Box · Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Box Terms or another agreement between a business customer and Nivora wherever Nivora processes personal data for that customer.
1. Parties, scope and roles
The customer identified in the Box account, order or signed agreement is the controller and Nivora Works, enterprise/VAT number BE 1041.516.417, is the processor for Customer Personal Data. If the customer is itself a processor, Nivora is its subprocessor and references to controller instructions include the relevant controller’s instructions.
This DPA applies only to personal data contained in connected communications, team content and other data that Nivora processes on the customer’s behalf. Nivora remains an independent controller for account administration, security, billing and its own legal obligations as described in the Privacy Policy.
2. Processing details and instructions
Subject matter and purpose: providing the Box unified inbox, account connections, storage, search, AI features chosen by the customer, notifications, support, security and deletion. Nature: collection from customer-directed providers, transmission, organisation, storage, retrieval, consultation, limited analysis, alteration, action on instruction and deletion. Duration: the service term plus the deletion and backup-rotation period.
Data subjects may include authorised users, employees, contractors, customers, prospects, suppliers and people communicating with them. Data may include identity and contact details, account identifiers, communication content and metadata, files, voice, images, professional information and any special-category or criminal-offence data a sender includes. The customer should avoid such sensitive data unless it has a documented lawful basis and suitable safeguards.
The agreement, product configuration and documented support instructions are the customer’s instructions. Nivora processes Customer Personal Data only on those instructions unless Union or Member State law requires otherwise, in which case Nivora will notify the customer before processing unless the law prohibits notice. Nivora will promptly tell the customer if an instruction appears to infringe data-protection law.
3. Customer obligations
The customer is responsible for lawful, fair and transparent collection; a valid legal basis; provider permissions; data-subject notices; configured users and roles; and instructions that comply with law. The customer must not connect an inbox or upload data it is not authorised to process.
The customer will use available security features, limit users to need-to-know access, protect credentials, remove departed users and notify Nivora promptly of suspected compromise or an unlawful instruction.
4. Confidentiality and security
Nivora ensures that people authorised to process Customer Personal Data are bound by confidentiality, receive appropriate instructions and access only what their role requires.
Nivora maintains measures appropriate to risk, including encrypted transport and managed storage, server-side secret management, tenant-scoped access controls, least privilege, authentication controls, secure development and dependency review, input and rate limits, logging without unnecessary content, backup and recovery, incident response and periodic control testing. Security measures evolve with risk and will not be materially weakened during the service term.
5. Subprocessors and transfers
The customer gives general written authorisation for the subprocessors at box.nivoraworks.com/subprocessors. Nivora will not permit a new subprocessor to receive production Customer Personal Data until contractual data-protection duties providing substantially the same protection required by this DPA are in place, and remains responsible for each subprocessor’s performance of those duties.
Nivora will give at least fifteen days’ advance notice before a new subprocessor processes Customer Personal Data, except where an urgent security replacement makes advance notice impracticable. The customer may object during that period on reasonable data-protection grounds. The parties will seek a reasonable solution; if none is available, either party may terminate only the affected feature or service without penalty for the unused prepaid portion.
For restricted transfers without an adequacy decision, the applicable 2021 European Commission Standard Contractual Clauses are incorporated by reference: Module Two for controller-to-processor and Module Three where the customer is a processor. The customer is data exporter, Nivora or its provider is data importer, Belgian law governs the optional clauses where allowed, and the Belgian Data Protection Authority is competent unless GDPR rules designate another authority. The processing details in this DPA and the security measures above complete the relevant annexes.
6. Assistance and data-subject requests
Taking account of the processing, Nivora will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection, security, breach notification, impact assessments and regulator consultations. If Nivora receives a request about customer-controlled data, it will direct the requester to the customer and will not respond substantively unless instructed or legally required.
Assistance included in standard product controls and reasonable support is included in the service. Nivora may charge agreed reasonable costs for unusually extensive, repetitive or customer-caused work, except where the work is required because Nivora breached this DPA.
7. Personal-data incidents
Nivora will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. Notice will include, as information becomes available, the nature and scope, likely consequences, containment and remediation, and a contact point. Nivora will preserve relevant evidence and cooperate so the customer can meet its notification duties.
Notification is not an admission of fault. The customer remains responsible for notifications required of it as controller; Nivora will not notify data subjects or a regulator about customer-controlled data without instruction unless law requires it.
8. Deletion, return and continuity
During the term, the customer can disconnect providers, delete content and request an export where supported. At termination or on documented request, Nivora will delete or return Customer Personal Data, at the customer’s choice where technically feasible, unless law requires retention. Provider credentials and active-system data are removed first; isolated backups expire on their protected rolling schedule and remain unavailable for normal processing.
Nivora may retain only data required by law or necessary to establish, exercise or defend legal claims, isolated and protected for that purpose. Controller account and invoice records follow the Privacy Policy rather than this processor deletion clause.
9. Demonstrating compliance and audits
Nivora will make information reasonably necessary to demonstrate Article 28 compliance available, beginning with current policies, provider reports, security summaries and questionnaire responses. No more than once per year, or after a material incident, the customer may request a proportionate audit by an independent qualified auditor bound by confidentiality.
Audits must avoid other customers’ data, source secrets and service disruption. Existing independent evidence is used first. The customer bears routine audit costs; Nivora bears reasonable costs where an audit identifies a material breach by Nivora.
10. Priority, liability and contact
This DPA prevails over conflicting service terms for its subject matter. The agreement’s lawful liability provisions apply, but nothing limits rights or liability that data-protection law does not permit the parties to limit.
Questions, instructions and subprocessor objections should be sent to box@nivoraworks.com. The parties accept this DPA when the customer accepts the Box Terms, places an order that references them, or signs a separate agreement incorporating it.
Back to Box