LILY Labs GmbH
LILY Beta — Data Processing Agreement
Annex to the LILY Beta Terms of Use
PREAMBLE
(1) This Data Processing Agreement (“DPA”) specifies the data-protection obligations of the parties arising from the processing of personal data carried out under the LILY Beta Terms of Use (the “Principal Agreement” or “Beta Terms”) pursuant to Art. 28 GDPR.
(2) This DPA is concluded between LILY (as identified in the Beta Terms), hereinafter “Processor” or “LILY” and the User admitted to the LILY Beta Programme in accordance with the Beta Terms, hereinafter “Controller”.
(3) Unless expressly defined otherwise in this DPA, capitalized terms used in this DPA shall have the same meaning as defined in the Principal Agreement (in particular “LILY”, “CLI”, “Platform”, “Void”, “User Application”, “Compiled Artefact”, “Customer Data”). The terms “personal data”, “processing”, “data subject”, “personal data breach”, “sub-processor” and “supervisory authority” shall be interpreted in accordance with the relevant provisions of the GDPR. In the event of a conflict between this DPA and the Principal Agreement, the provisions of this DPA prevail on data-protection matters.
§ 1 PURPOSE AND SCOPE
(1) The subject matter of the processing operations carried out by LILY under this DPA is the provision of the LILY Services pursuant to the Principal Agreement, in particular the compilation of the Controller’s source code into the Compiled Artefact, the execution of User Applications on the Void server infrastructure including the required storage, scheduling, routing, processing, monitoring and network services, and the operation of the Platform.
(2) The details of the processing operations carried out by LILY on behalf of the Controller, in particular the categories of personal data and the purposes of processing for which the personal data is processed by LILY on behalf of the Controller, are specified in Annex 1.
(3) This DPA takes effect upon its acceptance by the Controller when concluding the Principal Agreement and applies as long as LILY processes personal data on behalf of the Controller under the Principal Agreement. The term of this DPA corresponds to the term of the Principal Agreement and is not limited to, or terminated by, the end of any programme phase.
§ 2 CONTROLLER’S INSTRUCTIONS
(1) LILY processes personal data exclusively on documented instructions from the Controller. The Controller’s initial instructions derive from the Principal Agreement and are set out in this DPA (including its Annexes).
(2) Subsequent instructions, which may amend or supplement the Controller’s initial instructions, shall be given in text form and may only be given by persons sufficiently authorized to act on the Controller’s behalf and LILY may refuse instructions issued by persons who lack such authorization. The Controller shall provide the contact details of such persons to LILY upon conclusion of this DPA via email to privacy@lilylabs.io and shall promptly notify LILY of any changes in that regard. Verbal instructions shall be confirmed in text form without undue delay. Any such instructions must be directed to privacy@lilylabs.io.
(3) Unless specifically agreed otherwise between LILY and the Controller in text form and the necessary technical, organisational and contractual safeguards have been agreed, instructions by the Controller must not result in LILY processing the following categories of personal data via the LILY Services: special categories of personal data within the meaning of Art. 9 GDPR, personal data within the meaning of Art. 10 GDPR, personal data subject to professional or statutory confidentiality obligations (e.g. Section 203 of the German Criminal Code (Strafgesetzbuch) or classified information (together “Prohibited Data”). The Controller shall ensure that no Prohibited Data is processed by LILY.
(4) Instructions going beyond the scope of the Principal Agreement and this DPA require a separate agreement between the Controller and LILY. LILY is not obliged to implement individual special requests that are not covered by standard LILY Services features and that exceed LILY’s obligations under Art. 28 GDPR; it may charge a reasonable fee for assistance that exceeds the level owed under the Principal Agreement.
(5) If LILY is of the opinion that an instruction infringes applicable data-protection law, may result in LILY processing Prohibited Data or has already resulted in LILY processing Prohibited Data, it shall inform the Controller without undue delay (Art. 28(3) sentence 3 GDPR). In such case, LILY is entitled to suspend the execution of the instruction concerned until it is expressly confirmed or amended by the Controller, or, in case of Prohibited Data, at the choice of the Controller, either return or delete such data. Should the Controller insist on compliance with instructions infringing applicable data-protection law or resulting in LILY’s processing of Prohibited Data, LILY shall have the right to terminate the Principal Agreement for good cause in accordance with the applicable provisions of the Beta Terms.
(6) LILY shall promptly inform the Controller if it is unable, for whatever reason, to comply with its obligations under this DPA.
