Data Processing Agreement
Last updated 8 September 2026
This Data Processing Agreement ("DPA") is a template and is subject to legal review before it is offered to customers.
This DPA forms part of the Terms of Service between Letzscale S.à r.l. - S. ("Letzscale", "Processor") and the customer ("Customer", "Controller"). It applies where Letzscale processes personal data contained in Customer Data on the Customer's behalf in connection with the Services. If the Customer is itself a processor, it enters into this DPA as agent for and on behalf of its own controller.
1. Definitions
"Data Protection Law" means Regulation (EU) 2016/679 (GDPR), the Luxembourg Law of 1 August 2018 on the organisation of the National Commission for Data Protection and the general data protection framework, and, where it applies to the processing, the UK GDPR and the UK Data Protection Act 2018.
"Personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the GDPR. "Standard Contractual Clauses" means the clauses annexed to Commission Implementing Decision (EU) 2021/914.
"Sub-processor" means any third party engaged by Letzscale to process personal data on the Customer's behalf. The Annexes referred to below form part of this DPA.
2. Roles and scope
As between the parties, the Customer is the controller and Letzscale is the processor for personal data within Customer Data. Letzscale acts as controller only for the limited account, billing, and security data described in the Privacy Policy, and this DPA does not apply to that processing. Read the Privacy Policy
The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.
3. Processing on instructions
Letzscale processes personal data only on the Customer's documented instructions, including the instructions given through the Terms, this DPA, and the Customer's configuration and use of the Services, unless required to act otherwise by a law to which Letzscale is subject, in which case it informs the Customer of that legal requirement before processing, unless the law prohibits it.
Letzscale informs the Customer if, in its opinion, an instruction infringes Data Protection Law. Letzscale is not obliged to provide legal advice or to carry out a legal assessment of the Customer's instructions.
4. Confidentiality
Letzscale ensures that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality and are made aware of the confidential nature of the data.
5. Security
Letzscale implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Those measures are described in Annex II. [PLACEHOLDER: complete Annex II.]
6. Sub-processors
The Customer gives a general authorisation for Letzscale to engage the sub-processors listed on the subprocessor page. Letzscale imposes on each sub-processor, by written contract, data protection obligations that are equivalent to those in this DPA, and remains fully liable to the Customer for the sub-processor's performance. See the current subprocessor list
Letzscale gives the Customer at least [PLACEHOLDER: 30] days' notice of any intended addition or replacement of a sub-processor by [PLACEHOLDER: notification mechanism]. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Services and receive a refund of prepaid fees for the unused term.
7. Assistance to the Customer
Taking into account the nature of the processing, Letzscale assists the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
Taking into account the nature of the processing and the information available to Letzscale, Letzscale assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with a supervisory authority.
If Letzscale receives a request or complaint directly from a data subject that relates to Customer Data, it forwards the request to the Customer without undue delay and does not respond to it except on the Customer's documented instruction or as required by law.
8. Personal data breach
Letzscale notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and provides the information reasonably available to it to help the Customer meet its own notification obligations. Letzscale's notification is not an acknowledgement of fault or liability.
9. Return or deletion of personal data
On termination or expiry of the Services, at the Customer's choice, Letzscale deletes or returns all personal data within Customer Data and deletes existing copies within [PLACEHOLDER: 90] days, unless Data Protection Law or another law to which Letzscale is subject requires storage of the personal data, in which case Letzscale isolates and protects it and processes it no further.
10. Audit
Letzscale makes available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits take place on at least [PLACEHOLDER: 30] days' written notice, during business hours, subject to confidentiality obligations, not more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, and [PLACEHOLDER: state how audit costs are allocated]. Letzscale may satisfy an audit request by providing a current third-party audit report or certification where one is available.
11. International transfers
Letzscale does not transfer personal data within Customer Data to a country outside the European Economic Area, or to an international organisation, except in compliance with Data Protection Law. Customer Data is hosted and processed in the European Union, in the Frankfurt, Germany region (eu-central-1). Where such a transfer takes place and is not covered by an adequacy decision, the Standard Contractual Clauses apply and are incorporated into this DPA by reference, with Letzscale or the relevant sub-processor as data importer and the Customer as data exporter, together with any supplementary measures required. Module Three (processor to processor) applies to onward transfers to a sub-processor. [PLACEHOLDER: confirm with counsel whether the UK International Data Transfer Addendum is needed; it depends on whether Letzscale serves UK-established customers.]
12. Liability, term, and governing law
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms. This DPA takes effect when the Terms take effect and continues for as long as Letzscale processes personal data on the Customer's behalf. This DPA is governed by the law of the Grand Duchy of Luxembourg, except where the Standard Contractual Clauses require the law of another EEA member state. [PLACEHOLDER: confirm the governing law of the Standard Contractual Clauses.] If any provision of this DPA conflicts with the Terms, this DPA prevails in respect of the processing of personal data. Read the Terms of Service
13. Annexes
Annex I: Details of the processing
- Data exporter
- The Customer identified in the Terms, acting as controller (or as processor on behalf of its own controller).
- Data importer
- Letzscale S.à r.l. - S., providing the Services as processor.
- Subject matter
- Processing of personal data contained in supplier contracts and related documents that the Customer uploads, and in the DORA information register entries derived from them, in order to provide the Services.
- Duration
- For the term of the Customer's use of the Services and until deletion or return of the personal data in accordance with this DPA.
- Nature and purpose
- Storage, retrieval, comparison against a defined set of register fields, generation of a gap analysis and an export file, and related support and security operations.
- Types of personal data
- Business contact details and identifiers that appear in supplier contracts and register entries, such as names, job titles, email addresses, telephone numbers, and signature details of signatories, account managers, and other named individuals. [PLACEHOLDER: confirm whether any special categories of personal data are expected; if so, list them and the applicable safeguards.]
- Categories of data subjects
- Personnel and representatives of the Customer, and personnel and representatives of the Customer's suppliers and other counterparties named in the uploaded documents.
- Frequency of the transfer
- Continuous, for as long as the Customer uses the Services.
- Retention
- As set out in the Privacy Policy and section 9 of this DPA. [PLACEHOLDER: confirm retention periods.]
Annex II: Technical and organisational measures
[PLACEHOLDER: complete this Annex with the measures Letzscale actually operates. It should cover, at least: access control and least-privilege access; authentication; encryption of personal data in transit and at rest; network and application security; logging and monitoring; backup and restoration; pseudonymisation or minimisation where applicable; staff confidentiality and training; secure development practices; incident detection and response; physical and environmental security of the hosting environment; and vendor management.]
Annex III: Sub-processors
The authorised sub-processors are those listed on the subprocessor page, as updated from time to time in accordance with section 6. See the current subprocessor list