Skip to content

Data Processing Addendum

Effective 2026-08-18 · Version 2.5

This Data Processing Addendum, including its Annexes ("DPA"), forms part of and is incorporated by reference into the agreement between the customer ("Customer") and Vista del Lago Software LLC, a Delaware limited liability company ("Vista del Lago", "we", "us"), which operates the Lonzo service under that name. This DPA forms part of the agreement governing Customer's use of the Lonzo service (the "Service"). The master agreement is the Lonzo Terms of Use (the "Agreement"). This DPA governs the Processing of Personal Data that Vista del Lago carries out on behalf of Customer in connection with Lonzo.

Where Customer is a business, organization, or individual who is a Controller (or a Processor acting for another Controller) of Personal Data that is subject to Data Protection Laws, this DPA applies and prevails over any conflicting term of the Agreement with respect to that Personal Data. By accepting the Agreement, or by using the Service after this DPA is made available, Customer agrees to this DPA on its own behalf and, to the extent required, on behalf of its Authorized Users.


1. Definitions

Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. In this DPA:

  • "Actor" means the identity-bound execution scope of a single human account holder within the Fabric architecture underlying Lonzo. Each Actor's data is cryptographically isolated from every other Actor's data as described in Annex II.
  • "Actor-Scoped Data" means Personal Data that is bound to, and encrypted under keys unique to, a single Actor. The derived search-index rows described in Annex II item 1a are projections of Actor-Scoped Data, bound to a single Actor but not themselves so encrypted.
  • "Authorized User" means an individual whom Customer permits to use the Service under Customer's account.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR, and equivalent terms in other Data Protection Laws are construed accordingly.
  • "CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, and its regulations.
  • "Customer Personal Data" means Personal Data that Vista del Lago Processes on behalf of Customer under the Agreement, as described in Annex I.
  • "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable: (a) the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"); (b) the GDPR as incorporated into the law of the United Kingdom ("UK GDPR") together with the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection ("FADP"); and (d) US State Privacy Laws.
  • "DPF" means the EU–US Data Privacy Framework, the UK Extension thereto, and the Swiss–US Data Privacy Framework.
  • "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
  • "Sub-processor" means any third party engaged by Vista del Lago that Processes Customer Personal Data. The current list of Sub-processors is published at lonzo.ai/legal/subprocessors.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022).
  • "US State Privacy Laws" means, as applicable, the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and other comprehensive US state privacy statutes then in effect.

2. Roles and Scope of Processing

2.1 Roles. As between the parties and with respect to Customer Personal Data, Customer is the Controller (or, where Customer is itself a Processor acting on behalf of a third-party Controller, a Processor), and Vista del Lago is the Processor. Vista del Lago Processes Customer Personal Data only on behalf of Customer.

2.2 Customer instructions. Vista del Lago Processes Customer Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do otherwise by applicable law (in which case Vista del Lago will inform Customer of that legal requirement before Processing, unless the law prohibits such notice). The Agreement, this DPA, and Customer's use of the Service in accordance with the Agreement together constitute Customer's complete and final documented instructions to Vista del Lago. Vista del Lago will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

2.3 Customer responsibilities. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for the lawful basis on which it was collected, including providing any notices and obtaining any consents required for Vista del Lago to Process Customer Personal Data as contemplated by the Agreement. Customer is solely responsible for compliance obligations relating to any email, calendar, contact, or task communications initiated through the Service, including applicable anti-spam laws.

2.4 Vista del Lago as Controller. Vista del Lago acts as an independent Controller for a limited set of Processing that is not carried out on Customer's behalf, namely: (a) account, authentication, and billing administration; (b) fraud prevention, abuse detection, and security of the Service; (c) meeting Vista del Lago's own legal and regulatory obligations; and (d) creating and using de-identified or aggregated data that does not identify Customer, any Authorized User, or any Data Subject, to operate, secure, and improve the Service. Vista del Lago's Processing as a Controller is governed by Vista del Lago's Privacy Policy, not this DPA.

2.5 No sale or sharing. Vista del Lago does not sell Customer Personal Data and does not share it for cross-context behavioral advertising. Vista del Lago does not retain, use, or disclose Customer Personal Data for any purpose other than the specific purpose of performing the Service, or as otherwise permitted by Data Protection Laws.

