Nialli™ legal
Nialli Data Processing Addendum
Last Updated: September 29, 2026
This Data Processing Addendum ("DPA") is entered into by and between Nialli Inc. ("Nialli," "Processor," "Service Provider," "we," or "us") and the entity identified as Customer in the applicable order form, subscription agreement, master services agreement, or other agreement governing Customer’s use of Nialli services (the "Agreement") ("Customer," "Controller," "Business").
This DPA is incorporated into and forms part of the Agreement by reference and applies to the extent Nialli processes Personal Data on behalf of Customer in connection with the Services. Defined terms not defined herein have the meanings set out in the Agreement.
Order of Precedence. In the event of any conflict or inconsistency between this DPA and the Agreement, this DPA controls with respect to the processing of Personal Data. In the event of any conflict between the body of this DPA and the Annexes hereto, the SCCs and/or UK Addendum control with respect to international transfers.
1. Definitions
"Applicable Data Protection Laws" means all applicable privacy and data protection laws and regulations governing the processing of Personal Data under this DPA and the Agreement, including as applicable: the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679); the UK GDPR and UK Data Protection Act 2018; the Swiss Federal Act on Data Protection (FADP); the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); and any other privacy laws applicable to the processing of Customer Personal Data. [Note to Draft: Add Canadian references]
"Controller" means the entity that determines the purposes and means of processing Personal Data.
"Processor" or "Service Provider" means the entity that processes Personal Data on behalf of the Controller.
"Customer Personal Data" means Personal Data processed by Nialli on behalf of Customer under the Agreement.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
"Personal Data" has the meaning given under the applicable Applicable Data Protection Laws (or, in the absence of a specific statutory definition, means information relating to an identified or identifiable individual).
"Process" or "Processing" means any operation or set of operations performed on Personal Data, whether by automated means or otherwise.
"SCCs" means the Standard Contractual Clauses for the transfer of Personal Data to third countries as adopted by the European Commission, Decision 2021/914, as updated, amended, or replaced from time to time.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
"Services" means the products and services provided by Nialli to Customer under the Agreement.
"Subprocessor" means a third-party processor engaged by Nialli to process Customer Personal Data.
"Supervisory Authority" means the competent regulatory authority responsible for the enforcement of Applicable Data Protection Laws.
"UK Addendum" means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner’s Office, as in force from time to time.
2. Roles and Scope
2.1 Controller and Processor
As between the Parties, Customer is the Controller and Nialli is the Processor/Service Provider of Customer Personal Data processed in connection with the Services.
2.2 Processing on Documented Instructions
Nialli will process Customer Personal Data only on Customer’s documented instructions, including as set forth in the Agreement, this DPA, and any features or configurations that Customer enables within the Services. The subject matter, duration, nature, purposes, types of Personal Data, and categories of Data Subjects are described in Annex I.
If Nialli is required by applicable law to process Customer Personal Data other than in accordance with Customer’s instructions, Nialli will inform Customer of that legal requirement before processing (unless prohibited by law on grounds of public interest).
If Nialli reasonably believes that a Customer instruction infringes Applicable Data Protection Laws, Nialli will promptly inform Customer and may, pending resolution, suspend processing of the relevant data.
2.3 Customer Responsibilities
Customer is solely responsible for:
- The accuracy, legality, and appropriateness of Customer Personal Data;
- Obtaining all necessary notices, consents, and authorizations required by Applicable Data Protection Laws to permit Nialli’s processing as contemplated by the Agreement and this DPA;
- Customer’s configuration and use of the Services, including any Customer instructions given to Nialli;
- Ensuring Customer’s processing of Personal Data is lawful.
3. Confidentiality of Processing
Nialli will ensure that persons authorized to process Customer Personal Data are subject to enforceable contractual or statutory obligations of confidentiality and receive appropriate training with respect to data privacy and security. Nialli will limit access to Customer Personal Data to those personnel who require access to perform the Services.
