Legal

Data Processing Agreement

Last updated 28 June 2026

Section 1: Parties and Roles

  • 1.1 Processor: LeMans Labs OÜ, Estonian commercial registry no. 16872044, registered office Valukoja 8/1, 11415 Tallinn, Estonia ("ewpire", "Processor").
  • 1.2 Controller: the account holder (the "Subscription Admin") acting for the subscribing natural person or legal entity ("Controller"). The Processor acts as the Controller's processor only in respect of the product inputs and artifacts described in §1.5(a); the parties' roles for all other processing are set out in §1.5.
  • 1.5 Mixed roles. The parties acknowledge that the Processor does not act as a pure processor across the whole Service. Roles are allocated as follows:
    • (a) Processor role. For the product inputs and generated artifacts the Controller submits to or obtains from the Ideation, Validation and Traffic products (idea text, interview answers, brand/site content, prompts, generated source code, deployment artifacts, presence assets, brand-audit outputs, and the inference artifacts derived from them), the Processor acts as the Controller's processor and the processor obligations in this DPA apply.
    • (b) Independent-controller role. For account-management, billing and payment, security and fraud prevention, service telemetry, product-improvement and marketing data that the Processor determines the purposes and means of, the Processor acts as an independent controller under its own Privacy Policy and is not the Controller's processor for that processing. Such product-improvement is conducted through human or consensus review and never includes training or fine-tuning any LLM provider's model weights on Controller content.
    • (c) Joint controllership (Art. 26). Where the parties jointly determine the purposes and means of a given processing activity, they will agree the essential allocation of their respective Art. 26 GDPR responsibilities in a separate arrangement before that activity begins.
  • 1.3 Data Scope: all Personal Data (GDPR Art. 4(1)) processed by the Processor on the Controller's behalf in connection with the Service, including: the Controller's account and business-contact data; the idea text, interview answers, brand/site content and other inputs the Controller submits to the Ideation, Validation and Traffic products; source code, configuration and deployment artifacts generated or processed during Validation; brand- and entity-monitoring inputs and outputs in Traffic; and inference artifacts (prompts, model outputs, confidence and dissent-map metadata, telemetry).
  • 1.4 Exclusions. Payment-card and financial data submitted in the checkout flow are processed by Stripe Payments Europe Limited and/or other Stripe entities as applicable, as an independent controller under Stripe's own terms; the Processor does not store full card data. The Processor does not offer "bring-your-own-key" (BYOK) at v3 launch: the consensus LLM providers listed in Annex III are engaged by the Processor as its own direct sub-processors, and the BYOK-exclusion framing of the prior version does not apply. Where the Controller voluntarily pastes a third party's personal data or special-category data into a product input, the Controller remains responsible for having a lawful basis to do so (Art. 6, and where applicable Art. 9).

Section 2: Subject Matter, Duration, Purpose

  • 2.1 Subject matter. Processing necessary to deliver the Service (the Ideation, Validation and Traffic products and the surrounding account, credit-ledger, billing and support functions).
  • 2.2 Duration. From the effective date of this DPA until live-system Personal Data is deleted within 30 days after termination or cancellation of the account, with encrypted backups overwritten on a rolling cycle of at most 90 days (not restored except for disaster recovery), subject to any longer retention required by EU or Estonian law (including referral and financial records retained for 7 years under the Estonian Accounting Act (Raamatupidamise seadus)).
  • 2.3 Nature of processing. Collection, storage, transmission to sub-processors for inference and delivery, multi-provider LLM inference, code build and execution in a sandboxed runtime, deployment of generated applications to hosting infrastructure, rendering of outputs (reports, builds, presence assets, audits), brand/entity monitoring, and deletion.
  • 2.4 Purpose limitation. Solely to provide the Service; no other purpose without the Controller's specific documented instruction.
  • 2.5 Data subjects. The Controller and its personnel; co-founders, collaborators and team members invited to the account; and any natural persons whose personal data the Controller chooses to include in a product input (e.g. named individuals in an idea brief, brand or competitor research, or generated application content).
  • 2.6 Data categories. Identifiers (name, email); account and billing-contact data; product inputs (idea text, interview answers, brand and website content, prompts); generated artifacts (consensus reports, source code, deployment configuration, presence/AEO assets, brand-audit results); technical data (IP address, user-agent, timestamps, usage and credit-consumption telemetry).
  • 2.7 Special categories (Art. 9). Not intended. The Controller undertakes not to submit special-category data without a supplementary written schedule agreed in advance. The not-advice / structured-deliberation characterisation, confidence scores and dissent maps, and the AI-output marking are governed by the Terms of Service and the in-product disclaimers, not by this DPA; this clause does not host the substantive marketing or transparency disclaimers.
  • 2.8 Controller warranty and indemnity. The Controller warrants that, for all Personal Data it submits to the Service (including any third party's personal data and any named third parties in idea briefs, brand or competitor research, or generated content), it has a valid lawful basis under Art. 6 GDPR (and where applicable an Art. 9 condition), and has provided the transparency information required by Art. 13/14 GDPR to the relevant data subjects. The Controller indemnifies the Processor against third-party claims and regulatory liability arising from a breach of this warranty. The Processor may suspend or refuse processing of inputs it reasonably suspects to be unlawful or to contain special-category data submitted without an agreed schedule, and will notify the Controller without undue delay.