§ 3 OBLIGATIONS OF THE PROCESSOR
(1) Processing on instructions only (Art. 28(3)(a), Art. 29 GDPR). LILY processes personal data exclusively within the framework of this DPA, the Principal Agreement and on documented instructions from the Controller, unless otherwise required by Union or Member State law to which LILY is subject; in such a case LILY shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
(2) Confidentiality (Art. 28(3)(b) GDPR). LILY ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and ensures their instruction on the applicable data-protection requirements. The confidentiality obligations survive termination of the respective employment or engagement. LILY shall grant access to the personal data processed under this DPA to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of its obligations under this DPA and the underlying Principal Agreement.
(3) Security of processing (Art. 28(3)(c), Art. 32 GDPR). LILY implements the technical and organisational measures set out in Annex 2 of this DPA and reviews and adapts them in accordance with § 7.
(4) Assistance with data subject rights (Art. 28(3)(e) GDPR). LILY assists the Controller as set out in § 4.
(5) Assistance with security, breach notification, DPIA and prior consultation (Art. 28(3)(f) GDPR). Taking into account the nature of the processing and the information available to it, LILY assists the Controller in ensuring compliance with the Controller’s obligations under Arts. 32 to 36 GDPR and as further specified in this DPA.
§ 4 ASSISTANCE WITH DATA SUBJECT RIGHTS
(1) LILY shall assist the Controller in fulfilling its obligation to respond to requests by data subjects exercising their rights, taking into account the nature of the processing.
(2) Where a data subject contacts LILY directly with a request concerning personal data processed under this DPA, LILY shall forward the request to the Controller without undue delay and shall not respond to it itself, unless the Controller has authorized LILY to respond directly. Any such authorization by the Controller must be provided in text form.
(3) LILY may charge a reasonable fee for assistance that demonstrably exceeds the level of support owed under the Principal Agreement and this DPA.
§ 5 PERSONAL DATA BREACH NOTIFICATION
(1) In the event of a personal data breach affecting the personal data processed under this DPA, LILY shall inform the Controller without undue delay, and in any event within twenty-four (24) hours of becoming aware of it.
(2) The notification shall contain, at least (where available): a description of the nature of the breach including, where possible, the categories and approximate number of data subjects and data records concerned; the name and contact details of the responsible contact at LILY; a description of the likely consequences of the breach; and a description of the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
(3) Where, and insofar as, the information cannot be provided in full at the same time, it may be provided in phases without undue further delay as it becomes available.
§ 6 SUB-PROCESSORS
(1) The Controller hereby grants LILY general written authorisation to engage sub-processors. The sub-processor engaged at the time of conclusion of this DPA are listed in Annex 3 of this DPA.
(2) LILY shall inform the Controller of any intended change regarding the engagement or replacement of sub-processors identified in Annex 3 by way of notification via the Platform or in text form, thereby giving the Controller the opportunity to object to such changes (Art. 28(2) sentence 2 GDPR). LILY shall provide the Controller with the information necessary to enable the Controller to exercise the right to object.
(3) The Customer shall be entitled to object to the engagement of a new or replacement sub-processor only if the Controller demonstrates that the engagement would give rise to a concrete and material risk to the personal data processed under this DPA that cannot be adequately mitigated by the safeguards imposed under this DPA. Any objection must be raised in text form within ten (10) days of receipt of the notification and must set out in reasonable detail the specific grounds on which the objection is based. If the Controller does not raise an objection within this period, the Controller shall be deemed to have approved the engagement. If the Controller raises a justified objection, LILY LABS shall use reasonable efforts to propose an alternative arrangement or additional safeguards to address the Controller’s concerns. If no mutually acceptable solution can be found within fourteen (14) days of receipt of the objection, the Controller shall be entitled to terminate the Principal Agreement with fourteen (14) days’ notice to the end of the then-current monthly period; such termination shall be the Controller’s sole remedy in respect of the disputed engagement. For the avoidance of doubt, changes to subcontractors that do not involve access to personal data processed under this DPA shall not be subject to the notification and objection procedure set out in this Section.
(4) LILY shall impose on each sub-processor, by way of a contract or other legal instrument, essentially the same data-protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures meeting the requirements of Art. 32 GDPR and of Annex 2 (Art. 28(4) GDPR). Where a sub-processor fails to fulfil its data-protection obligations, LILY remains fully liable to the Controller for the performance of that sub-processor’s obligations.