4. Security Measures
Nialli will implement and maintain appropriate technical and organizational measures ("TOMs") designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature, scope, context, and purposes of processing and the risks to the rights and freedoms of Data Subjects.
The TOMs maintained by Nialli are described in Annex II (Security Measures). Nialli may update the TOMs from time to time to reflect improvements to security, provided that such updates do not materially reduce the overall level of protection afforded to Customer Personal Data.
5. Subprocessors
5.1 Authorization to Engage Subprocessors
Customer hereby grants Nialli general authorization to engage Subprocessors for the processing of Customer Personal Data in connection with the Services. Nialli’s current list of Subprocessors is published at: https://www.nialli.com/legal/subprocessors.
5.2 Nialli’s Obligations Regarding Subprocessors
When engaging a Subprocessor, Nialli will:
- Enter into a written agreement with the Subprocessor imposing data protection obligations no less protective than those in this DPA;
- Remain liable to Customer for the Subprocessor’s performance of its obligations under such agreement; and
- Maintain oversight of Subprocessor compliance.
5.3 Changes to Subprocessors and Objection Right
Nialli will provide notice (via its subprocessors page or by email to the Customer contact on record) of any intended addition or replacement of a Subprocessor with at least thirty (30) days’ prior notice.
Customer may object to a new or replacement Subprocessor on reasonable data protection grounds by notifying Nialli in writing within thirty (30) days of Nialli’s notice. If Customer objects, the Parties will work in good faith to resolve the objection (e.g., by configuring an alternative service, implementing additional safeguards, or modifying the services). If the objection cannot be resolved within a reasonable time, either Party may terminate the affected portion of the Services on written notice, without liability for such termination.
6. Assistance with Data Subject Rights
Taking into account the nature of the Processing and the information available to Nialli, Nialli will assist Customer by appropriate technical and organizational measures in fulfilling Customer’s obligations to respond to Data Subject requests to exercise rights under Applicable Data Protection Laws, including rights to:
- Access and obtain a copy of Personal Data;
- Rectification or correction of inaccurate Personal Data;
- Erasure or deletion of Personal Data;
- Restriction of processing;
- Data portability;
- Object to processing.
Customer is responsible for authenticating the identity of persons making requests and for determining how to respond. Where Nialli receives a Data Subject request directly, it will promptly forward it to Customer and refrain from responding except on Customer’s documented instructions or as required by applicable law.
7. Assistance with Compliance, DPIAs, and Prior Consultations
Nialli will provide reasonable assistance to Customer in connection with:
- Data protection impact assessments (DPIAs) relating to the Services, to the extent required by Applicable Data Protection Laws;
- Transfer risk assessments (TRAs) or transfer impact assessments (TIAs) relating to processing under the SCCs or UK Addendum;
- Prior consultations with Supervisory Authorities arising from DPIAs relating to the Services.
Nialli’s assistance under this section is limited to information relating to Nialli’s own processing and security practices and to the extent required by Applicable Data Protection Laws.
8. Security Incidents
8.1 Notification
Upon becoming aware of a Security Incident affecting Customer Personal Data, Nialli will notify Customer without undue delay (and, where reasonably feasible, within seventy-two (72) hours of becoming aware) and will provide Customer with the following information to the extent then known:
- A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and Customer Personal Data records affected;
- The likely consequences of the Security Incident;
- Measures taken or proposed to address the Security Incident, including to mitigate its possible adverse effects.
Nialli may provide notification and additional information in phases as information becomes available, and may withhold information where disclosure would compromise an ongoing investigation or is restricted by law.
8.2 Response
Nialli will take reasonable steps to investigate, contain, and remediate any Security Incident, and will cooperate with Customer as reasonably requested in connection with Customer’s own investigation and notification obligations.
Nialli’s notification of a Security Incident is not an acknowledgment of fault, negligence, or liability.
9. Return and Deletion of Customer Personal Data
Upon expiry or termination of the Services (or at Customer’s request at any time during the term), Nialli will, at Customer’s election and subject to Applicable Data Protection Laws:
- Return Customer Personal Data to Customer in a commonly used, machine-readable format; or
- Securely delete or destroy Customer Personal Data.
