Lyberty
PLATFORMINDUSTRIESMANIFESTOPRICING
LOG IN
PLATFORMINDUSTRIESMANIFESTOPRICING
LOG IN
Lyberty/Legal

Data Processing Agreement (DPA)

Effective
May 8, 2026
Last updated
May 12, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Lyberty Labs FZCO d/b/a Lyberty ("Lyberty," "Processor," "we," "us") and the customer entity that accepts or is party to that agreement ("Customer," "Controller," "you"). This DPA governs Lyberty's processing of Customer Personal Data in connection with the Services and applies to the extent Applicable Data Protection Laws apply to that processing. This DPA does not require execution to be effective; if Customer requires a counter-signed copy, contact privacy@lyberty.ai.

1. Definitions

  • Applicable Data Protection Laws means data protection, privacy, electronic communications, and similar laws applicable to a party's processing under this DPA, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), other US state privacy laws (CO, CT, UT, VA, TX, OR, etc.), the UAE Personal Data Protection Law (PDPL), and any successor or equivalent laws.
  • Controller, Processor, Personal Data, Processing, Special Categories of Personal Data, Personal Data Breach, Data Subject, Sub-processor, Standard Contractual Clauses, "Sale," and "Sharing" have the meanings given in the relevant Applicable Data Protection Laws.
  • Customer Personal Data means Personal Data processed by Lyberty on behalf of Customer under Customer's instructions through the Services.
  • Service Data means data Lyberty processes as an independent controller for account administration, billing, security, service telemetry, product improvement, support, and legal compliance, as described in the Privacy Policy. Service Data does not include Customer Content except to the limited extent Customer Content is incidentally reflected in logs, support tickets, security records, or telemetry necessary for those purposes.
  • Sub-processor means a processor engaged by Lyberty to process Customer Personal Data on Customer's behalf.
  • Lyberty Written Authorization has the meaning given in the Terms. Restricted Data, children's data, HIPAA/PHI processing, biometric identification data, and high-risk AI use require a signed addendum, order form, business associate agreement, DPA exhibit, or other executed agreement; ordinary email approval, chat responses, AI-generated responses, documentation, product UI text, automated messages, sales statements, and support suggestions are not sufficient.
  • EU SCCs means the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • UK Addendum means the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 (or successor) issued by the UK Information Commissioner.

Capitalized terms not defined here have the meanings in the agreement or the Applicable Data Protection Laws.

2. Roles, scope, and instructions

2.1 Roles

Customer is the Controller (or a Processor acting on behalf of another Controller). Lyberty is the Processor (or Sub-processor). Each party will comply with its own obligations under Applicable Data Protection Laws.

2.2 Documented instructions

Lyberty will Process Customer Personal Data only on Customer's documented instructions, including instructions in the agreement, this DPA, product configuration, APIs, dashboards, support requests, and customer-authorized workflows, and as required by applicable law. If Lyberty is required by law to process beyond Customer's instructions, Lyberty will inform Customer of that legal requirement before processing unless prohibited by law.

2.3 Suspension on unlawful instruction

If Lyberty reasonably believes an instruction violates Applicable Data Protection Laws or creates material security risk, Lyberty may notify Customer and suspend the affected processing until resolved.

2.4 Independent controller activities

Lyberty processes Service Data as an independent controller. The Privacy Policy describes that processing. Where the same data element is processed both as Customer Personal Data and Service Data, Lyberty processes it in each role only for the corresponding purposes and legal bases. Lyberty will not use Service Data to identify or profile Customer's end users for Lyberty's own advertising purposes.

3. Nature, purpose, and duration

Lyberty processes Customer Personal Data to provide, secure, support, and improve the Services, including execution graph records, integrations, sites, first-party tracking, analytics, experiments, workflows, approvals, artifacts, AI-assisted features, agent runtime actions, publishing, synchronization, support, troubleshooting, and compliance. "Improve the Services" means using Customer Personal Data and Customer Content only to maintain, debug, secure, operate, measure, and enhance the functionality, reliability, safety, performance, and user experience of the Services for Customer and similarly situated customers. It does not include training, fine-tuning, or otherwise improving general-purpose AI models or foundation models for use by other customers, unless Customer expressly opts in under a separate written agreement. Processing continues for the term of the agreement and any post-termination retention, deletion, audit, backup, or legal period described in the agreement, this DPA, the Privacy Policy, or customer configuration.

Lyberty may use aggregated or de-identified telemetry derived from use of the Services for analytics, benchmarking, reliability, security, capacity planning, and product development, provided such data does not identify Customer, Customer's users, or any individual and is not reasonably capable of re-identification.

