Skip to content
Nod
IntegrationsPricingPartners
ESEN
Log inGet started
OperationsCRM and pipelineEach contact, with its next step.Lead generationForms and landings that connect.Products and paymentsFrom the sale to the payment follow-up.Student PortalPrograms, resources and progress.AI ChatCheck your business data.
Nod AI Conversation inboxHistory, context and human control.
PlaybookYour offer, your criteria and your rules.SimulatorTest the conversation before approving.AI ManagementDecide when your team intervenes.AutomationsRespond to messages and comments.
IntegrationsStripeProducts, payments and subscriptions.Google CalendarCalls and calendar connected.Meta AdsCheck campaign performance.Calendly and Cal.comReservations associated with each contact. Security and privacy
See all features Let's talk about your business
Operations Nod AI
Features

Operations

CRM and pipelineEach contact, with its next step.Lead generationForms and landings that connect.Products and paymentsFrom the sale to the payment follow-up.Student PortalPrograms, resources and progress.AI ChatCheck your business data.

Nod AI

Conversation inboxHistory, context and human control.
PlaybookYour offer, your criteria and your rules.SimulatorTest the conversation before approving.AI ManagementDecide when your team intervenes.AutomationsRespond to messages and comments.
See all features
Integrations Pricing Partners Contact Log in
Legal and data

Data Processing Agreement (DPA)

Last updated · 09/25/2026

Legal NoticePrivacy PolicyCookie PolicyTerms of ServiceData Processing Agreement (DPA)SubprocessorsGoogle API DisclosureData DeletionAcceptable Use PolicyCancellation and Refund PolicyAffiliate Terms

This Processing Agreement (the "Agreement") is part of the Terms of Service and regulates the processing of personal data that WANDA LABS S.L. ("Nod" or the "Processor") performs on behalf of the Client (the "Controller") when providing the Platform, in accordance with article 28 of Regulation (EU) 2016/679 (RGPD) and Organic Law 3/2018 (LOPDGDD). The Client accepts this by accepting the Terms of Service.

1. Object

The Processor processes personal data included in the Customer Data solely to provide the Controller with the Platform services described in the Terms of Service and in https://thenodai.com/features, following the documented instructions of the Controller.

2. Duration

This Agreement will be in force as long as the Processor processes personal data on behalf of the Controller, and at least during the term of the Terms of Service.

3. Nature and purpose of the processing

Collection, registration, organization, structuring, conservation, consultation, use, communication by transmission, collation, limitation, deletion and destruction of data, through the Platform, with the purpose of allowing the Controller to manage its collection, sales, collections, training, care and operation, and to connect third-party services that the Controller decides.

4. Types of personal data

Depending on the use that the Controller makes of the Platform:

  • Identification and contact data: name, email, telephone, image.
  • Commercial data: origin, labels, notes, stages, responses to forms and their scoring.
  • Financial and transaction data: sales, payment plans, subscriptions and receipts, without complete card data.
  • Training and activity data: registrations, progress, tickets and attachments.
  • Call data: dates, guests, links, summaries and tasks.
  • Contract acceptance data: name, identity document number and date, and the accepted document.
  • Communications data: emails sent and unsubscribes.
  • Data imported from third-party services connected by the Controller.
  • Any other data that the Controller enters in personalized fields, notes or files.

The Controller must not enter special categories of data from article 9 of the GDPR on the Platform, such as health data, or data related to criminal convictions, unless it is strictly necessary, has a sufficient legal basis and has assessed its suitability.

5. Categories of interested parties

Leads, clients, students and contacts of the Controller; members of your team; and people who interact with your landings, forms, portal or welcome process.

6. Obligations of the Processor

The Processor agrees to:

  • Process the data only following the documented instructions of the Controller, including those resulting from the Controller's configuration and use of the Platform, unless it is required to do otherwise by Union or Member State Law, in which case it will inform the Controller before processing it, unless prohibited by law.
  • Inform the Controller if you consider that an instruction violates data protection regulations.
  • Do not use the data for your own purposes, do not sell it, do not use it for advertising or to train artificial intelligence models.
  • Ensure that persons authorized to process the data have agreed to respect confidentiality or are subject to a legal obligation of confidentiality.
  • Apply the technical and organizational measures of Annex II.
  • Respect the conditions of section 7 to use subprocessors.
  • Assist the Controller, through appropriate technical and organizational measures and to the extent possible, to respond to requests for the exercise of rights of the interested parties. If an interested party goes directly to the Processor, the latter will forward the request to the Controller without delay and will not respond to it on its own, unless instructed by the Controller.
  • Help the Controller ensure compliance with security obligations, breach notification, impact assessments and prior consultation, taking into account the nature of the processing and the information available.
  • Notify the Controller, without undue delay and in any case within a maximum period of 48 hours from becoming aware, of violations of the security of personal data that affect it, with the available information on its nature, the categories and the approximate number of interested parties and records affected, the possible consequences and the measures adopted or proposed.
  • Make available to the Controller the information necessary to demonstrate compliance with this Agreement and allow and contribute to audits, including inspections, carried out by the Controller or an auditor authorized by it, with a reasonable notice of at least 30 days, during business hours, without affecting the security or data of other clients, and the Controller will assume its costs.
  • Upon termination of the service, and at the Controller's option, return the personal data and delete existing copies, in accordance with section 9, unless the law requires retention.
  • Keep, when appropriate, the record of processing activities carried out on behalf of the Controller.

