Data processing agreement
Last updated 21 September 2026
This agreement applies whenever an agency (the "Customer") uses Lyra to process personal data about its clients and the people who interact with them. It forms part of our terms of service and needs no separate signature. If you need a countersigned copy, write to [email protected].
1. Parties and roles
The Customer is the controller of the personal data it puts into Lyra or has Lyra collect for it. ניקולאי בטורין ורומן ופרינסקי, trading as כוכבים ברשת (עוסק מורשה 558625729), is the processor ("we"). Where the Customer is itself a processor for its own clients, we act as its subprocessor and these terms apply in the same way.
2. Definitions
"Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the EU General Data Protection Regulation (GDPR), and the UK GDPR where it applies.
3. Instructions
- We process personal data only to provide Lyra as the Customer configures and uses it, and on its other documented instructions, which include everything the Customer does through the app and the API.
- We will tell the Customer if we believe an instruction breaks data protection law.
- The Customer is responsible for having a lawful basis for the processing, and for the permissions of the account owners whose accounts it connects.
4. Confidentiality
Only the partners operating Lyra have access to personal data, and only to run, support and secure the service. Anyone we authorise in future will be bound by confidentiality.
5. Security
We maintain the technical and organisational measures in Annex II, and improve them over time.
6. Subprocessors
- The Customer authorises the subprocessors listed on the subprocessors page.
- We will give at least 30 days' notice by email before adding or replacing one. The Customer may object on reasonable data protection grounds within 15 days; if we cannot resolve the objection, the Customer may end its use of Lyra without penalty.
- Each subprocessor is bound by data protection terms no weaker than these, and we remain responsible for it.
7. International transfers
Personal data is stored in the European Union. It is accessed from Israel, which the European Commission recognises as adequate. Where a subprocessor transfers data to a country without an adequacy decision, the transfer relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses (Module 2 or 3, as applicable), which are incorporated here by reference, with the UK addendum for UK data.
8. Helping the Customer
- We help the Customer answer data subjects' requests (access, correction, deletion, restriction, portability, objection). Much of this the Customer can do itself in Lyra; we handle the rest on request.
- If a data subject contacts us directly about the Customer's data, we pass the request on.
- We give reasonable help with data protection impact assessments and consultations with authorities.
9. Special categories
Lyra is not designed for special categories of data (health, religion and similar). If the Customer's content or messages contain them, the Customer is responsible for having a lawful basis.
10. Personal data breaches
We will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a breach affecting its data, with what we know and what we are doing, and will keep it informed.
11. Audits
We will make available the information needed to show compliance with this agreement. The Customer may audit once a year with 30 days' notice, or after a breach or at a regulator's request, at its own cost and without access to other customers' data.
12. Return and deletion
When the Customer stops using Lyra, we will, at its choice, export its data in a machine-readable format and then delete it within 30 days, unless the law requires us to keep something.
13. Liability
Liability under this agreement follows the limits in the terms of service, except where the law does not allow them to apply, including a data subject's rights under art. 82 GDPR.
14. General
If this agreement and the terms of service conflict on data protection, this agreement wins. It lasts as long as we process personal data for the Customer, and is governed by the same law as the terms.
Annex I: Details of the processing
| Subject and purpose | Running Lyra for the Customer: publishing and scheduling, the inbox, auto replies, analytics, advertising management, client portal links and the API. |
| Data subjects | The Customer's clients and their staff; people who message, comment on or interact with the connected accounts; people shown in published media; the Customer's own team. |
| Categories of data | Names, handles, platform ids and profile pictures; message and comment text; published content and media; audience and advertising figures; ad targeting settings; portal visit records (hashed). |
| Duration | While the Customer uses Lyra, subject to the retention periods in the privacy policy (direct messages 60 days, comments 30 days, among others). |
Annex II: Technical and organisational measures
- TLS encryption for all traffic to and from Lyra.
- Platform access tokens and saved API keys encrypted at rest with AES-256-GCM.
- Passwords stored only as salted scrypt hashes.
- Every request scoped to one workspace; role-based permissions inside it; portal links limited to one client.
- Incoming platform webhooks verified by signature; outgoing webhooks signed with HMAC-SHA256.
- Rate limits on sign-in, the API and public forms.
- Automatic deletion of direct messages, comments and other records on the schedule in the privacy policy.
- Database and cache on private networks with no public access; servers in Germany.
- Access to production limited to the two partners.
Annex III: Subprocessors
As listed on the subprocessors page.