Data Processing Agreement

Version v1.0 · Effective July 22, 2026

Draft: pending legal review. This document is a good-faith draft describing how Command Nexus actually operates. It has not yet been reviewed by a lawyer and does not constitute legal advice. It will be finalized before the platform accepts real payments.

This Data Processing Agreement ("DPA") supplements our Terms of Service and describes how Command Nexus, a company in formation("Command Nexus," "we," "us," "Processor") processes personal data on behalf of an organization using the Service ("Organization," "Controller") that relates to that organization's members. This DPA is a standard, self-serve annex that is automatically incorporated into the Terms of Service for every organization — it is not individually negotiated or separately signed. If your organization requires a countersigned version, email commandnexusproducts@gmail.com before relying on that requirement.

1. Roles and scope

Where an Organization uses the Service to manage personal data about its members — rosters, attendance, certifications, medals, ranks, requisition/commendation records, and related community data — the Organization is the data controller of that data and Command Nexus is the data processor, acting only on the Organization's behalf and instructions. This DPA governs that relationship only. It does not apply to personal data for which Command Nexus itself is the controller — namely each individual's own platform account data (login credentials, billing details, and the individual's use of the Service directly with us) — which is governed instead by our Privacy Policy.

"Member Data" under this DPA means the personal data of an Organization's members processed through the Service, including: names, contact and account identifiers; linked Discord and Steam identifiers; ranks, positions, and attendance records; certifications, merit, medals, and requisition/commendation records; and, where the Organization operates a Nexus Admin-enabled game server, in-game telemetry (Steam/game UID, in-game name, session and connection events, administrative actions, ban records, and anti-cheat flags).

2. Processing on instructions

Command Nexus processes Member Data only to provide the Service's documented features to the Organization (ORBAT, operations, certifications, merit, training, Discord/Steam linking, Nexus Admin server administration, and related functions) and otherwise only on the Organization's documented instructions, given through its use of the Service's configuration and administrative tools, or in writing to us. We will tell the Organization if we believe an instruction violates applicable data protection law, so the Organization can decide how to proceed.

3. Confidentiality and personnel

Access to Member Data is limited to the personnel who need it to operate and support the Service, and Command Nexus staff and any contractor with such access are bound to confidentiality obligations covering that data.

4. Security measures

Command Nexus maintains the following measures, appropriate to a small self-serve SaaS platform, and will keep them under review as the platform grows:

  • encrypted transport (HTTPS) for the Service and its APIs;
  • hashed password storage — plaintext passwords are never stored;
  • row-level tenant isolation, so one Organization's Member Data is not queryable by another;
  • hardened session cookies (SameSite=Lax, HttpOnly, Secure);
  • brute-force login throttling and lockout on authentication endpoints;
  • re-encoding of uploaded images before storage;
  • restricted, authenticated access to underlying configuration and infrastructure.

This is a good-faith description of what is actually in place today, not a certification against a formal security framework (such as SOC 2 or ISO 27001), which we do not currently hold.

5. Subprocessors

The Organization authorizes Command Nexus to engage the following subprocessors, each used only for the purpose described:

SubprocessorPurposeNotes
HostingerApplication and database hostingInfrastructure subprocessor
PayPalPayment processingActs as an independent controller of the payment data it collects directly; not a subprocessor for that data
DiscordBot integration, account linking, optional notificationsUsed only where the Organization or its members enable it
Steam / ValveIn-game identity linkingUsed only where a member links a Steam account

We will publish a new version of this document, and treat any addition of a new category of subprocessor as a material change requiring re-acceptance, before that subprocessor begins processing Member Data — giving Organizations the opportunity to object through the support channel in the MSA/SLA.

6. International transfers

Command Nexus and its hosting subprocessor operate from the United States. Where an Organization or its members are located in the EU/UK, Member Data will be transferred to and processed in the United States. Whether Standard Contractual Clauses or an equivalent transfer mechanism are required, and whether an EU/UK representative must be appointed, is flagged for lawyer review and is not yet finalized in this draft.

7. Breach notification

If Command Nexus becomes aware of a breach affecting Member Data, we will notify the affected Organization(s) without undue delay and in any event within seventy-two (72) hours of becoming aware, with the information reasonably available to us at that time (nature of the breach, categories and approximate number of data subjects/records affected, likely consequences, and measures taken or proposed). The Organization remains responsible for its own obligations to notify its members or regulators as the controller.

8. Assistance with data subject requests

Command Nexus provides tooling that lets an Organization (and, for their own platform account, individual members) export and erase personal data — see the account- and organization-deletion flows described in our Privacy Policy. Where a data subject request cannot be fulfilled through that self-serve tooling, we will provide reasonable assistance to the Organization in responding to it, taking into account the nature of the processing and the information available to us.

9. Deletion and return on termination

When an Organization's account is deleted, Member Data is handled through the organization erasure process: the organization is deactivated immediately, active subscriptions are cancelled, and a 30-day window opens during which the Organization owner can reverse the request. After that window, we execute the deletion cascade — deleting or anonymizing Member Data across the platform, releasing members from the Organization (their own accounts and other-organization memberships are not deleted), and retaining only what we are required or permitted to keep (such as payment records and anti-cheat/ban history, consistent with Section 4 below of our Privacy Policy's retention schedule). A deletion certificate is recorded that itself contains no personal data. An Organization may request an export of its Member Data before this process completes.

10. Audit information

On reasonable written request, and no more than once per year absent a specific security incident, Command Nexus will make available a summary of its security measures sufficient for the Organization to reasonably verify compliance with this DPA. Given the size of our team, we do not currently support on-site audits or formal third-party audit reports; if your organization requires either, contact us to discuss what we can realistically provide.

11. Precedence and changes

This DPA is incorporated into and forms part of the Terms of Service. If anything in this DPA conflicts with the Terms of Service on a data-protection question, this DPA controls. We may update this DPA; when a change is material, we publish the new version in our Legal Center with a new effective date and ask affected users to re-accept it.

12. Contact and governing law

Questions about this DPA: email commandnexusproducts@gmail.com, our official channel of record. This DPA is governed by the laws of the State of [U.S. STATE — set on LLC formation], United States, in the same manner as our Terms of Service, except where mandatory data-protection law applicable to the Organization's members requires otherwise.

← All legal documents Back to Command Nexus