under Art. 28(3) GDPR — As of: 4 October 2026
This is a courtesy translation. In case of doubt, the German version prevails.
1. Parties and applicability
The controller is the business or other body that uses the Nema Services in an organisation for its own purposes ("Customer").
The processor is Leonardo Antonio Carta (sole proprietor), c/o Emperon Studio GmbH, Sachsenring 51a, 50677 Cologne, Germany, leonardo@nema.im ("Provider").
This agreement becomes part of the usage agreement as soon as a person who has accepted the Terms creates an organisation for the Customer or books a plan for it (Terms Sections 1.3, 11). The Provider stores the acceptance of the Terms with the version and the time; the Terms refer to this agreement. It applies for the duration of the usage agreement and thereafter for as long as the Provider still processes data of the Customer. In the event of conflicts, this agreement takes precedence over the Terms insofar as the protection of personal data is concerned.
2. Subject matter, nature and purpose
The Provider makes the Nema Services, in particular Nema Crew, available to the Customer (Terms Section 3). In doing so, it processes personal data that the Customer, its members and their agents bring into the organisation or retrieve via connected services.
Nature of processing: storing, organising, searching, displaying, transmitting to the sub-processors named in Annex B for responses by language models, executing tasks in connected services, deleting.
Purpose: exclusively the provision of the contractually agreed service.
Types of data: contact data (name, email address, phone number), content of messages, emails, documents, tickets, code and calendar entries, data from connected services, images and screenshots, usage and log data of the members, pseudonymisation mappings, files and logs in the members' workshops for the organisation.
Categories of data subjects: members of the organisation; customers, prospects, suppliers, applicants, employees and other contacts of the Customer whose data appears in content.
Special categories (Art. 9 GDPR) are not the subject of the service. If the Customer brings them in, it is responsible for the legal basis.
3. What is not covered by this agreement
The Provider does not use the following recipients as sub-processors. They receive data because the Customer or a member has chosen and set them up, and process it on the basis of their own contract with the Customer or the member:
- Anthropic and OpenAI, if a member uses the Claude Code or Codex runtime with their own subscription (paragraph 2);
- connected services (modules such as GitHub, Slack, Gmail) and an agent's mailbox;
- own MCP servers;
- recipients of emails, messages and share links sent by an agent or member;
- a member's Mac, if the member enables its operation.
Claude Code and Codex. Processing by Anthropic and OpenAI is expressly not part of the data processing under this agreement; these providers are not sub-processors of the Provider. Members can use these runtimes only once an Admin or Owner of the organisation has confirmed once that the Customer bears responsibility for the processing by the respective provider (Terms Section 3.4). This confirmation is the Customer's documented instruction to transmit content of the organisation via the Provider's proxy to Anthropic or OpenAI; the Provider stores it with the person, the time and the version of the confirmation text. An Admin or Owner can withdraw it at any time; after that, agents with these runtimes no longer start a new run in the organisation, and new ones cannot be created. The Provider does not check which account a member uses to sign in with the respective provider. Whether a member may use their own subscription for this, and whether the terms of the subscription permit processing of the Customer's data, is for the Customer to clarify.
Whether data of the organisation may go to the other recipients in this Section is likewise decided by the Customer.
4. Instructions
The Provider processes the data only on documented instructions from the Customer, including with regard to transfers to third countries, unless it is required to do so by Union law or German law; in that case it informs the Customer of that legal requirement beforehand, unless the law prohibits this.
Instructions are this agreement, the Terms and the settings the Customer makes in the organisation — such as modules, pseudonymisation, field masks, roles, deletions and the confirmation under Section 3. Further instructions are given by Owners or Admins of the organisation in text form to leonardo@nema.im.
If the Provider considers an instruction to be unlawful, it says so without delay. It may suspend its execution until the Customer confirms or changes it.
5. Confidentiality
The Provider uses only persons who are committed to confidentiality or are under a statutory obligation of confidentiality. Currently only the Provider himself has access to the systems and data; he will use further persons only after committing them to confidentiality in writing.
6. Technical and organisational measures
The Provider takes the measures under Art. 32 GDPR described in Annex A. It may replace them with equivalent or better ones; the level of protection must not decrease. It documents significant changes.
7. Sub-processors
The Customer gives general authorisation to use the sub-processors named in Annex B. For the Nema runtime, these are an intermediary service for model interfaces and the operators of the models that the Provider specifies. With every request, the Provider gives the intermediary service the permitted operators, prohibits falling back to other operators and allows only operators that neither store requests nor use them for their own purposes.
The Provider announces a new or replaced sub-processor — including a different model operator — at least 30 days in advance: by an entry in the list of providers and by email to the Owners of the organisation. The Customer may object within this period on important data protection grounds. If the parties do not reach agreement, the Customer may terminate the agreement with effect from the time of the change and receives a pro rata refund of remuneration already paid for the period thereafter (Terms Sections 3.14, 5.4).
The Provider uses sub-processors only on the basis of a contract under Art. 28(4) GDPR and is liable for them as for its own actions. With the intermediary service, its data processing agreement (Data Processing Agreement) applies, which is part of its terms of service and contains standard contractual clauses. The intermediary service uses the model operators as its sub-processors and binds them itself; the Provider has no contract of its own with them.
