Lsanyلساني
Business enquiries
Business enquiries
Legal · Business privacy

Business Data Processing Addendum

Last updated: July 16, 2026

This Business Data Processing Addendum (“DPA”) forms part of the agreement between the organization buying Lsany for Business (“Customer”) and LSANY PORTAL, Trade Licence No. 1620246, Dubai, UAE (“Lsany”). It applies where Lsany processes Customer Personal Data to provide the business training service.

Terms such as personal data, processing, controller, processor, and data subject have the meanings given by applicable data-protection law.

1. Roles & Scope

For employee invitation, team membership, seat, job-role routing, assigned track, Customer-directed training brief, and Customer reporting data, Customer determines the business-training purpose and Lsany processes that data to provide the Services. For Lsany’s own billing, fraud prevention, platform security, legal compliance, direct user support, and product administration, Lsany may act as an independent controller as described in the Privacy Policy.

Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its instructions; for informing learners; and for having the necessary authority or lawful basis. Lsany will process Customer Personal Data only on documented instructions in the agreement, order form, product settings, and authorized support requests, unless law requires otherwise.

2. Processing Details

  • Subject and purpose: provision, security, support, customization, assessment, certification, and privacy-safe reporting for Lsany for Business
  • Duration: the business plan term plus the limited period needed for return, deletion, backup cycling, dispute handling, and legal compliance
  • Data subjects: Customer administrators, invited users, employees, contractors, and other authorized learners
  • Data: name or email, account identifier, organization membership and role, job role, seat, assigned tracks, Foundation completion and certification outcome, disclosed role-readiness outcome, employee-requested support category, and Customer-approved training inputs
  • Not included in employer reporting: XP, streaks, exact activity times, failed attempts, wrong answers, raw pronunciation scores, voice recordings, Saqr transcripts, private practice history, private assessment scores, and rankings

Customer must not place health data, biometric data, government identifiers, payment data, employee case details, patient data, customer data, or other sensitive or special-category personal data in a company training brief.

3. Confidentiality & Personnel

Lsany will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access it only as needed for their duties. Lsany will maintain access controls and review elevated access. Customer will restrict its administrator access to personnel with a genuine training need.

4. Security Measures

Taking account of the nature and risk of the processing, Lsany will maintain appropriate technical and organizational measures, including:

  • TLS encryption in transit and provider-supported encryption at rest
  • Authentication, session controls, database row-level security, and exact course-entitlement checks
  • Role-based business administration, with training admins restricted to permitted outcomes
  • Separation of employer outcomes from raw learner activity and a minimum cohort of five for readiness aggregates
  • Rate limits, request validation, least-privilege service access, security logging, dependency and configuration review, and incident response procedures
  • Session-scoped caching for paid browser content and removal on sign-out
  • Backup, availability, recovery, and vendor-management measures appropriate to the service

No security measure eliminates all risk. The parties will cooperate to reduce foreseeable risk and respond to incidents.

5. Subprocessors & International Processing

Customer authorizes Lsany to use subprocessors for cloud hosting, database and authentication, payment, email, monitoring, speech-to-text, and AI processing. Lsany will select providers with appropriate safeguards and require data-protection obligations appropriate to the service. Lsany remains responsible for its obligations under this DPA.

Some providers may process data outside the UAE. Lsany will use an applicable transfer mechanism and appropriate contractual, organizational, and technical safeguards. Lsany will provide reasonable information about relevant subprocessor categories and material changes on request. Customer may raise a reasonable documented data-protection objection; the parties will work in good faith on a practical solution.

6. Rights, Requests & Incidents

Taking account of the nature of processing, Lsany will reasonably assist Customer with verified requests for access, correction, deletion, portability, restriction, objection, or information about automated processing. Lsany may respond directly where it acts as controller or where Customer has authorized it.

Lsany will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and will provide available information about the nature, likely effects, affected records, and mitigation. Customer is responsible for notifications it is legally required to make as controller; Lsany will provide reasonable assistance.

7. Return, Deletion & Audit Information

At the end of the Services, Lsany will delete or return Customer Personal Data on Customer’s written request, unless law requires retention. Deletion from active systems may take up to 30 days, with encrypted backups aging out under the normal backup cycle. Aggregated or de-identified information that cannot identify a person may be retained.

On reasonable written request, Lsany will provide information needed to demonstrate compliance with this DPA, subject to confidentiality, security, third-party rights, and reasonable frequency limits. If information is insufficient and law requires an audit, the parties will agree scope, timing, confidentiality, and cost so the audit does not compromise other customers or systems.

8. Reporting Guardrail

The product enforces this rule: Employers see training outcomes, not private learning behavior. Customer will not ask Lsany to provide prohibited raw learner data or attempt to bypass product controls. Optional individual milestones require advance disclosure and appropriate configuration. Customer will not use a Lsany outcome as the sole basis for a decision with a serious legal, employment, financial, health, or safety effect.

Each learner can inspect the same employer-visible record. If Customer believes more data is required, it must contact Lsany for a privacy and necessity review before collection or access is enabled.

Contact

Data-protection requests and incident notices: info@lsany.ae. Business administration: business@lsany.ae.

This DPA should be read with the Lsany for Business Terms and Privacy Policy.

Lsanyلساني
BusinessBusiness TermsBusiness DPAPrivacyContact

© 2026 LSANY PORTAL.

Made in the UAE