// Legal
GDPR & Data Processing
Last updated: May 1, 2026
Namence is committed to the EU General Data Protection Regulation. This page summarizes our role, your rights and how to put a Data Processing Addendum (DPA) in place.
1. Roles
For your account data, Namence is the controller. For data you store on our infrastructure (your customers, your databases), Namence is the processor and you are the controller.
2. Your data subject rights
EU/UK residents have the right to access, rectify, erase, restrict, port and object to processing of their personal data, and to lodge a complaint with their supervisory authority. Submit requests to dpo@namence.com.
3. Data Processing Addendum
Our standard DPA incorporates the EU Standard Contractual Clauses (Module 2 — Controller-to-Processor) and the UK IDTA. Self-serve at dpo@namence.com — countersigned within 24 hours.
4. International transfers
For transfers outside the EEA we rely on SCCs plus supplementary measures (encryption in transit and at rest, EU-only data residency on request).
5. Subprocessors
The current subprocessor list is available in the customer dashboard. We notify customers at least 30 days before adding a new subprocessor.
6. Breach notification
Where Namence is the processor we will notify affected controllers without undue delay (and within 72 hours where feasible) of any confirmed personal-data breach.