Data Processing Addendum
Last updated: September 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Terms”) between Nobex Technologies Inc, a Delaware corporation at 261 Madison Avenue, 9th Floor, New York, NY 10016, United States (“Nobex”), and the customer that operates a station on Nobex Radio (the “Broadcaster”). It applies automatically, without signature, whenever Nobex processes Broadcaster Personal Data (defined below) in providing the service described in the Terms (the “Service”). If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.
1. Definitions
- Data Protection Law — all laws on the processing of personal data that apply to a party’s processing under the Terms, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as retained in UK law and the UK Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection (“FADP”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and similar US state laws.
- Broadcaster Personal Data — personal data that Nobex processes on the Broadcaster’s behalf in providing the Service, as described in Annex I.
- Standard Contractual Clauses or SCCs — the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- UK Addendum — the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
- “Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach”, “business”, “service provider”, “sell” and “share” have the meanings given in Data Protection Law.
2. Roles of the parties
For Broadcaster Personal Data, the Broadcaster is the controller (or, where it acts for another controller, a processor) and Nobex is the processor (or subprocessor). This covers in particular the personal data of the Broadcaster’s listeners and supporters, and of presenters, guests and callers whose voices appear in the Broadcaster’s live broadcasts, recordings and podcast episodes.
Nobex is a separate controller of the personal data it processes to run its own business — the Broadcaster’s account, billing and support relationship with Nobex, the security of the Service, fraud prevention, and compliance with law — as described in the Privacy Policy. This DPA does not apply to that data.
The Broadcaster is responsible for having a lawful basis for the processing it instructs, for giving its listeners and contributors the notices the law requires (including that shows may be recorded and published), and for obtaining any consent that is needed.
3. Subject matter, duration, nature and purpose
Nobex processes Broadcaster Personal Data only to provide the Service: receiving, encoding, storing and delivering the Broadcaster’s streams; recording and hosting episodes; measuring listening and producing the Broadcaster’s analytics; processing listener payments to the Broadcaster; and providing support. The processing lasts for the term of the Terms and until deletion under section 9. Annex I gives the details.
4. Nobex’s obligations
Nobex will:
- Instructions. Process Broadcaster Personal Data only on the Broadcaster’s documented instructions — which are the Terms, this DPA, and the Broadcaster’s configuration and use of the Service — including for transfers to a third country, unless required to do otherwise by law, in which case Nobex will inform the Broadcaster first unless the law prohibits it. Nobex will tell the Broadcaster if, in its opinion, an instruction infringes Data Protection Law.
- Confidentiality. Ensure that everyone it authorises to process Broadcaster Personal Data is bound by confidentiality obligations and accesses it only as needed to provide the Service or support.
- Security. Implement and maintain the technical and organisational measures in Annex II, which Nobex may update provided the overall level of protection is not reduced.
- Subprocessors. Engage subprocessors only as set out in section 5.
- Data subject requests. Taking into account the nature of the processing, assist the Broadcaster by appropriate technical and organisational measures to respond to requests from data subjects exercising their rights — including through the Service’s own tools for deleting recordings, episodes and stations — and promptly forward to the Broadcaster any request Nobex receives that concerns the Broadcaster’s data, without responding to it except to redirect the requester.
- Assistance. Provide reasonable assistance with the Broadcaster’s security obligations, breach notifications, data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Nobex.
- Personal data breaches. Notify the Broadcaster without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Broadcaster Personal Data, with the information available at the time (nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, and measures taken or proposed), supplemented as more becomes known. Notice is sent to the account owner’s email address. Notification is not an admission of fault.
- Deletion or return. Delete or return Broadcaster Personal Data at the end of the Service as set out in section 9.
- Demonstrating compliance. Make available the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and contribute to audits as described in section 8.
