Data Processing Addendum
Last updated: July 17, 2026
This Data Processing Addendum (“DPA”) is entered into between Lokuna Inc. (“Lokuna”, the “processor”/service provider) and the Operator (the “controller”) and governs Lokuna’s processing of personal information of the Operator’s customers (“End-Customer Data”) in providing the Services.
1. Scope and roles
The Operator determines the purposes and means of processing End-Customer Data and warrants it has the right to provide it. Lokuna processes End-Customer Data only as the Operator’s service provider, on the documented instructions constituted by the Terms, this DPA, and the Operator’s in-product configuration (agent settings, guardrails, approval modes, channel toggles). Lokuna will inform the Operator if, in its opinion, an instruction infringes applicable data-protection law.
2. Description of processing
- Subject matter and purpose: churn detection and retention operations — analyzing billing signals, sending retention communications, operating the hosted cancellation page, applying authorized offers, and reporting.
- Categories of data: identification and contact data (name, email, phone), subscription and billing metadata (plan, amounts, status, dates), message and engagement records, customer-written message content and cancellation reasons, support-signal enrichment where connected, and derived risk scores. No special categories are intended to be processed.
- Data subjects: the Operator’s customers and prospective ex-customers.
- Duration: the term of the Operator’s account, plus the deletion period in Section 8.
3. Confidentiality and personnel
Lokuna ensures persons authorized to process End-Customer Data are bound by confidentiality obligations and access it only as needed to provide or secure the Services.
4. Security
Lokuna implements technical and organizational measures appropriate to the risk, including: TLS encryption in transit; encryption at rest at its hosting providers; application-level AES-256-GCM encryption of connected-provider credentials; logical tenant isolation enforced by row-level security and workspace-scoped queries; cryptographic verification of inbound provider webhooks; signed, expiring tokens for the cancellation flow; least-privilege access controls; and logging of agent actions.
5. Sub-processors
The Operator provides general authorization for the sub-processors below. Lokuna will update this page before adding or replacing a sub-processor and, for material changes, notify operators by email or in-app at least 15 days in advance; the Operator may object on reasonable data-protection grounds, in which case the parties will seek a solution and the Operator may terminate if none is found.
| Sub-processor | Processing | Location |
|---|---|---|
| Supabase (on AWS) | Database, authentication, storage of all End-Customer Data | United States |
| Stripe | Billing-data source (Operator-connected account); offer application | United States / global |
| OpenAI | Generation of message and page copy from customer context | United States |
| Vercel | Application hosting and request processing | United States / global |
| Resend | Platform-default email delivery | United States |
| Sentry | Error monitoring | United States |
| Cloudflare | Inbound email routing | Global |
| Upstash | Rate limiting | United States / global |
Operator-connected providers are not Lokuna sub-processors. Email, SMS, and support services the Operator connects with its own credentials (e.g., SendGrid, Amazon SES, Postmark, Gmail, Outlook, Twilio, Vonage, MessageBird, Plivo, Intercom, Zendesk, HubSpot, Freshdesk, Help Scout) act under the Operator’s own agreements; Lokuna transmits data to them as instructed by the Operator’s configuration.
6. International transfers
Processing occurs in the United States and other locations shown above. For transfers of EEA/UK personal data, Lokuna relies on its sub-processors’ execution of the European Commission’s Standard Contractual Clauses (and UK addendum) in their data-processing agreements with Lokuna. For Quebec purposes, Lokuna has carried out and maintains the assessment required by section 17 of the Act (Law 25) and will cooperate with the Operator’s own assessments on request.
7. Assistance
- Data-subject requests: if an end-customer request (access, correction, deletion, portability, objection) reaches Lokuna, it will forward it to the Operator without undue delay. Lokuna will assist the Operator in fulfilling requests within 30 days, including deletion or export of a specific customer’s data on written request.
- Incidents: Lokuna will notify the Operator without undue delay, and in any case within 72 hours, after becoming aware of a confidentiality incident affecting End-Customer Data, with the information reasonably available to support the Operator’s own notification obligations, and will document incidents as required by Law 25.
- DPIAs: Lokuna will provide reasonable information to support the Operator’s privacy impact assessments concerning the Services.
8. Deletion and return
The Operator can self-serve: deleting the account in Settings permanently deletes the workspace and all End-Customer Data in it, including message archives. Otherwise, on termination Lokuna deletes End-Customer Data within 30 days of a written request, except copies required by law, which remain protected by this DPA until deleted. During the term, the Operator can export customer data as CSV from the product. Note: for auditability, deleting an individual customer record during the term retains the sent-message archive entries for that customer; full scrubbing of an individual’s archive entries is available on request under Section 7.
9. Audit
Lokuna will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of sub-processor certifications (e.g., SOC 2) and this DPA’s measures. Audits beyond documentation review require 30 days’ notice, at most once per year, at the Operator’s expense, without access to other operators’ data.
10. Liability and order of precedence
This DPA is subject to the limitations of liability in the Terms. If this DPA conflicts with the Terms regarding processing of End-Customer Data, this DPA prevails.