Lyberty personnel will not access Customer Content except as necessary to provide support requested by Customer, investigate security or abuse issues, comply with law, maintain the Services, or as otherwise authorized by Customer. Access is logged and limited to personnel with a need to know.

4. Categories of data and Data Subjects

Customer Personal Data may include account identifiers and workspace data; integration credentials and connected objects; data from customer-connected advertising, analytics, commerce, CRM, finance, content, search, support, productivity, storage, and development systems; first-party site, SDK, and event data; Customer Content, including artifacts, files, documents, spreadsheets, briefs, prompts, messages, attachments, AI inputs and outputs, workflow records, graph records, approvals, and revisions; and support, diagnostic, telemetry, and operational records generated through Customer's use of the Services.

Special Categories of Personal Data, children's data, biometric data used for identification, health data, payment-card numbers, financial-account credentials, full government-issued identifiers, and other highly regulated data are not intended for the Services and must not be submitted unless covered by Lyberty Written Authorization in a signed addendum, order form, business associate agreement, DPA exhibit, or other executed agreement. Lyberty may use automated and manual controls designed to detect, block, quarantine, or remove Restricted Data, but Lyberty does not guarantee detection of all Restricted Data. Any Lyberty Written Authorization to process Restricted Data must identify the data categories, safeguards, retention period, permitted processing, subprocessor restrictions, and any additional compliance terms.

Data Subjects may include Customer personnel, users, prospects, customers, website visitors, contacts, counterparties, and individuals reflected in Customer's connected systems, sites, content, or workflows.

5. Processor obligations

Lyberty will:

(a) Process Customer Personal Data only on Customer's documented instructions and as permitted by Applicable Data Protection Laws; (b) ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and have received privacy and security training proportionate to their role; (c) implement and maintain the technical and organizational measures described in Annex II, designed to ensure a level of security appropriate to the risk; (d) engage Sub-processors only under written obligations materially equivalent to this DPA and remain liable for Sub-processors' performance to the same extent as if Lyberty itself performed the processing; (e) provide reasonable assistance to Customer (taking into account the nature of the processing and information available to Lyberty) with: (i) responses to Data Subject requests, (ii) data protection impact assessments and prior consultations under GDPR Articles 35–36, (iii) security obligations under GDPR Article 32, and (iv) Personal Data Breach notifications under Articles 33–34; (f) notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a Personal Data Breach involving Customer Personal Data. Lyberty's notification may be preliminary and will include information reasonably available at the time, with further information provided as it becomes available. A notification is not an admission of fault or liability; (g) on termination of the agreement or upon Customer's valid written request, delete or return all Customer Personal Data unless retention is required by law or expressly permitted by the agreement, this DPA, or limited operational necessity such as backups, security logs, and immutable audit records; (h) make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as set out in Section 7; and (i) maintain records of processing activities required by Applicable Data Protection Laws.

6. Customer obligations

Customer is responsible for: (a) providing lawful instructions; (b) determining legal bases, purposes, and proportionality of processing; (c) giving Data Subjects all required notices and obtaining required consents, honoring opt-outs, and respecting applicable preference signals; (d) configuring tracking, SDKs, destinations, integrations, experiments, AI workflows, and automations lawfully; (e) responding to Data Subject requests where Customer is the Controller; (f) ensuring Customer Content and Customer Personal Data may be lawfully provided to Lyberty; (g) not submitting Restricted Data without Lyberty Written Authorization; (h) promptly notifying Lyberty if Restricted Data is submitted without Lyberty Written Authorization and cooperating in remediation, deletion, isolation, and required notices; (i) not deploying Lyberty technologies on websites, applications, or services directed to children, or where Customer has actual knowledge that children's personal data will be processed, unless a signed addendum authorizes that use and specifies required safeguards; and (j) configuring access controls, retention, and deletion settings to reflect Customer's compliance posture.

7. Audits

Lyberty will make available to Customer (i) industry-standard third-party audit reports such as SOC 2 Type II, ISO 27001 certificates, or equivalent (when available) and (ii) other information reasonably necessary to demonstrate compliance with this DPA. Until such third-party certifications or reports are available, Lyberty will provide reasonable security documentation, summaries of technical and organizational measures, penetration-test summaries where available, and responses to reasonable security questionnaires under confidentiality. If those materials do not address Customer's reasonable concerns, Customer may, on at least thirty (30) days' prior written notice, conduct an audit not more than once every twelve (12) months, during business hours, in a manner that does not unreasonably interfere with Lyberty's operations and is subject to confidentiality, security, and reasonable scope. Customer may not conduct penetration testing, vulnerability scanning, or technical testing of the Services without Lyberty's prior written approval. Audits requested in response to a regulator's mandatory order or following a confirmed material Personal Data Breach by Lyberty are not subject to the once-per-year limit. Customer bears the costs of audits, except where the audit reveals material Lyberty non-compliance, in which case Lyberty bears the reasonable, documented costs.

