June 19, 2026
This Data Processing Agreement (“DPA”) forms part of the contract between your association (“Controller”) and NexClass Luxembourg S.à r.l. (“Processor”) when you register for or use Nexpense. It reflects Article 28 GDPR. This template should be reviewed by your legal counsel.
1. Parties and roles
Controller: the association that registers for Nexpense and determines the purposes and means of processing personal data about its members, staff, and operations.
Processor: NexClass Luxembourg S.à r.l., 19 Rue de l'église, L-7421 Cruchten, Luxembourg. Email: contact@nexclass.lu.
2. Subject matter and duration
Processor provides the Nexpense cloud platform so Controller can manage members, accounting, communications, calendars, and related workflows. Processing continues for the duration of the subscription and until Controller data is deleted or returned as described below.
3. Nature and purpose of processing
Hosting, storage, backup, retrieval, organisation, disclosure by transmission (including email broadcasts initiated by Controller), and deletion of personal data entered by Controller or its users into Nexpense.
4. Types of personal data and data subjects
Depending on Controller’s use of Nexpense:
- Data subjects: association staff, members, and other individuals whose data Controller enters.
- Categories: identification and contact data, membership status, profile fields, accounting and receipt data, calendar and event data, broadcast message content, and authentication metadata.
5. Controller obligations
Controller shall ensure a lawful basis under GDPR for all personal data it processes via Nexpense, provide required notices to data subjects (including broadcast recipients), honour data-subject requests for data Controller controls, and instruct Processor only through documented use of the service or written requests to contact@nexclass.lu.
6. Processor obligations
Processor shall process personal data only on documented instructions from Controller, ensure confidentiality of personnel with access, implement appropriate technical and organisational measures (including isolation between associations and encryption in transit), assist Controller with data-subject requests and security obligations where feasible, delete or return Controller data upon termination subject to legal retention, and make available information necessary to demonstrate compliance.
7. Subprocessors
Controller authorises Processor to engage subprocessors listed below. Processor shall impose data-protection obligations on subprocessors equivalent to this DPA. Processor will inform Controller of intended changes to subprocessors and allow objection on reasonable grounds.
- Supabase, Inc. — database and file storage (EU region).
- Vercel, Inc. — application hosting and privacy-friendly analytics.
- Resend, Inc. — email delivery for verification, password reset, staff invitations, and member broadcasts.
- NexClass Luxembourg S.à r.l. — NexClass Forms (forms.nexclass.lu) for marketing contact inquiries on the public website.
8. International transfers
Primary processing occurs in the European Economic Area. Where subprocessors process data outside the EEA, Processor relies on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, supplemented by technical measures where appropriate.
9. Security and breaches
Processor maintains security measures described in its privacy policy and infrastructure documentation. Processor shall notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data and provide information reasonably required for Controller to meet its breach-notification obligations.
10. Deletion and return
Controller may delete its association and all association data through product functionality (Settings → General → Delete association). Upon deletion, Processor shall remove Controller data from active systems within a reasonable period; backup copies may persist for a limited time per Processor retention practices.
11. Liability and governing law
Liability is governed by the Terms of service unless mandatory law provides otherwise. This DPA is governed by the laws of Luxembourg. Courts in Luxembourg City have jurisdiction, subject to mandatory protections.
12. Contact
Processor contact for DPA matters: contact@nexclass.lu or +352 621 218 284.