Data Processing Agreement

Last updated: 16 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement governing the Customer's use of the Niro service ("Agreement") between:

Niro Intelligence Ltd, a company registered in England and Wales under company number 17193482, with its registered office at 58 West Towers, Pinner, England, HA5 1UA ("Niro"); and

the customer identified in the Agreement ("Customer").

This DPA applies where Niro processes personal data on behalf of the Customer in providing the Service.

1. Definitions and roles

1.1 Definitions

In this DPA:

"Customer Content" means source code, repository content, configuration, documentation, commit metadata, stack traces, log lines and other content submitted to, connected to, or made available to the Service by or on behalf of the Customer, together with the code structure, documentation, analysis and other outputs derived from it by the Service.

"Customer Personal Data" means personal data contained in Customer Content that Niro processes on behalf of the Customer.

"Data Protection Law" means applicable data protection and privacy law relating to the processing of Customer Personal Data, including, where applicable, the UK GDPR, the Data Protection Act 2018 and Regulation (EU) 2016/679 ("EU GDPR"), in each case as amended or replaced.

"Service" means the Niro code intelligence platform and related services provided under the Agreement.

"Sub-processor" means a third party appointed by Niro to process Customer Personal Data on Niro's behalf.

Terms including controller, processor, personal data, processing, data subject and personal data breach have the meanings given to them under applicable Data Protection Law.

1.2 Roles

Where the Customer acts as a controller of Customer Personal Data, Niro acts as its processor.

Where the Customer acts as a processor on behalf of another controller, Niro acts as the Customer's sub-processor. In that case, the Customer confirms that it is authorised to appoint Niro and to give Niro the instructions set out in this DPA.

1.3 Niro as independent controller

This DPA does not apply to personal data for which Niro independently determines the purposes and means of processing, including business contact, contracting, billing, account administration and service-relationship records. That processing is governed by Niro's Privacy Notice.

2. Processing of Customer Personal Data

2.1 Instructions

Niro shall process Customer Personal Data only:

a. to provide, secure, support and maintain the Service;
b. in accordance with the Agreement, this DPA and the Customer's use and configuration of the Service;
c. on other documented instructions agreed between the parties; or
d. where required by applicable law.

If Niro is required by law to process Customer Personal Data other than on the Customer's instructions, Niro shall inform the Customer before doing so unless prohibited by law.

2.2 Unlawful instructions

Niro shall inform the Customer if, in Niro's reasonable opinion, an instruction infringes applicable Data Protection Law.

Niro is not required to conduct a legal review of the Customer's instructions or of Customer Content, and is not responsible for the Customer's compliance with Data Protection Law as controller.

2.3 Processing details

The subject matter, nature, purpose and duration of processing, and the relevant categories of personal data and data subjects, are set out in Annex 1.

2.4 Sensitive data

The Service is not designed for the processing of special-category personal data or criminal-offence data. The Customer shall not submit such data to the Service, and shall take reasonable steps to prevent such data being submitted, unless Niro has expressly agreed to the processing in writing.

2.5 Excluded categories of data

The Service is not designed or offered for the processing of protected health information as defined under the United States Health Insurance Portability and Accountability Act, or of cardholder data within the scope of the Payment Card Industry Data Security Standard.

The Customer shall not connect a repository, or configure a log agent, that transmits such data to Niro. Niro does not act as a business associate and does not enter into business associate agreements. Where the Customer requires the processing of such data, it shall notify Niro in writing in advance, and Niro may decline.

3. Niro's obligations

Niro shall:

a. ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations;
b. implement and maintain appropriate technical and organisational security measures in accordance with clause 4;
c. taking into account the nature of the processing, provide reasonable assistance to the Customer in responding to requests by data subjects exercising their rights under Data Protection Law;
d. taking into account the nature of the processing and the information available to Niro, provide reasonable assistance with the Customer's obligations relating to security, personal data breaches, data protection impact assessments and prior consultation with supervisory authorities;
e. maintain the records required of Niro as a processor under applicable Data Protection Law;
f. promptly inform the Customer of any request received directly from a data subject relating to Customer Personal Data, and not respond to such a request except on the Customer's instructions or as required by law; and
g. cooperate with competent supervisory authorities where required by applicable law, and inform the Customer without undue delay of any binding request from a supervisory authority or law enforcement body relating to Customer Personal Data, unless prohibited by law.

Where assistance under this DPA requires material work beyond Niro's standard functionality and documentation, Niro may charge reasonable fees agreed with the Customer in advance. Niro shall not charge for assistance required as a result of Niro's breach of this DPA.

4. Security

4.1 Security measures

Niro shall maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Niro's principal security measures are described in Annex 2. Niro shall maintain measures providing a level of protection at least equivalent to those described in Annex 2.