2.6 Special categories of data. The Service is not designed to identify, target, or specially handle special categories of Personal Data (GDPR Art. 9) or comparable sensitive data, and Vista del Lago does not solicit such data. Customer acknowledges, however, that because the Service Processes a connected mailbox, calendar, contact list, and task list in their entirety at Customer's direction, special-category data present in that content will in practice be Processed — including by decryption for inference under Section 13 — and Vista del Lago cannot and does not represent that it is excluded, filtered, or separately handled. Customer is the Controller of that Processing and is solely responsible for identifying and satisfying its own Art. 9(2) condition and any equivalent condition under other Data Protection Laws, and for the notices and consents that condition requires. Customer must not use the Service to Process special-category data where doing so would require safeguards the Service does not provide; the safeguards the Service does provide are those in Annex II, and no others are represented. Vista del Lago's own Art. 9(2) position for consumer users, where it is not acting under this DPA, is described in its Privacy Policy.

3. Confidentiality

Vista del Lago ensures that persons authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are made aware of the confidential nature of the data. Access to Customer Personal Data is limited to personnel who require it to perform the Agreement.

4. Security

4.1 Security measures. Vista del Lago implements and maintains the technical and organizational measures set out in Annex II to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects. These measures are further described in the Lonzo security overview at lonzo.ai/legal/security-overview.

4.2 Committed measures. The measures in Annex II are contractual commitments, not merely a description of current practice. Vista del Lago may update them from time to time provided the updates do not materially reduce the overall level of protection.

5. Sub-processors

5.1 General authorization. Customer grants Vista del Lago general written authorization to engage Sub-processors to Process Customer Personal Data, subject to this Section 5. The current list of Sub-processors, including their Processing activities and locations, is published at lonzo.ai/legal/subprocessors.

5.2 Flow-down. Vista del Lago imposes on each Sub-processor, by written contract, data-protection obligations that are at least as protective as those in this DPA, to the extent applicable to the nature of the Sub-processor's services. Vista del Lago remains fully liable to Customer for the performance of each Sub-processor's obligations.

5.3 Change notice and objection. Vista del Lago gives notice of intended additions or replacements of Sub-processors by posting them on the Sub-processor page at lonzo.ai/legal/subprocessors, which is the notice mechanism for the purposes of this Section and of Clause 9 of the SCCs; that page carries the date it was last updated. Customer should check the page, and Vista del Lago will in addition notify Customer by email at the address on Customer's account where Customer has asked in writing to privacy@lonzo.ai to be notified that way. Vista del Lago will provide such notice at least thirty (30) days before the new Sub-processor begins Processing Customer Personal Data. Customer may object on reasonable data-protection grounds within thirty (30) days of the notice by writing to privacy@lonzo.ai. If Customer does not object within that period, the change is deemed accepted. If Customer objects and the parties cannot resolve the objection, Customer may, as its sole remedy, terminate the portion of the Service that cannot be provided without the objected-to Sub-processor, without penalty.

6. International Transfers

6.1 Location. Vista del Lago Processes Customer Personal Data in the United States. Where Customer Personal Data originates in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the transfer mechanisms in this Section 6 apply.

6.2 EEA transfers. The SCCs are hereby incorporated by reference and apply to transfers of Customer Personal Data from the EEA to Vista del Lago, with Module Two (Controller to Processor) applying where Customer is a Controller and Module Three (Processor to Processor) applying where Customer is a Processor. The SCCs are completed as follows: (a) Clause 7 (docking clause) does not apply; (b) Clause 9, Option 2 (general written authorization) applies, with the notice period specified in Section 5.3; (c) Clause 11 (independent dispute resolution) does not apply; (d) Clause 17 (governing law) is the law of Ireland; and (e) Clause 18 (forum and jurisdiction) is the courts of Ireland. The competent supervisory authority is the Irish Data Protection Commission (DPC). Annex I and Annex II to this DPA populate the corresponding annexes to the SCCs.

6.3 UK transfers. Transfers from the United Kingdom are governed by the SCCs as completed in Section 6.2, as amended by the UK Addendum, which is incorporated by reference. Tables 1–3 of the UK Addendum are populated by the corresponding information in Section 6.2 and the Annexes; Table 4 selects "Importer and Exporter."

6.4 Swiss transfers. Transfers from Switzerland are governed by the SCCs as completed in Section 6.2, with the following adjustments: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may enforce their rights in Switzerland (Clause 18(c)).

