Data Processing Agreement (DPA)
Effective date: 9 August 2026 | Version: 2.0
1. Parties and document precedence
1.1 Parties
This DPA forms part of the agreement between the Customer identified in the Order and:
Business name: Lemric Dominik Łabudziński
Address: Weteranów 74/3, 05 250 Radzymin, Poland
Polish tax ID (NIP): 5272448444
Statistical number (REGON): 141491900
| Contact | Address |
|---|---|
| Privacy and DPA | privacy@lemric.com |
1.2 Roles
- The Customer is the controller of personal data placed in its Organisation.
- Lemric is the processor (Article 28 GDPR).
- If the Customer processes data for another controller, Lemric acts as a further processor and the Customer confirms it is authorised to engage Lemric.
1.3 Precedence
On entrusted personal data, this DPA prevails over the Service Terms. An Order may supplement instructions but must not lower the protection required by applicable data protection law.
2. Definitions
- Controller: the Customer for data placed in the Organisation.
- Processor / Lemric: Lemric Dominik Łabudziński.
- Entrusted Data: personal data processed by Lemric on the Customer’s behalf in the Service.
- Organisation: the Customer’s workspace.
- Service: Lemric’s help centre, customer portal, and service desk.
- Subprocessor List: the current list of subprocessors published in the Service.
- Personal data breach: a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Entrusted Data.
- GDPR: Regulation (EU) 2016/679.
3. Subject matter, nature, purpose, and duration
3.1 Subject matter
The subject matter is processing needed to provide and secure the help centre, customer portal, and service desk configured by the Customer.
3.2 Nature: operations
Operations may include:
- collection, receipt, recording, organisation,
- storage, encryption, retrieval, consultation, display,
- transmission, combination, restriction,
- copying, export, erasure, and destruction.
3.3 Purpose
The purpose is:
- account and permission management,
- forms, tickets, messages, and attachments,
- queues, workflows, and service levels,
- automation, help content, and audit records,
- Customer chosen Jira and webhook integrations,
- support, security, and continuity.
Lemric does not sell Entrusted Data or use it for its own advertising.
3.4 Duration
Processing lasts for the period the Service is provided, and afterwards only as needed to:
- carry out a documented instruction to return or delete,
- complete the lifecycle of existing copies used to restore the Service,
- comply with law or establish and defend claims.
4. Categories of data subjects and types of data
4.1 Data subjects
These may include Customer representatives, administrators, staff, contractors, customers, requesters, portal users, ticket participants, and other persons named in Customer content.
4.2 Types of data
| Category | Examples |
|---|---|
| Identity and contact | Names, electronic mail address, organisation data, roles, identifiers |
| Accounts and access | Account, authentication, and permission data |
| Support content | Ticket subjects, messages, form answers, notes, communication history |
| Files | Attachments, file names, metadata |
| Operational | SLA, workflows, automation, notifications, activities |
| Technical and audit | IP addresses, session and device metadata, security events, audit records |
| Customer integrations | Jira references, webhook content chosen by the Customer |
| Other | Fields or content lawfully configured and provided by the Customer |
4.3 Special categories
Special category data and data about criminal convictions are not intended for ordinary use. The Customer must not provide them unless processing is lawful, necessary, and covered by documented safeguards.
5. Documented instructions
- Lemric processes Entrusted Data only on the Customer’s documented instructions, including those arising from the agreement, Order, Organisation configuration, and authorised support requests.
- Instructions also cover transfers of data unless this DPA provides otherwise.
- If European Union or Member State law requires other processing, Lemric will inform the Customer before starting it unless the law forbids that notice for important public interest reasons.
- Lemric will promptly inform the Customer if, in Lemric’s opinion, an instruction infringes applicable data protection law. Lemric may pause the affected action until the parties agree a lawful approach.
- The Customer is responsible for the lawfulness, accuracy, and scope of instructions, legal bases, information given to individuals, and permissions granted to users and integrations.
6. Confidentiality and authorised persons
- Lemric ensures that persons authorised to process Entrusted Data have committed to confidentiality or are under an appropriate statutory duty of confidentiality.
- Access is limited by role and need.
- Access is reviewed where appropriate and withdrawn when no longer needed.
7. Security (Article 32 GDPR)
7.1 Technical and organisational measures (TOMs)
Taking into account the state of the art, implementation cost, scope, and risk, Lemric maintains measures appropriate to the risk:
| Measure | Description |
|---|---|
| Organisation isolation | Logical isolation of Organisation data |
| Access control | Roles, permissions, protection of authentication data |
| Row access control | Restriction of access in the database |
| Encryption in transit | TLS / HTTPS |
| Encryption of selected data | Encryption of selected stored personal data |
| Attachment encryption | Attachments and exports in Cloudflare R2 encrypted by the application |
| Audit | Logging of selected privileged operations; audit archive protected separately |
| Abuse protection | Limits and monitoring |
| Incidents | Security incident handling procedures |
Technical details may change if overall protection remains appropriate to the risk and is not materially weakened.
