How Nexivol processes client personal and financial data when acting as a data processor on your behalf.
When Nexivol files tax returns, registers companies, or handles financial data on behalf of clients, we act as a Data Processor processing data on the client's instructions. This Data Processing Agreement (DPA) describes our obligations as a processor and is incorporated into our Terms of Service.
We process your data:
We currently do not use sub-processors who have access to client personal data. All work is performed by Nexivol personnel directly. If this changes, we will notify affected clients before engaging any sub-processor.
In the event of a personal data breach affecting your data, we will notify you within 72 hours of becoming aware of the breach, including the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed.
Upon termination of an engagement, we will — at your choice — return all client personal data in our possession or certify its deletion, within 30 days of your written request, subject to any retention obligations imposed by applicable tax or corporate law.
You have the right to audit our data processing practices with reasonable written notice. We will provide documentation of our security measures and processing activities upon request.
This DPA is designed to meet the requirements of Pakistan's data protection principles, UAE PDPL (Federal Decree-Law No. 45 of 2021), and UK GDPR Article 28 (processor obligations). Where you are subject to EU GDPR, the same obligations apply under Article 28.
Questions about this document:
Email: info@nexivol.com
WhatsApp: +92 333 104 4500
Registered Office: Blue Area, Islamabad, Pakistan
Operating Address: Dubai, United Arab Emirates