Security + Privacy

Data Processing Agreement (DPA)

Terms governing how Lisaiceland DBA processes personal data on behalf of customers acting as data controllers.

Effective DateJune 20, 2026
Version1.1
OwnerLisaiceland DBA
CoverageAll listed properties

Scope and Covered Properties

This policy applies to Lisaiceland DBA and all websites, applications, products, services, documentation, APIs, affiliate programs, creator programs, AI systems, integrations, and future offerings, including:

References to "Lisaiceland," "we," "us," or "our" mean Lisaiceland DBA.

Purpose

This Data Processing Agreement ("DPA") supplements the Terms of Service and forms a binding agreement between the customer ("Controller") and Lisaiceland DBA ("Processor") whenever the Processor processes personal data on the Controller's behalf in the course of providing the Lisaiceland services.

Roles of the Parties

The Controller determines the purposes and means of processing personal data submitted to the services. The Processor processes that personal data only on documented instructions from the Controller, which include the Order Form, the Terms of Service, this DPA, and any reasonable additional instructions consistent with them.

Subject Matter and Duration

  • Subject matter: processing of personal data as needed to deliver the Lisaiceland services.
  • Duration: for the term of the Controller's subscription, plus any post-termination retention period set out in the Data Retention Policy.
  • Nature and purpose: hosting, transmission, storage, AI inference, analytics, support, and security operations.
  • Categories of data subjects: Controller's end users, customers, employees, contractors, and other individuals whose data the Controller submits.
  • Categories of personal data: identifiers, contact details, account data, voice recordings, transcripts, AI prompts and outputs, usage and device data, and any other data the Controller chooses to submit.

Processor Obligations

  • Process personal data only on the Controller's documented instructions.
  • Ensure that personnel authorized to process personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organizational measures consistent with the Security Infrastructure Overview and Encryption Standards Policy.
  • Assist the Controller, taking into account the nature of processing, in responding to data subject requests, conducting impact assessments, and meeting breach-notification obligations.
  • At the Controller's choice, delete or return personal data at the end of the services, subject to legal retention requirements.

Sub-processors

The Controller provides general authorization for the Processor to engage sub-processors. A current list of sub-processors is maintained in the Vendor / Subprocessor Policy. The Processor will give reasonable notice of any intended additions or replacements and will impose data protection obligations on each sub-processor that are no less protective than those in this DPA.

International Transfers

Where personal data is transferred from a jurisdiction with cross-border restrictions, the parties will rely on an approved transfer mechanism such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent instrument, and will implement supplementary measures where required by applicable law.

Security Incidents

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data and will provide information reasonably necessary for the Controller to meet its own notification obligations. Operational handling follows the Incident Response Policy.

Audits

The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including current third-party assessments, security questionnaires, and policy documentation. On-site audits may be requested where required by law and will be coordinated to avoid disruption to the services and to other customers.

Data Subject Requests

The Processor will, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the Controller's obligations to respond to requests for exercising data subject rights, as further described in the DSAR Policy.

Liability and Precedence

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service. In the event of a conflict between this DPA and any other agreement between the parties regarding the processing of personal data, this DPA controls solely with respect to that processing.

General Legal Terms

Reservation of Rights

Lisaiceland DBA reserves all rights not expressly granted and may update, restrict, suspend, remove, review, or terminate access, content, workflows, affiliate participation, commissions, rewards, or AI functionality where needed to protect users, customers, legal compliance, product integrity, or brand trust.

No Professional Advice

Lisaiceland DBA products, documents, automations, and AI outputs are not legal, medical, financial, tax, employment, emergency, or professional advice.

Limitation of Liability

To the maximum extent permitted by law, Lisaiceland DBA will not be liable for indirect, incidental, consequential, special, exemplary, punitive, lost-profit, lost-data, or reputational damages.

Governing Law

Unless mandatory law requires otherwise, this policy is governed by the laws of the State of Texas, United States, without regard to conflict-of-law principles.

Contact

Questions, requests, or concerns about this policy may be directed to Support | Get Help.