Nialli may retain Customer Personal Data for longer periods to the extent required by applicable law, provided that such retained data will be kept confidential, isolated from further active processing, and deleted once retention is no longer required by law.
Upon Customer’s request, Nialli will certify in writing that Customer Personal Data has been deleted in accordance with this section.
10. Audits and Demonstrations of Compliance
10.1 Information and Certifications
Nialli will make available to Customer, upon reasonable written request and subject to confidentiality obligations, the following information or documentation to demonstrate Nialli’s compliance with this DPA:
- Third-party audit reports, certifications, or executive summaries (e.g., SOC 2 Type II, ISO 27001, or equivalent);
- Written responses to information security questionnaires; and
- Other reasonably appropriate documentation about Nialli’s security program.
10.2 On-Site Audits
If documentation provided under Section 10.1 does not reasonably satisfy Customer’s obligations under Applicable Data Protection Laws, Customer may (at its own expense and on not less than thirty (30) days’ prior written notice) conduct, or appoint a mutually agreed qualified independent third-party auditor to conduct, a reasonable audit of Nialli’s processing of Customer Personal Data.
Any such audit will be:
- Conducted no more than once per calendar year (unless required by a Supervisory Authority);
- Conducted during Nialli’s normal business hours and in a manner that does not unduly disrupt Nialli’s operations;
- Subject to confidentiality obligations no less protective than those in the Agreement;
- Limited to systems and processes relevant to Nialli’s processing of Customer Personal Data.
Customer will bear the costs of any audit unless the audit reveals a material breach by Nialli of this DPA attributable to Nialli’s negligence or willful misconduct, in which case Nialli will bear its own reasonable costs.
11. International Transfers
11.1 EEA Transfers – EU SCCs
To the extent that Customer Personal Data originating in the EEA is transferred by Nialli to countries not recognized as providing an adequate level of protection, the Parties agree that the EU SCCs (Module 2: Controller to Processor) are incorporated into this DPA by reference and completed by:
- Annex I to this DPA (description of transfer and processing activities);
- Annex II to this DPA (technical and organizational security measures); and
- Annex III to this DPA (list of Subprocessors, as applicable).
Customer (as data exporter) and Nialli (as data importer) agree to be bound by the SCCs as so completed. In the event of any conflict between the SCCs and this DPA, the SCCs will prevail with respect to the international transfer.
11.2 UK Transfers – UK Addendum
For transfers of Customer Personal Data from the UK to a country not subject to adequacy regulations under UK law, the UK Addendum is incorporated into this DPA by reference and completed by the information in Annexes I, II, and III and the Agreement, as required by the UK Addendum template.
11.3 Swiss Transfers
For transfers of Customer Personal Data from Switzerland, the SCCs as incorporated in Section 11.1 apply with such modifications as are required under the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC), including substituting Swiss-specific references where applicable.
11.4 Supplementary Measures
The Parties will cooperate in good faith on transfer risk assessments (TRAs) and on the implementation of supplementary technical and organizational measures where required or appropriate to support lawful transfers.
12. California (CCPA/CPRA) – Service Provider Terms
To the extent that Customer Personal Data constitutes "Personal Information" of California residents under the CCPA/CPRA:
- Nialli is acting as a "Service Provider" and Customer is acting as a "Business" within the meaning of the CCPA/CPRA;
- Nialli will not "sell" or "share" (as defined in the CCPA/CPRA) Customer Personal Information;
- Nialli will not retain, use, or disclose Customer Personal Information for any purpose other than the specific business purpose of providing the Services, or as otherwise permitted by the CCPA/CPRA;
- Nialli will not combine Customer Personal Information with Personal Information received from other sources except as permitted for a Service Provider (e.g., to detect security incidents or to maintain or improve the Services, consistent with the context in which the Personal Information was collected);
- Nialli will assist Customer in responding to verifiable consumer requests consistent with Section 6 of this DPA;
- Nialli certifies that it understands and will comply with the restrictions set forth in this Section 12.
