Skip to content

Legal

Data Processing Agreement

Last updated: September 19, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Pro Sistemos, MB ("Processor", "we"). It applies whenever we process personal data on your behalf — in the application and through the API.

You accept it when you accept the Terms. No signature is required: Article 28(9) GDPR allows a processing agreement to be in electronic form.

1. What we process, and why

Subject matter. Providing the Lapas nesting service: parsing the drawing files you submit, packing the parts onto sheets, and returning cut files.

Duration. For as long as your account is open, and for the retention periods in section 6.

Nature and purpose. Automated processing — parsing, geometric computation, file generation and storage — solely to produce the output you asked for.

Types of data. The content of the files you submit. Drawing geometry is not usually personal data, but CAD files routinely carry author names, file paths, company names in title blocks and text on layers, so we treat submitted files as if they may contain personal data.

Categories of data subject. Your personnel and your own customers, to the extent they appear in the files you submit.

Special categories. None. You must not submit special-category data under Article 9, and the Service is not designed to handle it.

2. Our obligations

  • Instructions. We process your files only on your documented instructions — for us, your use of the Service. If we are required by EU or member-state law to process otherwise, we will tell you first unless the law forbids it.
  • Confidentiality. Everyone we authorise to process your data is bound by confidentiality.
  • Security. We implement appropriate technical and organisational measures (section 5).
  • Sub-processors. Only as set out in section 4.
  • Data subject requests. If a request reaches us that relates to your data, we forward it to you and do not answer it ourselves. We will help you answer it, taking account of the nature of the processing.
  • Assistance. We assist you with security, breach notification and data protection impact assessments, taking account of the information available to us.
  • Deletion. Section 6.
  • Information and audit. We make available the information needed to demonstrate compliance with Article 28, and allow audits — see section 7.

3. Your obligations

You are the Controller. You warrant that you have a lawful basis for the data you submit and, where you submit files on behalf of someone else — for example as an ERP vendor or a developer acting for a fabrication shop — that you are authorised to do so and have a processing agreement in place with them. In that case we act as their sub-processor through you.

You must keep your API keys secret. A key identifies your account: anything done with it is treated as done by you until you revoke it, which you can do at any time in the console with immediate effect.

4. Sub-processors

You give general authorisation for us to engage sub-processors. The current list is published at lapas.io/subprocessors.

For the content of files you submit, there is exactly one: Hetzner, which hosts the application in the EU. Every other provider we use touches your account and telemetry data, not your drawings.

Before adding or replacing a sub-processor we will give you at least 30 days' notice by email to your account address, and you may object on reasonable data-protection grounds. If we cannot resolve your objection, you may terminate and we will refund any unused prepaid balance. We impose the same obligations on every sub-processor by contract, and we remain fully liable to you for their performance.

5. Security

  • Encryption in transit (TLS) for everything, including every API request.
  • Encryption at rest for the database.
  • Access to production is limited to those who need it, and authenticated individually.
  • API keys are stored only as a SHA-256 hash. We cannot recover a key, which is why a new key is shown once and never again.
  • Uploaded files are isolated per account; one account cannot read another's files or jobs.
  • Errors and access are logged and monitored.

6. Retention and deletion

  • Files submitted through the API are deleted 7 days after upload.
  • API request logs — the record of which key called which endpoint, when, and with what result — are deleted after 7 days. They contain no file content.
  • Jobs and their results are kept while your account is open, so you can return to them, and are deleted when you delete them or close your account.
  • On termination we delete your data within 30 days, except where EU or member-state law requires us to keep it — invoices, which we keep for the statutory accounting period.
  • Backups roll off within 30 days. Deleted data may persist in a backup until then and is not restored to live systems.

7. Audit

On request, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this DPA. Where that is not enough, you may audit — at your cost, with 30 days' notice, without disrupting the Service, and subject to confidentiality.

8. International transfers

Application infrastructure and file processing are in the EU. Where a provider we use is outside the EU, we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. The providers concerned are named at lapas.io/subprocessors.

9. Personal data breach

We notify you without undue delay after becoming aware of a breach affecting your data, with the information we have at the time, and follow up as we learn more. Notice goes to your account email address. If you want it to reach someone else — the person who actually runs your integration — tell us and we will record that contact.

10. Precedence and changes

Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. We will give at least 30 days' notice of material changes to it, by email.

11. Contact

Data protection questions: privacy@lapas.io.

Pro Sistemos, MB · Company code 306477207 · VAT LT100018954310 · Laisvės al. 110, LT-44253 Kaunas · Lithuania