Skip to main content
This Data Processing Agreement (“DPA”) is entered into by and between Nebius B.V. (“Nebius” or “Processor”), and the customer identified under the applicable service agreement (“Customer”). Nebius and Customer are collectively referred to as the “Parties” and individually as a “Party”. In consideration of the mutual obligations set forth herein, the Parties agree that the terms and conditions described below shall be incorporated into, and form an integral part of, the applicable agreement(s) governing Customer’s use of the relevant Services, including any applicable service agreement, terms of service, terms of use, order form, service-specific terms, or other agreement entered into or accepted by Customer in connection with such Services (collectively, the “Terms of Service”). In the event of any conflict between the provisions of this DPA and those of the Terms of Service, the provisions of this DPA shall govern with respect to the processing of personal data.

1. Definitions

Terms in this DPA have the same meaning as those in the Terms of Service, unless expressly defined otherwise in this DPA. Capitalized terms not defined herein shall have the meaning assigned to them in the Terms of Service. 1.1. “Adequacy Decision” means a decision adopted by the European Commission pursuant to Article 45 of the General Data Protection Regulation, determining that a third country, a territory or one or more specified sectors within that country ensure an adequate level of protection for personal data, allowing transfers of personal data from the European Economic Area (“EEA”) to such country without the need for additional safeguards. 1.2. “Applicable Data Protection Laws” means all data protection and privacy laws and regulations applicable to the respective Party in its role in the processing of personal data under the Terms of Service, which may include, to the extent applicable, European Data Protection Laws. 1.3. “Customer Content” means, if not defined within the Terms of Service, all data processed by Nebius on your behalf in the course of providing the Services. 1.4. “Customer Personal Data” means any personal data contained within Customer Content. 1.5. “European Data Protection Laws” means (a) Regulation 2016/679 (General Data Protection Regulation)(“EU GDPR”); (b) the EU GDPR as saved into United Kingdom law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); and (c) the Swiss Federal Data Protection Act and its implementing regulations (“Swiss Data Protection Act”); in each case as may be amended, superseded or replaced from time to time. 1.6. “Security Breach” means a breach of security leading to an accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. 1.7. “Security Measures” means the technical and organizational measures implemented and maintained by Nebius to protect Customer Personal Data, as described in the Annex 3. 1.8. “Services” means the services provided by Nebius to Customer under the applicable Terms of Service, including, as applicable, Nebius AI Cloud, Nebius Token Factory, and any other services identified in an applicable order, service description, account, or service-specific annex. 1.9. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021, as may be amended, superseded or replaced from time to time. 1.10. “Sub-processor” means any other processor engaged by Nebius to process Customer Personal Data. 1.11. “Sub-processor List” means, with respect to each Service, the then-current list of Sub-processors engaged by Nebius in connection with such Service, including their processing activities and countries of location, as published at the applicable URL for that Service: for Nebius AI Cloud, at https://docs.nebius.com/legal/sub-processors; and for Nebius Token Factory, at https://docs.nebius.com/legal/sub-processors_tofa, or such other location as Nebius may notify to Customer from time to time. 1.12. “UK Addendum” means the International Data Transfer Addendum issued by the Information Commissioners Office under S.119 (a) of the UK Data Protection Act 2018, as updated or amended from time to time. 1.13. The terms “controller”, “data subject”, “supervisory authority”, “processor”, “process”, “processing”, and “personal data” shall have the meanings given to them in Applicable Data Protection Laws.