4.2 Changes

Niro may modify its technical and organisational measures from time to time, provided that the changes do not materially reduce the overall level of protection for Customer Personal Data.

5. Sub-processors

5.1 General authorisation

The Customer gives Niro general written authorisation to appoint Sub-processors in accordance with this clause. Niro's current Sub-processors are listed in Annex 3.

5.2 Sub-processor obligations

Niro shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA. Niro remains responsible to the Customer for the performance of its Sub-processors' applicable data protection obligations.

5.3 Changes

Niro shall give the Customer at least 30 days' prior notice before a new Sub-processor begins processing Customer Personal Data. Notice is given in accordance with clause 14.

Where a change is reasonably required urgently to protect the security, availability or lawful operation of the Service, Niro may make the change first and notify the Customer without undue delay.

5.4 Objections

The Customer may object to a proposed Sub-processor during the notice period on reasonable grounds relating to the protection of Customer Personal Data.

The parties shall use reasonable efforts to resolve the objection.

If the objection cannot reasonably be resolved, Niro shall not use the proposed Sub-processor to process that Customer's Customer Personal Data unless the parties agree otherwise. Where this prevents Niro from providing the affected part of the Service, either party may terminate that affected part of the Service, and the Customer shall receive a pro-rata refund of any prepaid fees relating to the period after termination.

For an urgent change under clause 5.3, the parties shall follow the same process as soon as reasonably practicable following notification.

6. International transfers

6.1 Lawful transfer mechanism

Niro shall not transfer Customer Personal Data in breach of applicable restrictions on international transfers.

Where Customer Personal Data is transferred to a country recognised as providing an adequate level of protection under applicable Data Protection Law, the parties may rely on that adequacy decision or regulation.

6.2 Standard Contractual Clauses

Where a transfer from the EEA to Niro requires an appropriate safeguard under Article 46 of the EU GDPR, the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA and apply to that transfer.

By incorporating the EU SCCs, the parties agree to the obligations contained in the applicable module of the EU SCCs. The following selections apply:

The competent supervisory authority shall be determined in accordance with the EU SCCs.

For clarity, the EU SCCs apply only where they are required as a transfer mechanism under applicable Data Protection Law. Their incorporation does not change the governing law or jurisdiction of the Agreement or this DPA except to the extent required by the EU SCCs.

6.3 Onward transfers

Where Niro makes a restricted onward transfer of Customer Personal Data to a Sub-processor, Niro shall put in place an appropriate transfer mechanism required by applicable Data Protection Law, including the EU SCCs or the UK International Data Transfer Addendum where applicable. Niro shall provide reasonable information about the applicable transfer mechanism on request.

7. Personal data breaches

7.1 Notification

Niro shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Niro becomes aware of a personal data breach when it has a reasonable degree of certainty that a security incident has occurred that has compromised Customer Personal Data.

7.2 Information

To the extent reasonably available, Niro shall provide information concerning:

a. the nature of the breach;
b. the categories of Customer Personal Data and data subjects affected;
c. the likely consequences of the breach;
d. measures taken or proposed to address or mitigate it; and
e. a contact point for further information.

Niro may provide information in stages where it is not reasonably available at the same time.

7.3 Cooperation

Niro shall take reasonable steps to contain and remediate a breach for which it is responsible and shall reasonably assist the Customer in meeting its applicable notification obligations.

Notification of a breach does not constitute an admission of fault or liability.

8. Return and deletion

8.1 End of the Service

On termination or expiry of the Service, Niro shall, at the Customer's choice, delete or return Customer Personal Data.

The Customer may request return within 30 days after termination or expiry. Following that period, or on earlier written instruction from the Customer, Niro shall delete Customer Personal Data within 30 days.

Return shall be in the form in which Niro reasonably holds the Customer Personal Data or another reasonably available format.

8.2 Copies and backups

Following deletion, Niro shall delete existing copies of Customer Personal Data unless retention is required by law.

Customer Personal Data contained in backups may remain until deleted through Niro's normal backup retention cycle. During that period it shall remain protected under this DPA and shall not be restored or otherwise processed except where reasonably necessary for disaster recovery or legal compliance.

Where Niro is legally required to retain Customer Personal Data after the Service ends, Niro shall continue to protect that data under this DPA and process it only for the purpose requiring its retention.

8.4 Confirmation

On the Customer's written request following deletion, Niro shall confirm in writing that deletion has been completed.

9. Audits and compliance information

9.1 Compliance information

Niro shall make available information reasonably necessary to demonstrate compliance with its obligations as a processor under applicable Data Protection Law.

Niro may satisfy requests by providing relevant security documentation, independent audit reports, certifications or responses to reasonable security questionnaires.

9.2 Frequency

Unless required following a personal data breach, a material security incident, or a request from a supervisory authority, the Customer shall not require more than one security questionnaire or audit in any twelve-month period.

