Last updated: 25 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement under which Nabto provides the Service to the Customer, whether that is the Terms of Service and Payment Terms accepted online, an Order Form referencing this DPA or another written agreement into which this DPA is incorporated (the "Agreement"), between:
This DPA reflects the parties' agreement on the processing of personal data carried out by Nabto on behalf of the Customer through the Nabto platforms, namely Nabto Edge, Nabto WebRTC and Nabto 4 (the "Service"), in compliance with Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").
If there is a conflict between this DPA and the rest of the Agreement on the subject of personal data processing, this DPA prevails, except where the Agreement expressly amends an identified provision of this DPA without reducing the protection required by Article 28 of the GDPR. On all other subjects, including fees, payment and liability, the rest of the Agreement governs and this DPA does not import the Terms of Service or the Payment Terms into an Agreement that does not otherwise include them. Where Nabto and the Customer have signed a separately negotiated data processing agreement, that agreement prevails over this DPA for that Customer.
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Applicable Data Protection Law" means the GDPR and any other data protection laws applicable to the processing. "Sub-processor" means any processor engaged by Nabto to process personal data on the Customer's behalf.
2.1 For personal data processed through the Service on the Customer's behalf, the Customer is the controller and Nabto is the processor. Where the Customer is itself a processor for a third party, Nabto acts as a sub-processor.
2.2 Nabto's processing of personal data for which Nabto is itself the controller (for example, Customer account, authentication and billing data) is governed by Nabto's Platform Privacy Policy, not by this DPA.
2.3 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
3.1 Nabto shall process personal data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or member-state law; in such a case Nabto shall inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
3.2 The Agreement, this DPA and the Customer's configuration and use of the Service constitute the Customer's complete and documented instructions. Additional or different instructions require written agreement and may be subject to additional fees.
3.3 Nabto shall promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
Nabto shall ensure that persons authorized to process the personal data are bound by an appropriate duty of confidentiality and process the data only as necessary to provide the Service.
5.1 Nabto shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation and the nature, scope, context and purposes of processing, in accordance with Article 32 of the GDPR.
5.2 The measures in place as of the date of this DPA are described in Annex 2. Nabto may update them from time to time provided the level of protection is not materially reduced.
6.1 The Customer provides general authorization for Nabto to engage Sub-processors to process personal data, subject to this Section. The Sub-processors engaged as at the date of this DPA are listed in Annex 3 (or at the URL referenced there).
6.2 Nabto shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA and remains fully liable to the Customer for the performance of each Sub-processor's obligations.
6.3 Nabto shall give the Customer reasonable prior notice of any intended addition or replacement of a Sub-processor by updating the sub-processor list referenced in Annex 3 and by email to the Customer's registered contact as described on that page. The Customer may object on reasonable data-protection grounds within 14 days. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service with the refund of unused prepaid fees provided for in Section 9.6 of the Terms of Service.
Taking into account the nature of the processing, Nabto shall assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR. If Nabto receives such a request directly, it shall, where lawful, forward it to the Customer and not respond except on the Customer's instruction.
Taking into account the nature of the processing and the information available to it, Nabto shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including security of processing, notification of personal data breaches, communication to data subjects, data protection impact assessments and prior consultation with the supervisory authority.
9.1 Nabto shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf.
9.2 The notification shall, to the extent available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address it.
9.3 Nabto shall take reasonable steps to mitigate and remediate the breach. Nabto's notification is not an acknowledgement of fault or liability.
10.1 Nabto shall not transfer personal data to a country outside the EU/EEA without ensuring an appropriate transfer mechanism is in place under Chapter V of the GDPR, such as an adequacy decision, the EU Standard Contractual Clauses or the EU-US Data Privacy Framework.
10.2 Transfers of personal data by Nabto to a Sub-processor outside the EU/EEA take place under the transfer mechanism stated for that Sub-processor on the sub-processor list referenced in Annex 3. That mechanism is either the EU Standard Contractual Clauses, module three (processor to processor), concluded between Nabto and the Sub-processor; or the Sub-processor's certification under the EU-US Data Privacy Framework. Nabto makes the relevant documentation available to the Customer on request. The particulars of these transfers are set out in Annex 4.
10.3 Where the Customer is established outside the EU/EEA and the law applicable to the Customer requires a transfer instrument for the Customer's transfer of personal data to Nabto, for example the UK International Data Transfer Addendum, the parties conclude that instrument on request. For that transfer the instrument prevails over this DPA.
11.1 Nabto shall make available to the Customer information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
11.2 To minimize disruption, the Customer shall give reasonable prior notice, audits shall take place during business hours no more than once per year (unless required by a supervisory authority or following a breach) and the parties shall agree on scope and confidentiality in advance. Nabto may satisfy audit requests by providing relevant certifications or third-party audit reports where these reasonably address the Customer's request.
On termination of the Service, Nabto shall, at the Customer's choice, delete or return all personal data processed on the Customer's behalf and delete existing copies, unless EU or member-state law requires storage. The Customer may export the data through the console and the APIs for 30 days after termination (the retrieval period in Section 9.4 of the Terms of Service; where the Customer switches provider under Section 9.7 of the Terms of Service, the retrieval period starts when the transition period there ends), after which Nabto deletes it. On the Customer's written instruction Nabto deletes the data earlier; that deletion is carried out in the live systems without undue delay, with backup copies expiring on the ordinary cycle. Backup copies expire within 35 days of the deletion of the live data. Nabto confirms the deletion in writing on the Customer's request.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
This DPA takes effect when the Customer accepts it in one of the ways set out in Section 15 and remains in force for as long as Nabto processes personal data on the Customer's behalf. Provisions that by their nature should survive termination will survive.