Section 3: Processor Obligations (Art. 28(3))

  • 3.1 Instruction-only processing. The Processor processes Personal Data only on the Controller's documented instructions, including as to international transfers, unless required otherwise by EU or Estonian law (in which case the Processor informs the Controller before processing, unless that law prohibits such information on important grounds of public interest).
  • 3.2 Confidentiality. Persons authorised to process the data are bound by confidentiality.
  • 3.3 Security (Art. 32). The Processor implements the technical and organisational measures in Annex II.
  • 3.4 Sub-processors. Engaged only in accordance with Section 4.
  • 3.5 Data-subject requests. The Processor assists the Controller, by appropriate measures, to respond to data-subject requests (Art. 12–22); requests received directly are forwarded to the Controller without undue delay, and substantive responses require the Controller's authorisation.
  • 3.6 Compliance assistance. The Processor assists the Controller in ensuring compliance with Art. 32–36 (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and the information available.
  • 3.7 Deletion or return. At the end of the provision of the Service, the Processor deletes or returns all Personal Data at the Controller's choice. Live-system Personal Data is deleted within 30 days of account termination, and the Processor will certify that live deletion within that 30-day window on request. Existing copies held in encrypted backups are overwritten on a rolling cycle of at most 90 days and are not restored except for disaster recovery; backups are kept encrypted until overwritten. This is subject to any longer retention required by EU or Estonian law (including referral and financial records retained for 7 years under the Estonian Accounting Act (Raamatupidamise seadus)).
  • 3.8 Audit rights. The Processor makes available the information necessary to demonstrate Art. 28 compliance and allows for and contributes to audits (no more than once per year, on 30 days' written notice, during business hours, subject to confidentiality; more frequently on a regulatory trigger, complaint or incident). In the first instance, the Processor's SOC 2 Type II, ISO 27001 or equivalent reports plus a completed security questionnaire satisfy most audit requests. Where an on-site inspection is nonetheless required, it is limited to a confidentiality-bound independent third-party auditor (not the Controller's own staff or a competitor) and excludes any data of other controllers, shared production systems, and infrastructure that the Processor cannot expose without breaching other customers' confidentiality or security.
  • 3.9 Instruction-breach notice. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other EU/Member-State data-protection law.
  • 3.10 California service-provider obligations. To the extent CCPA/CPRA applies, the Processor acts as a service provider: it does not sell or share Personal Data, processes it only for the business purpose specified, does not combine it impermissibly, and notifies the Controller if it can no longer meet its obligations.
  • 3.11 AI Act transparency interface. The Processor provides the technical means for the Controller to meet its transparency obligations under Art. 50 of the AI Act (Reg. (EU) 2024/1689, Art. 50 applying from 2 August 2026), including disclosure that the user is interacting with an AI system (Art. 50(1), Ideation chat) and machine-readable marking of AI-generated or AI-manipulated outputs (Art. 50(2), Validation code and Traffic content) from 2 August 2026, by reference to the General-Purpose AI Code of Practice published 10 June 2026. The Processor acts as a provider of these AI systems; the Controller acts as a deployer and retains its own Art. 50 duties (including Art. 50(4) disclosure for deepfake or AI-generated text it publishes).

