Skip to main content
LemonSugar Ai

Data Processing Addendum

Last updated: June 10, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement (the “Agreement”) between LemonSugar Ai LLC (“Processor”) and the customer identified in the Agreement (“Controller”) and applies whenever Processor processes Personal Data on behalf of Controller in connection with the Service (including Relay API). It is offered as a clickwrap acceptance. For a counter-signed PDF, email hello@lemonsugar.ai.

1. Definitions

Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, and “Sub-processor” have the meanings in GDPR (Reg. 2016/679) and UK GDPR. “CCPA” means the California Consumer Privacy Act as amended by CPRA.

2. Scope & Roles

Processor processes Personal Data only on documented instructions from Controller as set out in the Agreement, this DPA, and Controller's use of the Service's features. For CCPA purposes, Processor acts as a “Service Provider” and shall not sell or share Personal Data, retain, use, or disclose it outside the direct business relationship, or combine it with data from other sources except as permitted by CCPA § 1798.140(ag)(1).

3. Subject Matter, Duration, Nature & Purpose
  • Subject matter: Ai inference, routing, and related platform features.
  • Duration: For the term of the Agreement plus any retention period required by law.
  • Nature & purpose: Transmission of prompts to Ai providers, generation of responses, storage of conversation history, billing, and support.
  • Categories of Data Subjects: Controller's end users, employees, and personnel.
  • Categories of Personal Data: Identifiers (email, account ID), prompt and output content (which may contain Data Subject content), usage metadata, IP address.
  • Special categories: May incidentally appear in user-submitted prompts; Controller is responsible for compliance with Art. 9 conditions.
4. Sub-processors

Controller grants Processor general authorization to engage the Sub-processors listed at /sub-processors. Processor will give Controller at least 30 days' notice before adding or replacing a Sub-processor. Controller may object in writing on reasonable data-protection grounds; if the parties cannot resolve the objection, Controller may terminate the affected portion of the Service for a pro-rata refund. Processor remains liable for Sub-processor performance.

5. International Transfers

For transfers of Personal Data from the EEA, UK, or Switzerland to a third country lacking an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (2021/914), Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor) as applicable, the UK IDTA, and the Swiss FDPIC addendum. Docking clause is accepted; the optional clauses are selected; supervisory authority is the lead EEA Member State authority of Controller; governing law is Ireland for the EU SCCs.

6. Security (Annex II)
  • Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
  • Row-Level Security (RLS) isolation per tenant in the application database.
  • Principle of least privilege for personnel access; SSO + MFA for production systems.
  • Audit logging of administrative actions and access to Personal Data.
  • Vulnerability scanning, dependency scanning, and timely patching.
  • Documented incident-response and business-continuity plans.
  • Background checks and confidentiality obligations on personnel.
  • Annual review of organizational and technical measures.
7. Personal Data Breach

Processor will notify Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Controller's Personal Data, including the information required by GDPR Art. 33(3).

8. Data Subject Rights & Assistance

Processor will provide reasonable assistance to Controller in responding to Data Subject requests, DPIAs (Art. 35), and prior consultations (Art. 36), taking into account the nature of processing and the information available.

9. Audits

Processor will make available all information necessary to demonstrate compliance with Art. 28. Controller may, at its expense and no more than once per year (unless a Personal Data Breach has occurred), audit Processor with 30 days' written notice during business hours, subject to confidentiality and minimal disruption. Third-party attestations (e.g. SOC 2) satisfy this obligation where applicable.

10. Return or Deletion

On termination, Processor will, at Controller's choice, return or delete all Personal Data within 30 days, except where Union or Member State law requires retention.

11. Order of Precedence

In case of conflict: (1) the EU SCCs / UK IDTA, (2) this DPA, (3) the Agreement. This DPA does not limit Processor's liability under data protection law.

12. Acceptance

Acceptance by an authorized representative of Controller (by email confirmation to hello@lemonsugar.ai or by continued use of paid features after publication) binds Controller to this DPA. A counter-signed PDF is available on request for procurement records.

  • Stripe — secure payments
  • 30-day money-back
  • No training on your data
  • 18 models, one bill