Data Processing Agreement (DPA)
Effective date: 4 August 2026
1. Parties and status
This DPA forms part of the agreement for the Lemric service. The Customer is the controller of personal data submitted through its organisation and the Lemric entity identified in the order or invoice is the processor. Where the Customer acts as a processor for another controller, Lemric acts as a subprocessor.
For conflicts concerning data protection, this DPA prevails, followed by the order and then the Service Terms.
2. Subject matter, duration and purpose
Lemric processes data for the service term and for limited export, backup-retention and legal-obligation periods after termination. Processing includes receiving, storing, organising, displaying, retrieving, transmitting, securing, backing up, deleting and other operations needed to provide the service desk, help centre, integrations and support.
The purpose is to provide and secure the functionality ordered by the Customer under documented instructions contained in the agreement and organisation settings.
3. Data subjects and data categories
Data subjects may include employees, contractors, agents, administrators, customers, requesters, request participants and other people identified in content submitted by the Customer.
Data may include identity and contact details, account and permission data, request and attachment content, communication history, technical metadata, audit data and other fields configured by the Customer. The Customer should not submit special-category or criminal-conviction data unless separately agreed.
4. Customer instructions
Lemric processes data only on documented Customer instructions unless law requires otherwise. Where permitted, Lemric informs the Customer before legally required processing. If Lemric believes an instruction infringes data-protection law, it informs the Customer and may suspend that instruction while it is clarified.
The Customer is responsible for lawful instructions, legal bases, transparency notices and configuring the appropriate data scope.
5. Confidentiality and access
Access is limited to authorised people bound by confidentiality and trained for their role. Access follows least privilege, is reviewed periodically and is revoked when no longer needed.
6. Security measures
Lemric maintains safeguards appropriate to risk, including logical tenant isolation and enforced tenant_id database context, encryption in transit, encryption of personal data covered by the data-protection model, access control and MFA for privileged operations, protected backups, operation logging, monitoring, vulnerability management, abuse limits, continuity arrangements and incident-response procedures.
Technical details may change provided the overall level of protection is not reduced.
7. Subprocessing
The Customer gives general authorisation for subprocessors needed to provide the service. Lemric makes the current list available and gives notice of planned changes, allowing a reasonable period for a substantiated data-protection objection.
Lemric imposes data-protection obligations no less protective than the relevant DPA obligations and remains responsible for subprocessors as required by law.
8. International transfers
A transfer outside the EEA takes place only under a GDPR-compliant mechanism. Where Standard Contractual Clauses apply, the parties treat them as incorporated to the extent identified in the order or subprocessor list, together with transfer assessments and supplementary measures where needed.
9. Individual rights and compliance assistance
Taking account of the processing, Lemric assists the Customer with individual rights, impact assessments, authority consultations, security duties and demonstrating compliance. If Lemric receives a request concerning Customer-controlled data, it forwards the request and does not respond substantively without Customer instructions unless required by law.
10. Personal data breaches
Lemric notifies the Customer of a confirmed breach affecting entrusted data without undue delay after becoming aware of it. The notice includes available information needed to assess notification duties. Lemric takes steps to contain the incident and provides updates as the investigation progresses.
11. Return, deletion and retention
After the service ends, according to the Customer’s selection and configuration, data is made available for export and then deleted or anonymised unless law requires continued retention. Backups are deleted through the ordinary retention cycle and remain protected until overwritten.
12. Information and audits
Lemric provides information reasonably needed to demonstrate compliance, primarily through documentation, reports and security responses. If that is insufficient, the Customer may audit no more than once per year after agreeing scope and timing, subject to confidentiality, other-customer security and service continuity. The frequency limit does not apply after a confirmed incident or regulatory request.
13. Contact
DPA matters may be sent to privacy@lemric.io. Party details, subscription scope and any additional instructions are set out in the order and organisation configuration.