Data Processing Agreement
Last updated: 2026-07-16
This Data Processing Agreement ("DPA") is entered into between:
- Controller: the customer entity that has accepted the Lessly Terms of Service ("Customer"); and
- Processor: Apliteni OÜ, an Estonian limited company, registry code 14296961, Tornimäe tn 3 // 5 // 7, Tallinn, Estonia — the company operating the Lessly platform and its extensions ("Apliteni").
This DPA supplements the Terms of Service and governs Apliteni's processing of personal data on the Customer's behalf in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").
1. Definitions
"Controller" means the Customer — the natural or legal person that determines the purposes and means of processing personal data. In the context of this DPA the Customer is the controller of personal data collected through the Lessly services they have enabled.
"Processor" means Apliteni — the entity that processes personal data on behalf of the Controller under this DPA.
"Sub-processor" means any third party engaged by Apliteni to carry out specific processing activities on behalf of the Controller. The authoritative list of sub-processors is published at lessly.com/legal/subprocessors (see Annex A).
"Personal data" has the meaning given in Article 4(1) GDPR: any information relating to an identified or identifiable natural person.
"Processing" has the meaning given in Article 4(2) GDPR and covers any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, or deletion.
"Data subject" means the natural person whose personal data is being processed — typically the Customer's end users, contacts, or the visitors to the Customer's websites and applications.
"Services" means the Lessly platform and any extensions the Customer has installed and enabled, as described in Schedule 1.
2. General Terms
2.1 Subject matter and duration
Apliteni shall process personal data only for the purpose of providing the Services and only for the duration of the Customer's subscription or until the personal data is deleted in accordance with the retention periods referenced in Schedule 1.
2.2 Instructions
Apliteni shall process personal data solely on documented instructions from the Customer. The configuration the Customer sets within the Lessly platform (extension settings, provider lists, retention settings) constitutes the Customer's documented instructions. Apliteni shall inform the Customer if, in its opinion, an instruction infringes GDPR or other applicable Union or Member State data-protection law, and may suspend processing of that instruction until it is clarified.
2.3 Confidentiality
Apliteni shall ensure that persons authorised to process personal data under this DPA are bound by an appropriate obligation of confidentiality.
2.4 Security measures
Apliteni shall implement and maintain technical and organisational measures appropriate to the risk, including at a minimum:
- encryption of personal data in transit (TLS 1.2+) and at rest;
- cryptographic signing of consent records to ensure integrity and non-repudiation;
- IP-address redaction from telemetry and APM traces before transmission to sub-processors;
- logical isolation of each Customer's data by product;
- access controls limiting internal access to personal data to staff who require it for service delivery;
- regular review of access rights.
2.5 Personal data breach notification
In the event that Apliteni becomes aware of a personal-data breach affecting data processed under this DPA, Apliteni shall:
- notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware of the breach;
- provide in the notification (or as soon as possible thereafter): a description of the nature of the breach; the categories and approximate number of data subjects affected; the categories and approximate volume of personal-data records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach and mitigate its effects.
The Customer remains responsible for any notification obligations towards supervisory authorities or data subjects under Articles 33 and 34 GDPR.
2.6 Assistance with data-subject rights
Apliteni shall assist the Customer, taking into account the nature of the processing, in fulfilling data-subject rights requests (access, rectification, erasure, restriction, portability, objection) to the extent technically feasible. Requests should be submitted through the Customer support channel. Apliteni may charge a reasonable fee for assistance that goes beyond what is technically straightforward.
2.6a Assistance with impact assessments and prior consultation
Apliteni shall assist the Customer, taking into account the nature of the processing and the information available to Apliteni, in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR — including data-protection impact assessments (Article 35) and prior consultation with a supervisory authority (Article 36) — by providing the information and support reasonably necessary in respect of the processing carried out on the platform.
2.7 Audit rights
Upon the Customer's written request (with reasonable notice), Apliteni shall make available all information necessary to demonstrate compliance with this DPA. Apliteni may satisfy an audit request by providing:
- current third-party audit reports (SOC 2 Type II or equivalent) for Apliteni and its sub-processors, where available; or
- facilitation of an inspection carried out by the Customer or an auditor mandated by the Customer, subject to the Customer giving at least 30 days' prior written notice and agreeing to a non-disclosure obligation.
