Legal · processor terms

Data Processing Addendum

Draft published: August 20, 2026 · LUCA LLC · Lincoln, Nebraska

Request a countersigned copy: hello@nexusfirma.io

Status: This page is a COMPLY-aligned draft Data Processing Addendum for NEXUS FIRMA. It is published so buyers can read processor terms without creating an account. It is not an attorney-signed or countersigned contract. LUCA will execute a DPA on request. Until both parties sign, the Terms of Service and Privacy Policy govern. A HIPAA Business Associate Agreement is a separate instrument and is not this DPA.

1. Parties and roles

This draft DPA is between LUCA LLC (“Processor,” operating NEXUS FIRMA at nexusfirma.io) and the customer that uses FIRMA (“Controller”). For personal data the customer uploads or instructs FIRMA to process, the customer is the controller and LUCA is the processor. For LUCA account, billing, and website data described in the Privacy Policy, LUCA is an independent controller.

2. Subject matter, duration, and nature

Processor provides the FIRMA software service: client records, documents, contracts, invoicing, books, banking connectivity, and related workspace features. Processing lasts for the subscription term and any retention window in the Privacy Policy (including the 90-day post-cancellation export window). Processing is limited to hosting, storing, transmitting, displaying, backing up, and otherwise handling customer data as needed to provide FIRMA and as the customer instructs through the product.

3. Types of personal data

Categories depend on what the customer enters. Typical service-business workspaces include names, emails, business contact details, invoices, contracts, and accounting records. FIRMA is a business application for adults. Customers must not upload children's data. Customers must not store Protected Health Information in FIRMA unless a separate Business Associate Agreement has been executed.

4. Processor obligations

  • Process customer personal data only on documented instructions, including this draft DPA, the Terms, and in-product configuration.
  • Ensure persons authorized to process the data are bound to confidentiality.
  • Implement technical and organizational measures described on the Security page, including encryption in transit and tenant isolation with row-level security.
  • Assist the customer with data-subject requests the customer cannot fulfill through the product, via hello@nexusfirma.io.
  • Notify the customer without undue delay after confirming a personal-data breach affecting that customer's workspace.
  • Delete or return customer data after the retention window, except where law requires longer retention.

5. Subprocessors

LUCA uses subprocessors to operate FIRMA. Current material subprocessors, matching the Privacy Policy:

  • Supabase — database, authentication, and infrastructure hosting
  • Stripe — subscription and invoice payment processing
  • Plaid — optional bank connectivity; LUCA does not store bank login credentials
  • Gusto — optional payroll sync
  • Intuit — optional QuickBooks Online integration
  • Vercel — application hosting for nexusfirma.io

LUCA will post material subprocessor changes on this page or the Privacy Policy. Continued use after notice constitutes acceptance unless the customer objects in writing to hello@nexusfirma.io before the change takes effect.

6. International transfers

FIRMA is operated by LUCA LLC in the United States. If the customer is in the EEA, UK, or Switzerland and requires Standard Contractual Clauses or an equivalent transfer addendum, request that package with the DPA at hello@nexusfirma.io. This draft does not by itself execute SCCs.

7. Audits and evidence

On written request, LUCA will provide available security documentation reasonably needed to assess processor controls, subject to confidentiality. This draft does not assert an independent audit attestation or a healthcare regulatory certification. Current public control language lives on /security.

8. Liability and order of precedence

Liability, indemnities, and limitations in the Terms of Service apply to this draft DPA. If a countersigned DPA conflicts with this page, the signed DPA controls. If no signed DPA exists, the Terms and Privacy Policy control.

9. How to request an executed DPA

Email hello@nexusfirma.io with your legal name, workspace email, and any required transfer addendum (SCCs, UK addendum). LUCA will return a signature-ready PDF. Do not treat this webpage as a signed instrument.

Related public pages: Privacy · Terms · Security · Support

We use cookies. We use strictly necessary cookies to keep you signed in and the site secure. With your consent, we may also use functional, analytics, and marketing cookies. You can accept all, reject non-essential, or choose per-category. Privacy policy.