5. Subprocessors
The Broadcaster gives Nobex general authorisation to engage subprocessors. The current list is on our subprocessors page (Annex III). Nobex will:
- impose on each subprocessor, by written contract, data protection obligations that are no less protective than this DPA;
- give at least 30 days’ notice before a new subprocessor begins processing Broadcaster Personal Data, by updating the subprocessors page and emailing those who have subscribed to updates (by writing to support@nobexinc.com);
- if the Broadcaster objects on reasonable data-protection grounds within that period, work with the Broadcaster in good faith to find an alternative; if none is found, the Broadcaster may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for it; and
- remain responsible to the Broadcaster for its subprocessors’ performance.
6. International transfers
Nobex and its main hosting are in the United States. The Broadcaster authorises the transfer of Broadcaster Personal Data to the United States and to the other locations of the subprocessors in Annex III, subject to this section. Section 10 sets out the transfer mechanisms that apply.
7. CCPA service-provider terms
Where the CCPA applies, Nobex is the Broadcaster’s service provider and processes Broadcaster Personal Data for the business purposes of providing the Service described in section 3. Nobex will not:
- sell or share Broadcaster Personal Data;
- retain, use or disclose it for any purpose — including any commercial purpose — other than the business purposes specified in the Terms and this DPA, or outside the direct business relationship with the Broadcaster, except as the CCPA permits;
- combine it with personal data Nobex receives from or on behalf of another person, or collects from its own interactions with consumers, except as the CCPA permits.
Nobex will comply with the CCPA, provide the same level of privacy protection it requires, and notify the Broadcaster if it can no longer meet these obligations. The Broadcaster may take reasonable and appropriate steps to stop and remediate unauthorised use. Nobex certifies that it understands and will comply with these restrictions.
8. Audits
On written request, and no more than once a year (or after a personal data breach, or when a supervisory authority requires it), Nobex will answer the Broadcaster’s reasonable security and data-protection questionnaire and provide documentation of the measures in Annex II. If that information is not enough to demonstrate compliance, the parties will agree the scope, timing and cost of any further audit, which must be conducted with reasonable notice, during business hours, by an auditor bound by confidentiality, and without access to other customers’ data. Requests go to support@nobexinc.com.
9. Deletion at the end of the Service
The Broadcaster can download its recordings and export its account data, and delete them, at any time through the Service. When the Broadcaster deletes its account, Nobex deletes Broadcaster Personal Data promptly, and in any case within 30 days from active systems, except where Data Protection Law or other law requires Nobex to keep it. Residual copies in logs and backups expire on their normal cycles (see the retention section of the Privacy Policy) and remain protected by this DPA until they do. Recordings are also deleted automatically at the end of the retention period of the Broadcaster’s plan.
10. Standard Contractual Clauses and transfer mechanisms
To the extent the Broadcaster (or its controller) is subject to the GDPR and Broadcaster Personal Data is transferred to Nobex in a country without an adequacy decision, the SCCs are incorporated by reference and completed as follows:
- Module Two (controller to processor) applies where the Broadcaster is a controller, and Module Three (processor to processor) where the Broadcaster is a processor for another controller;
- the Broadcaster is the data exporter and Nobex the data importer;
- Clause 7 (docking clause) applies;
- Clause 9(a): Option 2 (general written authorisation), with the notice period in section 5 of this DPA;
- Clause 11: the optional language does not apply;
- Clause 13: the supervisory authority of the Member State where the Broadcaster is established, or, if it is not established in the EU, where its representative is, or otherwise where the data subjects concerned are;
- Clauses 17 and 18: the law and courts of Ireland;
- Annexes I, II and III of the SCCs are completed by Annexes I, II and III below.
United Kingdom. For transfers subject to the UK GDPR, the UK Addendum applies, completed with the information in this DPA and its Annexes; Table 4: either party may end the Addendum as set out in its Section 19.
Switzerland. For transfers subject to the FADP, the SCCs apply with these changes: references to the GDPR are to the FADP; the competent supervisory authority is the Federal Data Protection and Information Commissioner; “Member State” includes Switzerland so that data subjects there can bring claims in their place of habitual residence.
If a transfer mechanism is invalidated or replaced, the parties will rely on the successor or another lawful mechanism.
