Version 1.0 · Effective October 1, 2026
Data Processing Agreement
This DPA v1.0 is between the customer identified in the Lysia workspace and Noora Auvinen, operating the Lysia service ("Lysia"). It governs personal data that Lysia processes on the customer's behalf under the GDPR.
It becomes binding when an authorised company owner accepts it electronically through Lysia. English is the authoritative language of this DPA. Any Finnish version is a translation of the same agreement. If there is any inconsistency between the language versions, the English version prevails.
1. Parties and scope
The customer is the controller and Lysia is the processor where the customer determines the purposes of processing and instructs Lysia to process personal data through supported Lysia features.
This DPA supplements the applicable Lysia Terms of Use. It does not apply to separate processing for which Lysia independently determines the purposes and means and therefore acts as controller, such as account administration, service security, fraud and abuse prevention, legal compliance, or other processing expressly described as Lysia-controlled processing in the Privacy Notice. Any such controller processing must have its own lawful basis and transparency and does not convert customer personal data processed under this DPA into data Lysia may freely use for its own purposes.
2. Documented instructions and purpose limitation
Lysia will process customer personal data only on documented instructions from the controller, including instructions expressed through the customer's use and configuration of Lysia, except where processing is required by applicable Union or Member State law. Where legally permitted, Lysia will inform the controller before processing required by such law.
Lysia will not sell customer personal data, use it for unrelated advertising or marketing, build an independent commercial customer dataset from it, or use identifiable customer communications or records to train or improve models or products for Lysia's own independent purposes merely because that data is available through the service. If Lysia proposes processing for a separate purpose for which it would act as controller, that processing must be separately identified, supported by an appropriate lawful basis, and described transparently as required by applicable law.
The controller is responsible for ensuring that its instructions comply with applicable data-protection law and that it has a lawful basis for the personal data it provides to Lysia. If Lysia believes an instruction infringes applicable data-protection law, Lysia will inform the controller as required by Article 28 GDPR.
3. Confidentiality and access
Lysia will ensure that persons authorised to process customer personal data are subject to appropriate confidentiality obligations. Access to customer personal data will be limited to persons and systems that reasonably require access to carry out the controller's documented instructions, provide the requested service, secure the processing, provide authorised support or maintenance, or comply with applicable law.
This may include Lysia employees, contractors or other personnel acting under Lysia's authority, such as personnel performing security, engineering, support or maintenance work. Such access will be limited to what is reasonably necessary for assigned duties, subject to confidentiality and appropriate access controls, and removed when it is no longer required. If a separate provider processes customer personal data on Lysia's behalf as an independent processor rather than merely acting under Lysia's authority, that provider will be treated as a subprocessor under Section 5.
4. Security of processing
Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, Lysia will maintain technical and organisational measures designed to provide a level of security appropriate to the risk.
The current categories of measures are described in Annex B and on the Security & Data Protection page. No description of security measures is a guarantee that security incidents can never occur.
5. Subprocessors
Lysia may engage subprocessors only in accordance with Article 28 GDPR and the controller's applicable authorisation. Where general written authorisation is used, the controller will be informed of intended additions or replacements in a manner that gives the controller a meaningful opportunity to object where required.
Lysia will impose data-protection obligations on each subprocessor that provide an appropriate level of protection for the processing delegated to that subprocessor. Lysia remains responsible for the performance of its subprocessor obligations to the extent required by applicable law and the applicable agreement.
The controller gives Lysia general written authorisation to use the subprocessors listed in Annex C. Lysia will provide notice of intended additions or replacements before the new subprocessor begins processing customer personal data where required by Article 28, giving the controller a reasonable opportunity to object on data-protection grounds.
6. Assistance with data-subject rights
Taking into account the nature of the processing, Lysia will provide reasonable assistance to the controller, through appropriate technical and organisational measures where possible, so that the controller can respond to requests from individuals exercising rights under applicable data-protection law.
Depending on the request and the features in use, this assistance may include helping the controller locate, access, export, correct, restrict or delete customer personal data held in the controller's workspace; providing information about relevant processing; and promptly forwarding a data-subject request received by Lysia where the request concerns data processed only on the controller's behalf. The controller remains responsible for deciding whether and how the request must be fulfilled.
7. Security incidents and regulatory assistance
Lysia will notify the controller without undue delay after becoming aware of a personal-data breach affecting customer personal data processed under this DPA and will provide information reasonably available to Lysia that the controller may need to meet applicable notification obligations.
Taking into account the nature of processing and the information available to Lysia, Lysia will provide reasonable assistance with security obligations, data-protection impact assessments and consultations with supervisory authorities where Article 28 requires such assistance. For a personal-data breach, Lysia will provide reasonably available information about the nature of the incident, affected data or data subjects where known, likely consequences, containment or remediation measures, and a contact point for follow-up, and will supplement that information as material facts become available.
8. International transfers
Lysia will not intentionally transfer customer personal data to a third country or international organisation except on documented controller instructions or where otherwise permitted by applicable law and supported by a lawful transfer mechanism where one is required.
Current transfer information and safeguards for subprocessors used within this DPA scope are documented in Annex D.
9. Return and deletion
At the end of the relevant processing services, and subject to the controller's choice and applicable law, Lysia will delete or return customer personal data and delete remaining copies unless Union or Member State law requires continued storage.
The product's active-workspace deletion process is described on the Company Data Deletion page. Residual copies may remain in protected backups until the applicable backup lifecycle removes them, where deletion from those backups is not immediately practicable and continued retention is otherwise lawful and appropriately protected.
10. Compliance information and audits
Lysia will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable under Article 28 GDPR. This may include relevant security documentation, processing and subprocessor information, transfer information, and other evidence reasonably available to Lysia.
