Legal — Data Processing Agreement
Data Processing Agreement
Version 1.0 · Effective: August 31, 2026
This Data Processing Agreement (“DPA”) is entered into between LUNR Oy, business ID 3626373-4, Jyväskylä, Finland (“LUNR”, the processor) and the customer that uses Adara (the “Customer”, the controller). It records the terms required by Article 28 GDPR where LUNR processes personal data on the Customer’s behalf.
It applies for as long as LUNR processes personal data for the Customer — including processing that lasts only seconds, such as a lead export. A short processing time does not remove the need for this agreement.
This DPA forms part of the Terms of Service and takes effect when the Customer begins using Adara. A countersigned copy, and the Standard Contractual Clauses referenced in section 12, are available on request from office@hellolunr.com.
01Roles, scope, and precedence
For personal data that the Customer submits to, or makes accessible through, Adara — including leads retrieved from the Customer’s own lead forms and data read from the Customer’s connected advertising accounts — the Customer is the controller and LUNR is the processor.
LUNR is a separate controller for its own account, billing, security, and service-usage data about the Customer’s users. That processing is governed by the Privacy Policy, not this DPA.
The advertising platforms — Meta, Google, and TikTok — are not LUNR’s sub-processors. They process the Customer’s advertising and lead data for their own purposes, under their own terms, as independent or joint controllers alongside the Customer. TikTok, for instance, identifies both itself and the advertiser as controllers for lead ads. The Customer’s relationship with each platform is its own.
Where this DPA conflicts with the Terms of Service, this DPA prevails for matters of data protection. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail.
02The Customer’s instructions
LUNR processes Customer personal data only on the Customer’s documented instructions, including for international transfers, unless EU or Finnish law requires otherwise — in which case LUNR informs the Customer before processing, unless that law forbids the notice on important grounds of public interest (Art. 28(3)(a)).
The Customer’s use of Adara constitutes its instructions. Those instructions are:
- to connect advertising accounts the Customer owns or is authorized to manage, and to read from them the data described in Annex I;
- to analyze that data and present reporting, insight, and recommendations to the Customer’s users;
- to prepare campaign changes and new campaigns for a Customer user to approve;
- to retrieve leads from the Customer’s lead forms on request and return them to an authorized Customer user as a file;
- to keep the export and audit metadata described in Annex I, for security and accountability.
LUNR will inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data-protection law (Art. 28(3), final paragraph).
The Customer warrants that it has a lawful basis for the processing it instructs; that its lead forms carry a notice identifying the Customer as the advertiser and linking to the Customer’s own privacy notice — not to LUNR’s; that any marketing consent it relies on was collected separately and freely; and that it is authorized to grant Adara access to each connected advertising account.
03What LUNR does not do with Customer data
LUNR does not, and will not without a further written instruction and a lawful basis established by the Customer:
- use Customer personal data for its own purposes, or for any other customer;
- use Customer personal data to train or improve machine-learning models;
- score, rank, enrich, or otherwise automatically evaluate leads;
- build custom audiences, lookalike audiences, or match lists from Customer data;
- sell Customer personal data or disclose it for anyone’s advertising.
04Confidentiality
LUNR ensures that every person authorized to process Customer personal data is bound by an appropriate obligation of confidentiality, contractual or statutory, that survives the end of their engagement (Art. 28(3)(b)). Access is granted on a need-to-know basis and withdrawn when it is no longer needed.
05Security measures
LUNR implements appropriate technical and organizational measures under Art. 32 GDPR, having regard to the state of the art, the cost of implementation, and the nature, scope, context, and risk of the processing. The measures in force are listed in Annex II.
LUNR may update those measures over time, provided the level of protection is not reduced. Annex II describes what LUNR actually does; it does not assert any certification LUNR has not obtained.
06Sub-processors
The Customer gives LUNR general written authorization to engage sub-processors (Art. 28(2)). Those currently engaged are listed in Annex III.
- LUNR imposes on each sub-processor, by contract, data-protection obligations no less protective than those in this DPA (Art. 28(4)).
- LUNR remains fully liable to the Customer for a sub-processor’s performance.
- LUNR gives the Customer at least 30 days’ notice before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected service without penalty for the remainder of its term.
07Assisting with data subject requests
Taking into account the nature of the processing, LUNR assists the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights under Chapter III GDPR (Art. 28(3)(e)).
In practice:
- If a data subject contacts LUNR directly about data LUNR processes for the Customer, LUNR does not respond substantively. It tells the person to contact the Customer, and notifies the Customer without undue delay.
- LUNR does not disclose, correct, or delete Customer personal data in response to a data subject request without the Customer’s instruction.
- Because lead content is not retained (Annex I), LUNR generally holds no record to disclose or erase. What LUNR can provide is the export metadata: which exports covered a given form and period, and which user made them — so the Customer can act on the copies it holds.
- The Customer is responsible for exported files once they have been downloaded, and for leads still held by an advertising platform. LUNR cannot reach either.
08Personal data breaches
LUNR notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data (Art. 28(3)(f), Art. 33(2)).
The notice describes, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where the information is not all available at once, LUNR provides it in phases without further undue delay. Notification is not an admission of fault.
09Impact assessments and prior consultation
LUNR assists the Customer, taking into account the nature of processing and the information available to it, with data protection impact assessments and prior consultation of a supervisory authority under Articles 35 and 36 (Art. 28(3)(f)).
10Deletion and return
At the Customer’s choice, on termination of the services (Art. 28(3)(g)):
- Lead content — nothing to delete or return. It is never written to LUNR’s database; it exists only for the duration of an export request. See Annex I.
