Data Processing Agreement
Effective Date: May 25, 2026 | Last Updated: July 30, 2026 | Version: 1.0
This Data Processing Agreement ("DPA") forms part of the agreement between Lesuto Technologies, Inc., a Delaware corporation with its principal office at 600 Congress Ave, STE 1400, Austin, TX 78701 ("Lesuto" or "Processor"), and the entity identified during onboarding ("Controller"), for the processing of personal data in connection with the Lesuto platform (the "Services"). This DPA supplements the applicable service agreement, including the Platform Operator Agreement, Merchant Agreement, or Supplier Agreement (collectively, the "Principal Agreement").
1. Definitions
Terms used in this DPA have the meanings set forth in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection, as applicable. In addition:
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Lesuto on behalf of the Controller in connection with the Services.
- "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
- "Sub-processor" means any third party engaged by Lesuto to process Personal Data on behalf of the Controller.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
2. Roles and Responsibilities
Lesuto Technologies, Inc. is the merchant of record and the controller for shopper checkout, customer accounts, payments, and order records. Platform Operators are not controllers of End User checkout data and receive aggregated analytics only.
For Merchant and Supplier business data (catalog, staff users, payout accounts), that business is the Controller and Lesuto is the Processor for hosting and operations, solely in accordance with this DPA and the Principal Agreement. Lesuto shall not process that business Personal Data for other purposes unless required by applicable law, in which case Lesuto shall inform the Controller of such legal requirement prior to processing (unless prohibited from doing so by law).
3. Processing Purposes
Lesuto processes Personal Data for the following purposes in connection with the Services:
- Commerce: Processing orders, managing payments (as merchant of record), handling refunds and chargebacks, facilitating shipping and fulfillment, and managing customer accounts.
- Analytics: Generating aggregated, anonymized analytics about platform activity, store performance, and customer engagement. Individual-level analytics are accessible only to the data subject (their own data) and to Lesuto for platform operations.
- Personalization: Providing personalized product recommendations, search results, and content based on user behavior and preferences, subject to user consent where required.
- Communications: Sending transactional emails (order confirmations, shipping updates), service notifications, and marketing communications (with user consent).
- Security: Fraud detection and prevention, platform security monitoring, and abuse prevention.
- Compliance: Tax calculation and reporting, regulatory compliance, and responding to legal requests.
4. Categories of Data and Data Subjects
The categories of Personal Data and Data Subjects processed under this DPA include:
- Customers: Name, email, shipping address, phone number, order history, payment transaction identifiers, browsing and shopping behavior, wishlist data, and communication preferences.
- Merchants: Business name, contact information, business address, tax identifiers, payout account details, storefront configuration, and sales data.
- Suppliers: Business name, contact information, business address, tax identifiers, payout account details, product catalog data, and fulfillment records.
5. Sub-processors
The Controller authorizes Lesuto to engage the following Sub-processors to assist in providing the Services. Lesuto ensures that each Sub-processor is bound by data protection obligations no less protective than those in this DPA.
- Stripe, Inc. - Payment processing, tax calculation, payout distribution, and fraud detection. Data processed: payment card information, transaction details, payout account details. Location: United States.
- Google Cloud Platform (Google LLC) - Cloud infrastructure, database hosting, application hosting, AI/ML services, and email delivery. Data processed: all categories of Personal Data necessary for platform operations. Location: United States (us-west1 region).
- Amazon Web Services (AWS) - AI content generation (Amazon Bedrock), media processing, and supplementary cloud services. Data processed: product content, media assets, and user-submitted content for AI processing. Location: United States.
- Cloudflare, Inc. - Content delivery network, DDoS protection, DNS, and web application firewall. Data processed: IP addresses, request metadata, and cached content. Location: Global edge network.
Lesuto shall notify the Controller at least thirty (30) days before engaging any new Sub-processor or replacing an existing Sub-processor. The Controller may object to the engagement of a new Sub-processor by providing written notice within fifteen (15) days of receiving notification. If Lesuto cannot reasonably accommodate the objection, either party may terminate the Principal Agreement.
6. Data Retention
Lesuto retains Personal Data for the duration of the Controller's account lifecycle and as follows:
- Active accounts: Personal Data is retained for as long as the account remains active and the Services are being provided.