13. Government and Law Enforcement Requests
If Nialli receives a legally binding request from a law enforcement agency, regulatory authority, court, or other government body for access to or disclosure of Customer Personal Data, Nialli will, to the extent permitted by law:
- Notify Customer of the request promptly (and before disclosing, if permitted);
- Limit any disclosure to the minimum amount of data required to satisfy the legal obligation;
- Challenge requests that appear unlawful, overbroad, or not supported by legally valid process.
Where notification is legally prohibited, Nialli will use reasonable efforts to obtain a waiver of that prohibition and will notify Customer as soon as permitted.
14. Liability
Each Party’s liability under this DPA (including in connection with any SCCs or UK Addendum incorporated herein) is subject to the limitations and exclusions of liability set out in the Agreement, to the extent permitted by applicable law. This limitation does not apply to losses incurred by Data Subjects arising from breaches of the SCCs or UK Addendum, for which liability is governed by those instruments.
15. Term and Termination
This DPA commences on the effective date of the Agreement and continues for the duration of the Agreement. This DPA will terminate automatically upon the termination or expiry of all Services under the Agreement.
Provisions that by their nature should survive termination will survive, including Sections 9 (Return and Deletion), 10 (Audits), 11 (International Transfers), 12 (California), and 14 (Liability).
16. Artificial Intelligence and Automated Processing
16.1 Restrictions on AI Training
Nialli will not use Customer Personal Data to train, fine-tune, benchmark, or otherwise improve any AI or machine learning model – whether developed by Nialli or a third party – without the prior written consent of Customer. This restriction applies regardless of whether the data is pseudonymised or aggregated, unless the data has been irreversibly anonymised such that re-identification is not reasonably possible.
Nialli will ensure, through contractual commitments with its Subprocessors, that Subprocessors are subject to equivalent restrictions on the use of Customer Personal Data for AI training purposes.
16.2 AI Features Within the Services
Nialli offers and uses AI-powered features within the Services (“AI Features”). Active AI Features as of the date of this DPA include HubSpot Breeze Copilot (AI assistant operating on CRM data), Breeze Intelligence (automated data enrichment), Breeze Customer Agent (AI chat on nialli.com), and Breeze Prospecting Agent (AI-assisted prospect research and outreach). Breeze Content Agent and Social Agent are also active for internal content creation and do not directly process Customer Personal Data. Nialli’s HubSpot contract DPA explicitly covers all Breeze components. Where AI Features process Customer Personal Data, Nialli will:
Disclose the use of AI Features in the applicable service documentation or this DPA;
Process Customer Personal Data through AI Features only to the extent necessary to provide the Services and only in accordance with Customer’s documented instructions;
Not enable AI Features that process Customer Personal Data by default where such use requires separate Customer consent under Applicable Data Protection Laws, unless Customer has provided that consent.
Specific note on Breeze Intelligence: Breeze Intelligence is an AI-powered data enrichment feature within HubSpot that automatically researches company and contact records and appends or updates data fields (such as firmographics, job titles, and technology data) using HubSpot’s third-party data sources. Where Customer Personal Data is processed by Breeze Intelligence, this constitutes automated processing that writes new inferred data points to existing records. Nialli uses Breeze Intelligence on its own CRM and sales data; to the extent Customer Personal Data flows through Nialli’s HubSpot instance (e.g., contact data submitted by Customers for support or onboarding purposes), Nialli will ensure Breeze Intelligence operates only on data fields Nialli is authorised to enrich, consistent with this DPA. HubSpot’s enrichment data sources (including Bombora and similar providers) function as sub-subprocessors of HubSpot for Breeze Intelligence purposes; they are subject to HubSpot’s subprocessor terms and DPA. Individuals whose records are enriched may exercise data rights by contacting PrivacyOfficer@nialli.com.
