Data Processing Agreement (DPA)
LISA Data Processing Agreement (DPA)
Status: ✅ FINALIZED — Ready for Customer Signature
Effective: Upon signature (or [DATE OF ACTIVATION] if specified)
Governing Law: Swiss law (Canton Zurich) + GDPR
GDPR Article 28 Data Processor Agreement
1. Parties
- Data Controller: [CUSTOMER NAME] ("Customer")
- Data Processor: LISA GmbH ("Processor" / "LISA")
- Effective Date: [DATE OF ACTIVATION]
2. Scope
This DPA governs the processing of personal data by LISA on behalf of the Customer as part of the LISA assessment or subscription service.
Applicable data:
- M365 configuration data (policies, settings, user counts)
- Entity identifiers (hashed/pseudonymized)
- Audit logs and scan results
NOT applicable to:
- Email contents, files, chats, or user data (not scanned)
- Publicly available information
3. Processing Details
3.1 Purpose
LISA processes customer data for the sole purpose of:
- Performing security assessments
- Generating findings and recommendations
- Providing the LISA service
3.2 Duration
Processing continues for the duration of the subscription or assessment engagement. After termination:
- Assessment findings retained for 90 days
- Raw Graph API logs deleted after 30 days
- Pseudonymized entity identifiers deleted after 90 days
- Backup copies deleted after 30 days of primary deletion
3.3 Nature & Scope
- Categories of data: Configuration settings, entity counts, security policies
- Categories of data subjects: Implied (users referenced in configuration)
- Processing operations: Collection, analysis, aggregation, reporting
- Frequency: Typically once per assessment period; continuous for subscriptions
4. Processor Obligations (GDPR Art. 28(3))
LISA commits to:
4.1 Confidentiality
- Only authorized personnel access customer data
- All LISA staff sign confidentiality agreements
- No disclosure to third parties without written consent
4.2 Security (GDPR Art. 32)
- Encryption in transit (HTTPS/TLS) and at rest (AES-256)
- Access controls (role-based, authentication, audit logs)
- Pseudonymization of identifiers (HMAC-SHA256 hashing)
- Regular security testing and vulnerability scanning
- Incident response procedures (breach notification within 72 hours)
4.3 Sub-processors (GDPR Art. 28(2)(4))
LISA uses the following sub-processors (with Data Processing Agreements in place):
| Sub-processor | Purpose | Location | DPA Status |
|---|---|---|---|
| Supabase | Data storage (findings, configs, metadata) | Switzerland (Zurich) | ✅ Signed (Adequacy Decision Art. 45 GDPR) |
| Anthropic Claude API | Findings synthesis (convert signals to recommendations) | USA | ✅ Standard Contractual Clauses (SCCs) in place |
| Microsoft Graph API | M365 configuration data access (read-only) | Global (customer's tenant) | ✅ Microsoft OST + implicit DPA via M365 agreement |
| Azure Key Vault | Encryption keys for pseudonym secrets | Switzerland (LISA tenant) | ✅ LISA-controlled |
Important notes on sub-processors:
- LISA does NOT send raw customer data to Anthropic; only aggregated, non-identifying signals
- LISA does NOT send customer data to any processor without explicit DPA
- All transfers are protected by Standard Contractual Clauses where required
Notice: Customer will be notified of new sub-processors at least 30 days in advance. Customer may object to new sub-processors on reasonable grounds; LISA will discuss alternatives or allow termination without penalty.
4.4 Assistance to Controller
LISA will assist the Customer in meeting their obligations under GDPR Articles 32–36:
- Implementing data subject rights (access, deletion, correction)
- Data breach notification
- Data protection impact assessments (DPIAs)
- Audit and inspection rights
4.5 Data Deletion / Return
Upon termination, subscription expiration, or customer request, LISA will:
- Delete or return customer data within 30 days
- Provide written certification of deletion
- Customer may request proof (at customer's expense for audits >1 year after deletion)
Exceptions to deletion:
- Data required by law (tax law, audit obligations) may be retained as anonymized records only
- Backup copies deleted within 30 days of primary deletion
- After 30 days, no original data remains
5. Data Transfers (GDPR Art. 46)
LISA may transfer data outside the EEA:
5.1 USA Transfers (Anthropic)
- Protected by Standard Contractual Clauses (SCCs) — GDPR Art. 46(2)(c)
- Anthropic has adopted SCCs per EU adequacy requirements
5.2 Customer Consent
By executing this DPA and accepting the Terms of Service, Customer consents to transfers to USA sub-processors under SCCs.
