Data Processing Agreement (DPA)
Review, accept and download your organization agreement with Codelynx, LLC
Last reviewed: 2026-09-15
Lumail provides an organization Data Processing Agreement (DPA) with Codelynx, LLC, 8 The Green STE B, Dover Delaware 19901, United States. It describes the parties' processing obligations, confidentiality, security, subprocessors, rights assistance, incidents, return and erasure, and audit arrangements.
Review and accept
- Open your organization's Settings → Configuration → Data Processing Agreement.
- Read the agreement and confirm the organization's legal name and address.
- Select whether the organization acts as a controller, a processor for its own client, or both for the transferred data.
- Enter your full legal name, including your family name.
- Check the express agreement and authority confirmation, then select Sign agreement.
Only an organization owner or administrator can sign on the organization's behalf. You must have authority to bind its legal entity. If your organization acts for a client, it must also have authority to appoint Codelynx as a further processor. A marketing opt-in or acceptance on behalf of your subscribers is not created by signing this contract.
Download your agreement
After signing, use Download signed PDF to receive the contract with the recorded parties, signer and acceptance details. Keep a copy for your records.
The accepted text is saved with its version and acceptance time. Changing an organization profile or publishing a new template does not rewrite an earlier agreement. Downloading an unsigned document does not constitute acceptance.
International transfers and compliance scope
The DPA is an agreement about processing obligations. It is not:
- An EU-only hosting or data-residency commitment.
- A Data Privacy Framework or security certification.
- A completed transfer impact assessment.
Version 2026-09-15.1 incorporates the European Commission's 2021 Standard Contractual Clauses by reference: Module Two for controller-to-processor transfers and Module Three for processor-to-subprocessor transfers. The Customer selects its applicable role or roles when signing. The DPA also incorporates the UK ICO transfer addendum and Swiss adaptations. Accepting that DPA electronically signs the selected transfer terms between the Customer and Codelynx.
The clauses do not remove the need to assess the destination country's laws, document the transfer assessment, apply any necessary supplementary measures, and verify the safeguards used for onward transfers. If those requirements cannot be met, the affected transfer must be suspended or stopped. Provider agreements do not replace the Customer-to-Codelynx clauses.
The Customer remains responsible for its lawful purposes, notices, recipient selection and tracking choices. See GDPR in Lumail and the Privacy Policy for the disclosed configuration and limitations.
Rights, erasure and contract questions
Contact [email protected] for data-subject assistance, authorized erasure or return, provider information, audit requests and transfer requirements. Ordinary unsubscribe preserves data and is not an erasure request. The scope and completion arrangements must account for archives, snapshots, queues, logs, backups and applicable exceptions.
The accepted DPA contains the binding terms for the signing organization. This explanatory page does not replace that contract or constitute a compliance certification.