Skip to content

Legal

Data Processing Agreement

Last updated: 16 September 2026

Template — pending legal review

This document is a working draft prepared for transparency. It has not yet been reviewed or approved by qualified legal counsel and does not constitute legal advice. The final executed version issued with a contract prevails over anything on this page.

A plain-English summary of how LAHJA AI handles personal data in a client engagement: where we act as processor and where we act as controller, what security measures apply, how sub-processing and breach notification work, and what happens to data when the engagement ends.

1.Purpose of this summary

This page summarises the data processing terms that apply when LAHJA AI SARL ("LAHJA AI") handles personal data in connection with a client engagement. It is written for procurement, legal and security reviewers who need to understand our position before signing.

It is a summary, not the contract. The operative document is the Data Processing Agreement ("DPA") executed alongside the client services agreement or statement of work. Where this page and the executed DPA differ, the executed DPA governs.

2.Two distinct roles

Our role depends on whose data is being handled, and the distinction matters because it determines who decides the purpose of the processing.

  • Processor: for personal data the client supplies to us — source audio, documents, transcripts, model outputs, end-user content, evaluation material. We process it only on the client's documented instructions, for the purposes set out in the statement of work.
  • Controller: for personal data relating to our own contributors — identity, language profile, credentials, quality scores, payment records and consent records. We decide the purpose of that processing because it is how we run and evidence our own workforce.
  • In practice a single project usually involves both roles at once, and the DPA addresses each separately.

3.Scope of processing

The DPA specifies, for each engagement, the subject matter and duration of the processing, its nature and purpose, the categories of data subjects, and the types of personal data involved.

For a typical speech or evaluation project this covers collecting and storing audio recordings, transcribing and annotating them, running quality review, generating quality statistics, and delivering a structured dataset with pseudonymous contributor identifiers.

We do not process client-supplied personal data for our own purposes, do not use it to train our own models, and do not combine it with data from other clients.

4.Client instructions and legal compliance

We act only on documented instructions from the client, including for any transfer of data to another country. If we consider an instruction to breach applicable data protection law, we will say so and may suspend that part of the processing until it is resolved.

The client is responsible for ensuring that it has a lawful basis for the data it supplies to us, that its own notices cover the processing we perform, and that it has obtained any consent required from its end users.

5.Confidentiality of personnel

Everyone with access to client data — employees, reviewers and contributors — is bound by written confidentiality obligations that survive the end of their engagement. Project-specific non-disclosure agreements are applied where the client requires them, and acceptance is recorded with version and timestamp before any task is assigned.

Access is granted on a need-to-know basis, scoped to the specific project, and withdrawn when the assignment ends.

6.Security measures

The DPA records the technical and organisational measures we apply. Those implemented today include the following.

  • Role-based access control enforced server-side on every request, with logical separation so that a client account can reach only its own projects.
  • No publicly readable storage: every file is served through a short-lived signed URL issued after an authorisation check.
  • Encryption of data in transit, and encryption at rest as provided by our hosting and storage providers.
  • argon2id password hashing, server-side sessions with hashed tokens, and secure HttpOnly SameSite cookies.
  • Upload validation and file-size limits, plus rate limiting on authentication and submission endpoints.
  • Append-only audit logging of privileged actions, including approvals, exports, payment marks and role changes.
  • Secrets held in server-side environment configuration and never exposed to the browser.
  • Pseudonymisation of contributor identity in every delivered dataset unless the contract and the contributor's consent provide otherwise.

7.Sub-processing

The client gives general authorisation for us to engage sub-processors. We currently rely on providers for cloud hosting and object storage, database hosting, transactional email and application monitoring.

Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in the DPA, and we remain fully liable to the client for their performance.

We maintain a current list of sub-processors, provide it on request, and give the client advance notice of any intended addition or replacement. The client may object on reasonable data protection grounds within the notice period, and the DPA sets out how an unresolved objection is handled.

8.Assistance to the client

We assist the client, taking into account the nature of the processing and the information available to us, with responding to data-subject requests, with data protection impact assessments, and with prior consultation of a supervisory authority where required.

Where a data subject contacts us directly about data we process on a client's behalf, we do not respond substantively ourselves — we refer the request to the client without undue delay.

9.Personal data breach notification

If we become aware of a personal data breach affecting client data, we notify the client without undue delay, and in any event within the period stated in the executed DPA.

The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact for further information. Where the full picture is not available immediately, we provide information in phases rather than delaying the first notification.

We cooperate with the client on containment, remediation and any notification the client must make to a supervisory authority or to affected individuals.

10.International transfers

Our clients are frequently outside Algeria and our infrastructure providers may operate in other jurisdictions, so cross-border transfers are a normal part of an engagement.

Transfers take place only on the client's documented instructions and under appropriate contractual safeguards covering security, purpose limitation, onward transfer and deletion. The DPA identifies the transfer mechanism relied on for the engagement.

11.Audit rights

We make available to the client the information reasonably necessary to demonstrate compliance with the DPA, including responses to security questionnaires and a description of our technical and organisational measures.

The client may audit our compliance, either itself or through an independent auditor it appoints, on reasonable prior written notice, no more than once in any twelve-month period except following a personal data breach or where a supervisory authority requires it. Audits take place during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality.

Auditors may not access other clients' data, contributor personal data beyond what the engagement requires, or commercially sensitive information unrelated to the engagement.

LAHJA AI does not currently hold SOC 2, ISO 27001 or an equivalent certification, and we will not present one in place of an audit response. Work toward those frameworks is described on our security page and is labelled as planned.

12.Deletion and return on termination

On expiry or termination of the engagement, and at the client's choice, we return client-supplied personal data or delete it, along with existing copies, within the period stated in the executed DPA.

We may retain data where applicable law requires it, and where retention is necessary to evidence quality, payment or consent in relation to work already delivered. Anything retained remains protected by the DPA's confidentiality and security obligations for as long as we hold it.

Contributor personal data for which LAHJA AI is the controller is not deleted on termination of a client engagement; it is retained and deleted under our own retention schedule as described in the Privacy Policy.

13.Contact

To request the full DPA, the current sub-processor list or a completed security questionnaire, write to contact@lahja.ai. Postal address: LAHJA AI SARL, Algiers, Algeria.

Questions about this document? Write to contact@lahja.ai.