Skip to main content
Lane is designed with privacy and data protection in mind, and we follow GDPR-aligned practices for handling, securing, and deleting personal data. This page describes what’s in place today and how to exercise your rights.
Lane hosts customer data in the EU (Frankfurt). For details, see Data Residency & Hosting.

What’s in place today

  • EU data residency for your workspace data.
  • A Data Processing Agreement (DPA) available to customers on request.
  • Standard Contractual Clauses (SCCs) governing transfers to sub-processors located outside the EU (such as OpenAI, Voyage AI, and our payments provider).
  • Encryption in transit and at rest — see Data Residency & Hosting.

Your rights

Under the GDPR you have the right to access, correct, export, or delete your personal data, and to restrict or object to certain processing. To exercise any of these, contact security@laneapp.co. How deletion works in practice is described on the Data Retention & Deletion page.

Roles

For the data in your workspace, you are the data controller and Lane is the data processor, processing that data on your behalf and under your instructions.

Requesting a DPA

To put a Data Processing Agreement in place, email security@laneapp.co.