Data Processing Addendum
Controller–processor terms for customer workspace data processed by Nice Products.
Effective: 20 September 20261. Scope and roles
This Addendum forms part of the agreement between the customer and Nice Corp Ltd (registration number 207994014) when Nice Products processes personal data in Brokery, Turbowork or SalesmanAI on the customer’s documented instructions. The customer is controller; Nice Corp Ltd is processor, unless the parties’ actual role for a processing activity is different under law.
Processing details
- Subject matter and purpose: hosting, securing, supporting and operating the subscribed CRM, training, messaging, calling and sales-automation features.
- Duration: the subscription term plus the documented export/deletion and backup-retention period, unless law requires longer retention.
- Nature: collection, storage, organisation, retrieval, transmission, analysis, transcription, generation, restriction and deletion as enabled by the customer.
- Data types: business identity/contact and access data, CRM records, message/call metadata, recordings, transcripts, prompts, outputs, usage, support and technical logs.
- Data subjects: the customer’s users, staff, prospects, leads, customers, call participants and other people whose data the customer submits. The customer determines the lawful basis, notices, instructions and accuracy of submitted data.
2. Instructions and confidentiality
- Process personal data only to provide, secure and support the subscribed services and as documented by the customer.
- Ensure persons authorised to process data are bound by confidentiality.
- Notify the customer if an instruction appears to infringe applicable data-protection law.
3. Security and incidents
We maintain proportionate technical and organisational measures including tenant isolation, access controls, encryption in transit, secret management, logging, backup controls and incident procedures.
- Notify the customer without undue delay after confirming a personal-data breach affecting customer data.
- Provide information reasonably needed for the customer’s notification and investigation duties.
4. Subprocessors and transfers
The customer gives general authorisation for the subprocessors listed on the Subprocessors page. We remain responsible for their data-protection obligations, impose written terms and provide reasonable notice of material changes. Transfers outside the EEA use an adequacy decision or appropriate safeguards, including the European Commission Standard Contractual Clauses where required.
5. Assistance, audit and deletion
Taking account of the processing, we assist with data-subject requests, security, breach notification, DPIAs and regulator consultations. We make compliance information available and permit reasonable audits subject to confidentiality and security controls.
At the end of service, customer workspace data is deleted or returned according to the product retention settings and agreement, except where law requires limited retention. Billing records retained by law are pseudonymised where possible.
6. Contact and execution
Questions or requests for a signed copy: [email protected]. This public version supplements the service agreement; a signed order form or negotiated DPA controls if it differs.
