For the complete documentation index, see llms.txt. This page is also available as Markdown.

Data Processing Addendum (DPA)

Last Updated: 27th of August 2026.

This Data Processing Addendum ("DPA") is entered into between Lleverage B.V., a company incorporated in the Netherlands with offices at Raamplein 1, 1016XK Amsterdam ("Lleverage AI", "we", "us", "our") and the Customer identified in the relevant Order Form ("Customer") (each a "Party" and together the "Parties"). This DPA is supplemental to, and forms part of, your Contract and the Terms of Service or other written agreement between Lleverage and Customer (in either case, the "Agreement"). This DPA becomes legally binding upon receipt by Lleverage of the validly completed DPA (the "DPA Effective Date").

1. Definitions

In this DPA, the following terms have specific meanings:

  • "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.

  • "Applicable Data Protection Law" means any data protection and privacy laws applicable to the respective Party in its role in the Processing of Personal Data under the Agreement, including the GDPR, UK Data Protection Laws, Swiss Data Protection Laws, and any other relevant data protection laws.

  • "Controller" means the entity which determines the purposes and means of the Processing of Personal Data.

  • "Customer Data" refers to all electronic data, content, or information that the Customer submits to the Services.

  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

  • "Personal Data" means any information relating to an identified or identifiable natural person.

  • "Processing" means any operation or set of operations performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, combination, restriction, erasure, or destruction.

  • "Processor" means the entity that Processes Personal Data on behalf of the Controller.

  • "Sub-processor" means any entity engaged by Lleverage AI or its Affiliates to Process Personal Data in connection with the Services.

Capitalized terms not defined in this DPA will have the meanings given to them in the Agreement or under applicable Data Protection Laws.

Lleverage identifies as processor in the relation of this DPA.

2. Processing of Personal Data

  • Customer Obligations: Customer shall, in its use of the Services and provision of instructions, Process Personal Data in compliance with applicable Data Protection Laws. Customer has sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which Customer acquired such data.

  • Details of Processing: The subject matter of the Processing is the provision of the Lleverage platform and any Managed Implementation services agreed in an Order Confirmation, and it lasts for the term of the Agreement plus the retention and deletion periods in Section 8. The nature of the Processing is the collection, storage, retrieval, use, transmission to AI model providers for inference, and erasure of Personal Data, in each case as necessary to operate the Services, execute the workflows and agents that Customer configures, provide support, maintain security and availability, and comply with law. The categories of Data Subjects and Personal Data are determined by Customer's configuration and use of the Services, and typically comprise Customer's Authorized Users (identity, role, authentication and activity records) and the business contacts and transaction data appearing in the documents, records and systems Customer submits or connects. The Services are not intended for special categories of Personal Data under Article 9 GDPR or criminal-offence data under Article 10 GDPR, and Customer shall not submit such data unless expressly agreed in writing. Retention periods are set out in the Terms of Service and Section 8 below. Customer Data is hosted in the European Union; current hosting, Sub-processor and security-measure details are published at https://trust.lleverage.ai/.

  • Lleverage’s Processing of Personal Data: Lleverage shall Process Personal Data only for the following purposes:

    • Processing in accordance with the Agreement and applicable Order Confirmation(s);

    • Processing initiated by Authorized Users in their use of the Services;

    • Processing to comply with instructions provided by the Customer, where such instructions are consistent with the terms of the Agreement.

  • Personnel: Lleverage shall ensure that all personnel authorized to Process Personal Data are subject to confidentiality obligations.

  • Zero data retention at AI model providers: When processing data for Customers with paid subscriptions through third-party AI model providers, the Processor (Lleverage) shall ensure that zero data retention options are enabled and enforced with such providers, preventing any storage or retention of the Controller's data beyond what is necessary for immediate processing. For users accessing the Test Environment, zero data retention is implemented on a best-effort basis without guarantees.

  • Service improvement: Lleverage may Process technical and operational information about use of the Services in order to operate, secure and improve them, in accordance with Section 7 (Intellectual Property Rights) of the Terms of Service. Lleverage does not use Personal Data to train general-purpose or foundation AI models, does not derive from Customer's environment anything that identifies or could reasonably be used to identify Customer, its personnel or any Data Subject, and never makes Personal Data available to another Customer.

3. Sub-processors

  • Appointment of Sub-processors: Customer acknowledges and agrees that Lleverage may engage third-party Sub-processors to Process Personal Data. Lleverage shall enter into written agreements with Sub-processors that impose data protection obligations that provide the same level of protection for Personal Data as those in this DPA.

  • List of Sub-processors: A current list of Sub-processors for the Services, including the identities of those Sub-processors and their country of location, is accessible via our Trust Center. Customer consents to these Sub-processors, their locations, and Processing activities as they pertain to Personal Data.

  • Objection Right for New Sub-processors: Customer may object to Lleverage's use of a new Sub-processor by notifying Lleverage promptly in writing within ten (10) business days after receipt of notice. If Customer reasonably objects and Lleverage cannot accommodate the objection, Customer may terminate the affected Services.