2. Processing of Personal Data

2.1. Scope and Roles of the Parties. This DPA applies when Customer Personal Data is processed by Nebius as a processor in its provision of the Services to Customer. Customer will act as either a controller or processor, as applicable, with respect to Customer Personal Data. 2.2. Processing by Nebius. When processing personal data on behalf of Customer, Nebius will: (i) comply with Applicable Data Protection Laws; (ii) process Customer Personal Data only as necessary to perform its obligations under the Terms of Service and this DPA, and strictly in accordance with Customer’s documented instructions; and (iii) process Customer Personal Data only for the purposes authorized by Customer, including as set out in the Terms of Service, this DPA, and the applicable Annexes describing the processing activities for the relevant Services, collectively (“Permitted Purpose”). 2.3. Processing by Customer. Customer will: (i) comply with Applicable Data Protection Laws in its processing of personal data and in any instructions it issues to Nebius; (ii) use the Services in a secure manner and independently determine whether the Security Measures available through the Services satisfy Customer’s legal and contractual obligations; (iii) provide all required notices and obtain, maintain and have all necessary consents, authorizations and rights to process Customer Personal Data through the Services and to provide Instructions to Nebius; and (iv) inform Nebius without undue delay if Customer is unable to comply with its responsibilities under Applicable Data Protection Laws or if Customer believes that its instructions would cause Nebius to violate Applicable Data Protection Laws. 2.4. Details of Processing. The subject matter of Nebius’s processing of Customer Personal Data is the provision of the applicable Services under the Terms of Services. The duration, nature and purpose of the processing, and the types of Customer Personal Data and categories of data subjects are set out in the service-specific Annexes describing the processing activities for the relevant Services: Annex 1A for Nebius AI Cloud and Annex 1B for Nebius Token Factory, as applicable. 2.5. Confidentiality of Processing. Nebius shall ensure that any person that it authorizes to process Customer Personal Data (including Nebius’ staff, agents and subcontractors) (“Authorized Person”) shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty) and shall not permit any person to process Customer Personal Data who is not under such a duty of confidentiality. Nebius shall ensure that all Authorized Persons process Customer Personal Data only as necessary for the Permitted Purpose and that Authorized Persons not access or otherwise process personal data or personal information that is not Personal Data and necessary for the Permitted Purpose.

3. Assistance Obligations

3.1. Data Subject Requests. Customer is responsible for responding to and complying with requests from data subjects to exercise their rights under Applicable Data Protection Laws (“DSR”). If Nebius receives a DSR directly and the request identifies Customer or enables Nebius to identify Customer, Nebius will promptly forward the DSR to Customer. Unless legally required to respond, Nebius will not respond to the data subject except to acknowledge receipt and refer the individual to Customer for a response. Nebius will provide reasonable assistance to Customer, taking into account the nature of the processing and the information available to Nebius, to enable Customer to respond to DSRs in accordance with Applicable Data Protection Laws. 3.2. Legal Requests. If Nebius receives a subpoena, court order, warrant, or other legally binding demand from law enforcement or any public or judicial authority seeking disclosure of Customer Personal Data, Nebius will first attempt to redirect the requesting authority to seek the information directly from Customer and may provide the authority with Customer’s basic contact information for that purpose. If Nebius is compelled to disclose Customer Personal Data, Nebius will provide Customer with reasonable prior notice of the demand so Customer may seek a protective order or other appropriate remedy, unless Nebius is legally prohibited from giving such notice. In responding to any legally binding demand, Nebius will disclose only the minimum amount of Customer Personal Data necessary to comply with the demand and will challenge requests that Nebius reasonably believes are overbroad, unlawful, or otherwise invalid.

4. Sub-processors

4.1. Authorization. Customer provides a general written authorization for Nebius to engage Sub-processors to process Customer Personal Data in accordance with this Section 4. Nebius has entered into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those set forth in this DPA, to the extent applicable to the nature and scope of the Services provided by the Sub-processor. Nebius remains responsible for the performance of its obligations under this DPA, including where such obligations are performed by its Sub-processors. 4.2. Service-Specific Sub-processor Lists. Nebius maintains a separate Sub-processor List for each applicable Service, including Nebius AI Cloud, at https://docs.nebius.com/legal/sub-processors, and Nebius Token Factory, at https://docs.nebius.com/legal/sub-processors_tofa. Customer hereby authorizes Nebius to engage the Sub-processors identified in the applicable Sub-processor List for the relevant Service, including their locations and processing activities, in connection with such Service. 4.3. Changes to Sub-processors. Nebius will provide Customer at least fifteen (15) days’ prior notice of any addition or replacement of a Sub-processor. Customer may object on reasonable data-protection grounds to the engagement of a new Sub-processor by providing written notice within that period. The Parties will discuss the objection in good faith. If no mutually acceptable solution is reached, Customer may terminate the affected Services and receive a pro-rata refund of any prepaid, unused fees, without liability to either Party, without prejudice to fees accrued before suspension or termination. Customer may also subscribe to receive notifications about Sub-processor updates at: https://docs.nebius.com/legal/sub-processors#summary-of-changes (currently available for Nebius AI Cloud only).

