Data Processing Agreement

Version 1.0 — Effective July 24th 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or any other agreement governing the Customer’s use of Limin (the “Agreement”).

It applies where Limin processes personal data on behalf of the Customer through the Limin service.

This DPA is provided in English and forms part of the Agreement.

1. Parties and roles

The parties to this DPA are:

  • the organization that owns or subscribes to a Limin workspace (“Customer”); and
  • Camille Hagenbourger, Entrepreneur individuel, trading as Limin Software (“Limin”).

For personal data contained in issues, comments, descriptions, attachments, activity records, and other workspace content:

  • the Customer acts as controller;
  • Limin acts as processor.

“Customer Personal Data” means personal data processed by Limin on behalf of the Customer through the Customer’s workspace.

This DPA does not apply to personal data that Limin processes as an independent controller for account administration, authentication, billing, security, support, legal compliance, or operation of the service. That processing is described in Limin’s Privacy Notice.

2. Processing instructions

Limin will process Customer Personal Data only:

  • to provide, secure, maintain, and support the service;
  • in accordance with the Agreement, this DPA, and the Customer’s documented instructions;
  • where required by applicable law.

The Agreement, the Customer’s use and configuration of the service, and its support requests constitute documented instructions.

If applicable law requires Limin to process Customer Personal Data beyond those instructions, Limin will inform the Customer before doing so unless prohibited by law.

Limin will inform the Customer if it reasonably believes that an instruction infringes applicable data-protection law and may suspend the affected processing until the issue is resolved.

The details of the processing are set out in Annex I.

3. Customer responsibilities

The Customer is responsible for:

  • ensuring that its processing of Customer Personal Data is lawful;
  • providing required information to data subjects;
  • issuing lawful processing instructions;
  • managing workspace access and permissions;
  • responding to data-subject and supervisory-authority requests.

The Customer must not use Limin for the systematic processing of special categories of personal data or criminal-conviction data unless it has determined that such processing is lawful and appropriately protected.

4. Confidentiality and security

Limin will ensure that persons authorized to process Customer Personal Data:

  • access it only where necessary;
  • are subject to an appropriate duty of confidentiality;
  • process it only in accordance with the Customer’s instructions, unless required by law.

Limin does not routinely inspect private workspace content. It may access such content where reasonably necessary to provide support, investigate a security or technical incident, prevent abuse, comply with the law, or protect the service and its users.

Limin will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, disclosure, or access.

The measures currently implemented are summarized in Annex II. Limin may update them as technology and risks evolve, provided that the overall level of protection is not materially reduced.

The Customer remains responsible for securely managing its accounts, permissions, devices, integrations, and exported data.

5. Personal data breaches

Limin will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

To the extent available, the notification will describe:

  • the nature of the breach;
  • the categories of data and individuals affected;
  • the likely consequences;
  • the measures taken or proposed in response;
  • a contact point for further information.

Information may be provided in stages as the investigation progresses.

Limin will take reasonable steps to investigate, contain, and mitigate the breach. The Customer remains responsible for determining whether notification to a supervisory authority or affected individuals is required.

6. Assistance and data-subject requests

Taking into account the nature of the processing and the information available to Limin, Limin will provide reasonable assistance to the Customer with:

  • requests from data subjects;
  • security and breach-notification obligations;
  • data protection impact assessments;
  • consultations with supervisory authorities.

The Customer should first use the functions available within the service to access, correct, export, or delete Customer Personal Data.

If Limin receives a request directly concerning Customer Personal Data, it will normally direct the person to the Customer and will not respond to the substance of the request without the Customer’s instructions, unless required by law.

7. Subprocessors

The Customer gives Limin general authorization to use subprocessors to provide the service.

The current subprocessors and their purposes are listed in Limin’s Subprocessor List.

Limin will:

  • use subprocessors that provide appropriate data-protection and security guarantees;
  • impose data-protection obligations materially equivalent to those contained in this DPA;
  • remain responsible for their performance to the extent required by applicable law.

Limin will provide at least 30 days’ notice before appointing or replacing a subprocessor that will process Customer Personal Data.

The Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable solution is available, the Customer may terminate the affected service before the new subprocessor begins processing its data.

Urgent changes required for security, legal compliance, or service continuity may be notified as soon as reasonably practicable.

8. International transfers

Limin may process Customer Personal Data outside the European Economic Area only where permitted by applicable law.

Where additional safeguards are required, Limin or the relevant subprocessor will use an appropriate mechanism, such as:

  • an adequacy decision;
  • the European Commission’s Standard Contractual Clauses;
  • another lawful transfer mechanism.

Unless prohibited by law, Limin will notify the Customer of a binding public-authority request for Customer Personal Data and will disclose only the information it reasonably believes it is legally required to provide.

9. Return and deletion

During the Agreement, the Customer may use the available service functions to access or export Customer Personal Data.

