Data Processing Addendum
Nephilim’s obligations as processor of the data the Customer uploads to Behemoth.
In effect from 2026-09-01
1. Subject matter and roles
This Addendum governs the processing of the personal data the Customer uploads to Behemoth about its own customers, suppliers, employees, and the other third parties with which it deals.
With respect to that data, the Customer is the controller: it decides what data it collects, for what purpose, and on what legal basis, and is answerable for having informed the data subjects and for having the necessary legal grounds. Nephilim Systems LLC is the processor and acts on the Customer’s behalf.
This Addendum forms part of the Terms of Service and is accepted together with them. Matters not addressed here are governed by the Terms; in the event of a conflict concerning the processing of personal data, this Addendum prevails.
The processing of the Customer’s own account data, in which Nephilim acts as controller, falls outside this Addendum and is governed by the Privacy Policy.
2. Details of the processing
Subject matter: the provision of Behemoth as a business management service, in the modules the Customer’s plan enables.
Duration: for as long as the subscription is in effect, plus the subsequent export window set by the Refund and Cancellation Policy.
Nature and purpose: collection, recording, structuring, storage, retrieval, modification, extraction, and erasure of data, for the sole purpose of providing the service and supporting it. Nephilim does not process this data for any purpose of its own.
Categories of data processed:
- Identification data: name, identity document, address, telephone number, and email address.
- Commercial and transactional data: sales, quotations, purchase orders, services engaged, and associated notes.
- Economic and financial data: credit extended by the Customer, installments, payments received, balances, late charges, and guarantees.
- Employment data, where the Customer registers its employees as users or as those responsible for a transaction.
Categories of data subjects:
- The Customer’s customers and prospective customers, including their sureties or guarantors.
- The Customer’s suppliers and the contact persons it registers for them.
- The Customer’s employees and collaborators with access to the system or mentioned in a transaction.
The Customer must not upload to Behemoth special categories of data — health, ethnic origin, beliefs, biometrics, or sexual orientation — or data of minors. The system is not designed to process them, and uploading them is the Customer’s exclusive responsibility.
3. The Customer’s instructions
Nephilim processes personal data solely in accordance with the Customer’s documented instructions. The Terms of Service, this Addendum, the configuration the Customer applies in the system, and the use it makes of the system’s features constitute documented instructions.
Nephilim does not disclose or use that data for any purpose unrelated to the provision of the service, unless a law applicable to it so requires. In that case, it informs the Customer before proceeding, unless that same law prohibits doing so on grounds of public interest.
If Nephilim considers that an instruction from the Customer infringes applicable data protection law, it informs the Customer without delay and may suspend the execution of that instruction until the Customer confirms, modifies, or withdraws it.
4. Confidentiality
Nephilim personnel with access to the Customer’s personal data are bound by an express duty of confidentiality, contractual in nature and of indefinite duration, which survives the end of their engagement.
Access is granted only to the personnel who need it in order to provide the service or support it, and is revoked as soon as it ceases to be necessary.
5. Security measures
Nephilim applies and maintains, at a minimum, the following technical and organizational measures:
- Encryption in transit by means of TLS in all communication with the service.
- Encryption at rest of the database and the file storage.
- Logical isolation between customers at the database level: the engine applies row-level policies that prevent a query from reaching another customer’s data, regardless of the application code that issues it.
- Access control by roles and permissions, administered by the Customer itself, so that each user operates only on what their function requires.
- Audit logging of creations, deletions, and modifications, identifying the user who executed the operation and the moment at which it occurred.
- Periodic backups, with verification that they can be restored.
- Private storage of the files the Customer uploads, accessible only through signed links of limited validity.
These measures may be updated in order to incorporate technical improvements. No update will reduce the level of security described in this section.
6. Subprocessors
The Customer grants a general authorization for Nephilim to engage subprocessors in order to provide the service. The current subprocessors, together with the service they provide, the data they access, and the place where they process it, are set out in the Subprocessor List published on this site.
Nephilim imposes on each subprocessor, by contract, data protection obligations equivalent to those of this Addendum, and remains liable to the Customer for the performance of those obligations.
Any addition or replacement of a subprocessor is notified to the Customer at least thirty calendar days in advance, by updating the List and by a notice within the system.
Within that period the Customer may object to the change on reasonable grounds relating to data protection. If the objection cannot be resolved, the Customer is entitled to terminate the subscription without penalty. The effects of that termination on amounts already paid are governed by the Refund and Cancellation Policy, which is the single refund rule of this package.
7. Assistance to the Customer
Nephilim assists the Customer, taking into account the nature of the processing and the information available to it, so that the Customer can comply with its own obligations.
In particular, it makes available to the Customer the features of the system that allow a data subject’s data to be located, exported, rectified, and deleted, so that the Customer can itself handle the requests for access, rectification, erasure, portability, objection, and restriction that it receives. Where those features are not sufficient, Nephilim provides reasonable additional cooperation.
If a data subject’s request reaches Nephilim directly, Nephilim does not answer it on its own account: it forwards it to the Customer without undue delay.
Nephilim likewise assists the Customer in carrying out data protection impact assessments and in any prior consultations with the supervisory authority arising from them, providing the technical information in its possession.
8. Security incidents
Nephilim notifies the Customer of any breach of security affecting personal data processed on the Customer’s behalf, without undue delay after becoming aware of it.
The notification describes the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed in order to mitigate it, together with a contact point from which further information can be obtained.
Where it is not possible to gather all of that information at once, what is available is notified immediately and updates are sent as more becomes known, without waiting for the investigation to be closed.
Nephilim documents each incident and the corrective measures applied, and makes that documentation available to the Customer so that the Customer can comply with its own notification duties.
9. Return and deletion of the data
On termination of the provision of the service, and at the Customer’s election, Nephilim returns or deletes the personal data processed on its behalf.
To that end, the export of the data remains available during the window published in the Refund and Cancellation Policy, counted from cancellation. The Customer is responsible for downloading its data within that period.
Once the window has expired, Nephilim deletes the data from its active systems and purges it from the backups in accordance with their rotation cycle.
Data that a legal, accounting, or tax obligation requires to be retained is excepted from deletion. In that case, it is retained only for the period required, is limited to that purpose, and remains covered by this Addendum for as long as the retention lasts.
10. Audit
Nephilim makes available to the Customer the reasonable information the Customer needs in order to verify compliance with the obligations of this Addendum, and responds to the security and privacy questionnaires the Customer sends it.
Where that information is not sufficient, and on reasonable prior notice, the Customer may request an audit limited to what is necessary in order to verify such compliance. The audit is conducted during business hours, without interrupting the operation of the service, subject to a duty of confidentiality, and without access to other customers’ data or to information that would compromise the security of the platform.
Unless the audit reveals a material breach, its costs are borne by the Customer.
11. Language
The Spanish version of this Addendum is the binding one. This English version is provided as a courtesy translation; in the event of any discrepancy, the Spanish text prevails.