Data Processing Agreement (DPA)
This page is provided for convenience and may be updated over time.
Data Processing Agreement
Effective date: Aug 10, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Lingonberry Island Ltd. (Business ID FI2912630-1, Finland) ("Company" or "Processor") and the Customer using the Service. It applies only to the extent Company processes Customer Personal Data on behalf of Customer.
This DPA is intended to satisfy Article 28 of the EU General Data Protection Regulation ("GDPR"). It does not replace any Standard Contractual Clauses needed for a restricted international transfer.
1. Parties and roles
Customer is the controller of Customer Personal Data or, where Customer processes that data for another controller, a processor authorized to appoint Company as a subprocessor. Company is Customer's processor for the processing described in Annex 1.
Each party must comply with the data-protection law applicable to its role. Nothing in the agreement changes a party's statutory role where the facts or law require a different classification.
Company acts as an independent controller, not as Customer's processor, for processing whose purposes and essential means Company determines itself. This includes business-account administration, fraud and security management, billing and legal compliance, and the public-source Company Database described in the Privacy Notice. Customer Proprietary Data, Customer Modifications, and Tool Outputs are excluded from that Company Database.
2. Definitions
- Applicable Data Protection Law means the GDPR, the Finnish Data Protection Act, and other data-protection law applicable to the processing under this DPA.
- Customer Personal Data means personal data contained in Customer Proprietary Data, Customer Modifications, or Tool Outputs that Company processes on Customer's behalf through the Service. It excludes personal data for which Company acts as an independent controller.
- Security Incident means a personal data breach affecting Customer Personal Data.
- Subprocessor means a processor engaged by Company to process Customer Personal Data.
The terms controller, data subject, personal data, personal data breach, processing, processor, and supervisory authority have the meanings in the GDPR. Other capitalized terms have the meanings in the Terms of Service.
3. Scope, subject matter, and duration
Company processes Customer Personal Data to provide, secure, maintain, troubleshoot, and support the Service and to carry out Customer's documented instructions. The subject matter, nature, purposes, personal-data types, and data subjects are described in Annex 1.
This DPA begins when Company first processes Customer Personal Data and continues until that data has been returned or deleted in accordance with Section 11.
4. Customer instructions
Company will process Customer Personal Data only:
- on Customer's documented instructions, including the agreement, Customer's use and configuration of the Service, and additional written instructions accepted by Company;
- as necessary to comply with applicable EU or Member State law, in which case Company will inform Customer of the legal requirement before processing unless that law prohibits notice on important grounds of public interest; or
- as otherwise required by binding law.
Customer instructs Company to process Customer Personal Data in order to provide the Service and to transfer it to the countries and Subprocessors identified in the Subprocessor List, subject to Sections 8 and 9.
Company will promptly inform Customer if, in Company's opinion, an instruction infringes Applicable Data Protection Law. Company may suspend the affected processing while the parties address the issue. Company is not required to perform an instruction that is unlawful, technically incompatible with the Service, or outside the agreed scope without a written change agreement.
Company will not sell Customer Personal Data, use it for targeted advertising, or use Customer Proprietary Data, Customer Modifications, or Tool Outputs to populate the Company Database or another Customer's Workspace.
5. Customer obligations
Customer is responsible for:
- ensuring its instructions and processing comply with Applicable Data Protection Law;
- having a lawful basis and providing required notices for Customer Personal Data;
- responding to data subjects and regulators as controller;
- configuring the Service, access permissions, retention, and integrations appropriately;
- limiting Customer Personal Data to what is necessary for the permitted purpose;
- ensuring that any controller for which Customer acts has authorized Company and its Subprocessors; and
- not submitting special categories of personal data, criminal-conviction data, government identifiers, payment-card data, health data, or other highly sensitive data unless the parties have agreed in writing on the scope and safeguards.
Customer represents that it has all rights and authorizations needed for Company to process Customer Personal Data under this DPA.
6. Confidentiality and personnel
Company will ensure that personnel authorized to process Customer Personal Data:
- access it only as necessary for their duties;
- are bound by contractual or statutory confidentiality obligations; and
- receive appropriate privacy and security guidance for their role.
The confidentiality obligations continue after personnel access ends.
7. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing and risks to individuals, Company will implement and maintain appropriate technical and organizational measures under Article 32 GDPR.
The current measures are described in Annex 2 and the Security and TOMs Overview. Company may update the measures to reflect technical and operational developments, provided the overall level of protection does not materially decrease during a subscription term.
