Data Processing Agreement

A clear controller–processor boundary.

The starting contractual framework for personal data LearnDo OÜ processes on behalf of an ExpoLeadZ business customer.

Version: 26 August 2026 · Article 28 contractual framework

1. Parties and application

This Data Processing Agreement (“DPA”) forms part of the agreement for ExpoLeadZ between LearnDo OÜ, registry code 16818398, Estonia (“LearnDo” or “Processor”), and the business customer identified in the account or order (“Customer”). It applies when LearnDo processes personal data on Customer's behalf. Customer is the controller or, where Customer processes for another controller, a processor authorized to appoint LearnDo as subprocessor. Terms such as personal data, controller, processor, data subject, and processing have their meaning under applicable data-protection law.

2. Scope, duration, and instructions

LearnDo processes Customer Personal Data to provide, secure, maintain, support, and terminate the ExpoLeadZ Service for the term of the customer agreement and any limited return, deletion, legal, or backup period afterward. The agreement, feature configuration, Customer's authorized user actions, support requests, and lawful written instructions comprise Customer's documented instructions. LearnDo will process only on those instructions unless law requires otherwise and, where legally permitted, will inform Customer of that requirement. LearnDo will notify Customer if an instruction appears to violate applicable data-protection law.

3. Processing details

4. Confidentiality and personnel

LearnDo will limit access to personnel and approved subprocessors who need it to deliver or secure the Service, ensure authorized personnel are bound by confidentiality, and maintain appropriate access management. Provider credentials and tokens remain in server-side secret stores; they are not exposed to ordinary customer users or mobile/browser bundles.

5. Security

Taking into account the nature, context, cost, and risk, LearnDo will maintain appropriate technical and organizational measures. Current measures include encrypted transport; row-level tenant isolation; private object storage with tenant-bound paths; restricted server functions; role, membership, plan, and event checks; encrypted mobile session and offline queue material; signed webhook verification; provider event and workflow idempotency; server-only provider secrets; logging boundaries; and reviewed suppression and send-safety controls. LearnDo regularly tests these boundaries but does not claim a certification it has not obtained.

6. Subprocessors

Customer gives general authorization for the subprocessors in the published Subprocessor List. LearnDo will require each processor subprocessor to protect Customer Personal Data through applicable written terms. We will publish a material addition or replacement before it begins processing where reasonably possible. Customer may object within 30 days on reasonable data-protection grounds by contacting contact@expoleadz.com. The parties will try in good faith to resolve the concern through a safeguard, alternative, or discontinuation of the affected feature; if that is not reasonably possible, Customer may stop that feature or terminate the affected Service in accordance with the agreement.

7. International transfers

LearnDo will not make a restricted transfer without an applicable legal mechanism. Depending on the provider and route, that may be an adequacy decision, the European Commission Standard Contractual Clauses, the UK Addendum or IDTA, or another valid mechanism. LearnDo will use the module and supplementary measures appropriate to the parties' roles. A provider-specific mechanism is relied on only after its contractual coverage is verified. This DPA does not represent that a particular transfer mechanism applies where the relevant provider and processing route have not been enabled.

8. Data-subject requests

Taking account of the processing, LearnDo will provide reasonable technical and organizational assistance for Customer to answer requests for access, correction, erasure, restriction, portability, objection, or other applicable rights. LearnDo will not independently decide a request for Customer-controlled data unless law requires it or Customer authorizes it. If LearnDo receives such a request, it will direct the person to Customer or notify Customer without undue delay, while protecting identity and confidentiality.

9. Security incidents and regulatory assistance

LearnDo will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data and provide information reasonably available for Customer's legal duties. LearnDo will take reasonable containment and remediation steps and cooperate with Customer's required impact assessment, prior consultation, breach assessment, or regulator enquiry, taking account of the processing and information available. Notice is not an admission of fault.

10. Return, deletion, and retention

At the end of the Service, LearnDo will provide the available export and deletion path and, at Customer's choice where technically and legally applicable, delete or return Customer Personal Data. Limited copies may remain in protected backups until overwritten and in tax, billing, security, audit, suppression, or dispute records where law or a documented legitimate need requires retention. Such retained data remains protected and is not used for an incompatible purpose. Company-owned records are not erased merely because one employee deletes their identity.

11. Compliance information and audits

LearnDo will make information reasonably necessary to demonstrate compliance available, including relevant architecture, test, provider, and security information subject to confidentiality. If that is insufficient, Customer may request one proportionate audit per year by itself or an independent qualified auditor, with reasonable notice, scope, security controls, and minimal disruption. Additional or customer-specific work may be charged at a reasonable rate unless an incident or material non-compliance makes that inappropriate. Audits must not expose other customers, credentials, or system vulnerabilities.

12. Customer obligations

Customer will provide lawful, documented instructions; ensure a legal basis and required notices or consent; collect and use data fairly; configure access and retention appropriately; respond to data subjects; avoid unsupported sensitive data; and ensure its use of capture, research, correspondence, and automation complies with the recipient's jurisdiction. Customer represents that it may disclose Customer Personal Data to LearnDo and that its instructions do not infringe another person's rights.

13. Liability, conflict, and regional addenda

Liability under this DPA follows the liability framework in the governing customer agreement, subject to mandatory law. If this DPA conflicts with the general Terms on data processing, this DPA controls. Applicable SCCs or mandatory regional clauses control over inconsistent provisions for the relevant transfer. Additional US state service-provider/contractor, Canadian, Australian, UK, or other regional terms may be attached where Customer's legal status and processing require them.

14. Contact

DPA, privacy, and subprocessor questions may be sent to contact@expoleadz.com. LearnDo OÜ's registered address is published in our Company Information.