01 Roles & scope
For personal data contained in the content your firm imports and the analysis derived from it ("Customer Personal Data"), your firm is the controller and North Lemma is the processor. This DPA applies to North Lemma's processing of Customer Personal Data to provide the Service and forms part of, and is subject to, the Terms of Service or any signed master agreement between the parties.
02 Processing instructions
North Lemma will process Customer Personal Data only on your documented instructions, including as set out in this DPA and the Terms, and as needed to provide and support the Service. Your configuration and use of the Service, and the content you choose to import, constitute your instructions. We will inform you if, in our opinion, an instruction infringes applicable data-protection law, and we will not process the data for our own purposes.
03 Personnel & confidentiality
North Lemma limits access to Customer Personal Data to personnel who need it to deliver or support the Service, ensures they are bound by appropriate confidentiality obligations, and provides them with relevant training on their responsibilities.
04 Security measures
North Lemma maintains technical and organizational measures appropriate to the risk, including:
- Tenant isolation. Each firm's data is stored in an isolated store and every request is scoped to a single tenant.
- Encryption. Data is encrypted in transit with TLS; managed storage is encrypted at rest.
- Access control. Signed, expiring session tokens, rate limiting, brute-force protection, and least-privilege administrative access with secrets held in a secrets manager.
- Logging & monitoring. Per-workspace access and write logging to support detection, review and incident response.
- Resilience. Managed, backed-up infrastructure with recovery procedures.
Our security program continues to expand toward single sign-on, key-management options, independent penetration testing, an SOC 2 examination and configurable data residency. This DPA reflects measures in place today; we will not represent controls as complete before they are.
05 Sub-processors
You authorize North Lemma to engage the sub-processors below, each bound by a written contract imposing data-protection obligations no less protective than this DPA:
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic PBC | AI inference for thesis evaluation and extraction (inputs not used for model training) | United States |
| Polygon.io | Market reference and pricing data, requested by ticker symbol only | United States |
| Render | Application hosting and encrypted data storage | United States |
We will give advance notice of any intended addition or replacement of a sub-processor so you have an opportunity to object on reasonable data-protection grounds. North Lemma remains responsible for its sub-processors' performance of their obligations.
06 Data-subject requests
Taking into account the nature of the processing, North Lemma will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). Where a data subject contacts North Lemma directly regarding Customer Personal Data, we will refer them to you.
07 Personal-data breach notification
North Lemma will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to help you meet your own notification obligations, along with the measures we are taking to address the breach.
08 International transfers
Where processing involves transfer of Customer Personal Data out of the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) are incorporated by reference and apply to that transfer, together with appropriate supplementary measures.
09 Return & deletion
On termination or expiry of the Service, or on your written request, North Lemma will delete Customer Personal Data, including from the isolated store and derived analysis, within 30 days, unless retention is required by law. On request before deletion, we will make Customer Data available for export.
10 Audits
North Lemma will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not compromise the security of other customers. Where available, current third-party reports or certifications may be provided to satisfy an audit request.
11 Annex: details of processing
| Subject matter | Provision of the North Lemma decision-intelligence Service. |
| Duration | For the term of the Service, plus the deletion period in Section 09. |
| Nature & purpose | Storage, structuring, and AI-assisted analysis of investment content to produce evaluations and analytics on the controller's instructions. |
| Types of personal data | Incidental personal data contained in imported theses, memos and trade records (e.g. names of analysts or authors), and workspace account contact details. |
| Categories of data subjects | The controller's personnel and authorized users; individuals named incidentally in imported content. |
| Special categories | None intended; the Service is not designed to process special-category data. |
12 Contact
To request a countersigned copy of this DPA or raise a data-protection matter, contact privacy@northlemma.com.