Data Processing Agreement
Last updated: 1 August 2026 · Version 2026-08-01
pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)
Parties
Lime Lift BV, a company incorporated under Belgian law with enterprise number BE 1021.859.168 and registered office at Bredabaan 342, 2170 Antwerpen, Belgium, operator of the LimeliJourney platform (“Lime Lift”, “we”, the “Processor”);
and
the Customer identified in the signature block and in the Order or onboarding confirmation for the LimeliJourney service (the “Customer”, “you”, the “Controller”).
Each a “Party” and together the “Parties”.
Background
A. The Parties have entered into an agreement for the Customer’s use of the LimeliJourney service — the Terms of Service together with any signed Order or onboarding confirmation (the “Agreement”).
B. In performing the Agreement, Lime Lift processes personal data on the Customer’s behalf. For that data the Customer is the controller and Lime Lift is the processor, as stated in Terms of Service §7 and Privacy Policy §4.
C. Article 28(3) GDPR requires that such processing be governed by a contract setting out the subject-matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects, and the obligations and rights of the controller. This Data Processing Agreement (the “DPA”) is that contract.
D. This DPA covers only the personal data the Customer tracks or otherwise submits through the platform, for which Lime Lift acts as processor (Privacy Policy §4). It does not cover the account, billing, security, support and administration data for which Lime Lift is itself the controller (Privacy Policy §§2–3); that data is governed by the Privacy Policy.
The Parties agree as follows.
1. Definitions
1.1 Terms in bold defined in the GDPR — including “personal data”, “processing”, “controller”, “processor”, “sub-processor”, “data subject”, “personal data breach” and “supervisory authority” — have the meanings given in the GDPR.
1.2 “Customer Personal Data” means the personal data described in Annex 1 that Lime Lift processes on the Customer’s behalf under the Agreement.
1.3 “Data Protection Law” means the GDPR and any other data-protection or privacy law applicable to the processing, including the UK GDPR and applicable United States state privacy laws.
1.4 “Sub-processor” means any processor engaged by Lime Lift to process Customer Personal Data on the Customer’s behalf.
1.5 Capitalised terms not defined here have the meaning given in the Agreement.
2. Subject-matter and details of processing
2.1 Lime Lift shall process Customer Personal Data only as a processor, for the purpose of providing the LimeliJourney service (tracking, attribution, affiliate-program management, reporting, platform email and AI features) as described in the Agreement.
2.2 The subject-matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of data subjects are set out in Annex 1.
2.3 The duration of the processing is the term of the Agreement, followed by the return or deletion period in section 10.
3. Roles and scope
3.1 The Customer is the controller of Customer Personal Data and Lime Lift is the processor. Where the Customer is itself a processor acting for a third-party controller, Lime Lift is a sub-processor and the Customer warrants it has authority to engage Lime Lift on these terms.
3.2 The Customer is responsible for the lawfulness of the Customer Personal Data and of its collection, including having a valid legal basis and any consent required in the data subjects’ jurisdictions (Terms of Service §3). The Customer warrants that its documented instructions comply with Data Protection Law.
3.3 United States state privacy laws. Where such laws apply to Customer Personal Data, Lime Lift acts as the Customer’s “service provider” or “processor” as defined in those laws and as further set out in the US State Privacy Addendum (Annex 4), which applies in addition to this DPA for such data.
4. Processor’s obligations
Lime Lift shall:
4.1 Instructions. Process Customer Personal Data only on the Customer’s documented instructions, including as to international transfers, unless required to process by Union or Member State law — in which case Lime Lift will inform the Customer of that requirement before processing, unless the law prohibits it. The Agreement, this DPA and the Customer’s use of the service’s configuration and features are the Customer’s complete and final documented instructions. Lime Lift will inform the Customer if, in its opinion, an instruction infringes Data Protection Law (it is not obliged to give legal advice).
4.2 Confidentiality. Ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality and have received appropriate data-protection guidance. Access within a workspace is limited to what is necessary and can be scoped by role.
4.3 Security. Implement and maintain the technical and organisational measures required by Article 32 GDPR, as described in Annex 3. Lime Lift may update these measures provided the overall level of protection is not materially reduced.
4.4 Sub-processors. Engage Sub-processors only in accordance with section 5.
4.5 Assistance with data-subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests to exercise data-subject rights under Chapter III GDPR. Where a data subject sends such a request directly to Lime Lift, Lime Lift will not respond on the Customer’s behalf but will, without undue delay, forward it to the Customer and support the Customer in responding. End users of a site tracked by a customer are directed to that customer (Privacy Policy §9).
