Data Processing Agreement

Last updated: 6 April 2026
Contents
  1. Introduction and scope
  2. Definitions
  3. Scope and purpose of processing
  4. Our obligations as processor
  5. Sub-processors
  6. International transfers
  7. Personal data breach notification
  8. Liability
  9. Duration and termination

1. Introduction and scope

This Data Processing Agreement ("DPA") forms part of the agreement between the subscribing organisation ("Customer", "Controller") and Laneden Ltd trading as Gravitas ("Processor"), company number 12297903.

This DPA governs the processing of personal data by Laneden Ltd on behalf of the Customer in connection with the Gravitas platform services.

Important: dual role clarification

Laneden Ltd acts in two distinct data protection roles:

2. Definitions

3. Scope and purpose of processing

The Processor processes personal data on behalf of the Controller for the following purposes:

The categories of personal data processed include: email addresses, domain names, IP addresses, and any other identifiers submitted by the Customer as monitoring seeds.

The categories of data subjects include: employees, contractors, and other individuals associated with the Customer's organisation whose identifiers are submitted for monitoring.

4. Our obligations as processor

Laneden Ltd shall:

5. Sub-processors

The Controller authorises the Processor to engage the following sub-processors:

Sub-processor Purpose Location
Neon Inc. PostgreSQL database hosting United States
Hetzner Online GmbH Platform hosting and compute Germany / Finland
Wasabi Technologies Inc. Object storage (file and archive storage) United States / EU
Anthropic PBC AI-powered analysis and enrichment United States
Redis Ltd. In-memory caching and message broker United States
Stripe Inc. Payment processing and billing United States
xAI Corp. AI-powered analysis and enrichment (fallback) United States

Before engaging a new sub-processor, the Processor shall:

The Controller may object to a new sub-processor within 14 days of notification. If the objection cannot be reasonably resolved, the Controller may terminate the affected services.

6. International transfers

Personal data is primarily processed within the United Kingdom and European Economic Area.

Where personal data is transferred to a country outside the UK that has not received an adequacy decision, the Processor shall ensure appropriate safeguards are in place, including International Data Transfer Agreements (the UK equivalent of Standard Contractual Clauses).

7. Personal data breach notification

In the event of a personal data breach affecting Controller data, the Processor shall:

8. Liability

The liability of each party under this DPA is subject to the liability limitations set out in the Terms of Service.

9. Duration and termination

This DPA is effective for the duration of the service agreement between the Controller and the Processor. It terminates automatically when the service agreement ends.

The Processor's obligations regarding data deletion, return, and confidentiality survive termination of this DPA until all personal data has been deleted or returned to the Controller.