6. Data Subject Rights
Customer is responsible for handling requests from data subjects (their employees, users). LISA will:
- Access requests (Art. 15): Provide a copy of data within 14 days of request
- Deletion requests (Art. 17): Delete data within 14 days (unless legal basis requires retention)
- Correction requests (Art. 16): Correct inaccurate data
- Restriction requests (Art. 18): Freeze processing upon request
- Portability requests (Art. 20): Provide data in portable format (CSV, JSON)
7. Audit & Inspection (GDPR Art. 28(3)(h))
7.1 Customer Audit Rights
Customer has the right to:
- Request proof of LISA's GDPR compliance (response within 14 days)
- Audit LISA's security practices (with 14-day advance notice)
- Engage a third-party auditor (e.g., SOC 2 auditor) to verify compliance
Audit frequency:
- Customer may conduct or request audits once per calendar year at no cost to LISA
- Additional audits may be conducted if LISA suffers a security incident
- Audits must occur during business hours and not disrupt service
7.2 LISA Audit Rights
LISA may audit Customer's M365 tenant data during scans to:
- Verify accurate data collection
- Validate scanner signals
- Ensure compliance with LISA's terms
8. Data Breach Notification (GDPR Art. 33–34)
If LISA discovers a data breach affecting Customer:
8.1 LISA's Notification
LISA will notify Customer within 24 hours of discovering the breach (not 72 hours, as GDPR allows — LISA is committed to speed).
Notification will include:
- Nature of the breach (what data, how much)
- Likely consequences
- Measures LISA has taken to contain it
- LISA's contact for further information
8.2 Customer's Notification
Customer is responsible for notifying data subjects if the breach poses high risk (GDPR Art. 34).
LISA will assist with breach notification drafting if needed.
9. Data Protection Impact Assessment (DPIA)
If a new processing activity poses high risk, LISA will:
- Conduct a DPIA with the Customer
- Share results with Customer
- Support Customer's DPIA filing with authorities if needed
10. Standard Contractual Clauses (SCCs)
For any data transfers outside the EEA (e.g., to Anthropic in USA), the parties agree to the EU's Standard Contractual Clauses (Modules available at: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en).
SCC Application:
- Anthropic (USA): SCCs Module Two (Processor to Processor) — LISA ensures Anthropic has adopted SCCs
- Supabase (Switzerland): SCCs not required — Adequacy Decision (Art. 45 GDPR)
- Microsoft (Global): Microsoft's own adequacy safeguards apply
Customer acknowledgment: By executing this DPA, Customer consents to transfers under SCCs to sub-processors in non-EEA jurisdictions.
11. Liability & Limitation
11.1 LISA's Liability for Data Processing
LISA is liable for breaches of this DPA and GDPR Article 82 (data processor liability).
Liability cap:
- Capped at fees paid by Customer in the 12 months prior to the breach
- Minimum: CHF 100,000 (for serious breaches)
- Maximum: CHF 500,000 (to align with LISA's insurance coverage and financial capacity)
- Excludes: Indirect, incidental, consequential, or punitive damages
11.2 Customer Indemnification
Customer indemnifies LISA for claims arising from:
- Customer's processing instructions that violate GDPR
- Customer's failure to obtain lawful basis for processing
- Customer's misuse of LISA findings or data
12. Amendment & Termination
12.1 Amendment
This DPA may be updated to reflect:
- GDPR regulatory changes
- New sub-processors (with 30-day notice)
- Updated security measures or infrastructure changes
LISA will notify Customer at least 30 days in advance of material changes. If Customer objects to material changes (other than security improvements), Customer may terminate without penalty.
12.2 Termination
This DPA terminates when:
- The subscription ends
- LISA is no longer processing customer data
- The agreement is otherwise terminated in writing
13. Governing Law
This DPA is governed by Swiss law (Canton Zurich) and GDPR (which overrides any conflicting local law).
Signature
By signing below, both parties agree to this Data Processing Agreement. This DPA is incorporated into and forms part of the Customer's Terms of Service with LISA.
For Customer:
Organization: ____________________
Signatory Name: ____________________
Title: ____________________
Signature: ____________________
Date: ____________________
For LISA GmbH:
Name: Thierry Schuepbach
Title: Chief Executive Officer
Signature: ____________________
Date: ____________________
Document Control
| Aspect | Value |
|---|---|
| Version | 1.0 (Final) |
| Last Updated | 2026-06-13 |
| Status | ✅ FINALIZED — Ready for Customer Signature |
| Effective Date | Upon signature (or [Customer Activation Date] if specified) |
| Governing Law | Swiss law (Canton Zurich) + GDPR/nDSG |
| Next Review | Annually or upon material GDPR regulatory change |
How to Use This DPA
For each customer assessment or subscription:
- Before collecting data: Customer signs this DPA
- During assessment: LISA processes M365 data per terms above
- After assessment: Data deleted per retention schedule (90 days findings, 30 days logs)
- Upon termination: All data deleted within 30 days, certification provided
Questions about this DPA? Contact: legal@runlisa.ch