Data Processing Agreement
Effective date: January 1, 2026 · Last updated: January 1, 2026
This Data Processing Agreement ("DPA") forms part of your agreement with Lebertech ("we", "us", or "our") for use of Atlas and governs how we process personal data on your behalf.
1. Definitions
In this DPA, "Controller" means the customer who determines the purposes and means of processing personal data; "Processor" means Lebertech, which processes personal data on behalf of the Controller; "Data Subject" means the individual to whom personal data relates; "Personal Data" has the meaning given in applicable data protection law, including the General Data Protection Regulation (GDPR).
2. Scope and purpose of processing
Lebertech processes personal data solely to provide the Atlas services described in your subscription agreement. Processing activities include storing, retrieving, organizing, and transmitting personal data entered into the platform by you or your users.
We act as a data processor with respect to personal data about your leads, contacts, accounts, and any other individuals whose data you input into the platform. You remain the data controller for all such data.
3. Our obligations as processor
Lebertech will:
- Process personal data only on your documented instructions, including with regard to transfers to third countries
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures as required by Article 32 of the GDPR
- Assist you in responding to data subject rights requests, including access, rectification, erasure, and portability
- Notify you without undue delay (and in any case within 72 hours) upon becoming aware of a personal data breach
- Delete or return all personal data upon termination of services at your choice, subject to applicable law
- Provide all information necessary to demonstrate compliance with Article 28 of the GDPR
4. Sub-processors
Lebertech uses sub-processors to provide portions of the Atlas service. By entering into this DPA, you grant us general authorization to engage sub-processors, provided we:
- Maintain an up-to-date list of sub-processors available at /legal/sub-processors
- Impose data protection obligations on sub-processors at least equivalent to those set out in this DPA
- Notify you of any intended additions or replacements of sub-processors at least 14 days in advance, giving you the opportunity to object
5. Security measures
We implement and maintain the following technical and organizational measures to protect personal data:
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256 field-level encryption for sensitive fields)
- Role-based access controls with principle of least privilege
- Comprehensive audit logging of all data access and mutations
- Multi-tenant data isolation ensuring no cross-organization data access
- Regular security assessments and vulnerability scanning
- Incident response procedures with documented breach notification processes
6. International data transfers
Atlas infrastructure is hosted in the European Union and United States. Where personal data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, or other lawful transfer mechanisms as applicable.
7. Audit rights
Upon your written request and at your expense, Lebertech will make available to you all information necessary to demonstrate compliance with this DPA, and will allow for audits conducted by you or a third-party auditor appointed by you (subject to reasonable confidentiality obligations and advance notice of not less than 30 days).
8. Term and termination
This DPA is effective for the duration of your subscription to Atlas and terminates automatically upon expiry or termination of your subscription agreement. Upon termination, we will delete or return personal data in accordance with section 3 above, unless retention is required by applicable law.
9. Contact
For questions about this DPA or our data protection practices, please contact our Data Protection Officer at: privacy@joyful.app