DPA
Data Processing Addendum
This Data Processing Addendum describes how Leara processes customer personal data on behalf of customers when providing the service.
Last updated August 31, 2026
1. Scope and Parties
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement between Techtale ABand the customer using Leara (the "Agreement"). It applies when Leara processes Customer Personal Data on behalf of the customer to provide the service.
For Customer Personal Data, the customer is the controller or processor, and Leara acts as processor or subprocessor. Leara remains an independent controller for account, billing, security, website, and business operations data described in the Privacy Policy.
2. Definitions
"Customer Personal Data" means personal data submitted to Leara by or on behalf of the customer and processed by Leara on the customer's instructions. "Data Protection Laws" means applicable privacy and data protection laws, including the GDPR, UK GDPR, and ePrivacy rules where applicable.
3. Customer Instructions
Leara will process Customer Personal Data only to provide the service, to comply with documented customer instructions, as described in the Agreement and this DPA, or as required by law. If Leara believes an instruction violates Data Protection Laws, Leara will inform the customer unless prohibited by law.
4. Customer Responsibilities
- Use Leara only in accordance with Data Protection Laws.
- Provide required notices and obtain required consents from users and data subjects.
- Ensure Customer Personal Data submitted to Leara is lawful, relevant, and limited to what is necessary.
- Configure prompts, tools, context, API keys, and model providers appropriately.
- Do not submit special category data or regulated data unless the Agreement expressly permits it.
5. Confidentiality
Leara will ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations or professional duties of confidentiality and receive access only as needed to provide, support, secure, and improve the service.
6. Security Measures
Leara will maintain technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures include:
- Transport encryption for application traffic.
- Server-side handling of Leara API keys and provider secrets.
- Hashing for stored Leara project API keys after creation.
- Role-appropriate access controls and least-privilege practices.
- Logging, monitoring, rate limiting, and abuse-prevention controls.
- Backup, hosting, and database protections provided by infrastructure subprocessors.
7. Subprocessors
The customer authorizes Leara to use subprocessors to provide the service. Leara remains responsible for subprocessors' processing of Customer Personal Data to the extent required by Data Protection Laws. The current list is published at /legal/subprocessors.
Leara will update the Subprocessors page when adding or replacing material subprocessors. Customers may object on reasonable data protection grounds by contacting privacy@leara.dev.
8. International Transfers
Where Leara transfers Customer Personal Data outside the EEA, UK, Switzerland, or another protected jurisdiction, Leara will use lawful transfer mechanisms such as adequacy decisions, standard contractual clauses, or other valid safeguards.
9. Assistance
Taking into account the nature of processing and information available to Leara, Leara will reasonably assist the customer with data subject requests, security obligations, data protection impact assessments, prior consultations, and compliance inquiries relating to Customer Personal Data.
10. Security Incidents
Leara will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notice will include available information reasonably needed for the customer to meet its own notification obligations.
11. Deletion and Return
At the end of the service relationship, Leara will delete or return Customer Personal Data as required by the Agreement, unless retention is required by law or permitted for legitimate backup, security, dispute, or compliance purposes.
12. Audit
Leara will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, limited to relevant systems and records, subject to confidentiality, and scheduled to avoid unnecessary disruption or security risk.
Annex 1: Processing Details
| Item | Details |
|---|---|
| Subject matter | Provision of Leara's generative interface runtime, hosted app, API, SDK, observability, billing controls, and support. |
| Duration | For the term of the Agreement and any post-termination period required for deletion, backup expiry, legal compliance, security, or dispute handling. |
| Nature and purpose | Receiving, storing, transmitting, validating, composing, rendering, logging, metering, securing, and supporting generated product UI workflows. |
| Data subjects | Customer users, employees, contractors, administrators, support contacts, end users whose data is submitted by the customer, and individuals referenced in prompts or context. |
| Personal data categories | Names, email addresses, account identifiers, workspace membership, prompts, context, generated outputs, usage metadata, logs, support messages, and billing metadata. |
| Sensitive data | Not intended for special category data, health data, payment card numbers, government identifiers, children's data, or other regulated data unless expressly agreed in writing. |
Annex 2: Technical and Organizational Measures
- Access controls for production systems and administrative functions.
- Transport security for browser, API, and server communication.
- Server-side storage and handling of API keys and provider secrets.
- Hashed storage of Leara project API keys after one-time display.
- Operational logging, rate limiting, and trace metadata for abuse prevention and debugging.
- Separation between application runtime, billing, database, and provider credentials.
- Security review of material subprocessors before production use.
- Incident response process for investigating and notifying affected customers.