Documentation Legal Center Account & Service Terms TenthLoop Data Processing Agreement

Data Processing Agreement

Effective Date: [DATE] · Last Revised: [DATE] · Entity: Leovoid Technologies, Inc. (Delaware) · Platform: TenthLoop

1. INTRODUCTION; RELATIONSHIP TO OTHER DOCUMENTS

This Data Processing Agreement (the “DPA”) is entered into between Leovoid Technologies, Inc., a Delaware corporation (“Leovoid,” “Processor,” “we,” “us,” or “our”) and the individual or entity that holds a Leovoid Account (“Customer,” “Controller,” “you,” or “your”), and forms part of, and is incorporated by reference into, the Master Account Terms. This DPA applies to the extent Leovoid processes Personal Data on Customer’s behalf in the course of providing the Site, a Product, a Solution, or a tool made available through the Marketplace, and reflects the parties’ agreement with respect to the requirements of applicable Data Protection Laws, including the GDPR, the UK GDPR, and other Data Protection Laws that impose obligations on a processor acting on a controller’s behalf.

Capitalized terms not defined in this DPA have the meaning given in the Master Account Terms or the Privacy Policy. In the event of a conflict between this DPA and the Master Account Terms with respect to the processing of Personal Data, this DPA controls; in all other respects, the order of precedence set out in the Master Account Terms applies.

2. DEFINITIONS

“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given in the GDPR, and, where applicable, the corresponding meanings given in the UK GDPR or other applicable Data Protection Laws.

“Sub-processor” means a third party Leovoid engages directly to process Personal Data on Customer’s behalf in connection with the Site, a Product, or a Solution.

“Data Subprocessors Page” means the page published on the Site listing Leovoid’s current Sub-processors, as referenced in the Master Account Terms.

“Security Annex” means Annex 2 to this DPA, describing the technical and organizational measures Leovoid maintains.

3. SCOPE AND ROLES

3.1 Roles of the Parties. With respect to Personal Data contained within Customer Data, Customer is the Controller (or, where Customer processes Personal Data on behalf of its own customers or clients, a processor acting on that party’s behalf, in which case Leovoid acts as a sub-processor with respect to that Personal Data), and Leovoid is the Processor. Each party will comply with the obligations applicable to its role under Data Protection Laws.

3.2 Details of Processing. The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Subjects are described in Annex 1 to this DPA.

3.3 Customer Instructions. Leovoid will process Personal Data only on Customer’s documented instructions, including as necessary to provide the Site, a Product, a Solution, or a tool made available through the Marketplace in accordance with the Agreement, unless Leovoid is required to do otherwise by applicable law, in which case Leovoid will inform Customer of that legal requirement before processing, unless that law prohibits such notice on important grounds of public interest.

4. PROCESSOR OBLIGATIONS

4.1 Confidentiality. Leovoid ensures that personnel authorized to process Personal Data are subject to a duty of confidentiality.

4.2 Security Measures. Leovoid implements and maintains the technical and organizational security measures described in the Security Annex, designed to ensure a level of security appropriate to the risk.

4.3 Sub-processor Engagement. Leovoid may engage Sub-processors in accordance with Section 5.

4.4 Assistance With Data Subject Rights. Taking into account the nature of the processing, Leovoid will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to enable Customer to respond to requests from Data Subjects exercising their rights under applicable Data Protection Laws.

4.5 Assistance With Compliance Obligations. Leovoid will provide reasonable assistance to Customer with data protection impact assessments and consultations with Supervisory Authorities, to the extent required under applicable Data Protection Laws and taking into account the information available to Leovoid.

4.6 Personal Data Breach Notification. Leovoid will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer’s Personal Data, and will provide information reasonably available to Leovoid to assist Customer in meeting its own notification obligations under applicable Data Protection Laws.

4.7 Deletion or Return of Data. Upon termination or expiration of the Agreement, Leovoid will delete or return Personal Data in accordance with the Plan Changes, Account Deletion, and Data Retention provisions of the Master Account Terms, unless applicable law requires continued storage.

4.8 Audits. Leovoid will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality protections, frequency limits, and cost allocation as the parties may separately agree; Leovoid may satisfy this obligation by providing a summary of a recent third-party audit or certification report where one exists and is responsive to the audit request.

5. SUB-PROCESSORS

5.1 General Authorization. Customer provides a general authorization for Leovoid to engage Sub-processors to process Personal Data in connection with the Site, a Product, or a Solution.

5.2 Current Sub-processors; Notice of Changes. Leovoid’s current Sub-processors are listed on the Data Subprocessors Page. Leovoid will provide notice of a new Sub-processor by updating the Data Subprocessors Page and, where Customer has subscribed to such notices, by additional notice through the mechanism Leovoid makes available for that purpose. If Customer reasonably objects to a new Sub-processor on legitimate data protection grounds within a reasonable period after notice, the parties will work together in good faith to reach a resolution; if no resolution is reached, Customer’s remedy is to terminate the affected Product or Solution subscription in accordance with the Account Terms.

5.3 Sub-processor Obligations. Leovoid imposes data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, to the extent applicable to the services that Sub-processor provides.

5.4 Scope of Disclosure. The Data Subprocessors Page identifies the Sub-processors Leovoid directly engages. A Sub-processor may itself engage further subprocessors in the ordinary course of its own operations; Leovoid does not undertake to identify, disclose, or vet those further subprocessors, and relies instead on its own Sub-processors’ contractual and legal obligations with respect to any subprocessor those Sub-processors engage. Leovoid remains liable for a Sub-processor’s performance of its data protection obligations to the same extent Leovoid would be liable if performing those services itself.

