On this page
- Introduction
- Definitions
- Roles of the parties
- Processing on documented instructions
- Confidentiality of personnel
- Subprocessors
- Security
- Assistance to Customer
- Personal Data Breach notification
- Audits and information
- Return and deletion
- International transfers
- CCPA service provider terms
- Liability, term, and precedence
- Annex I: Details of processing
- Annex II: Security measures
1.IntroductionLink to section 1
This Data Processing Addendum (“DPA”) forms part of the agreement between LiteSurface, Inc. (“LiteSurface”) and the customer (“Customer”) for LiteSurface under our Terms of Service or another written agreement (the “Agreement”). It applies whenever LiteSurface processes Customer Personal Data on Customer’s behalf, and it takes effect automatically when Customer accepts the Agreement.
Countersigned copy
If your organization needs a signed copy for its records, write to legal@litesurface.com. We will send this DPA, with its Annexes and the Standard Contractual Clauses completed, for signature.
2.DefinitionsLink to section 2
- “Data Protection Laws”
- All laws that apply to the processing of Customer Personal Data under the Agreement, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the CPRA (“CCPA”), each as amended.
- “Customer Personal Data”
- Personal data within Customer Content, or otherwise processed by us on Customer’s behalf, in providing the Service.
- “Personal Data Breach”
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by us or our Subprocessors.
- “Subprocessor”
- A third party we engage to process Customer Personal Data on our behalf.
- “Standard Contractual Clauses”
- The clauses adopted by European Commission Implementing Decision (EU) 2021/914, and the UK International Data Transfer Addendum to them.
3.Roles of the partiesLink to section 3
3.1Controller and processorLink to clause 3.1
Customer is the controller of Customer Personal Data (or a processor acting for its own clients), and LiteSurface is its processor (or subprocessor). Under the CCPA, LiteSurface is Customer’s service provider.
3.2Data we controlLink to clause 3.2
LiteSurface is an independent controller of account, billing, security, and usage data it needs to run its business, as described in the Privacy Policy. This DPA does not apply to that data.
3.3Provider keys supplied by CustomerLink to clause 3.3
When Customer uses its own AI Provider or other third-party credentials, that provider processes the data sent with those credentials under Customer’s own agreement with it. It is not our Subprocessor, and we transmit data to it on Customer’s instructions.
4.Processing on documented instructionsLink to section 4
4.1Customer’s instructionsLink to clause 4.1
We process Customer Personal Data only on Customer’s documented instructions, unless the law requires otherwise (in which case we will tell Customer first, unless the law prohibits it). The Agreement, this DPA, and Customer’s configuration of the Service, including allowed AI Providers, sensitive field classifications, run modes, budgets, sharing, transfers, exports, and deletions, are Customer’s complete instructions.
4.2Unlawful instructionsLink to clause 4.2
We will promptly tell Customer if we believe an instruction infringes Data Protection Laws, and may suspend the affected processing until it is confirmed or changed.
4.3Customer’s responsibilitiesLink to clause 4.3
Customer is responsible for the lawfulness of the processing it instructs, including its legal basis, the notices it gives, the accuracy of the data, and its right to use the sources it adds. Customer will not submit special categories of personal data unless necessary, and will mark any such fields as not for models.
4.4No other useLink to clause 4.4
We will not use Customer Personal Data to train or fine-tune AI models, sell or share it, or use it for any purpose other than providing the Service.
5.Confidentiality of personnelLink to section 5
We limit access to Customer Personal Data to personnel who need it to provide, support, or secure the Service, and ensure they are bound by confidentiality obligations. Access to production systems is granted on a least-privilege basis.
6.SubprocessorsLink to section 6
6.1General authorizationLink to clause 6.1
Customer authorizes us to engage the Subprocessors listed on our Subprocessors page. We impose data protection terms on each Subprocessor that are at least as protective as this DPA, and remain responsible for their performance.
6.2Notice of changesLink to clause 6.2
We will give at least 30 days’ notice before a new Subprocessor processes Customer Personal Data, by updating the Subprocessors page and emailing workspace owners and anyone subscribed to updates. In an emergency, such as replacing a failed provider to keep the Service running, we may give shorter notice and will explain why.
6.3ObjectionsLink to clause 6.3
Customer may object on reasonable data protection grounds within 15 days of notice by writing to privacy@litesurface.com. We will work in good faith to address the objection, for example by offering a configuration that avoids the Subprocessor. If we cannot, Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused term.
7.SecurityLink to section 7
We implement and maintain the technical and organizational measures in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing. We may update these measures, provided the overall level of protection is not reduced.
8.Assistance to CustomerLink to section 8
8.1Data subject requestsLink to clause 8.1
The Service lets Customer find, correct, export, and delete Customer Personal Data. If we receive a request from an individual about Customer Personal Data, we will refer them to Customer and will not respond ourselves unless Customer asks us to or the law requires. We will provide reasonable additional help where Customer cannot fulfill a request using the Service.
8.2Assessments and authoritiesLink to clause 8.2
We will provide reasonable information to help Customer carry out data protection impact assessments and consult supervisory authorities where required, taking into account the information available to us.
9.Personal Data Breach notificationLink to section 9
9.1TimelineLink to clause 9.1
We will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach, by email to workspace owners.
9.2Content of the noticeLink to clause 9.2
To the extent known, the notice will describe the nature of the breach, the categories and approximate numbers of individuals and records concerned, the likely consequences, the measures taken or proposed, and a contact for more information. We will provide further information as it becomes available.
9.3ResponseLink to clause 9.3
We will take reasonable steps to contain and remedy the breach and to prevent a recurrence. Notifying Customer of a breach is not an admission of fault or liability.
