Data Processing Agreement

The UK GDPR Art. 28 terms that apply when we process personal data for you.

  • Last updated 26 September 2026
  • UK GDPR Art. 28
On this page

Parties

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between:

  • Leveld, England and Wales (the “Processor” or “Leveld”); and
  • The Customer identified in the Order Form (the “Controller” or “Customer”).

Background

Leveld provides a B2B SaaS agentic project-management platform. In delivering the Service, Leveld processes Personal Data on behalf of the Customer. This DPA implements the Customer’s obligations under UK GDPR Art. 28 and the Data Protection Act 2018 — and, where applicable, EU GDPR Art. 28 — to engage processors only under a written contract setting out the matters in Art. 28(3).

1. Definitions

TermMeaning
Applicable Data Protection LawUK GDPR, the Data Protection Act 2018, and (for Customers established in the EEA or processing EEA-resident personal data) EU GDPR and the Privacy and Electronic Communications Regulations where engaged.
Personal Data; Processing; Controller; Processor; Data Subject; Special Categories; Personal Data Breach; Supervisory AuthorityAs defined in UK GDPR Art. 4 (and mirrored in EU GDPR Art. 4).
Customer Personal DataPersonal Data processed by Leveld on behalf of Customer under the Agreement. Annex I details categories.
Sub-processorAny third party engaged by Leveld to process Customer Personal Data on Leveld’s behalf. The current list is in Annex III and at /legal/sub-processors.
Independent Third-Party ControllerAny third party that receives Customer Personal Data as a separate Controller rather than as a Sub-processor. None are active for the free beta.
EU SCCsStandard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
UK AddendumUK International Data Transfer Addendum to the EU SCCs (Version B1.0, in force 21 March 2022), or any successor approved by the ICO.
DUAAData (Use and Access) Act 2025 (in force 5 February 2026).

2. Subject matter, duration, nature, purpose

FieldValue
Subject matterProvision of the Leveld Service to Customer.
DurationCo-terminous with the Agreement.
Nature and purposeIngest, extract, store, retrieve, present, draft, and (on Customer’s instruction) send Customer Personal Data and the Personal Data of Customer’s Data Subjects, in support of project-management workflows.
Categories of Personal DataSee Annex I.A.
Categories of Data SubjectsSee Annex I.B.
Special CategoriesMay be incidentally Processed (Art. 9 — health, political opinions, religious beliefs, or sexual orientation may surface in authorised Gmail content). Customer is responsible for nominating an Art. 9(2) condition and DPA 2018 Sch. 1 Part 4 appropriate policy document where required.

3. Customer’s role and warranties (Controller)

Customer is the Controller of Customer Personal Data. Customer warrants that:

(a) the Personal Data has been collected and is being shared with Leveld lawfully under Applicable Data Protection Law;
(b) Customer has provided all required notices to Data Subjects (UK GDPR Arts. 13–14);
(c) Customer has a lawful basis (Art. 6) and, where applicable, an Art. 9(2) or Art. 10 condition plus a DPA 2018 Sch. 1 Part 4 appropriate policy document; and
(d) Customer’s instructions to Leveld are lawful and complete.

Where Customer is itself a Processor (i.e. Customer processes the Personal Data on behalf of Customer’s own customer or a further Controller), this DPA operates as an EU SCCs Module 3 (processor-to- processor) instrument, and Customer warrants it has the further Controller’s authorisation to engage Leveld as a sub-processor.

4. Leveld’s obligations (Art. 28(3) processor)

Leveld shall:

(a) Documented instructions

Process Customer Personal Data only on documented instructions from Customer (including for transfers to a third country), unless required to do otherwise by domestic law — in which case Leveld notifies Customer beforehand unless that law prohibits notification on important grounds of public interest. The Agreement, this DPA, and Customer’s use of the Service constitute documented instructions.

(b) Confidentiality

Ensure that persons authorised to process Customer Personal Data are bound by confidentiality (statutory or contractual).