6.5 Transfer basis — primary and fallback. The SCCs (as completed above), the UK Addendum, and the Swiss adjustments are the primary transfer mechanism for EEA, UK, and Swiss transfers respectively. Vista del Lago additionally intends to rely on the EU–US Data Privacy Framework, the UK Extension thereto, and the Swiss–US Data Privacy Framework once Vista del Lago self-certifies to those frameworks. Vista del Lago is not yet certified under the DPF and makes no claim that the DPF is currently an active transfer mechanism. Where and for so long as Vista del Lago maintains an active certification under the DPF, the DPF becomes a transfer mechanism for transfers covered by that certification, and the SCCs (with the UK Addendum and Swiss adjustments) serve as the fallback mechanism that applies automatically if the DPF certification lapses or the DPF is invalidated or suspended for the relevant jurisdiction.

6.6 SCC signatory details. The parties' details for Annex I of the SCCs are set out in Annex I to this DPA. The data importer is Vista del Lago Software LLC, 18381 Vista del Lago, Yorba Linda, CA 92886, USA; authorized contact for data-protection matters: privacy@lonzo.ai.

6.7 Article 27 EEA/UK representative. The EEA and the United Kingdom are in scope. Because Vista del Lago has no establishment in the EEA or the United Kingdom, Vista del Lago is required to designate an EEA representative and a UK representative under GDPR Art. 27 and UK GDPR Art. 27. That designation is in progress and is not yet complete, and no representative is named in this DPA today. Vista del Lago undertakes to complete the designation and to publish the representative's name and registered EEA and UK addresses in this Section, and will notify Customer of the completed designation on request. In the interim, and without limiting Customer's rights or Vista del Lago's obligations, correspondence that would be addressed to a representative may be sent to privacy@lonzo.ai (attn: "EU Representative" / "UK Representative"), which Vista del Lago handles on the same terms and within the same deadlines.

Data Protection Officer. Vista del Lago has not appointed a Data Protection Officer, as one is not required (no large-scale systematic monitoring or special-category processing as a core activity). Data-protection contact: privacy@lonzo.ai.

7. Data Subject Requests

7.1 Assistance. Taking into account the nature of the Processing, Vista del Lago assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights under Data Protection Laws.

7.2 Self-service, request-based assistance, and redirection. Because Customer Personal Data is Actor-scoped by construction, Customer or its Authorized Users can access and correct Actor-Scoped Data in the Service, disconnect the connected Google account (which revokes Vista del Lago's access to it), and delete an individual assistant conversation. Export, deletion of an account and its data, and deletion of individual categories of data are request-based: Vista del Lago fulfils them on request to privacy@lonzo.ai within thirty (30) days of a verified request. Account deletion has two additional routes to the same request: a public page requiring no sign-in at lonzo.ai/delete-account, and an in-product control in the Service (Account → Delete account) that an Authorized User can use to raise the request from an authenticated session. All three routes reach the same manual fulfilment — the in-product control records and attributes the request; it does not itself perform the erasure, and no Vista del Lago copy presents it as doing so. For export and for deletion of individual categories of data there is no in-product control at all, and Vista del Lago states that plainly rather than describe a control Customer would look for and not find. If a Data Subject request is made directly to Vista del Lago regarding Customer Personal Data, Vista del Lago will, unless legally required to respond, promptly redirect the Data Subject to Customer, who is responsible for responding.

7.3 Costs. Where a request is unreasonable or repetitive, Vista del Lago may charge a reasonable, pre-agreed fee for that assistance.

8. Assistance with Compliance

Taking into account the nature of Processing and the information available to Vista del Lago, Vista del Lago provides reasonable assistance to Customer with: (a) data protection impact assessments under GDPR Art. 35; (b) prior consultations with supervisory authorities under GDPR Art. 36; and (c) Vista del Lago's obligations under GDPR Arts. 32–36. Vista del Lago maintains records of its Processing activities as required by GDPR Art. 30(2).

9. Personal Data Breach Notification

9.1 Notice. Vista del Lago notifies Customer without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 Content. The notice describes, to the extent known and as it becomes available: the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.

9.3 Forensic capability. Vista del Lago's immutable per-decryption audit log (Annex II item 3) enables Vista del Lago to characterize the scope of any incident involving decryption of Actor-Scoped Data on Vista del Lago's systems with a high degree of precision. As Annex II item 3a states, decryption performed by the Lonzo application on an Authorized User's own device is not recorded in that log, and the log therefore does not bound an incident confined to such a device.

