LLakopStart free

Data Processing Addendum

Last updated August 12, 2026

This Data Processing Addendum forms part of the Terms of Service when Lakop processes personal data on behalf of a merchant. The merchant is “Customer,” Lakop is “Processor,” and capitalized terms have the meanings in applicable data-protection law.

Instructions and purpose

Lakop processes Customer Personal Data only to provide, secure, support, and improve the service under the agreement and Customer’s documented configuration and instructions, unless law requires otherwise. Subject matter includes CRM, commerce, fulfillment, accounting, support, and related operations for the subscription term and limited retention period.

Data and people

Data may include identifiers, contact and shipping details, order and payment-status information, communications, employment or role information, device data, and business records. Data subjects may include Customer’s buyers, prospects, contacts, suppliers, employees, contractors, and authorized users. Customer will not submit prohibited sensitive data identified in the Acceptable Use Policy.

Customer obligations

Customer determines lawful purposes and instructions, provides required notices, obtains required consents, respects data-subject rights, configures access appropriately, and ensures its instructions comply with law. Customer is responsible for source accuracy and deciding retention required for its records.

Confidentiality and security

Lakop ensures personnel with access are bound by confidentiality and applies appropriate technical and organizational measures described in the Security Overview. Lakop will notify Customer without undue delay after confirming a breach of Customer Personal Data and provide information reasonably needed for Customer’s duties.

Subprocessors

Customer generally authorizes subprocessors listed on the Subprocessor List. Lakop will impose materially equivalent data-protection obligations, remain responsible for their performance, and provide advance notice of a new subprocessor through the list or account notice. Customer may object on reasonable data-protection grounds; the parties will seek a practical solution, and Customer may terminate the affected service if none exists.

Rights requests and assessments

Taking account of the processing, Lakop will reasonably assist Customer with verified data-subject requests, security obligations, impact assessments, and regulator consultations. If a person contacts Lakop about Customer-controlled data, we will direct the request to Customer unless prohibited.

Transfers

Customer authorizes processing in the United States and locations used by authorized subprocessors. Where a restricted transfer requires safeguards, the then-current applicable Standard Contractual Clauses are incorporated, with Customer as exporter and Lakop as importer, supplemented as legally required.

Return, deletion, and audit

During the term, Customer may use available exports. After termination, Lakop deletes or de-identifies Customer Personal Data within a commercially reasonable period, except backups cycled under standard retention and records lawfully retained. Retained data remains protected and isolated from routine use.

On reasonable written request, Lakop will provide security documentation needed to demonstrate compliance. Audits use independent reports first, occur no more than annually unless a breach or regulator requires otherwise, protect other customers, and are at Customer’s cost. Requests: privacy@lakop.app.