Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between LayrCake Ltd ("Processor") and the Customer ("Controller") governing the use of the LayrCake platform and services ("Services").
This DPA applies where LayrCake processes Personal Data on behalf of the Customer in accordance with UK GDPR and EU GDPR (together, "Data Protection Laws").
1. Definitions
Terms used but not defined in this DPA have the meanings set out in the Terms and Conditions.
"Personal Data" means personal data as defined under Data Protection Laws.
"Processing" means any operation performed on Personal Data.
"Sub-processor" means any third party engaged by LayrCake to process Personal Data.
2. Roles of the Parties
Customer
Data Controller
LayrCake
Data Processor
LayrCake processes Personal Data only on documented instructions from the Customer, unless required by law to act otherwise.
3. Scope of Processing
3.1 Subject Matter
Provision of the LayrCake Services, including platform access, support, and AI-assisted code generation within architectural constraints.
3.2 Duration
For the duration of the Customer's use of the Services, plus any legally required retention period.
3.3 Nature and Purpose
- Hosting and operation of the platform
- User authentication and access control
- Support and troubleshooting
- AI-assisted generation of Customer-defined business logic
3.4 Types of Personal Data
May include:
- Names
- Email addresses
- User identifiers
- Activity logs
- Configuration metadata
3.5 Categories of Data Subjects
- Customer employees
- Contractors
- Authorised users
4. Processor Obligations
LayrCake shall:
- Process Personal Data only on documented instructions from the Customer
- Ensure personnel are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Customer in responding to data subject requests
- Assist with security, breach notifications, and impact assessments
- Delete or return Personal Data upon termination, unless legally required otherwise
- Make available information reasonably necessary to demonstrate compliance
5. AI Processing and Customer Content
- AI features may process Customer Content, which may include Personal Data
- AI processing occurs only to deliver the Services
- Customer Content is not used to train public or third-party AI models
- LayrCake does not claim ownership of Customer Content
The Customer remains responsible for ensuring they have a lawful basis to process any Personal Data included in AI inputs.
6. Security Measures
LayrCake implements appropriate measures including, where applicable:
- Access controls
- Logical segregation of customer environments
- Encryption in transit and at rest where appropriate
- Monitoring and logging
Security measures are risk-based and proportionate.
7. Sub-processors
The Customer authorises LayrCake to engage Sub-processors for delivery of the Services.
LayrCake shall:
- Maintain a list of Sub-processors
- Ensure Sub-processors are bound by equivalent data protection obligations
LayrCake remains fully liable for the acts and omissions of Sub-processors.
8. International Transfers
Where Personal Data is transferred outside the UK or EEA, LayrCake ensures appropriate safeguards, including:
- UK adequacy decisions
- Standard Contractual Clauses (SCCs)
9. Data Subject Requests
LayrCake shall promptly notify the Customer if it receives a request from a data subject and shall not respond directly unless legally required.
10. Personal Data Breaches
LayrCake shall notify the Customer without undue delay upon becoming aware of a Personal Data breach affecting Customer data and provide reasonable assistance.
11. Audits
Upon reasonable notice, the Customer may audit LayrCake's compliance with this DPA, subject to:
- Confidentiality obligations
- Reasonable frequency
- Protection of other customers' data
12. Deletion or Return of Data
Upon termination of the Services:
- Personal Data will be deleted or returned at the Customer's request
- Unless retention is required by law
13. Liability
Liability under this DPA is subject to the limitations set out in the main Terms and Conditions.
Nothing in this DPA limits liability where prohibited by law.
14. Governing Law
This DPA is governed by the laws of England and Wales.
15. Order of Precedence
In the event of conflict:
- This DPA
- The Terms and Conditions
- Any Order Form or SLA
Appendix 1 – Security Measures (Summary)
- Logical tenant isolation
- Role-based access control
- Secure authentication
- Infrastructure monitoring
- Incident response procedures