LiKE Data Processing Agreement
Version 1.3 · Effective date: July 9, 2026 · Last updated: July 9, 2026
Controlling version. This English text is the sole legally binding and controlling version of the DPA. Any translation into another language is provided for convenience and informational purposes only; in the event of any discrepancy, ambiguity, or dispute, this English version prevails and is the sole legally binding text.
This Data Processing Agreement ("DPA") forms part of the LiKE User Agreement between the customer identified in the applicable account ("Customer", "Controller") and Lynkora DOO Beograd, Kneza Miloša 15, 11000 Belgrade, Republic of Serbia (company reg. no. MB 22195689, tax id PIB 115706177) ("Lynkora", "Processor") and applies where Lynkora processes personal data on Customer's behalf.
1. Subject Matter, Duration, Nature and Purpose
Processing of personal data contained in Customer's knowledge base content, user accounts, and related service data, for the purpose of providing the LiKE Service, for the duration of the subscription plus the retrieval and deletion periods set out in the User Agreement.
2. Categories of Data and Data Subjects
- Data subjects: Customer's users; individuals referenced in Customer's content (employees, customers, partners — as determined by Customer).
- Data categories: account data (name, email, role); any personal data Customer includes in content and uploads (including audio, where transcription features are offered). Special categories: not intended; Customer must not upload them without a lawful basis and is solely responsible for determining whether, and on what lawful basis, special-category data may be uploaded (ToS acceptable-use); Lynkora does not screen content.
3. Controller Instructions
Lynkora processes personal data only on documented instructions from Customer, including with regard to international transfers, unless required by EU/Member State/Serbian law (in which case Lynkora informs Customer unless legally prohibited). The User Agreement, this DPA, and Customer's use of Service settings constitute the complete instructions. Lynkora will inform Customer if, in its opinion, an instruction infringes the GDPR. By way of exception to acting only on Customer's instructions, with respect to Content the Customer has made public (public knowledge base, widget, integrations, public AI answers) Lynkora may reactively restrict, disable, or remove access to material it reasonably believes is unlawful or in breach of the User Agreement — upon a substantiated complaint, a rightsholder notice, or an order of a competent authority (notice-and-action) — notifying Customer where practicable, consistent with the User Agreement. This does not make Lynkora the controller of that Content.
4. Confidentiality
Persons authorized to process personal data are bound by confidentiality obligations (contractual or statutory).
5. Security (Art. 32)
Lynkora implements the technical and organizational measures described in Annex II (TOMs). Lynkora may update TOMs provided the level of protection is not materially reduced.
6. Sub-processors
- Customer grants general written authorization to the sub-processors listed in Annex III (published at the Privacy Policy sub-processors table / dedicated page). This authorization is given in electronic form by Customer's click-through acceptance of the User Agreement (recorded with version and timestamp); no wet-ink signature is required — see "Form and acceptance" below (Art. 28(9) GDPR).
- Lynkora will notify Customer at least 30 days before adding or replacing sub-processors (email or in-app). Customer may object on reasonable data-protection grounds; if unresolved, Customer may terminate the affected services and export data.
- Lynkora imposes equivalent data-protection obligations on sub-processors and remains liable for their performance.
7. Data Subject Rights Assistance
Taking into account the nature of processing, Lynkora assists Customer through built-in export, correction, and deletion functions, and by forwarding to Customer without undue delay any data subject request received directly (Lynkora does not respond on the merits — see DSR Procedure). Where a Customer's assistance request is manifestly unfounded or excessive, in particular because of its repetitive character, Lynkora may charge a reasonable fee reflecting the administrative costs, or decline to act on the request.
8. Personal Data Breach
Lynkora notifies Customer without undue delay after becoming aware of a personal data breach affecting Customer's data, with the information required by Art. 33(3) (provided in phases if necessary), and reasonably cooperates with Customer's own notification obligations. Specific notification timeframes, where required, may be agreed in an Order Form or the applicable enterprise agreement.