(c) Security

Implement appropriate technical and organisational measures per Art. 32, summarised in Annex II.

(d) Sub-processor regime

Only engage Sub-processors per §6.

(e) Data-subject request assistance

Assist Customer by appropriate technical and organisational measures, insofar as possible, to fulfil Customer’s obligation to respond to Data Subject rights requests under Chapter III.

(f) Compliance assistance

Assist Customer in ensuring compliance with Arts. 32–36 (security, breach notification, DPIA, prior consultation), taking into account the nature of Processing and the information available to Leveld.

(g) Return and delete

At Customer’s choice, return or delete all Customer Personal Data after the end of the provision of Services, and delete existing copies (subject to legal retention requirements). Default election: delete within 30 days of termination after a 30-day Customer- initiated export window. See §11.

(h) Audit and inspection

Make available to Customer all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by Customer or a Customer-mandated auditor. See §10.

5. Special-category data (Arts. 9 and 10)

Leveld processes Customer Personal Data that may incidentally include Special Categories of Personal Data (Art. 9) and personal data relating to criminal convictions and offences (Art. 10), particularly in authorised Gmail content that Customer’s Data Subjects generate.

Customer is responsible for nominating the Art. 9(2) condition (and where applicable the DPA 2018 Sch. 1 Part 4 appropriate policy document) on which Customer relies, and for ensuring Customer’s own lawful basis covers all incidental Special Categories. Leveld treats all ingested Gmail content as if it may contain Special Categories for security-control purposes (see Annex II).

Leveld does not deliberately solicit Special Categories. Where Leveld becomes aware that a particular ingest source is intentionally producing Special Categories (e.g. medical records as input), Leveld notifies Customer and may suspend the relevant connector pending Customer’s confirmation that lawful conditions are in place.

6. Sub-processors

6.1 General authorisation

Customer grants Leveld general written authorisation to engage Sub- processors per Art. 28(2). The current list is in Annex III and maintained at /legal/sub-processors.

6.2 Notification and objection

Leveld will give Customer at least 30 days’ prior written notice of any addition or replacement of a Sub- processor. Customer may object on reasonable data-protection grounds within 30 days. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Service for cause (refund of pre-paid fees for the unconsumed period).

6.3 Flow-down

Leveld imposes on each Sub-processor data-protection obligations no less protective than those in this DPA (Art. 28(4)). Leveld remains fully liable to Customer for the performance of each Sub- processor.

7. Independent third-party controllers

No independent third-party controller receives Customer Personal Data for payment collection during the free beta. Leveld does not collect card, bank-account, mandate, or payment-transaction data for this release profile.

Any future Independent Third-Party Controller addition is notified per §6.2 (same 30-day window and objection right).

8. International data transfers

Leveld is established in the United Kingdom. Where Leveld transfers Customer Personal Data outside the United Kingdom or the European Economic Area (as applicable), Leveld relies on:

(a) UK adequacy or EU adequacy where the destination benefits from a current adequacy decision (currently includes EEA → UK and UK → EEA, both in force; UK adequacy renewed by the European Commission on 19 December 2025, valid to 27 December 2031);
(b) the EU-US Data Privacy Framework (DPF) (active since 10 July 2023) — for transfers to US recipients listed on the active DPF List, Leveld may rely on DPF certification including, where applicable, the UK Extension to the DPF (Data Bridge, in force 12 October 2023);
(c) the EU SCCs Module 3 (processor-to- processor) for transfers to non-DPF-certified recipients, executed with the UK Addendum for UK-restricted transfers; and
(d) a data protection test (DUAA 2025 terminology, replacing “transfer risk assessment” effective 5 February 2026) using the “not materially lower” threshold.

Annex IV details the per-Sub-processor mechanism. Leveld bears the obligation to maintain valid transfer mechanisms across the Sub- processor chain.

If a transfer mechanism is invalidated, Leveld notifies Customer and adopts an alternative mechanism without undue delay.

