Skip to main content
Lonia AI
Pallas by Lonia AI
  • Home
  • About
  • Features
  • Guide
  • Pricing
  • Procurement
  • Resources
  • Contact
  • Free Scan
  • Sign in

LEGAL

Data Processing Agreement

Last updated: 17 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Lonia AI ("Processor") for the use of Pallas by Lonia AI ("Service"). It governs the processing of personal data that the Processor carries out on the Controller's behalf and is designed to meet the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR. Where the two conflict, this DPA prevails over conflicting terms in the main agreement with respect to data processing.

Need a countersigned copy? This page is the public template and names Lonia AI as the party. Once terms are agreed, request the executed version at support@lonia.ai. Include your legal entity name and the jurisdiction of your establishment.

1. Subject Matter and Duration

The subject matter is the provision of the Service. The Processor processes personal data for as long as the main agreement is in effect, plus any post-termination period required to return or delete data as described in Section 9.

2. Nature and Purpose of Processing

The Processor processes personal data solely to provide the Service: accessibility scanning of Controller-designated websites and documents, remediation tracking, governance and audit logging, reporting, and account administration. The Processor processes personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do otherwise by applicable law.

3. Categories of Data Subjects and Personal Data

Data subjects: the Controller's authorized users (organization administrators, managers, contributors, viewers) and any individuals whose personal data may appear incidentally within scanned websites or uploaded documents.

Categories of personal data: user identity data (name, email, profile photo, organization), usage and audit metadata, scan targets and findings, and any personal data incidentally contained in Controller-submitted content. The Controller must not intentionally submit special categories of personal data for scanning.

4. Obligations of the Controller

The Controller warrants that it has a lawful basis for the processing it instructs, that its instructions comply with applicable data-protection law, and that it has provided any notices and obtained any consents required from data subjects.

5. Obligations of the Processor

The Processor will: process personal data only on the Controller's documented instructions; ensure personnel authorized to process personal data are bound by confidentiality; implement the technical and organizational measures described in Section 6; assist the Controller in responding to data-subject requests; and assist the Controller with security, breach-notification, and data-protection-impact-assessment obligations, taking into account the nature of processing and the information available to the Processor.

6. Security Measures

The Processor maintains technical and organizational measures appropriate to the risk, including: OAuth-only authentication with no password storage; encryption of data in transit (TLS) and at rest, provided by the Processor's platform providers; row-level security enforcing tenant isolation at the database layer; least-privilege access controls; a tamper-evident audit log (SHA-256) with server-derived actor identity, in which any modification, deletion, or reordering of historical events is detected, and in which erasures carried out under Article 17 or under the Controller's retention policy are recorded as redaction entries carrying their reason; source files analyzed and discarded by default; and regular security reviews and dependency updates. Finding comments, evidence descriptions and code snippets, and evidence files are encrypted at rest by the database and storage provider under a key the provider holds, and in transit by TLS. They are not client-side encrypted: every member of the organization can read them, they are included in the organization's data export, and the Processor can read them as any SaaS operator can.

Data residency. Personal data at rest resides in the Processor's primary Supabase region in the United States. Cloudflare edge locations are global and handle data in transit (request routing, caching of static assets, and bot mitigation); they are not the system of record and do not hold customer data at rest. A current list of subprocessors and their regions is maintained on the Subprocessor page.

Independent assurance. The Processor holds no SOC 2 certificate today and does not claim one. Where a subprocessor holds its own certifications (for example SOC 2 Type II or ISO 27001), those are listed on the Subprocessor page and belong to that subprocessor, not to the Processor.

7. Data Subject Rights Assistance

Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, and objection). The Service provides self-service export of findings, reports, and audit records via CSV and PDF, and a full account export covering organizations, members, assets, scans, findings, reports, subscriptions, audit events, and retention policies as JSON.

8. Subprocessors

The Controller provides general authorization for the Processor to engage the subprocessors listed on our Subprocessor page. The Processor will inform the Controller of any intended addition or replacement of subprocessors at least 30 days in advance, giving the Controller the opportunity to object within 14 days of notification. The Processor imposes data-protection obligations on each subprocessor no less protective than those in this DPA and remains liable for its subprocessors' performance.

9. Personal Data Breach Notification

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach affecting the Controller's personal data, and will provide information reasonably necessary to allow the Controller to meet its own breach-notification obligations, including those under GDPR Articles 33 and 34.

Australia (Notifiable Data Breaches). Where the Australian Privacy Act 1988 applies, the Processor will assist the Controller in assessing a suspected eligible data breach within the 30 days the Notifiable Data Breaches scheme allows for that assessment, and, where the Controller forms the belief that an eligible data breach has occurred, in notifying affected individuals and the Office of the Australian Information Commissioner as soon as practicable thereafter. The 30 days is the assessment window, not a notification allowance; the Processor's own notice to the Controller remains bound by the 72-hour commitment in the paragraph above.

Quebec (Law 25). Where the Quebec Act respecting the protection of personal information in the private sector (as amended by Law 25) applies, the Processor will assist the Controller in notifying the Commission d'accès à l'information (CAI) and affected individuals of any confidentiality incident that presents a risk of serious injury, and in maintaining the required incident register.

10. Return and Deletion of Data

On termination of the Service, the Controller may export its data during the 30-day post-cancellation period. After that period, the Processor will delete or return the personal data in accordance with the Controller's configured retention policies and applicable law, except where retention is required by law.

11. International Transfers

Where processing involves the transfer of personal data out of the EEA, the parties agree that the European Commission's 2021 Standard Contractual Clauses, and specifically Module Two (Controller to Processor), are incorporated into this DPA by reference and apply to those transfers. The docking clause, the Processor's role as data importer, and the option selections default to those that provide the highest protection to data subjects. For transfers out of Switzerland, the SCCs apply with the amendments recognized by the Swiss Federal Data Protection and Information Commissioner. In each case the parties apply supplementary measures as appropriate following a transfer risk assessment. The full SCC text is published on the Procurement page; the executed version is issued on request at support@lonia.ai.

12. Audit

The Processor will make available to the Controller information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable confidentiality and scheduling arrangements.

13. Contact

Questions about this DPA, or to request the executed version, contact support@lonia.ai.

This document is provided for procurement and vendor-onboarding review. It is a contractual template, not legal advice; both parties should have it reviewed by counsel before execution.

Pallas by Lonia AI From scan to resolution.
  • Features
  • Pricing
  • Procurement
  • Compliance Guide
  • About
  • Contact

© 2026 Lonia AI