> ## Documentation Index
> Fetch the complete documentation index at: https://docs.laneapp.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Processing Agreement

> The terms governing Lane's processing of personal data on your behalf.

**Last updated: August 15, 2026**

This Data Processing Agreement ("**DPA**") forms part of the agreement between **MELT RAPID LLP**, doing business as **Lane** ("**Lane**", "we", "us"), a limited liability partnership registered in India, and the customer that uses the Service ("**Customer**", "you") governing Customer's use of Lane's services (the "**Agreement**", comprising Lane's [Terms of Use](https://www.laneapp.co/termsofuse) and any order form or subscription between the parties). It reflects the parties' agreement on the processing of Personal Data within Customer Data.

<Note>
  This DPA is incorporated into and forms part of the Agreement by reference (Section 15 of the Terms of Use), and applies from the date Customer first uses the Service. **No signature is required for this DPA to be binding.** If you need a countersigned copy for your records, email [security@laneapp.co](mailto:security@laneapp.co) - execution does not change these terms.
</Note>

If there is a conflict between this DPA and the Agreement, this DPA prevails with respect to its subject matter. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.

## 1. Definitions

**"Customer Data"** means data submitted to, stored in, or sent to the Service by or on behalf of Customer, including feedback, signals, plans, customer records, documents, and messages.

**"Data Protection Laws"** means all laws applicable to the processing of Personal Data under the Agreement, including, where applicable: (i) Regulation (EU) 2016/679 ("**GDPR**"); (ii) the GDPR as incorporated into United Kingdom law ("**UK GDPR**") and the UK Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection ("**FADP**"); and (iv) applicable US state privacy laws, including the California Consumer Privacy Act as amended ("**CCPA**").

**"Personal Data"** means any information within Customer Data relating to an identified or identifiable natural person, or otherwise constituting "personal data" or "personal information" under Data Protection Laws.

**"Personal Data Breach"** means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed by Lane or its Sub-processors. It does not include unsuccessful attempts that do not compromise Personal Data, such as pings, port scans, or failed login attempts.

**"Service"** means Lane's product intelligence platform and related services described in the Agreement.

**"Standard Contractual Clauses"** or **"SCCs"** means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.

**"Sub-processor"** means a third party engaged by Lane to process Personal Data on Customer's behalf in connection with the Service.

**"UK Addendum"** means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.

"Controller", "processor", "data subject", "processing", and "supervisory authority" have the meanings given in the GDPR, and their cognates apply to analogous terms in other Data Protection Laws.

## 2. Roles and Scope

**2.1 Roles.** Customer is the controller of Personal Data (or a processor acting on behalf of a third-party controller), and Lane is a processor acting on Customer's behalf. Each party will comply with its obligations under Data Protection Laws.

**2.2 Third-party controllers.** If Customer is itself a processor acting for a third-party controller, Customer warrants that its instructions to Lane, including appointment of Lane as sub-processor, have been authorised by that controller. Customer will be Lane's sole point of contact, and Lane may provide any required information, assistance, or notifications to Customer rather than to the third-party controller.

**2.3 Details of processing.** The subject matter, duration, nature and purpose of processing, categories of data subjects, and types of Personal Data are set out in **Annex I**.

## 3. Processing Instructions

**3.1** Lane will process Personal Data only on Customer's documented instructions, which consist of: (i) the Agreement and this DPA; (ii) Customer's and its users' configuration and use of the Service; and (iii) other written instructions agreed by the parties — unless processing is required by applicable law, in which case Lane will inform Customer before processing (unless legally prohibited from doing so).

**3.2** Lane will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Lane is not obliged to actively screen Customer instructions for compliance.

**3.3 No secondary use.** Lane will not: (i) sell or share Personal Data (as those terms are defined under the CCPA); (ii) retain, use, or disclose Personal Data for any purpose other than providing the Service and related support; or (iii) combine Personal Data with data from other customers except as inherent to providing the Service.

**3.4 No AI training.** Lane does not use Customer Data to train its own artificial-intelligence models, and contractually requires that its AI Sub-processors do not use Customer Data to train or improve their models.

