Skip to main content

Lefty - Data Processing Addendum

Written by Abed Tabbara

THIS CONTROLLER-TO-PROCESSOR DATA PROCESSING ADDENDUM is an addendum and exhibit to the Subscription Agreement entered into between Lefty and the Customer and sets forth the obligations and rights of the Parties regarding Lefty's processing of the Customer Data pursuant to such Subscription Agreement with effect from the commencement of the Subscription Agreement.

WHEREAS

(A) This Addendum is applicable in connection with the provision of Services by Lefty to the Customer pursuant to the Subscription Agreement.

(B) In respect of the Personal Data contained on the Lefty Platform, Lefty is the data controller of the data it collects and holds on such Lefty Platform. Once the Customer accesses the Lefty Platform, the Customer also becomes an independent data controller in respect of the data it accesses and uses on its company directory and for its analytics, as the Customer is able to determine the purposes and means of processing the data alone. Such activities of the Parties are governed by the terms of the Subscription Agreement, and not this Addendum.

(C) From time to time, the Customer may however contribute certain Customer Data to the Lefty Platform and, where Lefty is not considered to be a bona fide independent controller of such Customer Data, Lefty shall process such Customer Data on the Customer's behalf and on the Customer's instructions. In connection with such processing activities, the Parties therefore agree to implement this Addendum to the Subscription Agreement to comply with the requirements of the current legal framework in relation to data processing and, in particular, with the GDPR.

(D) In this Addendum, the Customer, to the extent it is from time to time the controller of the Customer Data being processed by Lefty as a processor pursuant to the GDPR, shall be the "Controller" and Lefty to the extent it is from time to time the processor of the Customer Data pursuant to the GDPR shall be the "Processor".


1. DEFINITIONS AND INTERPRETATION

1.1 Unless otherwise defined herein, capitalised terms and expressions shall be as defined in the Subscription Agreement, and otherwise shall have the following meaning:

  • "Addendum" means this Data Processing Addendum and all Schedules;

  • "Applicable Data Protection Laws" means European Data Protection Laws and all data and/or information protection laws and regulations applicable to any member of the Lefty Group and/or the Customer's Group from time to time in place;

  • "Customer" means the party to the Subscription Agreement which is therein defined as the Customer or the Client or otherwise stated to be the receiver of the Services from Lefty;

  • "Customer Data" shall be as defined in the Subscription Agreement, to the extent such data comprises Personal Data which is processed by Lefty as the Processor hereunder and pursuant to the GDPR;

  • "Data Subject" means a natural person identified or identifiable by, in or using the Customer Data either (i) connected to any member of the Controller's Group, or (ii) featuring on the Lefty Platform, in each case about whom Personal Data is received, held or processed by the Processor or any member of the Processor's Group, including without limitation influencers, talents, employees, officers, advisers, contractors, suppliers, clients and/or business contacts;

  • "European Data Protection Laws" means any and all of EU Data Protection Laws, UK Data Protection Laws and Swiss Data Protection Laws;

  • "European Personal Data" means any Customer Data comprised within the Lefty Platform that is subject to (i) the GDPR; (ii) UK Data Protection Laws; and/or (iii) the Swiss Data Protection Laws;

  • "EU Data Protection Laws" means (i) the GDPR; (ii) EU Directive 2002/58/EC; and (iii) the national laws of each Member State made under, pursuant to, or that implement (i) or (ii), or which otherwise relate to the processing of Personal Data; in each case, as amended or superseded from time to time;

  • "EEA" means the European Economic Area (EU Member States plus Iceland, Liechtenstein and Norway);

  • "GDPR" means EU General Data Protection Regulation 2016/679 and any national implementing laws, and the terms "controller", "processor" and "processing" (and derivations thereof) shall be as defined in the GDPR;

  • "Group" means, in respect of the applicable Party, such Party and each of its group undertaking from time to time, and "Group Company" and "member of the Group" shall be construed accordingly;

  • "Lefty" means the party to the Subscription Agreement which is therein defined as Lefty or otherwise stated to be the provider of the Services to the Customer, being either Modern Agency SAS or Gaucher LLC, in each case trading as "Lefty";

