Legal
Data processing agreement (DPA)
This agreement under Art. 28 (3) GDPR applies between the customer of Lampo Cloud as controller and nprompt UG (haftungsbeschränkt) as processor. It is concluded when a customer acting as a business (§ 14 BGB) accepts the terms, and is part of that contract for Lampo Cloud.
1. Subject and duration
(1) The processor provides the hosted service Lampo Cloud (app.lampo.video, media.lampo.video) to the controller. In doing so it processes personal data that the controller and the people and agents it authorises put into its workspaces, and the records of its review links.
(2) The agreement applies for as long as the contract for Lampo Cloud exists, and beyond that until all data have been deleted or returned under section 9.
2. Nature and purpose of the processing, types of data, data subjects
(1) Nature and purpose: storing; making preview and playback copies; running speech recognition and automatic checks (spelling on screen, loudness, picture faults) on our own servers; showing the data to the people, agents and review-link visitors the controller gives access to; sending email and push notifications about what happens in the workspace; making analysis within the workspace (Insights, who watched a video) for the controller; passing data on the controller's instructions to services it connects (for example when publishing).
(2) Types of data: videos and their versions, screenshots, notes, drawings, voice notes and their transcripts, attached files, playbooks, names and email addresses of members and invited people, names that review-link visitors type, their notes, approvals and downloads, and the review links' records (when opened, which parts of a version played and how often). What can be seen or heard in the videos and files themselves is up to the controller.
(3) Data subjects: members of the workspace and invited people, review-link visitors (such as the controller's clients), people who appear in videos, files or notes.
3. Instructions
(1) The processor processes the data only on the controller's documented instructions, including transfers to a third country, unless Union or German law requires it to; in that case it tells the controller before processing, unless that law forbids it.
(2) The instructions are this agreement, the terms, and what the controller sets up and triggers in the service (uploading, sharing and deleting content, connecting services). The controller gives further instructions in text form to hello@lampo.video.
(3) If the processor considers an instruction unlawful, it tells the controller without delay; it may suspend it until the controller confirms or changes it.
4. Confidentiality
The processor uses only people who have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and only as far as the service needs.
5. Security of processing
The processor takes the technical and organisational measures under Art. 32 GDPR described in Annex 1. It may develop them further as long as the level of protection does not fall.
6. Sub-processors
(1) The controller authorises the sub-processors listed in Annex 2.
(2) The processor announces a new or different sub-processor at least 30 days in advance: by email to the workspaces' owners and admins and on this page. Within that period the controller may object in text form on reasonable data protection grounds. If the parties find no solution, the controller may terminate the contract for Lampo Cloud as of the change; fees already paid for the time after it are refunded pro rata.
(3) The processor imposes the same data protection obligations as this agreement on every sub-processor by contract and is liable for it as for its own acts.
7. Assisting the controller
(1) The processor assists the controller with appropriate measures in answering data subjects' requests (Art. 12–23 GDPR). Much of it the controller can do itself in the service: download, change and delete content, revoke and delete review links. If a data subject contacts the processor directly, it forwards the request to the controller.
(2) It assists the controller with the obligations under Art. 32 to 36 GDPR (security, notifications, data protection impact assessment, prior consultation) with the information available to it.
8. Personal data breaches
The processor notifies the controller of a personal data breach without undue delay, where possible within 48 hours of becoming aware of it, by email to the workspace's owners, with the information under Art. 33 (3) GDPR as far as it has it, and takes the measures needed to mitigate its effects.
9. Deletion and return
(1) During the term, the controller can download and delete its data at any time.
(2) After the contract ends, the processor deletes the data within 30 days, unless Union or German law requires them to be kept. Until then the controller can download them. Deleted data remain in backups for up to twelve months (Annex 1); they are only brought back from them when recovering from an outage, and are finally deleted when the backups expire.
10. Evidence and audits
(1) The processor makes available to the controller all information needed to demonstrate compliance with this agreement.
