Legal · Data processing

Nebbos is infrastructure, not a data processor.

Customer data lives on the customer's Cradle, mediated by the customer's MCP, encrypted with keys derived from the customer's biometric. Nebbos never accesses it. The narrow processing that does happen — platform-account login, session cookies, product-usage analytics — is governed by the Privacy Policy at /legal/privacy.

Scope

What Nebbos DOES process (the narrow scope).

Platform account metadata: work email, organization name, session cookies. Product-usage analytics: pages viewed on nebbos.ai, form submissions on /demo and /contact. Support-request metadata: subject + timestamp of emails you send to Nebbos inboxes. Payment metadata (when a self-serve tier lands): billing name + address, card last-four, receipt records. This scope is disclosed in full at /legal/privacy.

What Nebbos does NOT process.

Your Pearl memory. Your operator's tool-call payloads. Your department data (finance rows, care coordination notes, ops handoffs, HR records). Your credentials. Your Cradle contents. Your operator biometric templates. All of it lives on your side — Cradle, host machine, self-hosted MCP, or your own workspace on the Managed platform where per-workspace encryption keys are held on the customer's Cradle. None of it crosses to Nebbos infrastructure.

The right legal instrument is the license, not a DPA.

Enterprise engagements sign a Master Services Agreement (MSA) and Software License Agreement (SLA) — those govern the vendor-customer relationship for infrastructure Nebbos provides. Hardware ships under a Purchase Agreement + warranty. If your legal team requires a data-processing addendum specifically for the narrow platform-metadata scope above (some procurement flows do), Nebbos will counter-sign a Standard Contractual Clauses (SCC)-based Addendum covering that scope. Request via legal@nebbos.ai.
Data processing · Nebbos is infrastructure, not a processor — Nebbos