  • "Lefty Platform" means the platform hosted and maintained by Lefty in respect of the Services;

  • "Member State" shall mean a state which is a member of the EEA;

  • "Personal Data" means any information identifying a Data Subject or information relating to a Data Subject that can be identified (directly or indirectly) from that data alone or in combination with other identifiers possessed or reasonably accessible which is Processed by the Processor on behalf of the Controller pursuant to or in connection with the Subscription Agreement;

  • "Personal Data Breach" shall have the same meaning as in the GDPR;

  • "Restricted Transfer" means (i) where the GDPR applies, a transfer of Personal Data to a country outside of the EEA which is not subject to an adequacy determination by the European Commission (an "EU Restricted Transfer"); (ii) where the UK GDPR applies, a transfer of Personal Data to any other country which is not subject to or based on adequacy regulations pursuant to Section 17A of the United Kingdom Data Protection Act 2018 (a "UK Restricted Transfer"); and (iii) where the Swiss DPA applies, a transfer of Personal Data to any other country which is not subject to an applicable adequacy determination (a "Swiss Restricted Transfer");

  • "Services" means the services Lefty has agreed to provide to the Customer pursuant to the Subscription Agreement;

  • "Standard Contractual Clauses", "SCCs" or "Clauses" means (i) where the GDPR or the Swiss DPA applies, the contractual clauses annexed to the European Commission's Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council ("EU SCCs"); and (ii) where the UK GDPR applies, the "International Data Transfer Addendum to the EU Commission Standard Contractual Clauses" issued by the Information Commissioner under section 119A(1) of the DPA 2018 ("UK Addendum"), as well as any alternative or successor clauses thereto, which are recognised by the European Commission or a relevant Supervisory Authority and which may be adopted by one of the Parties hereunder;

  • "Sub-Processor" means any person appointed by or on behalf of the Processor to process Personal Data on behalf of the Processor in connection with this Addendum. The Sub-Processors engaged as at the date of this Addendum are listed in Schedule 4 (Authorised Sub-Processors);

  • "Subscription Agreement" means the contract(s) entered into between Lefty and the Customer in respect of the Services;

  • "Supervisory Authority" means a data protection or other regulatory body or public agency with the jurisdiction to enforce Applicable Data Protection Laws;

  • "Swiss Data Protection Laws" means (i) the Swiss Federal Act on Data Protection of 25 September 2020 and its corresponding ordinances ("Swiss DPA"); and (ii) any other national laws in Switzerland applicable (in whole or in part) to the processing of Personal Data; in each case, as amended or superseded from time to time;

  • "UK Data Protection Laws" means (i) the GDPR as it forms part of UK law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR"); (ii) the Privacy and Electronic Communications (EC Directive) Regulations 2003 as it continues to have effect under section 2 of the European Union (Withdrawal) Act 2018; (iii) the Data Protection Act 2018 (the "DPA 2018"); and (iv) any other laws in the UK made under, pursuant to, or that implement (i), (ii) or (iii), or which otherwise relate to the processing of Personal Data; in each case, as amended or superseded from time to time.

1.2 Unless the context requires otherwise, words and expressions defined in or having a meaning provided by the GDPR shall have the same meaning in this Addendum.

1.3 Unless the context requires otherwise, references in this Addendum to the singular shall include the plural and vice versa; and any statute or statutory provision shall be deemed to include any instrument, order, regulation or direction made or issued under it and shall be construed so as to include a reference to the same as it may have been, or may from time to time be, amended, modified, consolidated, re-enacted or replaced.

1.4 The headings in this Addendum are for convenience only and shall not affect its meaning. References to a "clause", "Schedule" or "paragraph" are (unless otherwise stated) to a clause of and Schedule to this Addendum and to a paragraph of the relevant Schedule. The Schedules form part of this Addendum and shall have the same force and effect as if expressly set out in the body of this Addendum.

2. DATA PROTECTION

2.1 Each Party agrees to comply with all Applicable Data Protection Laws in connection with the Customer Data. This clause is in addition to, and does not relieve, remove or replace, a Party's obligations or rights under Applicable Data Protection Laws.