5. Security and Compliance

5.1. Security Measures. Nebius implements and maintains appropriate technical and organizational measures designed to safeguard Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. A summary of these Security Measures is provided in Annex 3 to this DPA for the relevant Services. The Customer is responsible for assessing whether the above mentioned Security Measures are sufficient for the intended processing of Personal Data, and for ensuring it has a valid legal basis and complies with any additional requirements under Applicable Data Protection Laws. 5.2. Security Breaches and Cooperation with Customer. Nebius will notify Customer without undue delay after becoming aware of a Security Breach. Nebius will provide Customer with information available to Nebius and reasonable assistance necessary for Customer to meet its obligations under Applicable Data Protection Laws in relation to the Security Breach. 5.3. Data Protection Impact Assessments. Upon reasonable request, Nebius will provide Customer with information about the applicable Services necessary for Customer to conduct data protection impact assessments and any related consultations with supervisory authorities, as required by Applicable Data Protection Laws, provided that Customer does not otherwise have access to the relevant information. 5.4. Audit Program. Upon written request and at no additional cost to Customer, Nebius will provide the Customer and/or its appropriately qualified third-party representative with access to documentation reasonably necessary to demonstrate Nebius’s compliance with its obligations under this DPA, including, where available and appropriate, security documentation, audit reports, certifications, summaries, or other relevant compliance materials. 5.5. Audits. Nebius will allow an independent, suitably qualified auditor appointed by the Customer to conduct inspections to verify Nebius’s compliance with its obligations under this DPA, provided that Customer gives at least thirty (30) days’ prior notice and does not request such inspections more than once per calendar year. All additional costs and expenses incurred by Nebius in connection with such audits may be charged to the Customer. Any audit or inspection must be conducted during regular business hours, in a manner that does not unreasonably disrupt Nebius’s business operations, and subject to appropriate confidentiality, security, and access restrictions. All additional costs and expenses incurred by Nebius in connection with such audits may be charged to Customer.

6. Transfer of Personal Data

6.1. Data Processing Location. For Nebius AI Cloud, Customer Content is hosted and processed in the region selected by Customer, subject to any limited Processing outside that region necessary for the operation, maintenance, security or support of the Services as described in the applicable Sub-processor List. For Nebius Token Factory, the processing location depends on the model, endpoint type and processing location used. For public model endpoints, the applicable processing location is specified in the API or displayed in the Token Factory interface. For dedicated endpoints, Customer Content is processed in the region selected by Customer, subject to any limited Processing outside that region necessary for the operation, maintenance, security or support of the Services as described in the applicable Sub-processor List. 6.2. Cross-Border Transfers; SCCs. To the extent any transfer of Customer Personal Data subject to the GDPR, the UK GDPR, or the Swiss FADP is made to a country lacking an Adequacy Decision, such transfer shall be governed by the Standard Contractual Clauses, which shall be deemed incorporated into and form an integral part of the Terms of Service in accordance with Annex 2 of this DPA.

7. Return and Deletion of Customer Personal Data Processed on Customer’s Behalf

Upon termination or expiration of the applicable Services, Nebius will, at Customer’s choice and subject to the functionality of the applicable Services, delete or return Customer Personal Data processed by Nebius on the Customer’s behalf. For clarity, this Section applies only to Customer Personal Data processed by Nebius on Customer’s behalf as a processor and does not apply to Personal Data processed by Nebius as a controller, which may be retained in accordance with Nebius’s Privacy Policy, applicable retention policies and Applicable Data Protection Laws.

