Data Processing Agreement
The Article 28 processor terms governing Laya’s handling of customer personal data, including sub-processing, security, transfers and deletion.
Last updated
On this page
This Data Processing Agreement ("DPA") applies where Laya processes personal data on your behalf in the course of providing the Laya service, and forms part of the terms of service. It reflects Article 28 of the UK GDPR and the EU GDPR.
1. Definitions
"Controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in the UK GDPR. "Customer content" means the data you and your workspace members put into, or connect to, the Laya service. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR.
2. Roles and scope
For customer content you are the controller and Laya is the processor. Laya processes customer content only to provide, secure, maintain and support the service, and only on your documented instructions — of which your use of the service, and this DPA, are the primary record. Laya will inform you if, in its opinion, an instruction infringes Data Protection Law.
3. Subject matter of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Laya work management and board mirroring service |
| Duration | The term of your use of the service, plus the deletion periods in clause 9 |
| Nature and purpose | Hosting, storing, transmitting, displaying, synchronising and backing up customer content; providing support; securing the service |
| Types of personal data | Names, email addresses, profile images and account identifiers of workspace members and of users of your connected tools; plus any personal data your members choose to place in board items, documents, comments or attachments |
| Categories of data subject | Your workspace members, your users in connected tools, and any individual referenced in customer content |
| Special category data | Not requested and not required by the service. If you place it in customer content you remain responsible for the lawfulness of doing so |
4. Confidentiality
Laya ensures that persons authorised to process customer content are subject to an appropriate duty of confidentiality, and limits access to those who need it to deliver or support the service.
5. Security
Laya implements appropriate technical and organisational measures to protect customer content, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Those measures are described in the security programme, which forms the technical and organisational measures annex to this DPA. Laya may update the measures provided the level of protection is not reduced.
6. Sub-processors
- You give general authorisation for Laya to engage sub-processors to deliver the service.
- The current list is published at sub-processors.
- Laya imposes on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to you for their performance.
- Laya will give at least 30 days’ notice before a new sub-processor begins processing customer content. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected part of the service without penalty.
7. Assistance to you
- Data subject rights — taking account of the nature of the processing, Laya assists you by appropriate technical and organisational measures in fulfilling requests. Workspace administrators can access, correct, export and delete customer content directly in the product; where that is not sufficient, contact privacy@laya.net.
- Security, breach and impact assessments — Laya assists you in ensuring compliance with Articles 32 to 36, taking into account the nature of processing and the information available to it.
8. Personal data breach
Laya notifies you without undue delay after becoming aware of a personal data breach affecting customer content, and provides the information reasonably available to it so you can meet your own notification duties — including the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, and the measures taken or proposed. See incident response.
9. Return and deletion
- You may export customer content at any time during the term using the product’s export functions.
- On termination, and at your choice, Laya deletes or returns customer content, and deletes existing copies unless required to retain them by law.
- Disconnecting a connected tool deletes Laya’s mirror of that tool’s boards. Deleting a workspace or account removes its customer content.
- Backups are cycled on a rolling basis and deleted content ages out with them.
- See data retention and deletion for detail.
10. Information and audits
Laya makes available the information necessary to demonstrate compliance with Article 28 — principally this Trust Centre, the published measures and the sub-processor list — and responds to reasonable written questions from your security and legal teams. Where you require further assurance, contact support@laya.net and we will agree a proportionate approach.
11. International transfers
Customer content is hosted in the United States. Transfers out of the UK and EEA are made under the UK International Data Transfer Addendum and the EU Standard Contractual Clauses respectively, together with the supplementary measures described in international data transfers.
Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.