1. Definitions
Terms in this DPA have the same meaning as those in the Terms of Service, unless expressly defined otherwise in this DPA. Capitalized terms not defined herein shall have the meaning assigned to them in the Terms of Service. 1.1. “Adequacy Decision” means a decision adopted by the European Commission pursuant to Article 45 of the General Data Protection Regulation, determining that a third country, a territory or one or more specified sectors within that country ensure an adequate level of protection for personal data, allowing transfers of personal data from the European Economic Area (“EEA”) to such country without the need for additional safeguards. 1.2. “Applicable Data Protection Laws” means all data protection and privacy laws and regulations applicable to the respective Party in its role in the processing of personal data under the Terms of Service, which may include, to the extent applicable, European Data Protection Laws. 1.3. “CCPA” means the California Consumer Privacy Act of 2018 (Cal. Civ. Code § 1798.100, et seq.), as may be amended, superseded or replaced from time to time. 1.4. “Customer Content” means, if not defined within the Terms of Service, all data processed by Nebius on your behalf in the course of providing the Services. 1.5. “Customer Personal Data” means any personal data contained within Customer Content. 1.6. “European Data Protection Laws” means (a) Regulation 2016/679 (General Data Protection Regulation)(“EU GDPR”); (b) the EU GDPR as saved into United Kingdom law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”); and (c) the Swiss Federal Data Protection Act and its implementing regulations (“Swiss Data Protection Act”); in each case as may be amended, superseded or replaced from time to time. 1.7. “Sell”, “Selling”, “Share”, and “Sharing” shall have the meanings given in the CCPA. 1.8. “Security Breach” means a breach of security leading to an accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. 1.9. “Security Measures” means the technical and organizational measures implemented and maintained by Nebius to protect Customer Personal Data, as described in the . 1.10. “Services” means the services provided by Nebius to Customer under the applicable Terms of Service, including, as applicable, Nebius AI Cloud, Nebius Token Factory, and any other services identified in an applicable order, service description, account, or service-specific annex. 1.11. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021, as may be amended, superseded or replaced from time to time. 1.12. “Sub-processor” means any other processor engaged by Nebius to process Customer Personal Data. 1.13. “Sub-processor List” means, with respect to each Service, the then-current list of Sub-processors engaged by Nebius in connection with such Service, including their processing activities and countries of location, as published at the applicable URL for that Service: for Nebius AI Cloud, at https://docs.nebius.com/legal/sub-processors; and for Nebius Token Factory, at https://docs.nebius.com/legal/sub-processors_tofa, or such other location as Nebius may notify to Customer from time to time. 1.14. “UK Addendum” means the International Data Transfer Addendum issued by the Information Commissioners Office under S.119 (a) of the UK Data Protection Act 2018, as updated or amended from time to time. 1.15. The terms “controller”, “data subject”, “supervisory authority”, “processor”, “process”, “processing”, “personal data”, and “personal information” shall have the meanings given to them in Applicable Data Protection Laws. The term “controller” includes “business”, the term “data subject” includes “consumers”, and the term “processor” includes “service provider” (in each case, as defined by the CCPA).2. Processing of Personal Data
2.1. Scope and Roles of the Parties. This DPA applies when Customer Personal Data is processed by Nebius as a processor in its provision of the Services to Customer. Customer will act as either a controller or processor, as applicable, with respect to Customer Personal Data. Under the terms of the CCPA, Nebius will take the role of the service provider, and the Customer will take the role of the business. 2.2. Processing by Nebius. When processing personal data on behalf of Customer, Nebius will: (i) comply with Applicable Data Protection Laws; (ii) process Customer Personal Data only as necessary to perform its obligations under the Terms of Service and this DPA, and strictly in accordance with Customer’s documented instructions; and (iii) process Customer Personal Data only for the purposes authorized by Customer, including as set out in the Terms of Service, this DPA, and the applicable Annexes describing the processing activities for the relevant Services, collectively (“Permitted Purpose”). 