Skip to content

Data Processing Addendum

Effective 2026-08-09 · Version 1.1

This Data Processing Addendum, including its Annexes ("DPA"), forms part of and is incorporated by reference into the agreement between the customer ("Customer") and Vista del Lago Software LLC, a Delaware limited liability company ("Vista del Lago", "we", "us"), which operates the Lonzo service under that name. This DPA forms part of the agreement governing Customer's use of the Lonzo service (the "Service"). The master agreement is the Lonzo Terms of Use (the "Agreement"). This DPA governs the Processing of Personal Data that Vista del Lago carries out on behalf of Customer in connection with Lonzo.

Where Customer is a business, organization, or individual who is a Controller (or a Processor acting for another Controller) of Personal Data that is subject to Data Protection Laws, this DPA applies and prevails over any conflicting term of the Agreement with respect to that Personal Data. By accepting the Agreement, or by using the Service after this DPA is made available, Customer agrees to this DPA on its own behalf and, to the extent required, on behalf of its Authorized Users.


1. Definitions

Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. In this DPA:

  • "Actor" means the identity-bound execution scope of a single human account holder within the Fabric architecture underlying Lonzo. Each Actor's data is cryptographically isolated from every other Actor's data as described in Annex II.
  • "Actor-Scoped Data" means Personal Data that is bound to, and encrypted under keys unique to, a single Actor.
  • "Authorized User" means an individual whom Customer permits to use the Service under Customer's account.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR, and equivalent terms in other Data Protection Laws are construed accordingly.
  • "CCPA" means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020, and its regulations.
  • "Customer Personal Data" means Personal Data that Vista del Lago Processes on behalf of Customer under the Agreement, as described in Annex I.
  • "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable: (a) the EU General Data Protection Regulation (Regulation 2016/679) ("GDPR"); (b) the GDPR as incorporated into the law of the United Kingdom ("UK GDPR") together with the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection ("FADP"); and (d) US State Privacy Laws.
  • "DPF" means the EU–US Data Privacy Framework, the UK Extension thereto, and the Swiss–US Data Privacy Framework.
  • "SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
  • "Sub-processor" means any third party engaged by Vista del Lago that Processes Customer Personal Data. The current list of Sub-processors is published at lonzo.ai/legal/subprocessors.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force 21 March 2022).
  • "US State Privacy Laws" means, as applicable, the CCPA, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and other comprehensive US state privacy statutes then in effect.

2. Roles and Scope of Processing

2.1 Roles. As between the parties and with respect to Customer Personal Data, Customer is the Controller (or, where Customer is itself a Processor acting on behalf of a third-party Controller, a Processor), and Vista del Lago is the Processor. Vista del Lago Processes Customer Personal Data only on behalf of Customer.

2.2 Customer instructions. Vista del Lago Processes Customer Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do otherwise by applicable law (in which case Vista del Lago will inform Customer of that legal requirement before Processing, unless the law prohibits such notice). The Agreement, this DPA, and Customer's use of the Service in accordance with the Agreement together constitute Customer's complete and final documented instructions to Vista del Lago. Vista del Lago will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

2.3 Customer responsibilities. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for the lawful basis on which it was collected, including providing any notices and obtaining any consents required for Vista del Lago to Process Customer Personal Data as contemplated by the Agreement. Customer is solely responsible for compliance obligations relating to any email, calendar, contact, or task communications initiated through the Service, including applicable anti-spam laws.

2.4 Vista del Lago as Controller. Vista del Lago acts as an independent Controller for a limited set of Processing that is not carried out on Customer's behalf, namely: (a) account, authentication, and billing administration; (b) fraud prevention, abuse detection, and security of the Service; (c) meeting Vista del Lago's own legal and regulatory obligations; and (d) creating and using de-identified or aggregated data that does not identify Customer, any Authorized User, or any Data Subject, to operate, secure, and improve the Service. Vista del Lago's Processing as a Controller is governed by Vista del Lago's Privacy Policy, not this DPA.

2.5 No sale or sharing. Vista del Lago does not sell Customer Personal Data and does not share it for cross-context behavioral advertising. Vista del Lago does not retain, use, or disclose Customer Personal Data for any purpose other than the specific purpose of performing the Service, or as otherwise permitted by Data Protection Laws.

