Home / Legal / Data Processing Addendum

Data Processing Addendum

Last updated July 17, 2026

Terms of ServicePrivacy PolicyCookie PolicyAcceptable UseData ProcessingSubprocessorsDisclaimer
These terms govern the Limen Systems website and evaluation materials. For a paid engagement, the separately executed agreement controls. This is not legal advice.

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and Limen Systems Holdings, Inc. ("Limen" or "Processor") for the provision of the Limen platform and related services (the "Services"), and governs the processing of personal data carried out under that agreement. It is drafted to meet Article 28 of the GDPR and the UK GDPR. Key takeaways:

  • The customer is the controller; Limen is the processor. In in-perimeter and air-gapped deployments, Limen does not process customer operational data outside the customer's own boundary at all.
  • Processing is on documented instructions only, under confidentiality, with defined security measures (Annex II).
  • Subprocessors are limited and disclosed; in-perimeter architecture keeps the operational-data footprint minimal.
  • Transfers rely on Standard Contractual Clauses and, for the UK, the IDTA/Addendum.
  • Breaches are notified without undue delay; data is returned or deleted at the end of the engagement.
This web version is provided for reference; a countersigned DPA executed as part of a paid engagement controls in the event of any conflict. See also our Privacy Policy and security and sovereignty.

Purpose, structure and order of precedence

This DPA sets out the terms on which Limen, as processor, processes personal data on behalf of the Controller in connection with the Services. It incorporates the Standard Contractual Clauses by reference where cross-border transfers occur.
In the event of conflict, the following order of precedence applies: (1) the Standard Contractual Clauses, where they apply; (2) this DPA; (3) the main agreement between the parties. This web version is a reference copy; the DPA executed by the parties as part of a paid engagement is the operative document.

Definitions

"Personal data," "processing," "controller," "processor," "data subject," "special categories of personal data," and "personal data breach" have the meanings given in the GDPR. "Applicable Data Protection Law" means the GDPR, the UK GDPR, and any other privacy or data-protection law applicable to the processing. "Subprocessor" means any third party engaged by Limen to process personal data on the Controller's behalf. "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission for transfers to third countries, as amended by the UK Addendum where relevant.

Roles of the parties and in-perimeter deployments

For personal data processed under the Services, the Controller determines the purposes and means of processing and Limen acts as processor, processing personal data only on the Controller's documented instructions (including this DPA and the main agreement).
Limen's product is designed to run inside the Controller's own perimeter, the Controller's VPC or a fully air-gapped environment. In these deployments, customer operational data (including any personal data within it) does not leave the Controller's boundary and is not processed on Limen's infrastructure; personally identifying data is masked or tokenised before it reaches any model. To the extent operational data is never transmitted to Limen, Limen does not process that data as a processor at all. This DPA governs any personal data Limen does process on the Controller's behalf, for example, limited support, configuration, or diagnostic data expressly shared with Limen.

Details of processing (Annex I)

The particulars of processing are as follows:
  • Subject matter: provision of the Limen platform and related implementation, support, and operation services.
  • Duration: for the term of the main agreement, plus any period required for return or deletion of data.
  • Nature and purpose: deploying and operating a governed agent over the Controller's systems of record; and, where expressly shared with Limen, processing limited configuration, support, and diagnostic data to deliver and improve the Services.
  • Types of personal data: determined by the Controller; in in-perimeter deployments this remains within the Controller's boundary. Data shared with Limen is limited to business-contact details of the Controller's personnel and any diagnostic or support data the Controller chooses to provide. The Controller instructs Limen not to be provided with special-category data unless separately agreed.
  • Categories of data subjects: the Controller's personnel and authorised users, and any data subjects within data the Controller elects to share with Limen for support.

Limen's obligations as processor

In respect of any personal data it processes on the Controller's behalf, Limen shall, in accordance with Article 28 GDPR:
  • process personal data only on the Controller's documented instructions, including regarding transfers, and inform the Controller if it believes an instruction breaches Applicable Data Protection Law;
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement the technical and organisational measures set out in Annex II below;
  • respect the conditions for engaging subprocessors (see below);
  • assist the Controller, taking into account the nature of the processing, in responding to data-subject requests and in meeting its security, breach-notification, and data-protection-impact-assessment obligations;
  • at the Controller's choice, delete or return personal data at the end of the Services; and
  • make available information necessary to demonstrate compliance and allow for and contribute to audits.

