Data Processing Agreement
Last updated: June 5, 2026
1. Definitions
- Controller: You — the entity that determines the purposes and means of processing personal data
- Processor: Lightarch — processes personal data on your behalf
- Personal Information: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data (collection, storage, use, retrieval, deletion)
- Sub-processor: Any third party engaged by Lightarch to process data
- Applicable Data Protection Laws: GDPR, CCPA/CPRA, POPIA, PIPEDA, PDPA, LGPD, and any other applicable laws
2. Scope and Permitted Uses
Lightarch processes Your Data only for the following purposes:
- Ingesting and storing application traces, logs, and metrics
- Executing queries and serving dashboard data
- Delivering alert notifications and anomaly detection
- Maintaining platform infrastructure, reliability, and security
- Technical support when explicitly requested by you
Lightarch will not:
- Use Your Data for marketing or advertising purposes
- Share Your Data with third parties except authorised sub-processors
- Sell or rent Your Data
- Process Your Data for any purpose other than providing the Service
3. Controller Obligations
As Controller, you warrant and represent that:
- You have a lawful basis for submitting personal data to the Service
- You have provided appropriate privacy notices to data subjects
- You will not submit special category data (health, biometric, etc.) without explicit consent
- You will ensure your use of the Service complies with Applicable Data Protection Laws
- You will promptly notify Lightarch of any suspected breach
4. Security Measures
Technical Measures
- TLS 1.2+ encryption for all data in transit
- Cloudflare R2 server-side encryption for data at rest
- Per-tenant database isolation (dedicated D1 and R2 per customer)
- PBKDF2 password hashing with unique salts
- DSN token-based ingest authentication with rotation capability
Organisational Measures
- Role-based access control (Owner, Admin, Member, Viewer)
- Audit logging of data access events
- Staff training on data protection obligations
- Incident response procedure for data breaches
5. Sub-processors
Lightarch authorises the following sub-processors:
- Cloudflare, Inc.: Infrastructure (compute, storage, edge network) — US, global
- Lemon Squeezy: Payment processing — global
- Resend: Transactional email delivery — global
We will notify you 30 days in advance of any new or changed sub-processor. You may object in writing within 15 days; if we cannot address your objection, you may terminate the Agreement.
6. Data Subject Rights
Lightarch will assist you in fulfilling data subject requests (access, rectification, erasure, portability, objection) within the timeframes required by Applicable Data Protection Laws. Contact [email protected] with any request.
7. Breach Notification
- Lightarch will notify you within 24 hours of discovering a personal data breach
- Notification will include the nature of the breach, categories of data affected, and remediation steps
- We will cooperate with relevant supervisory authorities as required by law
- You are responsible for notifying data subjects and authorities where required
8. International Data Transfers
Where Your Data is transferred outside your jurisdiction, Lightarch relies on:
- EU Standard Contractual Clauses (SCCs) for GDPR-covered transfers
- UK International Data Transfer Agreements where applicable
- Cloudflare's Data Localisation Suite for Enterprise customers requiring data residency
9. Audit Rights
Upon 30 days' written notice, you may audit (or appoint an independent auditor to audit) Lightarch's compliance with this DPA, no more than once per 12-month period. Lightarch may provide a SOC 2 Type II report in lieu of an on-site audit.
10. Termination
Upon termination of the Agreement, Lightarch will delete Your Data from hot storage within 30 days. Cold storage data in your R2 bucket remains under your control.
Questions about this policy?
Email[email protected]
Websitelightarch.io