4.6 Assistance with compliance. Taking into account the nature of processing and the information available to it, assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, data-protection impact assessments and prior consultation).
4.7 Breach notification. Notify the affected Customer’s designated privacy or security contact and its workspace administrators without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. To the extent reasonably available, the notification will describe: (a) the nature of the breach; (b) the categories and approximate number of affected data subjects and records; (c) the likely consequences; (d) the measures taken or proposed to address and mitigate it; and (e) a contact point for further information. Where all information is not available at once, Lime Lift may provide it in phases without undue further delay. This assists the Customer’s own obligations under Articles 33–34 GDPR and is not an acknowledgement of fault.
4.8 Records. Maintain a record of the categories of processing carried out on the Customer’s behalf, as required by Article 30(2) GDPR.
4.9 Demonstrating compliance. Make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allow for and contribute to audits in accordance with section 8.
4.10 Privileged support and administrative access. The Customer instructs and authorises Lime Lift to access Customer Personal Data where reasonably necessary to provide, maintain, secure, support and troubleshoot the service, investigate technical or security incidents, restore service availability, or carry out the Customer’s documented requests. Lime Lift shall ensure that such access: (a) is limited to authorised personnel with a legitimate operational need; (b) is carried out using individually assigned administrative identities and appropriate authentication controls; (c) is subject to confidentiality obligations; (d) is limited to the minimum data and functionality reasonably necessary for the relevant purpose; (e) is logged so that Lime Lift can identify the authorised person, the workspace accessed, the time of access and the relevant operational purpose; and (f) does not permit Customer Personal Data to be used for Lime Lift’s own unrelated purposes.
5. Sub-processors
5.1 General authorisation. The Customer gives Lime Lift general written authorisation to engage Sub-processors to process Customer Personal Data. The Sub-processors engaged as at the effective date are listed in Annex 2, consistent with Privacy Policy §11.
5.2 Flow-down. Lime Lift will impose on each Sub-processor, by contract, the same data-protection obligations as those imposed on Lime Lift under this DPA, to the extent applicable to the Sub-processor’s services, in particular appropriate Article 32 security measures. Lime Lift remains fully liable to the Customer for a Sub-processor’s performance of those obligations.
5.3 Notice and objection. Lime Lift will give at least 15 days’ prior written notice to the Customer’s workspace administrators before authorising a new or replacement Sub-processor, except where an urgent replacement is reasonably necessary for security, continuity or legal compliance (in which case notice is given as soon as practicable). The Customer must submit any objection within that notice period, on reasonable, documented data-protection grounds. The Parties will work in good faith to resolve the objection; while it is under review Lime Lift will not begin transferring the Customer’s data to the objected-to Sub-processor unless an urgent-replacement ground applies. If the objection cannot be resolved, the Customer may, as its sole remedy, terminate the affected part of the service by notice, with a pro-rata refund of any prepaid fees for the terminated part.
5.4 Independent controllers are not Sub-processors. Recipients that determine their own purposes and means of processing act as independent controllers and are not Sub-processors under this DPA. In particular, Stripe Payments Europe, Limited processes payment data as an independent controller (Privacy Policy §5) and receives only billing-contact and payment details — never Customer Personal Data or workspace/tracking data.
6. Data location and residency
6.1 The Customer’s primary workspace database, uploaded assets and stored tracking data are hosted in the workspace’s selected AWS region. Certain service components — including platform email delivery, AI inference, security monitoring, support operations and service metadata — may be processed in the additional locations identified in Annex 2.
6.2 The workspace region is selected when the workspace is created. The default region is the United States (US West, Oregon); European customers may request EU data residency at onboarding, in which case the workspace and the components that support in-region residency are provisioned accordingly (Terms of Service §7; Privacy Policy §6). The residency region is not changed without the Customer’s instruction.
7. International transfers
7.1 Each transfer of Customer Personal Data to a country outside the EEA that is not recognised as providing an adequate level of protection is made under an applicable transfer mechanism under Chapter V GDPR (an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognised safeguard) (Privacy Policy §6).