6. INTERNATIONAL DATA TRANSFERS

6.1 Leovoid’s Ability to Determine and Change Processing Locations. Leovoid may host, store, process, and transfer Personal Data in and to any country in which Leovoid or a Sub-processor operates, and Leovoid may change or redistribute the location of such processing at its discretion, based on factors including data volume, security requirements, cost, operational needs, or legal or regulatory considerations, subject to Leovoid’s compliance with the requirements of this Section. Leovoid’s current Sub-processors and their processing locations are reflected on the Data Subprocessors Page, which is updated as those locations change.

6.2 Transfer Safeguards. Where Leovoid’s processing of Personal Data under this DPA involves a transfer of Personal Data originating in a jurisdiction whose Data Protection Laws restrict the transfer of Personal Data to another country absent an appropriate safeguard — including a transfer of Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of data protection — the Standard Contractual Clauses approved by the European Commission (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable to the parties’ roles), the UK International Data Transfer Addendum, the Swiss Federal Data Protection and Information Commissioner’s requirements, or another valid transfer mechanism recognized under the applicable Data Protection Laws, as applicable, are incorporated by reference and apply to that transfer, completed with the details set out in Annex 1 and the Security Annex to this DPA.

7. LIABILITY

Each party’s liability arising out of or relating to this DPA is subject to the limitation of liability provisions of the Master Account Terms, applied as though this DPA were part of the Account Terms for that purpose.

8. TERM; ORDER OF PRECEDENCE

This DPA takes effect on the date Customer first processes Personal Data through the Site, a Product, a Solution, or a tool made available through the Marketplace, and remains in effect for as long as Leovoid processes Personal Data on Customer’s behalf under the Agreement. This DPA, together with its Annexes, forms part of the Agreement as defined in the Master Account Terms.

ANNEX 1 — DETAILS OF PROCESSING

Subject Matter. Leovoid’s provision of the Site, Products, Solutions, and Marketplace tools to Customer under the Agreement.

Duration. For the term of the Agreement, and thereafter as described in Section 4.7 of this DPA.

Nature and Purpose of Processing. Hosting, storage, transmission, and processing of Customer Data as necessary to provide, secure, support, and improve the Site, Products, and Solutions, including account administration, scanning and evaluation of Registered Assets, billing and payment processing, customer support (including session-based remote access described in the Account Terms), AI-assisted features (including the AI Help Center and third-party AI or large language model processing, where applicable), and communications with Customer and its Users.

Categories of Data Subjects. Customer’s Users and Authorized Users; individuals whose contact or account information is submitted to the Site, a Product, or a Solution; and, where applicable, end users or contacts of Customer’s own customers or clients.

Types of Personal Data. Account Data (name, email address, company name, billing address, phone number, login credentials); Usage Data; payment and billing information; support communications and, where applicable, session recordings or remote-access logs; identity verification documentation, including a self-recorded verification video, where verification is requested under the Account Terms; and other Customer Data submitted to the Site, a Product, a Solution, or a tool made available through the Marketplace, which may include Personal Data depending on Customer’s own use of the Services.

Special Categories of Data. Leovoid does not knowingly process special categories of Personal Data (as defined under applicable Data Protection Laws) in connection with the Site, a Product, or a Solution, except to the extent Customer submits such data to the Services, which Customer should avoid doing except as expressly permitted by the applicable Product or Solution Terms.

ANNEX 2 — SECURITY ANNEX: TECHNICAL AND ORGANIZATIONAL MEASURES

1. Infrastructure and Hosting. The Site, Products, and Solutions are hosted on infrastructure located in the United States, operated through Leovoid’s hosting provider. Physical and environmental security of the underlying data center is maintained by that provider.

2. Encryption. Personal Data is encrypted in transit using industry-standard transport encryption (such as TLS), and encrypted at rest where supported by the underlying storage infrastructure.

3. Access Controls. Access to Personal Data is restricted to personnel and systems with a legitimate business need, governed by role-based permissions consistent with the Account Terms’ Roles and Permissions provisions. Leovoid personnel accessing Customer’s Account for support purposes do so only with Customer’s session-based consent, as described in the Account Terms.

4. Authentication. Account access is protected by credential-based authentication, with support for third-party identity providers (such as Google or Apple) as described in the Account Terms. Leovoid personnel with administrative access to production systems are subject to authentication controls appropriate to that access level.

5. Network Security. Leovoid employs network security controls, including firewalls and access restrictions, designed to prevent unauthorized access to systems processing Personal Data.

6. Vulnerability and Patch Management. Leovoid maintains a process for identifying and remediating security vulnerabilities in its own systems within a risk-appropriate timeframe.

7. Incident Response. Leovoid maintains an incident response process designed to detect, investigate, and respond to a Personal Data Breach, including the notification described in Section 4.6 of this DPA.

8. Personnel. Leovoid personnel with access to Personal Data are subject to confidentiality obligations and receive guidance appropriate to their role regarding the handling of Personal Data.

9. Sub-processor Security. Leovoid requires its Sub-processors to maintain technical and organizational measures appropriate to the services they provide, consistent with Section 5.3 of this DPA.

10. Data Minimization and Retention. Leovoid retains Personal Data in accordance with the Plan Changes, Account Deletion, and Data Retention provisions of the Account Terms and the retention provisions of the Privacy Policy, and does not retain Personal Data beyond what is necessary for the purposes described in Annex 1.

11. Business Continuity. Leovoid maintains reasonable measures designed to support the availability of the Site, Products, and Solutions, consistent with the Force Majeure and general availability provisions of the Account Terms.

Was this page helpful?