Customer acknowledges that no system is completely secure and is responsible for using available security features, managing its Users, and protecting its own devices and credentials.
8. Subprocessors
Customer gives Company general written authorization to use the Subprocessors in the Subprocessor List. Company will:
- conduct appropriate data-protection and security diligence before engagement;
- enter into a written agreement requiring data-protection obligations that are no less protective in substance than those required by Article 28 GDPR;
- restrict each Subprocessor to the processing needed for its services; and
- remain responsible to Customer for the Subprocessor's performance of its processor obligations, subject to the agreement and Applicable Data Protection Law.
Company will notify Customer's account-administrator email at least 15 days before authorizing a new Subprocessor to process Customer Personal Data, where practicable. Advance notice may be shorter where an urgent security, legal, or service-continuity need requires it; Company will then notify Customer as soon as practicable.
Customer may object during the notice period on reasonable, documented grounds relating to protection of Customer Personal Data. The parties will work in good faith to address the objection, including a commercially reasonable configuration or alternative where available. If Company cannot reasonably resolve the objection, Customer may terminate the affected Service before the new Subprocessor begins processing and receive a pro-rata refund of prepaid fees for the unused affected period. This is Customer's sole contractual remedy for an unresolved Subprocessor objection, without limiting mandatory rights.
9. International transfers
Company will not transfer Customer Personal Data outside the EEA in violation of Applicable Data Protection Law. Where a transfer requires safeguards under Chapter V GDPR, Company will use an applicable mechanism, such as:
- an adequacy decision;
- the European Commission's then-current Standard Contractual Clauses ("SCCs"); or
- another lawful transfer mechanism.
Where SCCs are required directly between Customer and Company, the controller-to- processor module applies if Customer is a controller and the processor-to- processor module applies if Customer is a processor. The optional docking clause applies; the competent supervisory authority and governing law are determined under the SCCs using Finland where the clauses permit that selection. The SCCs prevail over conflicting commercial terms for the restricted transfer.
Company will implement supplementary measures where required and, on reasonable request, provide information needed for Customer's transfer assessment, subject to confidentiality, security, and third-party restrictions.
10. Data-subject requests and compliance assistance
Taking into account the nature of processing, Company will provide reasonable assistance through appropriate technical and organizational measures so Customer can respond to requests to exercise data-subject rights.
If Company receives a request concerning Customer Personal Data directly from a data subject, Company will, where legally permitted:
- direct the person to Customer or promptly notify Customer;
- not respond substantively without Customer's instruction; and
- comply with a binding legal requirement to respond.
Taking into account the nature of processing and information available to Company, Company will also reasonably assist Customer with:
- security of processing under Article 32 GDPR;
- Security Incident assessment and notifications under Articles 33 and 34;
- data-protection impact assessments under Article 35; and
- prior consultation with a supervisory authority under Article 36.
Assistance that requires material work outside standard Service functionality may be charged at agreed reasonable rates, unless the work is required because of Company's breach.
11. Return and deletion
At the end of the Service, Customer may use available export features or request reasonable assistance to return Customer Personal Data during the 30-day export window. At Customer's choice, Company will delete or return Customer Personal Data and delete remaining copies, unless EU or Member State law requires retention.
Unless Customer gives a different lawful instruction, Company will begin deletion after the export window and complete deletion from active systems within 90 days after termination. Customer Personal Data may remain in access-restricted backups until those backups expire or are overwritten under the applicable backup schedule. If a backup is restored, the original deletion requirement will be reapplied.
Company may retain minimal records necessary to demonstrate compliance, resolve disputes, or comply with law, subject to access restrictions and applicable retention limits. Data processed by Company as an independent controller is not governed by this Section.
On request, Company will provide reasonable confirmation of completion of the required deletion.
12. Security Incidents
Company will notify Customer without undue delay after becoming aware of a Security Incident. The notice will include, as information becomes available:
- the nature of the incident and categories and approximate number of affected data subjects and records;
- likely consequences;
- measures taken or proposed to address and mitigate it; and
- a contact point for follow-up.
Company may provide information in phases and will reasonably cooperate with Customer's investigation and legally required notifications. Notice is not an admission of fault or liability.
Customer is responsible for notifying regulators and data subjects unless law requires Company to do so. Customer must notify Company promptly of any incident caused by Customer, its Users, or systems under its control that may affect the Service.
13. Information, audits, and regulators
Company will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Customer should first use current security, privacy, certification, and independent-audit documentation made available by Company or its providers.