9.3 Audit procedure

Where the information provided under clause 9.1 is not reasonably sufficient, the Customer may conduct an audit itself or through an independent auditor. Audits shall:

a. be limited to matters relevant to Niro's processing of Customer Personal Data;
b. be conducted remotely, by supervised screen-sharing session hosted by Niro, with a Niro representative operating the systems and controlling what is displayed;
c. be subject to at least 30 days' prior written notice, unless a shorter period is reasonably required following a breach or by a supervisory authority;
d. take place during normal UK business hours, with the scope, systems to be shown, duration and participants agreed in advance in writing;
e. be subject to appropriate confidentiality obligations covering each participant;
f. not involve recording, screen capture or copying of material displayed, other than the Customer's own written notes;
g. not unreasonably interfere with Niro's business or compromise the security, confidentiality or availability of Niro's systems, another customer's data, Niro's own source code, or Niro's commercially sensitive information; and
h. not be conducted by a competitor of Niro or by a person acting on a competitor's behalf.

9.4 On-site inspection

Niro operates on a fully remote basis and maintains no premises at which Customer Personal Data is processed. The infrastructure on which processing takes place is operated by the Sub-processors listed in Annex 3 and is not within Niro's physical control. On-site inspection of Niro is accordingly not available.

In place of it, Niro shall make available, on request and to the extent Niro is permitted to disclose them, the audit reports and certifications published by those Sub-processors. Where a competent supervisory authority requires an inspection in another form, the parties shall cooperate in good faith to satisfy that requirement.

9.5 Costs

The Customer shall bear its reasonable audit costs and Niro's reasonable costs of supporting an audit, unless the audit identifies a material breach of this DPA by Niro.

10. Use of Customer Content and AI models

10.1 No model training

Niro shall not use Customer Content to train or fine-tune a machine-learning or foundation model.

This does not prevent Niro from processing Customer Content through machine-learning models as necessary to provide the Service.

10.2 Inference providers

Niro shall configure each third-party inference provider it uses so that Customer Content is not retained by, and is not available to, that provider for model training.

Content sent to a third-party inference provider passes through a masking layer designed to detect and remove secrets and common categories of personal data before egress. The Customer acknowledges that masking operates on a best-effort basis and that Niro does not warrant the removal of every sensitive value.

Where inference runs on models Niro hosts on its own infrastructure, no third-party inference provider receives the content.

10.3 Operational diagnostics

Where reasonably necessary to diagnose a parsing defect, Niro may retain a limited extract of Customer Content associated with that defect, with secrets and personal data masked before storage.

Any such extract remains Customer Content, remains protected under clause 11 and under this DPA where it contains personal data, is not disclosed to any third party, and is not used for model training. Diagnostic extracts are retained for no longer than 90 days.

10.4 Interaction signals

Niro records signals indicating whether a Service response was useful and the interaction pattern that produced it. These signals contain no Customer Content and no Customer Personal Data.

Niro may use them to improve the Service, including to train and improve its own models.

10.5 Opt-out

The Customer may disable the diagnostic retention in clause 10.3 and the signals in clause 10.4 by written request. Niro shall confirm the change within 10 business days, and it takes effect from the date of confirmation. The Service remains fully functional with both disabled.

10.6 Aggregated information

Niro may use aggregated or de-identified information concerning the operation and performance of the Service where that information does not contain Customer Content or Customer Personal Data, and cannot reasonably identify the Customer or an individual.

11. Confidentiality of Customer Content

11.1 Scope

This clause applies to all Customer Content, whether or not it constitutes personal data. It exists because the Customer's principal confidentiality interest is its source code, which is frequently not personal data and would not otherwise be covered by this DPA.

11.2 Obligations

Niro shall treat all Customer Content as the Customer's confidential information, shall use it solely to provide the Service and as permitted by clause 10, and shall not disclose it to any third party other than a Sub-processor appointed under clause 5.

11.3 Survival

This clause survives termination or expiry of the Agreement and continues for so long as Niro holds any Customer Content, and thereafter for a period of five years.

11.4 Ownership

Niro claims no ownership of Customer Content. All intellectual property in Customer Content, including source code, remains the Customer's.

12. Customer responsibilities and indemnity

12.1 Responsibilities

The Customer is responsible for:

a. ensuring that its instructions to Niro comply with applicable Data Protection Law;
b. having an appropriate lawful basis for the Customer Personal Data it instructs Niro to process;
c. providing required privacy information to data subjects;
d. determining whether the Service is appropriate for the categories of personal data it chooses to submit, and complying with clauses 2.4 and 2.5;
e. the content of the repositories and log data it connects to the Service; and
f. where the Customer acts as a processor, ensuring that its controller has authorised the appointment of Niro as a Sub-processor.