2.6 Special categories of data. The Service is not designed or intended to Process special categories of Personal Data (GDPR Art. 9) or comparable sensitive data. Vista del Lago does not solicit such data. Customer acknowledges that email bodies, calendar entries, and other free-text content synced or submitted to the Service may nonetheless contain sensitive information, and Customer is solely responsible for ensuring it has a lawful basis for any such Processing. Customer must not use the Service to Process special-category data where doing so would require safeguards the Service does not provide.

3. Confidentiality

Vista del Lago ensures that persons authorized to Process Customer Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory) and are made aware of the confidential nature of the data. Access to Customer Personal Data is limited to personnel who require it to perform the Agreement.

4. Security

4.1 Security measures. Vista del Lago implements and maintains the technical and organizational measures set out in Annex II to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risks to Data Subjects. These measures are further described in the Lonzo security overview at lonzo.ai/legal/security-overview.

4.2 Committed measures. The measures in Annex II are contractual commitments, not merely a description of current practice. Vista del Lago may update them from time to time provided the updates do not materially reduce the overall level of protection.

5. Sub-processors

5.1 General authorization. Customer grants Vista del Lago general written authorization to engage Sub-processors to Process Customer Personal Data, subject to this Section 5. The current list of Sub-processors, including their Processing activities and locations, is published at lonzo.ai/legal/subprocessors.

5.2 Flow-down. Vista del Lago imposes on each Sub-processor, by written contract, data-protection obligations that are at least as protective as those in this DPA, to the extent applicable to the nature of the Sub-processor's services. Vista del Lago remains fully liable to Customer for the performance of each Sub-processor's obligations.

5.3 Change notice and objection. Vista del Lago posts intended additions or replacements of Sub-processors on the Sub-processor page at lonzo.ai/legal/subprocessors, and notifies subscribers who have subscribed to change notifications as described on that page. Vista del Lago will provide such notice at least thirty (30) days before the new Sub-processor begins Processing Customer Personal Data. Customer may object on reasonable data-protection grounds within thirty (30) days of the notice by writing to privacy@lonzo.ai. If Customer does not object within that period, the change is deemed accepted. If Customer objects and the parties cannot resolve the objection, Customer may, as its sole remedy, terminate the portion of the Service that cannot be provided without the objected-to Sub-processor, without penalty.

6. International Transfers

6.1 Location. Vista del Lago Processes Customer Personal Data in the United States. Where Customer Personal Data originates in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the transfer mechanisms in this Section 6 apply.

6.2 EEA transfers. The SCCs are hereby incorporated by reference and apply to transfers of Customer Personal Data from the EEA to Vista del Lago, with Module Two (Controller to Processor) applying where Customer is a Controller and Module Three (Processor to Processor) applying where Customer is a Processor. The SCCs are completed as follows: (a) Clause 7 (docking clause) does not apply; (b) Clause 9, Option 2 (general written authorization) applies, with the notice period specified in Section 5.3; (c) Clause 11 (independent dispute resolution) does not apply; (d) Clause 17 (governing law) is the law of Ireland; and (e) Clause 18 (forum and jurisdiction) is the courts of Ireland. The competent supervisory authority is the Irish Data Protection Commission (DPC). Annex I and Annex II to this DPA populate the corresponding annexes to the SCCs.

6.3 UK transfers. Transfers from the United Kingdom are governed by the SCCs as completed in Section 6.2, as amended by the UK Addendum, which is incorporated by reference. Tables 1–3 of the UK Addendum are populated by the corresponding information in Section 6.2 and the Annexes; Table 4 selects "Importer and Exporter."

6.4 Swiss transfers. Transfers from Switzerland are governed by the SCCs as completed in Section 6.2, with the following adjustments: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may enforce their rights in Switzerland (Clause 18(c)).