9. DPIA and Prior Consultation Assistance
Lynkora provides reasonable assistance, using documentation reasonably available to Lynkora (including this DPA and the TOMs), for Customer's data protection impact assessments and prior consultations relating to the Service.
10. Deletion and Return
Upon termination, Customer may export personal data during the retrieval period set out in the User Agreement, which is the single source of truth for its duration. That period is: at least 30 days on ordinary termination or plan downgrade; 60 days during Beta; 60 days where Customer declines material changes to the User Agreement; and at least 60 days for switching under the EU Data Act (Regulation (EU) 2023/2854), where applicable. After the end of the provision of services and the expiry of the applicable retrieval period, Lynkora, at the Controller's choice, deletes or returns the personal data, and thereafter deletes existing copies unless further storage is required by law. Self-service export is available during the retrieval period; upon request, data is returned in a machine-readable format. Backups are deleted per the backup rotation cycle. Deletion certification is available upon request.
11. Audit Rights
Lynkora makes available information reasonably necessary to demonstrate compliance (documentation, security summaries, third-party attestations when available). Audits/inspections: max once per 12 months, 30 days' notice, during business hours, no access to other customers' data, at Customer's expense; remote/documentation-based first. Assistance and information provided beyond eight (8) hours per calendar year — including responses to security questionnaires, vendor assessments, or due-diligence requests beyond Lynkora's standard documentation — may be charged at Lynkora's then-current standard rates.
12. International Transfers
- Customer (EU) → Lynkora (Serbia): the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (SCCs), Module 2, are incorporated by reference; Serbia assessment in TIA.
- Lynkora → US sub-processors: because data is exported from Serbia (not the EU), SCC Module 3 is the primary transfer tool for every US sub-processor (OpenAI — SCC only, not DPF-certified; Resend — SCC Module 3, and is additionally EU-US DPF-certified as supplementary assurance). A TIA is maintained; Annex III lists the mechanism per sub-processor.
As a Serbian entity, Lynkora is also subject to the Serbian Law on Personal Data Protection (ZZPL); transfers from Serbia rely on ZZPL Art. 64 (appropriate safeguards / SCCs). The competent authority is the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik).
The Annexes to this DPA — Annex I (processing details), Annex II (TOMs), and Annex III (sub-processors) — simultaneously constitute the corresponding Annexes to the incorporated SCCs. The identity of the parties and their agreement to the SCCs are as recorded on the Customer's acceptance of the User Agreement (see "Form and acceptance").
13. Liability and Precedence
Liability under this DPA is subject to the limitations of the User Agreement (including €-caps and carve-outs), except where mandatory data protection law provides otherwise. In case of conflict for data-protection matters, this DPA prevails over the User Agreement. In the event of a conflict between the SCCs and this DPA, the SCCs prevail. Disputes under this DPA are resolved under the Dispute Resolution provisions of the User Agreement, except where mandatory data protection law provides otherwise (including data subjects' own statutory rights, which are not affected by this DPA). This DPA is made in English, which is the sole legally binding and controlling text; any translation is provided for convenience and informational purposes only, and in the event of any discrepancy the English version prevails. Data-protection terms of art (e.g., controller, processor, sub-processor, technical and organizational measures) are to be interpreted in accordance with the GDPR.
Customer warranty and indemnity. Customer warrants that it has all necessary rights, consents, and legal bases for the personal data it submits to, or instructs Lynkora to process through, the Service, and that its instructions and Content comply with applicable law. Customer shall indemnify Lynkora against third-party claims and regulatory actions to the extent arising from Customer's unlawful instructions, unlawful Content, or breach of applicable data protection laws by Customer, consistent with, and subject to, the indemnification and liability provisions of the User Agreement.
Form and acceptance. References in this DPA to "in writing", "written", "authorization", or "signature" include electronic form, consistent with Art. 28(9) GDPR; no handwritten (wet-ink) signature is required. This DPA forms part of the User Agreement; it is entered into, and the Customer's general written authorization for sub-processors under the Sub-processors section is given, by the Customer's electronic acceptance of the User Agreement (click-through), which Lynkora records with the document version and timestamp.