2.2 Schedule 1 sets out the scope, nature and purpose of processing by Processor, the duration of the processing and the types of Customer Data and categories of Data Subject.

3. PROCESSING OF PERSONAL DATA

The Processor hereby irrevocably and unconditionally agrees and undertakes:

3.1 to comply with Applicable Data Protection Laws in respect of the applicable Processing of Customer Data;

3.2 to Process such Customer Data only on the instructions of the Controller including with regard to transfers of Customer Data to a third country or an international organisation, unless required to do so by EU, Member State, UK and/or Swiss law to which the Processor is subject or as documented herein. In such a case the Processor shall inform the Controller without delay of that legal requirement before Processing, unless EU or Member State law prohibit such information;

3.3 to ensure all persons authorised to process Customer Data for or on behalf of the Processor are subject to appropriate confidentiality obligations;

3.4 that it shall, unless prohibited by law, immediately inform the Controller if, in its reasonable opinion, an instruction of the Controller under clause 3.2 infringes Applicable Data Protection Laws;

3.5 to ensure that it has in place appropriate technical and organisational measures, in such a manner that Processing by the Processor (or any member of the Processor's Group and/or any Sub-Processors) meets the requirements of Applicable Data Protection Laws. Where EU Data Protection Laws apply, the Processor must comply with Article 32 of GDPR;

3.6 to assist the Controller in ensuring compliance with its obligations under the Applicable Data Protection Laws with respect to Data Subject rights, security, Personal Data Breach notifications, data protection impact assessments, deletion or return of data and prior consultations with supervisory authorities or regulators;

3.7 to make available all information reasonably necessary to demonstrate compliance and contribute to audits. The Processor may satisfy such obligations by providing up-to-date independent third-party audit reports/certifications and responses to reasonable security questionnaires;

3.8 to cooperate, on request, with competent Supervisory Authorities in relation to Processing under this Addendum;

3.9 to notify the Controller without undue delay and in accordance with Applicable Data Protection Laws on becoming aware of (i) a Personal Data Breach or potential breach by it, any member of the Processor's Group or any Sub-Processor or (ii) any request from a Data Subject under any Applicable Data Protection Laws in respect of its Customer Data. The Processor shall reasonably assist the Controller on handling the Personal Data Breach or Data Subject request and shall provide the Controller with all reasonably necessary information regarding the Personal Data Breach or Data Subject request;

3.10 at the written direction of the Controller, to delete or return all of the Customer Data (including copies thereof) unless required by EU or Member State laws to store the Customer Data. Unless directed otherwise by the Controller, pseudonymised Customer Data may be retained by the Processor subject to the safeguards and derogations in Article 89 of GDPR;

3.11 to maintain and, upon request, make available complete and accurate records and information to demonstrate its compliance with the obligations set out in this Clause 3 and this Addendum;

3.12 where the Controller requests assistance in connection with Data Subject rights (including without limitation right of access, rectification, erasure, restriction of Processing and to object to Processing), to reasonably co-operate to assist the Controller (at Controller's cost) to comply with its obligations under Applicable Data Protection Laws;

3.13 promptly notify Controller (unless legally prohibited) of any binding request from a public authority for disclosure of Customer Data, and will challenge unlawful or disproportionate requests and seek to narrow scope, and will disclose only the minimum necessary; and

3.14 where US state privacy laws apply, to act as a service provider and processor, not sell or share such applicable Customer Data, and not retain, use or disclose it for any purpose other than providing the Services and/or as permitted by law.

4. SUB-PROCESSING

4.1 The Controller authorises the Processor to engage the third-party Sub-Processors listed in Schedule 4 to process the Customer Data as required in connection with the provision of the Services pursuant to the Subscription Agreement, provided that:

  • 4.1.1 the Processor imposes data protection terms on any Sub-Processor it appoints that require it to protect the Customer Data to the standard required by Applicable Data Protection Laws and consistent with this Addendum; and

  • 4.1.2 the Processor remains liable for any breach of this Addendum that is caused by its Sub-Processors.

