Data Processing Addendum (DPA)

Last updated: October 27, 2025

Overview

This Data Processing Addendum ("DPA") forms part of N3W's Terms of Service and Privacy Policy. It describes how N3W processes personal data and lists all subprocessors (third-party service providers) we use to deliver our services.

This DPA applies to all users of the N3W™ platform and is designed to comply with GDPR, CCPA, and other applicable data protection laws.

Definitions

  • Controller: The entity that determines the purposes and means of processing personal data (You, the user)
  • Processor: The entity that processes personal data on behalf of the Controller (N3W)
  • Subprocessor: Third-party service providers engaged by N3W to assist in processing personal data
  • Personal Data: Any information relating to an identified or identifiable individual
  • Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion)

Data Processing Activities

Types of Personal Data Processed

  • Account Information: Name, email address, authentication tokens
  • Chat Data: Conversation messages, timestamps, user queries
  • Uploaded Files: Images, documents (with EXIF metadata stripped)
  • Professional Credentials: For professionals in our directory (licenses, certifications)
  • Payment Information: Processed by Stripe (we do not store credit card details)
  • Usage Data: Feature usage, session duration, error logs
  • Technical Data: IP address, browser type, device information

Purposes of Processing

  • Provide AI-powered wellness conversation platform
  • Connect users with independent wellness professionals
  • Process payments and manage subscriptions
  • Improve service quality and user experience
  • Ensure platform security and prevent abuse
  • Comply with legal obligations

Subprocessors

N3W engages the following third-party subprocessors to provide our services. Each subprocessor has been vetted for security and compliance.

Infrastructure & Hosting

SubprocessorServiceData ProcessedLocationCompliance
Vercel Inc.Application hostingUser requests, logsUnited StatesSOC 2, ISO 27001
Supabase Inc.Database, authentication, file storageAll user data, messages, filesUnited StatesSOC 2 Type II, ISO 27001, GDPR

AI & Language Models

SubprocessorServiceData ProcessedLocationCompliance
OpenRouterLLM API aggregatorRedacted chat messages (PII removed)United StatesN/A (Proxy service)
OpenAI (via OpenRouter)GPT models, embeddingsRedacted chat messages, document embeddingsUnited StatesSOC 2, Zero data retention (API)
Google (via OpenRouter)Gemini modelsRedacted chat messagesUnited StatesSOC 2, ISO 27001, GDPR
Anthropic (via OpenRouter)Claude modelsRedacted chat messagesUnited StatesSOC 2, Zero data retention (API)

Payment Processing

SubprocessorServiceData ProcessedLocationCompliance
Stripe Inc.Payment processing, subscriptionsPayment details, billing address, customer IDUnited StatesPCI DSS Level 1, SOC 1/2, GDPR

Monitoring & Error Tracking

SubprocessorServiceData ProcessedLocationCompliance
SentryError tracking, performance monitoringError logs (PII scrubbed), stack tracesUnited StatesSOC 2, GDPR
Umami AnalyticsPrivacy-focused web analyticsAnonymized page views, referrers (no cookies)EuropeGDPR-compliant (no PII)

Data Retention

N3W and our subprocessors retain personal data only as long as necessary for the purposes outlined in this DPA and our Privacy Policy.

Retention Periods

  • Chat Messages: Stored to provide the service and may be automatically deleted after a limited retention period (by default, messages older than 180 days may be removed by scheduled server cleanup unless we configure a different period in production). Users may also delete conversations or their entire account sooner.
  • Account Data: Until you delete your account; deletion initiated in the N3 Wellness app is processed permanently subject to legal retention requirements described in our Privacy Policy
  • Professional profile & application data: Retained as necessary to operate the directory and process applications, then deleted or de-identified when no longer needed for legal, security, operational, or compliance purposes
  • Payment Records: 7 years (legal requirement for tax purposes)
  • Audit logs, consent records, backups, and verification-related records: Retained as necessary for legal, security, operational, or compliance purposes, then deleted or de-identified when no longer needed

AI Provider Data Retention

  • OpenAI: Zero retention via API (data not used for training)
  • Anthropic: Zero retention via API (data not used for training)
  • Google (Gemini): Zero retention via API (commercial tier)

Security Measures

N3W and our subprocessors implement industry-standard security measures to protect personal data:

Technical Measures

  • Encryption in Transit: TLS 1.3 for all data transmission
  • Encryption at Rest: AES-256 for database and file storage
  • Row-Level Security (RLS): Database-level access control
  • PII Redaction: Automatic removal of sensitive data before AI processing
  • EXIF Stripping: Removal of metadata from uploaded images
  • Output Validation: Scanning AI responses for leaked secrets/PII

Organizational Measures

  • Access Control: Role-based access with least privilege principle
  • Security Monitoring: 24/7 automated alerts for anomalies
  • Incident Response: Documented procedures with 72-hour notification
  • Regular Audits: Daily automated security checks
  • Vendor Vetting: Due diligence on all subprocessors

International Data Transfers

Most of our subprocessors are located in the United States. When we transfer personal data from the EU/EEA, we rely on:

  • Standard Contractual Clauses (SCCs): Approved by the European Commission
  • Adequacy Decisions: Where applicable (e.g., EU-US Data Privacy Framework)
  • Subprocessor Certifications: SOC 2, ISO 27001, GDPR compliance programs

Supabase provides EU hosting options, and data can be stored in EU regions upon request.

Subprocessor Change Notification

N3W reserves the right to add, remove, or replace subprocessors as necessary to provide and improve our services.

Notification Process

  • We will update this DPA page with the new subprocessor details
  • Enterprise customers will receive email notification 30 days in advance
  • Individual users will see the updated list on this page
  • The "Last Updated" date at the top of this page will reflect changes

Objection Process

If you have reasonable concerns about a new subprocessor, you may:

  • Contact us at privacy@n3w.io within 30 days
  • Explain your concerns in writing
  • We will work with you to address the concerns or offer alternatives
  • If unresolved, you may terminate your account without penalty

Contact Information

For questions or concerns about our data processing activities or subprocessors:

Downloadable Version

Need a PDF or signed copy of this DPA? Enterprise customers can request an executed DPA by contacting our legal team.