Data Processing Agreement
The UK GDPR Art. 28 terms that apply when we process personal data for you.
- Last updated 26 September 2026
- UK GDPR Art. 28
The UK GDPR Art. 28 terms that apply when we process personal data for you.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between:
Leveld provides a B2B SaaS agentic project-management platform. In delivering the Service, Leveld processes Personal Data on behalf of the Customer. This DPA implements the Customer’s obligations under UK GDPR Art. 28 and the Data Protection Act 2018 — and, where applicable, EU GDPR Art. 28 — to engage processors only under a written contract setting out the matters in Art. 28(3).
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | UK GDPR, the Data Protection Act 2018, and (for Customers established in the EEA or processing EEA-resident personal data) EU GDPR and the Privacy and Electronic Communications Regulations where engaged. |
| Personal Data; Processing; Controller; Processor; Data Subject; Special Categories; Personal Data Breach; Supervisory Authority | As defined in UK GDPR Art. 4 (and mirrored in EU GDPR Art. 4). |
| Customer Personal Data | Personal Data processed by Leveld on behalf of Customer under the Agreement. Annex I details categories. |
| Sub-processor | Any third party engaged by Leveld to process Customer Personal Data on Leveld’s behalf. The current list is in Annex III and at /legal/sub-processors. |
| Independent Third-Party Controller | Any third party that receives Customer Personal Data as a separate Controller rather than as a Sub-processor. None are active for the free beta. |
| EU SCCs | Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021. |
| UK Addendum | UK International Data Transfer Addendum to the EU SCCs (Version B1.0, in force 21 March 2022), or any successor approved by the ICO. |
| DUAA | Data (Use and Access) Act 2025 (in force 5 February 2026). |
| Field | Value |
|---|---|
| Subject matter | Provision of the Leveld Service to Customer. |
| Duration | Co-terminous with the Agreement. |
| Nature and purpose | Ingest, extract, store, retrieve, present, draft, and (on Customer’s instruction) send Customer Personal Data and the Personal Data of Customer’s Data Subjects, in support of project-management workflows. |
| Categories of Personal Data | See Annex I.A. |
| Categories of Data Subjects | See Annex I.B. |
| Special Categories | May be incidentally Processed (Art. 9 — health, political opinions, religious beliefs, or sexual orientation may surface in authorised Gmail content). Customer is responsible for nominating an Art. 9(2) condition and DPA 2018 Sch. 1 Part 4 appropriate policy document where required. |
Customer is the Controller of Customer Personal Data. Customer warrants that:
(a) the Personal Data has been collected and is being shared with Leveld lawfully under Applicable Data Protection Law;
(b) Customer has provided all required notices to Data Subjects (UK GDPR Arts. 13–14);
(c) Customer has a lawful basis (Art. 6) and, where applicable, an Art. 9(2) or Art. 10 condition plus a DPA 2018 Sch. 1 Part 4 appropriate policy document; and
(d) Customer’s instructions to Leveld are lawful and complete.
Where Customer is itself a Processor (i.e. Customer processes the Personal Data on behalf of Customer’s own customer or a further Controller), this DPA operates as an EU SCCs Module 3 (processor-to- processor) instrument, and Customer warrants it has the further Controller’s authorisation to engage Leveld as a sub-processor.
Leveld shall:
Process Customer Personal Data only on documented instructions from Customer (including for transfers to a third country), unless required to do otherwise by domestic law — in which case Leveld notifies Customer beforehand unless that law prohibits notification on important grounds of public interest. The Agreement, this DPA, and Customer’s use of the Service constitute documented instructions.
Ensure that persons authorised to process Customer Personal Data are bound by confidentiality (statutory or contractual).
Implement appropriate technical and organisational measures per Art. 32, summarised in Annex II.
Only engage Sub-processors per §6.
Assist Customer by appropriate technical and organisational measures, insofar as possible, to fulfil Customer’s obligation to respond to Data Subject rights requests under Chapter III.
Assist Customer in ensuring compliance with Arts. 32–36 (security, breach notification, DPIA, prior consultation), taking into account the nature of Processing and the information available to Leveld.
At Customer’s choice, return or delete all Customer Personal Data after the end of the provision of Services, and delete existing copies (subject to legal retention requirements). Default election: delete within 30 days of termination after a 30-day Customer- initiated export window. See §11.
Make available to Customer all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by Customer or a Customer-mandated auditor. See §10.
Leveld processes Customer Personal Data that may incidentally include Special Categories of Personal Data (Art. 9) and personal data relating to criminal convictions and offences (Art. 10), particularly in authorised Gmail content that Customer’s Data Subjects generate.
Customer is responsible for nominating the Art. 9(2) condition (and where applicable the DPA 2018 Sch. 1 Part 4 appropriate policy document) on which Customer relies, and for ensuring Customer’s own lawful basis covers all incidental Special Categories. Leveld treats all ingested Gmail content as if it may contain Special Categories for security-control purposes (see Annex II).