Inspections shall not unreasonably disrupt Apliteni's business operations. Costs of an inspection are borne by the Customer unless the inspection reveals a material non-compliance, in which case costs shall be agreed between the parties.
2.8 Deletion and return of personal data
Upon termination of the Services or written request from the Customer, Apliteni shall delete or return all personal data processed under this DPA, and delete existing copies, unless Union or Member State law requires continued storage. The Customer may export its data at any time via the platform's export functions.
2.9 Sub-processor engagement
Apliteni shall not engage a new sub-processor, or materially change the role of an existing sub-processor, without announcing the change (including the identity of the sub-processor and the nature of the processing) on the public sub-processor list at lessly.com/legal/subprocessors at least 30 days before the new engagement takes effect.
If the Customer objects to the change on reasonable data-protection grounds and Apliteni cannot accommodate the objection, the Customer may terminate the affected Services in accordance with the cancellation terms of the Terms of Service. Apliteni shall impose on sub-processors data-protection obligations equivalent to those in this DPA, by contract or other binding legal act. Apliteni remains liable to the Customer for sub-processors' compliance.
Annex A — Sub-processors
The authoritative list of sub-processors engaged by Apliteni across the Lessly platform and all extensions is published at lessly.com/legal/subprocessors. That page identifies each sub-processor, its role, the categories of personal data shared, its region, and the applicable transfer safeguard, and it announces upcoming changes in accordance with clause 2.9.
Schedule 1 — Processing details
This Schedule applies to the Lessly platform and every extension the Customer has installed and enabled.
- Subject matter: provision of the Lessly platform and installed extensions.
- Duration: the term of the Customer's subscription, plus the deletion/return period in clause 2.8.
- Nature and purposes of processing: hosting, storage, transmission, analysis, and display of Customer data as necessary to provide the Services, as configured by the Customer.
- Categories of data subjects: the Customer's users and staff; the Customer's end users, contacts, and the visitors to the Customer's websites and applications.
- Categories of personal data: account and identity data; content the Customer or its end users submit, deploy, or store on the platform (including, where the corresponding extensions are enabled, consent records, support conversations, contact records, and email addresses); usage and technical data.
- Special categories of data: the Services are not intended for special categories of personal data (Article 9 GDPR); the Customer shall not submit them.
- Retention: as set out in section 6 of the Privacy Policy and the Customer's own retention settings.
- Security measures: clause 2.4 of this DPA.
3. Acceptance
This DPA is incorporated by reference into the Lessly Terms of Service and takes effect automatically for every Customer whose use of the Services involves the processing of personal data, from the date the Customer first uses such a Service, as evidenced by the Customer's acceptance of the Terms of Service. No signature is required.
Customers who require a countersigned copy of this DPA for their records may request one by emailing privacy@lessly.com.
4. General provisions
4.1 Order of precedence
In the event of a conflict between this DPA and the Lessly Terms of Service with respect to data-protection matters, this DPA shall prevail.
4.2 Governing law and jurisdiction
This DPA is governed by the law of the Republic of Estonia, consistent with the Terms of Service. Any dispute between the parties arising out of or relating to this DPA that cannot be resolved through good-faith negotiation will be submitted to the jurisdiction of the courts of Estonia.
This does not restrict the right of data subjects to a judicial remedy under GDPR Article 79, or the competence of supervisory authorities under the GDPR, each of which applies regardless of this clause.
4.3 Amendments
Apliteni may update this DPA from time to time to reflect changes in law, regulatory guidance, or the Services. Material changes will be notified to the Customer at least 30 days before they take effect. Continued use of the Services after the effective date of an updated DPA constitutes acceptance of the updated terms.
4.4 Entire agreement
This DPA, together with Schedule 1 and the sub-processor list referenced in Annex A, constitutes the entire agreement between the parties with respect to the processing of personal data under GDPR Article 28.