Annexes

ANNEX 3 – Data Processing Agreement (DPA)

Version v1.5Last updated 17.08.2026Next review 01.10.2026Contractually binding

Owner: CTO · Approver: CEO

ANNEX 3 – Data Processing Agreement (DPA)

Data Controller (Customer): [Name, Business ID, Address]

Processor (Provider): Lyyli AI Oy; hello@lyyli.ai

Privacy contact: hello@lyyli.ai

1. Introduction and Applicable Terms

GDPR and national legislation; IT2022 YSE where applicable.

2. Subject and Duration of Processing

Duration of main agreement + maximum 30 days after termination for deletion/return purposes.

3. Nature and Purpose

Collection, storage, organization, restriction, retrieval, use, disclosure based on instructions, logging, verification/return, deletion/anonymization. Processing may include AI-assisted operations (e.g., drafting, analysis, communication support) within the Data Controller's instructions and the main agreement.

AI inference is routed via Vercel AI Gateway to model providers (Anthropic, Google Vertex AI, OpenAI). Language models process requests under Zero Data Retention. Processing region is model-specific and documented in the AI model register. Lyyli stores conversations to deliver the service.

4. Data Subjects and Data Categories

Organization users: name, email, role/position, usage and log data.

Content and communications: message metadata and content, comments, attachments, version history according to Data Controller's instructions.

Meeting participants (Meeting Agent): names, recordings, transcripts, and per-meeting insights when the Customer enables the feature.

External commenters: name and comment via public review links, without a user account.

Email senders (inbound mail): sender address, message metadata and content in inbox processing.

Integration users: Teams/Slack message metadata and content when using integrations.

No special categories of personal data without separate agreement. No customers' customers.

5. Data Controller's Obligations

Lawfulness, legal basis, information; user and rights management.

6. Processor's Obligations

Compliance with instructions, confidentiality, Annex 4 TOMs, assistance with requests and breaches, logs and documentation, enabling audits.

7. Subprocessors

Subprocessors are listed in Annex 5. The Processor ensures subprocessors have at least equivalent obligations. New subprocessors or material changes are notified to the Controller at least 30 days in advance; the Controller may object on reasonable grounds. AI inference is routed via Vercel AI Gateway to underlying model providers; model-level changes are documented in the AI model register. Controller-side vendors (e.g., payments, CRM) are described in the privacy notice.

8. International Transfers

Personal data may be transferred outside the EU/EEA where a subprocessor or technical implementation (e.g., AI or cloud services) requires it. Transfers are carried out using GDPR Chapter V safeguards, such as the European Commission's Standard Contractual Clauses (SCCs) and/or the EU–US Data Privacy Framework where applicable, together with supplementary technical and organizational measures as required by the relevant subprocessor and service description.

9. Data Breaches

Notification without delay; preliminary notification at the latest within 24 hours of the Processor becoming aware of the breach, supplemented when details are available.

10. Audits

Once per year, 14 business days advance notice, without unreasonable disruption.

11. Deletion or Return

Upon termination deletion/return from active systems; backups overwritten per Annex 6; logs deleted per separate schedule. Deletion certificate upon request.

12. Liability and Law

Main agreement & IT2022; Finnish law; Helsinki District Court.

Version history