Lysia will allow for and contribute to audits or inspections required by Article 28. Where appropriate, the parties should first use current independent reports, documentation, questionnaires or a remote review if those materials can reasonably demonstrate compliance. If an additional audit or inspection is reasonably necessary, it will be arranged on reasonable notice, during normal business hours where practicable, and in a way that protects other customers, confidential information and system security while still allowing the controller to exercise its Article 28 rights.
11. Controller responsibilities and lawful data
The controller remains responsible for the lawfulness of its processing, including providing required notices to individuals, identifying and maintaining an appropriate legal basis, responding to data-subject requests, configuring access appropriately, and ensuring that personal data uploaded, entered or connected to Lysia is necessary, proportionate and lawful for the controller's purposes.
The controller must have the right and lawful basis to collect, use and provide the personal data to Lysia and must give Lysia only lawful documented instructions. This DPA allocates processor obligations to Lysia; it does not create a lawful basis for the controller, cure unlawful collection or disclosure, or make an otherwise unlawful processing purpose lawful.
The controller must not instruct Lysia to process personal data in a manner that violates applicable data-protection law. Where Lysia becomes aware that an instruction infringes applicable data-protection law, Lysia will inform the controller as required by Article 28 GDPR and may decline or suspend the affected processing where necessary to avoid unlawful processing.
12. Duration and precedence
Once made effective, this DPA will apply for as long as Lysia processes customer personal data as processor on behalf of the controller. If this DPA conflicts with the Terms of Use regarding processor obligations for customer personal data, this DPA will control to the extent of that conflict.
Annex A
Processing details
Subject matter and purpose
Processing customer-provided personal data on the controller's documented instructions as necessary to provide Lysia business analytics, data-upload and editing tools, inventory and forecasting functionality, support, security and related service functionality requested by the controller. AI-assisted analysis and AI image extraction are outside the ordinary non-admin first-tester processing scope while those features are disabled. If those features are later enabled for customer personal data, Lysia will update the relevant subprocessor/transfer information before that processing begins. This purpose does not include independent commercial reuse of identifiable customer personal data by Lysia.
Duration
For the duration of the customer's use of the relevant processing services and until customer personal data is deleted or returned in accordance with the applicable agreement, controller instructions and lawful retention requirements.
Nature of processing
Collection, receipt, hosting, storage, organisation, structuring, retrieval, viewing, transformation, analysis, generation of derived analytics, transmission to authorised service providers where necessary to provide the instructed processing, support and security processing, and deletion.
Categories of data subjects
Depending on what the controller provides through supported features: the controller's customers and prospective customers, customer contacts, suppliers and supplier contacts, business partners, and other individuals whose personal data is contained in authorised business records entered or uploaded by the controller.
Types of personal data
Personal data intentionally entered or uploaded through supported features, which may include names or customer identifiers, contact details, transaction and order information, purchase or product history, supplier or business-contact information, and ordinary business-record metadata such as dates and timestamps.
Special-category and highly sensitive data
Lysia is not intended for special-category personal data, payment-card credentials, authentication secrets or other highly sensitive personal data unless Lysia expressly supports that processing and appropriate additional safeguards have been agreed. Controllers should not upload such data merely because it appears in a broader source file or conversation export.
Controller instructions
The controller's instructions are reflected in this DPA, the Terms of Use, the controller's configuration and use of Lysia, connected integrations, support requests, deletion requests and other documented instructions accepted by Lysia.
Annex B
Technical and organisational measures
Measures currently reflected in Lysia include authenticated user access; company-scoped authorisation and database policies; server-side checks for sensitive operations; controlled handling of service credentials and integration tokens; HTTPS/TLS for supported production connections; company-level data isolation; owner-restricted destructive controls; data-deletion procedures; and security-focused logging and testing.
These measures are subject to continued development and review as the beta service evolves. The public Security & Data Protection page provides additional current-state information.
Annex C
Subprocessors
Supabase Pte. Ltd.
Purpose: database hosting, authentication, database APIs and Edge Functions supporting the Lysia service.
Lysia project region: eu-west-1. Customer data is stored and primarily processed in the selected region, subject to Supabase's DPA, authorised subprocessors and lawful transfer mechanisms.
Data: customer personal data and associated service metadata stored or processed through the controller's Lysia workspace.
Contractual basis: Supabase Data Processing Addendum, including its subprocessor terms and applicable 2021 EU Standard Contractual Clauses.
Current beta scope note
Gemini-backed AI Analyst and AI image extraction are disabled for ordinary non-admin tester accounts and are not authorised under this Annex for customer personal data. The current supported personal-data paths use the browser and Supabase directly. Vercel currently provides application delivery on a Hobby plan and is not represented here as an Article 28-covered subprocessor for controller-submitted customer content. Lysia must not send controller-submitted personal data through Vercel server routes under this DPA scope. If the architecture or provider plan changes so another provider processes customer personal data on Lysia's behalf, Annex C must be updated and the controller notified as required before that processing begins.
Annex D
International transfer information
Supabase
The active Lysia Supabase project is configured in eu-west-1. Supabase's DPA states that data directed to a specific geographic region is stored and primarily processed in that region, while Supabase and authorised subprocessors may perform other processing subject to the DPA and applicable transfer rules.
Where a restricted transfer from the EEA to Supabase or an authorised subprocessor requires a transfer mechanism, Supabase's DPA incorporates the European Commission's 2021 Standard Contractual Clauses, including Module Two where the customer acts as controller and Supabase/Lysia's processor chain requires controller-to-processor protection, and Module Three where applicable to processor-to-subprocessor transfers.
Lysia will review Annex D when adding or replacing a subprocessor, changing relevant processing locations, or enabling a currently disabled provider for customer personal data.