Data Processing Agreement
Last updated: July 31, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Lein AI Systems (“Processor”) and the customer organization using Alatusa (“Controller”). It applies when Processor processes personal data in Customer Content on behalf of Controller in connection with the Alatusa service.
1. Roles and subject matter
- Controller: the Customer organization that determines the purposes and means of processing end-customer and conversation data in its Alatusa workspace.
- Processor: Lein AI Systems, providing the Alatusa SaaS platform.
- Subject matter: hosting, routing, display, storage, backup, and related processing of Customer Content required to operate the inbox and configured workspace features.
- Duration: for the term of the Controller’s Alatusa subscription and any post-termination export / deletion window under the Terms and this DPA.
2. Types of personal data and data subjects
Depending on Controller’s use of Alatusa:
- Data subjects: Controller’s end customers and prospects; Controller’s staff using the workspace; other persons whose data appears in messages.
- Personal data: identifiers such as names and phone numbers, message content and media, channel identifiers, timestamps, delivery status, and labels or notes Controller stores in the workspace (“Customer Content”).
Account, billing, and lead data about Controller’s own staff may be processed by Lein AI Systems as an independent controller under the Privacy Policy.
3. Nature and purpose of processing
Processor processes Customer Content only to provide, secure, and support the Alatusa service, including message delivery integration with Meta channels Controller connects, storage, search/display in the inbox, optional AI suggestions when enabled by Controller’s plan, analytics Controller configures, and backups.
4. Processor obligations
- Process Customer Content only on documented instructions from Controller (including configuration in the product and these Terms/DPA), unless required by law;
- Ensure persons authorized to process Customer Content are bound by confidentiality;
- Implement appropriate technical and organizational measures (see Annex A);
- Engage sub-processors under written terms offering equivalent protections and remain liable for their performance as required by Article 28 GDPR;
- Assist Controller, insofar as possible, with data-subject requests and GDPR obligations relating to Customer Content;
- Notify Controller without undue delay after becoming aware of a personal-data breach affecting Customer Content;
- At Controller’s choice after end of service, delete or return Customer Content (subject to the Terms’ export window and legal retention), and delete existing copies unless EU or Member State law requires storage;
- Make available information necessary to demonstrate compliance and allow reasonable audits (remote first; on-site only where remote is insufficient, with confidentiality and notice).
5. Controller instructions and responsibilities
Controller warrants it has a lawful basis to process Customer Content and to instruct Processor. Controller is responsible for the content of messages, Meta Business compliance, and responding to end-customer rights requests in the first instance.
6. Sub-processors
Controller authorizes Processor to use the following categories of sub-processors:
- Infrastructure / database: Supabase (primary region AWS eu-west-2 (London, United Kingdom));
- Payments: Stripe (billing; primarily Controller account data);
- Messaging platforms: Meta Platforms for WhatsApp, Instagram, and Messenger when Controller connects those channels;
- AI providers: Google (or successor providers disclosed in-product) when Controller’s workspace has AI features enabled.
Processor will inform Controller of material sub-processor changes in a reasonable manner (for example Privacy Policy / DPA update or in-product notice). Controller may object on reasonable GDPR grounds; if unresolved, Controller may terminate the affected service as its sole remedy.
7. International transfers
Primary hosting of application data is in AWS eu-west-2 (London, United Kingdom). Where Customer Content is transferred internationally, Processor uses appropriate safeguards required by the GDPR (such as adequacy decisions and/or standard contractual clauses).
8. No sale; no default foundation-model training
Processor does not sell Customer Content. Processor does not use Customer Content by default to train generic third-party foundation models. Workspace-scoped improvement features, if any, follow the Privacy Policy and Controller configuration.
9. Contact
Lein AI Systems
Paul Krugerstraat 356, 4381 WT Vlissingen, Netherlands
info@alatusa.com · +31 6 82 19 76 31
VAT: NL005354633B13
Annex A: Security measures (summary)
- Tenant isolation via Postgres row-level security and company-scoped access controls;
- Encryption in transit (TLS) for public endpoints;
- Authentication for workspace users (including Google Sign-In where enabled);
- Least-privilege operational access and secret management outside client code;
- Monitoring of service health without logging message bodies or auth tokens at info level;
- Backups and retention aligned with Provider’s operational practices and this DPA.