Data Processing Addendum
Last updated
This Addendum applies wherever LBREEZE LIMITED processes personal data on behalf of a customer. It forms part of our Terms of Service and takes effect automatically when you open an account: you do not need to sign or return a separate copy, though we will sign one on request for your records.
Where this Addendum conflicts with the rest of the agreement on the subject of personal data processed on your behalf, this Addendum wins.
1. Which data this covers, and which it does not
You are the controller and we are the processor for personal data that you or your users place inside the services: the contents of your virtual machines, containers, Incus instances, databases, object storage, mailboxes and self-hosted applications, together with the logs those systems generate.
We are the controller, not your processor, for personal data about you as our customer: your account details, your billing records, your support tickets, and the security and authentication logs of your access to our platform. What we do with those is described in our Privacy Policy, and this Addendum does not apply to them.
This distinction matters in practice. A request from one of your end users about data in your application is yours to answer, not ours, and we will say so and pass it to you.
2. Details of the processing
Subject matter. Provision of hosting, infrastructure, deployment automation and related services as described in your order.
Duration. For as long as you have an active service, plus the deletion window in section 10.
Nature and purpose. Hosting, storage, transmission, backup where purchased, and the technical operations needed to keep the service running, including replication, migration between hosts, failure recovery and security monitoring at the infrastructure layer.
Types of personal data. Whatever you choose to place in the services. We do not control or inspect this, and it may include names, contact details, account credentials, financial data, correspondence, usage records and content generated by your users.
Categories of data subjects. Whoever your systems are about: your customers, your employees, your suppliers, visitors to your sites, and users of your applications.
Special category data. You may place special category data or criminal offence data in the services, but if you do you must tell us in advance at privacy@lbreeze.com, because it changes the security measures we apply and may require a different plan.
3. Our obligations as processor
We will:
Process only on your documented instructions, including for transfers of personal data to a third country. Your instructions are the agreement, your configuration of the services, and anything else you send us in writing. If we believe an instruction breaches data protection law, we will tell you and may pause that processing until it is resolved. If we are required by law to process beyond your instructions, we will tell you before doing so unless the law forbids it.
Keep it confidential. Everyone we authorise to process your personal data is bound by a written duty of confidentiality that survives the end of their engagement, and is given access only where their role requires it.
Secure it with the technical and organisational measures in section 6.
Assist you. We will help you respond to requests from data subjects, and help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and what we have access to. Assistance that goes beyond giving you access to your own systems and data may be charged at our standard rates, and we will tell you the cost before starting.
Tell you about breaches without undue delay, as set out in section 7.
Delete or return the data at the end, as set out in section 10.
Make available the information you need to demonstrate compliance with Article 28 of the UK GDPR, and allow audits, as set out in section 9.
4. Your obligations as controller
You warrant that you have a lawful basis for the personal data you place in the services, that you have given the people it is about the information they are entitled to, and that your instructions to us will not put us in breach of data protection law.
You are responsible for the configuration of your own environment: access control, encryption of your application data, what you log, what you retain, and who you give access to. We provide the platform on which those decisions are implemented; we do not make them for you.
You must not place personal data in a free, trial or beta service that you would not be willing to lose, and you must not place special category data anywhere without telling us first.
5. Sub-processors
You give us general written authorisation to engage sub-processors. The current list, with the name, the service each provides, and the country each is located in, is published at lbreeze.com/legal/sub-processors and forms part of this Addendum.
We impose data protection obligations on every sub-processor that are no less protective than those in this Addendum, and we remain fully liable to you for their performance.
We will give at least 30 days' notice before adding or replacing a sub-processor. Subscribe to notifications at the sub-processor page, or write to privacy@lbreeze.com and we will email you directly. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate the affected service without penalty and receive a pro-rata refund of prepaid fees. Continuing to use the service after the notice period means you have not objected.
6. Security measures
We apply measures appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing. These include:
Encryption. TLS for all data in transit across public networks, with obsolete protocol versions disabled. Encryption at rest for backups and for the storage underlying customer instances.
