DATA PROCESSING ADDENDUM

Niiice Turbo Data Processing Addendum

Last updated: July 15, 2026

1. Roles and Scope

For customer-directed end-user data, the customer is the controller (or instructing business) and Niiice is the processor. This Addendum is part of the Agreement and applies only to such processing.

2. Processing Details

Niiice processes website visitors, leads, customers, social users, and communication participants for hosting, publishing, AI generation, customer service, social management, backup, support, security, and related ordered functions for the subscription term and deletion period. Data may include identifiers, contact data, communications, content, platform IDs, technical data, and customer-defined fields.

3. Customer Obligations

  • Provide lawful, complete, and documented instructions.
  • Give required privacy notices and obtain required permissions or other lawful bases.
  • Avoid unnecessary sensitive data and configure access and retention appropriately.
  • Respond to end-user requests and verify the legality of content and campaigns.

4. Niiice Obligations

  • Process only on the Agreement, order, product configuration, and documented instructions, unless law requires otherwise.
  • Bind authorized personnel to confidentiality and apply role-based access.
  • Maintain reasonable technical and organizational security measures.
  • Assist reasonably with rights requests, security, and compliance information considering the nature of processing.
  • Not sell the data or use it for third-party advertising.

5. Subprocessors and Transfers

The customer generally authorizes necessary hosting, database, security, payment, email, domain, AI, and integration subprocessors. Niiice remains responsible for imposing appropriate processing obligations. Where a material new subprocessor affects customer-directed data, Niiice will provide reasonable notice through the Service or documentation.

6. Incidents and Requests

Niiice will notify the customer without undue delay after confirming a security incident affecting customer-directed personal data where notice is legally or materially required, and will provide information reasonably available for the customer’s response. Niiice may refer a requester to the customer unless law requires otherwise.

7. Return, Deletion, and Review

On termination, data is exported where the applicable Product Schedule permits and is then deleted or de-identified under the Privacy Policy, subject to backup rotation and legal retention. On reasonable written request, Niiice will provide available compliance information; any exceptional audit must protect other customers, security, confidentiality, and Niiice operations.

8. Liability and Priority

The Terms’ liability allocation and cap apply to this Addendum to the maximum extent permitted by law. For processing obligations only, this Addendum prevails over inconsistent general language.