Data Processing Addendum (outline)
Last updated: July 2026 · Outline for Enterprise. Operated by Negi Enterprise Inc. Founder-maintained — not attorney-attested. Execute a signed DPA before processing EU personal data at scale.
1. Roles
Customer is Controller (or equivalent). Negi Enterprise Inc (EstiLumina) is Processor for Customer Personal Data uploaded to the Service. Negi Enterprise Inc acts as Controller for account billing and our own website analytics (if any).
2. Scope of processing
Subject matter: construction project collaboration data and account identifiers. Duration: term of the subscription plus retention window. Nature: hosting, storage, transmission, display, backup. Purpose: provide the Service per the Terms.
3. Subprocessors
Authorized subprocessors are listed at /legal/subprocessors. We will notify Enterprise customers of material changes with commercially reasonable notice.
4. Security measures
TLS in transit; encryption at rest via infrastructure providers; org RLS; access least-privilege; audit logging of material money/portal events; vulnerability management process. Details in Trust Center.
5. International transfers
Where required, parties will incorporate SCCs (or UK/Swiss addenda) into a signed DPA package.
6. Breach notification
We will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, per our Privacy Policy and incident process.
7. How to execute
Email support@estilumina.com for the counsel-reviewed executable DPA. This page is an outline, not a signed agreement.