4.2 The Processor shall give the Controller at least 30 days' prior written notice of the intended addition or replacement of any Sub-Processor, by updating Schedule 4 and notifying the Controller's designated contact.

4.3 If the Controller objects on reasonable grounds relating to data protection, the Processor will discuss with the Controller (in each case acting reasonably and in good faith) whether it is possible to appoint or replace the Sub-Processor in a way that objectively resolves the Controller's objection. If this is not reasonably possible, then:

  • 4.3.1 the Processor may (in its sole discretion) choose either not to appoint or replace the Sub-Processor, or to suspend or terminate the Subscription Agreement with one month's written notice (without prejudice to any fees incurred by the Controller up to and including the date of suspension or termination); or

  • 4.3.2 the Controller may choose to terminate the Subscription Agreement with one month's written notice to the Processor.

5. CROSS BORDER TRANSFERS OF CUSTOMER DATA

5.1 Restricted Transfers from Customer to Lefty

To the extent that any transfer of Customer Data from Customer to Lefty is a Restricted Transfer, the SCCs shall be incorporated into this Addendum and apply as follows:

5.1.1 EU Restricted Transfers

Where the Restricted Transfer is an EU Restricted Transfer, the EU SCCs will apply between the Controller and the Processor as follows:

  • Module Two will apply (unless Customer is a Processor and Lefty is a sub-Processor, in which case Module Three will apply);

  • In Clause 7, the optional docking Clause will apply;

  • In Clause 9, Option 2 will apply, and the time period for prior notice of sub-Processor changes shall be 30 days;

  • In Clause 11, the optional language will not apply;

  • In Clause 17, Option 1 will apply, and the EU SCCs will be governed by French law;

  • In Clause 18(b), disputes shall be resolved before the courts of Paris;

  • In Annex I: Parts A and B shall be deemed completed with the information set out in Schedule 2 to this Addendum; and Part C shall be deemed completed in accordance with the criteria set out in Clause 13(a) of the EU SCCs; and

  • Annex II shall be deemed completed with the security measures set out in Schedule 3 to this Addendum.

5.1.2 UK Restricted Transfers

Where the Restricted Transfer is a UK Restricted Transfer, the UK Addendum will apply between Customer and Lefty as follows:

  • The EU SCCs, completed as set out above, shall apply between Customer and Lefty, and shall be modified by the UK Addendum (completed as set out below); and

  • Tables 1 to 3 of the UK Addendum shall be deemed completed with relevant information from the EU SCCs, completed as set out above, and the options "Exporter" and "Importer" shall be deemed checked in Table 4. The start date of the UK Addendum (as set out in Table 1) shall be the date of the Subscription Agreement.

5.1.3 Swiss Restricted Transfers

Where the Restricted Transfer is a Swiss Restricted Transfer, the EU SCCs will apply between Customer and Lefty as set out above with the following modifications:

  • References to "Regulation (EU) 2016/679" shall be interpreted as references to the Swiss DPA;

  • References to specific Articles of "Regulation (EU) 2016/679" shall be replaced with the equivalent article or section of the Swiss DPA;

  • References to "EU", "Union", "Member State" and "Member State law" shall be replaced with references to "Switzerland" or "Swiss law" (as applicable);

  • The term "member state" shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (i.e., Switzerland);

  • Clause 13(a) and Part C of Annex I are not used, and the "competent supervisory authority" is the Swiss Federal Data Protection and Information Commissioner;

  • References to the "competent supervisory authority" and "competent courts" shall be replaced with references to the Swiss Federal Data Protection and Information Commissioner and applicable courts of Switzerland; and

  • In Clause 17, the EU SCCs shall be governed by the laws of Switzerland.

5.2 Restricted Transfers by Lefty

5.2.1 The Processor will not make a Restricted Transfer of the Customer Data to a recipient in another country unless it has done all such things as are necessary to ensure that the Restricted Transfer is compliant with European Data Protection Laws. Such measures may include transferring the Data to a recipient in a country that is deemed to provide adequate protection for Personal Data under European Data Protection Laws or to a recipient that has executed Standard Contractual Clauses with the Processor in accordance with European Data Protection Laws.

