数据处理协议(DPA)
最后更新:2026 年 8 月 7 日
本《数据处理协议》(“DPA”)作为 Layrax(“我们”,运营方 【请填写:公司全称】)与购买 Team / Enterprise 方案的企业客户(“客户”)之间主协议的附件,适用于我们为客户处理个人数据的场景。若本 DPA 与主协议冲突,就个人数据处理事宜以本 DPA 为准。如需签署本 DPA,请联系 sales@layrax.com。
1. 角色与处理
依据 GDPR,客户为“控制者”,Layrax 为“处理者”。我们仅按客户的书面指令(通过服务的功能配置传达)处理个人数据,用于提供 AI 室内装修设计服务。
2. 处理目的与期限
处理目的限于提供与维护客户订阅的服务(软装布局、图纸生成、渲染、团队协作)。我们仅在主协议存续及事后必要期限内处理数据,并依适用法律保留账务与税务记录。
3. 数据类别与数据主体
可能涉及:客户成员账号信息(姓名、邮箱)、客户上传的户型图 / 图纸 / 空间图像与项目内容、使用与设备日志。数据主体主要为客户成员及经其授权的最终用户。
4. 子处理商
我们聘用以下类别的子处理商(最新清单与更新见《子处理商清单》页):云端基础设施托管、AI 模型与图像处理、在线支付处理、产品分析(PostHog)。我们与各子处理商签订书面协议,提供不低于本 DPA 的保护标准,并就其违反向客户承担责任。未经客户同意,我们不会新增实质性子处理商;我们会在清单变更前至少 30 天通知客户,客户可在此类变更生效前提出异议。
5. 安全措施
我们采取合理的技术与组织措施,包括:传输加密(TLS)、静态数据加密、最小权限与基于角色的访问控制、定期安全评估、员工保密义务与安全培训。
6. 数据泄露通知
如发生涉及客户个人数据的安全事件,我们将在知悉后无不必要延迟地通知客户,并在可行范围内提供相关信息以协助调查与缓解。对于客户可能需要向监管机关通报的情形,我们通常在知悉后 72 小时内通知客户,以便其履行通报义务。
7. 协助数据主体行权与 DPIA
我们将在合理范围内协助客户响应数据主体的权利请求,并配合其进行数据保护影响评估(DPIA)及与监管机关的沟通(在适用法律允许且客户承担相应费用的情况下)。
8. 审计权
在合理事先通知并遵守保密义务的前提下,客户可要求我们提供必要信息或可获得的审计报告 / 认证(如 ISO、SOC 类),以核验我们对本 DPA 的遵守情况。如需独立审计,应就范围、费用与时间另行约定。
9. 跨境传输
如涉及向 EEA / 英国以外传输个人数据,我们将依据欧盟委员会《标准合同条款》(SCCs)或英国《国际数据传输协议》(IDTA)等适当保障措施进行,并对接收方进行传输影响评估。
10. 数据删除与返还
主协议终止后,客户可要求返还或删除其个人数据;我们将在合理期限内(通常 30 至 90 天内)完成删除或返还,除非适用法律要求保留,届时我们将仅保留法律要求范围内的数据并继续依本 DPA 保护。
11. 变更
我们可能更新本 DPA,重大变更将通知客户。
12. 联系与签署
- 运营方:【请填写:公司全称】(注册号 【请填写:注册号】)
- 销售 / DPA 签署:sales@layrax.com
- 隐私事务:privacy@layrax.com
Data Processing Agreement (DPA)
Last updated: August 7, 2026
This Data Processing Agreement ("DPA") forms an addendum to the main agreement between Layrax ("we", "us", operated by [Please fill in: legal entity name]) and enterprise customers purchasing Team / Enterprise plans ("Customer"), and applies where we process personal data on behalf of Customer. Where this DPA conflicts with the main agreement regarding the processing of personal data, this DPA prevails. To execute this DPA, contact sales@layrax.com.
1. Roles and Processing
Under the GDPR, Customer is the "Controller" and Layrax is the "Processor". We process personal data only on Customer's documented instructions (conveyed through the Service's configuration) to provide the AI interior design service.
2. Purpose and Duration
Processing is limited to providing and maintaining the subscribed Service (soft-furnishing layout, drawing generation, rendering, team collaboration). We process data only for the duration of the main agreement and any necessary period thereafter, retaining accounting and tax records as required by law.
3. Categories of Data and Data Subjects
This may include: Customer's member account information (name, email), Customer-uploaded floor plans / drawings / space images and project content, and usage and device logs. Data subjects are primarily Customer's members and end users authorized by Customer.
4. Sub-processors
We engage sub-processors in the following categories (the current list and updates are published on the Sub-processor List page): cloud infrastructure hosting, AI model and image processing, online payment processing, and product analytics (PostHog). We enter written agreements with each sub-processor providing protection no less stringent than this DPA, and remain liable to Customer for their breach. We will not add a material sub-processor without Customer's consent; we will notify Customer of changes to the list at least 30 days in advance, and Customer may object before a change takes effect.
5. Security Measures
We take reasonable technical and organizational measures, including: encryption in transit (TLS), encryption of data at rest, least-privilege and role-based access control, regular security assessments, and employee confidentiality obligations and security training.
6. Breach Notification
If a security incident involving Customer's personal data occurs, we will notify Customer without undue delay after becoming aware of it, and provide reasonably available information to assist with investigation and mitigation. Where Customer may need to notify a supervisory authority, we will typically notify Customer within 72 hours of becoming aware, to enable Customer to meet its reporting obligations.
7. Assistance with Data Subject Rights and DPIA
We will reasonably assist Customer in responding to data subject rights requests, and cooperate with data protection impact assessments (DPIA) and supervisory authority communications (where permitted by law and at Customer's reasonable expense).
8. Audit Rights
Upon reasonable prior notice and subject to confidentiality, Customer may request the necessary information or available audit reports / certifications (e.g., ISO, SOC-type) to verify our compliance with this DPA. Independent audits, if needed, will be agreed separately on scope, fees, and timing.
9. Cross-Border Transfers
Where personal data is transferred outside the EEA / UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), and conduct a transfer impact assessment of the recipient.
10. Data Deletion and Return
On termination of the main agreement, Customer may request return or deletion of its personal data; we will complete deletion or return within a reasonable period (typically 30 to 90 days), unless retention is required by law, in which case we retain only the minimum required and continue to protect it under this DPA.
11. Changes
We may update this DPA and will notify Customer of material changes.
12. Contact and Execution
- Operator: [Please fill in: legal entity name] (registration no. [Please fill in: registration number])
- Sales / DPA execution: sales@layrax.com
- Privacy matters: privacy@layrax.com