2.3. Processing by Customer. Customer will: (i) comply with Applicable Data Protection Laws in its processing of personal data and in any instructions it issues to Nebius; (ii) use the Services in a secure manner and independently determine whether the Security Measures available through the Services satisfy Customer’s legal and contractual obligations; (iii) provide all required notices and obtain, maintain and have all necessary consents, authorizations and rights to process Customer Personal Data through the Services and to provide Instructions to Nebius; and (iv) inform Nebius without undue delay if Customer is unable to comply with its responsibilities under Applicable Data Protection Laws or if Customer believes that its instructions would cause Nebius to violate Applicable Data Protection Laws. 2.4. Details of Processing. The subject matter of Nebius’s processing of Customer Personal Data is the provision of the applicable Services under the Terms of Services. The duration, nature and purpose of the processing, and the types of Customer Personal Data and categories of data subjects are set out in the service-specific Annexes describing the processing activities for the relevant Services: Annex 1A for Nebius AI Cloud and Annex 1B for Nebius Token Factory, as applicable. 2.5. Confidentiality of Processing. Nebius shall ensure that any person that it authorizes to process Customer Personal Data (including Nebius’ staff, agents and subcontractors) (“Authorized Person”) shall be subject to a strict duty of confidentiality (whether a contractual duty or a statutory duty), and shall not permit any person to process Customer Personal Data who is not under such a duty of confidentiality. Nebius shall ensure that all Authorized Persons process Customer Personal Data only as necessary for the Permitted Purpose and that Authorized Persons not access or otherwise process personal data or personal information that is not Personal Data and necessary for the Permitted Purpose.3. Assistance Obligations
3.1. Data Subject Requests. Customer is responsible for responding to and complying with requests from data subjects to exercise their rights under Applicable Data Protection Laws (“DSR”). If Nebius receives a DSR directly and the request identifies Customer or enables Nebius to identify Customer, Nebius will promptly forward the DSR to Customer. Unless legally required to respond, Nebius will not respond to the data subject except to acknowledge receipt and refer the individual to Customer for a response. Nebius will provide reasonable assistance to Customer, taking into account the nature of the processing and the information available to Nebius, to enable Customer to respond to DSRs in accordance with Applicable Data Protection Laws. 3.2. Legal Requests. If Nebius receives a subpoena, court order, warrant, or other legally binding demand from law enforcement or any public or judicial authority seeking disclosure of Customer Personal Data, Nebius will first attempt to redirect the requesting authority to seek the information directly from Customer and may provide the authority with Customer’s basic contact information for that purpose. If Nebius is compelled to disclose Customer Personal Data, Nebius will provide Customer with reasonable prior notice of the demand so Customer may seek a protective order or other appropriate remedy, unless Nebius is legally prohibited from giving such notice. In responding to any legally binding demand, Nebius will disclose only the minimum amount of Customer Personal Data necessary to comply with the demand and will challenge requests that Nebius reasonably believes are overbroad, unlawful, or otherwise invalid.4. Sub-processors
4.1. Authorization. Customer provides a general written authorization for Nebius to engage Sub-processors to process Customer Personal Data in accordance with this Section 4. Nebius has entered into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those set forth in this DPA, to the extent applicable to the nature and scope of the Services provided by the Sub-processor. Nebius remains responsible for the performance of its obligations under this DPA, including where such obligations are performed by its Sub-processors. 4.2. Service-Specific Sub-processor Lists. Nebius maintains a separate Sub-processor List for each applicable Service, including Nebius AI Cloud, at https://docs.nebius.com/legal/sub-processors, and Nebius Token Factory, at https://docs.nebius.com/legal/sub-processors_tofa. Customer hereby authorizes Nebius to engage the Sub-processors identified in the applicable Sub-processor List for the relevant Service, including their locations and processing activities, in connection with such Service. 4.3. Changes to Sub-processors. Nebius will provide Customer at least fifteen (15) days’ prior notice of any addition or replacement of a Sub-processor. Customer may object on reasonable data-protection grounds to the engagement of a new Sub-processor by providing written notice within that period. The Parties will discuss the objection in good faith. If no mutually acceptable solution is reached, Customer may terminate the affected Services and receive a pro-rata refund of any prepaid, unused fees, without liability to either Party, without prejudice to fees accrued before suspension or termination. Customer may also subscribe to receive notifications about Sub-processor updates at: https://docs.nebius.com/legal/sub-processors#summary-of-changes (currently available for Nebius AI Cloud only).5. Security and Compliance
