Data processing agreement
Last updated 23 September 2026
Parties and scope
This data processing agreement (verwerkersovereenkomst) under article 28 GDPR is part of our terms of service. It applies between the customer who hosts meetings (the controller) and RG-IT (the processor):
RG-IT B.V. · Vlotstraat 20, 6417 CB Heerlen, the Netherlands · KvK 51460602 · VAT NL850028954B01 · hello@leanbrew.app
It is accepted together with the terms when creating an account. You can save or print this page; a signed copy is available on request.
1. Subject, nature and purpose
We process personal data only to provide LeanBrew to you: running meetings where participants add topics, vote, discuss and record notes and actions, and delivering minutes, exports, reminders and integrations you enable. The processing lasts as long as you use the service, plus the deletion period below.
2. Personal data and data subjects
- Data subjects: your users, the participants and guests you invite, and people mentioned in meeting content.
- Personal data: names entered by participants, account names and email addresses of members, and whatever personal data appears in topics, notes and actions. Please don't put special categories of personal data (such as health data) into meetings.
3. Your instructions
We process the data only on your documented instructions, which are these terms and the way you configure and use the service. We tell you if we believe an instruction breaks the law. We don't use the data for our own purposes.
4. Confidentiality and security
Anyone processing the data for us is bound to confidentiality. We take appropriate technical and organisational measures (article 32 GDPR), including encryption in transit, hashed passwords, access limited to what's needed, rate limiting and hosting with established EU-region cloud providers.
5. Sub-processors
You give general permission to use these sub-processors: Google Cloud (hosting, europe-west4, the Netherlands), MongoDB Atlas (database), Resend (account emails), Stripe (payments) and Slack (only when you connect it). We bind them to equivalent obligations. We announce changes to this list at least 30 days in advance on this page and by email; you may object, and if we can't resolve it you may end your subscription. Transfers outside the EU take place only under an adequacy decision (such as the EU-US Data Privacy Framework) or standard contractual clauses.
6. Helping you
We help you, as far as reasonable, to respond to requests from data subjects (you can also delete and export data yourself in the app), and with security, data protection impact assessments and prior consultation (articles 32–36 GDPR).
7. Data breaches
We notify you without undue delay, and where possible within 48 hours after discovery, of a personal data breach affecting your data, with the information you need to meet your own notification duties.
8. Audits
We make available the information needed to demonstrate compliance with this agreement. You may have an audit carried out once a year, at your own cost, with reasonable notice and confidentiality, if the information we provide isn't sufficient.
9. End of processing
When your account ends, we delete the meeting content within 30 days, unless the law requires us to keep it. Before that you can export your minutes and actions at any time.
10. Liability and precedence
The liability limits of the terms of service apply. If this agreement and the terms conflict on data protection, this agreement prevails.
Version 2026-09-23.