Following termination of the Agreement or permanent deletion of the workspace, Limin will, at the Customer’s choice and subject to the available service functions, return Customer Personal Data through export or delete it, unless applicable law requires further retention.

Workspace deletion is subject to a seven-day recovery period. After that period, active workspace data and stored assets are deleted within 24 hours.

Deleted information may remain temporarily in restricted technical or disaster-recovery copies until those copies are overwritten through the relevant provider’s ordinary processes.

Limin may retain information that has been irreversibly anonymized so that it no longer identifies any individual or Customer.

10. Information and audits

Limin will make available the information reasonably necessary to demonstrate compliance with this DPA and applicable processor obligations.

The Customer should first review the documentation and information made available by Limin.

Where that information is insufficient, the Customer may conduct an audit itself or through an independent auditor subject to confidentiality obligations. Audits must:

  • relate to Limin’s processing of Customer Personal Data;
  • be conducted with reasonable advance notice;
  • take place during normal business hours;
  • minimize disruption and protect the rights and confidentiality of other customers.

Audits may normally be conducted no more than once in any 12-month period, unless a personal data breach, supervisory authority, or reasonable evidence of material non-compliance justifies an additional audit.

Limin may respond through relevant policies, questionnaires, certifications, summaries, or independent reports where these reasonably address the request.

The Customer bears its own audit costs and Limin’s reasonable assistance costs, unless the audit identifies a material breach of this DPA by Limin.

11. Duration and liability

This DPA takes effect when the Customer accepts the Agreement or begins using Limin and remains in force for as long as Limin processes Customer Personal Data on the Customer’s behalf.

Termination of the Agreement terminates this DPA, except for provisions that must continue while Customer Personal Data remains in Limin’s possession.

Each party’s liability under this DPA is subject to the exclusions and limitations contained in the Agreement, except where prohibited by applicable law.

Nothing in this DPA limits the rights of data subjects or the powers of a supervisory authority.

12. Order of precedence and contact

If there is a conflict concerning Customer Personal Data:

  1. mandatory data-protection law prevails;
  2. any applicable Standard Contractual Clauses prevail;
  3. this DPA prevails;
  4. the remainder of the Agreement applies.

The governing-law and dispute-resolution provisions of the Agreement also apply to this DPA.

Questions concerning this DPA may be sent to:

Limin Software
Camille Hagenbourger EI
20 avenue d’Ouessant
35740 Pacé
France

privacy@limin.dev


Annex I — Details of the processing

Subject matter and purpose

Processing of Customer Personal Data necessary to provide, host, secure, synchronize, maintain, and support the Customer’s Limin workspace.

Duration

For the duration of the Agreement and any limited period required to return, recover, or delete Customer Personal Data.

Nature of the processing

The processing may include collection, storage, organization, retrieval, display, modification, synchronization, transmission to authorized users and subprocessors, restriction, archiving, export, and deletion.

Categories of data subjects

Customer Personal Data may concern:

  • the Customer’s employees, contractors, and representatives;
  • workspace owners, members, guests, and invitees;
  • customers, suppliers, partners, or other persons referenced in workspace content;
  • any other individuals whose information the Customer submits to the service.

Categories of personal data

Depending on the Customer’s use of the service, this may include:

  • names, aliases, email addresses, and profile images;
  • roles, team memberships, permissions, and assignments;
  • issue authorship, comments, activity, and contribution history;
  • issue descriptions, attachments, labels, relations, and other workspace content;
  • dates, timestamps, identifiers, and technical metadata;
  • other personal data submitted by or on behalf of the Customer.

The service is not intended for the systematic processing of special categories of personal data or criminal-conviction data.

Frequency

Continuous or recurring for the duration of the Customer’s use of the service.


Annex II — Technical and organizational measures

Limin’s measures include, as appropriate:

Access and authentication

  • authentication required for access to private workspaces;
  • workspace-scoped permissions and tenant separation;
  • restricted production access based on operational need;
  • secure management of sessions and credentials.

Encryption

  • HTTPS and secure WebSocket connections;
  • encryption at rest for the primary database and file storage;
  • controlled authorization for access to private attachments.

Application and infrastructure security

  • input validation and workspace-scoped data access;
  • protected production configuration and secrets;
  • separation of development and production environments;
  • testing of material changes before deployment;
  • production errors designed not to expose sensitive internal information.

Logging and monitoring

  • operational and security logging limited to necessary information;
  • logs designed to exclude private workspace content, attachments, and authentication tokens;
  • truncated email addresses where required in logs;
  • monitoring of availability, errors, authentication, and relevant security events.

Data deletion and incident management

  • automated account, workspace, and file-deletion routines;
  • documented retention periods;
  • procedures for investigating and responding to security incidents;
  • infrastructure health monitoring and recovery mechanisms.

Confidentiality and providers

  • production access restricted to authorized persons subject to confidentiality obligations;
  • established infrastructure providers used for physical security, hosting resilience, and data-centre controls.