Data Processing Agreement

    Last updated: August 2026 - Version 2026-08

    1. Parties and Scope

    This Data Processing Agreement ("DPA") forms part of, and is subject to, the Lumenbase Terms of Service (the "Agreement") between Cosmic Fantasy, LLC, a limited liability company registered in the State of Wyoming, USA, with its registered office at 30 N Gould St, Sheridan, WY 82801, USA, which operates Lumenbase ("Lumenbase", "we", "us", or the "Processor") and the customer organization (the "Customer", "you", or the "Controller") that operates a Lumenbase workspace. This DPA applies where, and to the extent that, Lumenbase processes Personal Data on behalf of the Customer in the course of providing the Service.

    This DPA specifically governs the processing of Personal Data that the Customer collects from individuals ("Page Registrants") through the Lumenbase Pages feature: public registration, event, or landing pages published by the Customer ("Pages"). For that data, the Customer is the Controller and Lumenbase is the Processor. Where Lumenbase processes Personal Data for its own purposes (for example, account administration, billing, and securing the Service), Lumenbase acts as an independent controller and its Privacy Policy governs that processing.

    In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails.

    2. Definitions

    Terms such as "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Sub-processor", "Supervisory Authority", and "Personal Data Breach" have the meanings given to them in applicable Data Protection Laws, including the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR. "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement.

    3. Subject Matter and Duration

    The subject matter of the Processing is the provision of the Service to the Customer, including the collection, storage, and management of Personal Data submitted by Page Registrants through the Customer's Pages. The duration of the Processing is the term of the Agreement, plus any additional period during which Lumenbase retains Personal Data as permitted or required under Section 13 (Return and Deletion) and applicable law.

    4. Nature and Purpose of Processing

    Lumenbase processes Personal Data on the Customer's behalf for the purpose of operating the Service and the Pages feature. This includes hosting, storing, organizing, structuring, retrieving, displaying, transmitting, and deleting Personal Data; capturing registrations and consent records; sending transactional confirmation and reminder communications relating to a registration; and otherwise carrying out the Customer's documented instructions. Lumenbase does not sell Personal Data and does not use Page Registrant Personal Data for its own marketing.

    5. Categories of Data Subjects and Personal Data

    Categories of Data Subjects: individuals who register for, or submit information through, the Customer's Pages ("Page Registrants"), and, where applicable, the Customer's own users and contacts whose data is stored in the workspace.

    Categories of Personal Data: identification and contact details (such as name, email address, telephone number, and company or organization name); registration responses and form-field answers configured by the Customer; consent records, including the version of the privacy notice shown and the time of acceptance; and technical metadata associated with a submission, such as IP address, timestamps, and UTM or referral parameters.

    The Customer must not configure its Pages to collect special categories of Personal Data (as defined in Article 9 GDPR) unless it has a lawful basis to do so and has informed Lumenbase in writing. The Customer is responsible for the content of the form fields it creates and for the lawfulness of the data it elects to collect.

    6. Controller Obligations

    The Customer, as Controller, represents and warrants that:

    • It has a valid legal basis for the collection and Processing of Page Registrant Personal Data and for instructing Lumenbase to process it;
    • It will provide Page Registrants with all required information (including a privacy notice) and obtain any consents required by Data Protection Laws before collecting their data. The Pages feature requires the Customer to confirm a privacy notice before a Page can be published;
    • Its instructions to Lumenbase regarding the Processing comply with Data Protection Laws;
    • It is responsible for the accuracy, quality, and legality of the Personal Data and the means by which it acquired the Personal Data.

    7. Processor Obligations

    Lumenbase, as Processor, will:

    • Process Personal Data only on the Customer's documented instructions, including as set out in the Agreement and this DPA, and as necessary to provide and secure the Service, unless required to do otherwise by applicable law (in which case Lumenbase will inform the Customer of that requirement before Processing, unless prohibited from doing so by law);
    • Ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations;
    • Implement and maintain the technical and organizational security measures described in Section 9;
    • Assist the Customer, taking into account the nature of the Processing, in fulfilling its obligations under Sections 8, 9, and 10;
    • Promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.