7.2 Onward transfers by Lime Lift. Where Lime Lift transfers Customer Personal Data to a Sub-processor in a country outside the EEA that has not been recognised as adequate, Lime Lift shall ensure the transfer is subject to an applicable Chapter V mechanism. This may include the Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, using Module Three where Lime Lift acts as processor and the recipient acts as Sub-processor.
7.3 AWS transfers. Where Amazon Web Services processes Customer Personal Data outside the EEA, the transfer safeguards in the AWS Data Processing Addendum — including the applicable Standard Contractual Clauses, and AWS’s participation in the EU–US Data Privacy Framework — apply.
7.4 Transfers between the Parties. If a transfer mechanism is legally required for a transfer directly between the Customer and Lime Lift, the Parties shall enter into or incorporate the appropriate transfer terms for their respective roles and the relevant jurisdiction.
8. Audits
8.1 Lime Lift will make available the information reasonably necessary to demonstrate compliance with this DPA, which may include up-to-date third-party certifications, audit reports, or the compliance documentation of its Sub-processors (such as AWS’s reports).
8.2 Where that information is insufficient, the Customer (or an independent auditor it mandates, who is not a competitor of Lime Lift and is bound by confidentiality) may audit Lime Lift’s compliance no more than once per twelve months, on at least 30 days’ written notice, during business hours, without unreasonably disrupting Lime Lift’s operations, and subject to confidentiality. Each Party bears its own audit costs.
8.3 Exceptions. The frequency and notice restrictions in 8.2 do not apply where an audit is reasonably required following a personal data breach, credible evidence of material non-compliance, or a request from a competent supervisory authority.
9. Personal data breach
Section 4.7 governs breach notification. The Parties will cooperate in good faith to investigate and remediate a personal data breach and to keep records of it.
10. Return or deletion on termination
10.1 On expiry or termination of the Agreement, Lime Lift shall, at the Customer’s choice, return or delete Customer Personal Data, unless applicable Union or Member State law requires its retention. The Customer may request a commercially reasonable, machine-readable export during the subscription and for 30 days following termination. If the Customer does not provide another instruction within that period, Lime Lift may delete the Customer Personal Data (Terms of Service §6; Privacy Policy §8).
10.2 Backups. Customer Personal Data remaining in backups will be isolated from active use, will not be actively processed except where necessary for security or recovery, and will be deleted in accordance with Lime Lift’s normal backup-retention cycle, which does not exceed 35 days (Terms of Service §7; Privacy Policy §8).
10.3 Retention during the term. While the subscription is active, raw event-level records (individual clicks, impressions and similar events) may be archived or deleted once older than 12 months, with at least 30 days’ notice to workspace administrators before any such retention schedule takes effect. Conversion-pixel and postback attempt logs (the Pixel Log) are retained for 90 days, after which individual attempt entries are deleted; the resulting conversions and their attribution remain unaffected. Conversions, payout-bearing events and aggregated reporting remain for the life of the subscription (Terms of Service §7; Privacy Policy §8).
11. Liability
11.1 Each Party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement (Terms of Service §12). This DPA does not increase either Party’s aggregate liability beyond those limits, except where Data Protection Law does not permit such a limit.
12. Governing law, precedence and general
12.1 Governing law and forum. This DPA is governed by Belgian law. Disputes are subject to the exclusive jurisdiction of the competent courts of the district where Lime Lift BV has its registered office (currently Antwerp, Belgium), consistent with Terms of Service §14. Where the EU Standard Contractual Clauses apply to a transfer, their own governing-law and forum terms apply to that transfer.
12.2 Precedence. This DPA forms part of the Agreement. In the event of a conflict on the processing of Customer Personal Data, this DPA prevails over the rest of the Agreement; on all other matters the Agreement prevails. Where the EU Standard Contractual Clauses apply, they prevail over this DPA as to the transfer they govern.
12.3 Changes. Lime Lift may update its Sub-processor list (Annex 2) and its technical and organisational measures (Annex 3) in accordance with this DPA, provided the overall level of protection is not materially reduced. Amendments to the Parties’ material rights or obligations under this DPA require written agreement, except where an amendment is strictly necessary to comply with applicable Data Protection Law. Material changes are notified to workspace administrators (Terms of Service §16; Privacy Policy §12).
12.4 Severability and survival. If a provision is found invalid, the rest remains in effect. Provisions that by their nature should survive termination (including sections 10–12 and Annex 4) survive.
12.5 Entire agreement on processing. This DPA, together with the Agreement, is the Parties’ entire agreement on the processing of Customer Personal Data and supersedes any prior data-processing appointment between them for the same processing.