Leveld does not deliberately solicit Special Categories. Where Leveld becomes aware that a particular ingest source is intentionally producing Special Categories (e.g. medical records as input), Leveld notifies Customer and may suspend the relevant connector pending Customer’s confirmation that lawful conditions are in place.
Customer grants Leveld general written authorisation to engage Sub- processors per Art. 28(2). The current list is in Annex III and maintained at /legal/sub-processors.
Leveld will give Customer at least 30 days’ prior written notice of any addition or replacement of a Sub- processor. Customer may object on reasonable data-protection grounds within 30 days. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Service for cause (refund of pre-paid fees for the unconsumed period).
Leveld imposes on each Sub-processor data-protection obligations no less protective than those in this DPA (Art. 28(4)). Leveld remains fully liable to Customer for the performance of each Sub- processor.
No independent third-party controller receives Customer Personal Data for payment collection during the free beta. Leveld does not collect card, bank-account, mandate, or payment-transaction data for this release profile.
Any future Independent Third-Party Controller addition is notified per §6.2 (same 30-day window and objection right).
Leveld is established in the United Kingdom. Where Leveld transfers Customer Personal Data outside the United Kingdom or the European Economic Area (as applicable), Leveld relies on:
(a) UK adequacy or EU adequacy where the destination benefits from a current adequacy decision (currently includes EEA → UK and UK → EEA, both in force; UK adequacy renewed by the European Commission on 19 December 2025, valid to 27 December 2031);
(b) the EU-US Data Privacy Framework (DPF) (active since 10 July 2023) — for transfers to US recipients listed on the active DPF List, Leveld may rely on DPF certification including, where applicable, the UK Extension to the DPF (Data Bridge, in force 12 October 2023);
(c) the EU SCCs Module 3 (processor-to- processor) for transfers to non-DPF-certified recipients, executed with the UK Addendum for UK-restricted transfers; and
(d) a data protection test (DUAA 2025 terminology, replacing “transfer risk assessment” effective 5 February 2026) using the “not materially lower” threshold.
Annex IV details the per-Sub-processor mechanism. Leveld bears the obligation to maintain valid transfer mechanisms across the Sub- processor chain.
If a transfer mechanism is invalidated, Leveld notifies Customer and adopts an alternative mechanism without undue delay.
Leveld notifies Customer of any Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware. The contractual 24-hour clock is shorter than UK GDPR Art. 33(2)’s “without undue delay” standard, to allow Customer to meet its own Art. 33(1) 72-hour deadline to the Supervisory Authority.
The notification includes (a) nature of the Breach, (b) approximate categories and numbers of Data Subjects and records affected, (c) likely consequences, (d) measures taken or proposed, and (e) Leveld’s DPO contact (§13).
Leveld co-operates with Customer’s Breach response, including any notification to the ICO (Art. 33(1)) and to Data Subjects (Art. 34). Leveld documents all Breaches per Art. 33(5).
Leveld provides Customer with a copy of Leveld’s most recent annual third-party penetration test summary and relevant SOC 2 Type II report (when achieved) on Customer’s request, subject to Customer’s confidentiality obligations.
Where these standard artefacts are insufficient, Customer (or a Customer-mandated independent auditor) may, on 30 days’ written notice, conduct an audit of Leveld’s processing of Customer Personal Data, at Customer’s expense, during business hours, no more than once per 12-month period (unless a Personal Data Breach affecting Customer makes a more frequent audit reasonable).
Audit scope is limited to Leveld’s Art. 28 obligations and the security measures in Annex II. Audit must not compromise the confidentiality, security, or integrity of other customers’ data.
On termination of the Agreement, Customer may, within 30 days, request export of all Customer Personal Data in machine-readable JSON plus attachments zip.
Following the 30-day export window, Leveld deletes all Customer Personal Data within a further 30 days, subject to:
(a) data Leveld is required by law to retain (with the legal basis identified to Customer);
(b) tombstone records (audit-log entries) retained for compliance and dispute-resolution purposes (1 year hot + 6 years cold for SMB customers; 7 years cold for enterprise).
Backups containing Customer Personal Data are crypto-shredded within the backup retention cycle (30-day backup window). Leveld provides a certificate of deletion to Customer on request.
Leveld maintains records of processing carried out on Customer’s behalf, containing the matters set out in Art. 30(2)(a)–(d), in writing or electronic form, available to the Supervisory Authority on request.
Leveld’s Data Protection Officer is reachable at get@leveld.ai.
Leveld assists Customer with Data Protection Impact Assessments (Art. 35) by providing data flows, security-measure descriptions (Annex II), Sub-processor list (Annex III), transfer mechanisms (Annex IV), and risk inputs sufficient for Customer to complete Customer’s own DPIA. Assistance is provided at no additional charge for Customer-initiated DPIAs related to the Service.
