Data Processing Terms
Effective date: to be confirmed on publication · Last updated:
Draft pending legal review. Remaining registration details will be confirmed before publication.
1. Status
This page describes the data processing terms that apply to Letzo! subscriptions. It is not a signed agreement. Customers who require an executed DPA can request one. [EXECUTION PROCESS TO BE CONFIRMED]
2. Roles
The customer is the controller of personal data it manages in Letzo!. Letzo! is the processor.
3. Instructions
We process customer personal data only on documented instructions — to provide and support the platform.
4. Confidentiality
People authorised to process customer data are bound by confidentiality.
5. Security measures
Organisation-level isolation, role-based access, server-side authorisation, encryption in transit and at rest, MFA and private document storage. See the Security Centre.
6. Subprocessors
Lovable — cloud infrastructure, database, authentication, storage, transactional email, AI gateway and operational monitoring. Stripe — subscription payment processing. TrueLayer — regulated Open Banking connectivity. OpenAI — model processing for AI-assisted features through Lovable's AI gateway. Google Fonts — delivery of website typography. Each provider receives only the data needed for its purpose. This list will be reviewed when services change.
7. Data subject rights
We assist customers in responding to requests from individuals.
8. Breach assistance
We notify customers without undue delay after becoming aware of a personal data breach affecting their data.
9. Deletion and return
At the end of the contract, customer data is returned or deleted on request, subject to legal retention obligations.
10. Audits
We provide information reasonably necessary to demonstrate compliance with these terms.