Signatures and contract details
This DPA is signed electronically by the Customer through the LimeliJourney onboarding flow, or accepted through and incorporated into the Order/onboarding confirmation.
Contract details:
| Processor | Lime Lift BV |
|---|---|
| Registered address | Bredabaan 342, 2170 Antwerpen, Belgium |
| Company / registration number | BE 1021.859.168 |
| Privacy / security contact | hello@limelijourney.com |
| Notice email | hello@limelijourney.com |
| Customer | the full legal name, registered address, and signatory captured at signing |
Electronic signature: the Parties agree that this DPA may be executed electronically and that an electronic signature or acceptance through the Order has the same effect as a handwritten signature.
Annex 1 — Details of the Processing
Roles. Customer = controller; Lime Lift BV = processor. (Where the Customer is itself a processor for a third-party controller, Lime Lift is a sub-processor.)
Subject-matter. Provision of the LimeliJourney affiliate-tracking and attribution service under the Agreement.
Duration. The term of the Agreement, plus the return/deletion period in section 10.
Nature and purpose of the processing. Collecting, storing, organising, structuring, analysing, transmitting and reporting on marketing-interaction and related data to provide tracking, attribution, affiliate-program management (offers, campaigns, creatives, payouts, caps), reporting, an affiliate portal, platform email sending, and AI features (LimeliChat and the AI Creative Studio), on the Customer’s documented instructions.
Types of Customer Personal Data.
- Tracking and attribution data: clicks, impressions, leads, conversions and associated attribution data, including online identifiers such as click IDs, sub-IDs, IP addresses and IP-derived metadata, device/browser/request information, and cookie identifiers set on the Customer’s own domain.
- Affiliate and advertiser data: contact details of the affiliates and advertisers the Customer manages (names, email addresses, business contact details) and affiliate payment and payout records the Customer maintains.
- Communications data: email recipient names and addresses, subject lines and message content, and delivery, bounce and complaint information for platform email sent on the Customer’s instructions.
- AI data: prompts, instructions and conversation content submitted to, and outputs generated by, the AI features on the Customer’s instructions.
- Uploaded content: creatives, images and documents the Customer uploads.
- Other workspace content: any other personal data the Customer chooses to place in fields, custom fields, event payloads, or support/operational content within its workspace.
Restricted / prohibited data. The platform is not designed or approved for, and the Customer shall not submit through it, special-category personal data (Article 9 GDPR), criminal-conviction or offence data (Article 10 GDPR), medical or health data, payment-card credentials, authentication secrets or passwords, government identification documents, data relating to children, or other highly sensitive data — unless Lime Lift has expressly agreed in writing that the relevant feature is designed and approved for that processing.
Categories of data subjects.
- End users / visitors and leads whose marketing interactions the Customer tracks.
- The Customer’s affiliates and advertisers (and their contacts) managed in the workspace.
- Recipients of platform email sent on the Customer’s instructions.
Frequency of processing. Continuous, for the term of the Agreement.
Annex 2 — Sub-processors and processing locations
Authorised Sub-processor
| Sub-processor | Purpose | Transfer safeguard |
|---|---|---|
| Amazon Web Services EMEA SARL / Amazon Web Services, Inc. | Hosting, storage, platform email (Amazon SES) and AI inference (Amazon Bedrock, within Lime Lift’s AWS account) | AWS Data Processing Addendum incorporating the applicable EU Standard Contractual Clauses; AWS participates in the EU–US Data Privacy Framework |
Processing locations, by component (for the default US workspace; an EU-residency workspace is provisioned in an EU region with EU-region equivalents of these components):
| Component | Location (US default workspace) |
|---|---|
| Primary workspace hosting (database, uploaded assets, stored tracking data) | AWS US West (Oregon), us-west-2 |
| Platform email sending (Amazon SES) | AWS US West (Oregon), us-west-2 |
| Email bounce/complaint processing | AWS US West (Oregon), us-west-2 |
| AI inference (Amazon Bedrock) | US cross-region inference profile — processed within AWS US regions; data does not leave the US geography |
| Automated database backups | AWS US West (Oregon), us-west-2 |
| Administrative and support access | By Lime Lift personnel from Belgium (EU), via secured access to the above |
For a US-region workspace, Customer Personal Data — including platform email content and AI inference — is processed within the United States. EU-residency workspaces are provisioned so that primary content and the corresponding email and AI-inference components remain in the EU; Lime Lift does not use a global AI inference profile for a workspace promised EU-only processing.
