Nested / Data Processing Addendum (DPA)

Data Processing Addendum (DPA)

Last updated 1 October 2026 Nested Company Limited

This DPA is made to comply with the Personal Data Protection Act B.E. 2562 (“the PDPA”), in particular Section 40. Where this DPA conflicts with the Terms of Service, this DPA prevails in respect of the processing of personal data only.

1. Definitions

  1. Terms used in this DPA shall have the meanings given under the PDPA unless otherwise specified, whereby "personal data", "data controller", "data processor", "data subject" and "Processing" shall have the meanings given under the PDPA.
  2. "Processed Personal Data" means the personal data that the Controller inputs into the system and that the Processor processes in the capacity of a data processor, as detailed in Annex A.

2. Roles and Scope of Processing

  1. The Controller is the data controller and the Processor is the data processor.
  2. The scope, nature, purposes and duration of the Processing, the categories of personal data and the categories of data subjects are as specified in Annex A.

3. Processing on Instructions

  1. The Processor shall process the Processed Personal Data only in accordance with the lawful instructions of the Controller, to the extent necessary for the provision of the services and as set out in this DPA, unless otherwise required by law, in which case the Processor shall notify the Controller to the extent permitted by law.
  2. If the Processor considers that any instruction may conflict with the PDPA or other laws, the Processor shall notify the Controller without delay.

4. Confidentiality

  1. The Processor shall ensure that personnel having access to the Processed Personal Data are subject to a duty of confidentiality and access the data only to the extent necessary for the performance of their duties (need-to-know).

5. Security Measures

  1. The Processor shall implement appropriate security measures in accordance with Section 37(1) of the PDPA and as specified in Annex B, in order to prevent loss, unauthorised access to, use, alteration or disclosure of the data.

6. Sub-processors

  1. The Controller grants general authorisation for the Processor to engage the Sub-processors listed in Annex C for the provision of the services.
  2. The Processor shall impose on Sub-processors data protection obligations no less protective than those set out in this DPA, and the Processor remains responsible for the acts of the Sub-processors.
  3. If there is any change to, or addition of, a Sub-processor, the Processor shall give not less than 30 days’ prior notice by updating the list in Annex C on the Processor’s website, which shall constitute notice under this Clause, and the Controller has the right to object on reasonable grounds within that period.

7. Assistance to the Data Controller

  1. The Processor shall provide reasonable assistance to the Controller in responding to requests by data subjects to exercise their rights under Sections 30 to 36 of the PDPA, taking into account the nature of the Processing.
  2. The Processor shall provide reasonable assistance to the Controller in fulfilling its obligations relating to security, breach notification and data protection impact assessments (if any).

8. Personal Data Breach Notification

  1. Upon becoming aware of a personal data breach affecting the Processed Personal Data, the Processor shall notify the Controller without delay, together with such information as is reasonably necessary to enable the Controller to comply with its statutory breach notification obligations.

9. Deletion or Return of Data upon Termination of the Services

  1. Upon termination of the services, the Processor shall delete or return the Processed Personal Data at the Controller's election, within the data export and deletion timeframes specified in the Terms of Service, except for data that must be retained by law or held in routine backup systems.

10. Audit

  1. The Processor shall make available such information as is reasonably necessary to demonstrate compliance with this DPA and shall cooperate with audits reasonably requested by the Controller or an auditor mandated by the Controller, subject to prior notice and without unreasonable disruption to operations.

11. Cross-Border Data Transfers

  1. The Processor may process or store data through Sub-processors whose data centres are located outside Thailand as specified in Annex C, and shall do so in accordance with the conditions and measures for international data transfers under Sections 28 and 29 of the PDPA.

12. Liability

  1. The liability of the parties under this DPA is subject to the limitations of liability set out in the Terms of Service, except for liability that may not be limited or excluded by law.

13. Term and Effect

  1. This DPA remains in effect for so long as the Processor processes personal data in the capacity of a data processor under the Terms of Service.

Annex A — Details of Processing

ItemDetails
Purpose of ProcessingTo provide the ERP system and related services to the Controller
Nature of ProcessingStorage, recording, organisation, use, transmission and deletion of data in accordance with use of the system
DurationThroughout the term of the services, and in accordance with the data deletion/export timeframes set out in the Terms of Service
Categories of personal dataDepending on the data the Controller inputs into the system, generally including: first and last name, job title, business name, address, email, telephone number, taxpayer identification number, bank account and payment information, purchase–sale transactions and outstanding balances linked to natural persons, as well as system user account data (username, access rights and usage logs)
Categories of data subjectsThe Controller's system users (employees), customer contacts, business partner and vendor contacts, and natural persons who are counterparties of the Controller
Sensitive dataNo sensitive data is processed by the system (should any related module be introduced in the future, this section shall be updated)
CrispIn-app user support chatEuropean Union (France)
Google WorkspaceEmail and document storage used for communication and service deliveryUnited States

Annex B — Security Measures (TOMs)

  • Access control: authentication, role-based assignment of rights, and use of secure passwords
  • Data encryption: encryption of data in transit and at rest
  • Backup and recovery: periodic data backups and a system recovery plan
  • Logging & Monitoring: retention of access logs and monitoring for threats
  • Vulnerability management and updates: regular inspection and security updating of the system
  • Incident management: processes for responding to and notifying personal data breaches

Annex C — List of Sub-processors

Service ProviderServiceLocation/Region
Microsoft AzureCloud Infrastructure / data storage and processingSingapore
Internet Thailand Public Company Limited — INETService provider for the delivery of electronic tax invoices (e-Tax Invoice / e-Receipt)Thailand
Intuit MailchimpSending emails to contacts as designated by the ControllerUnited States of America

The list above is the list as at the date this document was last updated. If a Sub-processor is added or changed, the Processor shall give prior notice in accordance with Clause 6.3.

Scope of this document: This DPA applies only to personal data that the Controller enters into the system. For data of which Nested is itself the data controller, such as contact and billing data, see the Privacy Notice. To request a signed copy of this DPA, please contact privacy@nested.co.th
Language: This English version is provided for convenience only. Where it differs from the Thai version, the Thai version prevails.