Important Note
This template is provided for prospective customer review. It is not binding until incorporated into a signed agreement, order form, or other written contract between Laterite BV and the customer organization.
1. Parties
This Data Processing Agreement ("DPA") forms part of the LateriteAI Terms of Use, order form, or other written agreement between the customer organization ("Controller") and Laterite BV ("Processor").
Laterite BV is registered in the Netherlands, KvK number 69759103, VAT number NL858000118B01. Laterite's address is Herengracht 221, 1016 BG Amsterdam, The Netherlands.
2. Roles
The Controller determines the purposes and means of processing Service Data. Laterite processes Service Data on behalf of the Controller only to provide, secure, support, and administer LateriteAI.
Laterite may act as controller for its own account, billing, security, support, and business administration data. This DPA applies to Laterite's processing of Service Data as processor.
3. Service Data
"Service Data" means chats, prompts, user-uploaded documents, datasets, generated outputs, metadata, support information, and error information submitted to or generated through LateriteAI.
4. Processing Instructions
Laterite will process Service Data only on documented instructions from the Controller, including through users' ordinary use of LateriteAI, unless required by law. If Laterite believes an instruction infringes applicable data protection law, Laterite will inform the Controller unless legally prohibited from doing so.
5. Nature And Purpose Of Processing
Processing may include:
- hosting, storing, transmitting, securing, displaying, retrieving, and deleting Service Data
- processing user requests through the selected LateriteAI application
- generating responses, documents, or outputs requested by authorized users
- providing technical support and investigating errors or security issues
- maintaining audit logs, usage limits, access controls, and billing administration
6. No Training Or Secondary Use
Laterite will not use Service Data to train AI models, fine-tune AI models, improve Laterite workflows, develop benchmarks or datasets, conduct unrelated research, or build unrelated products or services.
Laterite may access Service Data only where needed to provide the Service, respond to support requests, investigate technical or security issues, comply with law, or follow the Controller's instructions.
7. Controller Responsibilities
The Controller is responsible for:
- ensuring Service Data is collected and uploaded lawfully
- providing required notices and obtaining required consents or other legal bases
- ensuring authorized users do not upload data they are not permitted to process
- determining whether sensitive, child, biometric, confidential, regulated, or third-party data may be uploaded
- obtaining any required local approvals, data transfer authorizations, ethics approvals, or regulator registrations
8. Laterite Responsibilities
Laterite will:
- process Service Data only as described in this DPA and the customer agreement
- limit access to personnel who need access to provide the Service
- ensure authorized personnel are bound by confidentiality obligations
- maintain appropriate technical and organizational security measures
- assist the Controller with data subject requests where reasonably possible
- maintain records reasonably necessary to demonstrate compliance with this DPA
9. Security Measures
Laterite will maintain reasonable technical and organizational measures for LateriteAI, including authenticated access, organization-level permissions, role-based controls, private storage, time-limited access links where applicable, audit logging, staff confidentiality obligations, security monitoring, and subprocessors subject to written data protection terms.
10. Subprocessors
Laterite may use subprocessors to provide LateriteAI, including hosting, database, authentication, storage, billing, support, security, and approved AI-processing providers. Current provider categories include Supabase, Vercel, DigitalOcean, Stripe, Slack, Google OAuth, and approved AI providers used by the selected agent.
Laterite will ensure subprocessors are bound by written obligations that are no less protective than this DPA in relation to Service Data. Laterite will make a current subprocessor list available on request or through the website.
11. International Transfers
Where Service Data is transferred internationally, Laterite will use appropriate safeguards required by applicable law, such as adequacy decisions, Standard Contractual Clauses, data processing terms, or other lawful transfer mechanisms.
Where local authorization is required for a transfer, the Controller is responsible for obtaining that authorization, and Laterite will provide reasonable assistance.
12. Deletion And Retention
Chat histories and user-uploaded documents are automatically deleted after 3 months. The Controller or an authorized user may request earlier deletion.
Laterite may retain limited account, billing, security, audit, backup, or dispute-resolution records where required by law or legitimate security and operational needs.
13. Data Subject Requests
Laterite will reasonably assist the Controller in responding to requests for access, correction, deletion, restriction, objection, and portability. If Laterite receives a request directly, Laterite may refer the requester to the Controller unless legally required to respond.
14. Personal Data Breaches
Laterite will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Service Data. Laterite will provide information reasonably available to assist the Controller with any required investigation, mitigation, or notifications.
15. Audits
Laterite will provide information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, confidential, limited to relevant systems and records, and must not compromise the security or confidentiality of Laterite, its systems, or other customers.
16. End Of Service
On termination of the customer agreement, Laterite will delete or return Service Data in accordance with this DPA and the customer agreement, except where retention is required by law or for limited security, billing, audit, backup, or dispute-resolution purposes.