LearnLumina Logo
    InsightLumina

    Data Processing Agreement

    InsightLumina — Enterprise DPA Template · Last updated: January 2025

    This DPA template is available for Enterprise customers. To request a signed copy customized to your organization, contact us after subscribing to an Enterprise plan.

    1. Parties

    This Data Processing Agreement (“DPA”) is entered into between:

    • • Data Controller (“Customer”): The entity that has entered into a subscription agreement for InsightLumina services.
    • • Data Processor (“InsightLumina” / “LearnLumina”): The entity providing the InsightLumina analytics service.

    2. Scope of Processing

    InsightLumina processes Customer data solely for the purpose of providing AI-powered analytics insights as described in the service agreement. Processing includes:

    • • Syncing business metrics from Customer's connected platforms (Shopify, Google Analytics, etc.)
    • • Aggregating and anonymizing metrics into summary statistics
    • • Submitting aggregated statistics to AI models for analysis
    • • Generating and delivering insight reports
    • • Storing aggregated metrics for the agreed retention period

    3. Data Minimization

    InsightLumina is architecturally designed to minimize data processing. The Processor does not collect, store, or process individual customer records, personal identifiable information (PII), or raw transaction data from the Controller's platforms. Only aggregated business metrics (revenue trends, conversion rates, product performance statistics, etc.) are processed.

    4. Sub-Processors

    The Processor uses the following sub-processors:

    • • AI/LLM Provider: Receives only aggregated, anonymized statistics for insight generation. Does not train on API-submitted data.
    • • Stripe: Processes subscription payments. Does not receive Customer's business data.
    • • Cloud Infrastructure Provider: Hosts encrypted data in isolated per-customer partitions.

    The Processor will notify the Controller at least 30 days before engaging any new sub-processor. The Controller may object to a new sub-processor within 14 days of notification.

    5. Security Measures

    The Processor implements the following technical and organizational measures:

    • • AES-256 encryption at rest for all stored data
    • • TLS 1.2+ encryption for all data in transit
    • • Separate encryption key material for OAuth tokens
    • • Strict tenant isolation at the database level
    • • Regular security reviews and dependency audits
    • • Access controls limiting employee access to Customer data

    6. Data Retention & Deletion

    The Processor retains Customer's aggregated metrics for the retention period specified in the subscription plan (configurable for Enterprise customers). Upon expiration or termination of the agreement, or upon Customer's request, the Processor will permanently delete all Customer data, including backups, within 48 hours. Deletion is irreversible and complete.

    7. Data Subject Rights

    The Processor will assist the Controller in responding to data subject requests (access, correction, deletion, portability, objection) to the extent that the Processor holds relevant data. Given the aggregated nature of the data processed, individual data subject requests are typically not applicable, but the Processor will cooperate fully with the Controller.

    8. Breach Notification

    In the event of a personal data breach, the Processor will notify the Controller without undue delay and no later than 48 hours after becoming aware of the breach. The notification will include the nature of the breach, categories of data affected, estimated number of records, and measures taken to address the breach.

    9. Audit Rights

    The Controller has the right to audit the Processor's compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and allow for audits conducted by the Controller or an independent auditor, subject to reasonable notice and confidentiality requirements.

    10. Governing Law

    This DPA is governed by the same governing law as the underlying service agreement between the parties. For processing subject to GDPR, EU data protection law applies to the data processing provisions of this DPA.

    11. Term

    This DPA remains in effect for the duration of the service agreement and until all Customer data has been deleted in accordance with Section 6.

    Download or Request a Signed Copy

    Download this DPA template for your review. Enterprise customers can also request a signed copy customized to their organization.

    Terms of ServicePrivacy PolicySecurityBack to InsightLumina
    InsightLumina
    Terms of ServicePrivacy PolicyData Processing AgreementSecurity