If that information is reasonably insufficient, Customer may conduct one audit in any 12-month period on at least 30 days' written notice. Additional audits are permitted following a material Security Incident affecting Customer Personal Data or where a supervisory authority requires one. Audits must:
- occur during normal business hours and minimize disruption;
- be limited to systems and processing relevant to Customer Personal Data;
- be conducted by qualified personnel who are not a Company competitor and are bound by confidentiality;
- not expose another customer's data or compromise security; and
- comply with reasonable safety and access procedures.
Customer bears its audit costs and Company's reasonable costs for extraordinary assistance, unless the audit identifies a material breach by Company. Company will cooperate with a competent supervisory authority as required by law.
14. Records and compliance
Company will maintain records of processing required of a processor under Article 30(2) GDPR and make them available to the competent supervisory authority as required. Each party will provide the other with reasonable information needed to demonstrate its own compliance, subject to legal privilege, confidentiality, security, and third-party rights.
15. Liability and priority
Liability arising under this DPA is subject to the Terms of Service, except to the extent Applicable Data Protection Law or the SCCs prohibit a contractual limitation.
If this DPA conflicts with the Terms on processing of Customer Personal Data, this DPA controls. If the SCCs apply and conflict with this DPA, the SCCs control for the restricted transfer.
Annex 1: Details of processing
A. Subject matter and purpose
Provision, authentication, hosting, storage, organization, retrieval, display, analysis, generation, collaboration, export, security, maintenance, troubleshooting, support, and deletion of Customer Personal Data within the Service on Customer's behalf.
B. Duration
The subscription term plus the export, deletion, backup, and legally required retention periods described in Section 11.
C. Nature of processing
Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission to authorized Subprocessors, combination within the Customer's Workspace, restriction, export, and deletion. AI and embedding features involve transmission of selected text and metadata to OpenAI for inference and return of results.
D. Categories of data subjects
- Customer's Users, employees, contractors, representatives, and invited members;
- Customer's business contacts, prospects, customers, partners, and suppliers;
- persons mentioned in Customer-provided internal sources, notes, interview answers, chat, or other Workspace content; and
- other individuals whose personal data Customer lawfully submits to the Service.
E. Types of Customer Personal Data
- identity and professional data, such as name, work contact details, organization, role, and professional biography;
- Workspace content, such as notes, tags, labels, selections, configurations, private prompts, interview answers, chat messages, and uploaded or pasted internal source material;
- Tool Outputs and structured analyses linked to identifiable persons;
- integration identifiers and content where Customer enables an integration;
- source URLs, excerpts, and provenance included in Customer Proprietary Data;
- authentication, authorization, audit, device, and usage data processed on Customer's behalf; and
- support material Customer submits concerning its Workspace.
The Service is not intended for special categories of personal data, criminal-conviction data, government identifiers, payment-card data, health data, or children's data.
F. Processing frequency
Continuous or as initiated by Customer and its Users during the subscription, with background maintenance, security, backup, and deletion processing as needed.
Annex 2: Technical and organizational measures
Company's current measures include:
- Identity and access: Firebase Authentication, verified tokens, role-based authorization, Workspace-scoped access, individual User accounts, and superadmin restrictions.
- Tenant isolation: Workspace identifiers on tenant data access, guarded internal reuse paths, and sanitization of cross-workspace public baseline artifacts to remove Customer-specific provenance and manual modifications.
- Network security: TLS for external traffic, Nginx reverse proxy controls, host firewalling, rate limits, a backend bound behind the proxy, and a PostgreSQL service on a private container network without a public database port.
- Secrets and credentials: environment- or file-based production secrets with restricted host permissions; service-account material kept outside source control.
- Application controls: input validation, request-size limits, SSRF defenses for URL retrieval, webhook-signature verification where billing is enabled, and guarded administrative routes.
- Logging and monitoring: security-relevant audit events, operational logs, metrics where enabled, and incident investigation procedures. Logs are designed to avoid unnecessary Customer Content.
- Availability and recovery: database health checks, documented deployment and rollback procedures, container restart policies, and backup/restore procedures maintained for the production environment.
- Data lifecycle: Workspace deletion procedures, intake and job-retention controls, access-restricted backup expiry, and cross-workspace privacy preflight checks before reusable baseline data is enabled.
- Personnel and operations: least privilege, confidentiality obligations, controlled production access, change review, and documented security and incident processes.
Encryption at rest and backup encryption depend on the configured hosting and backup layer. Company will not represent them as enabled unless the applicable production configuration has been verified.