Last updated: 19 June 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Use between Lemoniq (“Processor”, “we”, “us”) and the business customer or partner on whose behalf we process personal data (“Controller”, “you”). It applies where we process personal data on your behalf in connection with the Lemoniq website and related online services (the “Service”) and reflects the requirements of Article 28 of the EU General Data Protection Regulation (“GDPR”).
1. Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Customer Personal Data” means personal data contained in the content you submit to the Service that we process on your behalf. “Sub-processor” means any third party engaged by us to process Customer Personal Data.
2. Roles and Scope
For Customer Personal Data, you are the Controller and we are the Processor, processing it solely to provide the Service. For personal data we collect as a controller in our own right (such as analytics and contact data we collect directly from website visitors), our Privacy Policy applies and this DPA does not.
3. Processing Instructions
We process Customer Personal Data only on your documented instructions — including the Terms, this DPA, and your configuration and use of the Service — and as required by applicable law. If we are legally required to process otherwise, we will inform you before doing so unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes data protection law.
4. Confidentiality
We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as instructed.
5. Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Annex C, taking into account the state of the art, the nature of the processing and the rights of data subjects.
6. Sub-processors
You provide general authorisation for us to engage the Sub-processors listed in Annex B. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give you prior notice of any intended addition or replacement of a Sub-processor, and you may object on reasonable data protection grounds.
7. Data Subject Requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. If we receive such a request directly, we will refer the data subject to you unless legally required to respond.
8. Assistance
We will assist you, taking into account the nature of the processing and the information available to us, in ensuring compliance with your obligations regarding security, breach notification, data protection impact assessments and prior consultation with Supervisory Authorities (Articles 32 to 36 GDPR).
9. Personal Data Breach
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to us to help you meet your notification obligations.
10. International Transfers
Our website is hosted and published through Framer, which provides hosting within the European Union and the United States. Where personal data is transferred outside the European Economic Area to a Sub-processor, we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses or the Sub-processor’s certification under the EU-US Data Privacy Framework.
11. Deletion and Return
On termination of the Service, we will, at your choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. You may also export Customer Personal Data for a reasonable period after termination.
12. Audits
We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality and frequency conditions, and to protecting the security and confidentiality of other customers.
13. Liability and Precedence
Liability under this DPA is subject to the limitations of liability in the Terms of Use. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.
14. Governing Law
This DPA is governed by the laws of Romania and, where applicable, the GDPR.
Annex A — Details of the Processing
Subject matter: provision of the Lemoniq website and related online services.
Duration: for the term of your subscription, plus any post-termination export and deletion period.
Nature and purpose: hosting and operation of our website, processing of contact and enquiry form submissions, website analytics, and marketing communications.
Types of personal data: identification and contact details submitted through our forms (for example names, email addresses, company and role), and online identifiers such as cookie and device data.
Categories of data subjects: website visitors, prospects and business contacts.
Annex B — Sub-processors
Sub-processor | Purpose | Location |
|---|---|---|
Framer | Website hosting and publishing | EU / United States |
Google (Analytics, Tag Manager) | Website analytics and tag management | United States |
Apollo | B2B contact | United States |
Annex C — Technical and Organisational Measures
Encryption of data in transit and at rest
Role-based access controls and least-privilege access
Hosting through Framer’s secure, managed infrastructure
Access to website administration restricted to authorised personnel
Data minimisation — only data necessary to operate the website is collected
Regular backups and recovery procedures
Monitoring, logging and breach-response processes
Contact
Lemoniq
Tamasi 20, Buftea, Ilfov, Romania, 070000
Email: hello [at] lemoniq [dot] ai
Welcome back
What are we formulating today, George?