Niro is not responsible for the lawfulness of Customer Content or for determining whether the Customer is permitted to process or submit it.

12.2 Indemnity

The Customer shall indemnify Niro against all losses, liabilities, fines, penalties, damages, costs and expenses, including reasonable legal fees, arising out of or in connection with any breach by the Customer of clause 2.4, clause 2.5 or clause 12.1.

This includes any claim by a data subject and any regulatory action arising from the presence of special-category personal data, criminal-offence data, protected health information, or cardholder data in a connected repository or in log data submitted to Niro.

13. United States state privacy laws

Where the California Consumer Privacy Act as amended, or an equivalent United States state privacy law, applies to Customer Personal Data, Niro acts as a service provider or processor as those terms are defined in the applicable law.

Niro shall not sell or share Customer Personal Data, shall not retain, use or disclose it for any purpose other than performing the Service, and shall not combine it with personal information received from another source except as permitted by the applicable law.

Niro certifies that it understands and will comply with these restrictions.

14. Notices

Notices under this DPA are given in writing by email and take effect on delivery.

Notices to Niro are sent to privacy@niro.ai, or to such other address as Niro notifies to the Customer.

Notices to the Customer are sent to the administrative contact registered on the Customer's account, or to such other address as the Customer notifies to Niro in writing. The Customer is responsible for keeping that address current, and notice given to the last address notified is valid notice for all purposes under this DPA, including under clause 5.3.

15. Liability and general terms

15.1 Liability

Liability arising under this DPA is subject to the exclusions and limitations of liability in the Agreement. All claims by the Customer and its affiliates under this DPA and the Agreement are aggregated for the purpose of those limits, and only the entity that is party to the Agreement may bring a claim.

The indemnity in clause 12.2 is not subject to those limits.

Nothing in this DPA limits liability to the extent it cannot lawfully be limited.

15.2 Conflict

If this DPA conflicts with the Agreement, this DPA prevails in respect of the processing of Customer Personal Data and in respect of the confidentiality, permitted use and ownership of Customer Content under clause 11.

Where applicable EU SCCs conflict with this DPA or the Agreement, the EU SCCs prevail in relation to the transfer they govern.

15.3 Intellectual property

Except as set out in clause 11.4, this DPA does not change the ownership or licensing of Customer Content, Service outputs, software or other intellectual property. Those matters are governed by the Agreement.

15.4 Governing law

This DPA is governed by the governing law and jurisdiction specified in the Agreement. If the Agreement does not specify them, the laws of England and Wales apply and the courts of England and Wales have exclusive jurisdiction.

15.5 Survival

Clauses 8, 10.1, 11, 12.2 and 15 survive termination or expiry of this DPA.

15.6 Changes to this DPA

Niro may update this DPA from time to time. Where an update materially reduces the protections available to the Customer, Niro shall give at least 30 days' notice, and the Customer may terminate the affected part of the Service before the update takes effect.

15.7 Effect

This DPA forms part of, and is incorporated by reference into, the Agreement. It takes effect when the Customer accepts the Agreement, or on first use of the Service if earlier, and requires no separate signature. Where the Customer requires a separately executed copy, Niro will provide one on request.


Annex 1: Processing Details

Subject matter. Provision of the Niro code intelligence platform and related services.

Duration. For the period during which Niro provides the Service, together with the deletion period described in clause 8.

Nature and purpose. Niro may retrieve, receive, store, parse, index, structure, analyse, query, transmit and delete Customer Content for the purposes of providing, securing, supporting and maintaining the Service.

This includes analysing software repositories, constructing code structure and dependency information, generating documentation and analysis, answering queries and performing root-cause or related code analysis.

Categories of data subjects. Customer Personal Data may relate to:

Types of personal data. Depending on Customer Content, Customer Personal Data may include:

The Service is not intended for the processing of special-category personal data, criminal-offence data, protected health information or cardholder data.

Frequency. Processing occurs as required during the Customer's use of the Service.

Retention.


Annex 2: Technical and Organisational Measures

Niro maintains technical and organisational measures appropriate to the risks associated with the Service. Niro may vary individual measures in accordance with clause 4.2, provided the overall level of protection is maintained.

Access control

Encryption

Repository access

Customer-side agents

Operations

People

Measures not currently in place


Annex 3: Current Sub-processors

Sub-processor Purpose Processing location
Amazon Web Services Cloud infrastructure and object storage Ireland (EEA)
Verda Compute infrastructure and inference for models hosted by Niro UK / EEA
Groq Model inference United States
OpenAI Model inference United States
Google Workspace Business communication and collaboration where Customer Personal Data is involved EEA
Neo4j AuraDB Managed graph database EEA

Product analytics run on a self-hosted instance on Niro's own infrastructure and involve no third party.

The list above is current as at the effective date. Changes are notified in accordance with clause 5.