(5) Any transfer of personal data to a third country or an international organisation by the Processor shall be done only on the basis of documented instructions from the Controller or in order to fulfil a specific requirement under Union or Member State law to which the Processor is subject and shall take place in compliance with Chapter V of the GDPR. The Controller agrees that where the Processor engages a sub-processor in accordance with this § 6 for carrying out specific processing activities on behalf of the Controller and those processing activities involve a transfer of personal data, the Processor and the sub-processor can ensure compliance with Chapter V of the GDPR by using standard contractual clauses adopted by the EU Commission in accordance with of Art. 46(2) GDPR, provided the conditions for the use of those standard contractual clauses are met.
§ 7 TECHNICAL AND ORGANISATIONAL MEASURES
(1) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons in relation to the personal data, LILY implements the technical and organisational measures described in Annex 2 of this DPA to ensure a level of security of the personal data appropriate to the risk within the meaning of Art. 32 GDPR. These measures have been approved by the Controller before concluding this DPA.
(2) LILY is entitled to adapt the measures to the state of the art and to evolving risks, provided the level of protection is not reduced. Material changes to the technical and organisational measures will be communicated to the Controller in text form, using the email address provided by the Controller on the Platform.
(3) LILY reviews the measures at appropriate intervals (at least annually and upon any material change to the processing) and documents the review.
§ 8 EVIDENCE AND AUDIT RIGHTS
(1) LILY makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and in this DPA (Art. 28(3)(h) GDPR), in particular by: providing the current version of the technical and organisational measures (Annex 2), dealing promptly and adequately with inquiries from the Controller about the processing of personal data under this DPA, providing suitable certifications, attestations or audit reports (e.g. ISO/IEC 27001, BSI C5, SOC 2) where available.
(2) The Controller is additionally entitled to carry out, or to mandate, inspections including audits of LILY’s premises or physical facilities (Art. 28(3)(h) GDPR), conducted by an independent, suitably qualified auditor that is mutually agreed and bound by confidentiality. The Controller shall give at least four (4) weeks’ advance notice in text form. Audits shall take place during LILY’s regular business hours and shall not unreasonably impair LILY’s operations or the security and confidentiality of other customers’ data. A maximum of one (1) audit per calendar year is permitted, unless there is a specific data-protection-related reason (in particular following a personal data breach, a substantiated indication of non-compliance or a corresponding request from a supervisory authority) for an additional audit.
(3) Each party bears its own costs of an audit. LILY may charge a reasonable fee for its own cooperation effort exceeding a reasonable extent.
(4) Where LILY can demonstrate compliance through certifications, attestations or audit reports of independent third parties of equivalent informative value, the Controller shall accept these in priority, without prejudice to its right to an on-site inspection where there is a specific reason under paragraph (2).
§ 9 RETURN OR DELETION AFTER TERMINATION; RETRIEVAL WINDOW
(1) Controller’s choice (Art. 28(3)(g) GDPR). Following the end of this DPA or its termination, LILY shall, at the choice of the Controller, either return or delete all personal data processed under this DPA, unless Union or Member State law requires storage of the personal data. The Controller may choose different options for different data sets (e.g. return of the active data, deletion of copies). The Controller shall communicate its choice within the Exit Period (paragraph (2). In the absence of a choice within that period, LILY deletes the personal data in accordance with paragraph (4), unless required to store such data in accordance with this clause. LILY documents the return or deletion and, on request, provides the Controller with a deletion/return record (date, data categories, method, responsible person) within a reasonable period.
(2) Retrieval window (Exit Period).§ 8(4) Beta Terms shall also apply to the Controller’s export and retrieval of personal data processed under this DPA.
(3) Format of return / export. Where the Controller chooses return, or exercises its export/retrieval right during the Exit Period, LILY makes the personal data available in a structured, commonly used and machine-readable open format, transmitted with encryption according to the state of the art to a recipient designated by the Controller (e.g. via API endpoint or secure download).
(4) Deletion only after retrieval.LILY deletes the personal data processed under this DPA, including User Applications, deployments, Compiled Artefacts and associated configurations, only after the Exit Period has expired or the Controller has confirmed completed retrieval, whichever is earlier (Art. 25(2)(h) Data Act; Art. 28(3)(g) GDPR). Deletion is then carried out completely and irrecoverably within a reasonable period; backup media are overwritten or deleted in the next regular backup rotation, at the latest within ninety (90) days. Deletion is performed in accordance with recognised standards (e.g. DIN 66399, NIST SP 800-88). This expressly supersedes any earlier “delete without obligation to hand over” approach of the alpha programme.