8. General

8.1. Severability. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions will remain in full force and effect. 8.2. Limitation of Liability. The liability of each Party and its affiliates arising out of or in connection with this DPA will be subject to the limitations and exclusions set forth in the applicable Terms of Service. 8.3. Governing Law and Jurisdiction. This DPA will be governed by and construed in accordance with the governing law specified in Section 17 of the Terms of Service, without prejudice to the governing law and jurisdiction provisions applicable to the Standard Contractual Clauses. 8.4. Order of Precedence. In the event of any conflict between this DPA and any data protection provisions in the Terms of Service or other agreements between the Parties relating to the Services, this DPA will prevail with respect to the processing of Customer Personal Data. In the event of any conflict between the Standard Contractual Clauses and this DPA or the Terms of Service, the Standard Contractual Clauses will prevail to the extent of such conflict.

ANNEX 1 – DETAILS OF PROCESSING

ANNEX 1A. Nebius AI Cloud Details of Processing

Annex 1A.1 - List of Parties

Data Exporter / Data Importer (as applicable based on transfer direction) Data Importer / Data Exporter (as applicable based on transfer direction)

ANNEX 1A.2 - DESCRIPTION OF THE PROCESSING / TRANSFER

Annex 1A.3 - Competent supervisory authority

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)

ANNEX 1B. Nebius Token Factory Details of Processing

Annex 1B.1 - List of Parties

Data Exporter / Data Importer (as applicable based on transfer direction) Data Importer / Data Exporter (as applicable based on transfer direction)

ANNEX 1B.2 - DESCRIPTION OF THE PROCESSING / TRANSFER

ANNEX 1B.3 - Competent supervisory authority

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)

ANNEX 2 – STANDARD CONTRACTUAL CLAUSES

A. EEA Cross Border Transfers

The Parties hereby agree to the Standard Contractual Clauses as outlined in the Annex of the European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
  • Module Two (controller to processor) of the SCC shall apply where Customer is a controller of the personal data and Nebius acts as a processor.
  • Module Three (processor to processor) of the SCC shall apply where Customer is a processor of the personal data and Nebius acts as a Sub-processor.
  • Module Four (processor to controller) of the SCC shall apply where Nebius, acting as a Processor established in the EEA, transfers Personal Data to the Customer acting as a Controller located outside the EEA.
Clause 7 of the SCC (Docking Clause) shall not apply. For the purposes of Clause 9 of the SCC (concerning Module Three transfers), the Parties choose the option 2 “General Written Authorisation” in Clause 9 of the SCC shall apply, and specify that the processor shall inform in writing the controller of any intended changes of that list through the addition or replacement of Sub-processors at least fifteen (15) days in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned Sub-processor(s). The Parties also agree that the relevant agreed list of Sub-processors is provided in Annex 1 to this DPA and may be amended from time to time as agreed in this clause. For the purposes of Clause 11 of the SCC, the optional language will not apply. For the purpose of Clause 17 of the SCC, option 1 shall apply, and the Parties agree that the SCC shall be governed by the laws of the Netherlands. For the purpose of Clause 18(b), disputes shall be resolved before the courts of the Netherlands. Annex I.A of the SCC shall be completed as set out in Annex 1A.1 for Nebius AI Cloud and Annex 1B.1 for Nebius Token Factory, as applicable. Annex I.B of the Standard Contractual Clauses shall be completed as set out in Annex 1A.2 for Nebius AI Cloud and Annex 1B.2 for Nebius Token Factory, as applicable. The period for which the personal data will be retained is for the duration of the Agreement, unless agreed otherwise in the Agreement and/or the DPA. In relation to transfers to Sub-processors, the subject matter, nature, and duration of the processing are set forth in Annex 1A.2 for Nebius AI Cloud and Annex 1B.2 for Nebius Token Factory, as applicable. Annex I.C of the SCC shall be completed as follows: The competent supervisory authority in accordance with Clause 13 is the supervisory authority in the Member State stipulated in Section 8 of the DPA. Annex 3 of this DPA serves as Annex II of the SCC. The Parties agree that other clauses and additional safeguards added by this DPA to the SCC do not directly or indirectly contradict the SCC or detract from the fundamental rights or freedoms of data subjects. To the extent there is any conflict between the Standard Contractual Clauses and any other terms in this DPA or the Terms of Service, the provisions of the Standard Contractual Clauses will prevail.