(2) It allows for and contributes to audits, including inspections, by the controller or an auditor it appoints who is bound to confidentiality: with reasonable notice, during business hours, without disturbing operations, as a rule at most once a year, except after a breach under section 8. The controller bears the costs of an inspection.
11. Place of processing
The data are stored and processed on servers in Germany. Transfers to a third country take place only as Annex 2 names them, and only under the conditions of Chapter V GDPR.
12. Liability and precedence
(1) Liability follows Art. 82 GDPR; otherwise the terms apply.
(2) For the protection of personal data this agreement takes precedence over the terms. German law applies. The German version is binding.
Parties
Processor: nprompt UG (haftungsbeschränkt), Güglinger Str. 16, 70435 Stuttgart, Germany, Amtsgericht Stuttgart HRB 792779, represented by its managing director Philip Verropoulos. Contact for data protection: hello@lampo.video.
Controller: the customer, as given in its account and billing details at Lampo Cloud.
Annex 1: Technical and organisational measures
- Data centre: servers of Hetzner Online GmbH in its Falkenstein data centre (Germany), certified to ISO/IEC 27001, with access control, video surveillance and fire protection by the operator.
- Access to the servers: only for named administrators, by SSH with keys; a firewall lets through only the ports the service needs.
- Transmission: encrypted only (TLS 1.2 and 1.3, HSTS). The app sits behind Cloudflare (protection against attacks); videos travel directly between the browser and our server, through signed addresses that expire.
- Access to the service: sign-in with a password (stored only as a scrypt hash) or through connected apps (OAuth); API tokens stored only as a hash; limits on sign-in and password attempts; alerts about new sign-ins. Roles per workspace (owner, admin, reviewer); review links see only their own videos and can be restricted with a password, an expiry date and without downloads.
- Separation: each workspace's data are kept apart from other workspaces'; nobody sees that another workspace exists.
- Encryption of stored secrets: credentials of connected services are stored encrypted (AES-256-GCM); emails wait encrypted in the queue until sent.
- Pseudonymisation and data minimisation: review-link visitors are told apart by a derived key that differs per link; IP addresses are not stored; logs contain no requests, IP addresses, passwords or tokens, and email addresses only as a non-reversible hash.
- Processing in house: speech recognition and automatic checks run on our own servers; content goes to no third party for them.
- Availability and recovery: an encrypted backup every night (restic) to separate storage (a Storage Box) of Hetzner Online GmbH in Germany, kept on the schedule 14 daily, 8 weekly, 12 monthly; restoring is tested. Availability is monitored (status.lampo.video).
- Logs: only start, warnings, failed background tasks and references to server errors; overwritten continuously (at most five files of 10 MB).
- Deletion: content is deleted when the controller deletes it; a workspace with all its data when its owner deletes it; from backups after twelve months at the latest.
- Organisation: changes to the service go through reviewed changes to the source code with automated tests; security reviews of the code are documented; security issues are reported to security@lampo.video.
Annex 2: Sub-processors
| Sub-processor | Service | Where | Basis of a transfer |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | servers, storage and backups | Germany | – |
| Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA | reverse proxy and protection against attacks for app.lampo.video, DNS, TLS (videos don't pass through Cloudflare) | worldwide, USA | Data Privacy Framework, standard contractual clauses |
| Plus Five Five, Inc. ("Resend"), San Francisco, USA | sending the service's emails (invites, notifications) | EU data centre; company in the USA | Data Privacy Framework, standard contractual clauses |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | our team's mailbox: only what the controller writes to us (support) | EU, USA (Google LLC) | Data Privacy Framework |
Not sub-processors for the workspaces' content: Stripe (receives only billing data, for which we are the controller ourselves), the browser makers' push services (they only carry end-to-end encrypted notifications that the recipient turned on) and services the controller connects itself (such as YouTube, Zernio, AI agents): data go there only on its instructions and under its responsibility.
As of: 6 October 2026.