- Post-termination: Upon termination of the Principal Agreement, Lesuto will retain Personal Data for up to ninety (90) days to facilitate data export. After this period, Personal Data will be deleted or anonymized, except as required by law.
- Legal retention: Certain data (transaction records, tax documents, fraud investigation records) may be retained for up to seven (7) years as required by applicable tax, financial, and regulatory laws.
- Behavioral data: Behavioral tracking data (product views, searches, shopping activity) is anonymized after twelve (12) months and permanently deleted after twenty-four (24) months.
- Backups: Automated database backups may contain Personal Data and are retained for up to thirty (30) days before being overwritten.
7. Data Breach Notification
In the event of a Data Breach, Lesuto shall:
- Notify the Controller without undue delay and in any event within seventy-two (72) hours of becoming aware of the Data Breach
- Provide the Controller with sufficient information to enable the Controller to meet any obligations to report or inform Data Subjects of the Data Breach under applicable law
- Take reasonable steps to contain, investigate, and remediate the Data Breach
- Cooperate with the Controller and provide reasonable assistance in relation to any Data Breach investigation, notification, and remediation efforts
- Maintain records of all Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken
Notification shall include, to the extent available: the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.
8. Data Subject Rights
Lesuto shall assist the Controller in fulfilling its obligations to respond to Data Subject requests to exercise their rights under applicable data protection law, including the right of access, rectification, erasure, restriction of processing, data portability, and objection.
If Lesuto receives a request directly from a Data Subject, Lesuto shall promptly forward the request to the Controller and shall not respond to the Data Subject directly unless authorized by the Controller or required by law. Lesuto shall provide reasonable technical and organizational assistance to the Controller in responding to such requests within the timeframes required by applicable law.
9. International Data Transfers
As Lesuto is based in the United States, Personal Data originating from the European Economic Area (EEA), United Kingdom, or Switzerland will be transferred to and processed in the United States. Lesuto relies on the following mechanisms to ensure adequate protection for international data transfers:
- Standard Contractual Clauses (SCCs): Lesuto enters into EU Commission-approved Standard Contractual Clauses with the Controller for transfers of Personal Data from the EEA to the United States. The applicable SCCs (Module Two: Controller to Processor) are incorporated into this DPA by reference.
- UK International Data Transfer Agreement: For transfers from the United Kingdom, the UK Addendum to the EU SCCs applies.
- Supplementary Measures: Lesuto implements encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, audit logging, and data minimization as supplementary technical measures to protect transferred data.
10. Security Measures
Lesuto implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption: All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption.
- Access Controls: Role-based access controls, multi-factor authentication for administrative access, and the principle of least privilege.
- Infrastructure Security: Google Cloud Platform managed infrastructure with SOC 2 Type II and ISO 27001 certifications, automated vulnerability scanning, and DDoS protection via Cloudflare.
- Monitoring: Continuous security monitoring, intrusion detection, audit logging, and alerting.
- Business Continuity: Automated daily backups, disaster recovery procedures, and geographic redundancy.
- Personnel: Security awareness training for all employees with access to Personal Data, background checks, and confidentiality agreements.
- Incident Response: Documented incident response procedures with defined roles, escalation paths, and post-incident review processes.
11. Audits and Inspections
Lesuto shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent auditor mandated by the Controller, subject to reasonable advance notice (at least thirty (30) days) and during normal business hours. Audits shall be conducted no more than once per twelve (12) month period unless required by a supervisory authority or in response to a Data Breach.
12. Term and Termination
This DPA shall remain in effect for the duration of the Principal Agreement. Upon termination of the Principal Agreement, Lesuto shall, at the Controller's election, return or delete all Personal Data processed under this DPA within ninety (90) days, except to the extent that retention is required by applicable law. The Controller may request a copy of all Personal Data in a structured, commonly used, machine-readable format prior to deletion.
13. Governing Law
This DPA shall be governed by the laws of the State of Texas, without regard to its conflict of law provisions. To the extent that the GDPR, UK GDPR, or Swiss FADP applies to the processing of Personal Data under this DPA, the provisions of the applicable data protection law shall prevail in the event of any conflict with this DPA.
14. Contact
For questions about this Data Processing Agreement or to exercise data protection rights, please contact:
Lesuto Technologies, Inc.
600 Congress Ave, STE 1400
Austin, TX 78701
Email: privacy@lesuto.com