Data Processing Agreement
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR (Regulation (EU) 2016/679). "Sub-processor" means any processor engaged by us to process Personal Data on Customer's behalf. "Service Agreement" means the agreement (including our Terms of Service) under which Customer uses LaikaHub.
2. Subject matter, duration, and nature of processing
This Data Processing Agreement ("DPA") applies whenever Babete, Lda. ("we", "us", the "Processor") processes Personal Data on behalf of a Customer ("Controller") in connection with LaikaHub. It takes effect when Customer starts using LaikaHub and remains in effect for as long as the Service Agreement is in force.
Processing consists of storing and organizing Customer's contact and business records, authenticating Customer's users, generating AI-assisted drafts from data Customer submits, and delivering optional push notifications.
Data subjects are the individuals whose data Customer submits to LaikaHub — typically Customer's own contacts, leads, customers, and authorized users.
Categories of Personal Data processed may include names, email addresses, phone numbers, communication and interaction history, and any other business data Customer chooses to upload or create in LaikaHub.
3. Processor obligations
We agree to:
- Process Personal Data only on Customer's documented instructions, including as set out in the Service Agreement, unless required to do otherwise by EU or Member State law.
- Ensure persons authorized to process Personal Data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures under Article 32 GDPR (Section 6).
- Engage Sub-processors only as permitted under Section 5, and remain liable for their performance.
- Assist Customer, taking into account the nature of the processing, in responding to Data Subject rights requests (Section 8).
- Assist Customer with its obligations under Articles 32–36 GDPR (security, breach notification, and data protection impact assessments), taking into account the information available to us.
- At Customer's choice, delete or return all Personal Data at the end of the provision of services, and delete existing copies unless EU or Member State law requires storage.
- Make available to Customer information reasonably necessary to demonstrate compliance with this DPA.
4. Controller obligations
Customer warrants that it has a lawful basis for the Personal Data it submits to LaikaHub, that it has provided any required notices to Data Subjects, and that its instructions to us comply with applicable data protection law. Customer will promptly notify us of any Security Incident or Data Subject request it becomes aware of that relates to Personal Data we process on its behalf.
5. Sub-processors
Customer provides general authorization for us to engage the Sub-processors listed below. We will give Customer at least 10 business days' notice before adding a new Sub-processor or replacing an existing one, and Customer may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, Customer may terminate the affected part of the service.
The current Sub-processors, all engaged to support LaikaHub's hosting, database, analytics, and AI-drafting features, are listed in the table below. We impose data protection obligations on each Sub-processor that are substantially equivalent to those in this DPA.
| Sub-processor | Activity | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database hosting and user authentication | EU (Frankfurt primary, Dublin replica) | N/A — data stays in the EU |
| Cloudflare, Inc. | Edge hosting/compute for the application, plus feature-flag delivery (Cloudflare Flagship) | Global edge network, including EU points of presence | Standard Contractual Clauses (SCCs) |
| Google LLC | Website analytics via Google Tag Manager | United States | SCCs and/or EU-U.S. Data Privacy Framework certification |
| Lovable | AI request gateway that routes AI feature calls to an underlying model provider | United States | SCCs |
| OpenAI, L.L.C. | Underlying AI model provider for AI-drafted content (accessed via the Lovable gateway, not directly) | United States | SCCs |
6. Technical and organizational security measures
We maintain a security program that includes: encryption in transit (TLS) for all traffic to LaikaHub; secure, workspace-scoped access controls so one Customer's data is never visible to another; rate limiting on sensitive and AI-assisted actions; and audit logging of key account and data-access events.
7. Security incident notification
We will notify Customer without undue delay, and in any event within 72 hours of becoming aware, of a confirmed Personal Data Breach affecting Customer's data, including — to the extent known — the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address it. We will cooperate with Customer's reasonable requests for information needed to fulfil Customer's own breach-notification obligations.
8. Assistance with Data Subject rights
Where a Data Subject contacts us directly with a request concerning their Personal Data, we will forward it to Customer without undue delay and will not respond substantively without Customer's written instruction, except as required by law. We will provide reasonable assistance to Customer in fulfilling Data Subject requests, including access, rectification, erasure, restriction, and portability requests.
9. International transfers
Where Personal Data is transferred to a Sub-processor located outside the EU/EEA — currently Google, Lovable, and OpenAI, all U.S.-based — the transfer is governed by Standard Contractual Clauses approved under European Commission Decision 2021/914 (Module 2 or 3, as applicable) and, where available, the relevant provider's EU-U.S. Data Privacy Framework certification. Copies are available to Customer on request.
10. Audits and inspections
On reasonable prior written notice (at least 30 days, except following a confirmed Security Incident), and no more than once per year absent cause, Customer or its appointed auditor — subject to confidentiality obligations — may audit our compliance with this DPA during normal business hours, at Customer's expense.
11. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations of liability set out in the Service Agreement, except that nothing in this DPA limits liability for a party's breach of its obligations as Controller or Processor under Article 28 GDPR, or for gross negligence or wilful misconduct.
12. Term and termination
This DPA takes effect and terminates together with the Service Agreement. Sections 7 (Security Incidents), 8 (Data Subject Rights), and 10 (Audits) survive termination for 12 months. On termination, we will delete or return Customer's Personal Data within 30 days, unless EU or Member State law requires longer retention.
13. Governing law
This DPA is governed by Portuguese law and subject to the exclusive jurisdiction of the courts of Lisbon, Portugal, without prejudice to any mandatory provision of EU data protection law.
14. Contact
For any question about this DPA, contact us at privacy@babete.pt or dpo@babete.pt.