5.2.2 To the extent Lefty is deemed to be an independent controller of any Customer Data ("Controlled Customer Data"), it will:

  • (a) comply with the terms of the Subscription Agreement and European Data Protection Laws in respect of such role as a Controller of such Controlled Customer Data; and

  • (b) to the extent Lefty's access to such Controlled Customer Data is deemed a Restricted Transfer, Lefty agrees to comply with the EU Module 1 SCCs (as defined in the Subscription Agreement) in respect of such European Personal Data (including the UK Addendum set out therein in respect of UK-origin data and the Swiss Addendum set out therein in respect of Swiss-origin data).

6. TERM

6.1 This Addendum shall continue in force for as long as any of the Customer Data is Processed by the Processor and/or any member of its Group and/or any of its respective Sub-Processors.

7. DELETION OR RETURN OF CUSTOMER DATA

7.1 The Processor shall promptly and in any event within 30 days of the date of cessation of any Services involving the Processing of the Customer Data and payment of all fees and/or expenses, delete and procure the deletion of all copies of such Customer Data so Processed. Full deletion of such Customer Data from every backup, including encrypted off-site backup archives, is guaranteed within one month, consistent with the deletion commitments described in Schedule 3.

8. GENERAL

8.1 This Addendum is subject to the non-conflicting terms of the Subscription Agreement. With regard to the subject matter of this Addendum, if inconsistencies between the provisions of this Addendum and the Subscription Agreement arise, the provisions of this Addendum shall prevail with regard to the Parties' data protection obligations.

8.2 Except to the extent prohibited by applicable law, the total aggregate liability of the Processor and its affiliates (including any liability arising from acts or omissions of its sub-processors) for any breach of this Addendum will be subject to the aggregate limitation of liability set out in the Subscription Agreement between the Parties. If no aggregate liability limit is specified in the Subscription Agreement, the total liability of the Processor and its affiliates under or in connection with this Addendum will be limited to two (2) times the total fees paid by the Customer under the Subscription Agreement in the twelve (12) months preceding the event giving rise to the claim.

8.3 Except to the extent prohibited by applicable law, in no event shall either Party be liable to the other for any indirect, incidental, special, punitive, or consequential damages, including but not limited to lost profits, loss of use, loss of data, or interruption of business, whether under any theory of contract, tort, strict liability, or otherwise, even if advised of the possibility of such damages. This exclusion is in addition to, and not in place of, any other limitation or exclusion of liability provided in the Subscription Agreement.

8.4 All notices and communications given under this Addendum must be in writing and will be delivered personally or sent by post, and sent by email, to the postal and email addresses set out in the Subscription Agreement (or, for the Processor in respect of privacy and data protection matters, privacy@lefty.io), or such other address as notified from time to time by the Party changing address.

8.5 No variation of this Addendum shall be effective unless made in writing signed by or on behalf of each Party and expressed to be such a variation.

9. GOVERNING LAW AND JURISDICTION

9.1 This Addendum is governed by the laws of France.

9.2 Any dispute arising in connection with this Addendum, which the Parties will not be able to resolve amicably, will be submitted to THE EXCLUSIVE JURISDICTION OF THE COURTS OF PARIS, even in the event of multiple defendants and/or warranty claims.


SCHEDULE 1: DATA PROCESSED

1. Scope

1.1 In connection with the provision of Services by Lefty to the Client, Lefty may from time to time act as a Processor of Customer Data.

1.2 As agreed in the Subscription Agreement, in respect of the Personal Data contained on the Lefty Platform, Lefty is the data Controller of the data it collects and holds on such Lefty Platform. Once the Customer accesses the Lefty Platform, the Customer also becomes an independent data Controller in respect of the Personal Data it accesses and uses on its company directory and for its analytics, as the Customer is able to determine the purposes and means of processing the Personal Data alone.

