1. Scope and roles
This DPA forms part of the agreement between you (the Customer / Controller) and LyEve Labs (the Processor) for the limited personal data we process on your behalf when you use the customer portal, issuance API, and supporting infrastructure. Data your end users put inside your self-hosted CMS instances stays on your infrastructure. We are not a processor for that content.
2. Subject matter and duration
We process Customer Personal Data for the duration of your subscription and any post-termination retention period required by law. Categories of data are listed in our Privacy Policy.
3. Processor obligations
- Process Customer Personal Data only on documented Customer instructions.
- Ensure personnel processing data are bound by confidentiality obligations.
- Implement appropriate technical and organizational measures (TLS, argon2id password hashing, Ed25519 license signing, encrypted backups, role-based access).
- Engage subprocessors only with prior general authorization and at least 14 days' notice (see subprocessors list).
- Assist Customer with data-subject requests, DPIAs, and breach notifications.
- Notify Customer of a personal-data breach without undue delay (within 72 hours of becoming aware).
4. International transfers
Where personal data is transferred outside the EEA / UK, the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor, dated June 4, 2021) and the UK Addendum are incorporated by reference into this DPA. The data exporter is the Customer. The data importer is LyEve Labs.
5. Audit and information rights
Customer may request, no more than once per year, at Customer's expense, written information demonstrating compliance with this DPA. Where the request goes beyond the information already published in the SOC 2 reports of our subprocessors, an independent third-party audit may be commissioned by mutual agreement.
6. Return and deletion
On termination of the subscription, Customer may request an export of account data by email to privacy@lyeve.com, and we send it as JSON within 30 days. We delete Customer Personal Data within 30 days unless retention is required by law (e.g. tax records).
7. Liability and order of precedence
Liability under this DPA is subject to the limitation of liability in the LyEve Terms of Service. In case of conflict, the SCCs prevail over this DPA, which prevails over the Terms.
8. Signature
This DPA is automatically incorporated into the LyEve Terms of Service for any Customer subject to GDPR or UK GDPR. Customers requiring a counter-signed copy can email legal@lyeve.com with their company details.