10. Audit and Information Rights

10.1 Information. Vista del Lago makes available to Customer information reasonably necessary to demonstrate compliance with this DPA and GDPR Art. 28.

10.2 Third-party reports. Vista del Lago does not currently hold a third-party audit report or certification (no SOC 2 or ISO 27001; see the security overview). In the first instance, Vista del Lago satisfies Customer's audit right by answering reasonable written security questionnaires and sharing its security documentation as Confidential Information. Where Vista del Lago later obtains a third-party audit report or certification, it will make the then-current report available as Confidential Information.

10.3 On-site audits. Where third-party reports are insufficient to demonstrate compliance, Customer (or an independent auditor mandated by Customer and not a competitor of Vista del Lago) may conduct an audit no more than once per calendar year (and additionally following a Personal Data Breach), on at least thirty (30) days' prior written notice, during business hours, subject to confidentiality, and without unreasonably disrupting Vista del Lago's operations. Customer bears the costs of any such audit.

11. Deletion and Return

11.1 On termination. Upon termination or expiry of the Agreement, Vista del Lago deletes or returns all Customer Personal Data at Customer's election within thirty (30) days, and deletes existing copies held in encrypted backups as those expire, within ninety (90) days, unless retention is required by applicable law. The two windows are different because they are different mechanisms, and Section 11.2 states which is which; Annex II item 8 states the backup cycle that fixes the longer one. Both windows are reconciled with the deletion-completion SLA in the Lonzo data retention & deletion policy, which states the same pair of numbers; if either changes, both documents change, and an automated check against Vista del Lago's backup configuration fails its build if a published number drifts from the configured window. Where Customer elects return rather than deletion, the return of data is effected on request to privacy@lonzo.ai within thirty (30) days of a verified request, and Vista del Lago provides the Actor-Scoped Data it holds in a portable, machine-readable format (JSON and/or mbox) before deletion. Return is request-based; the Service does not currently provide an in-product export control.

11.2 What deletion consists of. Deletion under this Section is: (a) removal of Customer Personal Data from live systems, together with revocation of the connected-account authorization and stored tokens, completing within thirty (30) days; and (b) expiry of residual copies from encrypted backups as those age out on the 90-day rolling purge cycle in Annex II item 8, completing within ninety (90) days. After leg (a) no system Vista del Lago operates serves the data; after leg (b) Vista del Lago does not retain it at all, except as Section 11.3 permits. A residual copy in an encrypted backup cannot be reached individually before its cycle expires: the backup store admits writes only, holds each object under a retention lock, and grants the production fleet no delete permission — which is what makes the backup window a bound rather than a target.

Both numbers in Section 11.1 changed on 2026-08-17, and one of them was a correction. This Section previously stated that both legs complete within thirty (30) days, on the basis of a 30-day figure that was the window of one backup store of three. The longest — the nightly database export, which carries Actor rows — is retained for ninety (90) days, so leg (b) could not and did not complete inside the stated window. Leg (a) is unchanged, and is the leg after which no live system serves the data. Vista del Lago corrected the representation rather than shortening the retention, because the ninety days is disaster-recovery depth on which restoration of Customer data depends.

Vista del Lago does not represent that deletion is effected by cryptographic erasure. Actor-Scoped Data is protected by per-Actor envelope encryption, and destroying a key unique to an Actor would render that Actor's ciphertext unreadable immediately. Vista del Lago does not currently perform such destruction as part of deletion: the key-encryption key that wraps each per-Actor data key is a single managed key in AWS Key Management Service, shared across Actors and bound to each Actor cryptographically by encryption context, rather than a separate destroyable key per Actor (Annex II item 1). Accordingly, no term of this DPA should be read as a crypto-shredding commitment, and the operative commitment is the removal-and-expiry commitment above. Deletion mechanics and timelines are described in the Lonzo data retention & deletion policy at lonzo.ai/legal/data-retention-deletion.

11.3 Legal retention. Vista del Lago may retain Customer Personal Data to the extent required by applicable law, subject to legal hold, or as necessary to establish, exercise, or defend legal claims; any such retained data remains encrypted and access-restricted and is subject to the confidentiality and security obligations of this DPA.

