Data Processing Addendum

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer”, acting as Controller) and AOC (the “Processor”, operating Lagible) and sets out the obligations of both parties regarding the processing of Personal Data under GDPR Article 28 and equivalent provisions of UK GDPR and other applicable laws.

Effective 2026-06-08. Last updated 2026-06-08. Email ayushopchauhan@gmail.com to execute a countersigned copy. Download PDF version (placeholder, generated on request).

1. Definitions

  • Agreement: the Lagible Terms of Service together with these provisions.
  • Controller, Processor, Personal Data, Data Subject, Processing, Sub-processor: meanings given in GDPR Article 4 and Article 28.
  • Personal Data Breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
  • Standard Contractual Clauses (SCCs): the EU Commission's Implementing Decision 2021/914 modules as applicable.
  • TOMs: the technical and organisational measures described in the Security page, which form Annex II of this DPA by reference.

2. Subject matter, duration, nature, purpose

Subject matter: Processor provides the Lagible service to Customer as described in the Agreement. This DPA covers the Processing of Personal Data carried out under that service.

Duration: same as the duration of the Agreement.

Nature of Processing: collection, storage, indexing, threading, search, AI summarisation and Q&A on Customer instruction, transmission to subprocessors strictly as needed.

Purpose: to deliver the service Customer subscribed to. Processor may not process for any other purpose without prior written Customer instruction or unless required by Union or Member State law (in which case Processor will inform Customer of the legal requirement before processing, unless prohibited by that law).

3. Categories of Personal Data and Data Subjects

Type of Personal Data: identity (email, name), email contents (subject, body, attachments metadata), AI inference outputs, billing metadata. See full categorisation in the Privacy Policy.

Categories of Data Subjects: Customer (the User), and the User's email correspondents whose messages are present in the connected inbox.

4. Processor obligations

Processor shall:

  • Process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by Union or Member State law.
  • Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement and maintain appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, including those described on the Security page.
  • Engage Sub-processors only in accordance with Section 5 below.
  • Assist Controller, taking into account the nature of the Processing, by appropriate technical and organisational measures, in fulfilling Controller's obligation to respond to requests for exercising the Data Subject's rights.
  • Assist Controller in ensuring compliance with the obligations pursuant to GDPR Articles 32 to 36, taking into account the nature of Processing and the information available to Processor.
  • At the choice of Controller, delete or return all Personal Data to Controller after the end of the provision of services relating to Processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data.
  • Make available to Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28, and allow for and contribute to audits conducted by Controller or another auditor mandated by Controller.
  • Immediately inform Controller if, in Processor's opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions.

5. Sub-processors

Controller provides general written authorisation for Processor to engage Sub-processors. The current list of Sub-processors is published on the Security page and mirrored in the Privacy Policy. The list is the canonical source.

Processor shall inform Controller of any intended changes concerning the addition or replacement of other Sub-processors at least 30 days before the change. Notification is by posting the updated list on the Security page and emailing the billing contact on file. Controller may object to the change within the 30-day period by emailing ayushopchauhan@gmail.com. If the objection cannot be resolved, Controller may terminate the Agreement without penalty and request the return or deletion of Personal Data per Section 9.

Processor shall impose on each Sub-processor, by contract, data-protection obligations no less protective than those in this DPA, including obligations to provide sufficient guarantees to implement appropriate TOMs.

Processor remains fully liable to Controller for the performance of any Sub-processor that fails to fulfil its data-protection obligations.

6. International transfers

Where Processing involves a transfer of Personal Data from the EEA, UK, or Switzerland to a country not recognised by the European Commission (or competent authority) as providing an adequate level of protection, the parties hereby incorporate the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) by reference. Module 2 (Controller-to-Processor) applies. The Annexes to the SCCs are satisfied by the corresponding sections of this DPA and the Security page.

Processor has performed transfer impact assessments for each Sub-processor located outside the EEA, UK, and Switzerland, and applies supplementary measures including encryption in transit and at rest, minimisation of data exposed, and vendor selection by privacy posture. The TIAs are available on request to ayushopchauhan@gmail.com.

