// data processing
Data Processing Addendum
Last updated 21 August 2026
This Data Processing Addendum (“DPA”) supplements the HYN-view Terms of Use when NEXUSV TECHNOLOGIES PRIVATE LIMITED(“NexusV”) processes Customer Personal Data on behalf of a customer through the Hosted Service and data-protection law requires processor terms. The customer is the person or organisation identified by the applicable HYN-view account and instructions.
1. Roles and scope
The customer is controller of Customer Personal Data contained in telemetry or configuration that it chooses to send. NexusV is processor for that data. NexusV remains an independent controller or Data Fiduciary for account, authentication, fraud-prevention, security and legal-compliance information, as described in the Privacy Policy.
“Customer Personal Data” means personal data processed by NexusV on the customer's behalf through the Hosted Service. “Data Protection Law” means law applicable to that processing, including the EU/EEA GDPR where applicable.
2. Documented instructions
NexusV will process Customer Personal Data only to provide, secure and support the Hosted Service; receive notification-delivery records from linked agents; perform configuration and deletion requests; comply with the Terms; and meet legal obligations. Notification messages are sent directly by each monitored server to destinations configured locally by its administrator, not routed through central portal credentials. The Terms, this DPA, account settings and lawful support requests are the customer's documented instructions.
NexusV will inform the customer if an instruction appears to infringe applicable Data Protection Law, unless law prohibits notice. The customer is responsible for the lawfulness, accuracy and minimisation of its instructions and for giving required notices and obtaining required permissions.
3. Confidentiality and security
NexusV will limit access to personnel and providers who need it for their work and are subject to appropriate confidentiality duties. Safeguards include HTTPS, Supabase authentication, tenant row-level policies, restricted privileged roles, hashed node and pairing credentials, administrative action logging and local root-only secret-file permissions where configured. No measure eliminates all risk.
The customer is responsible for account access, monitored servers, local configuration, destination providers, staff permissions, backups and incident response. See the Security Policy.
4. Subprocessors
The customer gives general authorisation for the providers in the provider and subprocessor list. NexusV will impose data-protection obligations appropriate to each provider's function and remains responsible for its processor obligations to the extent required by law.
NexusV will give at least 30 days' notice of a new primary subprocessor where practical. A customer with a reasonable data-protection objection should contact NexusV during that period. The parties will try in good faith to find an alternative; if none is available, the customer may stop the affected processing and request deletion. Urgent security or continuity changes may occur sooner.
5. Assistance and incidents
Taking account of the processing and available information, NexusV will provide reasonable assistance with data-subject requests, security obligations, personal-data-breach notifications, impact assessments and regulator consultations required by law. If NexusV becomes aware of a confirmed personal-data breach affecting Customer Personal Data, it will notify the customer without undue delay and provide information reasonably needed for the customer's obligations. Notice is not an admission of fault.
The customer must promptly forward any request NexusV should handle as its processor and must not send unnecessary personal data in support correspondence.
6. Return and deletion
During an active account, the customer may request an available export by email. On a verified deletion request or termination, NexusV will delete requested Customer Personal Data from active Hosted Service systems within 7 days, as described in the Privacy Policy. Limited copies may remain temporarily in provider backups or security records, or where law requires retention; they remain protected, are not used for ordinary service purposes and are removed or allowed to expire under the applicable schedule.
7. Information and audits
NexusV will provide information reasonably necessary to demonstrate compliance with processor obligations. If that is insufficient, a business customer may request an audit no more than once per year, unless a regulator or confirmed incident reasonably requires more. Audits must be proportionate, protect other customers and confidential information, avoid disruption and use an independent qualified auditor. The customer bears reasonable audit costs unless the audit identifies a material NexusV breach.
8. International transfers
The Supabase project's primary database region is configured as Mumbai, India. Vercel, Supabase, Resend and optional providers may process data elsewhere. The parties will use an applicable transfer mechanism before a restricted transfer, such as an adequacy decision or applicable standard contractual clauses with required supplementary safeguards. This DPA does not claim all processing occurs in India.
9. Processing details
- Subject matter and purpose: hosting and displaying server-health telemetry, authenticating users, recording notification delivery outcomes, support and security.
- Duration: the account term and retention period in the Privacy Policy.
- Nature and frequency: automated collection from linked agents, storage, organisation, display, retrieval and deletion, ordinarily on the configured interval. A monitored server separately transmits notification messages to destinations configured locally by its administrator.
- People concerned: customer personnel, authorised users, administrators and people whose identifiers may appear in authorised telemetry or alerts.
- Data categories: account, host and node identifiers; system, resource, network, process, service and alert data; notification destinations and records; and request or security metadata.
- Sensitive data: not intentionally required. Customers must not send special-category data, passwords, private keys, or message content unrelated or unnecessary to an authorised server-health notification unless NexusV expressly agrees in writing and lawful safeguards are in place.
10. Precedence and liability
For processor obligations, this DPA controls over a conflicting Terms provision. A separately signed data-processing or transfer agreement controls over this public DPA. Liability is subject to lawful limitations in the Terms, without limiting rights or liabilities that cannot lawfully be limited.
Processor: NEXUSV TECHNOLOGIES PRIVATE LIMITED
Privacy contact: vivek.aryanvbw@gmail.com
Hosted Service: www.hyn-view.in and www.hyn-view.info