Each party is liable to the other for damage caused by Processing in breach of Applicable Data Protection Law in accordance with Art. 82, subject to the limitations of liability in the Agreement (see /legal/terms §11).
Where Leveld and a Sub-processor are jointly liable, Leveld remains fully liable to Customer for the Sub-processor’s performance per §6.3.
This DPA takes effect on the Agreement effective date and terminates with the Agreement. Sections that by their nature survive termination (return and deletion §11, records §12, audit §10 for any period during which Personal Data was Processed, liability §15) survive.
In the event of a conflict, the order of precedence is: (a) UK Addendum (where executed), (b) EU SCCs (where executed), (c) this DPA, then (d) the Agreement.
This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales, except that the EU SCCs (where executed) are governed per their own clause 17 and clause 18.
| Category | Examples |
|---|---|
| Identification | Name, job title, employee ID. |
| Contact | Email address, phone number, address. |
| Account | User ID, email magic-code authentication events, session identifiers, and security metadata. |
| Communication content | Authorised Gmail message content and attachments (incidentally including Special Categories per §5). |
| Project metadata | Register items, tags, assignments, dates, evidence references. |
| Behavioural | UI events, accept/dismiss/edit signals, calibration telemetry. |
| Technical | IP address and the approximate location derived from it (city, region, country), user-agent, device fingerprint (high-risk-action context only). |
| Account administration | Workspace membership, role, invitation status, and connector authorisation state. |
For UK-established Customers: the UK Information Commissioner’s Office (ICO). For EEA-established Customers: the lead Supervisory Authority per EU GDPR Art. 56.
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256 via AWS KMS envelope encryption. |
| Encryption in transit | TLS for external and service-to-service connections, with managed certificate validation and encrypted database, queue, and workflow connections. |
| Access control | Role-based access control with least-privilege; SSO + MFA for staff; per-tenant and per-user access governed by Postgres Row-Level Security. |
| Tenant isolation | Postgres Row-Level Security on every table; tenant-scoped vector indexes; daily isolation canary. |
| Data minimisation | Tenant- and role-scoped retrieval; bounded tool schemas; no customer-data training; provider data collection denied. Customer content sent for inference is not PII-redacted by Leveld. |
| Audit logging | Append-only audit log in separate database; user ID, session ID, timestamp, IP, and body hash on every send. |
| Backup and recovery | Encrypted snapshots; seven-day RDS automated-backup retention; protected production final snapshots; documented restore tests, RPO, and RTO targets. |
| Incident response | Runbooks; SEV-1/2/3 paging; quarterly tabletop exercises. |
| Vulnerability management | Automated dependency monitoring, CodeQL, OWASP ZAP; signed container images; pinned toolchains. |
| Personnel | Role-appropriate onboarding, security training, confidentiality obligations, and prompt access removal when responsibilities end. |
| Physical | Data centres are operated by contracted cloud sub-processors; Leveld inherits their documented physical-security controls. |
| Penetration testing | Risk-based security testing, automated scanning, and release review, with external testing commissioned according to risk and contractual commitments. |
The current Sub-processor list is maintained at /legal/sub-processors Section A. Notification of changes per §6.2.
Independent Third-Party Controllers (not Sub-processors) are listed at /legal/sub-processors Section B and are governed by §7 of this DPA, not §6.
| Sub-processor | Default location | UK→ mechanism | EU→ mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL | UK primary region; global CDN edge | UK-domestic primary processing; AWS DPA for permitted transfers | AWS DPA and applicable SCCs |
| Google Cloud EMEA Limited | Global APIs; EU analytics data | Google Cloud terms, SCCs and UK Addendum | Google Cloud terms and applicable SCCs |
| WorkOS, Inc. | United States | SCCs + UK Addendum in WorkOS DPA | EU SCCs |
| OpenRouter, Inc. and authorised downstream providers | United States and approved endpoint locations | Applicable contract and approved transfer safeguard | Applicable contract and approved transfer safeguard |
| Temporal Technologies, Inc. | Selected production namespace region | Temporal Cloud DPA and region-specific safeguard | Temporal Cloud DPA and region-specific safeguard |
| Grafana Labs | Selected European data region | Grafana Cloud DPA and applicable safeguard | Intra-EEA where EU-pinned; otherwise applicable SCCs |
| LangChain, Inc. | EU LangSmith region | EU adequacy and LangChain DPA | Intra-EEA |
| incident.io | Contracted service region | Executed data-processing and transfer terms | Executed data-processing and transfer terms |
| Zendesk, Inc. | Contracted service region | Executed DPA and transfer terms | Executed DPA and transfer terms |
There is no independent third-party controller for beta payment processing. See §7.
Last updated 26 September 2026. Contact get@leveld.ai for questions about this DPA.