Data Processing Policy

Last Updated: January 1, 2026

1. Scope and Applicability

This Data Processing Policy ("DPA") applies to the processing of personal data by Laungrid ("Data Processor") on behalf of our enterprise customers ("Data Controller"). It forms part of the master service agreement between the parties and ensures compliance with applicable data protection laws, including the GDPR and CCPA.

The provisions of this DPA shall apply to all data processing activities carried out by Laungrid in the course of providing its services to the Data Controller. In the event of a conflict between the master service agreement and this DPA, the terms of this DPA shall prevail.

2. Processing of Personal Data

Laungrid shall only process personal data in accordance with the documented instructions of the Data Controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by applicable law.

If Laungrid believes that an instruction from the Data Controller violates applicable data protection regulations, it will immediately inform the Data Controller. The processing covers the nature and purpose as defined in the service agreement, the duration of the processing, and the types of personal data and categories of data subjects involved.

3. Confidentiality

We ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to personal data is restricted on a strict "need-to-know" basis, and personnel undergo regular training regarding data security and privacy principles.

4. Security Measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Laungrid implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • The pseudonymisation and encryption of personal data both in transit and at rest;
  • The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
  • The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  • A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing;
  • Implementation of robust access controls, firewalls, intrusion detection systems, and regular vulnerability scanning.

5. Sub-processors

The Data Controller generally authorizes Laungrid to engage sub-processors. We will inform the Data Controller of any intended changes concerning the addition or replacement of other sub-processors, giving the Data Controller the opportunity to object to such changes.

Laungrid remains fully liable to the Data Controller for the performance of the sub-processor's data protection obligations. All sub-processors are required to enter into written agreements imposing data protection terms that require the sub-processor to protect personal data to the same standard required by this DPA.

6. Data Subject Rights

Laungrid shall, to the extent legally permitted, promptly notify the Data Controller if we receive a request from a Data Subject to exercise their rights (such as access, rectification, restriction of processing, erasure, data portability, object to processing).

We will assist the Data Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Data Controller's obligation to respond to such requests. Laungrid will not respond to any such request independently without the Data Controller's prior written consent, except to advise the Data Subject to submit their request directly to the Data Controller.

7. Personal Data Breach Notification

Laungrid will notify the Data Controller without undue delay after becoming aware of a personal data breach. We will provide reasonable assistance to the Data Controller in handling the breach, including providing information necessary for the Data Controller to notify the relevant supervisory authority and affected data subjects.

8. Deletion or Return of Data

At the choice of the Data Controller, Laungrid will delete or return all the personal data to the Data Controller after the end of the provision of services relating to processing, and delete existing copies unless applicable law requires storage of the personal data. The certificate of deletion will be provided upon the Data Controller's written request.