LYSETATranslate← Back to home
Legal

Data Processing Agreement

Last updated: 5 June 2026

1. Parties and scope

This Data Processing Agreement (“DPA”) is entered into between Lyseta Ltd, a company registered in England and Wales (company number 17167358, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ) (“Lyseta”, “we”, “us”, “Processor”), and the customer organisation that accepts this DPA at signup (“Customer”, “you”, “Controller”).

It forms part of the Terms of Serviceand governs our processing of personal data on your behalf in connection with your use of Lyseta Translate (the “Service”). It is supplementary to, and does not replace, the Privacy Policy, which governs personal data we process as controller in our own right (for example, account and billing data of users who sign in to the Service).

Where this DPA conflicts with the Terms of Service in relation to the processing of personal data on your behalf, this DPA prevails.

2. Definitions

Capitalised terms not defined here have the meanings given to them in the UK GDPR and, where relevant, the EU GDPR.

  • Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018, and (where it applies to your use of the Service) the EU GDPR and any implementing legislation.
  • Customer Personal Data means personal data contained in Customer Content that we process on your behalf as processor in the course of providing the Service.
  • Customer Contenthas the meaning given to “Your Content” in the Terms of Service: source strings, translations, screenshots, glossary entries, notes, translator question-and-answer threads, and similar content you or your members upload into the Service.
  • Sub-processor means any third party engaged by us to process Customer Personal Data on our behalf to provide the Service.
  • Personal Data Breach, Controller, Processor, Data Subject, and related terms have the meanings given to them in the UK GDPR.

3. Roles of the parties

In relation to Customer Personal Data, you are the Controller and we are the Processor. You determine the purposes and means of processing; we process Customer Personal Data only to provide the Service to you in accordance with this DPA.

In relation to data we collect and process for our own purposes (for example, your members' account credentials, billing data, our own service-operation telemetry), we act as Controller in our own right, as described in the Privacy Policy. This DPA does not govern that processing.

Each party is responsible for its own compliance with Applicable Data Protection Law in respect of the processing it controls.

4. Subject matter, duration, nature, and purpose

Subject matter: the processing of Customer Personal Data necessary for us to provide the Service.

Duration: the term of your subscription to the Service, plus any post-termination retention period described in the Privacy Policy (in summary: we do not automatically delete Customer Content on cancellation so that you can resubscribe and resume work; on written request we will delete within 30 days, subject to legal retention obligations).

Nature and purpose: storing, transmitting, displaying, and otherwise processing Customer Personal Data so you and your authorised organisation members can manage software localisation — including version-scoped storage of source strings and translations, per-language and per-role access control, screenshot storage and proxied delivery, glossary and notes management, translator question-and-answer threads, transactional email delivery to members, durable execution of background translation and glossary jobs, and (where you have enabled AI features) transmission of relevant Customer Content to our AI sub-processor to produce draft translations and glossary suggestions for human review.

5. Categories of data subjects and types of personal data

Categories of Data Subjects typically include:

  • Your members (admins, project owners, editors, translators) who sign in to the Service.
  • Your prospective members who have been invited but have not yet accepted.
  • Any individuals whose personal data you choose to upload into the Service, including individuals whose details appear in source strings, translations, glossary entries, notes, or screenshots of your software (for example, customers of yours whose names or email addresses are visible in a logged-in screenshot).

Types of Personal Data typically include:

  • Identifiers and contact data: names, email addresses, organisation membership, role, language assignments.
  • Content data: any personal data you choose to include in Customer Content (which may, depending on what you upload, include free-form text, names, identifiers, or images of natural persons).
  • Authentication metadata: claims released by your single-sign-on provider where SSO is configured.

You determine what Customer Content is uploaded and are responsible for ensuring you have a lawful basis to do so. The Service is not intended for processing of special-category personal data (UK GDPR Art 9) or criminal-offence data (UK GDPR Art 10); you must not upload such data into the Service without first agreeing with us in writing the additional safeguards required.

6. Customer instructions

We will process Customer Personal Data only on your documented instructions, including with regard to transfers of Customer Personal Data to a third country, unless required to do so by law to which we are subject. If we are required by law to process Customer Personal Data outside your instructions, we will inform you of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.