6.5 Transfer basis — primary and fallback. The SCCs (as completed above), the UK Addendum, and the Swiss adjustments are the primary transfer mechanism for EEA, UK, and Swiss transfers respectively. Vista del Lago additionally intends to rely on the EU–US Data Privacy Framework, the UK Extension thereto, and the Swiss–US Data Privacy Framework once Vista del Lago self-certifies to those frameworks. Vista del Lago is not yet certified under the DPF and makes no claim that the DPF is currently an active transfer mechanism. Where and for so long as Vista del Lago maintains an active certification under the DPF, the DPF becomes a transfer mechanism for transfers covered by that certification, and the SCCs (with the UK Addendum and Swiss adjustments) serve as the fallback mechanism that applies automatically if the DPF certification lapses or the DPF is invalidated or suspended for the relevant jurisdiction.

6.6 SCC signatory details. The parties' details for Annex I of the SCCs are set out in Annex I to this DPA. The data importer is Vista del Lago Software LLC, 18381 Vista del Lago, Yorba Linda, CA 92886, USA; authorized contact for data-protection matters: privacy@lonzo.ai.

6.7 Article 27 EEA/UK representative. The EEA and the United Kingdom are in scope. Because Vista del Lago has no establishment in the EEA or the United Kingdom, Vista del Lago has appointed an EEA representative and a UK representative under GDPR Art. 27 and UK GDPR Art. 27. Interim contact for both: privacy@lonzo.ai (attn: "EU Representative" / "UK Representative"). We will publish the representative's name and registered EEA and UK address on this page once appointed.

Data Protection Officer. Vista del Lago has not appointed a Data Protection Officer, as one is not required (no large-scale systematic monitoring or special-category processing as a core activity). Data-protection contact: privacy@lonzo.ai.

7. Data Subject Requests

7.1 Assistance. Taking into account the nature of the Processing, Vista del Lago assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights under Data Protection Laws.

7.2 Self-service, request-based assistance, and redirection. Because Customer Personal Data is Actor-scoped by construction, Customer or its Authorized Users can access and correct Actor-Scoped Data in the Service, disconnect the connected Google account (which revokes Vista del Lago's access to it), and delete an individual assistant conversation. Export, deletion of an account and its data, and deletion of individual categories of data are request-based: Vista del Lago fulfils them on request to privacy@lonzo.ai, and account deletion may also be requested from a public page requiring no sign-in at lonzo.ai/delete-account. The Service does not currently provide an in-product control for those three. If a Data Subject request is made directly to Vista del Lago regarding Customer Personal Data, Vista del Lago will, unless legally required to respond, promptly redirect the Data Subject to Customer, who is responsible for responding.

7.3 Costs. Where a request is unreasonable or repetitive, Vista del Lago may charge a reasonable, pre-agreed fee for that assistance.

8. Assistance with Compliance

Taking into account the nature of Processing and the information available to Vista del Lago, Vista del Lago provides reasonable assistance to Customer with: (a) data protection impact assessments under GDPR Art. 35; (b) prior consultations with supervisory authorities under GDPR Art. 36; and (c) Vista del Lago's obligations under GDPR Arts. 32–36. Vista del Lago maintains records of its Processing activities as required by GDPR Art. 30(2).

9. Personal Data Breach Notification

9.1 Notice. Vista del Lago notifies Customer without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 Content. The notice describes, to the extent known and as it becomes available: the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information.

9.3 Forensic capability. Vista del Lago's immutable per-decryption audit log (Annex II) enables Vista del Lago to characterize the scope of any incident involving decrypted Actor-Scoped Data with a high degree of precision.

10. Audit and Information Rights

10.1 Information. Vista del Lago makes available to Customer information reasonably necessary to demonstrate compliance with this DPA and GDPR Art. 28.

10.2 Third-party reports. Vista del Lago does not currently hold a third-party audit report or certification (no SOC 2 or ISO 27001; see the security overview). In the first instance, Vista del Lago satisfies Customer's audit right by answering reasonable written security questionnaires and sharing its security documentation as Confidential Information. Where Vista del Lago later obtains a third-party audit report or certification, it will make the then-current report available as Confidential Information.

10.3 On-site audits. Where third-party reports are insufficient to demonstrate compliance, Customer (or an independent auditor mandated by Customer and not a competitor of Vista del Lago) may conduct an audit no more than once per calendar year (and additionally following a Personal Data Breach), on at least thirty (30) days' prior written notice, during business hours, subject to confidentiality, and without unreasonably disrupting Vista del Lago's operations. Customer bears the costs of any such audit.

