legal
Data Processing Addendum (DPA)
Last updated: 2026-07-18
This DPA is incorporated into and forms part of the NukeAPI Terms of Service. By using NukeAPI, you agree to this DPA.
1. Definitions
Controller: The customer (you) who determines the purposes and means of processing personal data.
Processor: NukeAPI, who processes personal data on behalf of the Controller.
Personal Data: Any information relating to an identified or identifiable natural person submitted to the Service.
Processing: The deletion operations performed on personal data via the NukeAPI service.
2. Scope of Processing
| Item | Detail |
|---|---|
| Subject matter | Deletion of personal data from third-party services |
| Duration | For the term of the service agreement |
| Nature | Automated deletion via API calls to connected services |
| Purpose | GDPR Art. 17 / CCPA-CPRA compliance — right to erasure |
| Types of data | Email addresses, user IDs submitted by the Controller |
| Categories of subjects | End-users of the Controller's service |
3. Processor Obligations
- Process personal data only on documented instructions from the Controller.
- Ensure all personnel processing data are bound by confidentiality.
- Implement appropriate technical and organisational security measures.
- Not engage sub-processors without prior notification (see Section 6).
- Assist the Controller in responding to data-subject rights requests.
- Delete or return all personal data upon termination of services.
- Provide all information necessary to demonstrate compliance with this DPA.
4. Controller Obligations
- Have a lawful basis for submitting personal data to NukeAPI.
- Ensure data subjects have been notified of deletion where required.
- Only submit data for which they have legal authority to request deletion.
5. Security Measures
- AES-256-GCM encryption of credentials at rest.
- TLS 1.2+ for all data in transit.
- API-key authentication with bcrypt hashing.
- Row-level security on all database tables.
- Access logging and signed audit trails for all deletion operations.
6. Sub-processors
The following sub-processors may process personal data on our behalf. This list is the single source of truth shared with our Privacy Policy:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Primary database, auth and encrypted credential storage | United States |
| Upstash | Redis-backed rate limiting and abuse protection | United States |
| Resend | Transactional email delivery | United States |
| Dodo Payments | Merchant of record for billing (card/PayPal) | United States |
| Vercel | Hosting and serverless compute | United States |
7. International Transfers
Data may be transferred to and processed in countries outside your home jurisdiction. NukeAPI ensures all such transfers are protected by appropriate safeguards including Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent internationally recognised transfer mechanisms.
8. Data Retention and Deletion
NukeAPI retains deletion-request logs and audit trails for 90 days, after which they are permanently purged. Upon termination of your account, all personal data associated with your account is deleted within 30 days.
9. Breach Notification
In the event of a personal-data breach, NukeAPI will notify the Controller without undue delay and no later than 72 hours after becoming aware, providing sufficient information to allow the Controller to meet any applicable notification obligations.
10. Audit Rights
The Controller may request an audit of NukeAPI's data-processing activities no more than once per year, with 30 days' written notice, at the Controller's expense.
11. Contact
For DPA requests or questions: hello@nukeapi.dev