Data Processing Agreement
Release 1 · Published 6 August 2026, 16:23
Effective from: sixth August two thousand twenty six
1. Parties and precedence
This DPA forms part of the agreement between the Customer identified in the order and Lemric Dominik Łabudziński, a sole trader with the address Weteranów 74/3, 05 250 Radzymin, Poland, Polish tax identification number 5272448444 and statistical number 141491900.
The Customer is the controller for personal data placed in its organisation and Lemric is the processor. If the Customer processes data for another controller, Lemric acts as a further processor and the Customer confirms that it is authorised to appoint Lemric.
For matters concerning entrusted personal data, this DPA prevails over the Service Terms. The order may add instructions but may not reduce protection required by applicable data protection law.
2. Subject matter and duration
The subject matter is processing needed to provide and secure the Customer’s configured help centre, customer portal and service desk. Processing continues for the term of the service and afterwards only as needed to follow a documented return or deletion instruction, complete the cycle of any existing service restoration copies, comply with law or establish and defend claims.
3. Nature and purpose
Operations may include collection, receipt, recording, organisation, storage, encryption, retrieval, consultation, display, transmission, matching, restriction, backup, export, deletion and destruction.
The purpose is to provide accounts and permissions, forms, requests, messages, attachments, queues, workflows, service levels, automation, help content, audit records, Customer selected Jira and webhook integrations, support, security and continuity.
Lemric does not sell entrusted data or use it for its own advertising.
4. People and data types
People may include the Customer’s representatives, administrators, staff, contractors, customers, requesters, portal users, request participants and other people identified in Customer content.
Data may include:
- names, electronic mail addresses, organisation details, roles and identifiers
- account, authentication and permission information
- request subjects, messages, form answers, internal notes and communication history
- attachments, file names and related metadata
- service level, workflow, automation, notification and activity information
- IP addresses, session and device metadata, security events and audit records
- Jira references and webhook content selected by the Customer
- any other fields or content configured and lawfully submitted by the Customer
Special categories of data and data about criminal convictions are not intended for routine use. The Customer must not submit them unless processing is lawful, necessary and covered by documented safeguards.
5. Documented instructions
Lemric processes entrusted data only on documented instructions from the Customer, including the agreement, order, organisation configuration and authorised support requests. Instructions also cover transfers unless this DPA states otherwise.
If European Union or member state law requires other processing, Lemric informs the Customer before processing unless that law prohibits notice for important public interest reasons.
Lemric promptly informs the Customer if, in its opinion, an instruction infringes applicable data protection law. Lemric may pause the affected operation while the parties clarify a lawful instruction.
The Customer is responsible for the lawfulness, accuracy and scope of its instructions, its legal bases, notices to people and permissions granted to users and integrations.
6. Confidentiality and personnel
Lemric ensures that persons authorised to process entrusted data have committed themselves to confidentiality or are under an appropriate statutory duty. Access is limited according to role and need, reviewed where appropriate and removed when no longer required.
7. Security
Taking account of the state of the art, implementation cost, scope and risk, Lemric maintains measures appropriate to risk. Current measures include logical organisation isolation, database row access controls, encrypted transmission, encryption of selected stored personal data, access control, protected authentication secrets, logging of selected privileged operations, abuse controls and incident procedures.
Attachments and exports stored in Cloudflare R2 are encrypted by the application. Audit archive data is protected separately. Technical details can change if the overall protection remains appropriate to risk and is not materially reduced.
The Customer remains responsible for role assignment, endpoint security, its integration credentials, lawful configuration and prompt removal of unnecessary access.
8. Subprocessors
The Customer grants general written authorisation for the subprocessors identified in the Subprocessor List. Lemric will provide electronic notice before adding or replacing a subprocessor that will process entrusted data and will allow a reasonable period for a specific objection based on data protection grounds.
The parties will try in good faith to resolve an objection. If no reasonable alternative is available, the Customer may terminate the affected service before the change takes effect. Urgent changes needed for security or continuity may take effect sooner, with notice as soon as reasonably possible.
Lemric imposes by contract substantially the same data protection duties that apply to Lemric under this DPA. Lemric remains responsible to the Customer for a subprocessor’s performance as required by article 28 of the GDPR.
Jira and webhook destinations chosen by the Customer are recipients under the Customer’s instruction and are not permanent Lemric subprocessors.
9. Assistance with individual rights
Considering the nature of processing, Lemric assists the Customer through appropriate technical and organisational measures, insofar as possible, to respond to requests for access, rectification, erasure, restriction, portability and objection.
If Lemric receives a request concerning entrusted data, it forwards the request to the Customer without undue delay and does not respond substantively unless instructed by the Customer or required by law.
10. Security obligations and breaches
Lemric assists the Customer, taking account of available information and the nature of processing, with security duties under article 32 of the GDPR.
Lemric notifies the Customer without undue delay after becoming aware of a personal data breach concerning entrusted data. As information becomes available, the notice describes the nature of the breach, affected people and records where known, likely consequences, measures taken or proposed, and a contact for further information. Lemric may provide information in stages and takes reasonable steps to contain and investigate the event.
Notification does not by itself constitute an admission of fault or liability.
11. Assessments and authority consultation
Lemric provides reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority where the Customer’s processing requires them. Assistance depends on the nature of processing and information available to Lemric. Additional work outside normal service support may be charged if agreed in advance.
12. Return, deletion and backups
At the end of the service, Lemric will, at the Customer’s choice stated in a documented request, return available entrusted data or delete it, unless law requires continued storage. The request must be made while Lemric can reasonably identify and access the relevant data. No user operated export after termination is promised.
If data is held in a service restoration copy when the service ends, deletion takes place by safely overwriting or removing that copy and may not be immediate. Until then, the data remains outside ordinary use and may be restored only for continuity, security or legal need. Legal holds, mandatory retention and evidence needed for claims may delay deletion.
The Customer should not assume that organisation retention settings replace a specific end of service instruction.
13. Information and audits
Lemric makes available information reasonably necessary to demonstrate compliance with article 28 of the GDPR and contributes to audits, including inspections, conducted by the Customer or an independent auditor authorised by it.
Audits must be proportionate, protect other customers and confidential information, avoid unnecessary disruption and normally use existing documentation first. Unless an incident, authority request or credible evidence justifies otherwise, the Customer gives reasonable notice and conducts no more than one audit in twelve months. The Customer bears its audit costs, and exceptional assistance may be charged if agreed in advance.
Lemric promptly informs the Customer if an audit instruction would infringe applicable data protection law.
14. International transfers
Lemric will not transfer entrusted data outside the European Economic Area except on the Customer’s documented instruction or where needed to use an authorised subprocessor and a lawful transfer basis has been identified.
Where required, the parties will document an adequacy decision, valid contractual safeguards or another lawful basis and any necessary supplementary measures before the transfer. This DPA does not claim that standard contractual clauses or a transfer impact assessment are already completed for every possible destination.
The Customer is responsible for transfers to Jira, webhook destinations and other recipients it selects. Lemric will provide available information reasonably needed for the Customer’s assessment.
15. Customer duties
The Customer ensures that its processing complies with law, that instructions are lawful and that entrusted data is relevant and not excessive. It handles notices, legal bases and individual requests as controller, and informs Lemric of instructions through authorised channels.
16. Contact
DPA notices and instructions may be sent to privacy@lemric.com. General legal notices may be sent to legal@lemric.com. Customer details, service scope and additional instructions are stated in the order and organisation configuration.