8. Third countries
Transfers to countries outside the EU and the EEA take place only under the conditions of Chapter V GDPR — adequacy decision including the EU-US Data Privacy Framework, insofar as the recipient is certified, or standard contractual clauses (Module 3, processor to sub-processor) with a transfer impact assessment. Annex B states the country and basis for each recipient.
9. Assistance to the Customer
The Provider assists the Customer with appropriate measures
- with requests from data subjects (Art. 12–22 GDPR). If such a request reaches the Provider, it forwards it without delay and does not answer it itself, except on instruction;
- with security, notification of breaches, data protection impact assessment and prior consultation (Art. 32–36 GDPR), insofar as it has information on this.
For assistance that goes beyond the functions of the app and is not based on an error of the Provider, the Provider may charge reasonable remuneration based on effort if it states it in advance.
10. Personal data breaches
The Provider notifies the Customer of a personal data breach without undue delay after becoming aware of it, to the email address of the Owners. The notification contains, as far as known, the information under Art. 33(3) GDPR; it provides missing information subsequently.
11. Deletion and return
After the end of the agreement, the Provider deletes the Customer's data unless there is an obligation to retain it. The agreement ends in particular when the Customer deletes the organisation. If only a paid plan ends, the organisation continues on the Free plan; Terms Section 4.7 then applies to the workshops.
Return: Before deletion, the Customer can retrieve data itself — each member via the export of their data and the archive of their workshop in the organisation, and after a member's departure the organisation via the archive of that member's workshop. There is no export of the entire organisation in one step. If the Customer requests, before deletion, the release of data that it cannot retrieve in this way, the Provider makes it available in a common, machine-readable format. If the Provider terminates, Terms Section 5.5 applies.
Departure of a member: If a member leaves the organisation or is removed, the Provider pauses that member's agents and workshop in the organisation. If the member does not rejoin within 30 days, the Provider deletes both. The workshop does not pass into the member's personal area, and the member can no longer retrieve its archive after departure; only the Customer receives the data. The Provider confirms deletion in text form on request.
During the term of the agreement, the Customer deletes data itself in the app or instructs deletion.
Backups: Deleted data remains contained in the database backups (Annex A) for up to about 6 months. The Provider does not remove it there individually; it drops out with the rotation. Until then, the Provider uses the backups only to restore operation and, after a restoration, deletes data that had already been deleted again.
Deletion of an account by a member: If a member deletes their account, the Provider deletes the channels this member created with all their messages, also in the organisation and including the messages of other members. Content that the organisation wants to keep should be kept in channels created by an Owner or Admin.
12. Evidence and audits
The Provider makes available to the Customer the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR, and allows for audits by the Customer or an auditor mandated by it who is bound to confidentiality and is not a competitor of the Provider. On-site audits must be announced with reasonable notice, as a rule two weeks, and take place during business hours without disproportionately disrupting operations. The Provider may initially provide evidence in writing.
13. Liability
Art. 82 GDPR applies to liability. Otherwise, the liability provisions of the Terms (Section 10) apply. They do not restrict claims of data subjects.
14. Final provisions
Amendments require text form. German law applies. If the Customer is a merchant, a legal entity under public law or a special fund under public law, the exclusive place of jurisdiction is Cologne.
Annex A: Technical and organisational measures
Confidentiality
- Physical access: server in the data centre of Hetzner Online GmbH in the EU; access control by Hetzner, with whom a data processing agreement is in place. Hetzner is certified to ISO/IEC 27001 for its hosting services and data centres (certificate ZN-2025-35, valid until 26 September 2028, published on hetzner.com).
- System access: administrative access to the server only via SSH and only for the Provider itself (Section 5).
- Data access: content of an organisation only for its members according to role (Owner, Admin, Member); agents, channels and direct messages only for the respective member.
- Separation: each workshop and each own subscription (Claude Code, Codex) in its own container; data of different organisations logically separated in the database. Each member has a separate workshop for each organisation, separate from their personal workshop and from the workshops of other organisations; agents reach only the workshop of their context.
- Passwords only as bcrypt hashes.
- Pseudonymisation (Art. 32(1)(a) GDPR): optional per organisation; field masks for events from modules. Limits: see Privacy Policy Section 7.
Integrity
- Transmission over the internet encrypted via TLS.
- Credentials of connected services, mailboxes, MCP servers and SSH keys as well as jobs in the queue stored encrypted (AES-GCM); without the key, the queue accepts no jobs. The sign-in tokens for Claude Code and Codex are stored in the respective member's container, protected by file permissions.
- An agent's SSH keys are kept during a run only in a dedicated directory of the workshop and are overwritten and deleted afterwards.
- Model operators of the Nema runtime only if the intermediary service lists them as not storing requests (zero data retention); no fallback to operators that have not been specified.
Availability and resilience
- Backup: a complete dump of the database every day, encrypted with AES-256; the key is kept only on the server, not at the storage location. Kept on the server and additionally, every day, on storage of Hetzner Online GmbH in data centres in the EU. Retention: every backup of the last 7 days, then one per week for 4 weeks and one per month for 6 months.
- Not backed up are the workshops (files, histories of Claude Code and Codex), the search index and caches (Terms Section 3.5).
Procedures for review
- The Provider reviews these measures with every significant change to the technology or the sub-processors, but at least once a year, and documents the result.
Annex B: Sub-processors
The current list is available at crew.nema.im/legal/subprocessors and forms part of this agreement. Changes in accordance with Section 7.