Legal · Data Processing

Data Processing Agreement

Last updated: July 9, 2026

This DPA governs North Lemma's processing of personal data on your firm's behalf. It forms part of the agreement between your firm (the controller) and North Lemma (the processor) and reflects the requirements of the GDPR, UK GDPR and similar laws.

01 Roles & scope

For personal data contained in the content your firm imports and the analysis derived from it ("Customer Personal Data"), your firm is the controller and North Lemma is the processor. This DPA applies to North Lemma's processing of Customer Personal Data to provide the Service and forms part of, and is subject to, the Terms of Service or any signed master agreement between the parties.

02 Processing instructions

North Lemma will process Customer Personal Data only on your documented instructions, including as set out in this DPA and the Terms, and as needed to provide and support the Service. Your configuration and use of the Service, and the content you choose to import, constitute your instructions. We will inform you if, in our opinion, an instruction infringes applicable data-protection law, and we will not process the data for our own purposes.

03 Personnel & confidentiality

North Lemma limits access to Customer Personal Data to personnel who need it to deliver or support the Service, ensures they are bound by appropriate confidentiality obligations, and provides them with relevant training on their responsibilities.

04 Security measures

North Lemma maintains technical and organizational measures appropriate to the risk, including:

  • Tenant isolation. Each firm's data is stored in an isolated store and every request is scoped to a single tenant.
  • Encryption. Data is encrypted in transit with TLS; managed storage is encrypted at rest.
  • Access control. Signed, expiring session tokens, rate limiting, brute-force protection, and least-privilege administrative access with secrets held in a secrets manager.
  • Logging & monitoring. Per-workspace access and write logging to support detection, review and incident response.
  • Resilience. Managed, backed-up infrastructure with recovery procedures.

Our security program continues to expand toward single sign-on, key-management options, independent penetration testing, an SOC 2 examination and configurable data residency. This DPA reflects measures in place today; we will not represent controls as complete before they are.

05 Sub-processors

You authorize North Lemma to engage the sub-processors below, each bound by a written contract imposing data-protection obligations no less protective than this DPA:

Sub-processorPurposeRegion
Anthropic PBCAI inference for thesis evaluation and extraction (inputs not used for model training)United States
Polygon.ioMarket reference and pricing data, requested by ticker symbol onlyUnited States
RenderApplication hosting and encrypted data storageUnited States

We will give advance notice of any intended addition or replacement of a sub-processor so you have an opportunity to object on reasonable data-protection grounds. North Lemma remains responsible for its sub-processors' performance of their obligations.

06 Data-subject requests

Taking into account the nature of the processing, North Lemma will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). Where a data subject contacts North Lemma directly regarding Customer Personal Data, we will refer them to you.

07 Personal-data breach notification

North Lemma will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to help you meet your own notification obligations, along with the measures we are taking to address the breach.

08 International transfers

Where processing involves transfer of Customer Personal Data out of the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) are incorporated by reference and apply to that transfer, together with appropriate supplementary measures.

09 Return & deletion

On termination or expiry of the Service, or on your written request, North Lemma will delete Customer Personal Data, including from the isolated store and derived analysis, within 30 days, unless retention is required by law. On request before deletion, we will make Customer Data available for export.

10 Audits

North Lemma will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not compromise the security of other customers. Where available, current third-party reports or certifications may be provided to satisfy an audit request.

11 Annex: details of processing

Subject matterProvision of the North Lemma decision-intelligence Service.
DurationFor the term of the Service, plus the deletion period in Section 09.
Nature & purposeStorage, structuring, and AI-assisted analysis of investment content to produce evaluations and analytics on the controller's instructions.
Types of personal dataIncidental personal data contained in imported theses, memos and trade records (e.g. names of analysts or authors), and workspace account contact details.
Categories of data subjectsThe controller's personnel and authorized users; individuals named incidentally in imported content.
Special categoriesNone intended; the Service is not designed to process special-category data.

12 Contact

To request a countersigned copy of this DPA or raise a data-protection matter, contact privacy@northlemma.com.