Data Processing Addendum
This Data Processing Addendum (“DPA”) describes how Leucine, Inc. d/b/a Leucine and its affiliates (“Leucine,” “we,” “us” or “our”) process Customer Personal Data on behalf of our customers (“you” or “your”) in connection with Leucine’s software platform and related services (the “Services”). This DPA supplements the Leucine Privacy Policy and is incorporated by reference into any agreement under which you subscribe to or otherwise use the Services (the “Agreement”).
Effective Date: 01-Jan-2022
1. Definitions
Whenever used in this DPA, the following terms have the meanings set forth below (capitalized terms not defined here have the meaning given in the Agreement or Privacy Policy):
- Customer Personal Data means any personal data that you submit to Leucine or that Leucine collects, hosts, or processes on your behalf in the course of providing the Services, excluding your own account credentials and contact/billing information.
- Data Protection Laws means all data protection and privacy laws applicable to the Processing of Customer Personal Data, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”).
- “Process,” “Processing,” and “Processed” mean any operation or set of operations performed on Customer Personal Data, whether by automated or manual means.
2. Our Roles and Responsibilities
- Controller & Processor: You act as the Controller of Customer Personal Data; Leucine acts as your Processor. We Process Customer Personal Data strictly on your documented instructions, as set forth in the Agreement, this DPA, and the Leucine Privacy Policy.
- Order of Precedence: In the event of any conflict between this DPA and the Agreement, this DPA shall govern.
3. Categories of Data & Processing Activities
- Subject Matter: Delivery, support, enhancement, and security of the Services.
- Duration: For the term of the Agreement and thereafter as needed to comply with data-retention obligations.
- Categories of Data Subjects: Your employees, contractors, prospects, end users, and other individuals whose data you submit.
4. Types of Customer Personal Data.
- Identifiers & Contact Data: Name, email, phone, address.
- Professional Data: Employer, job title, department.
- Usage & Technical Data: IP address, log files, device/browser information.
- Call/Video Recordings: Audio/video content of any recorded calls, where consented.
4. Leucine’s Commitments
4.1 Processing
We will Process Customer Personal Data only in accordance with your instructions and for the purposes set out in Section 3. If we believe any instruction would violate applicable Data Protection Laws, we will notify you.
4.2 Confidentiality
We restrict access to Customer Personal Data to those Leucine personnel who need to know the data to perform the Services. All such persons are bound by confidentiality obligations.
4.3 Security
We maintain administrative, physical, and technical safeguards designed to protect Customer Personal Data, including (but not limited to):
- Encryption of data in transit (TLS) and, where supported, at rest;
- Regular vulnerability assessments and penetration testing;
- Access controls, logging, and multifactor authentication.
4.4 Data Subject Rights
If we receive a request from a Data Subject to exercise any right (e.g., access, correction, deletion, portability), we will promptly inform you and assist, to the extent legally permitted, with your obligations to respond.
5. Contact Information
If you have any questions or wish to object to Subprocessors, exercise data-subject rights, or discuss any matter under this DPA, please contact: contact@leucinetech.com
By continuing to use Leucine’s Services, you acknowledge that you have read, understood, and agree to the terms of this Data Processing Addendum.