12. US State Privacy Laws

12.1 Roles. With respect to Customer Personal Data subject to US State Privacy Laws, Customer is the "business" or "controller" and Vista del Lago is the "service provider," "processor," or "contractor," as those terms are defined by the applicable law.

12.2 Restrictions. Vista del Lago will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the specific business purpose of performing the Service, or as otherwise permitted by US State Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with Personal Data obtained from other sources, except as permitted by US State Privacy Laws.

12.3 Certification and compliance. Vista del Lago certifies that it understands and will comply with the restrictions in Section 12.2. Vista del Lago will notify Customer if it determines that it can no longer meet its obligations under applicable US State Privacy Laws, and Customer may take reasonable steps to stop and remediate unauthorized Processing. Vista del Lago flows these obligations down to its Sub-processors.

13. Artificial Intelligence Processing

13.1 Inference. To provide its assistant features, the Service submits Customer content — including email and calendar content — to a large-language-model inference Sub-processor (AWS Bedrock, running the Nova, Claude, and Titan model families) for the purpose of generating responses and derived outputs on Customer's behalf. This Processing is carried out under Customer's instructions and solely to provide the Service.

13.2 Decryption for inference. Actor-Scoped Data is decrypted only for bounded, specified purposes (including inference) under the purpose-bound decryption controls described in Annex II, and every such decryption on Vista del Lago's systems is recorded in an immutable audit log (Annex II item 3, subject to the device exception in item 3a). There is no bulk-decrypt path.

13.3 No training; no retention. Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum (which incorporates the EU Standard Contractual Clauses), and Bedrock is in scope for AWS SOC and ISO 27001/27017/27018 reports. Bedrock is additionally a HIPAA-eligible AWS service, but that eligibility is AWS's and does not extend to the Service: Vista del Lago holds no Business Associate Agreement, offers none, and the Service must not be used to Process protected health information or any data subject to a HIPAA obligation. Nothing in this Section 13.3 is a representation that the Service is HIPAA-compliant or suitable for PHI.

14. General

14.1 Precedence. In the event of a conflict concerning the Processing of Customer Personal Data, the following order of precedence applies: (a) Data Protection Laws; (b) the SCCs and other transfer mechanisms in Section 6; (c) this DPA; and (d) the Agreement.

14.2 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

14.3 Term and survival. This DPA takes effect on the Effective Date and remains in force for as long as Vista del Lago Processes Customer Personal Data under the Agreement. Provisions that by their nature should survive termination — including Sections 3, 9, 11, and 14 — survive.

14.4 Changes. Vista del Lago may amend this DPA where required to comply with Data Protection Laws, on reasonable notice, provided the amendment does not materially reduce Customer's protections.

14.5 Incorporation. This DPA is incorporated into and forms part of the Agreement — the Lonzo Terms of Use — and the Terms of Use in turn incorporate this DPA by reference. Except as expressly modified here, the Agreement remains in full force and effect.


Annex I — Description of Processing

A. List of parties

  • Data exporter (Controller / Processor): Customer, as identified in the Agreement. Contact: the account owner or administrator designated in Customer's account.
  • Data importer (Processor): Vista del Lago Software LLC, 18381 Vista del Lago, Yorba Linda, CA 92886, USA. Contact for data-protection matters: privacy@lonzo.ai.

B. Subject matter and duration. The subject matter is Vista del Lago's provision of the Lonzo service. The duration is the term of the Agreement plus the deletion window in Section 11.

C. Nature and purpose of Processing. Collection, storage (as caches), organization, structuring, retrieval, use, and — for the inference purpose only — controlled decryption and transmission to the inference Sub-processor, all to provide the assistant, scheduling, messaging, and organization features of the Service on Customer's behalf.

D. Categories of Data Subjects.

  • The human account holder (the "Actor") and their Authorized Users.
  • The account holder's correspondents, contacts, and meeting participants whose Personal Data appears in synced Gmail, Calendar, Contacts, or Tasks data, or in messages handled by the Service.

E. Categories of Personal Data.

  • Email message metadata and message bodies (cached, not authoritative), including sender/recipient addresses, subjects, timestamps, and content.
  • Calendar events, including titles, descriptions, times, locations, and participant details.
  • Contacts, including names, email addresses, phone numbers, and related fields.
  • Tasks and related content.
  • Account identity and authentication data.
  • Subscription status and the purchase/subscription tokens provided by Google Play (no payment-card data — Google Play holds the payment method).

