Data processing agreement
Last updated: 22 September 2026
1. Purpose
This Data Processing Agreement ("DPA") template describes the terms under which Lanevo processes personal data on behalf of a customer ("Controller") as part of providing the Service. Customers who require a signed DPA — typically those with their own data-protection obligations to their end customers — can request an executed copy through the Contact page.
2. Roles
The Controller determines the purposes and means of processing personal data entered into the Service (its own customers’ booking and contact details). Lanevo acts as Processor, handling that data only on the Controller’s documented instructions, as configured through normal use of the Service.
3. Subject matter and duration
Processing covers the personal data the Controller enters into the Service for as long as the Controller maintains an active subscription, plus any post-termination export/retention period described in the Privacy policy.
4. Categories of data and data subjects
Typical categories: names, contact details, identification/licence details, and booking or payment history, relating to the Controller’s renters, staff, and business partners (such as brokers).
5. Sub-processors
Lanevo uses a limited set of sub-processors necessary to operate the Service (cloud hosting, payment processing, and, where enabled, WhatsApp’s Cloud API). A current list is available on request. Material changes to sub-processors will be communicated in advance.
6. Security measures
Lanevo maintains administrative, technical, and physical safeguards appropriate to the nature of the data processed, including encrypted connections, role-based access control enforced server-side, and activity logging.
7. Assistance with data subject requests
Lanevo will provide reasonable assistance to the Controller in responding to data subject requests (access, correction, deletion) relating to data held in the Service.
8. Breach notification
Lanevo will notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller’s data, and will provide information reasonably necessary for the Controller to meet its own notification obligations.
9. International transfers
Where personal data is transferred internationally, Lanevo will use appropriate safeguards as required by applicable law.
10. Deletion on termination
On termination, the Controller may export its data within the period described in the Privacy policy, after which Lanevo will delete or anonymise the data, except where retention is required by law.
11. Requesting a signed copy
This page is a template for reference. To execute a signed DPA for your organisation, contact us through the Contact page.