8. US state privacy terms (CCPA/CPRA and equivalents)

Where US state privacy laws apply, Lyberty will act as a service provider, contractor, or processor for Customer Personal Data and will not: (i) Sell or Share Customer Personal Data; (ii) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the agreement, including not for any commercial purpose other than providing the Services; (iii) retain, use, or disclose Customer Personal Data outside the direct business relationship; (iv) combine Customer Personal Data with personal information collected from any other source, except as permitted by Applicable Data Protection Laws or instructed by Customer; or (v) process Customer Personal Data for "cross-context behavioral advertising" or targeted advertising except on Customer's documented instructions and where legally permitted. Lyberty certifies that it understands these restrictions.

9. Sub-processors

Customer generally authorizes Lyberty to use the Sub-processors listed at /trust/sub-processors. Lyberty will provide at least thirty (30) days' advance notice of material Sub-processor additions or replacements by updating that page, by email to account administrators, or by in-product notice, unless shorter notice is required for security, continuity, or emergency reasons. Customer may object on reasonable, demonstrable data-protection grounds during the notice period by writing to privacy@lyberty.ai. If the parties cannot resolve the objection through good-faith discussion, Customer may stop using the affected feature or terminate the affected portion of the Services with a pro-rata refund of prepaid unused fees for the affected portion as Customer's sole remedy.

10. International transfers

For transfers of Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision recognized by the relevant authority, the parties incorporate by reference: (a) the EU SCCs (Module 2 for Controller-to-Processor; Module 3 for Processor-to-Sub-processor), with Clause 7 ("docking") enabled; Clause 9 Option 2 (general authorization, 30-day notice unless shorter notice is required for security, continuity, or emergency reasons); Clause 17 governing law of Ireland; Clause 18 forum of Ireland; Annexes I and II completed by this DPA; Annex III completed by the Sub-processor list; (b) the UK Addendum with the information in this DPA and Tables 1–4 completed accordingly; and (c) the Swiss FADP addendum referencing the Swiss Federal Data Protection and Information Commissioner.

For transfers of Customer Personal Data subject to the UAE PDPL, transfers rely on adequacy decisions or appropriate safeguards as recognized by the UAE Data Office.

For transfers of Customer Personal Data subject to other jurisdictions (e.g. PRC PIPL, India DPDPA, Brazil LGPD, Australia Privacy Act), Customer is the Controller responsible for ensuring lawful transfer, and Lyberty will reasonably cooperate with Customer's compliance program.

Lyberty will maintain supplementary measures described in Annex II and will notify Customer if Lyberty reasonably believes it can no longer comply with applicable transfer safeguards.

11. AI providers and model training

Lyberty will not use Customer Personal Data or Customer Content to train general-purpose AI models for other customers. Customer authorizes Lyberty to process Customer Personal Data through AI providers and model infrastructure necessary to provide Customer-selected or Customer-configured AI features, subject to this DPA and the Sub-processor list. Lyberty will contractually prohibit third-party AI model providers used as Sub-processors from using Customer Personal Data or Customer Content to train their general-purpose models except where Customer expressly enables or authorizes that provider or feature under separate terms.

12. Retention and deletion

During the term, Customer may delete, export, or configure retention for Customer Personal Data where the Services support it. Upon termination or valid written request, Lyberty will delete or return Customer Personal Data within a commercially reasonable period (target: thirty (30) days from request), unless retention is required by law, necessary for the establishment, exercise, or defense of legal claims, or maintained in routine backups, security logs, or immutable audit records until overwritten or no longer required, in which case Lyberty will continue to protect it under this DPA until deletion. Backup copies are overwritten or deleted in accordance with Lyberty's standard backup lifecycle unless legally required. Immutable audit logs are retained only for security, fraud prevention, compliance, and legal-defense purposes and are access-restricted. During retention, Lyberty will not actively process retained Customer Personal Data except as necessary for those purposes.

13. Liability and order of precedence

Liability under this DPA is subject to the limitations in the agreement (including the aggregate cap in the Terms). If there is a conflict between this DPA and the agreement, this DPA controls for data-protection matters. The EU SCCs, UK Addendum, and Swiss addendum control for transfers they govern. Where the SCCs allocate liability differently than the agreement, the SCCs control for the processing they govern, and any remedies are subject to the cap in the agreement.