(5) Provider-distress retrieval.Because the Compiled Artefact runs only on LILY infrastructure (lock-in by design), a failure of LILY could otherwise render both retrieval and continued operation impossible. To mitigate this, the retrieval rights under this § 9 are coordinated with the business-continuity arrangements in § 14 of the Principal Agreement and the Continuity Addendum: in a provider-distress or wind-down scenario, the Exit Period and the export mechanics of this § 9 remain available and are integrated into the continuity process, and the technology-disclosure backstop and the conditional disclosure licence support the Controller’s ability to retrieve and continue.
§ 10 LIABILITY
(1) The liability regime of the Principal Agreement applies correspondingly to the liability of the parties under or in connection with this DPA. In particular, § 11 (Warranty and Liability) of the Principal Agreement governs the limitation of LILY’ liability, including the unlimited carve-outs (intent/gross negligence; life, body or health; the Product Liability Act; expressly assumed guarantees; fraudulently concealed defects), the cap calibrated to the fees paid and the separate data-loss/-recovery sub-limit.
(2) The foregoing limitations apply except where mandatory statutory provisions provide otherwise; in particular, liability under Art. 82 GDPR remains unaffected (carve-back). In the relationship to data subjects, each party is liable in accordance with the applicable statutory provisions (Art. 82 GDPR), and the internal apportionment between the parties follows Art. 82(5) GDPR and § 11 of the Principal Agreement.
§ 11 FINAL PROVISIONS
(1) Amendments and additions to this DPA require text form. This also applies to the cancellation or amendment of this text-form requirement.
(2) Should individual provisions of this DPA be or become wholly or partly invalid or unenforceable, the validity of the remaining provisions shall not be affected. A statutory provision applies in place of the invalid one, and the same applies to any gaps.
ANNEX 1 — PROCESSING DETAILS
The details of the processing operations carried out by the Processor are set out below.
| Categories of data subjects whose personal data is processed |
|
| Categories of personal data processed |
|
| Sensitive data processed (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. | n/a (Controller must ensure that no sensitive data are processed by LILY) |
| Nature of the processing | Providing web-based access to LILY's services (SaaS) and related processing operations, such as collection, storage, use and deletion |
| Purpose(s) for which the personal data is processed on behalf of the controller | Providing of the contractually agreed LILY Services and enabling the functionality of the Controller's User Application as intended and instructed by the Controller |
| Duration of the processing | See § 1 (3) of the DPA |
| For processing by (sub-) processors, also specify subject matter, nature and duration of the processing | The information above also applies to processing by sub-processors |
ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES (TOMs)
LILY implements the following technical and organisational measures pursuant to Art. 32 GDPR.
1. Physical access control (confidentiality — Art. 32(1)(b) GDPR)
The Void is operated in certified EU data centres of the sub-processors IONOS SE and Google Ireland Limited, which implement comprehensive physical access controls (man-traps, CCTV, 24/7 security, access logging) per their certifications (incl. ISO/IEC 27001). LILY itself operates no premises with productive data processing; staff access is exclusively remote.
2. Encryption (Art. 32(1)(a) GDPR)
- 2.1 In transit: TLS (current version, with forward secrecy; configuration aligned with BSI TR-02102) for all transmission between CLI and Void, between browser and Platform, and for all employee access to production systems.
- 2.2 At rest (committed and live): AES-256 encryption of data at rest on the Void, including databases and backups. Encryption-at-rest is implemented before the first paying customer; it is not deferred.
- 2.3 Key management: centrally managed keys using a key-management service (KMS) backed by hardware security modules (HSM) or an equivalent solution; documented key-rotation policy with periodic rotation; separation of key-management duties from data access.
3. System and access control (confidentiality — Art. 32(1)(b) GDPR)
- 3.1 Unique personal login accounts per employee (no shared accounts in production).
- 3.2 Multi-factor authentication (2FA) for all admin access to the Void and for employee accounts at cloud providers (Google Cloud Console, IONOS); hardware security keys (e.g. YubiKey) as an additional factor for privileged access.
- 3.3 VPN required for employee access to production systems; automatic account lockout on inactivity or departure (joiner-mover-leaver process with immediate revocation of access rights on departure).
