1 — Application and roles
This Data Processing Addendum forms part of the agreement between Lainstack Ltd and a customer where that agreement or an order form incorporates it. It applies to personal data that Lainstack processes on the customer's behalf to provide the service (“Customer Personal Data”).
The customer is the controller and Lainstack is the processor. If the customer acts as a processor for another controller, Lainstack acts as its subprocessor. Each party will comply with the data protection law applicable to its role. The customer is responsible for the lawfulness of its instructions and its use of Customer Personal Data and has the rights set out in this Addendum.
2 — Processing details
- Subject and purpose: providing, securing, supporting, and maintaining the Lainstack service as configured by the customer.
- Operations: collecting, recording, organising, storing, retrieving, transmitting, adapting, and deleting Customer Personal Data as needed to provide the service.
- Duration: the term of the customer agreement and the period required to return or delete Customer Personal Data under section 8.
- Data subjects: customer users and personnel, and any other people whose information the customer submits to the service.
- Data: account and business contact information, authentication and access information, workflow inputs and outputs, files, records, communications, service logs, and any other categories described in the applicable order.
3 — Instructions
Lainstack will process Customer Personal Data only on the customer's documented instructions, including the customer agreement, service configuration, and written instructions consistent with that agreement. This also applies to international transfers. If law requires other processing, Lainstack will inform the customer before processing unless the law prohibits it.
Lainstack will immediately inform the customer if, in its opinion, an instruction infringes applicable data protection law.
4 — Confidentiality and security
Lainstack will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations. Lainstack will maintain technical and organisational measures appropriate to the risk and meeting the requirements of Article 32 UK GDPR or EU GDPR, as applicable.
5 — Subprocessors and transfers
The customer gives general written authorisation for Lainstack to use the subprocessors in the Subprocessor Register. Lainstack will notify the customer before appointing a new subprocessor and allow the customer to object on reasonable data protection grounds. Lainstack will impose data protection obligations providing an equivalent level of protection and remains responsible for each subprocessor's performance of those obligations.
Lainstack will use a lawful transfer mechanism where Customer Personal Data is transferred outside the UK or EEA and no applicable adequacy decision covers the transfer.
6 — Assistance and data subject requests
Taking into account the nature of the processing and the information available, Lainstack will assist with data subject requests and with the customer's obligations concerning security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
If Lainstack receives a request concerning Customer Personal Data, it will notify the customer and will not respond on the customer's behalf unless authorised or legally required to do so.
7 — Personal data breaches
Lainstack will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. It will provide the information reasonably available to help the customer meet its notification obligations and will provide further information as it becomes available.
8 — Return and deletion
At the end of the service, Lainstack will, at the customer's choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires retention. Data in protected backups will remain beyond ordinary use and be deleted through the applicable backup lifecycle.
9 — Information and audits
Lainstack will provide information necessary to demonstrate compliance with this Addendum and allow and contribute to audits and inspections by the customer or its appointed auditor. The parties will use reasonable notice, confidentiality safeguards, and arrangements that avoid unnecessary disruption without preventing the customer's audit rights.
10 — Agreement and contact
If this Addendum conflicts with the customer agreement on the protection of Customer Personal Data, this Addendum prevails. Other liability, governing-law, and termination terms remain as stated in the customer agreement.
DPA enquiries: [email protected]. Security incidents: [email protected].