B. UK Cross Border Transfers

In relation to transfers of Customer Personal Data protected by the UK GDPR, the SCCs as implemented under section A above shall apply with the following modifications: The SCCs shall be modified and interpreted in accordance with Part 2 of the UK Addendum (“UK Addendum”), which shall be deemed incorporated into and form an integral part of the DPA. Tables 1, 2 and 3 in Part 1 of the UK Addendum shall be deemed completed with the information set out in Annex 2 and, as applicable, Annex 1A and Annex 3 for Nebius AI Cloud, and Annex 1B and Annex 3 for Nebius Token Factory. Table 4 in Part 1 of the UK Addendum shall be deemed completed by selecting “neither party”. Any conflict between the terms of the SCCs and the UK Addendum will be resolved in accordance with Section 10 and Section 11 of the UK Addendum.

C. Swiss Cross Border Transfers

In relation to transfers of Customer Personal Data protected by the Swiss Data Protection Act, the SCCs as implemented under section A above will apply with the following modifications: References to “Regulation (EU) 2016/679” (or GDPR) and specific articles therein shall be interpreted as references to the Swiss Data Protection Act and the equivalent articles or sections therein. References to “EU”, “Union”, “Member State” and “Member State law” shall be replaced with references to “Switzerland” and/or “Swiss law” (as applicable). References to the “competent supervisory authority” and “competent courts” shall be replaced with references to the “Swiss Federal Data Protection Information Commissioner” and “applicable courts of Switzerland”). The SCCs shall be governed by the laws of Switzerland. Disputes shall be resolved before the competent Swiss courts.

ANNEX 3 – Security Measures

Nebius implements and maintains the technical and organizational measures described in this Annex for Customer Personal Data processed by Nebius as processor or sub-processor under the applicable DPA in providing Nebius AI Cloud and Nebius Token Factory. The measures apply to systems, infrastructure and processes under Nebius’s control. This Annex provides a common security-control baseline for both Services. Product-specific qualifications for Nebius Token Factory are identified expressly in this Annex. The measures are designed to provide a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the Processing, and the risks of varying likelihood and severity to the rights and freedoms of natural persons. Nebius AI Cloud and Nebius Token Factory are included within the scope of Nebius’s security, privacy, business continuity and AI governance assurance programme. Current information regarding certifications, independent assurance reports, standards-alignment materials and regulatory-alignment materials, including their respective scope, validity or assessment periods, and availability, is published through the Nebius Trust Center at https://nebius.com/trust-center. Trust Center materials provide assurance evidence and do not replace or amend this Annex or the applicable DPA. Product-specific capabilities, configurations and data-handling details for each Service are described in its applicable documentation, available at https://docs.nebius.com/ for Nebius AI Cloud and https://docs.tokenfactory.nebius.com/ for Nebius Token Factory (collectively, the “Documentation”). The measures in this Annex describe Nebius’s common baseline controls for Nebius AI Cloud and Nebius Token Factory, subject to the product-specific qualifications expressly identified in this Annex. References to the Documentation provide implementation details and do not override this Annex or the applicable DPA. Under the shared responsibility model, the Customer remains responsible for the measures within its control, including classifying and configuring its workloads; managing Customer-controlled backups and monitoring where applicable; determining whether a selected model, endpoint type and processing location are appropriate for its use case; managing users, groups, project permissions and API keys; protecting credentials; configuring Zero Data Retention and other available security or privacy features; and minimizing and lawfully submitting Customer Content. The measures described in this Annex include the following:

