Skip to content
Legal

Data Processing Agreement

Last updatedJuly 12, 2026
Summary. This DPA forms part of the agreement between Landi and its customers. It applies when Landi processes personal data on a customer’s behalf — most notably data about visitors to pages the customer publishes — and sets out roles, security measures, subprocessing, and transfer safeguards.

1. Introduction and roles

This Data Processing Agreement (the “DPA”) forms part of the agreement between Landi and the customer (the “Agreement”) and applies where Landi processes personal data on the customer’s behalf in providing the Services (“Customer Personal Data”) — most notably data about visitors to landing pages the customer generates and publishes through Landi.

For Customer Personal Data, the customer is the controller (or a processor acting on behalf of another controller) and Landi is the processor. Where Landi processes personal data for its own purposes — such as account, billing, and marketing data — it does so as a controller under its Privacy Policy, and that processing is outside the scope of this DPA.

2. Scope and purpose of processing

Landi processes Customer Personal Data only to provide the Services under the Agreement: generating, personalizing, publishing, and measuring the performance of the customer’s landing pages, and providing related support. Processing continues for the duration of the Agreement.

  • Data subjects — visitors to the customer’s published pages, the customer’s prospects and contacts, and the customer’s authorized users.
  • Categories of data — online identifiers, device and browser data, usage and engagement data, campaign attributes, and information submitted through forms on the customer’s pages.
  • Sensitive data — the Services are not designed for special categories of data, and the customer agrees not to submit them.

3. Customer instructions

Landi processes Customer Personal Data only on the customer’s documented instructions, which consist of the Agreement, this DPA, and the customer’s configuration of the Services, unless processing is required by law — in which case Landi will inform the customer before processing where legally permitted. Landi will inform the customer if, in its opinion, an instruction infringes applicable data protection law.

4. Confidentiality and personnel

Landi ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations, receive data protection training, and access the data only to the extent needed to provide the Services.

5. Subprocessors

The customer grants Landi general authorization to engage subprocessors — such as cloud hosting and infrastructure providers — to support the Services. Landi maintains a current list of subprocessors, available on request at [email protected].

Landi will give the customer advance notice of new or replacement subprocessors and a reasonable opportunity to object on legitimate data protection grounds; if the objection cannot be resolved, the customer may terminate the affected Services. Landi imposes data protection obligations on each subprocessor that are no less protective than those in this DPA and remains responsible for its subprocessors’ performance.

6. Security measures

Landi implements and maintains industry-standard technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including:

  • Encryption of data in transit;
  • Role-based access controls and the principle of least privilege;
  • Logging and monitoring of production systems;
  • Segregation of production and non-production environments;
  • Regular backups and tested recovery procedures;
  • Secure software development practices and vulnerability management.

Landi may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.

7. Personal data breach notification

Landi will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to Landi about the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address it, so the customer can meet its own notification obligations.

8. Data subject requests

Taking into account the nature of the processing, Landi will assist the customer with appropriate technical and organizational measures to respond to data subject requests — such as access, correction, deletion, and objection. If Landi receives a request directly from a data subject relating to Customer Personal Data, it will redirect the data subject to the customer where legally permitted.

9. International transfers

Where the provision of the Services involves transferring Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties rely on the Standard Contractual Clauses adopted by the European Commission (together with the UK Addendum and Swiss adaptations where applicable), which are incorporated into this DPA by reference, alongside any supplementary measures reasonably required.

10. Deletion and return of data

Upon termination or expiry of the Agreement, Landi will, at the customer’s choice, delete or return Customer Personal Data within a reasonable period, and delete remaining copies, unless applicable law requires continued storage — in which case the data remains protected under this DPA and is processed for no other purpose.

11. Audits and information

Landi will make available to the customer information reasonably necessary to demonstrate compliance with this DPA and, where required by applicable law, will allow for and contribute to audits conducted by the customer or an independent auditor mandated by the customer — at reasonable notice, no more than once per year unless required by a supervisory authority or following a personal data breach, and subject to reasonable confidentiality controls.

12. Contact

To execute this DPA, request the subprocessor list, or ask questions about it, contact [email protected], or write to Landi, [street address], [city, country].