Data Processing Agreement
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between Logos Industries ("idapt", "we") and the customer agreeing to them ("Customer", "you"). It applies wherever idapt processes personal data on your behalf.
You do not need to sign this. It takes effect automatically as part of the Terms. If your procurement process requires a countersigned copy, write to [email protected] and we will provide one.
1. Roles
idapt processes two different kinds of personal data, in two different roles.
idapt is the controller of your Account Data: your name, email address, billing details, security logs, and usage metrics. We decide why and how those are processed, and our Privacy Policy describes it.
idapt is the processor of Customer Personal Data: any personal data contained in the content you put into the Service. Your conversations, files, notes, tasks, and repositories may describe or identify other people, and where they do, you are the controller and we act only on your instructions. This DPA governs that processing.
Where you are an individual consumer using idapt for your own purposes, you are not acting as a controller and this DPA does not apply to you. Your protections are in the Privacy Policy instead.
2. Subject matter and scope (Annex I)
| Subject matter | Provision of the idapt Service |
| Duration | The term of the Terms of Service, plus the retention periods in Section 9 |
| Nature and purpose | Hosting, storage, transmission, indexing, and AI processing of Customer Content at your instruction |
| Types of personal data | Whatever you choose to put into the Service. Typically: identifiers, contact details, professional information, and free-text content that may mention identifiable people |
| Categories of data subjects | Your personnel, your customers, your correspondents, and any person described in content you upload |
| Special categories | Not requested and not required. If you choose to process special-category data, you remain responsible for the lawfulness of doing so |
3. Processing on documented instructions
We process Customer Personal Data only on your documented instructions, including for international transfers, unless a law we are subject to requires otherwise. In that case we will tell you before processing, unless that law prohibits it.
Your instructions are: the Terms of Service, this DPA, the configuration you choose in the Service (including workspace settings, provider routing, and retention controls), and any use you make of the Service's features.
If we consider an instruction to infringe data protection law, we will tell you.
We do not use Customer Personal Data to train AI models, and we do not permit our sub-processors to do so on our behalf. This is a standing instruction you do not need to give us.
4. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by an appropriate duty of confidentiality, and access is limited to those who need it to provide or support the Service.
5. Security (Annex II)
We implement appropriate technical and organisational measures, including:
- Encryption in transit using TLS for every connection to the Service.
- Encryption at rest for object storage, backups and secrets, which our providers encrypt by default (Cloudflare R2, Amazon S3, AWS Secrets Manager and KMS), and for Kubernetes secrets at the cluster level. The database volumes themselves are not separately encrypted at rest, and we say so rather than imply otherwise; closing that is an open item on our roadmap.
- Row-level security enforced in the database itself, so tenant isolation does not depend on application code being correct.
- Least-privilege access control, with authentication and authorisation on every request. Administrative access is restricted to a small explicit allowlist of verified idapt staff addresses, and two-factor authentication is available on every account.
- Tenant isolation through workspaces, and a separate origin per published application so that one customer's app cannot reach another's data.
- Audit logging of access to resources: who viewed, downloaded, changed, shared or deleted what, and when.
- Backups with a bounded recovery point objective, 30-day retention, and a second write-once copy held under object lock in a different provider.
- Vulnerability management, including a published disclosure policy and prompt patching.
The current detail is on our Trust page, which forms part of Annex II. We may improve these measures over time; we will not reduce the overall level of security.
6. Sub-processors
You give us general written authorisation to engage sub-processors.
The current list, with each one's legal entity, location, and transfer safeguard, is published at /legal/sub-processors and generated directly from the registry the Service itself uses.
We give at least 30 days' notice before adding or replacing a sub-processor that processes Customer Personal Data. To receive those notices, write to [email protected].
If you reasonably object to a new sub-processor on data protection grounds within those 30 days, we will work with you to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of any prepaid fees for it.
We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
7. Assisting you with data subject requests
If a data subject contacts us directly about Customer Personal Data, we will refer them to you rather than responding ourselves, unless you tell us otherwise.
We provide self-service tools that let you answer most requests without our involvement: export, deletion, and, for Teams, administrative access to the data held in your workspaces. Where those are not enough, we will assist you, taking into account the nature of the processing.
8. Assisting you with security, breaches, and assessments
We assist you with your obligations under Articles 32 to 36 GDPR.
Personal data breaches. We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information we hold at that point, and we keep you updated as we learn more. We do not wait until we have a complete picture.
Impact assessments. We provide the information reasonably needed for your data protection impact assessments and any prior consultation with a supervisory authority.
9. Deletion and return
Every resource exports from its own screen at any time, in open formats, for as long as your account is active. A single archive of the whole account is available on request to [email protected] within one month.
On termination, and at your choice, we delete or return Customer Personal Data, within one month of your request.
We retain data beyond that point only where EU or Member State law requires it, which in practice means invoices and payment records kept for the 10 years French tax and accounting law prescribes. Those records are retained under Article 17(3)(b) GDPR and are not used for any other purpose.
10. Audit
We make available the information necessary to demonstrate compliance with this DPA, including our published security documentation, our sub-processor register, and responses to reasonable security questionnaires.
You may audit our compliance once in any 12-month period, and additionally after a personal data breach affecting your data. Audits are conducted on at least 30 days' written notice, during business hours, without unreasonably disrupting the Service, and subject to confidentiality. You bear your own costs.
11. International transfers
The Service processes data in the United States. Section 7 of our Privacy Policy sets out exactly where, and /legal/sub-processors sets out the safeguard for each provider.
Where personal data is transferred out of the European Economic Area, the following apply and are incorporated into this DPA by reference:
- Module Two (controller to processor) of the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, where you are a controller established in the EEA and idapt processes on your behalf.
- Module Three (processor to processor) of the same Clauses, where you are yourself a processor.
- The UK International Data Transfer Addendum (version B1.0) for transfers subject to UK data protection law.
- For transfers subject to Swiss law, the Clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner as the competent authority.
For those Clauses:
- The docking clause (Clause 7) applies.
- Clause 9(a), option 2 applies: general written authorisation for sub-processors, with the 30 days' notice in Section 6 above.
- Clause 11 applies without the optional independent dispute resolution body.
- Clause 17 selects the law of France. Clause 18(b) selects the courts of France.
- Annex I is Section 2 of this DPA, Annex II is Section 5, and Annex III is the published sub-processor list.
You may obtain a copy of the safeguards by writing to [email protected].
12. General
Liability. Each party's liability under this DPA is subject to the limitations in the Terms of Service, except where those limitations are not permitted by applicable data protection law.
Precedence. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Term. This DPA applies for as long as we process Customer Personal Data on your behalf.
Contact. [email protected]. Our full identification is in the Legal Notice.