11. Liability and general terms
Each party’s liability under or in connection with this DPA, including the SCCs to the extent the law allows, is subject to the limitations and exclusions of liability in the Terms. Nothing in this DPA limits either party’s liability to data subjects under the SCCs or Data Protection Law. This DPA ends when Nobex no longer processes Broadcaster Personal Data. Apart from the SCCs, it is governed by the law that governs the Terms. Nobex may update this DPA to reflect changes in law or the Service, with notice as provided in the Terms; an update will not reduce the protection of Broadcaster Personal Data.
12. Annex I — Details of processing
| Item | Details |
|---|---|
| Parties | Data exporter: the Broadcaster (controller or processor), contact details as in its account. Data importer: Nobex Technologies Inc, 261 Madison Avenue, 9th Floor, New York, NY 10016, USA; support@nobexinc.com (processor). |
| Categories of data subjects | Listeners to the Broadcaster’s streams and players; listeners who tip, subscribe, request songs or sponsor; presenters, co-hosts, guests and callers whose voices are broadcast or recorded; the Broadcaster’s team members; any other people featured in the Broadcaster’s content. |
| Categories of personal data | Listening sessions: keyed hash of IP address and user agent, approximate location (city, region, country), browser, operating system, player or app, session times. Transient edge server logs with IP address and user agent. Supporter data: email, name, display name, message, payment references (card data is held by Stripe/PayPal). Audio: live broadcasts, recordings and podcast episodes, including voices. Station content and metadata supplied by the Broadcaster. |
| Special categories | None intended. Recordings may incidentally reveal special-category data (for example opinions or beliefs expressed on air); the Broadcaster decides what it broadcasts and records. Annex II measures apply. |
| Frequency of transfer | Continuous, for the term of the Service. |
| Nature and purpose | Hosting, encoding, storing and delivering streams; recording and hosting episodes and feeds; listener measurement and analytics for the Broadcaster; processing listener payments to the Broadcaster; support. |
| Retention | Listener analytics: while the Broadcaster’s account exists. Recordings: per plan retention or until the Broadcaster deletes them. Edge logs: a few hours (HLS) to 3 days (MP3 relay). Application logs: about 30 days. Everything else: until account deletion, then as in section 9. |
| Subprocessor transfers | As listed in Annex III, for the purposes stated there. |
| Competent supervisory authority | As set out in section 10 (Clause 13). |
13. Annex II — Technical and organisational measures
- Encryption in transit — TLS for the dashboard, API, mobile app, administrative access and HTTPS stream delivery; secure WebSocket (WSS) for live ingest from the browser studio and app.
- Encryption at rest — databases, file storage and disks on Google Cloud are encrypted at rest by the platform.
- Pseudonymisation and minimisation — listener analytics store a keyed (HMAC) hash of IP address and user agent, never the raw IP address; location is reduced to city/region/country using a database on our own servers, with no call to an external service; edge logs holding IP addresses are kept only hours to days; passwords are stored as salted bcrypt hashes.
- Access control — least-privilege access to production systems for named staff only, via Google Cloud identity and access management; customer data accessed only to provide the Service or support; administrative sign-in-as-customer access is logged; each station has its own streaming credentials, which the Broadcaster can rotate.
- Tenant separation — every request is authorised against the account that owns the station; one customer cannot read another’s stations, files or analytics.
- Availability and resilience — managed database (Cloud SQL) with backups; monitoring and automatic restart of streaming engines; multiple delivery paths for streams.
- Logging and monitoring — application and security logs retained about 30 days; alerting on failures and anomalies.
- Secure development — automated tests run in continuous integration before every release; production secrets held in a managed secret store, not in code.
- Vendor management — subprocessors bound by written data protection terms; list published and changes notified (section 5).
- Incident response — investigation, containment and notification as in section 4.
- Data subject rights and deletion — self-service deletion of recordings, episodes, stations and accounts, and self-service data export, in the dashboard.
14. Annex III — Subprocessors
The subprocessors authorised under section 5 are listed, with their purpose, the personal data they receive and their location, at nobexradio.com/legal/subprocessors. Only the providers in section 1 of that page process Broadcaster Personal Data; the analytics and advertising partners in section 2 do not.