Security, confidentiality, integrity, availability and resilience

Nebius maintains security policies, procedures, systems and controls designed to ensure the ongoing security, confidentiality, integrity, availability and resilience of its processing systems, networks and services. These measures include network segmentation and traffic controls, firewalls, continuous security monitoring, capabilities to detect intrusions and other security threats, a vulnerability management programme, and periodic security assessments and penetration testing. Identified vulnerabilities are prioritised and addressed based on their severity, exploitability and potential business impact. The measures applied to the Customer’s Personal Data are at least as stringent and protective as those applied by Nebius to its own data and systems of a similar nature.

Restoration of availability and access

Nebius maintains a business continuity management system and recovery procedures designed to restore the availability of and access to Personal Data in a timely manner following a physical or technical incident. Business impact analyses inform continuity priorities and recovery planning for both Services. Continuity and recovery plans are periodically exercised and reviewed. Service-specific availability, backup, restoration and Customer responsibility details, where applicable, are described in the Documentation or applicable service terms. For Nebius AI Cloud, the Customer is responsible for configuring and managing backups of Customer Content unless a specific Service expressly provides a Nebius-managed backup capability. For Nebius Token Factory, Nebius backs up control-plane and service-configuration metadata for platform recovery; these backups do not provide a Customer-directed restore. Customers remain responsible for backing up Customer Content, including uploaded files, model weights and fine-tuning artifacts.

Testing and evaluation

Nebius regularly monitors, tests, assesses and evaluates the effectiveness of the technical and organizational measures implemented to ensure the security of the Processing. Activities may include risk assessments, vulnerability scanning, penetration testing, control reviews, continuity exercises, internal audits and independent assessments, as appropriate to the relevant systems and risks. For both Services, the assurance programme includes periodic risk assessments, internal audits and independent assessments. Findings and corrective actions are documented and tracked.

Access management and access control

Nebius maintains appropriate and current controls designed to prevent unauthorised access to data processing systems. These controls include:
  • access granted on a need-to-know basis and in accordance with the principles of least privilege and segregation of duties; and
  • a verifiable approval process under which each access request is reviewed to confirm that the requested access is necessary.
Nebius applies an access management framework covering identification, authentication, authorisation and accountability, including logging. Access to critical Nebius systems is role-based, subject to least privilege, regularly reviewed and protected with multi-factor authentication where appropriate. Nebius AI Cloud also provides Customer-facing identity and access management groups, roles and identity-federation capabilities for managing access to Customer resources. Nebius Token Factory provides Customer-facing organization- and project-level groups and permissions, API keys within projects, and SAML 2.0-compatible identity federation for managing access to supported Customer resources.

Data segregation and sharing controls

Nebius maintains controls designed to logically segregate Personal Data from data processed on behalf of other customers or for other purposes. In Nebius AI Cloud, Customer resources are scoped to tenants and projects, access permissions are managed through identity and access controls, and Customers can use virtual networks, subnets, routing controls and security groups to isolate and control traffic between resources. In Nebius Token Factory, Customer resources are organized within organizations and projects, with project-level access controls. Nebius Token Factory supports public and dedicated endpoints. Public endpoints use shared multi-tenant capacity. Dedicated endpoints use capacity reserved for the Customer’s organization, with logical isolation enforced through organization- and project-level access controls. Nebius also maintains controls governing the sharing of Personal Data within Nebius and with authorised third parties.

Data residency

For Nebius AI Cloud, Customer Content is hosted and processed in the region selected by Customer, subject to any limited Processing outside that region necessary for the operation, maintenance, security or support of the Services as described in the applicable Sub-processor List. Processing and storage locations in Nebius Token Factory depend on the Service, model, endpoint type and Customer configuration. Public endpoints are not region-pinned, and their real-time processing location may vary among the locations identified in the Documentation. For dedicated endpoints, the inference data plane remains in the region selected by the Customer.

