Data Processing Addendum (DPA)
This page explains the matters Invokora and a business customer need to agree on in a Data Processing Addendum. It is not a signed agreement. The addendum takes effect only after both parties sign a written document identifying the parties and the processing activities. To request one, email support@invokora.com.
Agreement overview; updated September 9, 2026.Scope and responsibilities
The addendum must identify NEXUSCORTEX LLC and the business customer by full name and contact details, and describe the processing each is responsible for. Who decides the purposes and means of processing, and who acts on instructions, depends on the actual activities. Not signing the addendum described here does not remove legal duties.
Invokora is responsible for processing whose purposes it determines, including accounts, identity checks, transactions, tax, fraud prevention, security, audits, and consented website analytics. When we handle personal information on a business customer’s instructions, the addendum sets out the parties’ responsibilities. Merchants remain responsible for their data-protection duties for API requests received by their own servers.
Data and purposes
The addendum must describe whose information is involved, the data categories, any sensitive information, and the purpose, method, frequency, duration, and location of processing.
We process personal information under the customer’s control only on lawful written instructions, including instructions for international transfers. If the law requires otherwise, we will notify the customer before processing unless the law prohibits notice. We will tell the customer if an instruction may be unlawful. We do not use this information for marketing profiles, model training, or product development unrelated to the service.
Confidentiality and security
People with access to personal information must have a duty of confidentiality. The security schedule must describe measures relevant to the actual service, including access controls, identity checks, encryption in transit and at rest, key management, data isolation, log protection, vulnerability handling, file scanning, backup recovery, and incident response.
The schedule must also state where the measures apply, evidence of implementation, service-provider review requirements, and how gaps will be addressed. The parties should verify the measures and implementation evidence before signing.
Other providers involved in processing
Other providers that process personal information on the customer’s behalf are called subprocessors. The addendum must identify them, their services, processing locations, data involved, and safeguards for international transfers.
Using a subprocessor requires the customer’s prior specific or general written authorization. Additions or replacements require advance notice as agreed, with an opportunity to object and discuss alternatives. We must contractually require appropriate data-protection obligations and remain responsible for their performance as required by applicable law and the addendum.
Privacy requests and assistance
We will assist with access, correction, deletion, copies, restriction, objection, and data portability as required by applicable law and the addendum. For data whose purposes the customer determines, the customer verifies the requester’s identity, assesses the basis for the request, and prepares the response. We retain our own responsibilities for processing whose purposes we determine.
Online requests currently require identity verification and manual review. They do not automatically provide a data copy or delete an account. We mark a request complete only after verifying the relevant export, correction, or deletion and any necessary account and subscription actions.
The addendum must set out how assistance is provided, response times, and any fees, including assistance with data-protection impact assessments and necessary regulatory consultations. These terms cannot remove either party’s legal duties.
Retention, return, and deletion
The API Gateway does not store query parameters, request or response headers, or bodies. Call records are kept for no more than 30 days. Aggregate usage and financial records follow their applicable retention periods. Quote and service files follow the order-related periods in the Privacy Policy.
When the service ends, personal information processed for the customer is returned or deleted at the customer’s choice within the agreed period, including handling of existing copies. The addendum must specify how backup copies are deleted and identify records that must be kept by law, the reasons, and the retention periods.
Payment, tax, contract, security, and dispute records that must be kept by law are not automatically deleted when the contract ends. A retention requirement applies only to the affected data and does not prevent normal deletion of other data.
Security incident notices
When we become aware of a breach or other security incident involving customer personal information, we will notify the customer promptly within the time required by applicable law and the addendum. We will not wait for the investigation to finish. The initial notice will give the known scope, steps taken, and a contact, followed by updates on findings and remedies.
The addendum must specify notice channels, each party’s response duties, and assistance with notices to regulators and affected people.
Audits and international transfers
We must provide necessary information and cooperate with checks by the customer or its appointed auditor as required by applicable law and the addendum. Audit scope, frequency, confidentiality, remote evidence, and on-site arrangements are agreed in the addendum.
For international transfers, the addendum must identify recipients, processing locations, and applicable safeguards, such as an adequacy decision or standard contractual clauses, with a transfer impact assessment where required.
Before signing, the parties must also agree on governing law, liability and indemnity, priority when documents conflict, the security schedule, and the subprocessor list. The signed addendum and applicable law determine the parties’ rights and duties.
