Skip to content

Legal

Data Processing Agreement

Effective 13 July 2026. This page explains what our Data Processing Agreement (DPA) covers and how to request it. It is not the DPA itself; the signed agreement is the binding document.

A Data Processing Agreement (DPA) is a contract that governs how one company handles personal data on behalf of another. It sets out the roles: the controller decides why and how personal data is processed, and the processor handles that data only on the controller's documented instructions. Under Article 28 of the GDPR, a DPA is required whenever a processor handles personal data for a controller.

Who needs a DPA with us

When Lumienzo launches, business customers (brands, agencies, and talent managers) will process personal data through the Service, for example, the details of creators they work with or their own team members. In that relationship the business customer is the controller and Lumienzo is the processor acting on their instructions. Those customers will need a DPA in place with us.

Our pre-launch status

Lumienzo is not yet live. Because there are no business customers using the Service today, no controller has handed us personal data to process on their behalf, so no DPA is operative right now. The only personal data we currently handle is the email addresses of people who join our waitlist, and for that we act as the controller. You can read more in our Privacy Policy.

Even though it is not yet operative, we make our DPA available now on request. This lets prospective customers review the terms with their legal and privacy teams well ahead of launch, so a signed agreement can be ready before any processing begins.

What our DPA covers

  • GDPR Article 28 processor terms: we process personal data only on your documented instructions, keep our staff under confidentiality obligations, assist you with data-subject requests and breach notifications, and delete or return data at the end of the engagement.
  • International transfers: the EU Standard Contractual Clauses (Commission Decision 2021/914) cover transfers of personal data outside the EEA.
  • UK transfers: the UK International Data Transfer Addendum to the EU SCCs covers transfers of UK personal data.
  • Security measures appendix: the technical and organizational measures we will operate for the Service, including encryption in transit and at rest, access controls, and incident response.
  • Sub-processor list: the third parties we rely on to deliver the Service, with a commitment to flow equivalent obligations down to them.

Sub-processors

These are the third-party service providers we use. We only list the ones we actually rely on. Today, while we are pre-launch, these providers support our marketing site and waitlist and Lumienzo acts as the controller. The providers marked as planned will support the Service once it launches.

Today (pre-launch)

  • Buttondown: stores waitlist email addresses and sends updates.
  • Netlify: hosts our static marketing website and its content delivery network.
  • Unsplash: serves some decorative images from its image CDN.

At launch (planned)

  • Google Cloud: application hosting, database, and file storage.
  • Stripe: payment processing and escrow.

Google Cloud and Stripe each process personal data under their own data processing addenda, which our DPA incorporates by reference. We will give at least 30 days' notice of any material change to this sub-processor list, so you have time to review and, where you have the right, object.

How to request the DPA

Email [email protected] with the subject line "DPA request" and include:

  • Your company name.
  • Your registered address.
  • A signatory contact (name, role, and email).

We will return a counter-signed DPA to you promptly.

Contact

Lumienzo, Inc., 2093 Philadelphia Pike #7740, Claymont, DE 19703, USA. For DPA, privacy, or security questions, email [email protected].

We will update this page and the DPA as the product develops, and where the law requires it we will seek fresh terms before new processing begins.