Lineo Data Processing Addendum
Last Updated: July 24, 2026
Effective Date: July 24, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Lineo, Inc. ("Lineo") and the customer accepting Lineo's Terms of Service or executing an ordering document referencing them ("Customer") (together, the "Agreement"). This DPA is incorporated into the Agreement by reference and applies to the extent Lineo processes Personal Data on Customer's behalf in providing the Services. It reflects the parties' agreement on the processing of Personal Data in accordance with the requirements of Data Protection Laws. A countersigned copy of this DPA is available on request at privacy@lineo.co.
1. Definitions
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 and its UK equivalent ("GDPR") and the California Consumer Privacy Act as amended by the CPRA ("CCPA"). "Personal Data" means information relating to an identified or identifiable natural person that Lineo processes on Customer's behalf. "Sub-processor" means a third party engaged by Lineo to process Personal Data on Customer's behalf. "Processing," "controller," "processor," "data subject," and "personal data breach" have the meanings given in the GDPR; "business," "service provider," "sell," and "share" have the meanings given in the CCPA.
2. Roles and Details of Processing
Customer is the controller (or, where Customer acts on behalf of a third-party controller, a processor) and Lineo is the processor of Personal Data within Customer Data. Under the CCPA, Customer is the business and Lineo is a service provider. Details of processing: subject matter and nature — hosting, syncing, displaying, exporting, and (where Customer uses AI features) extracting data from documents, to provide production-accounting and project management services; duration — the term of the Agreement plus the deletion period in Section 10; categories of data subjects — Customer's personnel and users, vendors and their representatives, production crew and credited contributors, and other individuals whose data Customer submits; categories of Personal Data — contact and account details, production and financial records (including budgets, purchase orders, payroll documents, invoices, and receipts), vendor records including government tax identifiers on W-9 forms, uploaded documents and media, and usage/audit records.
3. Processing on Instructions
Lineo will process Personal Data only on Customer's documented instructions — the Agreement, this DPA, Customer's configuration and use of the Services (including any opt-in integrations Customer enables), and any further written instructions the parties agree — unless required otherwise by applicable law, in which case Lineo will inform Customer unless legally prohibited. Lineo will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality
Lineo ensures that persons authorized to process Personal Data are bound by contractual or statutory confidentiality obligations and receive appropriate data protection training. Access to Personal Data is limited to personnel who require it to provide the Services.
5. Security
Lineo implements and maintains appropriate technical and organizational measures to protect Personal Data, taking into account the state of the art and the risks presented by the processing (GDPR Art. 32). These include: encryption in transit (TLS 1.2+) and at rest (AES-256); tenant isolation enforced at the database layer (row-level security) and verified by automated tests on every code change; multi-factor authentication, including customer-configurable MFA enforcement; role-based and membership-scoped access controls; PII-minimized audit logging; automated data-retention and erasure machinery with regression guards; and a documented incident-response process. Current summaries are available in Lineo's Information Security Policy and GDPR & CCPA Readiness Summary, available on request.
6. Sub-processors
Customer provides general authorization for Lineo's engagement of Sub-processors. The current list is published in the "Third-Party Service Providers" section of Lineo's Privacy Policy at run.lineo.co/privacy. Lineo will update that list before adding or replacing a Sub-processor that processes Personal Data. Customer may object on reasonable data-protection grounds within fifteen (15) days of an update by writing to privacy@lineo.co; if the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees. Lineo imposes data-protection obligations on Sub-processors materially equivalent to those in this DPA and remains responsible for their performance.
7. Data Subject Requests
The Services include self-serve tools through which most data subject rights can be exercised directly (data export in machine-readable format, account deletion, profile rectification). Taking into account the nature of the processing, Lineo will assist Customer with appropriate technical and organizational measures in fulfilling Customer's obligation to respond to data subject requests. If a data subject contacts Lineo directly regarding Customer Data, Lineo will promptly route the request to Customer and will not respond substantively except as required by law.
8. Personal Data Breach
Lineo will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a confirmed personal data breach affecting Customer's Personal Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate volume of data and data subjects concerned, likely consequences, and measures taken or proposed. Lineo will provide timely updates as the investigation proceeds and reasonable cooperation with Customer's own notification obligations. Notification is not an acknowledgment of fault or liability.
9. Assistance
Taking into account the nature of the processing and the information available to it, Lineo will provide reasonable assistance with Customer's data protection impact assessments, consultations with supervisory authorities, and compliance with its security obligations under Data Protection Laws.
10. Return and Deletion
Customer may export Customer Data at any time during the term using the Services' export tools. Following termination or expiration of the Agreement, Lineo will delete Personal Data processed on Customer's behalf within thirty (30) days, except where retention is required by applicable law or where residual copies persist in encrypted backups until those backups expire in the ordinary course (after which they are unrecoverable). On written request, Lineo will confirm deletion in writing.
11. Audits and Demonstrating Compliance
Lineo will make available information reasonably necessary to demonstrate compliance with this DPA, including its Information Security Policy, GDPR & CCPA Readiness Summary, controls documentation (under NDA), and responses to reasonable written security questionnaires. Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by the foregoing, Customer (or an independent auditor that is not a Lineo competitor) may audit Lineo's compliance no more than once per twelve (12) months, on at least thirty (30) days' written notice, during business hours, without access to other customers' data, subject to confidentiality obligations, and at Customer's expense.
12. International Transfers
Personal Data is processed in the United States. Where Data Protection Laws restrict transfers of Personal Data from the EEA, UK, or Switzerland, the parties rely on appropriate safeguards, including Sub-processors' participation in the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses incorporated in Lineo's agreements with its Sub-processors. Where the parties are themselves required to execute Standard Contractual Clauses, the applicable module (Module Two: controller-to-processor) is deemed incorporated into this DPA, with Customer as data exporter and Lineo as data importer, populated by the details in Section 2 and the security measures in Section 5.
13. CCPA Service Provider Terms
To the extent the CCPA applies, Lineo acts as a service provider. Lineo will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, including any commercial purpose other than providing the Services; or (c) retain, use, or disclose Personal Data outside the direct business relationship between the parties. Lineo certifies that it understands and will comply with these restrictions, will notify Customer if it can no longer meet them, and grants Customer the rights to take reasonable steps to stop and remediate unauthorized use of Personal Data.
14. Liability
Each party's and its affiliates' aggregate liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement, and references in those provisions to a party's liability mean the aggregate liability of that party and its affiliates under the Agreement and this DPA together.
15. General
In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls; where Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control. Lineo may update this DPA from time to time to reflect changes in law or the Services; material changes will be notified per the Agreement and will not reduce the overall protection of Personal Data. Questions and requests (including for a countersigned copy): privacy@lineo.co.