F. Special categories of data. Not intended or solicited. Free-text content (email/calendar/tasks) may incidentally contain special-category data; see Section 2.6. Customer is responsible for the lawful basis of any such data.

G. Frequency of transfer. Continuous, for the duration of the Agreement.

H. Authoritative source. Google is the authoritative source for the email, calendar, contacts, and tasks data synced into the Service; Vista del Lago holds caches of that data only.

I. Retention. As described in Section 11 and the Lonzo data retention & deletion policy, which states the full schedule. Every retention period is bounded; in summary:

DataRetention
Cached Gmail message bodies15 minutes, in process memory; no at-rest copy is written
The messages of an email conversation the assistant is asked to work onlife of the account, as assistant history — this is not a cache and is not bounded by the row above
Derived memory, assistant history, and other Actor-Scoped Datalife of the account, then deleted under Section 11
Authentication and security audit events90 days, and in no case more than 12 months
Technical and usage logs30 days, and in no case more than 90 days
Encrypted backups90-day rolling purge cycle (nightly database exports 90 days; superseded object-store copies 30 days; machine-disk snapshots 14 days)
Account-lifecycle logde-identified on deletion; no identifiable record in live systems beyond the 30-day removal window, nor in backups beyond the 90-day purge cycle
Support and escalation correspondence30 days after case closure; 180 days from last activity while open or escalated
Billing, payment, and tax records7 years, as tax and accounting law requires (survives deletion; Section 11.3)
Opt-out records (a recipient asked a Controller's account to stop)life of that account — never expires while it exists, and removed with it on deletion (it is that account's data)
Email-provider suppression entries (address plus bounce/complaint reason, for mail sent from Lonzo's own addresses)indefinite by design, on the basis of Art. 17(3) GDPR; keyed to the address, so it survives deletion

J. Sub-processors. As published at lonzo.ai/legal/subprocessors, with the transfer details in Section 6.

K. Competent supervisory authority (for SCC purposes). The Irish Data Protection Commission (DPC).

Annex II — Technical and Organizational Measures

Vista del Lago maintains the following measures. They are summarized here and described in fuller, user-facing terms in the Lonzo security overview at lonzo.ai/legal/security-overview.

1. Encryption at rest — per-Actor envelope encryption. Each human Actor's data is encrypted under a per-Actor AES-256-GCM data key (the "ADK"). Each ADK is itself wrapped by a key-encryption key (the "KEK") held in AWS Key Management Service and backed by hardware security modules, whose plaintext never exists in Vista del Lago's application processes. The KEK is a single managed key bound to each Actor cryptographically — the Actor's identity forms part of the encryption context that KMS requires to match before it will unwrap that Actor's ADK, so one Actor's ADK cannot be unwrapped in another Actor's context — and not a separate key per Actor. Encryption and decryption occur at the Kernel layer; application logic never handles plaintext keys or ciphertext. Section 11.2 states what this does and does not mean for deletion.

1a. The one store outside item 1 — the search index. Vista del Lago maintains a search index over Actor-Scoped Data in which each indexed item contributes a bounded text excerpt of that item, a vector embedding derived from that excerpt, and a projected field map used for predicate filtering. Those rows are stored in plaintext, because similarity search and predicate filtering are not expressible over values encrypted under a per-Actor key; an index that is both encrypted and searchable requires a mechanism Vista del Lago has not implemented. This exception is stated rather than left implicit, and it is bounded: cross-Actor isolation of those rows is enforced by identity-partitioned queries rather than by encryption (item 4); the indexed item itself remains encrypted under item 1; field names indicating a secret are dropped and projected text truncated before a row is written; the index is excluded from the logical database exports taken under item 8, though a residual copy persists in the encrypted daily volume snapshots of the database host and expires within the item 8 purge cycle; and because no decryption occurs, a read of those rows does not produce an entry in item 3's ledger, so items 5 and 6 are the operative controls for this store. The security overview describes the exception in user-facing terms.

2. Encryption in transit. TLS 1.3 on every connection our own software terminates — the app's live transport and all internal service-to-service traffic run over QUIC, which permits no earlier TLS version. The public HTTPS edge (pages and endpoints a browser fetches over ordinary HTTPS) prefers TLS 1.3 and accepts TLS 1.2 for older clients; nothing below TLS 1.2 is accepted. Mutual TLS (mTLS) between internal services. (Stated at this granularity since 2026-08-17; this Annex previously read "TLS 1.3 for data in transit", which was more than the edge configuration delivers.)

