Legal
Data Processing Addendum
The processing commitments a lender's compliance and vendor-management teams need before a single borrower record enters the system.
1. Roles of the parties
For consumer financial information processed in your workspace, you are the data controller and, under GLBA, the financial institution. NexusMortgageOS is a service provider / data processor acting only on your documented instructions, which are given through your configuration and use of the platform.
For account-administration data (workspace admins, billing contacts, support correspondence), NexusMortgageOS acts as controller for the limited purpose of operating the business relationship.
2. Scope of processing
Categories of data subjects: loan applicants and co-applicants, borrowers, your employees, and your broker/TPO contacts.
Categories of data: identity and contact details, employment and income data, asset and bank data, credit report data, property and appraisal data, loan terms and pricing, documents and disclosures, communications, and system audit metadata.
Purpose: to provide loan origination, processing, underwriting support, closing, compliance logging, analytics and support services to you. We do not use your data for advertising, do not sell it, and do not use it to train third-party public AI models.
Duration: for the term of your subscription plus the retention window in section 8.
3. Confidentiality and personnel
Personnel with access to Customer Data are bound by confidentiality obligations, receive security and privacy training, and receive access only where required to operate or support the platform. Production access is least-privilege, individually attributed, and logged.
4. Security measures
Encryption of data in transit (TLS 1.2+) and at rest (AES-256). Per-tenant secret storage with envelope encryption for vendor credentials. Row-level security enforcing tenant isolation on every table. Role-based access control with multi-factor authentication for administrative roles. Append-only audit logging of data changes and agent decisions. Automated backups with point-in-time recovery. Vulnerability monitoring and dependency scanning.
We test tenant-isolation policies on an ongoing basis and re-verify vendor credential health on a scheduled basis.
5. Subprocessors
You authorize the use of the subprocessors below. We remain responsible for their performance and will give notice before adding a new subprocessor that processes Customer Data, with a reasonable opportunity to object.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Managed Postgres, authentication, object storage | United States |
| Amazon Web Services | Underlying cloud infrastructure for the database platform | United States |
| Cloudflare | DNS, TLS termination, edge delivery and application runtime | United States |
| Stripe | Subscription billing and payment processing (billing data only) | United States |
| Twilio | SMS and voice notifications where enabled by the tenant | United States |
| Resend | Transactional email delivery | United States |
6. Your vendor accounts
Credit bureaus/resellers, automated underwriting systems, e-sign, doc prep, appraisal and verification vendors are contracted directly by you under your own agreements. When you seal credentials in your vault and place an order, we transmit only the data required for that order at your instruction. Those vendors are your subprocessors, not ours, and their handling of the data is governed by your agreements with them.
7. Data subject and consumer rights
You control responses to consumer access, correction, deletion and portability requests. The platform provides export, correction and deletion tooling so you can satisfy those requests directly. If a consumer contacts us, we will refer them to you and assist you at no charge, taking into account the nature of the processing.
8. Retention and deletion
Active loan records are retained for the life of your subscription. After termination, Customer Data is available for export for 30 days and is then deleted from primary systems within 30 days and from encrypted backups within 90 days.
Audit and compliance records required for regulatory examination are retained per the retention schedule published in the Privacy Policy. Trial workspaces are deleted 30 days after expiry unless converted.
9. Incident response and breach notice
We maintain a documented incident response plan. On becoming aware of a security incident affecting Customer Data, we will notify your designated workspace administrators without undue delay and in any event within 72 hours, with the facts known at the time, the categories and approximate volume of data affected, likely consequences, and containment and remediation steps.
We will cooperate with your regulatory and consumer notification obligations, including GLBA Safeguards Rule and applicable state breach-notification law.
10. Location of processing
Customer Data is stored and processed in the United States. We do not transfer Customer Data outside the United States without prior written notice to you.
11. Audit and assurance
On request, no more than once per year, we will provide our current security documentation, infrastructure certification reports available to us from our hosting providers, tenant-isolation test results, and responses to a reasonable security questionnaire. Onsite audits may be arranged for enterprise customers under a confidentiality agreement.
12. Order of precedence
This Addendum forms part of the Master Subscription Agreement. Where it conflicts with the Agreement regarding processing of Customer Data, this Addendum controls.
Contact for privacy matters: privacy@nexusmortgageos.com.
Signature
Countersigned copies available on request
Acceptance of the Master Subscription Agreement constitutes acceptance of this Addendum. If your vendor-management process requires an executed PDF, email privacy@nexusmortgageos.com and we will return a countersigned copy.