Skip to content

Processor agreement

Data Processing Agreement

The terms on which naulon processes personal data on your behalf. You are the controller, we are the processor, and this describes exactly what that means here.

Last updated July 2026
Our role
Processor
Governing law
Japanese law
Transfer basis
EU adequacy decision (Japan)
Signature
On request

Roles

#

For the personal data in your organization's account, you are the controller and naulon is the processor: we act on your documented instructions, and your use of the service is that instruction. For your own account data as our customer, and for the operational logs we need in order to run the service, we act as controller. Your readers pay your wallet directly, so we are not party to their payments. naulon is operated as a sole proprietorship established in Japan.

Subject matter, duration and purpose

#

Subject matter: operating the citation toll on your behalf, which means resolving who may read your content, recording what happened, and settling payments to the wallets you nominate. Duration: for as long as you have an account, plus the retention periods below. Purpose: providing the service you signed up for and nothing else. We do not sell data, and we do not use your data to train models.

Data categories and data subjects

#

Data subjects are the people in your organization: owners, team members and contributing authors. The categories we hold are their email address and account identifier, their organization and site memberships, their role grants, the sites they own, any scheduled exports or alerts they configured, the feature-gating decisions evaluated for them, and the audit entries recording actions they took, which carry their email and source address. You can see the exact set at any time by running a subject access request from your dashboard, which returns all of it as a machine-readable package.

Security measures

#

The technical and organizational measures are described in full on our security page and in the control mapping any administrator can download from the dashboard: tenant isolation enforced at the database, encryption in transit and at rest, encrypted offsite backups, an immutable audit trail, role-based access denying by default, optional MFA enforcement, network restriction and SCIM-driven deprovisioning, and dual control over privileged operator actions with every support session visible in your own activity log.

Subprocessors

#

You authorize the subprocessors listed on our subprocessors page. Each is engaged under terms no less protective than these, and that page is the record of who they are and where they operate. Tell us if you need advance notice of additions.

International transfers

#

Your live data is stored in Frankfurt, Germany. Encrypted database backups are transferred to storage in Tokyo, Japan, and secrets management and container images are held in the same Japanese region. Japan holds a European Commission adequacy decision (adopted January 2019, reviewed April 2023 and still in force), so personal data may flow from the EEA to Japan without an additional transfer safeguard. Independently of that, the storage provider is engaged under its own GDPR data processing agreement, which carries standard contractual clauses covering the provider relationship itself.

Helping you answer data subjects

#

The product does this rather than a support queue. An administrator can export everything held about a person in your organization, and can erase that person's footprint within it, from the dashboard. Each request is itself recorded. Some records survive an erasure and the response says so explicitly: the audit trail, which is immutable by construction and retained as the accountability record; financial records retained under accounting obligations; and the person's own login account, which belongs to them rather than to your organization.

Security incidents

#

We will tell you without undue delay after becoming aware of a personal data breach affecting your data, and in any case within 24 hours of becoming aware. You will get what we know at the time: what happened, whose data is involved, what we have already done to contain it, what is still in progress, and a named person to reply to. We follow up as the picture changes and once more when it closes. You are the controller, so any notification to a supervisory authority or to the people affected is your decision; our job is to get you what you need in time to make it.

Retention, return and deletion

#

Audit history is kept for 365 days, and indefinitely on the top tier, where it is kept deliberately as the compliance record. That period is set independently of your plan's dashboard history, so changing your subscription does not shorten it. Deletion is whole-entry expiry on an automated schedule, never redaction of a recorded entry. On termination we delete or return your data on request, subject to the retained categories named above.

Audits

#

You can verify most of this yourself, which we prefer to a questionnaire: the control mapping gives every control a procedure you can run, including the exact database queries for the isolation claims. For anything that needs more, contact us and we will arrange it on reasonable notice.

Executing this agreement

#

naulon is operated as a sole proprietorship established in Japan, and this agreement is governed by Japanese law. We do not publish the contracting party's registered name and address on this page; we provide them on request and alongside any DPA we execute. To put a signed agreement in place for your organization, email us and we will return a countersigned copy together with the contracting details.

Getting the contracting details

Email us and a human answers. Say what you need and we will send the contracting party's registered details along with the agreement.

[email protected]

This English version is the governing text. Translations are provided for convenience only; if they differ, the English controls.