1.3 For the avoidance of doubt, this Addendum therefore only applies to situations where the Customer gives specific instructions to Lefty to process Customer Data for which the Customer is the Controller as listed hereafter. In respect of such Customer Data, Lefty will comply with this Addendum and the Customer's reasonable instructions and requirements relating to any processing activities pursuant to this Addendum.

2. Types and categories of Personal Data and purpose of processing

  • Category of Data Subject: Influencers listed on the Lefty Platform, including Lefty campaigns and directory.

  • Type of Data Subject: Social media influencers, talents, KOLs, content creators, industry experts and VIPs ("Influencers").

  • Categories of Personal Data: "Customer Data", being Personal Data from Influencers entered or contributed by Customer, including without limitation names and handles, bio and interests, public posting activity, public conversations, engagement, followers and follower counts, audience analytics. To the extent the Customer uses the Lefty Platform to process payments, the Customer Data may include such payment and account information.

  • Purpose: Providing the Services and permitting the Customer to set up and manage campaigns on the Lefty Platform and keep track of brand ambassadors.

3. Duration of the processing

3.1 For the length of time the Services are being provided and for such time thereafter as is required by law or regulation to be retained or as retained pursuant to bona fide disaster recovery procedures.


SCHEDULE 2: DATA PROCESSING SCHEDULE

PART A: LIST OF PARTIES

Customer and Data Exporter

  • Name: The Customer company name as set out in the Subscription Agreement.

  • Address: The Customer details as set out in the Subscription Agreement.

  • Contact person's name, position and contact details: The Customer details as set out in the Subscription Agreement and/or available in their Lefty Platform administration details.

  • Activities relevant to the data transferred under the SCCs: Contributing the Customer Data for the purposes of receiving the Services pursuant to the Subscription Agreement.

  • Signature and Date: This Addendum is deemed executed upon execution of the Subscription Agreement.

  • Role: Controller (unless the Customer is a Processor on behalf of a third-party Controller, in which case it shall be a Processor).

Processor and Data Importer

  • Name: The Lefty company name as set out in the Subscription Agreement.

  • Address: The Lefty details set out in the Agreement.

  • Contact person's name, position and contact details: privacy@lefty.io

  • Activities relevant to the data transferred under the SCCs: Receiving the Customer Data for the purposes of providing the Services pursuant to the Subscription Agreement.

  • Signature and Date: This Addendum is deemed executed upon execution of the Subscription Agreement.

  • Role: Processor.

PART B: DESCRIPTION OF PROCESSING AND TRANSFER

  • Categories of Data Subjects whose Personal Data is processed and transferred: Social media influencers, talents, KOLs, content creators, industry experts and VIPs (together, "Influencers").

  • Categories of Personal Data processed and transferred: "Customer Data", being Personal Data from Influencers entered or contributed by Customer, including without limitation: names and handles, bio and interests, public posting activity, public conversations, engagement, followers and follower counts, audience analytics. To the extent the Customer uses the Lefty Platform to process payments, the Customer Data may include such payment and account information. Customer Data is stored and processed within the European Union, on infrastructure located in Germany (Falkenstein, Nuremberg) and Finland (Helsinki), as described in Schedule 3. Limited categories of data are processed by the Sub-Processors listed in Schedule 4, under the safeguards stated there.

  • Sensitive data transferred (if applicable): Not applicable, unless Customer submits Sensitive Data in its use of the Services and/or the Lefty Platform pursuant to the Subscription Agreement, save that to the extent the Customer uses the Lefty Platform to process payments, the Customer Data may include such payment and account information which shall be kept secure by the Customer and Lefty.

  • The frequency of the transfer: Continuous during subscription to the Lefty Platform pursuant to the Subscription Agreement.

  • Nature of the processing: Data collection, recording, organisation, structuring, storage and analysis.

  • Purpose(s) of the processing, transfer and further processing: In connection with the receipt of the Services, in particular to enable the Customer to discover, evaluate, and manage influencer campaigns, including social listening, analytics, and reporting and, where applicable, to handle and process payments.

  • The period for which the Personal Data will be retained: The period of access to the Platform during the term of the Subscription Agreement. The data importer will retain EU personal data no longer than necessary for the stated purposes following termination or expiry of the Subscription Agreement.

