Data Processing Agreement (DPA)
1. Introduction
This DPA applies to the personal data that LCNC Inc collects, processes, and stores when users interact with our no-code web application platform. By using Processor's services, you agree to the processing of your data as described in this agreement.
2. Personal Data We Process
When you use Processor, we may collect and process the following types of personal data:
- Account Information: Name, email, phone number, and company details.
- Usage Data: IP address, browser type, operating system, and activity logs.
- Payment Data: Transaction details (processed securely via third-party payment providers).
- Customer Content: Any data you upload or create using our platform.
We do not process sensitive personal data (e.g., health, biometric, or racial data) unless explicitly required by the user, for e.g. healthcare/financial services apps, etc and those are covered in our Enterprise plans and we sign a separate agreement for the same.
3. Purpose of Data Processing
We process personal data for the following reasons:
- To provide and improve Processor services.
- To manage user accounts and authentication.
- To process transactions and payments securely.
- To ensure security, detect fraud, and prevent abuse.
- To communicate important updates, support requests, and marketing (with consent).
4. Data Sharing & Sub-Processors
The processor does not sell personal data. However, we may share data with:
- Hosting & Infrastructure Providers (e.g., AWS, Google Cloud, etc).
- Analytics Services (e.g., Google Analytics, Mixpanel, Hotjar, etc).
- Payment Processors (e.g., Stripe, PayPal, NMI Payments, Imagine Pay, RazorPay, etc).
- Support & CRM Tools (e.g., Pipedrive, Salesforce, HubSpot, etc).
All sub-processors comply with strict data security and confidentiality obligations.
5. Data Retention & Deletion
- We retain personal data only as long as necessary to fulfill its purpose.
- Users can request account deletion or data removal at any time by contacting support@drapcode.com.
- Upon termination of services, Processor will delete or anonymize personal data unless legal obligations require retention.
6. Data Security Measures
Processor implements robust security measures, including:
- Data & Files Encryption (for data in transit and at rest).
- Role based Access Controls (to prevent unauthorized access).
- Regular Security Audits (to identify vulnerabilities).
- Incident Response Procedures (for quick action in case of a breach).
In case of a data breach, we will notify affected users and regulatory authorities without undue delay.
7. Data Processing Responsibilities
Processor's Responsibilities:
- Process personal data in accordance with applicable laws.
- Ensure confidentiality and security of processed data.
- Assist users in fulfilling data protection rights.
User (Controller) Responsibilities:
- Ensure lawful collection and use of data.
- Provide accurate and up-to-date information.
- Implement security measures for data uploaded to the Processor.
8. Contact Information
For any questions related to this DPA, please contact:
📧 Email: support@drapcode.com
By continuing to use Processor, you acknowledge and agree to this Data Processing Agreement (DPA).