**3.5 Sensitive data.** The Service is not designed to process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). Customer agrees not to submit such data to the Service, and Lane's obligations under this DPA do not extend to sensitive data submitted in breach of this Section.

## 4. Confidentiality and Personnel

Lane will ensure that personnel authorised to process Personal Data are subject to obligations of confidentiality, and that access to Personal Data is limited to personnel who require it to provide and support the Service.

## 5. Security

**5.1** Lane will implement and maintain appropriate technical and organisational measures to protect Personal Data against Personal Data Breaches, as described in **Annex II**. Lane may update these measures from time to time provided that updates do not materially degrade the overall security of the Service.

**5.2** Customer is responsible for its own secure use of the Service, including securing account credentials, managing user access within its workspace, and the lawfulness of the Personal Data it submits.

## 6. Sub-processors

**6.1 General authorisation.** Customer authorises Lane to engage the Sub-processors listed on the [Sub-processors page](/subprocessors) (the "Sub-processor Page"), which states each Sub-processor's purpose and processing region.

**6.2 Changes.** Lane will provide at least **seven (7) days' advance notice** of the addition or replacement of a Sub-processor by updating the Sub-processor Page and notifying Customer by email. Customer may object in writing on reasonable data-protection grounds within seven (7) days of notice. The parties will discuss the objection in good faith; if Lane cannot reasonably accommodate it, Customer may, as its sole remedy, terminate the affected Service on written notice and receive a pro-rata refund of prepaid fees for the unused period.

**6.3 Flow-down and liability.** Lane will enter into a written agreement with each Sub-processor imposing data-protection obligations materially equivalent to those in this DPA, and remains liable for its Sub-processors' performance of those obligations.

## 7. Data Subject Requests

**7.1** The Service enables Customer to access, rectify, export, and delete Personal Data directly. Customer is responsible for responding to data subject requests.

**7.2** If Lane receives a request from a data subject relating to Customer Data, Lane will promptly notify Customer and will not respond to the request except on Customer's documented instructions or where required by law, other than to direct the data subject to Customer.

**7.3** Taking into account the nature of the processing, Lane will provide reasonable assistance to Customer in fulfilling its obligations to respond to data subject requests and, on request, with data protection impact assessments and prior consultations with supervisory authorities, insofar as the required information is available to Lane. Lane may charge a reasonable fee for assistance that goes materially beyond the self-service capabilities of the Service, except where the need for assistance arises from Lane's own acts or omissions.

## 8. Personal Data Breach

**8.1** Lane will notify Customer **without undue delay, and in any event within 72 hours**, after becoming aware of a Personal Data Breach affecting Customer's Personal Data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate volume of affected data and data subjects, measures taken or proposed to address it, and a contact point.

**8.2** Lane will take reasonable steps to contain and remediate the breach and will cooperate with Customer's reasonable requests to support Customer's own notification obligations. Lane's notification of a breach is not an acknowledgement of fault or liability.

## 9. Data Location and International Transfers

**9.1 Hosting.** Lane hosts Customer Data in the **European Union (Frankfurt, Germany)** — application and compute, primary database, and file storage — as described on the [Sub-processors](/subprocessors) and [Data Residency & Hosting](/data-residency) pages.

**9.2 Transfers.** Customer acknowledges that: (i) Lane is established in India and its authorised personnel access the Service's production systems from India for operating and supporting the Service; and (ii) certain Sub-processors process Personal Data in the United States and other countries outside the EEA/UK, as identified on the Sub-processor Page. Where Personal Data protected by European Data Protection Laws is transferred to a country not covered by an adequacy decision, the parties will ensure appropriate safeguards are in place, including the Standard Contractual Clauses.

**9.3 SCCs between Customer and Lane.** To the extent Customer's transfer of Personal Data to Lane is a transfer to a third country requiring safeguards under the GDPR, the SCCs are incorporated into this DPA and **deemed executed by the parties as of the Effective Date**, as follows:

* **Module Two** (Controller → Processor) applies where Customer is a controller; **Module Three** (Processor → Processor) applies where Customer is a processor. Customer is the data exporter; Lane (MELT RAPID LLP) is the data importer.
* Clause 7 (docking) does not apply; in Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 6.2; the optional language in Clause 11 does not apply; in Clause 17, Option 1 applies and the SCCs are governed by the laws of **Ireland**; in Clause 18(b), disputes will be resolved before the courts of **Ireland**.
* Annex I of the SCCs is completed by **Annex I** of this DPA; Annex II of the SCCs is completed by **Annex II** of this DPA; Annex III is the Sub-processor Page.

