Data processing agreement
How we process personal data on your organisation's behalf, and the measures standing behind that. No signature needed.
This Data Processing Agreement ("DPA") forms part of the Lumural Terms of Service. It applies whenever you use a Lumural Team workspace on behalf of an organisation and that use involves personal data of your members, colleagues, customers or others.
It is entered into between:
- Customer: the organisation that owns the workspace, represented by the workspace owner (the "Controller"); and
- CA Systems, Sweden, operator of Lumural (the "Processor"). Organisation number and postal address are provided on request.
No signature is needed. By creating or using a workspace on behalf of an organisation you accept this DPA. If you need a countersigned copy, email support@lumural.com.
01Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor" and "data subject" have the meaning given in the GDPR (Regulation (EU) 2016/679).
"Customer Data" means personal data that the Controller, or people acting for it, puts into a Team workspace: member details, board content, uploaded files and related metadata.
02Roles
The Controller decides what Customer Data goes into the workspace and why. The Processor processes it only to provide the Service.
The Processor is an independent controller for account data of individual users, for personal boards and boards shared on the Free plan, for published community content, for billing records and for security and usage logs. Those are covered by the Privacy Policy, not this DPA.
03Details of processing
- Subject matter
- Providing the Lumural workspace service.
- Duration
- For as long as the workspace exists, plus the deletion period in section 9.
- Nature and purpose
- Storing, displaying, syncing, backing up and rendering Customer Data so members can collaborate.
- Categories of data
- Names, email addresses, account identifiers, board content and uploaded files, which may contain any personal data the Controller chooses to put there.
- Data subjects
- Workspace members and invitees; anyone whose personal data members put into boards.
The Controller must not put special-category data (Art. 9 GDPR) or data about criminal offences into Lumural unless it has confirmed with the Processor in writing that appropriate measures are in place.
04Processor obligations
The Processor will:
- process Customer Data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the Service, unless EU or Swedish law requires otherwise, in which case the Processor will inform the Controller before processing unless the law forbids it;
- tell the Controller if an instruction appears to breach the GDPR;
- ensure that everyone with access to Customer Data is bound by confidentiality;
- implement the security measures in Annex 1;
- assist the Controller, with reasonable notice, in responding to data subject requests and in meeting its obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available;
- delete or return Customer Data at the end of the service as described in section 9;
- make available the information needed to demonstrate compliance and allow audits under section 8.
05Controller obligations
The Controller is responsible for having a lawful basis for the Customer Data it processes, for informing its data subjects, and for the accuracy and legality of what its members put into Lumural. The Controller will not use the Service in a way that causes the Processor to breach the GDPR.
06Sub-processors
The Controller gives general authorisation for the Processor to use the sub-processors listed at lumural.com/legal/subprocessors. All are EU companies operating EU data centres.
The Processor will update that page at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Controller may terminate the affected workspace and receive a pro-rata refund of prepaid fees.
The Processor remains responsible for its sub-processors and imposes data protection obligations on them equivalent to those in this DPA.
07International transfers
The Processor stores and processes Customer Data only within the EU/EEA. Any future transfer outside the EU/EEA would be announced as a sub-processor change under section 6 and covered by an appropriate transfer mechanism under Chapter V GDPR.
08Audits
On request, no more than once a year unless a breach or supervisory authority requires otherwise, the Processor will answer reasonable written security questions and provide available documentation. If that does not satisfy a legal requirement, the Controller may conduct an audit at its own cost, with at least 30 days' notice, during business hours, under confidentiality, and without disrupting the Service.
09Deletion and return
The Controller can export boards to PDF or PNG at any time. When a workspace is deleted, or a membership ends, the Processor deletes the relevant Customer Data from live systems within 30 days and from backups within 60 days, unless EU or Swedish law requires retention.
Content that a member has published to the Lumural community before leaving is governed by the Terms and the licence chosen at publication, not by this section.
10Personal data breaches
The Processor will notify the Controller without undue delay, and no later than 72 hours after becoming aware of a personal data breach affecting Customer Data. The notification will describe what is known: the nature of the breach, likely consequences, measures taken or proposed, and a contact point. Further information follows as it becomes available.
Notification goes to the workspace owner's email address. Keep it current.
11Liability
Each party is liable to the other under this DPA to the extent set out in the Terms of Service. Nothing here limits either party's liability towards data subjects or supervisory authorities under Art. 82 GDPR.
12Term and precedence
This DPA lasts for as long as the Processor processes Customer Data. If it conflicts with the Terms, this DPA prevails on data protection matters. Swedish law governs it.
Annex 1: technical and organisational measures
- Hosting
- Application and database on dedicated servers at Hetzner (Finland, Germany). Uploaded assets and backups in object storage at Scaleway (France). All providers are EU companies with ISO 27001 certified data centres.
- Encryption
- TLS 1.2 or higher for all traffic. Encryption at rest on database volumes and object storage. Backups encrypted before leaving the application server.
- Access control
- Production access is limited to the operator. SSH access is key-based only, with password authentication disabled. Administrative interfaces are not exposed to the public internet. Passwords are hashed with a modern algorithm.
- Application security
- Workspace isolation is enforced at the application and database layer. Dependencies are updated regularly. Error monitoring is self-hosted on the Processor's own infrastructure.
- Backups
- Automated nightly encrypted backups retained for up to 60 days, stored with a different provider from the live system. Restore procedures are tested.
- Logging
- Server and error logs kept for a maximum of 30 days.
- Deletion
- Deleted data is removed from live systems within 30 days and expires from backups within 60 days.
- Organisation
- CA Systems is a sole proprietorship. The operator is the only person with access to production data and is bound by this DPA's confidentiality obligations directly. Any future staff or contractors with access will sign confidentiality agreements before access is granted.
- Incidents
- Breaches are assessed, contained and reported as described in section 10.