LegalNaytto

Data Processing Addendum

This addendum forms part of the Terms of Service between Relyt Works LLC, 1925 Lovett Avenue, STE 7 278, Bismarck, North Dakota 58504, United States ("Naytto", processor) and a customer that uses Naytto for an organization ("Customer", controller). It applies when Naytto processes personal data on the Customer's behalf under the GDPR, the UK GDPR, the Swiss FADP or the CCPA/CPRA.

1. Processing details

2. Naytto's obligations

Naytto will:

  1. Process personal data only on the Customer's documented instructions. These terms and the Customer's use of the product are those instructions. Naytto will tell the Customer if it believes an instruction breaks the law.
  2. Ensure that anyone authorized to process the data is bound by confidentiality.
  3. Maintain the security measures in section 5.
  4. Use subprocessors only as set out in section 6.
  5. Help the Customer respond to data subject requests. The self-service export and deletion on the Account page are the primary means.
  6. Help the Customer with security, breach notification, impact assessments and prior consultation, as far as Naytto's processing allows.
  7. Delete personal data at the end of the service, as set out in section 7.
  8. Make available the information needed to demonstrate compliance, and allow audits by the Customer or its auditor, at most once a year with 30 days' notice, or by providing independent reports where they exist.

3. CCPA/CPRA

Naytto is a service provider. It will not sell or share personal information, or retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service. It will not combine it with personal information from other sources except as the law permits, and it will tell the Customer if it can no longer meet these obligations.

4. Breach notification

Naytto will notify the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer's data. The notice will include what is known about its nature, likely consequences and the measures taken.

5. Security measures

6. Subprocessors

The Customer authorizes the subprocessors listed here. Naytto will give at least 30 days' notice of a new or replacement subprocessor through that page and by email to customers who ask for notice. The Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may end the affected service. Naytto binds each subprocessor to data protection terms at least as protective as this addendum and remains responsible for it.

7. Deletion

When the Customer deletes a user's account or the whole account, Naytto deletes the associated personal data immediately, except as follows. Activity records are kept 90 days after deletion, and abuse reports up to 365 days, to investigate unauthorized access. Service logs expire within 7 days, email delivery records within 31 days and backups within 30 days.

8. International transfers

Naytto processes data in the United States and on Cloudflare's global network. Where a transfer requires it, the parties agree to the EU Standard Contractual Clauses (Module 2, controller to processor), which are incorporated by reference. For UK data they are supplemented by the UK International Data Transfer Addendum, and for Swiss data by the Swiss adaptation. Onward transfers to Cloudflare and Google rely on their data processing terms and their EU-US Data Privacy Framework certifications. Section 1 completes Annex I of the Clauses and section 5 completes Annex II. The competent supervisory authority is the one for the Customer's establishment or representative in the EU. The Clauses are governed by Irish law, and disputes under them go to the courts of Ireland.

Last updated: 2026-09-25.