Terms & Policies

Standard Contractual Clauses

Last updated: August 17, 2026

These Standard Contractual Clauses describe the safeguards We rely on when Personal Data is transferred to Us from the European Economic Area, the United Kingdom or Switzerland. They form part of the Data Processing Agreement and, through it, part of the Contract. Words used but not defined here have the meaning given to them in the Data Processing Agreement.

When These Clauses Apply

If the Customer is established in the European Economic Area, or otherwise transfers Personal Data to Us from it, the EU Standard Contractual Clauses set out below apply to that transfer.

If the Customer is established in the United Kingdom, or otherwise transfers Personal Data to Us from it, the EU Standard Contractual Clauses apply as modified by the UK Addendum set out at the end of this page.

These clauses cover Personal Data the Customer sends Us to process on its behalf. They are not needed for information an individual gives Us directly, such as when an Authorized User creates their own account, because that is not a transfer between organizations.

The Clauses We Have Adopted

We adopt the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, the official text of which is published at eur-lex.europa.eu and is incorporated here in full and unaltered. Module Two applies, covering transfers from a controller to a processor: the Customer is the data exporter and We are the data importer.

Where those clauses offer a choice, We have made it as follows:

ClauseOur selection
Clause 7 — Docking clauseNot used
Clause 9 — Use of sub-processorsOption 2, general written authorization. We will give at least 30 days' notice of a new Subprocessor by updating the Subprocessors page
Clause 11 — RedressThe optional paragraph providing for an independent dispute resolution body is not used
Clause 17 — Governing lawOption 1. These clauses are governed by the law of Ireland
Clause 18(b) — Choice of forumThe courts of Ireland

By entering into the Contract, the Customer and We are each deemed to have signed these clauses, including their annexes, as of the date the Contract takes effect.

Annex I

A. List of Parties

Data exporter. The Customer, as identified in the Contract. The Customer's role is controller. Its activities relevant to the transfer are its use of the Services under the Contract, and its contact details and signature are those recorded in the Contract.

Data importer. Lean Sensory Systems, Inc., doing business as DraughtLab, of PO Box 585, Webster, NY 14580-0585, United States. Contact: info@leansensory.com. Our role is processor. Our activities relevant to the transfer are providing, maintaining, securing and supporting the Services.

B. Description of the Transfer

Categories of data subjectsThe Customer's Authorized Users
Categories of personal dataSensory evaluation results, ratings and comments, images attached to them, and training and assessment results, each associated with the Authorized User who submitted it
Sensitive dataNone. The Services provide no fields for special categories of personal data and We do not require it
Frequency of the transferContinuous, for as long as the Customer uses the Services
Nature of the processingHosting, storage, organization, retrieval, analysis and presentation of the personal data in order to deliver the Services
Purpose of the processingProviding, maintaining, securing and supporting the Services under the Contract
Retention periodFor the duration of the Contract, and afterwards as described in the Customer Terms of Service
Transfers to sub-processorsAs set out in Annex III, for the same duration and purposes as above

C. Competent Supervisory Authority

The supervisory authority of the Member State in which the Customer is established. Where the Customer is not established in the European Economic Area but has appointed a representative under Article 27 of the GDPR, the supervisory authority of the Member State in which that representative is established.

Annex II — Technical and Organisational Measures

We maintain the measures described in the "Security" section of the Data Processing Agreement, which are incorporated here. In summary:

  • Encryption of personal data at rest, and encryption in transit using HTTPS/TLS;
  • Storage of passwords only as salted, non-reversible hashes, and automatic account lockout after repeated failed sign-in attempts;
  • Separation of each Organization's data, with no access between Organizations, and permissions assigned by an administrator the Customer designates;
  • Operation of Our systems on private networks, with administrative access restricted and individually authenticated;
  • Logging and monitoring of infrastructure activity, with automated alerting for suspicious events;
  • Nightly backups, retained and copied to a second location;
  • A documented incident response plan, under which We notify the Customer of a confirmed security incident within 72 hours; and
  • Independent assessment of Our security program, most recently a SOC 2 Type 1 report for the Security trust services category.

For transfers to sub-processors, We impose data protection obligations no less protective than these, as described in the Data Processing Agreement.

Annex III — List of Sub-processors

The Customer gives general authorization for the Subprocessors listed at Subprocessors, which identifies each Subprocessor, its location and its role, and which We update before a new Subprocessor begins processing personal data. The description of the processing carried out by each is set out on that page.

UK Addendum

For transfers from the United Kingdom, the EU Standard Contractual Clauses above apply as modified by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0 in force 21 March 2022, the official text of which is published by the Information Commissioner's Office and is incorporated here in full and unaltered.

Table 1 — Parties. The start date is the date the Contract takes effect. The exporter is the Customer, as identified in the Contract. The importer is Lean Sensory Systems, Inc., doing business as DraughtLab, of PO Box 585, Webster, NY 14580-0585, United States. Contact for each party is as recorded in the Contract and, for Us, info@leansensory.com.

Table 2 — Selected SCCs, Modules and Selected Clauses. The Addendum is appended to the EU Standard Contractual Clauses set out above, including the Appendix Information and with Module Two in operation and the selections recorded in the table above.

Table 3 — Appendix Information. Annex 1A, Annex 1B, Annex II and Annex III are as set out above.

Table 4 — Ending this Addendum when the Approved Addendum changes. Neither party may end this Addendum as set out in Section 19 of the Addendum.

Switzerland

For transfers from Switzerland, the EU Standard Contractual Clauses above apply, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, references to Member State law read as references to Swiss law, and the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.

Questions

If you have questions about these clauses, please contact Our Privacy Contact at info@leansensory.com.