11. Deletion and Return

11.1 On termination. Upon termination or expiry of the Agreement, Vista del Lago deletes or returns all Customer Personal Data at Customer's election, and deletes existing copies, within thirty (30) days unless retention is required by applicable law. This window is reconciled with the deletion-completion SLA in the Lonzo data retention & deletion policy; the two must state the same number if either changes. Where Customer elects return rather than deletion, the return of data is effected on request to privacy@lonzo.ai, and Vista del Lago provides the Actor-Scoped Data it holds in a portable, machine-readable format (JSON and/or mbox) before deletion. Return is request-based; the Service does not currently provide an in-product export control.

11.2 Irrecoverability. Deletion under this Section renders Customer Personal Data irrecoverable. Actor-Scoped Data is protected by per-Actor envelope encryption; destroying an Actor's key hierarchy cryptographically shreds all of that Actor's ciphertext, including copies held in backups, rendering it permanently unrecoverable. Deletion mechanics and timelines are described in the Lonzo data retention & deletion policy at lonzo.ai/legal/data-retention-deletion.

11.3 Legal retention. Vista del Lago may retain Customer Personal Data to the extent required by applicable law, subject to legal hold, or as necessary to establish, exercise, or defend legal claims; any such retained data remains encrypted and access-restricted and is subject to the confidentiality and security obligations of this DPA.

12. US State Privacy Laws

12.1 Roles. With respect to Customer Personal Data subject to US State Privacy Laws, Customer is the "business" or "controller" and Vista del Lago is the "service provider," "processor," or "contractor," as those terms are defined by the applicable law.

12.2 Restrictions. Vista del Lago will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the specific business purpose of performing the Service, or as otherwise permitted by US State Privacy Laws; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or (d) combine Customer Personal Data with Personal Data obtained from other sources, except as permitted by US State Privacy Laws.

12.3 Certification and compliance. Vista del Lago certifies that it understands and will comply with the restrictions in Section 12.2. Vista del Lago will notify Customer if it determines that it can no longer meet its obligations under applicable US State Privacy Laws, and Customer may take reasonable steps to stop and remediate unauthorized Processing. Vista del Lago flows these obligations down to its Sub-processors.

13. Artificial Intelligence Processing

13.1 Inference. To provide its assistant features, the Service submits Customer content — including email and calendar content — to a large-language-model inference Sub-processor (AWS Bedrock, running the Nova, Claude, and Titan model families) for the purpose of generating responses and derived outputs on Customer's behalf. This Processing is carried out under Customer's instructions and solely to provide the Service.

13.2 Decryption for inference. Actor-Scoped Data is decrypted only for bounded, specified purposes (including inference) under the purpose-bound decryption controls described in Annex II, and every such decryption is recorded in an immutable audit log. There is no bulk-decrypt path.

13.3 No training; no retention. Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum (which incorporates the EU Standard Contractual Clauses); Amazon Bedrock is also a HIPAA-eligible service under BAA and is in scope for AWS SOC and ISO 27001/27017/27018 reports.

14. General

14.1 Precedence. In the event of a conflict concerning the Processing of Customer Personal Data, the following order of precedence applies: (a) Data Protection Laws; (b) the SCCs and other transfer mechanisms in Section 6; (c) this DPA; and (d) the Agreement.

14.2 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

14.3 Term and survival. This DPA takes effect on the Effective Date and remains in force for as long as Vista del Lago Processes Customer Personal Data under the Agreement. Provisions that by their nature should survive termination — including Sections 3, 9, 11, and 14 — survive.

14.4 Changes. Vista del Lago may amend this DPA where required to comply with Data Protection Laws, on reasonable notice, provided the amendment does not materially reduce Customer's protections.

14.5 Incorporation. This DPA is incorporated into and forms part of the Agreement — the Lonzo Terms of Use — and the Terms of Use in turn incorporate this DPA by reference. Except as expressly modified here, the Agreement remains in full force and effect.


Annex I — Description of Processing

A. List of parties

  • Data exporter (Controller / Processor): Customer, as identified in the Agreement. Contact: the account owner or administrator designated in Customer's account.
  • Data importer (Processor): Vista del Lago Software LLC, 18381 Vista del Lago, Yorba Linda, CA 92886, USA. Contact for data-protection matters: privacy@lonzo.ai.

