> ## Documentation Index
> Fetch the complete documentation index at: https://docs.laneapp.co/llms.txt
> Use this file to discover all available pages before exploring further.

# GDPR

> Lane's approach to GDPR, EU data residency, and your data-subject rights.

Lane is designed with privacy and data protection in mind, and **we follow GDPR-aligned practices for handling, securing, and deleting personal data.** This page describes what's in place today and how to exercise your rights.

<Note>
  Lane hosts customer data in the EU (Frankfurt). For details, see [Data Residency & Hosting](/security/data-residency).
</Note>

## What's in place today

* **EU data residency** for your workspace data.
* **A Data Processing Agreement (DPA)** available to customers on request.
* **Standard Contractual Clauses (SCCs)** governing transfers to sub-processors located outside the EU (such as OpenAI, Voyage AI, and our payments provider).
* **Encryption** in transit and at rest — see [Data Residency & Hosting](/security/data-residency).

## Your rights

Under the GDPR you have the right to access, correct, export, or delete your personal data, and to restrict or object to certain processing. To exercise any of these, contact [security@laneapp.co](mailto:security@laneapp.co). How deletion works in practice is described on the [Data Retention & Deletion](/security/retention-deletion) page.

## Roles

For the data in your workspace, **you are the data controller** and **Lane is the data processor**, processing that data on your behalf and under your instructions.

## Requesting a DPA

To put a Data Processing Agreement in place, email [security@laneapp.co](mailto:security@laneapp.co).