16.3 Automated Decision-Making
Where Nialli’s processing of Customer Personal Data involves solely automated decision-making that produces legal or similarly significant effects on Data Subjects (within the meaning of GDPR Article 22 or equivalent provisions of Applicable Data Protection Laws), Nialli will:
Disclose such processing to Customer prior to implementation;
Implement appropriate safeguards as required by Applicable Data Protection Laws;
Assist Customer in meeting any obligations to inform Data Subjects and, where applicable, to implement a mechanism for human review.
As of the date of this DPA, Nialli does not employ solely automated decision-making that produces legal or similarly significant effects on Data Subjects in connection with the Services. Nialli will provide reasonable prior written notice to Customer before introducing any such processing.
16.4 Subprocessor AI Features
HubSpot Breeze AI components are active Subprocessor AI features. Nialli’s HubSpot contract DPA explicitly covers all Breeze components. Active Breeze features and their data processing scope: (i) Breeze Customer Agent – processes conversation transcripts from nialli.com visitors; (ii) Breeze Copilot – processes CRM contact, deal, and email data to generate team suggestions; (iii) Breeze Intelligence – processes and enriches contact and company records using third-party data sources (sub-subprocessors include Bombora and similar providers under HubSpot’s DPA); (iv) Breeze Prospecting Agent – processes CRM and publicly available data for prospect research and outreach drafting; (v) Breeze Content Agent and Social Agent – operate on Nialli-controlled content data; do not directly process Customer Personal Data. None of the above Breeze components are used to train HubSpot AI models on Customer Personal Data without opt-in; Nialli has not opted in to such use. Nialli will:
Review and, where necessary, restrict the activation of Subprocessor AI features that would process Customer Personal Data in a manner inconsistent with this DPA;
Update the Subprocessors List (Annex III) when AI-capable Subprocessors are added or when material AI feature changes affect the processing of Customer Personal Data;
Require Subprocessors to provide notice of material changes to their AI feature terms that affect Customer Personal Data.
16.5 EU AI Act and Other AI Regulations
The Parties acknowledge that AI-specific regulations, including the EU AI Act (Regulation (EU) 2024/1689), the Canadian Artificial Intelligence and Data Act (AIDA), and applicable US state AI laws, impose or will impose obligations on entities that develop, deploy, or use AI systems.
As between the Parties:
Each Party is responsible for its own compliance with applicable AI regulations in respect of AI systems it independently develops or deploys;
Where the Services involve AI systems that are subject to the EU AI Act, Nialli will provide Customer with the information and cooperation reasonably necessary for Customer to meet its obligations as a “deployer” under the EU AI Act;
Where Nialli acts as a “provider” of an AI system under the EU AI Act that is incorporated into or offered as part of the Services, Nialli will comply with the applicable provider obligations under that Act.
Nialli will update this section and the Agreement as AI regulatory obligations applicable to the Services are clarified or come into force, and will provide reasonable notice to Customer of material changes.
17. Miscellaneous
- Governing Law. This DPA is governed by the laws set out in the Agreement, unless Applicable Data Protection Laws or the SCCs/UK Addendum require otherwise.
- Severability. If any provision of this DPA is held to be invalid, illegal, or unenforceable, the remaining provisions will remain in full force and effect.
- Entire Agreement. This DPA, together with the Agreement and any SCCs/UK Addendum incorporated herein, constitutes the entire agreement between the Parties with respect to the processing of Customer Personal Data and supersedes all prior agreements or understandings relating to the same subject matter.
- Amendment. Nialli may update this DPA from time to time to reflect changes in Applicable Data Protection Laws or Nialli’s practices. Nialli will provide reasonable notice of material changes. Continued use of the Services after the effective date of any update constitutes acceptance.