  • For transfers to (sub-) processors: The subject matter, nature and duration of the processing are as set out above.

PART C: COMPETENT SUPERVISORY AUTHORITY

  • Where the EU GDPR applies: The competent EU supervisory authority shall be determined by reference to the place of establishment of the Customer in accordance with Clause 13 of the Standard Contractual Clauses.

  • Where the UK GDPR applies: The Information Commissioner's Office.


SCHEDULE 3: TECHNICAL AND ORGANISATIONAL MEASURES (TOMs)

The following measures are implemented by Lefty for the Lefty Platform. They are reviewed at least annually.

1. Hosting and data residency

  • All live applications and Customer Data are hosted on dedicated servers operated by Hetzner Online GmbH, in datacenters located in Falkenstein and Nuremberg (Germany) and Helsinki (Finland), all within the European Union.

  • Encrypted backups are stored with Backblaze in its Amsterdam (Netherlands, EU) datacenter.

  • Physical security is ensured by the datacenter operators (Hetzner: ISO 27001; Backblaze: SOC 2 Type 2, operating in ISO 27001-certified data centres).

2. Encryption

  • All data in transit is encrypted using TLS 1.2 or above (TLS 1.3 preferred), including all connections between internal services, which additionally enforce mutual TLS with per-host client certificates issued by an internal certificate authority rotated on a dated cycle.

  • Customer passwords are hashed with Argon2id and unique salts; passwords are never stored or transmitted in clear form. Single sign-on (SAML 2.0) is available.

  • Personally identifiable information is encrypted at rest. Database backups are encrypted before upload to off-site storage.

3. Network security

  • Public traffic to the Lefty API transits Cloudflare, providing edge firewalling, managed WAF rulesets and L3/L4/L7 DDoS mitigation, complemented by Hetzner's provider-level DDoS protection.

  • Every server runs a host firewall (ufw) with a default-deny inbound policy and an explicit per-host allow-list. Inter-server traffic transits a private mesh VPN. fail2ban runs on every production server for log-based intrusion prevention.

  • SSH access is key-only (no passwords, no root login) with a named-user allow-list.

4. Access control

  • Production data access by engineers requires senior staff approval, is limited to specific debugging needs, and bulk exports are prohibited. Support (impersonation) sessions are performed at the customer's request only, audited, and time-limited.

  • Access to third-party services is provisioned on corporate accounts and terminated on the employee's last day. Access rights are reviewed quarterly.

5. Secure development and change management

  • Every code change goes through mandatory peer review on a merge request before reaching the main branch; automated test suites run in continuous integration; static analysis (self-hosted SonarQube) includes security hotspots.

  • Infrastructure is managed as code (Ansible): firewall policies, SSH hardening and TLS configuration are version-controlled, peer-reviewed and auditable.

  • Operating system security patching is automated weekly across the fleet. Third-party dependencies are scanned automatically every week by scheduled pipelines: the JavaScript dependency tree is audited against the npm advisory database, and every pinned Java artifact is checked against the OSV vulnerability database, with both reports delivered to a monitored engineering channel and direct dependencies separated from transitive ones so that remediation can be prioritised. Critical patches are applied with a 1-day SLA, and routine library updates are applied monthly.

6. Backups and disaster recovery

  • The primary business database (MariaDB) is fully backed up daily, complemented by a 6-hourly backup of all business-critical tables. Large-scale public social data (ScyllaDB) is backed up weekly; search indexes are rebuilt from primary stores and do not require backup. All backups are encrypted and stored off-site (Backblaze, Amsterdam, EU).

  • A documented Disaster Recovery Plan defines recovery time and recovery point objectives per system, with tested restoration procedures (most recent exercises: infrastructure recovery drills in 2025, database failover exercise in 2026). A Business Continuity Program covers organisational continuity.

7. Monitoring and incident response

  • Infrastructure and application health are monitored continuously (Grafana metrics alerting; self-hosted Sentry error tracking). Application logs are collected in a self-hosted ELK stack, encrypted end to end, retained for 7 days, and scrubbed of PII wherever feasible.

