Legal — Data Processing Agreement

Data Processing Agreement

Version 1.0 · Effective: August 31, 2026

This Data Processing Agreement (“DPA”) is entered into between LUNR Oy, business ID 3626373-4, Jyväskylä, Finland (“LUNR”, the processor) and the customer that uses Adara (the “Customer”, the controller). It records the terms required by Article 28 GDPR where LUNR processes personal data on the Customer’s behalf.

It applies for as long as LUNR processes personal data for the Customer — including processing that lasts only seconds, such as a lead export. A short processing time does not remove the need for this agreement.

This DPA forms part of the Terms of Service and takes effect when the Customer begins using Adara. A countersigned copy, and the Standard Contractual Clauses referenced in section 12, are available on request from office@hellolunr.com.

01Roles, scope, and precedence

For personal data that the Customer submits to, or makes accessible through, Adara — including leads retrieved from the Customer’s own lead forms and data read from the Customer’s connected advertising accounts — the Customer is the controller and LUNR is the processor.

LUNR is a separate controller for its own account, billing, security, and service-usage data about the Customer’s users. That processing is governed by the Privacy Policy, not this DPA.

The advertising platforms — Meta, Google, and TikTok — are not LUNR’s sub-processors. They process the Customer’s advertising and lead data for their own purposes, under their own terms, as independent or joint controllers alongside the Customer. TikTok, for instance, identifies both itself and the advertiser as controllers for lead ads. The Customer’s relationship with each platform is its own.

Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of data protection. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.

02The Customer’s instructions

LUNR processes Customer personal data only on the Customer’s documented instructions, including for international transfers, unless EU or Finnish law requires otherwise — in which case LUNR informs the Customer before processing, unless that law forbids the notice on important grounds of public interest (Art. 28(3)(a)).

The Customer’s use of Adara constitutes its instructions. Those instructions are:

LUNR will inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data-protection law (Art. 28(3), final paragraph).

The Customer warrants that it has a lawful basis for the processing it instructs; that its lead forms carry a notice identifying the Customer as the advertiser and linking to the Customer’s own privacy notice — not to LUNR’s; that any marketing consent it relies on was collected separately and freely; and that it is authorized to grant Adara access to each connected advertising account.

03What LUNR does not do with Customer data

LUNR does not, and will not without a further written instruction and a lawful basis established by the Customer:

04Confidentiality

LUNR ensures that every person authorized to process Customer personal data is bound by an appropriate obligation of confidentiality, contractual or statutory, that survives the end of their engagement (Art. 28(3)(b)). Access is granted on a need-to-know basis and withdrawn when it is no longer needed.

05Security measures

LUNR implements appropriate technical and organizational measures under Art. 32 GDPR, having regard to the state of the art, the cost of implementation, and the nature, scope, context, and risk of the processing. The measures in force are listed in Annex II.

LUNR may update those measures over time, provided the level of protection is not reduced. Annex II describes what LUNR actually does; it does not assert any certification LUNR has not obtained.

06Sub-processors

The Customer gives LUNR general written authorization to engage sub-processors (Art. 28(2)). Those currently engaged are listed in Annex III.

07Assisting with data subject requests

Taking into account the nature of the processing, LUNR assists the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights under Chapter III GDPR (Art. 28(3)(e)).

In practice:

08Personal data breaches

LUNR notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data (Art. 28(3)(f), Art. 33(2)).

The notice describes, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where the information is not all available at once, LUNR provides it in phases without further undue delay. Notification is not an admission of fault.

09Impact assessments and prior consultation

LUNR assists the Customer, taking into account the nature of processing and the information available to it, with data protection impact assessments and prior consultation of a supervisory authority under Articles 35 and 36 (Art. 28(3)(f)).

10Deletion and return

At the Customer’s choice, on termination of the services (Art. 28(3)(g)):

Backups are overwritten on their ordinary rotation and are not restored to retrieve deleted data. Data remaining in a backup stays subject to this DPA until it is overwritten.

What deletion here does not cover. Removing a connection or closing an account does not delete files the Customer has already downloaded, nor leads held by Meta, Google, or TikTok in their own systems under their own retention rules. Those remain the Customer’s responsibility as controller.

11Information and audits

LUNR makes available to the Customer the information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates (Art. 28(3)(h)).

12International transfers

LUNR processes Customer personal data within the EEA where the service permits it. Where a sub-processor listed in Annex III processes data outside the EEA, the transfer relies on a mechanism under Chapter V GDPR — in practice the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), supplemented where the provider offers it by certification under the EU–US Data Privacy Framework.

Where the Clauses apply between the Customer and LUNR, Module Two (controller to processor) applies, with the Customer as data exporter and LUNR as data importer; Annexes I–III of this DPA populate the corresponding Annexes of the Clauses; the optional docking clause applies; and the governing law and forum are Finland.

LUNR states a specific transfer mechanism for a specific sub-processor only where it has confirmed it in that provider’s current terms. The Customer may request the applicable clauses at office@hellolunr.com.

13Term, liability, and governing law

This DPA takes effect when the Customer begins using Adara and continues until LUNR has ceased all processing of Customer personal data and completed its obligations under section 10. Sections 04, 10, and 13 survive termination.

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by applicable data-protection law. Nothing in this DPA limits a data subject’s rights, or either party’s liability to a supervisory authority.

This DPA is governed by Finnish law, and disputes are subject to the courts of Finland, without prejudice to Art. 79 GDPR.

A1Annex I — Details of the processing

Subject matter. Provision of the Adara advertising workspace to the Customer.

Duration. The term of the Customer’s agreement, plus the wind-down periods in section 10. For lead exports, the duration of each export request only.

Nature and purpose. Reading advertising data from the Customer’s connected accounts; analysis and reporting; preparing campaign changes for a Customer user to approve; and retrieving leads from the Customer’s lead forms on request and returning them as a file.

Categories of data subjects.

Categories of personal data.

Special categories. None are requested or required. The Customer must not configure lead-form questions that solicit Article 9 data.

Frequency. Continuous for advertising data; on request for lead exports.

Retention — the point that matters most. Lead content is not persisted. When an authorized user requests an export, Adara retrieves the records from the platform API, holds them only for the duration of the request, returns a CSV, and discards them. What is retained is export and audit metadata — which user, which workspace, which connected account, which form, how many records, and when — which contains no lead content, and is deleted per section 10.

A2Annex II — Technical and organizational measures

The measures in force under Art. 32. This is a description of practice, not a claim of certification.

A3Annex III — Approved sub-processors

Sub-processors engaged by LUNR to process Customer personal data as at the effective date of this DPA:

Processors that LUNR uses for its own controller-side processing — such as Resend for contact-form email, and Google Analytics and Microsoft Clarity for consent-gated website analytics — do not process Customer personal data under this DPA and are described in the Privacy Policy instead.

Meta, Google, and TikTok are not sub-processors under this DPA. They are the source of, and independent or joint controllers for, the Customer’s advertising and lead data, under the Customer’s own relationship with each platform. See section 01.

Changes to this Annex are notified under section 06.

14Contact

LUNR Oy — Data Protection Business ID (Y-tunnus) 3626373-4 Jyväskylä, Finland office@hellolunr.com