Data Processing Agreement (DPA)
Effective: Upon activation of your lisa subscription
Governing Law: Swiss law (Canton Zurich) + GDPR
GDPR Article 28 Data Processor Agreement
Last updated: 2026-07-20
By activating the lisa service or checking "I accept" during onboarding, the Customer agrees to this Data Processing Agreement. No signature is required for self-serve subscriptions — acceptance is recorded electronically at the time of activation.
For enterprise customers requiring a signed DPA, contact legal@runlisa.ch.
1. Parties
- Data Controller: The Customer (the organization activating the lisa service)
- Data Processor: lisa i.G. ("lisa"), Zurich, Switzerland
Note: lisa currently operates as a simple partnership (Einfache Gesellschaft) under Swiss law. Upon incorporation of lisa GmbH, this DPA transfers automatically to lisa GmbH without requiring re-acceptance by the Customer.
2. Scope
This DPA governs the processing of personal data by lisa on behalf of the Customer as part of the lisa subscription service.
Data processed:
- M365 configuration data (policies, settings, user counts)
- Entity identifiers (hashed/pseudonymized — not names or email addresses)
- Audit logs and scan results
Not processed:
- Email contents, files, chats, or user-generated content
- Publicly available information
3. Processing Details
3.1 Purpose
lisa processes customer data for the sole purpose of:
- Performing security and compliance assessments of your M365 tenant
- Generating findings and recommendations
- Providing the lisa service
3.2 Duration
Processing continues for the duration of the subscription. Raw Graph API logs are deleted after 30 days on an ongoing basis, independent of termination.
Upon termination, lisa performs cryptographic erasure ("offboarding") of the Customer's tenant:
- All encryption keys and pseudonym-mapping records are deleted, making entity identifiers permanently and irreversibly unresolvable
- All operational tenant data (consents, scanner state, membership, pricing, PII) is deleted
- Backup copies are deleted within 30 days of primary deletion
De-identified retention: Assessment findings, security signals, entity statistics, and configuration data are retained indefinitely after offboarding, but only once de-identified — the cryptographic key linking this data to the Customer's tenant is destroyed during offboarding and cannot be recomputed. This retained data contains no customer identifier, no pseudonym, and no data point that could be linked back to a specific customer or individual. As anonymized data, it falls outside the scope of GDPR (Recital 26) and is not subject to the retention limits above. Purpose: product improvement and industry benchmarking.
3.3 Nature & Scope
- Categories of data: Configuration settings, entity counts, security policies
- Categories of data subjects: Implied (users referenced in M365 configuration)
- Processing operations: Collection, analysis, aggregation, reporting
- Frequency: Scheduled scans; on-demand scans when triggered by the Customer
4. Processor Obligations (GDPR Art. 28(3))
4.1 Confidentiality
- Only authorized lisa personnel access customer data
- No disclosure to third parties without written consent
- All lisa staff are bound by confidentiality obligations
4.2 Security (GDPR Art. 32)
- Encryption in transit (HTTPS/TLS) and at rest (AES-256)
- Role-based access controls with audit logs
- Pseudonymization of identifiers (HMAC-SHA256 hashing)
- Regular security testing and vulnerability scanning
- Incident response procedures with breach notification within 24 hours
4.3 Sub-processors (GDPR Art. 28(2)(4))
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Data storage (findings, configs, metadata) | Switzerland (Zurich) | Adequacy Decision (Art. 45 GDPR) |
| Anthropic Claude API | Findings synthesis (signals → recommendations) | USA | Standard Contractual Clauses (SCCs) |
| Microsoft Graph API | M365 configuration data access (read-only) | Customer's tenant region | Microsoft OST + M365 DPA |
| Azure Key Vault | Encryption keys for pseudonym secrets | Switzerland (lisa tenant) | lisa-controlled |
Important:
- lisa does NOT send raw customer data to Anthropic — only aggregated, non-identifying signals
- All third-party transfers are protected by Standard Contractual Clauses where required
- Customers will be notified at least 30 days in advance of any new sub-processor. Customers may object on reasonable grounds; lisa will discuss alternatives or allow termination without penalty.
