Data Processing Addendum
Effective date: June 16, 2026
This Data Processing Addendum (the "DPA") forms part of the agreement between Leia, Inc. ("Leia", "Processor") and the customer entity that accepts it ("Customer", "Controller"), and governs Leia's processing of Personal Data on behalf of Customer in connection with the Service. It is designed to satisfy Article 28 of the EU GDPR, the UK GDPR, the Swiss FADP, and applicable U.S. state privacy laws (including CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and TDPSA).
Consumer users: If you use Leia as an individual consumer (not on behalf of an organization), this DPA does not apply to you — your relationship with us is governed by the Terms of Service and Privacy Policy.
1. Definitions
- "Applicable Data Protection Laws" means all data-protection and privacy laws applicable to the processing of Personal Data under the agreement, including the GDPR, UK GDPR, Swiss FADP, and U.S. state privacy laws.
- "Personal Data", "Controller", "Processor", "Processing", "Data Subject", and "Sub-processor" have the meanings given in the GDPR (or the equivalent terms — e.g. "Business", "Service Provider", "Personal Information" — under U.S. state privacy laws).
- "Customer Personal Data" means Personal Data that Leiaprocesses on behalf of Customer to provide the Service.
2. Roles and Scope
With respect to Customer Personal Data, Customer is the Controller (or Business) and Leia is the Processor (or Service Provider). Leia will process Customer Personal Data only on documented instructions from Customer, including as set out in the agreement, this DPA, and Customer's configuration of the Service, except where required to do so by law.
3. Subject Matter, Duration, Nature, and Purpose
- Subject matter: Provision of the Leia wellness application and related services to Customer and its authorized end users.
- Duration: The term of the agreement, plus any post-termination period during which Leia retains Customer Personal Data as permitted by this DPA.
- Nature and purpose: Hosting, storage, transmission, generation of AI-assisted content, customer support, security, and other processing necessary to provide the Service.
- Categories of Data Subjects: Customer's authorized end users.
- Categories of Personal Data: account identifiers, profile and self-reported wellness inputs, usage and device data, communications, and any other Personal Data Customer chooses to submit through the Service.
4. Confidentiality
Leia will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
5. Security Measures
Leia implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include, at a minimum: encryption in transit (TLS) and at rest where supported by our infrastructure; role-based access controls; least-privilege administration; environment isolation; vulnerability management; logging and monitoring; secure software-development practices; and personnel security training.
6. Sub-processors
Customer authorizes Leia to engage Sub-processors to process Customer Personal Data in connection with the Service, including:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud hosting & database | Application hosting, edge compute, managed Postgres, authentication, storage. | US / EU |
| AI model providers | Generation of routines, coach responses, and other AI-assisted content. | US |
| Text-to-speech provider | Voice narration of coach scripts. | US |
| Transactional email | Account, support, and service-related email delivery. | US / EU |
| Analytics & monitoring | Aggregate product analytics, error monitoring, and performance. | US / EU |
Leia will impose data-protection terms on each Sub-processor that are no less protective than those in this DPA. Leia will give Customer reasonable prior notice of any intended changes to its Sub-processors by updating this DPA; Customer may object on reasonable data-protection grounds by emailing legal@leia.fit.
7. Data Subject Requests
Taking into account the nature of the processing, Leia will provide reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If a Data Subject contacts Leia directly, Leia will refer them to Customer where appropriate.
8. Personal Data Breach Notification
Leia will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide Customer with information reasonably necessary to enable Customer to meet any obligations to notify supervisory authorities or Data Subjects.
9. Data Protection Impact Assessments
Leia will provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Applicable Data Protection Laws.
10. International Transfers
Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree that the EU Standard Contractual Clauses (Module Two: Controller to Processor; and, where applicable, Module Three: Processor to Processor), as approved by the European Commission, together with the UK International Data Transfer Addendum and the Swiss-specific addenda, are incorporated by reference into this DPA and apply to such transfers.
11. Deletion and Return of Personal Data
On termination or expiry of the agreement, Leia will, at Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless retention is required by law. Customer may also delete its end users' accounts and associated Personal Data at any time through the Service.
12. Audits
Leia will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including by providing written responses to reasonable security questionnaires, summaries of independent third-party assessments (where available), and other documentation. On Customer's reasonable written request, and no more than once per year (or as required by a supervisory authority),Leia will allow for and contribute to audits conducted by Customer or an independent auditor mandated by Customer, subject to mutually agreed scope, timing, confidentiality, and reasonable expense reimbursement.
13. U.S. State Privacy Law Terms
With respect to Personal Information processed under U.S. state privacy laws, Leia acts as a "Service Provider", "Processor", or "Contractor" (as applicable) and shall not: (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information outside of the direct business relationship with Customer or for any purpose other than the specific business purposes set out in the agreement and this DPA; or (c) combine Personal Information received from Customer with Personal Information from other sources, except as permitted by Applicable Data Protection Laws. Leia certifies that it understands and will comply with these restrictions.
14. Liability and Governing Law
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations of liability set out in the agreement. This DPA is governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles, except where Applicable Data Protection Laws require otherwise.
15. Order of Precedence
In the event of any conflict between this DPA and the agreement, this DPA controls with respect to the processing of Customer Personal Data. The Standard Contractual Clauses, where they apply, prevail over any conflicting terms of this DPA.
16. Contact
Data-protection requests and DPA inquiries: legal@leia.fit.
To execute a signed counterpart of this DPA on behalf of your organization, email legal@leia.fit with your legal entity name, signatory, and the Leia account email.