Not a Sub-processor (independent controller): Stripe Payments Europe, Limited (Dublin, Ireland) processes subscription payment data as an independent controller. It receives billing-contact and payment details only, and never receives Customer Personal Data or workspace/tracking data. Listed for transparency, consistent with Privacy Policy §§5 and 11.
Lime Lift gives at least 15 days’ prior notice to workspace administrators before adding or replacing a Sub-processor (section 5.3).
Annex 3 — Technical and Organisational Measures (Article 32)
Lime Lift maintains, and keeps under review, technical and organisational measures appropriate to the risk, including the following. (These describe Lime Lift’s current measures and may be updated provided the overall level of protection is not materially reduced.)
- Tenant isolation. The platform is multi-tenant. Access controls are designed and implemented to prevent unauthorised cross-tenant access: every tenant-scoped record carries a tenant identifier and access is scoped to the authenticated tenant.
- Encryption. Customer Personal Data is encrypted in transit (TLS) and at rest.
- Access control. Authentication through Amazon Cognito with per-tenant, per-role logins; multi-factor authentication available to customer users; least-privilege roles within a workspace; least-privilege IAM for infrastructure; multi-factor authentication required for Lime Lift production-administrator access; periodic review of privileged access; platform secrets held in AWS Secrets Manager rather than in code.
- Privileged-access controls. Privileged access to customer workspaces is restricted by role and granted only to authorised personnel. Administrative personnel use individually assigned accounts protected by multi-factor authentication. Cross-workspace access and support-impersonation events are recorded in security or audit logs. Shared administrator credentials are prohibited, and privileged-access rights are reviewed periodically.
- Confidentiality of personnel. Access to production data is limited to authorised personnel bound by confidentiality and granted on a need-to-know basis.
- Logging and monitoring. Audit and security logging of administrative and security-relevant actions, with access to logs restricted and monitored. Logging is configured to minimise the inclusion of Customer Personal Data; sensitive fields are masked, redacted or excluded where reasonably practicable.
- Vulnerability, patch and dependency management. Lime Lift monitors for security vulnerabilities in its infrastructure and dependencies and applies security patches on a risk-prioritised basis.
- Secure development and change management. Infrastructure is managed as code and changes are reviewed; database schema changes are applied through versioned migrations designed to be reversible; security is considered before major releases.
- Resilience, backup and recovery. Managed, encrypted database with automated backups and point-in-time recovery, and documented disaster-recovery procedures.
- Incident response. Documented procedures for detecting, responding to and recording security incidents and personal data breaches (section 4.7).
- Key management. Encryption keys are managed using AWS key-management services with restricted access.
- Secure disposal. Customer Personal Data is deleted or rendered inaccessible at end of life in accordance with section 10.
- Data residency. Workspace primary content is kept in the workspace’s selected AWS region (Annex 2; section 6).
Annex 4 — US State Privacy Addendum
This Addendum applies where US state privacy laws (such as the California Consumer Privacy Act as amended by the CPRA, and comparable state laws) apply to Customer Personal Data. Terms used here have the meanings given in the applicable state law.
1. Roles. The Customer is the “business” (or controller) and Lime Lift is the “service provider” / “processor” with respect to Customer Personal Data.
2. Limited purpose. Lime Lift processes Customer Personal Data only to perform the services under the Agreement (the “business purpose”), and not for any other purpose.
3. No sale / no share. Lime Lift does not “sell” or “share” Customer Personal Data, and does not retain, use or disclose it outside the direct business relationship or for any purpose other than the services, except as permitted by applicable law.
4. No combining. Lime Lift does not combine Customer Personal Data with personal information from other sources, except as permitted by applicable law for a service provider.
5. Notice of inability to comply. Lime Lift will notify the Customer if it determines it can no longer meet its obligations under the applicable law, and the Customer may take reasonable steps to stop and remediate unauthorised processing.
6. Assistance and rights. Lime Lift assists the Customer in responding to verifiable consumer requests, consistent with section 4.5.
7. Subcontractors. Lime Lift engages Sub-processors as “service providers”/“contractors” under written terms consistent with this Addendum (section 5).
8. Precedence. For Customer Personal Data subject to US state privacy law, this Addendum controls over any conflicting term of the DPA or Agreement to the extent required by that law.