Data Processing Agreement

Version 1.0 · This DPA forms part of the agreement between the customer identified on the applicable order or account (“Customer”, the controller) and LogLens (“LogLens”, the processor) for the LogLens log-analysis service (the “Service”). This DPA is incorporated into the Terms of Service and applies automatically to every account from registration — there is nothing to sign. If your organisation’s procurement process requires a countersigned copy for its records, email privacy@salience.com and we will provide one.

1. Definitions and roles

“GDPR” means Regulation (EU) 2016/679 and, where applicable, the UK GDPR as defined in the Data Protection Act 2018. “Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the GDPR. For all Customer Log Data processed under this DPA, the Customer is the controller and LogLens is the processor.

2. Scope and instructions

LogLens shall process Customer Log Data only: (a) to provide, maintain and support the Service as configured by the Customer; and (b) on the Customer's documented instructions, unless required otherwise by law (in which case LogLens will inform the Customer before processing, unless the law prohibits it). The Customer's configuration of the Service (ingestion sources, retention settings, traffic filters, feature toggles) constitutes documented instructions.

3. Details of processing (Annex A)

4. Confidentiality

LogLens ensures that persons authorised to process Customer Log Data are bound by confidentiality obligations and access it only as needed to operate and support the Service.

5. Security (Annex B)

LogLens implements appropriate technical and organisational measures under GDPR Art. 32, as described in the Security Overview, which forms Annex B of this DPA. These include encryption in transit (TLS 1.2+) and at rest (AES-256), UK-region storage, credential hashing, least-privilege access control, per-customer data partitioning and point-in-time recovery on primary data stores.

6. Sub-processing

The Customer grants general written authorisation for the sub-processors listed at loglens.ai/legal/subprocessors.html (Annex C). LogLens will: (a) give at least 30 days' notice before adding or replacing a sub-processor (via that page and email to the account owner); (b) impose data-protection obligations on each sub-processor no less protective than this DPA; and (c) remain liable for its sub-processors' performance. If the Customer reasonably objects to a new sub-processor on data-protection grounds and no workaround is agreed within 30 days, the Customer may terminate the affected Service with a pro-rata refund of prepaid fees.

7. Data subject rights

Taking into account the nature of the processing, LogLens will assist the Customer with appropriate technical and organisational measures to fulfil data-subject requests (access, erasure, restriction, objection), including searching and deleting records associated with a given IP address on the Customer's instruction. Requests received directly by LogLens from data subjects will be forwarded to the Customer without undue delay.

8. Personal data breach

LogLens will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Log Data, providing the information reasonably required for the Customer's obligations under GDPR Arts. 33–34, and will cooperate in the investigation and remediation.

9. DPIA assistance

LogLens will provide reasonable assistance with data protection impact assessments and prior consultations relating to the Service, primarily via this DPA, the Security Overview and the LIA template.

10. International transfers

Customer Log Data is stored in the United Kingdom (AWS eu-west-2, London). The parties acknowledge: (a) transfers from the EEA to the UK are covered by the European Commission's UK adequacy decision; (b) where the Customer ingests via AWS CloudFront, log records transit AWS infrastructure in the United States prior to storage, under AWS's GDPR Data Processing Addendum incorporating the EU Standard Contractual Clauses and the UK Addendum/IDTA; (c) optional AI features (dashboard assistant, alert summaries) involve processing of derived analytics data by Anthropic in the United States under equivalent safeguards, and can be disabled for the Customer's organisation on request; and (d) LogLens will not otherwise transfer Customer Log Data outside the UK/EEA without ensuring a valid transfer mechanism.

11. Aggregated and anonymised data

LogLens may produce and use aggregated, anonymised statistics that do not identify the Customer, its websites, or any data subject (for example, global counts of crawler user-agents used in public bot research). Such data is not Personal Data and falls outside this DPA.

12. Return and deletion

Upon termination or expiry, LogLens will delete Customer Log Data within 30 days of the Customer's written request or account closure, and in any event will purge residual copies from backups within a further 35 days, unless retention is required by law. Billing records may be retained as required for tax and accounting.

13. Audit and information

LogLens will make available information reasonably necessary to demonstrate compliance with GDPR Art. 28, including responses to reasonable written security questionnaires (no more than annually, unless following a breach). Where the Customer requires an audit, the parties will first rely on documentation and third-party attestations of LogLens's infrastructure providers; any on-site audit shall be subject to reasonable notice, scope, confidentiality and cost agreement.

14. Liability, precedence and term

This DPA is subject to the limitations of liability in the underlying agreement (Terms of Service or a signed order). In case of conflict concerning the processing of Personal Data, this DPA prevails. This DPA takes effect on the Customer's registration or first use of the Service and lasts for the duration of the processing. This DPA is governed by the laws of England and Wales.

How this DPA takes effect

This DPA takes effect automatically for each Customer upon account registration or first use of the Service, as part of the Terms of Service. No signature is required.

Need a countersigned copy for your procurement records, or have questions from your DPO or counsel? Email privacy@salience.com — we respond within one business day.