14. Notices
Notices and requests under this DPA (sub-processor objections, audit requests, deletion certification) shall be sent to [email protected].
Annex I — Processing Details
This Annex describes the processing carried out by Lynkora as processor on the Controller's behalf. Processing in which Lynkora acts as an independent controller (e.g., account, billing, and marketing data) is described in the Privacy Policy and is outside the scope of this DPA.
| Item | Details |
|---|---|
| Categories of data subjects | The Controller's authorized users; individuals referenced in the Controller's content (e.g., the Controller's employees, customers, partners); visitors to the Controller's public knowledge bases and widget. |
| Categories of personal data | Account data of the Controller's users (email, display name, role, language preferences); any personal data the Controller includes in knowledge-base content and uploads (articles, media, and audio where transcription features are used); usage data generated in the Service (search-query text, user identifier, relevant content fragments); integration identifiers (e.g., Telegram/Slack IDs, SSO subject identifiers; integration tokens stored encrypted). |
| Special categories of data | Not intended. The Controller must not upload special-category data without a lawful basis and is solely responsible for determining whether, and on what basis, it may be uploaded (User Agreement, acceptable-use); Lynkora does not screen content. |
| Nature and purpose of processing | Providing the LiKE knowledge-management Service on the Controller's documented instructions: storage, text extraction, indexing and embedding, semantic search and AI-generated answers, collaboration, and integrations. |
| Duration of processing | For the term of the subscription, plus the retrieval and deletion periods set out in the User Agreement (see §10). |
| Frequency of processing | Continuous, for the duration of the provision of the Service. |
| Sub-processors | As listed in Annex III. |
Annex II — TOMs (Technical and Organizational Measures)
- Encryption: TLS 1.2+ in transit; encrypted backups (WAL-G); secrets in dedicated secrets manager (BWS).
- Tenant isolation: mandatory tenant-scoped query filtering at application layer; cross-tenant access tests in CI.
- Access control: SSH key-only production access; role-based admin access (owner/support); admin actions audit-logged (AdminAuditLog).
- Infrastructure: EU data centers (OVHcloud Frankfurt — application; Gravelines — database); database on isolated host, IP-whitelisted, TLS 1.3.
- Monitoring: server-side logging with secret/PII redaction (
redact_secrets); security event logging. External error monitoring (Sentry) is configured to run withsend_default_pii=Falseand abefore_sendredaction hook, but is currently not activated in production (see Annex III). - Data minimization: AI providers receive only relevant content fragments; PII redaction in logs; log retention limits per Retention Schedule.
- Resilience: daily backups, point-in-time recovery; incident response procedure with a breach-notification workflow.
- Personnel: confidentiality obligations; least-privilege access.
Annex III — Authorized Sub-processors
| Sub-processor | Role | Location | Transfer mechanism |
|---|---|---|---|
| OVHcloud | infrastructure, storage | EU (DE/FR) | in-EEA |
| OpenAI, L.L.C. | LLM API | US | SCC Module 3 (not DPF-certified) |
| Resend | transactional email | US | SCC Module 3 (primary — export from Serbia); additionally EU-US DPF-certified (incl. UK Extension) |
Certification and transfer-mechanism status for each sub-processor is kept current on the sub-processors page referenced in the Privacy Policy; that page is the authoritative, dated source.
Merchant of Record — not a sub-processor. A third-party payment provider acting as Merchant of Record is an independent controller with respect to payment, billing, and tax data: it determines the purposes and means of card processing, VAT/GST calculation, collection and remittance, and fraud prevention under its own compliance obligations (PCI DSS, tax law). It is therefore not a sub-processor under this DPA and is referenced for transparency only; the Merchant of Record is not engaged by Lynkora as a processor or sub-processor. Its processing is governed by its own terms and privacy policy. The specific Merchant of Record is designated when paid billing launches after the beta.
Sentry (error monitoring) is currently not activated in production and is not a sub-processor; upon activation, the sub-processor list will be updated with 30 days' notice.