B. Subject matter and duration. The subject matter is Vista del Lago's provision of the Lonzo service. The duration is the term of the Agreement plus the deletion window in Section 11.

C. Nature and purpose of Processing. Collection, storage (as caches), organization, structuring, retrieval, use, and — for the inference purpose only — controlled decryption and transmission to the inference Sub-processor, all to provide the assistant, scheduling, messaging, and organization features of the Service on Customer's behalf.

D. Categories of Data Subjects.

  • The human account holder (the "Actor") and their Authorized Users.
  • The account holder's correspondents, contacts, and meeting participants whose Personal Data appears in synced Gmail, Calendar, Contacts, or Tasks data, or in messages handled by the Service.

E. Categories of Personal Data.

  • Email message metadata and message bodies (cached, not authoritative), including sender/recipient addresses, subjects, timestamps, and content.
  • Calendar events, including titles, descriptions, times, locations, and participant details.
  • Contacts, including names, email addresses, phone numbers, and related fields.
  • Tasks and related content.
  • Account identity and authentication data.
  • Subscription status and the purchase/subscription tokens provided by Google Play (no payment-card data — Google Play holds the payment method).

F. Special categories of data. Not intended or solicited. Free-text content (email/calendar/tasks) may incidentally contain special-category data; see Section 2.6. Customer is responsible for the lawful basis of any such data.

G. Frequency of transfer. Continuous, for the duration of the Agreement.

H. Authoritative source. Google is the authoritative source for the email, calendar, contacts, and tasks data synced into the Service; Vista del Lago holds caches of that data only.

I. Retention. As described in Section 11 and the Lonzo data retention & deletion policy. In summary: cached Gmail bodies expire on a short (~30-day) TTL; authentication audit events are retained for at least 90 days; the account-lifecycle log is de-identified after account deletion, with no identifiable lifecycle record retained beyond the 30-day deletion window.

J. Sub-processors. As published at lonzo.ai/legal/subprocessors, with the transfer details in Section 6.

K. Competent supervisory authority (for SCC purposes). The Irish Data Protection Commission (DPC).

Annex II — Technical and Organizational Measures

Vista del Lago maintains the following measures. They are summarized here and described in fuller, user-facing terms in the Lonzo security overview at lonzo.ai/legal/security-overview.

1. Encryption at rest — per-Actor envelope encryption. Each human Actor's data is encrypted under a per-Actor AES-256-GCM data key (the "ADK"). Each ADK is itself wrapped by a hardware-security-module-backed key-encryption key (the "KEK", AES-256-KW), one per human Actor. Encryption and decryption occur at the Kernel layer; application logic never handles plaintext keys or ciphertext.

2. Encryption in transit. TLS 1.3 for data in transit; mutual TLS (mTLS) between internal services.

3. Purpose-bound decryption and audit ledger. Actor-Scoped Data is decrypted only for bounded, specified purposes. Every decryption is recorded in an immutable, per-event audit log. There is no bulk-decrypt path.

4. Structural cross-Actor isolation. Cross-Actor data access is structurally inexpressible in the Fabric-Starlark execution language; isolation is enforced by the execution model, and one Actor's data is encrypted under a key another Actor's execution context cannot obtain.

5. Access control. Least-privilege internal access; access to production restricted to authorized personnel. Multi-factor authentication is mandatory for all staff access to production and to environments that can reach user data; a phishing-resistant WebAuthn/FIDO2 hardware security key is required for administrative and production access (TOTP authenticator otherwise). Personnel are bound by confidentiality agreements, access grants are reviewed on a recurring basis, and background screening is conducted where lawful.

6. Logging and monitoring. Audit logging of access to Customer Personal Data and monitoring for anomalous decryption patterns.

7. Deletion. Crypto-shred deletion by destruction of per-Actor key material, rendering ciphertext (including backup copies) irrecoverable.

8. Resilience. Encrypted backups on a 30-day rolling purge cycle; multi-AZ redundancy within a single AWS US region; use of a major cloud infrastructure provider (AWS, US regions) whose own infrastructure certifications provide inherited assurance.


All legal documents · Help · Lonzo home