Your documented instructions consist of: (a) the Terms of Service; (b) this DPA; (c) the Service's in-product configuration (including organisation-level toggles for AI features, language assignments, member roles, and screenshot privacy settings); and (d) any further written instructions you give us, provided those instructions are consistent with the Service's documented functionality.

We will notify you without undue delay if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law. We are not obliged to follow an instruction that would require us to act unlawfully.

7. Confidentiality

We will ensure that personnel authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality (whether by contract of employment, by statute, or by separate confidentiality undertaking), and that access is restricted on a need-to-know basis.

8. Security measures

We will implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against a Personal Data Breach, having regard to the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as required by Article 32 UK GDPR.

The measures in place as at the date of this DPA include:

  • Transport encryption (TLS / HTTPS) for all traffic to the Service.
  • Encryption at rest of stored data by our database provider.
  • Application-layer encryption (AES-256-GCM) of high-sensitivity stored secrets (including OIDC client secrets), with the encryption key held outside the database.
  • Private-by-default storage of screenshots, served only through a server-authorised proxy that enforces project access rules on every request.
  • Server-enforced per-language and per-role access controls applied at the database query layer, so a translator's scope cannot be bypassed by crafted API calls.
  • Audit logging of administrative actions, including admin self-grants of project-owner role.
  • Restricted administrative access to production systems, with authentication tied to individual personnel.
  • Regular dependency updates and security review of our codebase.
  • A documented breach-response process aligned with our notification obligations under Article 33 UK GDPR.

We may update these measures from time to time, provided that the overall level of protection is not materially reduced.

9. Sub-processors

You give us general written authorisation to engage sub-processors to process Customer Personal Data, subject to the conditions in this clause. The sub-processors engaged as at the date of this DPA are those listed in the Privacy Policyunder “Third-party processors”.

Before engaging a new sub-processor, or replacing an existing sub-processor with one that processes Customer Personal Data on materially different terms, we will give you at least 30 days' prior notice by email to the admin email address on your organisation and by updating the list in the Privacy Policy. You may object on reasonable data-protection grounds within that notice period by emailing hello@lyseta.ai with a brief statement of the grounds. If we cannot reasonably accommodate your objection, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees for the unused period.

We will impose on each sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures so that the processing meets the requirements of UK GDPR. We remain liable to you for the acts and omissions of our sub-processors in respect of Customer Personal Data.

10. International transfers

Customer Personal Data is stored in the European Union by default (MongoDB Atlas, Ireland; Resend, EU region). Certain sub-processors described in the Privacy Policy are based outside the United Kingdom and the EEA, principally in the United States (including Stripe, Anthropic, Inngest, and parts of Vercel and Google).

Where we transfer Customer Personal Data outside the United Kingdom or the EEA, we will rely on one or more of the following safeguards under UK GDPR Chapter V (and, where the EU GDPR also applies, the equivalent provisions of EU GDPR Chapter V):

  • The UK Extension to the EU–US Data Privacy Framework (the “UK–US Data Bridge”), where the receiving organisation is certified to it.
  • The UK International Data Transfer Addendum to the EU Standard Contractual Clauses (the “UK IDTA”), or the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), as a fallback.
  • Any other transfer mechanism recognised under Applicable Data Protection Law from time to time.

Where the UK IDTA or EU Standard Contractual Clauses are required between you and us in respect of any transfer (for example if your establishment is outside the United Kingdom and the EEA), they are incorporated by reference into this DPA. The Module 2 (controller-to-processor) clauses apply, with the following elections: docking clause applies; option 1 (general written authorisation) for sub-processor changes; option 1 (independent dispute resolution body) for redress; governing law and forum as set out in Section 14 below.

11. Data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of your obligation to respond to requests by Data Subjects exercising their rights under Chapter III UK GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).

The Service provides limited self-service tools that can be used to action some requests directly — including editing or removing Customer Content through the project workspace, managing members and their roles, and (where you are the last remaining member of an organisation) deleting the organisation and its content. For all other requests — including data export, deletion of specific Customer Personal Data while the organisation remains active, and requests relating to former members — please contact us at hello@lyseta.ai and we will provide reasonable assistance.