4.4 Assistance to Controller
lisa will assist the Customer in meeting GDPR obligations under Articles 32–36:
- Data subject rights (access, deletion, correction, portability)
- Data breach notification support
- Data protection impact assessments (DPIAs)
- Audit and inspection rights
4.5 Data Deletion / Return
Upon termination or customer request, lisa will:
- Delete or return customer data within 30 days
- Provide written certification of deletion upon request
Exceptions: Data required by law (tax, audit obligations) may be retained as anonymized records only. Assessment findings, security signals, and entity statistics — once de-identified during offboarding, when the cryptographic key linking them to the Customer's tenant is destroyed — may be retained indefinitely for product improvement and industry benchmarking.
5. Data Transfers (GDPR Art. 46)
Lisa may transfer data outside the EEA. All such transfers are protected by Standard Contractual Clauses (SCCs) in accordance with GDPR Art. 46(2)(c).
By accepting this DPA, the Customer consents to transfers to sub-processors in non-EEA jurisdictions under SCCs.
6. Data Subject Rights
The Customer (as Data Controller) is responsible for handling requests from their users. Lisa will support the Customer:
| Right | lisa's response time |
|---|---|
| Access (Art. 15) | 14 days |
| Deletion (Art. 17) | 14 days |
| Correction (Art. 16) | 14 days |
| Restriction (Art. 18) | Immediate freeze upon request |
| Portability (Art. 20) | CSV/JSON within 14 days |
7. Audit & Inspection (GDPR Art. 28(3)(h))
Customers have the right to:
- Request proof of GDPR compliance (response within 14 days)
- Audit lisa's security practices (14-day advance notice required)
- Engage a third-party auditor to verify compliance
Audits may be conducted once per calendar year at no cost to lisa. Additional audits are permitted following a security incident.
8. Data Breach Notification (GDPR Art. 33–34)
If lisa discovers a breach affecting Customer data:
- lisa notifies the Customer within 24 hours (more stringent than GDPR's 72-hour requirement)
- Notification includes: nature of breach, likely consequences, measures taken, and lisa's contact person
- Lisa will assist with Customer-side breach notifications to data subjects if needed
9. Liability
Except for gross negligence or willful misconduct, lisa's liability for breaches of this DPA is capped at the fees paid by the Customer in the 3 months prior to the breach. Indirect, incidental, or consequential damages are excluded.
Rationale: lisa processes only pseudonymized M365 configuration data — no email contents, no user files, no plaintext personal data. The realistic harm of any breach is therefore limited.
Customer indemnifies lisa for claims arising from: Customer's processing instructions that violate GDPR; Customer's failure to obtain lawful basis for processing; Customer's misuse of lisa findings.
10. Amendments
This DPA may be updated to reflect regulatory changes, new sub-processors, or updated security measures. Lisa will notify Customers at least 30 days in advance of material changes. If a Customer objects to a material change (other than security improvements), they may terminate without penalty.
11. Governing Law
This DPA is governed by Swiss law (Canton Zurich), including the Swiss Federal Act on Data Protection (nDSG, in force since September 2023), and GDPR where applicable to EEA data subjects. In case of conflict, the stricter standard applies.
Acceptance
For self-serve subscriptions (Starter and Business tiers): acceptance of this DPA is recorded electronically at the time of subscription activation. No wet signature is required.
For enterprise customers (Scale tier) requiring a signed DPA: contact legal@runlisa.ch.
Contact
Legal & DPA inquiries: legal@runlisa.ch
Data privacy requests (GDPR / nDSG): dpo@runlisa.ch
General support: hello@runlisa.ch
lisa i.G. · Zurich, Switzerland · www.runlisa.ch