NexusMotive Legal
Data Processing Addendum
How NexusMotive processes Customer Data on behalf of Dealer Customers — technical and organizational measures, sub-processors, breach notification, audit rights.
Table of contents
- 1. Roles of the Parties
- 2. Subject Matter and Duration
- 3. Processor Obligations
- 4. Controller Obligations
- 5. Technical and Organizational Measures (TOMs)
- 6. Sub-Processors
- 7. Assistance with Data-Subject Requests
- 8. Personal-Data Breach Notification
- 9. Audit Rights
- 10. Cross-Border Transfers
- 11. Term
- 12. Contact
This Data Processing Addendum ("DPA") supplements the NexusMotive Terms of Service and any executed Order Form between NexusMotive, Inc. ("Processor") and the Dealer Customer ("Controller"). It governs Processor's processing of Customer Data on Controller's behalf.
In the event of a conflict between this DPA and the Terms or Order Form, this DPA governs as to the subject matter addressed herein.
1. Roles of the Parties#
For Customer Data submitted to the Platform by Controller or an End User, the Dealer Customer is the Controller (the "business" under CCPA) and NexusMotive is the Processor (the "service provider" under CCPA). NexusMotive will process Customer Data only on Controller's documented instructions, including with regard to transfers, except where required to do otherwise by applicable law.
2. Subject Matter and Duration#
Subject matter — the provision of the Platform as described in the Terms and the applicable Order Form, including operating the dealer's website, lead routing, CRM and DMS connectors, ad-measurement, the AI Inventory Connector, and the NexusID identity graph.
Duration — the term of the applicable Order Form, plus the limited post-termination retention window described in §10 of the Terms.
Nature and purpose of processing — hosting, transmission, storage, access, retrieval, aggregation, and deletion of Customer Data as needed to deliver the Platform.
Types of personal data — identifiers and contact data, vehicle-interest data, transaction data, service data, behavioral data, communication data, and derived inferences, all as detailed in §1 of the Privacy Policy.
Categories of data subjects — End Users of the Controller's website, Controller's sales and service customers, and Controller's authorized users of the admin dashboard.
3. Processor Obligations#
NexusMotive will:
- Process Customer Data only on Controller's documented instructions, including those set out in the Order Form, the Terms, this DPA, and any subsequent written instructions Controller issues through the admin dashboard or by written communication to legal@nexusmotive.com.
- Ensure that personnel authorized to process Customer Data are subject to confidentiality obligations.
- Implement and maintain the technical and organizational measures described in §5 below.
- Engage sub-processors only in accordance with §6 below.
- Assist Controller with responding to data-subject requests under §7 below.
- Notify Controller of personal-data breaches under §8 below.
- On termination, return or delete Customer Data in accordance with §10 of the Terms.
4. Controller Obligations#
Controller represents and warrants that:
- It has provided all required notices to End Users and obtained any required consents before submitting Customer Data to the Platform.
- Its instructions to NexusMotive comply with applicable law, including the CCPA, the FTC Safeguards Rule, and any other privacy or financial-services law applicable to the Controller.
- It maintains its own information-security program appropriate to the data it controls.
- It will not submit to the Platform any data category that NexusMotive declines to process (for example, Social Security numbers, drivers-license numbers, or financial-account numbers other than as required by an explicit feature of the Platform).
5. Technical and Organizational Measures (TOMs)#
NexusMotive maintains the following safeguards:
- Encryption at rest — AES-256-GCM for all personally identifying fields, using per-tenant AWS KMS customer master keys. The IAM policy on each tenant key denies kms:Decrypt to the platform-administrator role pattern; platform admins cannot decrypt Controller's PII.
- Encryption in transit — TLS 1.2 or higher with modern cipher suites (no SSLv3, no early TLS) on every external endpoint. HSTS is enforced on production hostnames.
- Access control — role-based access control with the principle of least privilege; multi-factor authentication required for all administrative access; just-in-time elevation for production database access with audit-logged justification.
- Network segmentation — production data plane is isolated in a private VPC; egress is filtered; AWS WAF protects public endpoints; rate-limiting and bot-mitigation rules are applied at the edge.
- Audit logging — every read and write of Customer Data is logged with actor, timestamp, action, and tenant. Logs are retained for at least 12 months on tamper-evident storage.
- Vulnerability management — automated dependency scanning, container-image scanning, and quarterly authenticated vulnerability scans of the production environment. Critical vulnerabilities are remediated within 7 days.
- Penetration testing — independent third-party penetration test performed at least annually; remediation tracked to closure.
- Backup and disaster recovery — encrypted database backups with point-in-time recovery; cross-region disaster-recovery plan tested at least annually; defined Recovery Time Objective (4 hours) and Recovery Point Objective (15 minutes) for production.