10.Audits and informationLink to section 10
10.1InformationLink to clause 10.1
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including written answers to a reasonable security questionnaire no more than once a year. We do not currently hold third-party certifications; when independent audit reports become available, we may provide them to satisfy audit requests.
10.2AuditsLink to clause 10.2
If that information is insufficient, or a supervisory authority requires it, Customer (or an independent auditor bound by confidentiality) may audit our compliance once in any 12-month period, with at least 30 days’ notice, during business hours, and in a way that does not disrupt the Service or compromise other customers’ data. Customer bears its own costs. Audits after a Personal Data Breach are not limited to once a year.
11.Return and deletionLink to section 11
During the term, Customer can export and delete Customer Personal Data using the Service. After the Agreement ends, we will make Customer Personal Data available for export for 30 days and then delete it from our active systems within a further 30 days. Copies in backups are deleted as backups expire in the normal course and remain protected by this DPA until then. We may retain data where the law requires, subject to this DPA. On request, we will confirm deletion in writing.
12.International transfersLink to section 12
12.1Transfer mechanismLink to clause 12.1
Where Customer Personal Data subject to the EU GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. Annexes I and II of this DPA complete the Clauses’ Annexes, and the list of Subprocessors completes Annex III.
12.2ElectionsLink to clause 12.2
For the Clauses: the optional docking clause (Clause 7) applies; Clause 9 Option 2 (general authorization) applies with the notice period in Section 6; the optional language in Clause 11 does not apply; and for Clauses 17 and 18 the parties choose the law and courts of Ireland. The supervisory authority is the one determined under Clause 13.
12.3UK and SwitzerlandLink to clause 12.3
For UK transfers, the UK International Data Transfer Addendum applies, with its tables completed by the information in this DPA. For Swiss transfers, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
12.4Onward transfersLink to clause 12.4
We will make onward transfers to Subprocessors only under an appropriate transfer mechanism, and will provide reasonable information to support Customer’s transfer impact assessment.
13.CCPA service provider termsLink to section 13
We will not sell or share Customer Personal Data; retain, use, or disclose it outside our direct business relationship with Customer or for any purpose other than the business purposes in the Agreement; or combine it with personal data from other sources except as the CCPA permits. We will comply with the CCPA, give the same level of privacy protection it requires, and tell Customer if we can no longer meet these obligations. Customer may take reasonable steps to stop and remediate unauthorized use.
14.Liability, term, and precedenceLink to section 14
Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws or the Standard Contractual Clauses do not allow it. This DPA lasts as long as we process Customer Personal Data. If this DPA conflicts with the Agreement, this DPA prevails for the processing of Customer Personal Data; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.
15.Annex I: Details of processingLink to section 15
| Item | Description |
|---|---|
| Parties | Data exporter: Customer. Data importer: LiteSurface, Inc., [Registered address to be confirmed]. Contact: privacy@litesurface.com. |
| Subject matter and duration | Providing the Service for the term of the Agreement plus the post-termination export and deletion periods. |
| Nature of processing | Hosting and storage; retrieval of web pages at Customer’s direction; extraction, embedding, and search; analysis and generation by AI models; scoring; export; email delivery; support; and deletion. |
| Purpose | To provide, secure, and support the Service in accordance with the Agreement and Customer’s instructions. |
| Categories of data subjects | Customer’s Authorized Users; people named in Customer Content, such as interviewees, customers, prospects, and colleagues; and authors or subjects of sources Customer adds. |
| Categories of personal data | Names and contact details; professional details such as role and organization; content of notes, documents, and sources; and usage records linked to Authorized Users. |
| Special categories | None intended. Customer should not submit them unless necessary, and should mark such fields as not for models. |
| Frequency | Continuous, for as long as the Service is used. |
| Retention | As set by Customer through the Service, and as described in Section 11 and the Privacy Policy. |
| Subprocessors | As listed on the Subprocessors page, for the purposes described there. |
16.Annex II: Security measuresLink to section 16
- Tenant isolation. Every tenant-owned record carries a workspace and project identifier; every data access is scoped and authorized on the server; automated tests attempt cross-workspace and cross-project access; object storage paths are prefixed by project.
- Access control. Role-based permissions (owner, admin, member, viewer); HttpOnly, Secure session cookies with SameSite protection and trusted-origin checks; hashed passwords; rate limiting on authentication and API endpoints.
- Encryption. TLS for data in transit; encryption at rest provided by our database and storage providers.
- Secrets. Provider keys and other credentials kept in a secrets manager or encrypted form, never in plain text in application tables, never sent to browsers, and redacted from logs.
- AI data minimization. Only task-required fields are sent to AI Providers; workspace policy limits allowed providers; fields classified as not for models are removed before prompt assembly; raw prompts and responses are not logged by default.
- Untrusted content handling. Retrieved content is treated as data, not instructions; model tools are allowlisted per task and authorized by code; the fetcher blocks private, link-local, and metadata addresses, revalidates redirects, and enforces size and time limits.
- Application security. Sanitized rendering of model and source content; security headers, including a Content Security Policy; pinned dependency lockfiles.
- Exports. Random object keys, short-lived signed or authenticated download links, and expiry after seven days unless pinned.
- Logging and audit. Append-only audit events for significant actions; application logs kept for 30 days.
- Resilience. Daily database backups with point-in-time recovery where offered, regular restore testing, and documented recovery objectives.
- Deletion. Asynchronous purge across database, object storage, and derived data, with a deletion record that contains no content.
- Personnel. Confidentiality obligations, least-privilege production access, and separate service credentials; no shared personal tokens in production.
Questions about this document
Write to legal@litesurface.com for legal questions or privacy@litesurface.com for privacy requests. Postal notices go to LiteSurface, Inc., [Registered address to be confirmed].