**9.4 UK and Swiss transfers.** For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, with the tables completed by reference to Section 9.3 and the Annexes, and "importer" selected for Table 4. For transfers subject to the FADP, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, with references to the GDPR read as references to the FADP and the FDPIC as competent authority.

**9.5 Onward transfers.** Lane's transfers to Sub-processors outside the EEA/UK are made under appropriate safeguards, including SCCs or participation in recognised frameworks (such as the EU-US Data Privacy Framework), as reflected in each Sub-processor's data processing terms.

## 10. Government and Law-Enforcement Requests

If Lane receives a legally binding request from a public authority for access to Personal Data, Lane will, unless legally prohibited: (i) promptly notify Customer; (ii) redirect the authority to request the data from Customer where possible; and (iii) disclose only the minimum information required based on a reasonable interpretation of the request. Lane has not created back doors for any public authority to access Customer Data.

## 11. Deletion and Return

**11.1 During the term.** The Service enables Customer to delete Personal Data at any time. A workspace owner may permanently delete the entire workspace from within the Service; such deletion is an instruction to Lane to delete the corresponding Personal Data from production systems.

**11.2 On termination or deletion.** Upon workspace deletion or termination of the Agreement, Lane will delete Personal Data from its production systems, including associated sign-in records held by its identity Sub-processor. Residual copies in Lane's encrypted backups are automatically purged within **seven (7) days**. Sub-processors delete data in accordance with their own deletion schedules under their data processing terms (in each case within ninety (90) days at most), and Lane will procure such deletion. Lane may retain Personal Data to the extent required by applicable law, in which case it will remain protected under this DPA.

**11.3 Export.** Customer is responsible for exporting any Customer Data it wishes to retain before deletion. On written request made before deletion, Lane will provide reasonable assistance with export.

## 12. Audit

**12.1** On written request at reasonable intervals (no more than once per twelve-month period), Lane will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures, its Sub-processors' certifications and audit reports where Lane is permitted to share them, and written responses to reasonable security questionnaires.

**12.2** Where the information under Section 12.1 is insufficient to demonstrate compliance under Data Protection Laws, or following a Personal Data Breach, or where required by a supervisory authority, Customer may conduct an audit (itself or through an independent auditor that is not a competitor of Lane, bound by confidentiality). The parties will agree in advance on the scope, timing, and duration; audits will be conducted during business hours, no more than once per year, without unreasonable disruption, and at Customer's cost. The parties agree this Section satisfies any audit rights under the SCCs.

## 13. Liability

Each party's aggregate liability arising out of or related to this DPA (including the SCCs, to the greatest extent permitted by Data Protection Laws) is subject to the limitations and exclusions of liability in the Agreement. Nothing in this Section limits either party's liability with respect to a data subject's rights under Data Protection Laws or the SCCs.

## 14. CCPA Service Provider Terms

To the extent the CCPA applies, Lane acts as a "service provider": Personal Data is disclosed to Lane only for the limited business purpose of providing the Service; Lane will not sell or share Personal Data, will not retain, use, or disclose it outside its direct business relationship with Customer or for any purpose other than providing the Service, will provide the same level of privacy protection as required of businesses under the CCPA, and will notify Customer if it can no longer meet its CCPA obligations. Customer may take reasonable and appropriate steps under Section 12 to ensure Lane's use of Personal Data is consistent with the CCPA and to stop and remediate any unauthorised use.

## 15. General

**15.1 Term.** This DPA applies for as long as Lane processes Personal Data under the Agreement, and its obligations survive termination of the Agreement until all Personal Data is deleted or returned.

**15.2 Changes to this DPA.** Lane may update this DPA to reflect changes in the Service, its Sub-processors, or Data Protection Laws. Material changes that reduce Customer's protections will be notified in advance in the same manner as sub-processor changes under Section 6.2. Where a change in Data Protection Laws or a decision of a competent authority requires amendment (including replacement of the SCCs), the parties will cooperate in good faith, and Lane may adopt any valid successor transfer mechanism.