    8. Data Subject Rights Assistance

    Taking into account the nature of the Processing, Lumenbase will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, to respond to requests from Data Subjects to exercise their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection). The Service provides self-service tools that allow the Customer to access, export, correct, and delete Page Registrant records directly. If Lumenbase receives a request from a Data Subject relating to the Customer's data, Lumenbase will, where legally permitted, direct the Data Subject to the Customer and will not respond to the request itself except on the Customer's instructions.

    9. Security Measures

    Lumenbase implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing. These measures include, as appropriate:

    • Encryption of Personal Data in transit and at rest;
    • Logical access controls, including role-based permissions and row-level security that isolate each workspace's data;
    • Authentication controls for the Service and administrative systems;
    • Regular logging, monitoring, and backup of production systems;
    • Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems;
    • Procedures for regularly testing and evaluating the effectiveness of these measures.

    10. Personal Data Breach Notification

    Lumenbase will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. The notification will, to the extent known and reasonably available to Lumenbase, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Lumenbase will provide reasonable cooperation and assistance to help the Customer meet its own breach-notification obligations to Supervisory Authorities and affected Data Subjects. A notification under this section is not an acknowledgement by Lumenbase of fault or liability.

    11. Sub-processors

    The Customer provides a general authorization for Lumenbase to engage Sub-processors to support the provision of the Service (for example, cloud hosting and database infrastructure, transactional email delivery, and payment processing). Lumenbase will impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, and Lumenbase remains responsible for the performance of its Sub-processors' obligations.

    Lumenbase publishes its current list of Sub-processors, including each Sub-processor's purpose and processing region, at lumenbase.io/legal/subprocessors. Lumenbase will give the Customer reasonable advance notice of any intended addition or replacement of a Sub-processor before that Sub-processor begins Processing, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer reasonably objects and the parties cannot agree on a resolution, the Customer may terminate the affected part of the Service.

    12. International Transfers

    Lumenbase and its Sub-processors may process Personal Data in countries other than the country in which the Customer or its Data Subjects are located. Where such Processing involves a transfer of Personal Data subject to GDPR or UK GDPR to a country that has not been recognized as providing an adequate level of protection, Lumenbase will ensure an appropriate transfer mechanism is in place, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with any supplementary measures required to protect the Personal Data.

    13. Return and Deletion of Personal Data

    Upon termination or expiry of the Agreement, Lumenbase will, at the Customer's choice, delete or return the Personal Data processed on the Customer's behalf, and delete existing copies, unless applicable law requires continued storage. The Customer may also delete Page Registrant records and export its data at any time during the term using the Service's self-service tools. Routine backups containing Personal Data are deleted in accordance with Lumenbase's standard backup-retention cycle.

    14. Audit and Demonstration of Compliance

    Lumenbase will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. To minimize disruption, the Customer agrees that such audits will be conducted on reasonable prior written notice, no more than once per year (except where required by a Supervisory Authority or following a Personal Data Breach), during normal business hours, and subject to confidentiality obligations. Lumenbase may satisfy an audit request by providing relevant certifications, third-party audit reports, or security documentation where these reasonably address the Customer's request.

    15. Liability

    Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA does not limit any rights a Data Subject may have under Data Protection Laws.

    16. Term and Changes

    This DPA takes effect on the date the Customer accepts it (including at workspace signup) or begins using the Pages feature, whichever is earlier, and remains in effect for as long as Lumenbase processes Personal Data on the Customer's behalf. We may update this DPA from time to time to reflect changes in our Processing or in Data Protection Laws; material changes will be communicated through the Service or by updating the "Last updated" date, and continued use of the Service constitutes acceptance of the updated DPA.

    17. Contact

    For questions about this Data Processing Agreement, or to exercise rights or make requests described above, please contact us at legal@lumenbase.io.