Subprocessors

The Controller grants Limen general authorisation to engage subprocessors, subject to the safeguards below. Limen will impose data-protection obligations on each subprocessor no less protective than those in this DPA and remains liable for its subprocessors' performance.
Because product deployments run inside the Controller's perimeter, the subprocessor footprint for operational data is deliberately minimal, the Controller's own cloud or on-premises infrastructure hosts the deployment. Where Limen processes limited support, configuration, or diagnostic data, its subprocessors may include a cloud infrastructure provider, and business-productivity and communications tools. Website analytics providers (Google Analytics 4 and PostHog) are used for the Limen website only and do not process customer operational data.
Limen will give the Controller advance notice of any intended addition or replacement of a subprocessor and a reasonable opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Controller may terminate the affected Services.

International transfers and Standard Contractual Clauses

Where Limen's processing on the Controller's behalf involves transferring personal data outside the EEA, the UK, or Switzerland to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses (controller-to-processor module) apply and are incorporated by reference, completed with the particulars in Annex I and the security measures in Annex II.
For transfers subject to the UK GDPR, the parties adopt the UK International Data Transfer Addendum to the SCCs; for transfers subject to Swiss law, the SCCs apply with the Swiss amendments. The parties will carry out a transfer-impact assessment and apply supplementary measures where required. In in-perimeter and air-gapped deployments, operational data remains within the Controller's boundary and no such transfer occurs.

Technical and organisational security measures (Annex II)

Limen implements and maintains appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, having regard to the state of the art and the risks of the processing. These measures include:
  • In-perimeter architecture: for product deployments, models and processing run inside the customer's VPC or air-gapped environment; personally identifying data is masked or tokenised before it reaches any model.
  • Encryption: encryption of personal data in transit (TLS) and at rest using industry-standard algorithms and managed keys.
  • Access control: role-based, least-privilege access; unique credentials; multi-factor authentication for administrative and remote access; prompt revocation on role change or departure.
  • Network and application security: segmentation, firewalls, hardened configurations, dependency and vulnerability management, and secure software-development practices.
  • Logging and monitoring: audit logging of privileged actions, tamper-evident where feasible, with alerting and retention appropriate to the environment.
  • Determinism and human control: workflows are modelled as state machines with evaluation gates; consequential writes require two-phase human confirmation; the controller halts to a human rather than improvising.
  • Data minimisation and PII masking: masking or tokenisation before inference, and configuration to process only the personal data necessary for the agreed purpose.
  • Personnel: confidentiality obligations, background checks where lawful, and security-awareness training.
  • Business continuity: backup, recovery, and incident-response procedures proportionate to the deployment.
  • Assurance: Limen is building toward SOC 2 and ISO/IEC 27001 alignment with sector-specific controls; current status is disclosed honestly on request.
Limen reviews and updates these measures over time and will not materially reduce the overall level of protection during the term.

Assistance, data subject requests and DPIAs

Taking into account the nature of the processing, Limen will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). If Limen receives such a request directly, it will, unless legally prohibited, promptly forward it to the Controller and not respond except on the Controller's instructions.
Limen will also provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities where the processing is likely to result in a high risk to data subjects.

Personal data breach notification

Limen will notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on the Controller's behalf, and will provide, in phases as it becomes available, information reasonably necessary for the Controller to meet its own notification obligations, including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it and mitigate harm.
Limen will cooperate with the Controller and take reasonable steps to contain, investigate, and remediate the breach. Notification is not an acknowledgement of fault or liability.

Audits and inspections

Limen will make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor it mandates.
The parties will agree reasonable scope, timing, and confidentiality in advance; audits will take place on reasonable notice, no more than once a year absent a specific concern or a regulator's requirement, during business hours, and in a manner that does not compromise the security of other customers. Limen may satisfy audit requests in whole or part by providing recognised third-party attestations or reports where available.

Return and deletion of personal data

On termination or expiry of the Services, Limen will, at the Controller's choice, delete or return all personal data it processes on the Controller's behalf, and delete existing copies unless retention is required by law. In in-perimeter and air-gapped deployments, operational data resides within the Controller's own environment and remains under the Controller's control throughout.
Where the engagement concludes with a Transfer under the Build-Operate-Transfer model, the Controller takes ownership of the platform, the fine-tuned weights, and the infrastructure; data handling on transfer is governed by the main agreement. See how ownership works.

Liability and duration

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement. This DPA takes effect on the effective date of the main agreement and continues for as long as Limen processes personal data on the Controller's behalf.

Contact and execution

To request an executable copy of this DPA for signature, or to discuss its terms, contact hello@limensystems.com. Data-protection questions may also be sent to hello@limensystems.com, and security questions to hello@limensystems.com.

Questions about this document: hello@limensystems.com