NectarScoutSign in

Data Processing Agreement

Version 2026-10-01

Effective 1 October 2026. This Data Processing Agreement ("DPA") forms part of the Terms of Service between The Hashtag Crew ("we", "us", the "Processor") and the customer that has accepted them ("you", the "Controller") for the use of NectarScout (the "Service"). It applies whenever we process Customer Personal Data for you. If this DPA and the Terms conflict on data protection, this DPA wins.

A countersigned copy is available on request from hello@nectarscout.com.

1. Definitions

2. Roles

You are the controller of Customer Personal Data and we are your processor. Where you are yourself a processor for your own client, we are your sub-processor, and you confirm that your client has authorised our appointment.

For a small amount of data we act as an independent controller: our records about you as a customer, data we need to secure the Service and prevent abuse, and the do-not-contact records we keep so that opt-outs are honoured. Our Privacy Policy covers that data.

3. Your instructions

We will process Customer Personal Data only on your documented instructions, unless the law requires otherwise (in which case we will tell you first, unless the law forbids it). Your instructions are this DPA, the Terms, and the way you configure and use the Service. We will tell you if we believe an instruction breaks Data Protection Laws.

You are responsible for:

4. Details of the processing

5. Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law.

6. Security

We implement appropriate technical and organisational measures to protect Customer Personal Data, including:

We may update these measures, provided we do not reduce the overall level of protection.

7. Sub-processors

You give us general authorisation to engage Sub-processors. Our current Sub-processors are listed at nectarscout.com/legal/subprocessors.

8. Helping you with data subject requests

Taking into account the nature of the processing, we will help you respond to requests from data subjects exercising their rights. If we receive a request directly that relates to your data, we will pass it to you without undue delay and will not respond ourselves except to confirm it has been passed on, unless you ask us to or the law requires it.

9. Personal data breaches

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as we know them, what happened, the data and people affected, the likely consequences, and what we are doing about it. We will give you further information as it becomes available and reasonably help you meet your own obligations to notify regulators and individuals.

10. Help with assessments

We will give you reasonable help with data protection impact assessments and prior consultations with supervisory authorities, where these relate to the Service and you cannot get the information elsewhere.

11. Deletion or return at the end

When your subscription ends, you may export your data by asking us at hello@nectarscout.com within 30 days. We will then delete Customer Personal Data within 90 days of the end of your subscription, unless the law requires us to keep it. Data in backups is deleted within a further 60 days, and is not used in the meantime.

12. Audits

We will make available the information reasonably needed to show that we comply with this DPA, including written answers to security questionnaires. If that is not enough, or a supervisory authority requires it, you may audit our compliance, at your own cost, no more than once a year, with at least 30 days' notice, during business hours, and under a duty of confidentiality. An audit must not access other customers' data.

13. International transfers

Customer Personal Data is processed in the United States and in the other countries listed on the Sub-processors page.

14. US state law terms

Where the CCPA or a similar US state law applies, we act as your service provider or processor, and we will not:

We will comply with those laws and tell you if we can no longer meet them. We certify that we understand these restrictions.

15. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where the law does not allow them to apply.

16. General

This DPA lasts as long as we process Customer Personal Data for you. If any part of it is found to be invalid, the rest continues. It is governed by the same law as the Terms, except where the SCCs or the UK Addendum require otherwise.