9. Personal Data Breach

Leveld notifies Customer of any Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware. The contractual 24-hour clock is shorter than UK GDPR Art. 33(2)’s “without undue delay” standard, to allow Customer to meet its own Art. 33(1) 72-hour deadline to the Supervisory Authority.

The notification includes (a) nature of the Breach, (b) approximate categories and numbers of Data Subjects and records affected, (c) likely consequences, (d) measures taken or proposed, and (e) Leveld’s DPO contact (§13).

Leveld co-operates with Customer’s Breach response, including any notification to the ICO (Art. 33(1)) and to Data Subjects (Art. 34). Leveld documents all Breaches per Art. 33(5).

10. Audit and inspection

Leveld provides Customer with a copy of Leveld’s most recent annual third-party penetration test summary and relevant SOC 2 Type II report (when achieved) on Customer’s request, subject to Customer’s confidentiality obligations.

Where these standard artefacts are insufficient, Customer (or a Customer-mandated independent auditor) may, on 30 days’ written notice, conduct an audit of Leveld’s processing of Customer Personal Data, at Customer’s expense, during business hours, no more than once per 12-month period (unless a Personal Data Breach affecting Customer makes a more frequent audit reasonable).

Audit scope is limited to Leveld’s Art. 28 obligations and the security measures in Annex II. Audit must not compromise the confidentiality, security, or integrity of other customers’ data.

11. Return and deletion at termination

On termination of the Agreement, Customer may, within 30 days, request export of all Customer Personal Data in machine-readable JSON plus attachments zip.

Following the 30-day export window, Leveld deletes all Customer Personal Data within a further 30 days, subject to:

(a) data Leveld is required by law to retain (with the legal basis identified to Customer);
(b) tombstone records (audit-log entries) retained for compliance and dispute-resolution purposes (1 year hot + 6 years cold for SMB customers; 7 years cold for enterprise).

Backups containing Customer Personal Data are crypto-shredded within the backup retention cycle (30-day backup window). Leveld provides a certificate of deletion to Customer on request.

12. Records of processing (Art. 30(2))

Leveld maintains records of processing carried out on Customer’s behalf, containing the matters set out in Art. 30(2)(a)–(d), in writing or electronic form, available to the Supervisory Authority on request.

13. Data Protection Officer

Leveld’s Data Protection Officer is reachable at get@leveld.ai.

14. Compliance assistance and DPIA

Leveld assists Customer with Data Protection Impact Assessments (Art. 35) by providing data flows, security-measure descriptions (Annex II), Sub-processor list (Annex III), transfer mechanisms (Annex IV), and risk inputs sufficient for Customer to complete Customer’s own DPIA. Assistance is provided at no additional charge for Customer-initiated DPIAs related to the Service.

15. Liability

Each party is liable to the other for damage caused by Processing in breach of Applicable Data Protection Law in accordance with Art. 82, subject to the limitations of liability in the Agreement (see /legal/terms §11).

Where Leveld and a Sub-processor are jointly liable, Leveld remains fully liable to Customer for the Sub-processor’s performance per §6.3.

16. Term and termination

This DPA takes effect on the Agreement effective date and terminates with the Agreement. Sections that by their nature survive termination (return and deletion §11, records §12, audit §10 for any period during which Personal Data was Processed, liability §15) survive.

17. Order of precedence

In the event of a conflict, the order of precedence is: (a) UK Addendum (where executed), (b) EU SCCs (where executed), (c) this DPA, then (d) the Agreement.

18. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales, except that the EU SCCs (where executed) are governed per their own clause 17 and clause 18.

Annex I — Processing details

I.A — Categories of Personal Data

CategoryExamples
IdentificationName, job title, employee ID.
ContactEmail address, phone number, address.
AccountUser ID, email magic-code authentication events, session identifiers, and security metadata.
Communication contentAuthorised Gmail message content and attachments (incidentally including Special Categories per §5).
Project metadataRegister items, tags, assignments, dates, evidence references.
BehaviouralUI events, accept/dismiss/edit signals, calibration telemetry.
TechnicalIP address and the approximate location derived from it (city, region, country), user-agent, device fingerprint (high-risk-action context only).
Account administrationWorkspace membership, role, invitation status, and connector authorisation state.