Section 4: Sub-Processors

  • 4.1 General authorisation. The Controller grants general authorisation to the sub-processors listed in Annex III and to their replacements.
  • 4.2 Change notice. The Processor gives tiered advance notice before adding or replacing a sub-processor, by updating ewpire.com/subprocessors and emailing the Controller's billing contact: at least 30 days' notice for a new non-EEA sub-processor, and at least 14 days' notice for an EEA or like-for-like replacement. The Controller may object within the applicable notice window on reasonable data-protection grounds; if the parties cannot agree, the Controller may terminate the affected portion of the Service with a pro-rata refund of any prepaid, unused credits or subscription fees.
  • 4.3 Flow-down. The Processor imposes on each sub-processor, by contract, data-protection obligations materially equivalent to those in this DPA, and remains fully liable to the Controller for each sub-processor's performance.

Section 5: International Transfers

  • 5.1 EEA default storage. Persistent Controller Personal Data is stored on EEA infrastructure – primarily Cloudflare EU edge/storage and a Hetzner Germany VPS that runs the Processor's own consensus engine and Python worker. User applications generated in Validation are not co-located on the Hetzner VPS; they are deployed to and hosted on Cloudflare (Pages/Workers). The Hetzner VPS hosts ewpire's own engine only.
  • 5.2 Transfers to third countries. Where Personal Data is transmitted to a sub-processor outside the EEA without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), using the module appropriate to the transfer: Module Two (controller-to-processor) for the Processor's transfers to its non-EEA processor sub-processors, Module Three (processor-to-processor) for onward processor-to-processor transfers, including those routed via OpenRouter to additional labs, and Module One (controller-to-controller) where both parties act as independent controllers (e.g. Stripe). Each transfer is supplemented by a transfer-impact assessment (TIA) and appropriate supplementary measures (encryption in transit and at rest, data minimisation, contractual no-training commitments). Where the data importer is itself directly subject to the GDPR under Art. 3(2), the SCCs are not the correct instrument; pending adoption of the additional clauses the Commission has indicated it will publish for such importers, the Processor relies on the importer's direct GDPR compliance together with the same supplementary safeguards, and will adopt the appropriate dedicated transfer tool once it is available.UK transfers rely on the UK International Data Transfer Addendum (IDTA) to the SCCs. Signed copies are available on request.
  • 5.3 Multi-provider LLM inference (v3-specific). The Controller is informed and instructs that, to operate the consensus primitive, the idea text, interview answers, brand and site content, prompts and (in Validation) generated code are transmitted to multiple frontier LLM providers for inference, some of which are located outside the EEA (United States, Singapore). The Processor contracts with each such provider on a no-training / no-model-improvement basis (the data is not used to train or fine-tune the provider's models) and uses the safeguards in Section 5.2. China-based providers (DeepSeek, Zhipu AI/GLM) are OFF by default. No identifiable Controller Personal Data is routed to a China-based provider: such providers are engaged only where the Controller has expressly opted in, or after pseudonymisation that ensures no identifiable data leaves the EEA. The Controller may set a permanent, free, account-level exclusion of all China-based providers, which the Processor will honour.The list of providers and their transfer mechanisms is in Annex III.
  • 5.4 Destinations. Transfer destinations and mechanisms are set out in Annex III.

Section 6: Breach Notification

  • 6.1 The Processor notifies the Controller of any personal-data breach without undue delay, where feasible within 24 hours, and in no event later than 48 hours of becoming aware of it, with the information required by Art. 33(3) to the extent available.
  • 6.2 The Controller is responsible for notifying supervisory authorities and data subjects where required; the Processor assists as set out in §3.6.
  • 6.3 The Processor maintains a breach log for at least three years (Art. 33(5)).

Section 7: Liability

  • 7.1 The liability cap in the Terms of Service "Limitation of Liability" section applies to this DPA, except that: for damages payable under Art. 82 GDPR an enhanced super-cap of two (2) times the total fees paid by the Controller in the twelve (12) months before the event applies in place of the standard cap; and no cap applies to liability arising from gross negligence or wilful misconduct. Mandatory liability that cannot be limited under applicable law (including supervisory-authority fines borne by the liable party) is unaffected.
  • 7.2 Where the Processor and Controller are both responsible for damage, liability is allocated in accordance with Art. 82(4) and (5).