7. Subprocessors

  • The Controller grants general authorization for the Processor to use the subprocessors listed in https://thenodai.com/subprocessors.
  • The Processor will inform the Controller, at least 15 days in advance, of any incorporation or substitution of subprocessors, by email or by updating that page with notice. The Controller may object on reasonable grounds related to data protection within that period. If a solution is not reached, the Controller may terminate the contract, with reimbursement of the proportional part not enjoyed.
  • The Processor will impose on each subprocessor, by contract, the same data protection obligations of this Agreement, and will remain responsible to the Controller for the subprocessor's compliance.
  • Third-party services that the Controller connects by its own decision through the Integrations (for example, Google, Meta, Calendly, Cal.com, Fathom, Commas, Stripe or Resend of the Controller's account, or Slack) are not subprocessors of the Processor: the Controller maintains its own contractual relationship with them and the Processor is limited to transmitting or receiving data following its instructions.

8. International transfers

The Processor will not transfer personal data outside the European Economic Area unless there is an adequacy decision, standard contractual clauses approved by the European Commission or other appropriate guarantee from Chapter V of the GDPR, together with complementary measures where applicable. Information about the location and guarantees of each subprocessor appears in https://thenodai.com/subprocessors.

9. Return and deletion of data

  • During the term of the contract and up to 30 days after its termination, the Controller may request a copy of its data in a commonly used structured format.
  • After the period of conservation of the Frozen Space indicated in the Terms of Service, or sooner if the Controller requests it in writing, the Processor will delete the personal data within a maximum period of 30 days, including copies, except for those that must be kept by legal obligation, which will be kept blocked. Backups are overwritten within a maximum of an additional 30 days.
  • At the request of the Controller, the Processor will certify the deletion in writing.

10. Obligations of the Controller

The Controller undertakes to:

  • Ensure that you have a valid legal basis for the processing of the data you enter or import.
  • Fulfill the duty of information to interested parties, particularly their leads, students and clients.
  • Obtain the necessary consents, including those required by the LSSI-CE to send electronic commercial communications.
  • Configure the Platform, its Users, permissions and Integrations in a manner appropriate to its obligations.
  • Carry out, where appropriate, the impact assessment and consult the supervisory authority.
  • Monitor the processing and compliance with the GDPR by the Processor.

11. Responsibility

Each party will be liable for damages resulting from failure to comply with its obligations under Article 82 of the GDPR. Where not provided for, the limitations of liability in the Terms of Service apply, unless otherwise provided by law.

12. Priority

In the event of a data protection contradiction between this Agreement and the Terms of Service, this Agreement shall prevail.

Annex I — Details of the treatment

ItemDescription
ControllerThe Client, identified in their registration on the Platform
ProcessorWANDA LABS S.L., B70618970, Plaça Can Portabella 8, 08030, Barcelona, hello@thenodai.com
Object, nature and purposeSections 1 and 3
Data TypesSection 4
Categories of interested partiesSection 5
DurationSection 2
Main locationEuropean Union for database and files; Frankfurt (Germany) for the implementation of the application

Annex II — Technical and organizational security measures

  • Data isolation: logical separation of each Client's Space; Filtering by Client on all queries and row-level security policies in the database.
  • Encryption in transit: HTTPS/TLS in all communications.
  • Secret encryption: third-party integrations credentials and keys encrypted with AES-256-GCM, never shown again.
  • Authentication: specialized authentication provider; passwords never stored clear; One-time access links to set password.
  • Access control: roles and permissions by area within each Space; permission checking on every screen and action; immediate withdrawal of access; protection that prevents a user from elevating his or her own role.
  • Files: private storage for sensitive documents, served only via temporary signed links.
  • External Notification Integrity: signature verification of notices received from payment and recording services.
  • Least privilege: request for strictly necessary permissions from third-party services; read-only access to Meta Ads.
  • Registration and monitoring: record of automatic jobs and their errors.
  • Continuity: backups managed by the database provider; backup of the source code in a mirror repository.
  • Suppliers: selection of suppliers with security guarantees and custom contracts.
  • Staff: access to data limited to those who need it to provide or maintain the service, under the duty of confidentiality.
  • Incident management: breach notification and response procedure in accordance with articles 33 and 34 of the GDPR.
  • Review: periodic review of measures based on risk and the evolution of the Platform.

Annex III — Subprocessors

Consult the list of subprocessors.

Nod AI · intended scope of treatment

The treatment of the complement is subject to the effective suppliers and contracts. The planned processing includes authorized messages from Instagram, identity of the interlocutors, contact details, playbook instructions, documents provided, simulations and execution records to provide the requested commercial assistance. The Client determines the purpose and legal basis regarding its contacts; WANDA LABS S.L. acts as manager following your instructions. Nod's account and billing management has its own purposes as the person responsible.

Minimization, access control, and the retention periods in this policy will apply. Inference providers, their locations and transfer guarantees must be identified in the list of subprocessors to provide the processing. It is not assumed that the data is processed exclusively in the European Union. The proposal does not authorize using Client data to train general models or clone voices without authorization.

Nod

Your business.
One place.

Product

OperationsNod AIFeaturesIntegrationsPricingSecurity

Company

ContactPartnershello@thenodai.com+34 691 33 84 18

Legal

Legal NoticePrivacy PolicyCookie PolicyTerms of ServiceAcceptable Use PolicyCancellation and Refund Policy

Data

Data Processing Agreement (DPA)SubprocessorsGoogle API DisclosureData DeletionAffiliate Terms
ESEN
© 2026 Nod. All rights reserved.Designed for businesses that move forward.