5.1. Security Measures. Nebius implements and maintains appropriate technical and organizational measures designed to safeguard Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. A summary of these Security Measures is provided in Annex 3 to this DPA for the relevant Services. The Customer is responsible for assessing whether the above mentioned Security Measures are sufficient for the intended processing of Personal Data, and for ensuring it has a valid legal basis and complies with any additional requirements under Applicable Data Protection Laws. 5.2. Security Breaches and Cooperation with Customer. Nebius will notify Customer without undue delay after becoming aware of a Security Breach. Nebius will provide Customer with information available to Nebius and reasonable assistance necessary for Customer to meet its obligations under Applicable Data Protection Laws in relation to the Security Breach. 5.3. Data Protection Impact Assessments. Upon reasonable request, Nebius will provide Customer with information about the applicable Services necessary for Customer to conduct data protection impact assessments and any related consultations with supervisory authorities, as required by Applicable Data Protection Laws, provided that Customer does not otherwise have access to the relevant information. 5.4. Audit Program. Upon written request and at no additional cost to Customer, Nebius will provide the Customer and/or its appropriately qualified third-party representative with access to documentation reasonably necessary to demonstrate Nebius’s compliance with its obligations under this DPA, including, where available and appropriate, security documentation, audit reports, certifications, summaries, or other relevant compliance materials. 5.5. Audits. Nebius will allow an independent, suitably qualified auditor appointed by the Customer to conduct inspections to verify Nebius’s compliance with its obligations under this DPA, provided that Customer gives at least thirty (30) days’ prior notice and does not request such inspections more than once per calendar year. All additional costs and expenses incurred by Nebius in connection with such audits may be charged to the Customer. Any audit or inspection must be conducted during regular business hours, in a manner that does not unreasonably disrupt Nebius’s business operations, and subject to appropriate confidentiality, security, and access restrictions. All additional costs and expenses incurred by Nebius in connection with such audits may be charged to Customer.6. Transfer of Personal Data
6.1. Data Processing Location. For Nebius AI Cloud, Customer Content is hosted and processed in the region selected by Customer, subject to any limited Processing outside that region necessary for the operation, maintenance, security or support of the Services as described in the applicable Sub-processor List. For Nebius Token Factory, the processing location depends on the model, endpoint type and processing location used. For public model endpoints, the applicable processing location is specified in the API or displayed in the Token Factory interface. For dedicated endpoints, Customer Content is processed in the region selected by Customer, subject to any limited Processing outside that region necessary for the operation, maintenance, security or support of the Services as described in the applicable Sub-processor List. 6.2. Cross-Border Transfers; SCCs. To the extent any transfer of Customer Personal Data subject to the GDPR, the UK GDPR, or the Swiss FADP is made to a country lacking an Adequacy Decision, such transfer shall be governed by the Standard Contractual Clauses, which shall be deemed incorporated into and form an integral part of the Terms of Service in accordance with Annex 2 of this DPA.7. CCPA Compliance
Nebius will not process, retain, use, or disclose Customer Personal Data for any purpose other than as set forth in the Terms of Service, this DPA, or as otherwise permitted under the CCPA. Nebius will not “sell” or “share” Customer Personal Data, as those terms are defined under the CCPA. If Nebius becomes aware of any activity or action which would be deemed non-compliant with CCPA requirements, Nebius will promptly notify Customer of such non-compliance and work to correct such activity or action to re-establish compliant practices.8. Return and Deletion of Customer Personal Data Processed on Customer’s Behalf