3. Purpose-bound decryption and audit ledger. Actor-Scoped Data is decrypted only for bounded, specified purposes. Every decryption performed on Vista del Lago's systems is recorded in an immutable, per-event audit log, at a scope that survives the audited Actor's own key state, and each entry identifies the component that performed the decryption. There is no bulk-decrypt path.

3a. The decryptions outside item 3 — the Authorized User's own device. The Lonzo application decrypts Actor-Scoped Data on the Authorized User's own device, for that same Actor, to serve an offline read cache and an offline write queue; those decryptions produce no entry in item 3's ledger. This exception is structural rather than a configuration Vista del Lago could change: an audit entry is written to a system-wide scope that a device client is deliberately not authorized to write — that authorization is what makes an entry outlive the account it describes — and a device that retained entries it could never deliver would ultimately have to either discard them or refuse the Actor's own reads. The risk item 3's ledger addresses, and which item 6's monitoring keys on, is one component decrypting many Actors' data or an anomalous volume of one Actor's; a single-Actor device on hardware the Authorized User holds is not that surface. For that store the operative controls are the device's platform protections, the fact that it holds only content already fetched for that Actor, that the ADK is never persisted on the device (it is obtained over the authenticated transport and held in memory only, under a time bound, so the sealed cache on a powered-off device is not readable without re-authentication), and clearing on sign-out — with the deliberate exception of writes that have not yet reached Vista del Lago, which are retained because on an offline device they are the Authorized User's only copy, and are transmitted and then dropped at the next opportunity — as described in the Cookie & Local Storage Notice at lonzo.ai/legal/cookie-localstorage-notice; Vista del Lago can additionally revoke an individual device's credential on request. The security overview describes the exception in user-facing terms.

4. Structural cross-Actor isolation. Cross-Actor data access is structurally inexpressible in the Fabric-Starlark execution language; isolation is enforced by the execution model, and one Actor's data is encrypted under a data key another Actor's execution context cannot obtain. For the search index in item 1a the isolation holds but the mechanism differs: those rows are not encrypted under a per-Actor key, and every query against them is partitioned by the caller's authenticated identity.

5. Access control. Least-privilege internal access; access to production restricted to authorized personnel. Multi-factor authentication is mandatory for all staff access to production and to environments that can reach user data; a phishing-resistant WebAuthn/FIDO2 hardware security key is required for administrative and production access (TOTP authenticator otherwise). Personnel are bound by confidentiality agreements, access grants are reviewed on a recurring basis, and background screening is conducted where lawful.

6. Logging and monitoring. Audit logging of access to Customer Personal Data and monitoring for anomalous decryption patterns.

7. Deletion. Removal of Customer Personal Data from live systems, with revocation of the connected-account authorization and stored tokens, within thirty (30) days, followed by expiry of residual copies from encrypted backups on the purge cycle in item 8, within ninety (90) days. Not effected by destruction of per-Actor key material; see Section 11.2.

8. Resilience. Encrypted backups holding the same per-Actor ciphertext as live storage, on a 90-day rolling purge cycle — the same number stated in Section 11.1, the security overview, and the data retention & deletion policy, and the bound on how long a residual copy of deleted data survives. The 90 days is the longest of three windows and is stated because it is the binding one: nightly database exports are retained 90 days, superseded object-store copies expire 30 days after they stop being current, and machine-disk snapshots are kept 14 days. (Corrected from 30 days on 2026-08-17, which was the object store's window stated as though it covered all three; see Section 11.2.) Multi-AZ redundancy within a single AWS US region (multi-region redundancy is deferred). Restore from backup is tested at least annually. Use of a major cloud infrastructure provider (AWS, US regions) whose own infrastructure certifications provide inherited assurance.

9. Status of these measures. The measures in items 1–4 and 6 are properties of the running system, item 1 as qualified by item 1a and item 3 as qualified by item 3a. The organizational measures in item 5, and the periodic restore test in item 8, are contractual commitments under Section 4.2; for any measure described as recurring or periodic, the first cycle runs within ninety (90) days of the Effective Date of this DPA. None of these measures has been audited or certified by a third party — see Section 10.2, which states how Vista del Lago satisfies Customer's audit right in the absence of a report.


All legal documents · Help · Lonzo home