Data Processing Addendum (DPA)
Last updated: October 27, 2025
Overview
This Data Processing Addendum ("DPA") forms part of N3W's Terms of Service and Privacy Policy. It describes how N3W processes personal data and lists all subprocessors (third-party service providers) we use to deliver our services.
This DPA applies to all users of the N3W™ platform and is designed to comply with GDPR, CCPA, and other applicable data protection laws.
Definitions
- Controller: The entity that determines the purposes and means of processing personal data (You, the user)
- Processor: The entity that processes personal data on behalf of the Controller (N3W)
- Subprocessor: Third-party service providers engaged by N3W to assist in processing personal data
- Personal Data: Any information relating to an identified or identifiable individual
- Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion)
Data Processing Activities
Types of Personal Data Processed
- Account Information: Name, email address, authentication tokens
- Chat Data: Conversation messages, timestamps, user queries
- Uploaded Files: Images, documents (with EXIF metadata stripped)
- Professional Credentials: For professionals in our directory (licenses, certifications)
- Payment Information: Processed by Stripe (we do not store credit card details)
- Usage Data: Feature usage, session duration, error logs
- Technical Data: IP address, browser type, device information
Purposes of Processing
- Provide AI-powered wellness conversation platform
- Connect users with independent wellness professionals
- Process payments and manage subscriptions
- Improve service quality and user experience
- Ensure platform security and prevent abuse
- Comply with legal obligations
Subprocessors
N3W engages the following third-party subprocessors to provide our services. Each subprocessor has been vetted for security and compliance.
Infrastructure & Hosting
| Subprocessor | Service | Data Processed | Location | Compliance |
|---|---|---|---|---|
| Vercel Inc. | Application hosting | User requests, logs | United States | SOC 2, ISO 27001 |
| Supabase Inc. | Database, authentication, file storage | All user data, messages, files | United States | SOC 2 Type II, ISO 27001, GDPR |
AI & Language Models
| Subprocessor | Service | Data Processed | Location | Compliance |
|---|---|---|---|---|
| OpenRouter | LLM API aggregator | Redacted chat messages (PII removed) | United States | N/A (Proxy service) |
| OpenAI (via OpenRouter) | GPT models, embeddings | Redacted chat messages, document embeddings | United States | SOC 2, Zero data retention (API) |
| Google (via OpenRouter) | Gemini models | Redacted chat messages | United States | SOC 2, ISO 27001, GDPR |
| Anthropic (via OpenRouter) | Claude models | Redacted chat messages | United States | SOC 2, Zero data retention (API) |
Payment Processing
| Subprocessor | Service | Data Processed | Location | Compliance |
|---|---|---|---|---|
| Stripe Inc. | Payment processing, subscriptions | Payment details, billing address, customer ID | United States | PCI DSS Level 1, SOC 1/2, GDPR |
Monitoring & Error Tracking
| Subprocessor | Service | Data Processed | Location | Compliance |
|---|---|---|---|---|
| Sentry | Error tracking, performance monitoring | Error logs (PII scrubbed), stack traces | United States | SOC 2, GDPR |
| Umami Analytics | Privacy-focused web analytics | Anonymized page views, referrers (no cookies) | Europe | GDPR-compliant (no PII) |
Data Retention
N3W and our subprocessors retain personal data only as long as necessary for the purposes outlined in this DPA and our Privacy Policy.
Retention Periods
- Chat Messages: Stored to provide the service and may be automatically deleted after a limited retention period (by default, messages older than 180 days may be removed by scheduled server cleanup unless we configure a different period in production). Users may also delete conversations or their entire account sooner.
- Account Data: Until you delete your account; deletion initiated in the N3 Wellness app is processed permanently subject to legal retention requirements described in our Privacy Policy
- Professional profile & application data: Retained as necessary to operate the directory and process applications, then deleted or de-identified when no longer needed for legal, security, operational, or compliance purposes
- Payment Records: 7 years (legal requirement for tax purposes)
- Audit logs, consent records, backups, and verification-related records: Retained as necessary for legal, security, operational, or compliance purposes, then deleted or de-identified when no longer needed
AI Provider Data Retention
- OpenAI: Zero retention via API (data not used for training)
- Anthropic: Zero retention via API (data not used for training)
- Google (Gemini): Zero retention via API (commercial tier)
Security Measures
N3W and our subprocessors implement industry-standard security measures to protect personal data:
Technical Measures
- Encryption in Transit: TLS 1.3 for all data transmission
- Encryption at Rest: AES-256 for database and file storage
- Row-Level Security (RLS): Database-level access control
- PII Redaction: Automatic removal of sensitive data before AI processing
- EXIF Stripping: Removal of metadata from uploaded images
- Output Validation: Scanning AI responses for leaked secrets/PII
Organizational Measures
- Access Control: Role-based access with least privilege principle
- Security Monitoring: 24/7 automated alerts for anomalies
- Incident Response: Documented procedures with 72-hour notification
- Regular Audits: Daily automated security checks
- Vendor Vetting: Due diligence on all subprocessors
International Data Transfers
Most of our subprocessors are located in the United States. When we transfer personal data from the EU/EEA, we rely on:
- Standard Contractual Clauses (SCCs): Approved by the European Commission
- Adequacy Decisions: Where applicable (e.g., EU-US Data Privacy Framework)
- Subprocessor Certifications: SOC 2, ISO 27001, GDPR compliance programs
Supabase provides EU hosting options, and data can be stored in EU regions upon request.
Subprocessor Change Notification
N3W reserves the right to add, remove, or replace subprocessors as necessary to provide and improve our services.
Notification Process
- We will update this DPA page with the new subprocessor details
- Enterprise customers will receive email notification 30 days in advance
- Individual users will see the updated list on this page
- The "Last Updated" date at the top of this page will reflect changes
Objection Process
If you have reasonable concerns about a new subprocessor, you may:
- Contact us at privacy@n3w.io within 30 days
- Explain your concerns in writing
- We will work with you to address the concerns or offer alternatives
- If unresolved, you may terminate your account without penalty
Contact Information
For questions or concerns about our data processing activities or subprocessors:
- Privacy Team: privacy@n3w.io
- Security Team: security@n3w.io
- DPO (Data Protection Officer): Available for enterprise customers
Downloadable Version
Need a PDF or signed copy of this DPA? Enterprise customers can request an executed DPA by contacting our legal team.