- Connected-account credentials and cached advertising data — deleted within 30 days of the connection being removed or the account being closed.
- Export and audit metadata — deleted 12 months after the export, or within 30 days of account closure, whichever is earlier, unless EU or Finnish law requires it to be kept.
- Data the Customer asks to be returned — provided in a commonly used machine-readable format before deletion, where the Customer requests it in writing before the account closes.
Backups are overwritten on their ordinary rotation and are not restored to retrieve deleted data. Data remaining in a backup stays subject to this DPA until it is overwritten.
What deletion here does not cover. Removing a connection or closing an account does not delete files the Customer has already downloaded, nor leads held by Meta, Google, or TikTok in their own systems under their own retention rules. Those remain the Customer’s responsibility as controller.
11Information and audits
LUNR makes available to the Customer the information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates (Art. 28(3)(h)).
- LUNR responds in writing to reasonable data-protection questionnaires, at no charge, once per year.
- An on-site or technical audit may be requested once per year, on 30 days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. The Customer bears its own costs; LUNR may charge for time beyond one working day at its standard rates.
- Either party may request more frequent audits following a personal data breach or a supervisory authority’s direction.
12International transfers
LUNR processes Customer personal data within the EEA where the service permits it. Where a sub-processor listed in Annex III processes data outside the EEA, the transfer relies on a mechanism under Chapter V GDPR — in practice the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), supplemented where the provider offers it by certification under the EU–US Data Privacy Framework.
Where the Clauses apply between the Customer and LUNR, Module Two (controller to processor) applies, with the Customer as data exporter and LUNR as data importer; Annexes I–III of this DPA populate the corresponding Annexes of the Clauses; the optional docking clause applies; and the governing law and forum are Finland.
LUNR states a specific transfer mechanism for a specific sub-processor only where it has confirmed it in that provider’s current terms. The Customer may request the applicable clauses at office@hellolunr.com.
13Term, liability, and governing law
This DPA takes effect when the Customer begins using Adara and continues until LUNR has ceased all processing of Customer personal data and completed its obligations under section 10. Sections 04, 10, and 13 survive termination.
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where those limitations are not permitted by applicable data-protection law. Nothing in this DPA limits a data subject’s rights, or either party’s liability to a supervisory authority.
This DPA is governed by Finnish law, and disputes are subject to the courts of Finland, without prejudice to Art. 79 GDPR.
A1Annex I — Details of the processing
Subject matter. Provision of the Adara advertising workspace to the Customer.
Duration. The term of the Customer’s agreement, plus the wind-down periods in section 10. For lead exports, the duration of each export request only.
Nature and purpose. Reading advertising data from the Customer’s connected accounts; analysis and reporting; preparing campaign changes for a Customer user to approve; and retrieving leads from the Customer’s lead forms on request and returning them as a file.
Categories of data subjects.
- The Customer’s authorized users of Adara.
- Individuals who submit one of the Customer’s lead forms on Meta, Google, or TikTok.
Categories of personal data.
- Users: name, email address, login identifiers, role in the workspace, and action logs.
- Lead submitters: name; email address; phone number where the form requests it; company details where the form requests them; answers to that form’s custom questions; and submission metadata (platform lead identifier, form identifier, campaign or ad identifier, submission time).
- Advertising data: account, campaign, ad set, ad, creative, performance, conversion, and reporting data, which is generally not personal data but may contain it incidentally.
Special categories. None are requested or required. The Customer must not configure lead-form questions that solicit Article 9 data.
Frequency. Continuous for advertising data; on request for lead exports.
Retention — the point that matters most. Lead content is not persisted. When an authorized user requests an export, Adara retrieves the records from the platform API, holds them only for the duration of the request, returns a CSV, and discards them. What is retained is export and audit metadata — which user, which workspace, which connected account, which form, how many records, and when — which contains no lead content, and is deleted per section 10.
A2Annex II — Technical and organizational measures
The measures in force under Art. 32. This is a description of practice, not a claim of certification.
- Encryption in transit — TLS on all connections to and from the service and to platform APIs.
- Encryption at rest — OAuth access tokens and credentials are stored encrypted.
- Data minimization by architecture — lead content is never written to the database; the export path is memory-only for the duration of the request. This is the single largest risk reduction in the system: data that is not stored cannot be breached.
- Minimum scopes — advertising account connections request only the scopes the Customer’s features require.
- Access control — workspace-scoped authorization; a user reaches only the accounts their workspace is connected to. Internal administrative access is limited to personnel who need it and is revoked when no longer needed.
- Human approval gate — no change affecting campaigns, delivery, targeting, budgets, bidding, ads, or spend is applied without explicit confirmation by a Customer user; new campaigns are created paused.
- Audit logging — exports and connection changes are logged with actor, scope, and timestamp.
- Hosting — infrastructure operated by the provider named in Annex III, with its own physical, network, and availability controls.
- Confidentiality obligations — as set out in section 04.
- Breach process — as set out in section 08.
A3Annex III — Approved sub-processors
Sub-processors engaged by LUNR to process Customer personal data as at the effective date of this DPA:
- Vercel Inc. — application hosting, serverless compute, and content delivery for Adara and hellolunr.com. Processing takes place in the EEA and the United States.
Processors that LUNR uses for its own controller-side processing — such as Resend for contact-form email, and Google Analytics and Microsoft Clarity for consent-gated website analytics — do not process Customer personal data under this DPA and are described in the Privacy Policy instead.
Meta, Google, and TikTok are not sub-processors under this DPA. They are the source of, and independent or joint controllers for, the Customer’s advertising and lead data, under the Customer’s own relationship with each platform. See section 01.
Changes to this Annex are notified under section 06.