14. Governing law

This DPA is governed by the law specified in the agreement (the Dubai International Financial Centre, unless otherwise specified). For the EU SCCs, Clause 17 designates the law of Ireland and Clause 18 designates the courts of Ireland. For the UK Addendum, English law and the courts of England and Wales apply. For the Swiss FADP, Swiss law applies.

Annex I — Details of Processing

Data exporter: Customer, as identified in the agreement or order form.

Data importer: Lyberty Labs FZCO d/b/a Lyberty, Premises Number 23201, IFZA Business Park, Dubai, UAE. Contact: privacy@lyberty.ai.

  • Nature and purpose: providing, securing, supporting, and improving the Services as described above.
  • Frequency: continuous or as initiated by Customer.
  • Duration: the term of the agreement plus post-termination periods described in this DPA.
  • Data Subjects: Customer personnel, users, prospects, customers, website visitors, contacts, counterparties, and individuals reflected in Customer's connected systems, sites, content, or workflows.
  • Personal data categories: as described in Section 4.
  • Special Categories: not intended; prohibited unless covered by Lyberty Written Authorization in a signed addendum, order form, business associate agreement, DPA exhibit, or other executed agreement.
  • Sub-processors: /trust/sub-processors.
  • Competent Supervisory Authority (SCC Clause 13): the Irish Data Protection Commission (DPC), unless another EEA authority is competent under GDPR Art. 56.

Annex II — Technical and Organizational Measures

Lyberty maintains a security program designed to protect Customer Personal Data, including:

  • Personnel security: confidentiality obligations for all personnel; privacy and security training; background screening as permitted by law.
  • Access control: role-based access control, least privilege, unique user IDs, multi-factor authentication for administrative and production access, periodic access reviews, prompt removal on role change or termination.
  • Encryption: encryption in transit using TLS 1.2 or higher; encryption at rest where supported by the underlying storage or service.
  • Secrets management: centralized secrets management, environment separation, secrets rotation procedures.
  • Network and application security: segmentation, firewalling, rate limits, DDoS mitigation, secure-by-default API configurations, input validation, dependency scanning.
  • Logging, monitoring, and detection: centralized logging, audit trails, anomaly detection, security alerting.
  • Vulnerability management: periodic vulnerability scanning, secure development lifecycle, code review, third-party penetration testing as appropriate.
  • Incident response: documented incident response plan, on-call rotation, breach notification procedures.
  • Backup and continuity: routine backups, restoration testing, disaster recovery procedures appropriate to the Services.
  • Data minimization, retention, and deletion: controls to align processing with purpose limitation and to support deletion, return, and retention configuration.
  • Customer controls: access controls, exports, deletion, configuration, and audit trails where available in the Services.
  • Sub-processor governance: due diligence, contractual obligations, monitoring.

Lyberty may update these measures provided the overall level of security is not materially reduced.

Annex III — International Transfers

EU SCCs Modules 2 and 3 apply as appropriate. Clause 7 docking is enabled. Clause 9 uses the general authorization with 30 days' notice unless shorter notice is required for security, continuity, or emergency reasons. Clause 17 designates the law of Ireland. Clause 18 designates the courts of Ireland. Annexes I and II are completed by this DPA. Annex III is completed by the Sub-processor list.

UK transfers: the UK Addendum applies using the information in this DPA and Tables 1–4 are completed accordingly.

Swiss transfers: Swiss-law references and FDPIC references apply as required.

Annex IV — California and US State Privacy Addendum

Where US state privacy laws apply, Customer is the business or controller, and Lyberty is the service provider, contractor, or processor. Lyberty will process Customer Personal Data only for the permitted business purposes described in the agreement, will not Sell or Share Customer Personal Data, will not retain, use, or disclose it outside the agreement except as permitted by law, will not combine it with personal information from other sources except as permitted by law, will not process it for cross-context behavioral advertising or targeted advertising except on Customer's documented instructions, and will provide reasonable assistance for consumer requests and opt-outs.

End of DPA.

Lyberty

You set the target. Lyberty pulls the numbers together, shows you what is driving the result, and gets the response live through the tools your team already uses.

PRODUCT

  • Platform
  • How it works
  • Industries
  • Pricing

COMPANY

  • Manifesto
  • Contact

RESOURCES

  • Docs
  • Trust

Works with: Shopify, Meta, Stripe, Klaviyo and your existing stack.

Removes: manual reconciliation, approval chasing, repeated reporting and lost decisions.

© 2026 Lyberty, Inc.

Privacy·Terms·DPA·Acceptable use·Cookies