  • A documented incident response process defines detection, escalation, communication (internal and customer-facing) and post-incident review. Personal Data Breaches are notified to the Controller without undue delay in accordance with Clause 3.9.

8. Organisational measures

  • All staff able to access Customer Data are full-time employees bound by confidentiality obligations in their employment contracts, issued hardened company hardware (full-disk encryption, enforced password standards), and trained on security at onboarding and annually thereafter.

  • Analytics (PostHog) and error tracking (Sentry) are self-hosted on Lefty's own EU infrastructure; the data they collect is not transmitted to any external entity.

9. Assessments and certifications

  • Lefty completes an annual CASA (Cloud Application Security Assessment) Tier 2 assessment, validated by an App Defense Alliance authorized laboratory against the OWASP ASVS standard (first completed September 2025, renewed annually; Letter of Validation available on request).

  • A SOC 2 Type II readiness program covering Security, Availability and Confidentiality is underway.

10. Data retention and deletion

  • Customers may export their data at any time via the in-application export features. Upon written request, all Customer Data is deleted, with full deletion from every backup guaranteed within one month of the request.


SCHEDULE 4: AUTHORISED SUB-PROCESSORS

The Processor engages the following Sub-Processors. Providers whose software Lefty self-hosts on its own EU infrastructure (analytics: PostHog; error tracking: Sentry) are not Sub-Processors: the data they collect never leaves Lefty-administered servers and the vendors have no access to it.

Sub-Processor

Purpose

Data concerned

Processing location

Safeguards

Hetzner Online GmbH

Infrastructure hosting

All platform data

Germany, Finland (EU)

EU processing; ISO 27001; DPA

Backblaze, Inc.

Off-site encrypted backup storage

Encrypted database backups

Amsterdam, Netherlands (EU)

EU datacenter; data encrypted before upload; SOC 2 Type 2, data centres ISO 27001-certified; DPA plus SCCs (US parent)

Cloudflare, Inc.

CDN, WAF, DDoS protection and DNS in front of the Lefty API

Application traffic in transit (transient processing in memory; no storage)

Global edge network (US parent)

SCCs / EU-US DPF; Full (strict) TLS to origin

Google LLC (Firebase)

Background task progress tracking; frontend static hosting

Task progress metadata (internal user ids, export file names, which may include the public campaign name); no other influencer or campaign content

United States (Firestore multi-region nam5)

SCCs / EU-US DPF

Google LLC (Cloud Vision)

Logo detection on publicly posted social media images

Public social media content only (image URLs); no Customer-contributed data

United States / global

SCCs / EU-US DPF

OpenRouter, Inc. and its downstream inference providers (Groq, Google Vertex AI, AWS Bedrock, Together AI, Fireworks AI, nCompass)

AI inference routing (sentiment analysis, brand safety) on publicly posted social media content

Public social media content only; zero-data-retention and no-training enforced on every request

United States

SCCs; routing restricted at request time to zero-data-retention endpoints of the listed downstream providers; no-data-collection enforcement on every request

Intercom, Inc.

In-app customer support chat

Support conversations; customer employee name, email, workspace

United States

SCCs / EU-US DPF

GitLab Inc.

Source code management and issue tracking, including customer-reported bug tickets

Bug report context (customer employee name, email, workspace name)

United States

SCCs

Stripe, Inc.

Payment processing

Billing contact and payment data

EU/US

SCCs / EU-US DPF; PCI-DSS

Chargebee, Inc.

Subscription billing

Billing contact and subscription data

EU/US

SCCs / EU-US DPF

GoCardless Ltd

Direct debit payments

Billing contact and bank details

UK/EU

UK adequacy; DPA

Twilio Inc. (SendGrid)

Transactional email delivery

Recipient name and email address

United States

SCCs / EU-US DPF

Customer-side integrations activated at the Customer's request (Shopify, Magento, Salesforce Commerce Cloud, Slack, Pipedrive) connect to systems the Customer controls and are not Sub-Processors of Lefty.

Did this answer your question?