Data Processing Agreement
1. Introduction and scope
This Data Processing Agreement ("DPA") forms part of the agreement between the subscribing organisation ("Customer", "Controller") and Laneden Ltd trading as Gravitas ("Processor"), company number 12297903.
This DPA governs the processing of personal data by Laneden Ltd on behalf of the Customer in connection with the Gravitas platform services.
Important: dual role clarification
Laneden Ltd acts in two distinct data protection roles:
- As a Processor (covered by this DPA): When we process Customer seed data (domains, email addresses, IP addresses) to deliver monitoring and alerting services. The Customer determines what data to monitor — we process it on their instructions.
- As a Controller (not covered by this DPA): When we independently collect and process threat intelligence data (breach records, stealer logs, dark web data) for our intelligence databases. This processing is governed by our Privacy Policy.
2. Definitions
- "Controller" — The Customer organisation that determines the purposes and means of processing personal data via the Platform
- "Processor" — Laneden Ltd, which processes personal data on behalf of the Controller
- "Sub-processor" — A third party engaged by the Processor to process personal data on behalf of the Controller
- "Personal Data" — Any information relating to an identified or identifiable natural person, as defined in UK GDPR
- "Processing" — Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, and deletion
- "Data Subject" — An identified or identifiable natural person whose personal data is processed
- "Data Breach" — A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data
3. Scope and purpose of processing
The Processor processes personal data on behalf of the Controller for the following purposes:
- Receiving and storing seed data (domains, email addresses, IP addresses) submitted by the Customer for monitoring
- Matching seed data against threat intelligence databases to identify compromised credentials and exposed data
- Generating and delivering alerts to the Customer when matches are found
- Enriching alerts with service identification, risk scoring, and incident response recommendations
The categories of personal data processed include: email addresses, domain names, IP addresses, and any other identifiers submitted by the Customer as monitoring seeds.
The categories of data subjects include: employees, contractors, and other individuals associated with the Customer's organisation whose identifiers are submitted for monitoring.
4. Our obligations as processor
Laneden Ltd shall:
- Process personal data only on documented instructions from the Controller, unless required by law
- Ensure that all personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures, including:
- Encryption of personal data at rest and in transit
- Role-based access controls
- Audit logging of data access
- Regular security assessments
- Assist the Controller in responding to data subject access requests within the required timeframes
- Assist the Controller with data protection impact assessments and prior consultation with the ICO where required
- At the Controller's choice, delete or return all personal data within 30 days of service termination
- Make available all information necessary to demonstrate compliance with this DPA
- Allow for and contribute to audits conducted by the Controller or an authorised auditor, subject to reasonable notice and scope
5. Sub-processors
The Controller authorises the Processor to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Neon Inc. | PostgreSQL database hosting | United States |
| Hetzner Online GmbH | Platform hosting and compute | Germany / Finland |
| Wasabi Technologies Inc. | Object storage (file and archive storage) | United States / EU |
| Anthropic PBC | AI-powered analysis and enrichment | United States |
| Redis Ltd. | In-memory caching and message broker | United States |
| Stripe Inc. | Payment processing and billing | United States |
| xAI Corp. | AI-powered analysis and enrichment (fallback) | United States |
Before engaging a new sub-processor, the Processor shall:
- Provide the Controller with 30 days' prior written notice, including the identity and purpose of the new sub-processor
- Ensure the new sub-processor is bound by data protection obligations no less protective than those in this DPA
The Controller may object to a new sub-processor within 14 days of notification. If the objection cannot be reasonably resolved, the Controller may terminate the affected services.
6. International transfers
Personal data is primarily processed within the United Kingdom and European Economic Area.
Where personal data is transferred to a country outside the UK that has not received an adequacy decision, the Processor shall ensure appropriate safeguards are in place, including International Data Transfer Agreements (the UK equivalent of Standard Contractual Clauses).
7. Personal data breach notification
In the event of a personal data breach affecting Controller data, the Processor shall:
- Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach
- Provide the following information (to the extent available):
- The nature of the breach
- The categories and approximate number of data subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
- Cooperate with the Controller in investigating the breach and meeting regulatory notification obligations
8. Liability
The liability of each party under this DPA is subject to the liability limitations set out in the Terms of Service.
9. Duration and termination
This DPA is effective for the duration of the service agreement between the Controller and the Processor. It terminates automatically when the service agreement ends.
The Processor's obligations regarding data deletion, return, and confidentiality survive termination of this DPA until all personal data has been deleted or returned to the Controller.