I.B — Categories of Data Subjects

  • Customer’s authorised users.
  • Customer’s personnel referenced in Customer’s data (managers, contributors, stakeholders).
  • Customer’s clients, suppliers, and counterparties referenced in Customer’s data.
  • Personnel of Customer’s third parties whose communications transit through Customer’s connectors.

I.C — Competent Supervisory Authority

For UK-established Customers: the UK Information Commissioner’s Office (ICO). For EEA-established Customers: the lead Supervisory Authority per EU GDPR Art. 56.

Annex II — Technical and organisational measures (Art. 32)

MeasureImplementation
Encryption at restAES-256 via AWS KMS envelope encryption.
Encryption in transitTLS for external and service-to-service connections, with managed certificate validation and encrypted database, queue, and workflow connections.
Access controlRole-based access control with least-privilege; SSO + MFA for staff; per-tenant and per-user access governed by Postgres Row-Level Security.
Tenant isolationPostgres Row-Level Security on every table; tenant-scoped vector indexes; daily isolation canary.
Data minimisationTenant- and role-scoped retrieval; bounded tool schemas; no customer-data training; provider data collection denied. Customer content sent for inference is not PII-redacted by Leveld.
Audit loggingAppend-only audit log in separate database; user ID, session ID, timestamp, IP, and body hash on every send.
Backup and recoveryEncrypted snapshots; seven-day RDS automated-backup retention; protected production final snapshots; documented restore tests, RPO, and RTO targets.
Incident responseRunbooks; SEV-1/2/3 paging; quarterly tabletop exercises.
Vulnerability managementAutomated dependency monitoring, CodeQL, OWASP ZAP; signed container images; pinned toolchains.
PersonnelRole-appropriate onboarding, security training, confidentiality obligations, and prompt access removal when responsibilities end.
PhysicalData centres are operated by contracted cloud sub-processors; Leveld inherits their documented physical-security controls.
Penetration testingRisk-based security testing, automated scanning, and release review, with external testing commissioned according to risk and contractual commitments.

Annex III — Sub-processors (incorporated by reference)

The current Sub-processor list is maintained at /legal/sub-processors Section A. Notification of changes per §6.2.

Independent Third-Party Controllers (not Sub-processors) are listed at /legal/sub-processors Section B and are governed by §7 of this DPA, not §6.

Annex IV — International transfer mechanisms per Sub-processor

Sub-processorDefault locationUK→ mechanismEU→ mechanism
Amazon Web Services EMEA SARLUK primary region; global CDN edgeUK-domestic primary processing; AWS DPA for permitted transfersAWS DPA and applicable SCCs
Google Cloud EMEA LimitedGlobal APIs; EU analytics dataGoogle Cloud terms, SCCs and UK AddendumGoogle Cloud terms and applicable SCCs
WorkOS, Inc.United StatesSCCs + UK Addendum in WorkOS DPAEU SCCs
OpenRouter, Inc. and authorised downstream providersUnited States and approved endpoint locationsApplicable contract and approved transfer safeguardApplicable contract and approved transfer safeguard
Temporal Technologies, Inc.Selected production namespace regionTemporal Cloud DPA and region-specific safeguardTemporal Cloud DPA and region-specific safeguard
Grafana LabsSelected European data regionGrafana Cloud DPA and applicable safeguardIntra-EEA where EU-pinned; otherwise applicable SCCs
LangChain, Inc.EU LangSmith regionEU adequacy and LangChain DPAIntra-EEA
incident.ioContracted service regionExecuted data-processing and transfer termsExecuted data-processing and transfer terms
Zendesk, Inc.Contracted service regionExecuted DPA and transfer termsExecuted DPA and transfer terms

There is no independent third-party controller for beta payment processing. See §7.

Last updated 26 September 2026. Contact get@leveld.ai for questions about this DPA.