexes I, II and III completed by Annexes I, II and III of this DPA.
7.4 If a public authority makes a binding request for Customer Personal Data, Supernomial notifies Customer unless legally prohibited and uses reasonable efforts to challenge a request it considers unlawful where it has standing.
8. Assistance
8.1 Supernomial forwards data-subject requests concerning Customer Personal Data to Customer without undue delay, answers them only on Customer's instruction, and assists Customer in responding.
8.2 Supernomial gives reasonable assistance with Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation) and with Customer's EU AI Act obligations concerning the Materials, taking into account the nature of the processing and the information available to Supernomial. Assistance beyond what is proportionate to the engagement is charged at the Agreement's rates.
9. Security incidents
9.1 Supernomial notifies Customer of a Security Incident without undue delay, and in any event within 48 hours after becoming aware of it. Supernomial is aware when it has a reasonable degree of certainty that a Security Incident has occurred. The first notice may be partial and is completed as the facts develop; it is timed so that Customer can meet its own deadline under Article 33 GDPR or, where Customer acts as processor, its controller's deadline.
9.2 The notice describes, as far as known, the nature of the incident, the categories and approximate numbers of data subjects and records concerned, the likely consequences and the measures taken or proposed. Supernomial cooperates in investigation, containment and remediation and provides a written summary once the incident is closed.
9.3 Supernomial makes no public statement naming Customer in connection with a Security Incident without Customer's consent, unless the law requires it.
10. Return and deletion
10.1 At the end of the Engagement Services, or earlier on instruction, Supernomial, at Customer's choice, returns any Customer Personal Data it keeps outside the Customer Environment in a common electronic format or deletes it, and in either case deletes remaining copies within 30 days and from provider backups as they cycle, confirming deletion in writing on request.
10.2 Supernomial retains Customer Personal Data only where and for as long as the law requires, under continued confidentiality and for no other purpose.
10.3 Inside the Customer Environment, Customer removes Supernomial's access at the end of the engagement; Supernomial cooperates and confirms in writing that its personnel have no remaining access.
11. Audit and information
11.1 Supernomial makes available the information needed to demonstrate compliance with this DPA. Questionnaires and documentation requests come first: a first response within 5 business days, with the Trust Center documents, Annex II and relevant Sub-processor reports.
11.2 Where that is not sufficient, Customer, or an independent auditor bound by confidentiality and not a competitor of Supernomial, may audit compliance with this DPA at most once in any 12 months, on 30 days' written notice, during business hours, within a scope agreed in advance, at Customer's cost and without access to other customers' information. More frequent audits are permitted only after a Security Incident or at a supervisory authority's request. Supernomial may charge its reasonable time beyond one working day per audit at the Agreement's rates.
11.3 Where Customer acts as processor for its own clients, those clients' auditors and regulators may audit Supernomial through Customer under the same conditions.
12. Liability, precedence, term, changes and law
12.1 Liability. Each party's liability under this DPA and the SCCs is subject to the limitations and exclusions of liability in the Agreement, including the increased cap for breach of this DPA (Terms of Service, section 12), to the extent Applicable Data Protection Law permits. Data subjects' rights as third-party beneficiaries under the SCCs are unaffected; as between the parties, recourse under Article 82(5) GDPR applies.
12.2 Precedence. On data-protection matters the SCCs prevail over this DPA; this DPA prevails over the Terms of Service and any master agreement; an Order prevails over this DPA only where it states an express deviation by section number (for example client-specific requirements under section 2.3). On all other matters the Agreement applies.
12.3 Term. This DPA applies for as long as Supernomial processes Customer Personal Data, and section 10 until the deletion it describes is complete.
12.4 Changes. Changes to this DPA require written agreement, except where Applicable Data Protection Law requires a change, in which case Supernomial notifies Customer of the change and its date. Annexes I, II and III may be updated as sections 2.5, 5 and 6 provide.
12.5 Governing law and venue. This DPA is governed by the laws of Finland, excluding its conflict-of-law rules and the CISG; the District Court of Helsinki has exclusive jurisdiction, subject to the arbitration election on the Order and to injunctive relief in any competent court, as the Agreement provides.