Upon termination or expiration of the applicable Services, Nebius will, at Customer’s choice and subject to the functionality of the applicable Services, delete or return Customer Personal Data processed by Nebius on the Customer’s behalf. For clarity, this Section applies only to Customer Personal Data processed by Nebius on Customer’s behalf as a processor and does not apply to Personal Data processed by Nebius as a controller, which may be retained in accordance with Nebius’s Privacy Policy, applicable retention policies and Applicable Data Protection Laws.9. General
9.1. Severability. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions will remain in full force and effect. 9.2. Limitation of Liability. The liability of each Party and its affiliates arising out of or in connection with this DPA will be subject to the limitations and exclusions set forth in the applicable Terms of Service. 9.3. Governing Law and Jurisdiction. This DPA will be governed by and construed in accordance with the governing law specified in Section 17 of the Terms of Service, without prejudice to the governing law and jurisdiction provisions applicable to the Standard Contractual Clauses. 9.4. Order of Precedence. In the event of any conflict between this DPA and any data protection provisions in the Terms of Service or other agreements between the Parties relating to the Services, this DPA will prevail with respect to the processing of Customer Personal Data. In the event of any conflict between the Standard Contractual Clauses and this DPA or the Terms of Service, the Standard Contractual Clauses will prevail to the extent of such conflict.ANNEX 1 – DETAILS OF PROCESSING
ANNEX 1A. Nebius AI Cloud Details of Processing
Annex 1A.1 - List of Parties Data Exporter / Data Importer (as applicable based on transfer direction)| Field | Details |
| Name of the data exporter | The entity identified as the “Customer” in the Terms of Service and this DPA |
| Contact person’s name, position and contact details | The address and contact details associated with Customer’s Account, or as otherwise specified in this DPA or the Terms of Service |
| Activities relevant to the data transferred | The activities specified in Annex 1A.2 below |
| Signature and date | As set out in the Customer’s Account |
| Role (Controller / Processor) | Controller (for Module 4) or Processor (for Module 2 or 3) |
| Field | Details |
| Name of the data importer | Nebius Inc. |
| Contact person’s name, position and contact details | Marina Benassi, Global Data Protection Officer, privacy@nebius.com |
| Activities relevant to the data transferred | The activities specified in Annex 1A.2 below |
| Signature and date | As set out in the Terms of Service |
| Role (Controller / Processor) | Processor |
| Field | Details |
| Categories of data subjects whose personal data is transferred | Customer’s and its Affiliates’ employees, contractors, representatives, administrators, Authorized Users, end users, including individuals added to Customer’s account, organization, tenant or federated account, and any other individuals whose Personal Data is submitted to, uploaded to, stored in, transmitted through, or otherwise processed using the Services by Customer or its Authorized Users, including individuals whose Personal Data is contained in Customer Content. |
| Categories of personal data transferred | Customer Personal Data processed in the course of the AI Cloud Services as Customer Content, which may include any personal data that Customer or its Authorized Users choose to submit to, upload to, store in, transmit through, or otherwise process using the Services. Depending on Customer’s use of the Services, such Customer Content may also include, without limitation, virtual machine or container workloads, configurations, logs, metadata, and other content processed by the Services on Customer’s behalf. |
| Sensitive data transferred (if appropriate) | Subject to any applicable restrictions and/or conditions in the Terms of Services and this DPA, Customer may include Sensitive personal data or similarly personal data (as described or defined in Applicable Data Protection Laws, i.e. special categories of personal data) in Customer Personal Data, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to Customer Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data processed for the purposes of uniquely identifying a natural person, data concerning health and/or data concerning a natural person’s sex life or sexual orientation. |
| Frequency of the transfer | Continuous basis depending on the use of the Services by Customer. |
| Nature, subject matter and duration of the processing | Nature: Nebius provides cloud- and related services, as further described in the Terms of Service. Subject Matter: Customer Personal Data. Duration: The duration of the processing will be for the term of the Terms of Service. |