**15.3 Governing law.** This DPA is governed by the law governing the Agreement, except that the SCCs are governed as set out in Section 9.3, and except where Data Protection Laws require otherwise.

**15.4 Notices.** Notices under this DPA may be given by email: to Customer, at the workspace owner's registered email address; to Lane, at [security@laneapp.co](mailto:security@laneapp.co).

***

## Annex I — Details of Processing

### A. List of parties

**Data exporter:** Customer (contact details as provided in Customer's Lane account). Role: controller (or processor on behalf of a third-party controller). Activities: use of the Service under the Agreement.

**Data importer:** MELT RAPID LLP (d/b/a Lane), 1B, Tottee Lane, Kolkata, West Bengal, India. Contact: [security@laneapp.co](mailto:security@laneapp.co). Role: processor.

### B. Description of processing / transfer

| Item                            | Details                                                                                                                                                                                                                                                                                                 |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Subject matter                  | Provision of Lane's product intelligence platform: capturing and analysing product feedback, generating signals, planning, and related support.                                                                                                                                                         |
| Duration                        | The term of the Agreement, plus the deletion period in Section 11.                                                                                                                                                                                                                                      |
| Nature and purpose              | Hosting, storage, analysis (including AI-assisted processing of feedback into signals and plans, semantic search, and question answering), display, transmission to Customer-connected integrations at Customer's direction, and related technical support.                                             |
| Categories of data subjects     | Customer's users (employees and contractors); Customer's own customers, prospects, and end users whose feedback or details are submitted to the Service; other individuals appearing in content submitted to the Service.                                                                               |
| Categories of Personal Data     | Names, email addresses, job titles, company affiliations; feedback content and communications that may contain personal data; usage and technical data (IP addresses, device and browser information, and masked session recordings capturing interaction events); account and billing contact details. |
| Sensitive data                  | None intended. Submission of special-category data is prohibited under Section 3.5.                                                                                                                                                                                                                     |
| Frequency                       | Continuous, for the duration of the Agreement.                                                                                                                                                                                                                                                          |
| Retention                       | Personal Data is retained while the Customer account is active; on deletion or termination, deleted per Section 11.                                                                                                                                                                                     |
| Competent supervisory authority | Determined in accordance with Clause 13 of the SCCs based on the data exporter's establishment or Article 27 representative; for UK transfers, the Information Commissioner's Office; for Swiss transfers, the FDPIC.                                                                                   |

## Annex II — Technical and Organisational Measures

**Hosting and residency.** Customer Data is hosted in the European Union (Frankfurt): application and compute (Render), primary database (MongoDB Atlas), and file/object storage (Cloudflare R2, EU jurisdiction).

**Encryption.** All data is encrypted in transit using TLS. Data is encrypted at rest in the primary database and file storage. Third-party integration credentials (access tokens) are additionally encrypted at the application layer using AES-256 before storage.

**Access control.** Access to production systems is restricted to a small number of authorised Lane personnel, on a need-to-know basis, for operating and supporting the Service. Authentication for the Service is managed by a dedicated identity provider (Clerk), supporting Google sign-in; workspace owners control member roles and permissions within the Service.

**Tenant isolation.** Customer Data is logically separated per workspace at the application layer.

**Backups.** Encrypted backups are retained in-region (EU) and rolled off automatically after 7 days.

**Deletion.** Self-service workspace deletion permanently removes Customer Data from production systems, including identity records, per Section 11.

**Monitoring.** Error monitoring with PII scrubbing (request bodies, query strings, cookies, and authorisation headers are stripped before events leave the server); EU-region error data storage.

**Sub-processor security.** Sub-processors are bound by written data-protection terms; Lane reviews their published security documentation and certifications (e.g. SOC 2 / ISO 27001 where held) before engagement.

**Personnel.** Personnel with production access are subject to confidentiality obligations.

## Annex III — Sub-processors

The current list of Sub-processors, including each Sub-processor's purpose and processing region, is maintained on the [Sub-processors page](/subprocessors).

Notice and objection rights for changes to this list are set out in Section 6.
