Terms & Policies

Data Processing Agreement

Last updated: August 17, 2026

This Data Processing Agreement (the "DPA") describes how We handle Personal Data on your behalf when you use Our Services, and forms part of the Contract. It applies wherever Data Protection Law requires an agreement of this kind. "We", "Our" and "Us" refers to Lean Sensory Systems, Inc., doing business as DraughtLab. Words used but not defined in this DPA have the meaning given to them in the Customer Terms of Service.

How This DPA Works

It Forms Part of the Contract

This DPA is incorporated into the Contract. Where something in this DPA conflicts with the rest of the Contract, this DPA governs — but only in respect of the processing of Personal Data.

Definitions

"Personal Data" means information within Customer Content that relates to an identified or identifiable individual. "Data Protection Law" means any law governing the processing of Personal Data that applies to that processing. "Subprocessor" means a third party We engage to process Personal Data in delivering the Services.

Our Roles

For Personal Data within Customer Content, the Customer is the controller and We are the processor. You decide what Personal Data goes into the Services and why; We process it to deliver the Services and to follow your instructions.

We act as a controller, not as a processor, for the Other Information described in the Customer Privacy Policy — such as account and contact details, and the sign-in information We use to keep accounts secure. That information is handled under that policy rather than this DPA.

What We Process

Subject Matter, Nature, Purpose and Duration

We process Personal Data in order to provide, maintain, secure and support the Services under the Contract. We do so for as long as the Contract is in effect, and afterwards only as described in "Returning or Deleting Personal Data" below.

Personal Data and Individuals Concerned

The Personal Data We process on your behalf is the sensory evaluation results, ratings, comments, attached images, and training and assessment results that your Authorized Users submit to the Services, each associated with the Authorized User who submitted it. The individuals concerned are your Authorized Users.

We do not require special categories of Personal Data, and the Services provide no fields for it. Please do not submit it.

Our Commitments

Your Instructions

We will only process Personal Data to provide the Services and to follow your documented instructions. Your Contract with Us, and your and your Authorized Users' use of the Services, are those instructions. If We are ever required by law to process Personal Data in some other way, We will tell you first, unless that law forbids Us from telling you.

Confidentiality

We will make sure that everyone We allow to process Personal Data is bound by an appropriate duty of confidentiality, whether by contract or by law, and that they access Personal Data only where they need it to do their work.

Security

We will maintain appropriate technical and organizational measures to protect Personal Data, taking account of the state of the art, the cost of implementation, the nature and purposes of the processing, and the risk to the individuals concerned. Those measures currently include:

  • Encryption of Personal Data at rest, and encryption in transit using HTTPS/TLS;
  • Storage of passwords only as salted, non-reversible hashes, and automatic account lockout after repeated failed sign-in attempts;
  • Separation of each Organization's data, with no access between Organizations, and permissions assigned by an administrator you designate;
  • Operation of Our systems on private networks, with administrative access restricted and individually authenticated;
  • Logging and monitoring of infrastructure activity, with automated alerting for suspicious events;
  • Nightly backups, retained and copied to a second location; and
  • A documented incident response plan, tested and maintained.

We may change these measures as technology and risks change, but We will not reduce the overall level of protection during a subscription term.

Subprocessors

You give Us general authorization to engage Subprocessors to help deliver the Services. We keep a current list, including the location and role of each, at Subprocessors, and We will update that page at least 30 days before a new Subprocessor begins processing Personal Data.

If you object to a new Subprocessor on reasonable data protection grounds, tell Us and We will work with you in good faith to find an alternative. If We cannot, you may stop using the affected part of the Services and, if that leaves the Services materially unusable for you, terminate the affected subscription and receive a refund of any prepaid fees for the remainder of its term.

We will place data protection obligations on every Subprocessor that are no less protective than those in this DPA, and We remain responsible to you for their performance.

Helping You Respond to Individuals

Taking into account the nature of the processing, We will help you respond to requests from individuals exercising their rights under Data Protection Law, so far as We reasonably can. The Services allow you to access, correct, export and delete Customer Content yourself, which is usually the fastest route. If one of your Authorized Users makes such a request to Us directly, We will direct them to you rather than act on it ourselves, unless Data Protection Law requires otherwise.

Helping You With Security Incidents and Assessments

We will notify you of a confirmed security incident affecting Personal Data as described in the Customer Terms, and will give you the information you reasonably need to meet your own obligations. Taking into account the nature of the processing and the information available to Us, We will also assist you with data protection impact assessments and with any prior consultation with a supervisory authority.

Returning or Deleting Personal Data

During a subscription term you may export Customer Content from the Services. When the Contract ends, We will delete Personal Data as described in the Customer Terms, or return it to you if you ask Us before it is deleted. We may retain Personal Data where Data Protection Law requires Us to, and We will keep it protected for as long as We hold it.

Demonstrating Compliance

We will make available to you the information you reasonably need to show that We are meeting Our obligations under this DPA, including Our most recent SOC 2 report under a non-disclosure agreement.

If that information is not sufficient for your purposes, you may request an audit no more than once in any twelve-month period, on reasonable written notice, at a time We agree, during business hours, and subject to confidentiality. We may satisfy such a request by arranging an audit by an independent auditor instead.

If an Instruction Looks Unlawful

If We believe an instruction from you would breach Data Protection Law, We will tell you promptly.

Where We Process Personal Data

We process Personal Data in the United States. Where Data Protection Law requires a specific mechanism for the transfer of Personal Data you send Us, the Standard Contractual Clauses apply and form part of this DPA.

Your Responsibilities

You are responsible for making sure that you have a lawful basis for the Personal Data you put into the Services; that your Authorized Users receive any privacy notice they are entitled to; that your instructions to Us comply with Data Protection Law; and for responding to requests from individuals about their Personal Data.

Questions

If you have questions about this DPA, please contact Our Privacy Contact at info@leansensory.com.