Legal
Data Processing Agreement
Standard contractual terms for customers who require a processor agreement under GDPR and similar laws.
Last updated
Introduction
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller," "you") and LRP360, Inc. ("Processor," "LRP360," "we") for the LRP360 platform. It applies when LRP360 processes personal data on your behalf and where GDPR, UK GDPR, or similar data protection laws require a written processor agreement.
By using the paid service or executing an order that references this DPA, you agree to these terms on behalf of the Controller.
Definitions
- "Personal Data," "Processing," "Controller," "Processor," "Sub-processor," and "Data Subject" have the meanings in applicable data protection law.
- "Customer Data" means personal data submitted to the service by or on behalf of Controller.
- "Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data processed by LRP360.
Scope and roles
Controller determines the purposes and means of processing employee, rater, and related personal data in connection with 360-degree feedback programs. LRP360 processes Customer Data only on documented instructions from Controller, including as set out in these Terms, this DPA, and configuration within the tenant account.
Processing instructions
- Provide the LRP360 platform, including authentication, storage, aggregation, reporting, and optional AI features when enabled.
- Maintain tenant isolation using PostgreSQL Row-Level Security and role-based access controls.
- Send transactional email (invitations, reminders) and system notifications as configured.
- Provide support, troubleshooting, and security monitoring as described in the agreement.
Confidentiality of processing
LRP360 ensures that personnel authorized to process Customer Data are bound by confidentiality obligations. Access is limited to those with a need to know for service delivery, support, or legal compliance.
Security measures
LRP360 implements appropriate technical and organizational measures, including encrypted transport, tenant-scoped database policies, access logging, vulnerability management, and secure development practices. Details of measures are available in our security documentation and upon reasonable request.
Sub-processors
Controller authorizes LRP360 to engage Sub-processors for the categories below. We will provide notice before adding a new Sub-processor that materially changes risk where required by law. Controller may object on reasonable grounds relating to data protection.
The current categories are:
Infrastructure hosting
- Purpose: Application servers, databases, object storage, and backups.
- Typical providers: Cloud VPS / IaaS provider selected for production deployment.
Email delivery
- Purpose: Transactional email (invitations, password resets, demo notifications).
- Typical providers: SMTP relay configured in production (e.g. SendGrid, Amazon SES, Mailgun).
Payment processing
- Purpose: Subscription billing and invoicing when checkout is enabled.
- Typical providers: Stripe and/or Razorpay when configured in Super Admin settings.
Error monitoring (optional)
- Purpose: Crash and performance diagnostics when SENTRY_DSN is configured.
- Typical providers: Sentry
AI providers (optional, tenant-enabled)
- Purpose: Executive narrative generation and comment embeddings when enabled.
- Typical providers: Anthropic (narratives), Voyage AI (embeddings) — only when API keys are set and tenant AI is on.
International transfers
Where Customer Data is transferred outside the EEA, UK, or Switzerland, LRP360 will implement appropriate safeguards such as Standard Contractual Clauses (Module Two: Controller to Processor) and supplementary measures where required. A data residency preference may be recorded in the tenant profile for contractual purposes; separate regional deployments are available only when expressly agreed in writing.
Assistance to Controller
Taking into account the nature of processing, LRP360 will assist Controller with data subject requests, DPIAs, and consultations with supervisory authorities where feasible, using available product features (tenant user export, erasure workflows, audit logs, access controls) and reasonable commercial efforts.
Security incidents
LRP360 will notify Controller without undue delay after confirming a Security Incident affecting Customer Data and provide information reasonably required for Controller to meet its breach notification obligations. Notifications will not include unrelated customer data.
Return and deletion
Upon termination of the service, Controller may export Customer Data during any applicable retrieval period. Thereafter, LRP360 will delete Customer Data from active systems within the timeframe stated in the order or standard retention schedule, except where retention is required by law or encrypted backups cycled on a documented schedule.
Audits
LRP360 will make available information necessary to demonstrate compliance with this DPA and allow audits mandated by applicable law, subject to reasonable notice, confidentiality, and frequency limits. LRP360 may satisfy audit requests through security documentation summaries and penetration-test reports where appropriate; we do not represent that SOC 2 or ISO 27001 certification is in place unless separately stated in writing.
Controller obligations
- Ensure a lawful basis and required notices for processing employee and rater data.
- Configure cycles, anonymity thresholds, and access roles appropriately.
- Respond to data subject requests where Controller is responsible.
- Not instruct LRP360 to process data in violation of applicable law.
Order of precedence
If there is a conflict between this DPA and other commercial terms, this DPA controls with respect to data protection obligations. Standard Contractual Clauses incorporated by reference prevail over conflicting DPA terms to the extent required by law.
DPA contact
To execute a countersigned copy or request the Sub-processor list: dpa@lrp360.com
LRP360, Inc.