Legal

Data Processing Addendum

Effective 15 September 2026 · Version 2026-09-15

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between you, the customer, and Zachary Tyler Lehmann trading as LTNA (ABN 80 226 912 105). It applies when LTNA processes personal information on your behalf in providing LTNA Hosting.

It is intended to meet the requirements of the Australian Privacy Act 1988, the EU General Data Protection Regulation, the UK GDPR and similar laws, to the extent each applies. If this DPA conflicts with the Terms about personal information, this DPA prevails. Capitalised terms have the meanings given in the Terms.

1. Roles

For Customer Data and Visitor Data, you are the controller and LTNA is your processor, or the equivalent roles under the law that applies. You decide why and how that information is processed, and we process it only to provide the Services.

For personal information about you and the people who use your Account, such as account and billing details, LTNA is the controller and our Privacy Policy applies instead of this DPA.

2. Details of the processing

ItemDetails
Subject matterHosting, building, running and monitoring your sites and applications, and managing connected services on your instructions.
DurationFor as long as you use the Services, and until the information is removed under the Return and removal section.
Nature of processingStorage, transmission, building and running of code, logging, caching, aggregation into analytics, and removal.
PurposeProviding, securing and supporting the Services under the Terms.
Types of personal informationAnything contained in Customer Content; visitor request data such as IP addresses, browser details, referrers and requested URLs; the contents of build and runtime logs; and information in databases and connected services you manage through the Services.
People it relates toYour end users, visitors to your sites, your staff and contractors, and anyone whose information you include in Customer Content.
Sensitive informationDon’t use the Services to process sensitive or special category information, such as health information, unless you have assessed that the measures in this DPA are adequate for it.

3. Our obligations

We will:

  • process the personal information only on your documented instructions, which are the Terms, this DPA and your use and configuration of the Services, unless the law requires otherwise, and tell you if we believe an instruction breaks data protection law;
  • make sure anyone authorised to process it is bound by confidentiality;
  • apply the measures in the Security measures section;
  • help you, taking into account the nature of the processing, to respond to requests from individuals exercising their rights, and with security, breach notification, impact assessments and consultation with regulators; and
  • make available the information reasonably needed to show we comply with this DPA, as set out in the Information and audits section.

4. Your obligations

You confirm you have a lawful basis for the processing, have given any notices and obtained any consents needed for us to process the personal information under this DPA, and that your instructions comply with data protection law.

5. Security measures

We maintain the technical and organisational measures below, and may improve them over time without reducing the overall protection:

  • Row-level access controls that limit each customer’s records to their own Account.
  • Encryption of secrets, environment variables and connected-service credentials at rest in a managed vault.
  • Encryption in transit between browsers, our edge and our servers, including encrypted tunnels between the edge and our servers.
  • Isolation of customer workloads in containers with restricted privileges, a system call filter, user namespace separation and resource limits.
  • Network controls that stop customer workloads reaching cloud metadata services, private networks and other customers’ containers, with optional allowlists for outbound traffic.
  • Credentials for customers’ Supabase projects fetched only when needed and never stored.
  • Removal of internal network details from logs shown to customers, and short log retention: runtime logs 7 days, build logs 30 days.
  • Rate limiting, and audit logging of account and administrative actions.
  • Administrative access to production systems restricted to LTNA’s operator.

6. Sub-processors

You authorise us to use the sub-processors listed on our Sub-processors page. We use only providers that commit to protecting personal information under their own data processing terms, and we remain responsible to you for their performance under this DPA.

We will give at least 30 days’ notice before adding a new sub-processor, by updating that page and telling you by email or in the dashboard. You may object on reasonable data protection grounds during that period. If we can’t address the objection, you may end the affected Services and receive a refund of fees paid in advance for the unused period.

7. Personal data breaches

We will tell you without undue delay after becoming aware of a breach affecting personal information we process for you. We will share what we know about its nature, its likely consequences and the measures taken, and update you as we learn more. Telling you is not an admission of fault.

8. Information and audits

On written request, and no more than once a year unless a regulator requires it or a breach has occurred, we will answer reasonable written questions about our compliance with this DPA. If that isn’t enough to demonstrate compliance, we will cooperate with a reasonable audit at your cost, on reasonable notice, subject to confidentiality and without access to other customers’ information.

9. Return and removal

When your Account closes, we remove the personal information we process for you within 30 days, except where the law requires us to keep it. Information in logs that expire automatically is removed when they expire. Before your Account closes you can remove your own projects and retrieve the information you need.

10. International transfers

We store customer and account information in Australia. Some of our providers process it in other countries, as listed on the Sub-processors page.

Where the GDPR or UK GDPR applies and personal information is transferred from the European Economic Area, Switzerland or the United Kingdom to a country without an adequacy decision, including Australia, the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where relevant, apply to that transfer and are incorporated into this DPA by reference, with LTNA as data importer.

11. Australian Privacy Act

Where the Privacy Act 1988 applies, we handle personal information we process for you consistently with the Australian Privacy Principles as they apply to that processing, and we don’t use or disclose it except to provide the Services or as the law requires.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms, except where the law does not allow them to apply.

13. Contact

Zachary Tyler Lehmann trading as LTNA (ABN 80 226 912 105), Victoria, Australia.

This is version 2026-09-15. Earlier versions are available on request from [email protected].