Encryption and pseudonymisation

For Nebius AI Cloud, Nebius supports encryption of Personal Data in transit using secure protocols such as TLS and encryption at rest for supported public storage services and configurations using AES-256. Encryption keys for Nebius-managed storage encryption are managed through Nebius Key Management Service (KMS) using envelope-encryption controls. Service-specific encryption defaults and any Customer enablement requirements are described in the Documentation. For Nebius Token Factory, Nebius applies encryption at rest to Customer Personal Data in supported Nebius-managed storage services and configurations. Data in transit between the Customer and Nebius is protected with TLS. Nebius also uses TLS for communication between Nebius Token Factory services over external networks. Encryption keys are Nebius-managed, and Customer-managed keys are not currently offered. Nebius applies pseudonymisation, anonymisation or de-identification where applicable to Nebius-controlled Processing, taking into account the purposes and risks of the Processing. The Customer remains responsible for minimizing Customer Content and applying application-level encryption, pseudonymisation or tokenisation where required by its use case.

Data access control

Nebius maintains logical access controls, service-level isolation and storage protections designed to prevent unauthorised access, reading, copying, alteration or deletion of Personal Data during Processing or while in storage. Service-specific storage controls and Customer configuration responsibilities are described in the Documentation.

Data transmission and transfer control

Nebius uses access controls, secure communication protocols and transfer records, where applicable, to protect Personal Data against unauthorised access, copying, alteration or deletion during electronic transmission or transport and to enable intended transfer recipients to be identified and verified.

Logging and audit trails

Nebius maintains logging and monitoring designed to record security-relevant and administrative activity within Nebius-controlled systems. Nebius AI Cloud maintains central logging and provides Audit Logs capabilities for supported Services so Customers can view and export relevant control-plane events and, where available and configured, data-plane events. The scope, enablement and retention of these logs vary by Service and event type as described in the Documentation. Nebius Token Factory provides Customer facing operational observability for supported dedicated endpoints, including metrics and supported export interfaces, with access governed by project permissions. For Nebius Token Factory, Customer facing operational observability is distinct from Nebius’s internal security logging and audit trails and does not currently include Customer-facing audit logs for identity, permission, API-key, endpoint or deployment changes.

Information security and incident management

Nebius maintains an information security policy, security incident management procedures and business continuity plans. These include, among other things:
  • security and risk assessments relating to the Processing of Personal Data;
  • defined security responsibilities and organizational rules;
  • procedures for identifying, responding to and managing security incidents; and
  • processes for maintaining security systems and controls in an up-to-date state.
If Nebius becomes aware of a Security Breach affecting Customer Personal Data, Nebius notifies the Customer without undue delay in accordance with Section 5 of the DPA, documents the response and implements appropriate corrective actions and lessons learned.

Security governance and personnel training

Information security is overseen by personnel with appropriate expertise and competence. Relevant personnel are subject to confidentiality obligations and receive appropriate data protection training and annual information security awareness training.

Physical and environmental security

Nebius maintains measures designed to protect buildings, premises and facilities housing data processing systems or media containing Personal Data. Data centre facilities use layered physical access controls, video surveillance and on-site security, together with redundant power, cooling and fire-suppression systems designed to support availability and resilience.

Asset management

Nebius maintains asset management policies and procedures, including an inventory of relevant information and technology assets that is reviewed at least annually.

Human resources security

Nebius maintains human resources security policies and procedures, including, where applicable, pre-employment background checks and the timely disabling of user accounts upon termination of employment or other engagement.

Supplier and Sub-processor security

Nebius assesses relevant suppliers and Sub-processors based on risk and imposes written data protection, security and confidentiality obligations appropriate to the services provided. Sub-processors that process Customer Personal Data are engaged in accordance with the applicable DPA and are identified in the Sub-processor List for the relevant Service, as referenced in Section 4 of that DPA. Changes to Sub-processors are governed by the notification and objection provisions of the applicable DPA.

