Data Processing Addendum
Last updated: August 30, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Pitcher Holdings LLC, a New York limited liability company doing business as Lejr (“Lejr,” “we,” or “us”), and the customer identified in the Agreement (“Customer,” “you”). It applies to the extent Lejr processes Personal Data on your behalf. Where this DPA conflicts with the rest of the Agreement on the subject of data protection, this DPA controls.
1. Definitions
- Personal Data, Controller, Processor, Processing, Data Subject, and Supervisory Authority have the meanings given in applicable Data Protection Law.
- Data Protection Law means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and US state privacy laws such as the California Consumer Privacy Act as amended by the CPRA.
- Customer Personal Data means Personal Data contained in the ledger data and account information you or your authorized users submit to Lejr.
- Subprocessor means a third party engaged by Lejr to process Customer Personal Data.
2. Roles of the parties
You are the Controller of Customer Personal Data. Lejr is the Processor, processing Customer Personal Data only on your documented instructions — which comprise the Agreement, this DPA, and your use of the product's features. Where you act as a processor on behalf of a third party, you appoint Lejr as your subprocessor, and you are responsible for the third party's authorizations and instructions.
3. Scope and purpose of processing
- Subject matter: provision of the Lejr accounting platform.
- Duration: the term of the Agreement, plus the retention window described in Section 9.
- Nature and purpose: hosting, storing, and processing ledger and account data so you can keep your books; and, where you enable it, allowing an AI assistant you connect to read and write those books on your instruction.
- Categories of Data Subjects: your authorized users, and the individuals represented in your books (for example, customer, vendor, and contact records).
- Categories of Personal Data: names, email addresses, and business contact details; transaction and ledger data; and usage and security logs (timestamps, IP address). Lejr does not require, and you agree not to submit, special categories of Personal Data (such as health, biometric, or government-identifier data) except as strictly incidental to ordinary accounting.
4. Lejr's obligations
Lejr will:
- process Customer Personal Data only on your documented instructions and as required by applicable law, and tell you if, in our reasonable opinion, an instruction appears to violate Data Protection Law;
- ensure that personnel authorized to process Customer Personal Data are bound by an obligation of confidentiality;
- implement and maintain the technical and organizational measures described in Section 5;
- taking into account the nature of the processing, assist you with Data Subject requests and with your obligations around security, breach notification, and data protection impact assessments; and
- make available information reasonably necessary to demonstrate compliance with this DPA.
5. Security measures
Taking into account the state of the art and the risks presented by the processing, Lejr maintains appropriate technical and organizational measures, including:
- row-level access controls that scope data to the organization that owns it;
- encryption of data in transit and at rest;
- secrets and third-party credentials stored encrypted, and never exposed in exports;
- an immutable ledger with a full audit trail of create, edit, and void operations;
- off-site encrypted backups taken every few hours with a 30-day retention window and a verified restore procedure; and
- least-privilege access for personnel.
Lejr may update these measures from time to time provided the level of protection is not materially reduced.
6. Subprocessors
You authorize Lejr to engage the Subprocessors listed in our Privacy Policy, currently:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and edge network.
- Anthropic — the optional AI assistant, where you enable it.
- Stripe — payments, where you subscribe to a paid plan.
- ZeptoMail — transactional email.
- Plaid — bank connections, where you connect an account.
Lejr imposes on each Subprocessor data-protection obligations no less protective than those in this DPA, and remains responsible for each Subprocessor's performance. Lejr will give you at least 30 days' notice before adding or replacing a Subprocessor, by email or by updating the list in our Privacy Policy, during which you may object on reasonable data-protection grounds. If you object and we cannot reasonably accommodate the objection, you may terminate the affected part of the service.
7. Data Subject rights and cooperation
To the extent legally permitted, Lejr will promptly notify you of a request received directly from a Data Subject and, taking into account the nature of the processing, assist you by appropriate technical and organizational measures in responding to it. Lejr will likewise assist you with your obligations around security, breach notification, and data protection impact assessments as required by Data Protection Law.
8. Personal Data breach
Lejr will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed, and Lejr will provide further information reasonably available to help you meet your own notification obligations. You can reach our security team at security@lejr.app.
9. Return and deletion
On termination of the Agreement, or on your earlier request, Lejr will delete or return Customer Personal Data in line with the account-deletion and retention behavior described in the Privacy Policy: ledger data is retained for up to 30 days so you can restore or export it and is then purged from the primary database, backups roll off on a 30-day window, and operational logs are retained for 90 days. Lejr may retain Customer Personal Data where retention is required by applicable law, for only as long as that law requires.
10. International transfers
Lejr processes Customer Personal Data in the United States. Where Lejr processes Customer Personal Data that is subject to the EU or UK GDPR and transfers it out of the European Economic Area or the United Kingdom, the parties incorporate an appropriate transfer mechanism — the EU Standard Contractual Clauses (module one, controller-to- processor) and, for UK data, the UK International Data Transfer Addendum — which are deemed executed on the effective date of this DPA, with Lejr as the data importer and you as the data exporter, and with the details in Sections 3, 5, and 6 completing their annexes. If a transfer mechanism is invalidated, the parties will work in good faith to adopt a valid alternative.
11. Audits
Lejr will make available to you information reasonably necessary to demonstrate compliance with this DPA. Where a third-party audit report or certification (such as a SOC 2 report) is available, you agree that providing it satisfies this obligation. Otherwise, no more than once per year and on at least 30 days' written notice, you may audit Lejr's compliance, during business hours, without disrupting the service or compromising the confidentiality of other customers, and at your own cost.
12. Liability and governing law
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the laws of the State of New York, and disputes are resolved as set out in the Agreement.
Contact
Questions about this DPA, or a request for a countersigned copy? Reach us at legal@lejr.app.
Pitcher Holdings LLC d/b/a Lejr
New York, United States