Data Processing Agreement

Data Processing Agreement

Last updated: 19 June 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Use between Lemoniq (“Processor”, “we”, “us”) and the business customer or partner on whose behalf we process personal data (“Controller”, “you”). It applies where we process personal data on your behalf in connection with the Lemoniq website and related online services (the “Service”) and reflects the requirements of Article 28 of the EU General Data Protection Regulation (“GDPR”).

1. Definitions

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. “Customer Personal Data” means personal data contained in the content you submit to the Service that we process on your behalf. “Sub-processor” means any third party engaged by us to process Customer Personal Data.

2. Roles and Scope

For Customer Personal Data, you are the Controller and we are the Processor, processing it solely to provide the Service. For personal data we collect as a controller in our own right (such as analytics and contact data we collect directly from website visitors), our Privacy Policy applies and this DPA does not.

3. Processing Instructions

We process Customer Personal Data only on your documented instructions — including the Terms, this DPA, and your configuration and use of the Service — and as required by applicable law. If we are legally required to process otherwise, we will inform you before doing so unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes data protection law.

4. Confidentiality

We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as instructed.

5. Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Annex C, taking into account the state of the art, the nature of the processing and the rights of data subjects.

6. Sub-processors

You provide general authorisation for us to engage the Sub-processors listed in Annex B. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give you prior notice of any intended addition or replacement of a Sub-processor, and you may object on reasonable data protection grounds.

7. Data Subject Requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the GDPR. If we receive such a request directly, we will refer the data subject to you unless legally required to respond.

8. Assistance

We will assist you, taking into account the nature of the processing and the information available to us, in ensuring compliance with your obligations regarding security, breach notification, data protection impact assessments and prior consultation with Supervisory Authorities (Articles 32 to 36 GDPR).

9. Personal Data Breach

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to us to help you meet your notification obligations.

10. International Transfers

Our website is hosted and published through Framer, which provides hosting within the European Union and the United States. Where personal data is transferred outside the European Economic Area to a Sub-processor, we rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses or the Sub-processor’s certification under the EU-US Data Privacy Framework.

11. Deletion and Return

On termination of the Service, we will, at your choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. You may also export Customer Personal Data for a reasonable period after termination.

12. Audits

We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality and frequency conditions, and to protecting the security and confidentiality of other customers.

13. Liability and Precedence

Liability under this DPA is subject to the limitations of liability in the Terms of Use. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.

14. Governing Law

This DPA is governed by the laws of Romania and, where applicable, the GDPR.

Annex A — Details of the Processing

  • Subject matter: provision of the Lemoniq website and related online services.

  • Duration: for the term of your subscription, plus any post-termination export and deletion period.

  • Nature and purpose: hosting and operation of our website, processing of contact and enquiry form submissions, website analytics, and marketing communications.

  • Types of personal data: identification and contact details submitted through our forms (for example names, email addresses, company and role), and online identifiers such as cookie and device data.

  • Categories of data subjects: website visitors, prospects and business contacts.

Annex B — Sub-processors

Sub-processor

Purpose

Location

Framer

Website hosting and publishing

EU / United States

Google (Analytics, Tag Manager)

Website analytics and tag management

United States

Apollo

B2B contact

United States

Annex C — Technical and Organisational Measures

  • Encryption of data in transit and at rest

  • Role-based access controls and least-privilege access

  • Hosting through Framer’s secure, managed infrastructure

  • Access to website administration restricted to authorised personnel

  • Data minimisation — only data necessary to operate the website is collected

  • Regular backups and recovery procedures

  • Monitoring, logging and breach-response processes

Contact

Lemoniq
Tamasi 20, Buftea, Ilfov, Romania, 070000
Email: hello [at] lemoniq [dot] ai

Get started today

Get started today

From raw idea to formula, audit-ready docs — in one platform, not ten spreadsheets. Book a demo and we'll build your first one live.

From raw idea to formula, audit-ready docs — in one platform, not ten spreadsheets. Book a demo and we'll build your first one live.

Welcome back

What are we formulating today, George?

780

Raw Ingredients

Raw

150

Semi-Finished

Semi

450

Active BOMs

BOMs

8

Drafts Pending

Drafts Pending

Active BOM · Protein Powder · Strawberry

Edit

Formula

Packaging

Claims

Label

Compliance

Transparent image of sand dunes