Access control. Role-based access on the principle of least privilege. Multi-factor authentication for all staff access to production systems. Unique named accounts with no shared credentials. Access reviewed on a defined cycle and revoked on the day a person leaves.
Segregation. Customer environments are isolated from each other at the hypervisor and network layers. Management networks are segregated from customer traffic.
Logging and monitoring. Administrative actions on production systems are logged to a store the acting administrator cannot alter. Logs are monitored for anomalous access and retained as stated in the Privacy Policy.
Resilience. The ability to restore availability and access to personal data in a timely manner after an incident, with restore procedures tested on a defined cycle rather than assumed to work.
Vulnerability management. Security patches applied to platform components on a defined schedule, with a shorter path for actively exploited vulnerabilities.
Personnel. Background checks appropriate to the role where the law allows, data protection training on joining and periodically after, and a written confidentiality undertaking.
Change management. Changes to production reviewed before deployment, with the ability to roll back.
We may update these measures, but not in a way that materially reduces the overall level of security.
7. Personal data breaches
If we become aware of a personal data breach affecting personal data we process on your behalf, we will tell you without undue delay and in any event within 24 hours of becoming aware, using the contact on your account. We will give you what we know: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we do not have all of it at once, we will send it in stages as it becomes available rather than waiting.
Notifying the ICO and affected data subjects is your decision and your obligation as controller, and we will not make a notification on your behalf unless you ask us to in writing. We will give you reasonable assistance in making it.
We will not tell a third party about a breach affecting your data without telling you first, unless the law requires it.
8. Data subject requests
If we receive a request from one of your data subjects that concerns data we process on your behalf, we will not respond to it substantively. We will tell the person to contact you, and we will tell you about the request without undue delay.
Where you need our help to answer a request, ask at privacy@lbreeze.com. We will provide reasonable assistance, taking account of what we can actually reach: for data inside your instances, that normally means giving you the access you already have rather than extracting data on your behalf.
9. Audits and information
We will make available to you the information necessary to demonstrate compliance with this Addendum. In the first instance that means our current security documentation, our sub-processor list, and written answers to a reasonable security questionnaire.
Where that is not enough, you may audit us, or appoint an independent auditor who is not one of our competitors and who signs a confidentiality undertaking. Audits are limited to once in any 12 months unless a breach or a regulator's instruction requires another, must be requested at least 30 days in advance, must take place during business hours, and must not disrupt our operations or compromise the confidentiality or security of other customers. You bear the cost of the audit, except where it finds a material breach of this Addendum, in which case we bear it. We will not give access to systems, premises or records that would reveal another customer's data.
10. Return and deletion
When a service ends, we keep the data for 30 days so that you can retrieve it, and then delete it. Tell us in writing during that window if you want it deleted sooner and we will delete it.
You are responsible for taking your own export before termination. We will provide reasonable assistance in doing so, at our standard rates for anything beyond giving you access to your own data.
After the deletion window, data remaining in backups is deleted on the normal backup rotation described in the Privacy Policy retention schedule, and is not restored or accessed in the meantime. We may retain personal data where the law requires it, in which case we keep it only for that purpose, only for as long as required, and continue to protect it under this Addendum. We will confirm deletion in writing on request.
11. International transfers
We process personal data in the United Kingdom and the European Economic Area. Request metadata, including IP addresses, is additionally processed at the global edge locations of the content delivery and DNS provider identified in our sub-processor list. Where a sub-processor is in a country without a UK adequacy finding, the transfer is made under the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, supported by a transfer risk assessment and additional measures. You instruct us to enter into those instruments on your behalf as your processor, and we will provide a copy of the relevant one on request.
12. Liability and general
Liability under this Addendum is subject to the limitations and exclusions in the Terms of Service, except where the law does not allow it to be limited.
This Addendum is governed by the law of England and Wales. Terms used here that are defined in the UK GDPR or the Data Protection Act 2018 have the meaning given there.
If data protection law changes so that this Addendum no longer meets it, we will update this Addendum and, where the change materially affects your rights, give you notice as set out in the Terms of Service.