Endpoint protection

Nebius maintains risk-appropriate anti-malware and endpoint security controls on systems used to administer Nebius-controlled environments.

Change management

Nebius maintains change management policies and procedures designed to ensure that changes are reviewed, tested and approved before deployment to production environments.

System configuration and hardening

Nebius maintains secure configuration standards and hardening baselines for Nebius-controlled systems, including security-relevant default configurations where applicable. Configurations are reviewed and updated in response to relevant changes and threats, and security patches or compensating controls are applied according to risk.

Secure development and vulnerability management

Nebius follows a secure software development lifecycle with separated development, test and production environments, segregation of responsibilities, version control, controls over source-code libraries, application security testing, automated source-code analysis and controlled release processes. Nebius’s vulnerability management programme includes automated and manual scanning, threat-informed prioritisation and tracking of remediation to resolution.

Security documentation and accountability

Nebius maintains complete and up-to-date documentation proportionate to the risk profile of the Processing, including records of relevant security measures, risk assessments, reviews, audits and corrective actions. Nebius makes appropriate public assurance information available through the Trust Center and provides additional compliance information in accordance with the audit and assistance provisions of the DPA.

Data processing governance and lifecycle management

Nebius processes Personal Data solely in accordance with the relevant Controller’s documented instructions. Nebius applies privacy-by-design and data-minimization principles to its own relevant processes. Nebius Token Factory does not use Customer Content to train, fine-tune or improve models for Nebius or any third party, except as directed by the Customer to perform a Customer-requested fine-tuning or post-training operation. The Customer determines the content of its workloads, inputs, datasets and other resources and remains responsible for their accuracy, relevance, lawfulness and minimization. Nebius retains Customer Personal Data only for as long as necessary to provide the applicable Services or meet applicable legal obligations. For Nebius AI Cloud, Nebius applies documented retention schedules, and Customers can delete Customer-controlled resources. Nebius deletes or returns Customer Personal Data following termination as provided in the applicable DPA. Nebius maintains secure data deletion and media disposal procedures appropriate to the relevant technology and risk. Nebius Token Factory qualifications: When Zero Data Retention is enabled, Nebius Token Factory does not retain supported chat-completion request and response content after each request is processed, as described in the Documentation. Unless Zero Data Retention is enabled, inputs and outputs may be retained and used solely for the documented speculative-decoding purpose and not for model training or improvement. Customers can delete supported resources through available interfaces and APIs. Account-level deletion requests are handled through Nebius’s operational deletion procedures. Zero Data Retention is configured at the Nebius Token Factory organization level for the supported inference content described above; request metadata and observability data are retained and are not covered by Zero Data Retention. Supported deletions remove applicable data from active storage but do not individually purge existing backup copies. Service-specific retention and deletion behavior for other Customer Content, metadata, logs, backups and product features varies by data type and feature and is further described in the Documentation where applicable. Data portability and assistance with data subject rights: Nebius AI Cloud provides interfaces and tools that enable Customers to export data from supported Services. Nebius Token Factory provides interfaces and APIs that enable Customers to access, export or delete supported Customer Content and to manage supported resources, as described in the Documentation. Nebius provides channels through which Customers may request assistance with data subject requests in accordance with the DPA, taking into account the nature of the Processing and the information available to Nebius.

Review and updates

Nebius reviews the technical and organizational measures described in this Annex at least annually and may update them from time to time to reflect changes in technology, industry practices or the nature of the Processing, provided that no such update materially reduces the overall level of security afforded to Personal Data.
Web address: https://docs.nebius.com/legal/dpa Publication date: September 15, 2026
Effective date: September 15, 2026
Previous version of the document: https://docs.nebius.com/legal/archive/dpa-20251031Previous version of the document: https://docs.nebius.com/legal/archive/dpa-20250331