This DPA is incorporated into and forms part of the Agreement by reference (Section 15 of the Terms of Use), and applies from the date Customer first uses the Service. No signature is required for this DPA to be binding. If you need a countersigned copy for your records, email security@laneapp.co - execution does not change these terms.
1. Definitions
“Customer Data” means data submitted to, stored in, or sent to the Service by or on behalf of Customer, including feedback, signals, plans, customer records, documents, and messages. “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including, where applicable: (i) Regulation (EU) 2016/679 (“GDPR”); (ii) the GDPR as incorporated into United Kingdom law (“UK GDPR”) and the UK Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection (“FADP”); and (iv) applicable US state privacy laws, including the California Consumer Privacy Act as amended (“CCPA”). “Personal Data” means any information within Customer Data relating to an identified or identifiable natural person, or otherwise constituting “personal data” or “personal information” under Data Protection Laws. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed by Lane or its Sub-processors. It does not include unsuccessful attempts that do not compromise Personal Data, such as pings, port scans, or failed login attempts. “Service” means Lane’s product intelligence platform and related services described in the Agreement. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time. “Sub-processor” means a third party engaged by Lane to process Personal Data on Customer’s behalf in connection with the Service. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018. “Controller”, “processor”, “data subject”, “processing”, and “supervisory authority” have the meanings given in the GDPR, and their cognates apply to analogous terms in other Data Protection Laws.2. Roles and Scope
2.1 Roles. Customer is the controller of Personal Data (or a processor acting on behalf of a third-party controller), and Lane is a processor acting on Customer’s behalf. Each party will comply with its obligations under Data Protection Laws. 2.2 Third-party controllers. If Customer is itself a processor acting for a third-party controller, Customer warrants that its instructions to Lane, including appointment of Lane as sub-processor, have been authorised by that controller. Customer will be Lane’s sole point of contact, and Lane may provide any required information, assistance, or notifications to Customer rather than to the third-party controller. 2.3 Details of processing. The subject matter, duration, nature and purpose of processing, categories of data subjects, and types of Personal Data are set out in Annex I.3. Processing Instructions
3.1 Lane will process Personal Data only on Customer’s documented instructions, which consist of: (i) the Agreement and this DPA; (ii) Customer’s and its users’ configuration and use of the Service; and (iii) other written instructions agreed by the parties — unless processing is required by applicable law, in which case Lane will inform Customer before processing (unless legally prohibited from doing so). 3.2 Lane will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Lane is not obliged to actively screen Customer instructions for compliance. 3.3 No secondary use. Lane will not: (i) sell or share Personal Data (as those terms are defined under the CCPA); (ii) retain, use, or disclose Personal Data for any purpose other than providing the Service and related support; or (iii) combine Personal Data with data from other customers except as inherent to providing the Service. 3.4 No AI training. Lane does not use Customer Data to train its own artificial-intelligence models, and contractually requires that its AI Sub-processors do not use Customer Data to train or improve their models. 3.5 Sensitive data. The Service is not designed to process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). Customer agrees not to submit such data to the Service, and Lane’s obligations under this DPA do not extend to sensitive data submitted in breach of this Section.4. Confidentiality and Personnel
Lane will ensure that personnel authorised to process Personal Data are subject to obligations of confidentiality, and that access to Personal Data is limited to personnel who require it to provide and support the Service.5. Security
5.1 Lane will implement and maintain appropriate technical and organisational measures to protect Personal Data against Personal Data Breaches, as described in Annex II. Lane may update these measures from time to time provided that updates do not materially degrade the overall security of the Service. 5.2 Customer is responsible for its own secure use of the Service, including securing account credentials, managing user access within its workspace, and the lawfulness of the Personal Data it submits.6. Sub-processors
6.1 General authorisation. Customer authorises Lane to engage the Sub-processors listed on the Sub-processors page (the “Sub-processor Page”), which states each Sub-processor’s purpose and processing region. 6.2 Changes. Lane will provide at least seven (7) days’ advance notice of the addition or replacement of a Sub-processor by updating the Sub-processor Page and notifying Customer by email. Customer may object in writing on reasonable data-protection grounds within seven (7) days of notice. The parties will discuss the objection in good faith; if Lane cannot reasonably accommodate it, Customer may, as its sole remedy, terminate the affected Service on written notice and receive a pro-rata refund of prepaid fees for the unused period. 6.3 Flow-down and liability. Lane will enter into a written agreement with each Sub-processor imposing data-protection obligations materially equivalent to those in this DPA, and remains liable for its Sub-processors’ performance of those obligations.7. Data Subject Requests
7.1 The Service enables Customer to access, rectify, export, and delete Personal Data directly. Customer is responsible for responding to data subject requests. 7.2 If Lane receives a request from a data subject relating to Customer Data, Lane will promptly notify Customer and will not respond to the request except on Customer’s documented instructions or where required by law, other than to direct the data subject to Customer. 7.3 Taking into account the nature of the processing, Lane will provide reasonable assistance to Customer in fulfilling its obligations to respond to data subject requests and, on request, with data protection impact assessments and prior consultations with supervisory authorities, insofar as the required information is available to Lane. Lane may charge a reasonable fee for assistance that goes materially beyond the self-service capabilities of the Service, except where the need for assistance arises from Lane’s own acts or omissions.8. Personal Data Breach
8.1 Lane will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer’s Personal Data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate volume of affected data and data subjects, measures taken or proposed to address it, and a contact point. 8.2 Lane will take reasonable steps to contain and remediate the breach and will cooperate with Customer’s reasonable requests to support Customer’s own notification obligations. Lane’s notification of a breach is not an acknowledgement of fault or liability.9. Data Location and International Transfers
9.1 Hosting. Lane hosts Customer Data in the European Union (Frankfurt, Germany) — application and compute, primary database, and file storage — as described on the Sub-processors and Data Residency & Hosting pages. 9.2 Transfers. Customer acknowledges that: (i) Lane is established in India and its authorised personnel access the Service’s production systems from India for operating and supporting the Service; and (ii) certain Sub-processors process Personal Data in the United States and other countries outside the EEA/UK, as identified on the Sub-processor Page. Where Personal Data protected by European Data Protection Laws is transferred to a country not covered by an adequacy decision, the parties will ensure appropriate safeguards are in place, including the Standard Contractual Clauses. 9.3 SCCs between Customer and Lane. To the extent Customer’s transfer of Personal Data to Lane is a transfer to a third country requiring safeguards under the GDPR, the SCCs are incorporated into this DPA and deemed executed by the parties as of the Effective Date, as follows:- Module Two (Controller → Processor) applies where Customer is a controller; Module Three (Processor → Processor) applies where Customer is a processor. Customer is the data exporter; Lane (MELT RAPID LLP) is the data importer.
- Clause 7 (docking) does not apply; in Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 6.2; the optional language in Clause 11 does not apply; in Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; in Clause 18(b), disputes will be resolved before the courts of Ireland.
- Annex I of the SCCs is completed by Annex I of this DPA; Annex II of the SCCs is completed by Annex II of this DPA; Annex III is the Sub-processor Page.
