Laudia

Data Processing Agreement

Last updated

This Data Processing Agreement (DPA) applies when Laudia processes personal data on your behalf as part of a paid subscription. It forms part of our Terms of Service for those subscriptions, automatically and without a signature; if you need a countersigned copy for your records, write to hi@laudia.ai.

Parties and roles

You, the subscribing business, are the controller of the personal data described below. BlockNovum GmbH (Swiss limited liability company), Josefstrasse 112, 8005 Zürich, Switzerland, operating as Laudia, is your processor. This DPA is made under Art. 28 EU GDPR and the Swiss revFADP.

What we process for you, and for how long

Depending on what you connect and enter, we process on your behalf:

  • Brand profile details you provide, which can include personal data such as the name of the person your brand is built around and your business address.
  • Access credentials for the site or store you connect, stored encrypted and used only to publish the fixes you approve.
  • Aggregated daily traffic figures from an analytics property you connect (visit counts by source and day). We do not receive or store your visitors' personal data.
  • The content of fixes you approve for publication on your own site.

The free Laudia Score needs none of this: it works only on your public website and public AI answers, and the service is deliberately designed never to need your customers' or patients' personal data. Processing lasts for the duration of your subscription. On termination, and at your choice, we return or delete the personal data we process for you, within 30 days of your request and in any event within 90 days of termination; copies held in routine encrypted backups, if any, are deleted in the ordinary backup cycle and remain subject to this DPA until then. We may retain data where the law requires it.

Our obligations

  • We process this data only to provide the subscribed service and on your documented instructions, never for our own purposes, except that we may use data in aggregated and anonymised form that does not identify you or any individual, as described in our Terms of Service.
  • We will tell you if, in our opinion, an instruction infringes data-protection law.
  • Everyone with access is bound to confidentiality.
  • We take appropriate technical and organisational measures, currently including encryption in transit, tenant isolation enforced in the database, restricted access, and expiring, unguessable report links. These are our current measures; we may update them provided the level of protection is not reduced.
  • We assist you, in a reasonable way, in answering data-subject requests and meeting your own data-protection duties.
  • If a personal-data breach affects data we process for you, we inform you without undue delay.

Your responsibilities

You warrant that you have a lawful basis for the processing you instruct, that you have given any notices and obtained any consents required, and that your instructions comply with data-protection law. You will indemnify us against claims arising from your breach of this warranty.

Subprocessors

You authorise the service providers listed in the subprocessor table of our Privacy Policy, which we keep current. When we add or replace a subprocessor that touches data we process for you, we update that table at least 30 days in advance and notify subscribers by email; if you object on reasonable data-protection grounds, you can end the subscription before the change takes effect.

One provider deserves plain words: to draft content for your brand, the profile facts you enter can be included in our requests to the AI provider we use for drafting, currently Anthropic, under business API terms that restrict it from using your data for its own purposes. The other AI assistants we measure receive only your public brand name and domain. If you prefer not to enter a person's name in your profile, the service works without it.

Audits and information

We provide the information reasonably necessary to demonstrate compliance with this DPA on request, starting with any certifications or summaries we hold. Where that is not sufficient and you are required to audit us, you may audit us, or have a mutually agreed independent auditor bound to confidentiality do so, no more than once in any twelve-month period, on 30 days' written notice, during business hours, without unreasonable disruption to our operations, and at your cost, except where the audit reveals a material breach of this DPA by us.

International transfers

Your data is stored in Switzerland, which the EU recognizes as providing adequate protection. Where a listed subprocessor processes data outside Switzerland or the EU/EEA, the transfer is covered by the EU Standard Contractual Clauses or an equivalent safeguard.

Liability

Each party's liability under this DPA is subject to the limitations and exclusions in our Terms of Service, to the extent the law permits. Nothing here affects a data subject's rights under Art. 82 GDPR.

Questions

For anything about this DPA, write to hi@laudia.ai.