7.2 Customer duties
The Customer is responsible for assigning roles, protecting end devices, integration credentials, lawful configuration, and promptly removing access that is no longer needed.
Lemric assists the Customer, taking into account the information available to Lemric and the nature of processing, in meeting security duties under Article 32 GDPR.
8. Subprocessors (Article 28 GDPR)
8.1 General authorisation
The Customer grants general written authorisation to use the subprocessors listed in the Subprocessor List: https://lemric.com/en/legal/subprocessors
8.2 Notice and objection
- Lemric will give electronic notice before adding or replacing a party that will process Entrusted Data.
- Lemric will allow a reasonable period for a specifically reasoned objection on data protection grounds.
- The parties will try in good faith to resolve the objection.
- If there is no reasonable alternative, the Customer may stop using the affected Service before the change takes effect.
- An urgent change needed for security or continuity may take effect earlier, with notice given as soon as reasonably possible.
8.3 Responsibility for subprocessors
- Lemric imposes on each subprocessor essentially the same data protection obligations as apply to Lemric under this DPA (Article 28(4) GDPR).
- Lemric remains responsible to the Customer for the subprocessor’s performance of those duties to the extent required by Article 28 GDPR.
8.4 Recipients chosen by the Customer
Jira and webhook destinations chosen by the Customer are recipients acting on the Customer’s instruction, not permanent Lemric subprocessors.
9. Assistance with data subject rights
- Taking into account the nature of processing, Lemric assists the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests for access, rectification, erasure, restriction, portability, and objection.
- If Lemric receives a request about Entrusted Data, it will forward it to the Customer without undue delay and will not give a substantive reply without the Customer’s instruction unless required by law.
10. Personal data breaches (Article 33 GDPR)
- Lemric notifies the Customer without undue delay after becoming aware of a personal data breach affecting Entrusted Data.
- As information becomes available, the notice describes: the nature of the breach, the individuals and records affected (where known), likely consequences, measures taken or proposed, and a contact for further information.
- Lemric may provide information in stages and takes reasonable steps to contain and investigate the incident.
- Notice alone is not an admission of fault or liability.
11. Impact assessments and prior consultation
- Lemric provides reasonable assistance with data protection impact assessments (DPIA) and prior consultation with the supervisory authority where the Customer’s processing requires them.
- Assistance takes into account the nature of processing and information available to Lemric.
- Extra work beyond ordinary support may be chargeable if the parties agree in advance.
12. Return, deletion, and backups
- After the Service ends, Lemric will, according to the Customer’s choice in a documented request, return available Entrusted Data or delete them unless law requires further retention.
- The request must be made when Lemric can reasonably identify and access the relevant data.
- Lemric does not provide self service export after the agreement ends.
- If at Service end data sit in a copy used to restore the Service, deletion happens by securely overwriting or deleting that copy and may not be immediate. Until then the data remain out of ordinary use and may be restored only for continuity, security, or legal duty.
- Legal holds, mandatory retention, and evidence needed for claims may delay deletion.
- The Customer should not assume Organisation retention settings replace a specific end of Service instruction.
13. Information and audits
- Lemric makes available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allows audits, including inspections, by the Customer or an independent auditor authorised by the Customer.
- An audit must be proportionate, protect other customers and confidential information, avoid unnecessary disruption, and usually start from existing documentation.
- Unless an incident, authority request, or credible evidence justifies otherwise, the Customer gives reasonable advance notice and conducts no more than one audit in twelve months.
- The Customer bears its own audit costs; exceptional assistance may be chargeable if agreed in advance.
- Lemric will promptly inform the Customer if an audit instruction would infringe applicable data protection law.
14. International transfers
- Lemric does not transfer Entrusted Data outside the European Economic Area unless on the Customer’s documented instruction or as needed to use an authorised subprocessor with a lawful transfer basis in place.
- Where required, before a transfer the parties will document an adequacy decision, appropriate contractual safeguards, or another lawful basis, plus any necessary supplementary measures.
- This DPA does not state that standard contractual clauses or a transfer impact assessment are already prepared for every possible destination.
- The Customer is responsible for transfers to Jira, webhook destinations, and other recipients it chooses.
- Lemric will provide information it holds that the Customer reasonably needs for assessment.
15. Customer duties
The Customer ensures:
- lawfulness of its own processing,
- lawfulness of instructions,
- adequacy and limitation of Entrusted Data to what is needed,
- information to individuals, legal bases, and handling of their requests as controller,
- that instructions are given to Lemric through authorised channels.
16. Contact
- DPA notices and instructions: privacy@lemric.com
- General legal notices: legal@lemric.com
- Subprocessor List: https://lemric.com/en/legal/subprocessors
- Terms: https://lemric.com/en/legal/terms
- Privacy Policy: https://lemric.com/en/legal/privacy
Customer details, Service scope, and further instructions are set out in the Order and Organisation configuration.
Effective date: 9 August 2026
Document version: 2.0