- 3.4 Role-based access control (RBAC) on a need-to-know / least-privilege basis; regular re-certification and review of permissions.
4. Transmission, input and integrity control (integrity — Art. 32(1)(b) GDPR)
- 4.1 Documented interfaces; audit logging of all administrative data exports.
- 4.2 Logging of administrative inputs and configuration changes in production; versioning of infrastructure and configuration changes (infrastructure-as-code).
- 4.3 Integrity checks using SHA-256 or better.
5. Availability, resilience and backups (availability — Art. 32(1)(b)/(c) GDPR)
- 5.1 Provider backups (committed and live): regular automated backups of the data hosted on the Void — incremental backups at least daily and full backups at least weekly — implemented before the first paying customer.
- 5.2 Recovery objectives: RPO (Recovery Point Objective) ≤ 24 hours; RTO (Recovery Time Objective) ≤ 72 hours.
- 5.3 Immutability: backups are held in an immutable / write-once-read-many (WORM) or equivalent tamper-resistant manner to protect against ransomware and unauthorised deletion; backup data is encrypted (No. 2.2).
- 5.4 Restore tests: documented restore procedures, verified by actual restore tests at least semi-annually; results documented.
- 5.5 Infrastructure operated in geo-redundant EU data centres of the sub-processors; malware protection and DDoS protection by appropriate technical measures.
6. Vulnerability handling and regular testing (regular review — Art. 32(1)(d) GDPR)
- 6.1 Penetration test by independent third parties at least annually.
- 6.2 Vulnerability scanning at least monthly (with continuous dependency/SBOM scanning where applicable).
- 6.3 Coordinated vulnerability-handling process .
- 6.4 At least annual internal review of the technical and organisational measures (§ 7(3)).
7. Logging and log retention (integrity / accountability)
- 7.1 Logging of administrative access and security-relevant events on the Void (audit logs).
- 7.2 Audit logs are retained for 90 days and deleted thereafter, within the limits of data minimisation and subject to applicable statutory retention rules.
8. Separation control (confidentiality — Art. 32(1)(b) GDPR)
Logical separation (multi-tenancy) of different users’ data on the Void; separation of production, test and development systems; unambiguous assignment of deployments and User Applications to a single user account. Personal data of different controllers is not combined and is not subject to cross-tenant analysis.
9. Pseudonymisation (Art. 32(1)(a) GDPR)
Where personal data is required in development and test environments, it is processed in pseudonymised form to the extent technically feasible; the assignment/key table is stored separately with restricted access.
10. Sub-processor control (Art. 28(4) GDPR)
DPAs pursuant to Art. 28 GDPR with relevant sub-processors; careful selection and vetting; sub-processors bound to technical and organisational measures meeting Art. 32 GDPR and at least the level of this Annex; sub-processor attestations/audit reports obtained where available.
11. Organisational measures
All employees bound to confidentiality; data-protection and security training at onboarding and at least annually; a written information-security policy (password policy, access rules, incident-response principles); designated responsible contact for data-protection matters; the obligation to appoint a data protection officer is reviewed regularly against the applicable thresholds.
12. Data-protection and security management
Record of processing activities maintained pursuant to Art. 30(2) GDPR; established processes for escalation of data-subject requests to Controller; documented incident-response plan with the notification channel to the Controller under § 5 of this DPA (24-hour clock); regular review and further development of the technical and organisational measures.
ANNEX 3 — SUB-PROCESSORS
The following sub-processors have been approved by the Controller pursuant to § 6 of this DPA.
| Sub-processor | Seat | Processing location | Role / processing activity | Transfer mechanism |
|---|---|---|---|---|
| IONOS SE | Montabaur, Germany | Karlsruhe / Frankfurt, Germany | Server infrastructure (Void), hosting | n/a (EU only) |
| Google Ireland Limited | Dublin, Ireland | EU data centres (europe-west) | Parts of the Void server infrastructure | n/a (EU only) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Dublin, Ireland | EU and United States (Stripe, Inc.) | Payment processing | n/a for EU, EU-U.S. DPF for US |
Version: August 2026 — this version applies to acceptances recorded from that date
Step into the world after the cloud.
Start for free, integrate in minutes, and scale when you need to.
What is coming after the cloud
LILY Labs GmbH, Maudacherstraße 45, 67065 Ludwigshafen am Rhein
Amtsgericht Ludwigshafen am Rhein, HRB 70791
© 2026 LILY Labs GmbH. All rights reserved.