Data Processing Agreement
Your customers’ data, processed on your behalf.
When customers register a product, your brand is the controller and ItemDocs is your processor. These are the terms (GDPR Art. 28).
Last updated 5 October 2026. Part of the Terms of service.
- 1. Parties and roles
- You (the manufacturer or brand using ItemDocs) are the controller of the personal data your customers enter in your product registration form. Nexivara (a sole proprietorship of Karan Bindal, Jaipur, India), operator of ItemDocs, is your processor. This agreement forms part of the Terms of service and applies for as long as you use ItemDocs.
- 2. Subject matter and data
- Storing product registrations and showing them to your team in the Console, exporting them for you, and sending the registration confirmation emails you switch on. Data: the fields you choose to collect (for example name, email, phone, postal address, purchase date and place, invoice and serial number, marketing consent), plus language, country and time of registration. Data subjects: your customers. No special-category data should be collected.
- 3. Instructions
- We process the data only on your documented instructions, which are these terms and your settings in the Console, unless the law requires otherwise (we’ll tell you first where we’re allowed to).
- 4. Confidentiality
- Only people who need access to run and support the service can access the data, and they are bound by confidentiality.
- 5. Security (Art. 32)
- Encryption in transit (HTTPS with HSTS) and at rest; hashed credentials and session tokens; role-based access within your organisation; strict tenant isolation; rate limits; an activity log of changes; hosting in the EU (Frankfurt).
- 6. Sub-processors
- You authorise the sub-processors listed in the Privacy notice. We impose the same data-protection obligations on them, announce changes on that page before they apply, and you can object by contacting us; if we can’t accommodate the objection you may stop using the service.
- 7. International transfers
- Data is stored in the EU. Where a sub-processor or our support team processes it outside the EEA/UK, the transfer is covered by an adequacy decision or the European Commission’s Standard Contractual Clauses.
- 8. Helping you with requests
- You can view, export and correct registrations in the Console. We assist you with data subject requests (access, erasure, objection and so on) that you can’t handle yourself, and forward requests sent to us about your registrations.
- 9. Breaches
- We notify you without undue delay after becoming aware of a personal-data breach affecting your registrations, with the information you need for your own notifications.
- 10. Deletion and return
- Export everything at any time from Settings. When you delete your organisation, registrations are erased after a 30-day recovery period; backups expire within a further 30 days.
- 11. Audits
- We make available the information needed to demonstrate compliance with Art. 28 and answer reasonable security questionnaires. Larger customers can agree further audit terms in an enterprise contract.
Need a signed copy for your records? Ask through the contact form.