12.6 Contact. Notices under this DPA go to hello@supernomial.co and to the contact Customer names in the Order. Supernomial's address: Supernomial Oy, Business ID 3542056-6, Bulevardi 21, 00180 Helsinki, Finland.
13. Acceptance
This DPA is accepted as part of each Order by the Order's signature or acceptance; no separate signature is needed. The version in force on the date the Order is signed or accepted applies to that Order; a later version applies only by written agreement or as section 12.4 provides. Where Supernomial personnel access the Customer Environment or receive personal data from Customer outside an Order (for example during an evaluation under Terms of Service section 21), this DPA applies from that moment. A copy with a signature page is available on request at hello@supernomial.co.
Annex I. Description of processing
Parties. Customer (controller or processor), as named in the Order. Supernomial Oy, Business ID 3542056-6, Bulevardi 21, 00180 Helsinki, Finland (processor or sub-processor), hello@supernomial.co.
Common terms for every row:
- Purpose: the Engagement Services ordered.
- Nature: access, consultation, configuration, testing, transformation and, where instructed, temporary storage.
- Frequency and duration: continuous during the engagement, plus the deletion period in section 10.
- Special categories: not intended; Customer does not direct such processing and informs Supernomial where special-category or criminal-offense data is unavoidable.
- Retention: none outside the Customer Environment beyond the deletion period in section 10, except what law requires (section 10.2).
- Supervisory authority for Supernomial: the Office of the Data Protection Ombudsman, Finland.
| Row | Engagement | Data subjects | Personal data | Where |
|---|---|---|---|---|
| I.1 | AI Deployment Program (assess, architect, data readiness, agent shaping, go-live, scale) | Customer's employees, contractors and management; counterparties' contacts; for consultancies their clients' staff; for tax agencies taxpayer representatives in sample material | Names, roles, work contact details, user identities; document and workpaper content used to shape playbooks (signatories of intercompany agreements, executives in functional and DEMPE analyses, preparers and approvers in audit trails); engagement communications | Customer Environment; Supernomial-controlled laptops for working notes and deliverable drafts |
| I.2 | Managed Agents: implementation and support with access | As I.1 | As I.1, plus customer-specific plugin configuration | Customer's AI platform; Supernomial's email suite (Annex III) for support correspondence |
| I.3 | Private Agents: build, customization, maintenance | As I.1 | As I.1, plus the playbooks and knowledge bases being built | Customer's repositories, cloud and platform; Supernomial-controlled laptops for deliverable drafts |
| I.4 | TP Warehouse: deployment, data readiness, support | Employees in cost allocations or master data; vendor and customer contacts in ERP and CPM extracts; warehouse users | Master-data fields identifying individuals; user identities and actions in the audit trail; extract contents during mapping and validation | Customer's TP Warehouse deployment: the managed database and sign-in platform and the cloud account in Customer's name, in the region Customer chooses |
| I.5 | Support and maintenance after go-live | Customer's users | Support requests, screenshots and log extracts Customer shares | Customer Environment; Supernomial's email suite (Annex III) for support correspondence |
| I.6 | Academy workshops on Customer's real data | Participants and persons appearing in the material used | As I.1 | Customer Environment |
| I.7 | Product operation of Managed Agents, Private Agents and TP Warehouse | None | None: no processing by Supernomial | Not applicable |
Annex II. Technical and organizational measures
Supernomial's controls are designed to meet the standards its clients are certified against: ISO 27001 internationally, SOC 2 in the United States. Supernomial has no certification and publishes no audit report. For Customer's review Supernomial answers Customer's questionnaire, walks Customer's security and data protection teams through each data path, and provides its policies under NDA. Supernomial does not operate a multi-tenant system that stores Customer Personal Data; the measures below therefore focus on people, devices, access and working practice inside the Customer Environment.
