Legal

Data Processing Addendum

Last updated · May 1, 2026

This DPA applies when lepta processes personal data on behalf of a Customer in connection with the service, including for GDPR and UK GDPR compliance.

Roles

You are the data controller. lepta is the data processor and processes data only on documented instructions.

Security

lepta maintains industry-standard administrative, technical, and physical safeguards including SOC 2 Type II controls.

Sub-processors

A current list is published at /legal/sub-processors. New sub-processors are announced 30 days in advance.

International transfers

Where applicable, Standard Contractual Clauses (SCCs) and the UK Addendum are incorporated by reference.

Subject requests

lepta assists with subject access, deletion, and portability requests within the timeframes required by law.

Audits

Customers on Enterprise plans may request annual SOC 2 reports and complete security questionnaires.

Acceptance

This DPA is automatically incorporated into the Terms of Service for all paid customers. To request a counter-signed copy, email legal@lepta.app.