  • European Data Residency Option: For Customers on paid plans, Lleverage offers the option to restrict data processing to subprocessors hosted exclusively within the European Union. Upon written request, Lleverage will disable any subprocessors that are hosted outside of the EU area for Customer's instance of the Services. Customer acknowledges that selecting this option may limit certain features and functionalities of the Services, particularly those dependent on non-EU based integration partners such as Pipedream.

  • Liability: Lleverage shall be liable for the acts and omissions of its Sub-processors to the same extent Lleverage would be liable if performing the Services directly under this DPA.

4. Data Subject Rights

  • Data Subject Requests: Lleverage shall, to the extent legally permitted, notify Customer if Lleverage receives a request from a Data Subject to exercise rights under Data Protection Laws. Lleverage shall assist Customer in responding to such requests, to the extent possible and as required by Data Protection Laws.

  • Regulator Correspondence: Lleverage shall promptly notify Customer of any correspondence from a Supervisory Authority or other regulatory authority related to Personal Data, unless prohibited by law.

5. Security & Confidentiality

  • Security Measures: Lleverage shall implement appropriate technical and organizational measures to protect the security, confidentiality, and integrity of Personal Data. These measures shall include encryption, access controls, and regular security assessments. Lleverage will not materially decrease the overall security of the Services during the subscription term.

  • Security Incidents: A "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data.

    Lleverage notifies Customer's designated security and administrative contacts without undue delay, and in any event within forty-eight (48) hours of confirming a Security Incident affecting Customer's Personal Data. The notification states, so far as then known, the nature and timing of the incident, the categories and approximate volume of Personal Data and Data Subjects affected, the likely consequences, the measures taken or proposed, and a named contact at Lleverage. Where information is incomplete, Lleverage provides it in phases without further undue delay and keeps Customer updated in writing until the incident is closed. Notification is not an admission of fault or liability. Notifcations will be send pro-actively through communication channels and posted to status.lleverage.ai

  • Lleverage takes immediate reasonable steps to contain the incident, mitigate its effects, preserve evidence and prevent recurrence, and provides Customer with a written summary of root cause, impact and corrective measures within thirty (30) days of closure. Lleverage requires its Sub-processors to report Security Incidents to it without undue delay and passes on any Sub-processor incident affecting Customer's Personal Data on the same timeline.

  • Customer, as Controller, is responsible for assessing whether an incident is notifiable under Articles 33 and 34 GDPR and for notifying its supervisory authority or Data Subjects. Lleverage provides the information and reasonable assistance Customer needs to meet the seventy-two (72) hour deadline under Article 33 GDPR, and cooperates in good faith in the investigation and resolution of the incident.

  • Secrecy and confidentiality: The Parties have a duty to maintain the confidentiality of all personal data received by Lleverage from Customer and/or that Lleverage gathers itself in the context of this DPA, towards third parties. Lleverage will not use this information for any purpose other than that for which it was acquired by it, not even if it has been placed in a form preventing it from being traceable to Data Subjects. This duty of confidentiality does not apply insofar as Customer has given explicit written consent to provide the information to third parties, if the disclosure of the information to third parties is logically necessary given the nature of the assignment granted and the execution of this DPA, or if there is a legal obligation to disclose the information to a third party.

6. Data Transfers

  • Restricted Transfers: To the extent that Customer makes a transfer of Personal Data subject to EU, Swiss, or UK Data Protection Laws, the Parties agree to be bound by the relevant Standard Contractual Clauses, which shall be incorporated into this DPA.

7. Audits and Certifications

  • Third-Party Certifications: Upon Customer’s request, Lleverage shall make available information regarding its compliance with the obligations set forth in this DPA in the form of third-party certifications (such as ISO 27001 or SOC-2) or audit reports. Summaries of these are always accessible through the Trust Center.

  • Standard verification: On request, Lleverage makes available its current ISO/IEC 27001 certificate, its most recent SOC 2 Type II report (under a non-disclosure agreement), summary penetration test results, and written responses to a reasonable security or data protection questionnaire once per twelve (12) month period. This is the primary means by which Lleverage demonstrates compliance with this DPA.

    Customer Audits: Where those materials do not reasonably allow Customer to verify compliance with a specific obligation under this DPA, or where a supervisory authority requires it, Customer may audit Lleverage's compliance with this DPA on thirty (30) days' written notice, once per twelve (12) month period, at Customer's expense. A shorter notice period and an additional audit apply following a confirmed Security Incident affecting Customer's Personal Data or where a supervisory authority so requires. Audits take place during business hours, for a reasonable duration agreed in advance, and are documentary and interview-based together with review of evidence provided by Lleverage. They do not extend to active testing of production systems, to other customers' data or environments, or to physical access to third-party data centres; active testing may be agreed separately in writing.

8. Return and Deletion of Personal Data

Upon termination of the Services, Lleverage shall, at the choice of Customer, return all Personal Data or delete all Personal Data from its systems, unless applicable law requires the retention of such data.

9. Governing Law and Jurisdiction

This DPA shall be governed by and construed in accordance with the laws of the Netherlands. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts located in Amsterdam, Netherlands.

Last updated