7. Personal Data Breach notification

Processor shall notify Controller of any Personal Data Breach affecting Controller's Personal Data without undue delay and in any event within 24 hours of Processor becoming aware of the Breach.

The notification shall, at a minimum:

  • Describe the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned.
  • Communicate the name and contact details of the Processor data-protection contact (ayushopchauhan@gmail.com).
  • Describe the likely consequences of the Personal Data Breach.
  • Describe the measures taken or proposed to be taken to address the Personal Data Breach, including, where appropriate, measures to mitigate possible adverse effects.

Where, and in so far as, it is not possible to provide all information at the same time, the information may be provided in phases without further undue delay.

Notification of a Personal Data Breach is without prejudice to Controller's independent obligation to notify supervisory authorities under GDPR Article 33 and Data Subjects under Article 34.

8. Data Subject requests and supervisory assistance

Taking into account the nature of the Processing, Processor shall assist Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Controller's obligation to respond to requests for exercising Data Subject rights laid down in GDPR Chapter III.

Response time: Processor shall acknowledge a Data Subject request forwarded by Controller within 5 business days and complete substantive assistance within 15 business days, except where the request is complex or numerous, in which case Processor may extend by a further 15 business days with notice.

Where a Data Subject contacts Processor directly with a request relating to Personal Data Processed under this DPA, Processor shall forward the request to Controller without undue delay and shall not respond to the Data Subject directly unless legally required or authorised by Controller.

9. Return or deletion of Personal Data

On termination or expiry of the Agreement, Processor shall, at the choice of Controller communicated in writing within 30 days of termination:

  • Return all Personal Data to Controller via secure export (JSON) within 30 days of the choice notice; or
  • Delete all Personal Data within 30 days of the choice notice (default if Controller does not communicate a choice).

Backups containing residual copies cycle out within a further 30 days. Deletion certificate available on written request to ayushopchauhan@gmail.com.

Processor may retain Personal Data only to the extent and for the period required by Union or Member State law, and only for that purpose.

10. Audit rights

Controller has the right to audit Processor's compliance with this DPA. The audit right is exercisable as follows:

  • Frequency: not more than once per 12 months, except in case of a confirmed Personal Data Breach affecting Controller in which case there is no frequency limit.
  • Notice: 30 calendar days written notice to ayushopchauhan@gmail.com.
  • Scope: limited to information and systems within Processor's control that are used for the Processing of Controller's Personal Data.
  • Auditor: Controller or a third-party auditor bound by confidentiality.
  • Cost: borne by Controller, unless the audit identifies material non-compliance, in which case Processor bears reasonable cost.
  • Alternative satisfaction: Processor may satisfy the audit obligation by providing relevant third-party audit reports (e.g. SOC 2 Type 2 once available) at no cost to Controller.

11. Liability

Processor's liability under this DPA is subject to the Limitation of Liability set out in Section 10 of the Terms of Service. Nothing in this DPA increases either party's liability beyond the limit set in the Terms, except where applicable law (including GDPR Article 82) prohibits such limitation.

12. Governing law and jurisdiction

Governing law and dispute resolution are as set out in Sections 11 and 12 of the Terms of Service. The SCCs incorporated under Section 6 of this DPA are governed by the law of the EU Member State of the Controller, as required by SCC Clause 17.

13. Conflict and entire agreement

In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs, the SCCs prevail.

Annex I, Annex II, Annex III

Annex I (Description of the transfer): categories of Data Subjects, categories of Personal Data, special categories, frequency, nature, and purpose of processing, period of retention. Satisfied by Sections 2 and 3 above and the corresponding sections of the Privacy Policy.

Annex II (Technical and organisational measures): satisfied by reference to the Security page, which is maintained under version control and is the canonical source for the TOMs implemented by Processor.

Annex III (List of Sub-processors): satisfied by reference to the Subprocessor list, which is maintained under version control and updated at least 30 days before any change.

Execution

This DPA is incorporated into the Agreement automatically when Customer accepts the Terms of Service. Customer accepts this DPA on behalf of Controller by clicking accept on the sign-up flow, by paying a subscription, or by otherwise using the service.

For a countersigned copy of this DPA on Processor letterhead, email ayushopchauhan@gmail.com with Customer entity name, registered address, and signatory.