- Personnel — background checks on engineering and operations staff; mandatory annual security and privacy training; signed confidentiality agreements; immediate access revocation on termination.
- Secure development — code review on all production-bound changes; static application security testing in CI; secrets stored only in AWS Secrets Manager; no production credentials in source control.
6. Sub-Processors#
Controller authorizes NexusMotive to engage the following sub-processors:
- Amazon Web Services, Inc. (United States (us-east-1, us-west-2)) — Primary cloud hosting — Aurora PostgreSQL, ECS Fargate, ElastiCache, S3, KMS, CloudFront, Lambda@Edge, Route 53, WAF.
- Stripe, Inc. (United States) — Payment processing for dealer subscriptions and end-user transactions where applicable.
- Twilio SendGrid (United States) — Transactional email delivery (lead receipts, password resets, dealer alerts).
- Meilisearch SAS (France / United States) — Inventory search indexing (vehicle metadata only — no consumer PII).
- Google LLC (United States) — Google Ads conversion measurement, Google Analytics 4, Google Merchant Center inventory feeds — all driven by dealer-owned accounts.
- Meta Platforms, Inc. (United States) — Conversions API and Pixel measurement on behalf of dealers running paid Meta ads.
- OpenAI, OpenAI / Anthropic / Perplexity / Microsoft (Bing) / Google (Gemini) (United States) — AI shopping surfaces that call the NexusMotive AI Inventory Connector on behalf of end users.
- Sentry (Functional Software, Inc.) (United States) — Production error monitoring and performance traces. PII is redacted before transmission.
- Cloudflare, Inc. (United States) — DNS for the nexusmotive.com apex and DDoS mitigation for the marketing site.
NexusMotive will impose written obligations on each sub-processor that are no less protective of Customer Data than the obligations imposed on NexusMotive under this DPA. NexusMotive will give Controller at least 30 days' notice before engaging a new sub-processor by updating this page; Controller may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection (which may include terminating the affected service for a pro-rata refund of pre-paid fees).
7. Assistance with Data-Subject Requests#
When an End User submits a data-subject request directly to NexusMotive, NexusMotive will, where reasonably possible, route the request to the originating Controller and provide reasonable technical assistance for Controller to respond.
When Controller submits a data-subject request to NexusMotive on behalf of an End User, NexusMotive will assist Controller in fulfilling the request within the statutory window applicable under the CCPA (generally 45 days, extendable by 45 days where reasonably necessary). NexusMotive provides self-service tooling in the admin dashboard for the most common request types (export, delete, correct).
NexusMotive will not require Controller to send NexusMotive an End User's PII solely to identify the End User's records within the Platform; identifiers such as NexusID, lead ID, or hashed email are sufficient.
8. Personal-Data Breach Notification#
NexusMotive will notify Controller without undue delay, and in any event within 72 hours after NexusMotive becomes aware of a personal-data breach affecting Customer Data. The notice will describe, to the extent then known:
- The nature of the breach, including the categories and approximate number of affected data subjects and records.
- The likely consequences of the breach.
- The measures NexusMotive has taken or proposes to take to address the breach and to mitigate adverse effects.
- A point of contact at NexusMotive for further information.
NexusMotive will cooperate with Controller's reasonable efforts to investigate, mitigate, and notify regulators or affected individuals.
9. Audit Rights#
NexusMotive will, on Controller's written request no more than once per 12-month period, provide Controller with:
- A copy of the most recent SOC 2 Type II report (under NDA).
- A completed Cloud Security Alliance CAIQ or equivalent due-diligence questionnaire.
- Reasonable responses to follow-up questions in writing.
If the above information is not sufficient to demonstrate compliance, the parties will discuss a scoped on-site or virtual audit, at Controller's expense, conducted by a mutually acceptable independent auditor under appropriate confidentiality and during normal business hours, and not unreasonably interfering with NexusMotive's operations.
10. Cross-Border Transfers#
NexusMotive processes Customer Data exclusively in the United States. NexusMotive does not target the European Economic Area or the United Kingdom and does not rely on Standard Contractual Clauses; no SCCs apply to this DPA. If Controller introduces data subjects from a jurisdiction with cross-border-transfer restrictions, Controller is responsible for evaluating whether the Platform meets its compliance needs.
11. Term#
This DPA takes effect on the later of (a) the effective date of the applicable Order Form and (b) the date NexusMotive publishes this DPA at this URL, and remains in effect until the termination of the Order Form, plus any post-termination period during which NexusMotive retains Customer Data.
12. Contact#
For DPA questions or to submit a data-subject request on behalf of an End User, contact privacy@nexusmotive.com. For sub-processor objections or audit requests, contact legal@nexusmotive.com.