The Customer accepts this DPA by accepting the Terms of Service online, by signing an Order Form or other agreement that references this DPA by URL and "Last updated" date, by confirming in writing, including by email, that this DPA in an identified version applies to an existing agreement between the Customer and Nabto, or by both parties signing a printed copy of this DPA. Where a signed copy is required, signature does not alter the terms of this DPA.
This DPA is governed by the laws of Denmark, with the courts of Denmark having jurisdiction, consistent with the Agreement, without prejudice to any mandatory provisions of Applicable Data Protection Law.
Subject matter: Provision of the Nabto IoT connectivity platforms (Nabto Edge, Nabto WebRTC and Nabto 4) to the Customer.
Duration: For the term of the Agreement and any wind-down period.
Nature and purpose of processing: Hosting, transmission, relay, signaling, connectivity, storage and related processing necessary to operate the Service and connect the Customer's Devices and End Users.
Types of personal data. The personal data the Customer processes through the Service, which may include:
Categories of data subjects. The individuals whose personal data the Customer processes through the Service, which may include:
Special category data: The Service does not require or solicit special categories of personal data. Content transmitted at the Customer's direction may contain such data; the Customer is responsible for the lawfulness of that processing.
This Annex describes the technical and organizational measures referenced in Section 5.
A current list of Sub-processors engaged by Nabto to process personal data on the Customer's behalf is maintained at https://downloads.nabto.com/assets/legal/subprocessors.html.
Vendors engaged only for card payment processing, such as Stripe, process data for which Nabto is the controller and are described in the Platform Privacy Policy rather than on that list.
This Annex sets out the particulars of the international transfers referred to in Section 10. The mechanism that applies to a given transfer is stated for each Sub-processor on the sub-processor list referenced in Annex 3; that list is the authoritative source for the per-vendor mechanism.
| Item | Particulars |
|---|---|
| Data exporter | The Customer, as controller, for its transfer of personal data to Nabto; Nabto, as processor, for onward transfers to Sub-processors. |
| Data importer | Nabto ApS, Åbogade 15, 8200 Aarhus N, Denmark, as processor; for onward transfers, the Sub-processor named on the sub-processor list. |
| Categories of personal data and of data subjects | As set out in Annex 1. |
| Frequency of the transfer | Continuous, for the duration of the Agreement. |
| Nature and purpose of the transfer | As set out in Annex 1. |
| Retention | For the duration stated in Annex 1, then deletion or return under Section 12: Export for 30 days after termination, deletion thereafter or earlier on the Customer's instruction, backup copies expiring within 35 days of the deletion of the live data. |
| Competent supervisory authority | Datatilsynet, the Danish Data Protection Agency, as Nabto is the processor established in Denmark. |
| Transfer mechanism | As stated for each Sub-processor on the sub-processor list referenced in Annex 3, namely the EU Standard Contractual Clauses concluded between Nabto and that Sub-processor or that Sub-processor's certification under the EU-US Data Privacy Framework. |
EU storage does not by itself settle the transfer analysis. The table below states, for each Sub-processor, what the transfer consists of and the mechanism that covers it. The sub-processor list referenced in Annex 3 remains the authoritative source for the current Sub-processors.
Transfers by Sub-processor
| Sub-processor | Recipient entity and country | Where the data is stored | What constitutes the transfer | Mechanism |
|---|---|---|---|---|
| Amazon Web Services | AWS EMEA SARL, Luxembourg, with AWS, Inc. affiliates operating the non-EU regions | In the platform region the device or client attaches to; EU-only organizations in eu-west-1 and eu-central-1 only | For Global organizations only: Processing in us-west-2 or ap-south-1 when a device or client attaches there. No transfer for EU-only organizations | EU Standard Contractual Clauses in the AWS Data Processing Addendum for all non-EU regions; AWS's EU-US Data Privacy Framework certification additionally covers the US regions |
| Google Cloud | Google Cloud EMEA Limited, Ireland, with Google LLC for support and operations | Message storage pinned to europe-west1 (Belgium) | For Global organizations only: Delivery of state messages to Nabto's platform regions in the United States and Asia-Pacific. Support and operational access from outside the EU/EEA. No delivery outside the EU for EU-only organizations | EU Standard Contractual Clauses in Google's Cloud Data Processing Addendum; Google's EU-US Data Privacy Framework certification for support access |
| Grafana Labs | Grafana Labs, Inc., United States | Frankfurt, AWS eu-central-1 | Access to the stored logs and metrics by Grafana Labs, Inc. from the United States | EU Standard Contractual Clauses in Grafana's data processing addendum and Grafana Labs, Inc.'s EU-US Data Privacy Framework certification |
| Shortcut | Shortcut Software Company, Inc., United States | United States | Storage and processing in the United States of the personal data the Customer includes in support requests | EU Standard Contractual Clauses in Shortcut's data processing addendum and Shortcut's EU-US Data Privacy Framework certification |
| Google Workspace | Google Ireland Limited, with Google LLC for support and operations | EU | Support and operational access from the United States to the personal data the Customer includes in email to Nabto | EU Standard Contractual Clauses in the Google Workspace Data Processing Amendment and Google's EU-US Data Privacy Framework certification |