Annex I – Details of Processing
A. Parties
| Data Exporter (Controller) | Customer as identified in the Agreement. Contact: as set out in the Agreement. |
|---|---|
| Data Importer (Processor) | Nialli Inc. (and its affiliates, where applicable). 1301 – 401 9th Ave. SW, Calgary, AB T2P 3C5, Canada. Contact: PrivacyOfficer@nialli.com. |
B. Description of Transfer and Processing
| Subject Matter | Provision of Nialli products, cloud services, and support to Customer. |
|---|---|
| Duration | For the term of the Agreement; Customer Personal Data retained as per Section 9 and Applicable Data Protection Laws. |
| Nature of Processing | Hosting, storage, retrieval, transmission, analysis, support, security monitoring, backup, and other processing necessary to provide and improve the Services in accordance with Customer’s documented instructions. |
| Purpose of Processing | To provide the Services as described in the Agreement; to maintain and improve service performance; to ensure security and integrity; to fulfill legal obligations; and to execute documented Customer instructions. |
| Categories of Personal Data | Contact and professional data (name, email, phone, job title, company); account credentials; usage, telemetry, and device data; support communications; transaction data; and other data submitted by or for Customer through the Services. |
| Special Categories of Personal Data | Not expected. Customer agrees not to submit special categories of personal data (as defined under GDPR Article 9) without prior written agreement with Nialli. |
| Categories of Data Subjects | Customer’s employees, contractors, and end users; and other individuals whose data is submitted by or on behalf of Customer through the Services. |
| Frequency of Transfer | Continuous for the duration of the Agreement. |
| Subprocessors | As listed in Annex III and at https://www.nialli.com/legal/subprocessors. |
C. Competent Supervisory Authority
The lead supervisory authority will be determined in accordance with GDPR Article 55 or 56 based on the Customer’s location within the EEA. For UK Data Subjects, the competent authority is the UK Information Commissioner’s Office (ICO).
Annex II – Technical and Organizational Security Measures
Nialli maintains a risk-based information security program. The measures described below represent the current state of Nialli’s security controls. Nialli may update these measures over time to reflect improvements, provided that any updates do not materially reduce the overall level of protection.
| Governance and Policies | Documented information security policies and standards; designated security leadership; periodic review and update of policies; risk management program. |
|---|---|
| Access Controls | Role-based access control (RBAC); principle of least privilege; multi-factor authentication (MFA) for privileged and remote access; account provisioning and de-provisioning procedures; session management and timeout controls; access logging and review. |
| Encryption | TLS (1.2 or higher) for data in transit; industry-standard encryption for credentials and sensitive configuration data; key management procedures. |
| Network and System Security | Network segmentation; firewalls and web application firewall (WAF); DDoS mitigation; vulnerability scanning and patch management; anti-malware controls; secure configuration baselines for systems and services. |
| Secure Development | Secure software development lifecycle (SSDLC); code review and security testing; dependency and supply chain scanning; secrets management; separation of development, staging, and production environments. |
| Monitoring and Detection | Centralized logging and SIEM; real-time alerting; anomaly detection; defined incident response runbooks; regular drills and tabletop exercises. |
| Business Continuity and Disaster Recovery | Regular data backups; tested business continuity and disaster recovery plans; defined recovery time and recovery point objectives. |
| Third-Party Risk Management | Vendor due diligence prior to engagement; contractual security and data protection requirements; periodic monitoring of key subprocessors. |
| Physical Security | Physical access controls at data center facilities (maintained by Nialli’s infrastructure providers in accordance with their security certifications). |
| Personnel | Background screening as permitted by applicable law; confidentiality obligations for all personnel; onboarding and offboarding access controls; annual security awareness training. |
| Audits and Certifications | Periodic internal and third-party security assessments; provision of independent audit reports or summaries (e.g., SOC 2, ISO 27001) under confidentiality upon request. |
Annex III – Subprocessors
Nialli’s current list of Subprocessors engaged in the processing of Customer Personal Data in connection with the Services is maintained at:
https://www.nialli.com/legal/subprocessors
This list is updated when Nialli adds, modifies, or removes a Subprocessor. Customer may subscribe to notifications of changes via the mechanism described on that page or by contacting PrivacyOfficer@nialli.com.
Note: This Annex III applies to Subprocessors engaged in processing Customer Personal Data in connection with Nialli’s enterprise products and services. Subprocessors engaged for nialli.com website operations are listed separately on the same Subprocessors page.