| Purpose(s) of the data transfer and further processing |
|
| Sub-processor transfers | In relation to transfers to Sub-processors, the subject matter and nature of the processing are specified in the list of Sub-processors (accessible at the link - https://docs.nebius.com/legal/sub-processors). The duration of the processing by Sub-processors will be the same as the duration of the Terms of Service, unless otherwise specified in the Terms of Service or this DPA. |
ANNEX 1B. Nebius Token Factory Details of Processing
Annex 1B.1 - List of Parties Data Exporter / Data Importer (as applicable based on transfer direction)| Field | Details |
| Name of the data exporter | The entity identified as the “Customer” in the Terms of Service and this DPA |
| Contact person’s name, position and contact details | The address and contact details associated with Customer’s Account, or as otherwise specified in this DPA or the Terms of Service |
| Activities relevant to the data transferred | The activities specified in Annex 1B.2 below |
| Signature and date | As set out in the Customer’s Account |
| Role (Controller / Processor) | Controller (for Module 4) or Processor (for Module 2 or 3) |
| Field | Details |
| Name of the data importer | Nebius Inc. |
| Contact person’s name, position and contact details | Marina Benassi, Global Data Protection Officer, privacy@nebius.com |
| Activities relevant to the data transferred | The activities specified in Annex 1B.2 below |
| Signature and date | As set out in the Terms of Service |
| Role (Controller / Processor) | Processor |
| Field | Details |
| Categories of data subjects whose personal data is transferred | Customer’s and its Affiliates’ employees, contractors, representatives, administrators, Authorized Users, end users, including individuals added to Customer’s account, organization, tenant or federated account, and any other individuals whose Personal Data is submitted to, uploaded to, stored in, transmitted through, or otherwise processed using the Services by Customer or its Authorized Users, including individuals whose Personal Data is contained in Customer Content. |
| Categories of personal data transferred | Customer Personal Data processed in the course of Nebius Token Factory Services as Customer Content, which may include, depending on Customer’s use of the Services, prompts, inputs, queries, instructions, files, datasets, training or fine-tuning data, model weights, embeddings, model outputs, generated content, logs, metadata, and voice recordings (if any). |
| Sensitive data transferred (if appropriate) | Subject to any applicable restrictions and/or conditions in the Terms of Services and this DPA, Customer may include Sensitive personal data or similarly personal data (as described or defined in Applicable Data Protection Laws, i.e. special categories of personal data) in Customer Personal Data, the extent of which is determined and controlled by Customer in its sole discretion, and which may include, but is not limited to Customer Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data processed for the purposes of uniquely identifying a natural person, data concerning health and/or data concerning a natural person’s sex life or sexual orientation. |
| Frequency of the transfer | Continuous basis depending on the use of the Services by Customer. |
| Nature, subject matter and duration of the processing | Nature: Nebius provides cloud- and related services, as further described in the Terms of Service. Subject Matter: Customer Personal Data. Duration: The duration of the processing will be for the term of the Terms of Service. |
| Purpose(s) of the data transfer and further processing |
|
| Sub-processor transfers | In relation to transfers to Sub-processors, the subject matter and nature of the processing are specified in the list of Sub-processors (accessible at the link - https://docs.nebius.com/legal/sub-processors_tofa). The duration of the processing by Sub-processors will be the same as the duration of the Terms of Service, unless otherwise specified in the Terms of Service or this DPA. |
ANNEX 2 – STANDARD CONTRACTUAL CLAUSES
A. EEA Cross Border Transfers The Parties hereby agree to the Standard Contractual Clauses as outlined in the Annex of the European Commission Implementing Decision (EU) 2021/914 of June 4, 2021.- Module Two (controller to processor) of the SCC shall apply where Customer is a controller of the personal data and Nebius acts as a processor.
- Module Three (processor to processor) of the SCC shall apply where Customer is a processor of the personal data and Nebius acts as a Sub-processor.
- Module Four (processor to controller) of the SCC shall apply where Nebius, acting as a Processor established in the EEA, transfers Personal Data to the Customer acting as a Controller located outside the EEA.