If we receive a request from a Data Subject relating to Customer Personal Data, we will (a) not respond directly without your prior authorisation, except to acknowledge receipt and refer the Data Subject to you; and (b) promptly forward the request to the admin email address on your organisation.

12. Assistance with controller obligations

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you in ensuring compliance with your obligations under Articles 32 to 36 UK GDPR, including:

  • providing the information about the Service and our processing activities that you need to carry out a data protection impact assessment under Article 35;
  • providing the information you reasonably require to consult with the Information Commissioner's Office under Article 36;
  • assisting you to comply with your security obligations under Article 32, through the security measures described in Section 8 of this DPA.

13. Personal Data Breach notification

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will (to the extent the relevant information is available) describe:

  • the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and personal data records concerned;
  • the likely consequences of the Personal Data Breach;
  • the measures we have taken or propose to take to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects; and
  • a point of contact for further information.

Where it is not possible to provide all of this information at the same time, we will provide it in phases without undue further delay. We will cooperate with you in good faith to investigate and remediate the Personal Data Breach. We will not notify the Information Commissioner's Office or any Data Subject of a Personal Data Breach on your behalf without your prior written instruction, except where required to do so by law.

14. Audits

We will make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 UK GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you, subject to the following:

  • We will, on reasonable written request and no more than once in any twelve-month period, provide you with a written response to a reasonable security questionnaire and, where available, third-party audit reports or certifications applicable to the Service or to our sub-processors.
  • Where the information provided is not sufficient to demonstrate compliance, you may request an on-site audit at our principal place of business on at least 30 days' prior written notice, during normal business hours, for a duration not exceeding two business days, conducted by you or a reputable independent auditor mandated by you who is not a competitor of ours and who has signed appropriate confidentiality undertakings.
  • On-site audits are at your cost, except where the audit identifies a material breach of this DPA by us, in which case the reasonable costs of the audit will be borne by us.
  • Audits must not unreasonably disrupt the Service or our operations and must not include access to data of other customers, our personnel records, or our internal commercial information.

Where a competent supervisory authority requires an audit that does not meet these conditions, the parties will cooperate in good faith to facilitate it.

15. Return or deletion of Customer Personal Data

On termination of your subscription, Customer Personal Data is retained in accordance with the Privacy Policy: we do not automatically delete it, so that you can resubscribe and resume work without loss. You may request deletion at any time by emailing hello@lyseta.ai. On request, we will delete or return Customer Personal Data within 30 days, except where retention is required by Applicable Data Protection Law or other law to which we are subject (for example, billing records retained for up to six years for HMRC purposes).

Following deletion, residual copies may persist in encrypted backups for the duration of our standard backup-retention cycle, after which they are overwritten in the ordinary course.

16. Liability

Each party's liability arising out of or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA excludes or limits a party's liability where it cannot be excluded or limited by Applicable Data Protection Law, including a Data Subject's right to compensation under Article 82 UK GDPR.

17. Term and termination

This DPA takes effect when you accept it (whether by ticking the agreements box at signup, by continuing to use the Service after notice of an updated DPA, or by separate signature) and continues for the duration of your subscription to the Service and any post-termination period during which we continue to process Customer Personal Data on your behalf.

18. Changes to this DPA

We may update this DPA from time to time to reflect changes in Applicable Data Protection Law, changes to our sub-processors, or changes to the Service. We will notify you of material changes by email or by displaying a notice in the Service, and the date at the top of this page shows when this DPA was last revised.

19. Governing law and jurisdiction

This DPA is governed by the laws of England and Wales. Any disputes arising out of or in connection with it are subject to the exclusive jurisdiction of the courts of England and Wales, without prejudice to any right of a supervisory authority or Data Subject under Applicable Data Protection Law to seek redress in another forum.

20. Contact

Data protection enquiries and requests under this DPA should be sent to hello@lyseta.ai.

HomeTermsPrivacyDPA
© 2026 Lyseta Ltd. All rights reserved. Registered in England and Wales · Company no. 17167358 · 71-75 Shelton Street, London, WC2H 9JQ