Section 8: Term, Conflict, Governing Law

  • 8.1 Term. From the effective date until cancellation of the account and for so long as the Processor retains Controller Personal Data.
  • 8.2 Conflict. In case of conflict on data-protection matters, this DPA prevails over the Terms of Service.
  • 8.3 Governing law and forum. This DPA is governed by Estonian law. The courts of Tallinn (Harju County Court) have jurisdiction, without prejudice to the data subject's rights under Art. 79(2) GDPR.

Annex II: Technical & Organizational Measures (Art. 32)

  • Access control. Role-based access control, least privilege, multi-factor authentication, bastion-host access to production infrastructure.
  • Encryption. TLS 1.3 in transit; AES-256-GCM at rest; per-account Data Encryption Keys so that one Controller's data cannot be decrypted with another's key.
  • Tenant isolation. Per-account logical isolation across the platform. Generated user MVPs are isolated per Cloudflare Worker / Pages project (one deployment target per build), and Validation builds run in per-build sandboxed runtimes (Daytona) that are torn down after use. The Processor's own consensus engine on the Hetzner VPS enforces per-account separation of stored data and credentials.
  • Logging. Structured security-event logging with 90-day retention and operational alerting.
  • Change management. Version-controlled configuration, mandatory peer review, blue-green / progressive deployment.
  • Backups. Daily encrypted backups overwritten on a rolling cycle of at most 90 days; backups are kept encrypted and not restored except for disaster recovery; point-in-time recovery within 48 hours.
  • Vulnerability management. Automated dependency scanning, regular patching, and an annual independent third-party penetration test.
  • Personnel. Confidentiality undertakings, GDPR training (onboarding and annual), access revocation within 24 hours of a role change.
  • Business continuity. Documented incident-response plan; recovery-time objective within 24 hours (Business); recovery-point objective within 1 hour.
  • Deletion. Live-system Personal Data deleted within 30 days of a valid request or of account termination, certified on request; backup copies overwritten on the rolling cycle of at most 90 days described above. Referral and financial records are retained for 7 years under the Estonian Accounting Act (Raamatupidamise seadus). Further detail available under NDA at ewpire.com/security.

Annex III: Authorised Sub-Processors

The current, authoritative list of the Processor's authorised sub-processors – each with its role, processing location, and transfer mechanism – is published and maintained at ewpire.com/subprocessors. That list forms part of this DPA, and the Controller's general authorisation under §4.1 extends to it as updated from time to time under the §4.2 change-notice procedure. A point-in-time snapshot as of the effective date of this DPA is available on request.

Referral-payout / DAC7 note. Stripe performs the referral payouts and runs any tax-form onboarding (W-8/W-9) for payees. The DAC7 platform-reporting regime (Council Directive (EU) 2021/514) does not cover affiliate, referral or advertising arrangements; the Processor therefore does not assert and does not undertake a DAC7 reporting role for its referral programme.

China-provider TIA note. DeepSeek and Zhipu AI (GLM) are established in the People's Republic of China, which has no EU adequacy decision and a legal regime (including state data-access and national-intelligence laws) that warrants a heightened transfer-impact assessment. These providers are OFF by default: per §5.3, no identifiable Controller Personal Data is routed to them; they are engaged only on the Controller's express opt-in, or after pseudonymisation so that no identifiable data leaves the EEA. The Processor applies enhanced supplementary measures: contractual no-training and confidentiality commitments, encryption in transit, and data minimisation. The Controller may set a permanent, free, account-level exclusion of all China-based providers, and may otherwise object under §4.2; the Processor will document the TIA and supplementary measures and make them available on request.

Routing note. Because the consensus primitive selects the best model per task, not every listed sub-processor processes every request; a given input is transmitted only to the subset of providers engaged for that deliberation. OpenRouter is used as a fallback to reach additional labs and for resilience.

Deferred / not yet engaged. Additional providers (e.g. further frontier labs reached via OpenRouter, or future Validation-tooling sub-processors) will be added under the §4.2 change-notice procedure (30 days' notice for a new non-EEA sub-processor, 14 days for an EEA or like-for-like replacement). BYOK and any enterprise-only arrangements are out of scope at v3 launch.

Annex IV: Notification Contacts

  • Processor → Controller: the account billing email (Stripe billing contact) and in-product notification to the Subscription Admin.
  • Controller → Processor: [email protected] (copy: [email protected]).
  • Supervisory Authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI), Tatari 39, 10134 Tallinn, Estonia.