ANNEX 3 – SECURITY MEASURES
Nebius implements and maintains the technical and organizational measures described in this Annex for Customer Personal Data processed by Nebius as processor or sub-processor under the applicable DPA in providing Nebius AI Cloud and Nebius Token Factory. The measures apply to systems, infrastructure and processes under Nebius’s control. This Annex provides a common security-control baseline for both Services. Product-specific qualifications for Nebius Token Factory are identified expressly in this Annex. The measures are designed to provide a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the Processing, and the risks of varying likelihood and severity to the rights and freedoms of natural persons. Nebius AI Cloud and Nebius Token Factory are included within the scope of Nebius’s security, privacy, business continuity and AI governance assurance programme. Current information regarding certifications, independent assurance reports, standards-alignment materials and regulatory-alignment materials, including their respective scope, validity or assessment periods, and availability, is published through the Nebius Trust Center at https://nebius.com/trust-center. Trust Center materials provide assurance evidence and do not replace or amend this Annex or the applicable DPA. Product-specific capabilities, configurations and data-handling details for each Service are described in its applicable documentation, available at https://docs.nebius.com/ for Nebius AI Cloud and https://docs.tokenfactory.nebius.com/ for Nebius Token Factory (collectively, the “Documentation”). The measures in this Annex describe Nebius’s common baseline controls for Nebius AI Cloud and Nebius Token Factory, subject to the product-specific qualifications expressly identified in this Annex. References to the Documentation provide implementation details and do not override this Annex or the applicable DPA. Under the shared responsibility model, the Customer remains responsible for the measures within its control, including classifying and configuring its workloads; managing Customer-controlled backups and monitoring where applicable; determining whether a selected model, endpoint type and processing location are appropriate for its use case; managing users, groups, project permissions and API keys; protecting credentials; configuring Zero Data Retention and other available security or privacy features; and minimizing and lawfully submitting Customer Content. The measures described in this Annex include the following: Security, confidentiality, integrity, availability and resilience Nebius maintains security policies, procedures, systems and controls designed to ensure the ongoing security, confidentiality, integrity, availability and resilience of its processing systems, networks and services. These measures include network segmentation and traffic controls, firewalls, continuous security monitoring, capabilities to detect intrusions and other security threats, a vulnerability management programme, and periodic security assessments and penetration testing. Identified vulnerabilities are prioritised and addressed based on their severity, exploitability and potential business impact. The measures applied to the Customer’s Personal Data are at least as stringent and protective as those applied by Nebius to its own data and systems of a similar nature. Restoration of availability and access Nebius maintains a business continuity management system and recovery procedures designed to restore the availability of and access to Personal Data in a timely manner following a physical or technical incident. Business impact analyses inform continuity priorities and recovery planning for both Services. Continuity and recovery plans are periodically exercised and reviewed. Service-specific availability, backup, restoration and Customer responsibility details, where applicable, are described in the Documentation or applicable service terms. For Nebius AI Cloud, the Customer is responsible for configuring and managing backups of Customer Content unless a specific Service expressly provides a Nebius-managed backup capability. For Nebius Token Factory, Nebius backs up control-plane and service-configuration metadata for platform recovery; these backups do not provide a Customer-directed restore. Customers remain responsible for backing up Customer Content, including uploaded files, model weights and fine-tuning artifacts. Testing and evaluation Nebius regularly monitors, tests, assesses and evaluates the effectiveness of the technical and organizational measures implemented to ensure the security of the Processing. Activities may include risk assessments, vulnerability scanning, penetration testing, control reviews, continuity exercises, internal audits and independent assessments, as appropriate to the relevant systems and risks. For both Services, the assurance programme includes periodic risk assessments, internal audits and independent assessments. Findings and corrective actions are documented and tracked. Access management and access control Nebius maintains appropriate and current controls designed to prevent unauthorised access to data processing systems. These controls include:- access granted on a need-to-know basis and in accordance with the principles of least privilege and segregation of duties; and
- a verifiable approval process under which each access request is reviewed to confirm that the requested access is necessary.
- security and risk assessments relating to the Processing of Personal Data;
- defined security responsibilities and organizational rules;
- procedures for identifying, responding to and managing security incidents; and
- processes for maintaining security systems and controls in an up-to-date state.
Web address: https://docs.nebius.com/legal/dpa-inc Publication date: September 15, 2026 Effective date: September 15, 2026