Landi Inc. — Data Processing Agreement (DPA)
This DPA applies where Landi Inc. processes personal data of End Users on behalf of a Customer. The Customer is the controller; Landi Inc. is the processor. It forms part of, and is governed by, the Terms of Service. In the event of a conflict between this DPA and the Terms with respect to the processing of personal data, this DPA prevails.
Effective date: August 18, 2026 · Version: 2026-08-18-v1.1
1. Definitions
Terms such as "personal data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings in the GDPR. "Data Protection Laws" means all applicable privacy and data-protection laws, including the GDPR/UK GDPR, the Israeli Protection of Privacy Law, 5741-1981 (as amended, including Amendment 13) and its regulations, the CCPA/CPRA and other US state privacy laws, as applicable. "End User Data" means personal data of the Customer's End Users processed by Landi Inc. through the Service.
2. Roles and Scope
2.1 The Customer is the controller (or a processor acting for a third-party controller) of End User Data. Landi Inc. is the processor. Under US laws, Landi Inc. acts as a "service provider" / "processor" and not a "third party," and will not "sell" or "share" End User Data.
2.2 Landi Inc. processes End User Data only to provide the Service and only on the Customer's documented instructions (including as set out in the Terms, this DPA, and the Customer's configuration of the Service), unless required by law (in which case Landi Inc. will notify the Customer where legally permitted).
2.3 The Customer is responsible for the lawfulness of its instructions and for having a valid legal basis and all required notices and consents for collecting and processing End User Data.
2.4 Customer marketing obligations. Where the Customer deploys advertising, analytics, or remarketing tags on its pages, or drives paid traffic to them, the Customer is responsible for: (a) obtaining all legally required consents, including EEA/UK cookie and ad-personalization consent; (b) providing the disclosures required by the relevant ad platform; (c) ensuring End User Data is not exposed in URLs or query strings (forms must transmit via secure POST over HTTPS); and (d) not collecting special-category data without a valid legal basis and appropriate safeguards. Tags the Customer deploys are the Customer's responsibility and are outside the scope of Landi Inc.'s processing under this DPA.
2.5 Aggregated and Anonymized Data. The Customer instructs Landi Inc. to process End User Data to create anonymized, aggregated statistical data ("Aggregated Data"), including counts of impressions and interactions associated with Landi Inc.'s persona archetypes, segmented by industry or similar categories. Aggregated Data is irreversibly anonymized such that it does not identify, and cannot reasonably be used to identify, the Customer, any End User, or any Customer Content, and is not personal data. Landi Inc. acts as controller with respect to Aggregated Data and may use, retain, and disclose it to operate and improve the Service. Landi Inc. will not disclose Aggregated Data in any form that identifies the Customer or reveals Customer Content.
3. Processor Obligations
Landi Inc. will:
3.1 process End User Data only per Section 2 and Annex 1;
3.2 ensure personnel authorized to process End User Data are bound by confidentiality;
3.3 implement and maintain the technical and organizational measures in Annex 2 (TOMs), appropriate to the risk;
3.4 assist the Customer, taking into account the nature of processing, in: (a) responding to data-subject requests; (b) ensuring security; (c) breach notification; and (d) data protection impact assessments and prior consultations, to the extent the Customer cannot reasonably do so itself;
3.5 notify the Customer without undue delay after becoming aware of a personal-data breach affecting End User Data, with information reasonably available to assist the Customer's own notification obligations;
3.6 at the Customer's choice, delete or return End User Data at the end of the Service, and delete existing copies unless retention is required by law;
3.7 make available information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-Processors
4.1 The Customer provides general authorization for Landi Inc. to engage sub-processors to provide the Service. Current sub-processors are listed in Annex 3.
4.2 Landi Inc. will impose data-protection obligations on sub-processors that are no less protective than this DPA, and remains responsible for their performance.
4.3 Landi Inc. will give the Customer notice (e.g., via [URL / email list]) of intended changes to sub-processors, and the Customer may object on reasonable data-protection grounds within [14] days. If the parties cannot resolve the objection, the Customer may terminate the affected Service.
5. International Transfers
5.1 Where End User Data is transferred from the EEA/UK to a country without an adequacy decision, the parties will rely on the applicable Standard Contractual Clauses (and the UK Addendum where relevant), which are incorporated by reference and completed by the details in the Annexes. Transfers to the United States (including to Landi Inc.) may additionally rely on the EU–US Data Privacy Framework and its UK extension where Landi Inc. is certified. Transfers to Israel may rely on Israel's EU adequacy status.
5.2 The Customer authorizes transfers necessary to provide the Service, including to sub-processors in [the United States and other locations listed in Annex 3].
6. Data Subject Requests
If Landi Inc. receives a request from a data subject regarding End User Data, it will, where legally permitted, direct the request to the Customer and assist the Customer in responding, rather than responding directly.
7. Audits
Landi Inc. will, on reasonable prior written request and no more than [once per year] (unless required by a supervisory authority or after a breach), make available information and, where necessary, allow for and contribute to audits of its compliance, subject to confidentiality and reasonable security constraints. [Consider allowing satisfaction via third-party audit reports / certifications.]
8. Liability
Liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws prohibit such limitation.
9. Term
This DPA remains in effect for as long as Landi Inc. processes End User Data on the Customer's behalf.
Annex 1 — Details of Processing
- Subject matter: provision of the Landi Inc. landing-page platform, including hosting and processing of data collected through Customer-published pages.
- Duration: for the term of the Service plus any legally required retention.
- Nature and purpose: hosting, storage, transmission, and processing of End User Data as configured by the Customer (e.g., lead capture, form submissions, analytics).
- Categories of data subjects: the Customer's website visitors, leads, and prospects (End Users).
- Categories of personal data: contact details (name, email, phone), form-submission content, IP address, device/usage/analytics data, and
[any other fields the Customer configures]. - Special-category data: none intended; the Customer must not configure collection of special-category data without appropriate legal basis and safeguards.
Annex 2 — Technical and Organizational Measures (TOMs)
[Confirm and tailor to your actual controls before finalizing.]
- Encryption of data in transit (TLS) and at rest where supported by the infrastructure.
- Access controls: role-based access, least privilege, MFA for administrative access.
- Network and application security controls; secrets management.
- Logging and monitoring of access to production systems.
- Backups and tested restoration procedures.
- Secure development practices and dependency/vulnerability management.
- Personnel confidentiality obligations and security awareness.
- Incident-response process with breach-notification workflow.
- Data segregation between Customers (e.g., row-level security).
- Personal data collected through published pages is transmitted over HTTPS and via
POSTrequests; personal data is not placed in URL query strings.
Annex 3 — Approved Sub-Processors
| Sub-processor | Service | Location(s) |
|---|---|---|
| Google LLC (Gemini) | AI model provider — generation of landing-page content | United States / global |