Leiko Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA”) forms part of the Leiko Terms of Service (“Agreement”) between Keidas AI Oy (Business ID 3446327-3), Kanavakatu 1 A 3009, FI-00160 Helsinki, Finland (“Processor”, “Keidas AI”) and the Customer. It applies to the extent Keidas AI processes personal data on the Customer's behalf. In case of conflict regarding data processing, this DPA prevails over the Agreement.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the EU General Data Protection Regulation 2016/679 (“GDPR”). “Customer Data” means personal data that the Customer submits to or connects with the Service, as described in Annex 1.
2. Roles and scope
The Customer is the controller of Customer Data; Keidas AI is the processor. For the Customer's own account, billing, and usage data, Keidas AI is an independent controller as described in the Privacy Policy, and this DPA does not apply. This DPA remains in force as long as Keidas AI processes Customer Data.
3. Instructions
Keidas AI processes Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do otherwise by EU or Member State law (in which case Keidas AI informs the Customer before processing, unless the law prohibits it). The Agreement, this DPA, and the Customer's configuration and use of the Service (connecting integrations, approving actions, using features) constitute the documented instructions. Keidas AI will inform the Customer if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality
Keidas AI ensures that persons authorized to process Customer Data are bound by confidentiality obligations and access Customer Data only on a need-to-know basis for operating, securing, or supporting the Service.
5. Security
Keidas AI implements and maintains appropriate technical and organizational measures pursuant to GDPR Article 32, as described in Annex 2, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing. Keidas AI may update the measures provided the overall level of protection is not reduced.
6. Subprocessors
The Customer grants a general authorization to engage the subprocessors listed in the Subprocessor List. Keidas AI will notify the Customer of intended additions or replacements at least 30 days in advance (by email or in-Service notice). The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected parts of the Service and receives a refund of prepaid fees for the unused period. Keidas AI imposes data protection obligations on subprocessors that are materially equivalent to this DPA and remains liable for their performance.
AI subprocessors. Keidas AI uses AI providers solely to provide features of the Service. Keidas AI does not use Customer Data to train general-purpose AI or machine-learning models and contractually requires the same of its AI subprocessors.
7. Assistance to the Customer
Taking into account the nature of processing, Keidas AI assists the Customer with appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data subject requests (GDPR Chapter III), and in ensuring compliance with GDPR Articles 32–36 (security, breach notification, data protection impact assessments, prior consultation), taking into account the information available to Keidas AI. If a data subject contacts Keidas AI directly regarding Customer Data, Keidas AI will forward the request to the Customer without undue delay and will not respond on the merits except on the Customer's instruction or where legally required.
8. Personal data breaches
Keidas AI notifies the Customer without undue delay after becoming aware of a personal data breach concerning Customer Data. The notification describes, to the extent known: the nature of the breach, categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. Keidas AI provides updates as information becomes available and cooperates with the Customer's own notification obligations.
9. International transfers
Customer Data is hosted in the EU. Where a subprocessor processes Customer Data outside the EU/EEA (see the Subprocessor List), the transfer is protected by the EU–U.S. Data Privacy Framework where the recipient is certified, or by the European Commission's Standard Contractual Clauses with supplementary measures where appropriate. Keidas AI will implement an alternative lawful transfer mechanism if a relied-upon mechanism is invalidated.
10. Audits
Keidas AI makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits or certifications of its infrastructure providers, and responses to reasonable written security questionnaires (at most once per 12 months, unless a supervisory authority requires otherwise or a breach has occurred). Where GDPR Article 28(3)(h) requires more, the Customer may conduct, at its own cost and with at least 30 days' notice, an audit during business hours that does not endanger other customers' data, confidentiality, or the security of the Service; the parties will agree on scope and timing in advance.
11. Deletion and return
Upon termination of the Agreement (account deletion), Keidas AI deletes Customer Data within 30 days, except where EU or Member State law requires storage. Residual copies in backups are purged in the ordinary backup rotation cycle. Before deletion, the Customer can export data using the Service's export features and may request reasonable assistance with export at hello@leiko.ai. During the Agreement, the Customer can delete specific Customer Data directly in the Service (for example, chats, memories, receipts, or synced email by disconnecting Gmail).
12. Liability
Liability under this DPA is subject to the limitations and exclusions of the Agreement, without prejudice to data subjects' rights under GDPR Article 82 and to any liability that cannot be limited under mandatory law.
Annex 1 — Description of processing
Subject matter and nature. Hosting, storage, syncing, analysis (including AI-assisted classification, extraction, summarization, and drafting), and transmission-on-approval of the Customer's business content to provide the Leiko service.
Purpose. Providing the Service as described in the Agreement.
Duration. The term of the Agreement plus the deletion period in Section 11.
Categories of data subjects. The Customer and its personnel; the Customer's clients and prospects; suppliers and merchants; email correspondents; calendar/meeting participants.
Categories of personal data. Identification and contact details (names, email addresses, phone numbers, postal addresses); business identifiers (business IDs, VAT IDs); correspondence content and metadata; calendar event details and participants; financial and transactional data (invoices, line items, bank details on invoices, receipts, amounts, payment card last four digits where printed on receipts); notes and free-text content; communication-style attributes derived from correspondence.
Special categories of data. Not intended to be processed. The Customer must not deliberately submit special-category data; incidental occurrences in correspondence are processed only as unavoidable parts of the content.
Annex 2 — Technical and organizational measures
- Encryption: TLS for data in transit; provider-level encryption at rest; application-level AES-256 encryption of OAuth tokens.
- Access control: authentication via a managed identity provider; per-workspace (per-entity) application-level isolation of Customer Data on every data access; role-based access for personnel on a need-to-know basis; administrative functions gated by role.
- File storage: private storage buckets; files served only via short-lived signed URLs.
- Infrastructure: EU-region hosting (application: Google Cloud, Belgium; database and storage: Supabase, Stockholm); managed platform patching; infrastructure providers holding recognized certifications (e.g., SOC 2 / ISO 27001).
- Data minimization in operations: message content excluded from operational logs; AI usage metering stores counts and metadata, not content; short log rotation.
- Human-in-the-loop: outbound communications require explicit Customer approval; automated suggestions are marked for review.
- Resilience: managed backups with rotation; deletion propagates through the backup cycle.
- Organizational: confidentiality undertakings for personnel; least-privilege administrative access; documented incident response with customer notification per Section 8; subprocessor due diligence and contracts per Section 6.
Annex 3 — Approved subprocessors
The current list is maintained in the Subprocessor List (see the separate document forming part of this DPA).