- Work inside the perimeter. Engagement work on Customer Personal Data takes place inside the Customer Environment, under identities Customer issues, for the time Customer sets, under Customer's terms. No copies to Supernomial systems except the correspondence, working notes and deliverable drafts described in section 2.2 (on Supernomial-controlled laptops and in the suite listed in Annex III) and copies Customer instructs in writing for a defined purpose and period, all deleted under section 10.
- Access control. Named accounts and least privilege; access reviewed at each milestone and removed at hand-over with written confirmation; Customer's identity provider and multi-factor authentication policy govern the Customer Environment; multi-factor authentication on Supernomial's own systems.
- Devices. Supernomial-controlled laptops with full-disk encryption, screen lock and automatic updates; no Customer Personal Data on personal devices; the same controls wherever Supernomial personnel work, including when traveling.
- Confidentiality and briefing. Written confidentiality undertakings for everyone with access; a data-protection and secure-working briefing at onboarding and at least annually.
- AI tooling. No Customer Personal Data in AI tools other than the Customer Environment or a tool named in the Order under terms that exclude training and fix retention.
- Communication channels. The channel Customer designates; Supernomial's own channels only where listed in Annex III or the Order.
- Secure delivery of the Materials. Version control and review before release; instruction files in readable text that Customer's administrators can inspect before installation; pinned, traceable releases; no secrets in repositories; no Supernomial endpoint, account or API key in the Materials. No Customer Personal Data and no customer-specific configuration in Supernomial repositories unless the Order instructs it, in which case the code-hosting provider is listed in the Order under Annex III.
- Segregation. One workspace and one set of working files per customer and engagement; nothing combined across customers.
- Incident management. A written incident procedure with a named owner; hello@supernomial.co monitored by the founders; notification under section 9; post-incident review; vulnerability reports accepted.
- Vendor management. Sub-processors selected on published data processing terms, transfer safeguards and security documentation, reviewed annually, with written flow-down.
- Backup and deletion. Working files kept only for the engagement and deleted under section 10; no archive of Customer Personal Data.
- Logging. Inside the Customer Environment, Customer's own logs are the record of what Supernomial personnel and agents do under the identities Customer issues; Supernomial's own authentication and access logs are kept for 12 months.
- Business continuity. Deployments and data live in the Customer Environment and run without Supernomial's systems; repositories are backed up by the code-hosting provider; engagement documentation is written so the system runs without Supernomial.
Annex III. Sub-processors
A. Sub-processors for Engagement Services
| Sub-processor | Purpose | Location and transfer safeguard | Applies |
|---|---|---|---|
| Google Workspace (Google) | Email and collaboration suite: engagement correspondence, support correspondence and deliverable drafts | Google Cloud EMEA Limited (Ireland) for our subscription; data stored in Google's data centers in the EU and the United States; EU-US Data Privacy Framework (Google LLC is certified) and SCCs in Google's data processing terms | Every engagement with Customer Personal Data in correspondence or drafts |
| Other tools named in the Order | A conferencing tool (recordings only on Customer's instruction); a Supernomial-hosted support channel; AI tooling under terms that exclude training and fix retention; a Supernomial-hosted staging environment (policy: synthetic data); code hosting (GitHub, Inc.) where the Order asks Supernomial to keep customer-specific configuration | As stated in the Order | Only where the Order lists them |
B. Not Sub-processors under this DPA
- Customer's AI platform vendor (for example Anthropic, Microsoft, OpenAI or Mistral AI) and cloud provider: Customer's own processors under Customer's agreements with them.
- Supernomial's website and company vendors Vercel Inc., Supabase Pte. Ltd, Resend (operated by Plus Five Five, Inc.) and, outside the case in Annex III.A, GitHub, Inc.: they process website visitor and contact data or source code for Supernomial as controller, are disclosed in the Privacy Policy and on the Trust Center overview, and receive no Customer Personal Data.
C. Changes
The current list is published at supernomial.co/trust-center/ with its last-updated date. Additions and replacements follow section 6 (30 days' email notice to the contact Customer names in the Order, with the objection and termination rights described there). The Order records which rows of this Annex apply to the engagement.