Data Processing Agreement
Lashvae Technologies Ltd. · Effective from: 27 July 2026 · Version 1.0
This DPA governs how we process personal data on behalf of our business customers. It supplements our Privacy Notice, which explains the data we process as a controller for your account, billing, and website-visitor data.
This Data Processing Agreement ("DPA") forms part of, and is subject to, the agreement between Lashvae Technologies Ltd. ("Lashvae", "we", "us", "Processor") and the business customer that uses our services ("Customer", "you", "Controller") under which we provide the Lashvae platform (the "Principal Agreement").
It records the terms on which we process personal data on your behalf when you use our AI-powered inbox to manage messages from channels such as Instagram, WhatsApp, Facebook, Telegram, YouTube, and Google Maps.
By accepting the Principal Agreement, or by using the Lashvae platform, you enter into this DPA on behalf of yourself and, to the extent required by applicable data protection law, in the name and on behalf of your authorised affiliates. Where any conflict arises between this DPA and the Principal Agreement on the subject of data protection, this DPA prevails.
Terms such as "controller", "processor", "data subject", "personal data", "processing", "personal data breach", and "supervisory authority" have the meanings given to them under Applicable Data Protection Law.
- Applicable Data Protection Law — the UK GDPR and the Data Protection Act 2018; the EU GDPR; India's Digital Personal Data Protection Act, 2023 and rules made under it ("DPDPA"); and any other privacy or data protection law that applies to the processing under this DPA.
- Customer Personal Data — any personal data that we process on your behalf under the Principal Agreement, including end-user message content and the categories set out in Annex 1.
- End-user — an individual who messages you through a channel connected to the Lashvae platform.
- Sub-processor — any third party engaged by us to process Customer Personal Data on our behalf.
Under the DPDPA, references to "controller" include "data fiduciary" and references to "data subject" include "data principal".
For Customer Personal Data (including end-user message content), you are the controller and we are the processor. You determine the purposes and means of processing; we act only on your behalf.
You are responsible for ensuring you have a valid legal basis (for example, consent or another lawful ground under Applicable Data Protection Law) for the processing you instruct us to carry out, including for enabling optional features such as using conversation data to train AI models, and for providing any notices required to your end-users.
Separately, for your account, billing, and website-visitor data, Lashvae acts as an independent controller. That processing is described in our Privacy Notice and is not governed by this DPA.
We will:
- process Customer Personal Data only on your documented instructions, including as set out in the Principal Agreement, this DPA, and your configuration of the platform, unless required to do otherwise by law (in which case we will inform you, unless the law prohibits it);
- process Customer Personal Data only for the purposes described in Annex 1 — to deliver, maintain, secure, and support the service — and not for our own independent purposes;
- not sell Customer Personal Data and not use it for our own marketing; and
- immediately inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
Because the service processes free-text messages, special category (sensitive) data may incidentally appear in message content. We do not deliberately collect sensitive data and apply access controls to limit exposure. You remain responsible for the content your end-users submit.
We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory), are trained on their data protection responsibilities, and access Customer Personal Data only on a need-to-know basis to perform their role.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, we implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
A summary of the measures currently in place is set out in Annex 2. We may update these measures over time, provided the level of protection is not materially reduced.
You provide general authorisation for us to engage the sub-processors listed in Annex 3 to process Customer Personal Data. Before adding or replacing a sub-processor, we will update Annex 3 (or otherwise notify you) so that you have the opportunity to object on reasonable data-protection grounds.
We impose data protection obligations on each sub-processor by written contract that are no less protective than those in this DPA, and we remain responsible to you for a sub-processor's performance of its obligations.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects to exercise their rights (such as access, correction, erasure, restriction, portability, and objection). If we receive such a request directly from one of your end-users, we will not respond ourselves except on your instructions, and will promptly forward the request to you unless legally required to act otherwise.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within the timeframe required by Applicable Data Protection Law, so that you can meet your own notification obligations. Under the DPDP Rules, 2025, breaches affecting Indian data principals must be reported to the Data Protection Board of India within 72 hours regardless of severity; we will support you accordingly.
Our notification will include, to the extent available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. We will cooperate with you and take reasonable steps to mitigate and remediate the breach.
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you carry out data protection impact assessments and, where required, prior consultations with a supervisory authority, in relation to your use of the Lashvae platform.
We and our sub-processors may process Customer Personal Data in countries other than your own (for example, cloud hosting in AWS EU or US regions). Where we transfer Customer Personal Data out of the UK or EU, we put appropriate safeguards in place — such as Standard Contractual Clauses, the UK International Data Transfer Addendum, or reliance on an applicable adequacy decision. Where we transfer data governed by the DPDPA, we do so consistently with its requirements, including any Central Government restrictions on transfers to specified countries.
On termination or expiry of the Principal Agreement, and at your choice, we will delete or return all Customer Personal Data and delete existing copies, unless retention is required by law. Conversation logs are retained for 12 months by default (or a custom period for enterprise customers), and residual copies may persist in secure backups for up to 90 days after deletion before being overwritten in the ordinary course, consistent with the retention terms in our Privacy Notice.
We will make available to you information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are subject to reasonable notice, confidentiality obligations, and a frequency and scope that avoids undue disruption; where available, we may satisfy an audit request by providing relevant third-party certifications or reports.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. This DPA takes effect on the date you accept the Principal Agreement and continues for as long as we process Customer Personal Data on your behalf.
This DPA is governed by the laws of England and Wales, without prejudice to any mandatory requirements of Applicable Data Protection Law in your place of establishment or the location of the relevant data subjects.
| Subject matter | Provision of the Lashvae AI-powered inbox and related support services. |
| Duration | For the term of the Principal Agreement, plus applicable retention and backup periods. |
| Nature and purpose | Receiving, storing, routing, and displaying messages; automated and manual support; lead scoring and intent detection; AI-generated replies where enabled; analytics and security. |
| Types of personal data | Message content and metadata (timestamps, status, participants); contact identifiers such as name, handle, phone number, or email; engagement and lead-score data; and any personal data end-users choose to include in messages. |
| Categories of data subjects | Your end-users and any individuals referenced in messages; your authorised platform users. |
We apply industry-standard security measures, including HTTPS encryption, password hashing, encrypted authentication tokens, role-based access controls, separation of customer data between accounts, restricted database access, firewalls, rate limiting, webhook verification, audit logs, regular backups, and ongoing security monitoring.
We engage the following categories of sub-processor to help deliver the service. Each is bound by data protection obligations no less protective than those in this DPA.
- Cloud hosting and infrastructure providers (e.g., AWS).
- AI model and inference providers, used to power automated features you enable.
- Payment processors, for billing and subscription management.
- Email and communications providers, for transactional and support messages.
- Analytics providers, for aggregate usage and error monitoring.
A current, named list with each provider's role and processing location is available on request at privacy@lashvae.com.
For questions about this DPA or our data processing, contact us:
Lashvae Technologies Ltd.
Office 18036, 182–184 High Street North East, Ham, London E6 2JA
Email: privacy@lashvae.com
Data Protection / Grievance Officer: Vishal T U — dpo@lashvae.com
This DPA is governed by the laws of England and Wales, without prejudice to any mandatory requirements of the data protection law applicable to you or to the relevant data subjects.