
Last updated: 14 July 2026. Changed: AI features enabled inside Ledidi
Suite.This Data Processing Addendum ("DPA") supplements the Ledidi Subscription Agreement and the Terms of Service governing the use of the Services.
This DPA is an agreement between The Customer or User as the "Controller" and Ledidi as the "Processor" (together referred to as the "Parties").
Introduction
In the event of a conflict between this DPA and the Subscription Agreement or the Terms of Service, this DPA shall prevail.
The parties have agreed to this DPA to establish the respective Parties' rights and obligations regarding Processing of Personal Data.
All capitalized terms in this Data Processing Addendum relating to the Processing of Personal Data shall have the same meaning as set out in EU Regulation 2016/679 ("GDPR"), UK GDPR and its applicable national implementation.
Roles and responsibilities
Ledidi is the Processor of Personal Data as a result of the Controller's use of Ledidi's Services. Ledidi is only processing Personal Data included in the User Content on behalf of the Controller in accordance with the Controller's instructions and this DPA and will comply with all applicable data protection legislation.
The Controller warrants that it has a legal basis for all Data Processing for which Ledidi is instructed to carry out on behalf of the Controller under this DPA.
Taking into account the nature of the processing, Controller agrees that it is unlikely that Ledidi would become aware that Controller Data transferred under the Standard Contractual Clauses is inaccurate or outdated.
For Personal Data related to the User's use of the Services that is not User Content, Ledidi will act as Controller. Please refer to Ledidi's Privacy Policy.
Data processing
The Processor will always act on the Controller's instruction.
1. Subject matter
The subject matter of the data processing under this DPA is personal data included in the "User Content", which refers to the data the User enters into a project using the User's Ledidi user account. It also includes any other personal data related to the User's use of Ledidi's Services that is not specifically mentioned in the Privacy Policy where Ledidi is the Controller.
2. Duration of the processing
The duration of the processing shall be in accordance with the Controller's instructions and the terms of this DPA.
3. Purpose
The purpose of the data processing under this DPA is the provision of the Services initiated by the Controller, including (where opted in by the Controller) the AI Features described below.
4. Nature of the processing
Compute, storage, and other Services as described in the Documentation and initiated by the Controller. Where AI Features are enabled, the nature of the processing also includes natural-language-driven generation and modification of Project Metadata, assisted by AWS Bedrock (EU-scoped) as an AI sub-processor.
5. Type of personal data
The types of Personal Data processed by Ledidi when providing the Services include Personal Data that the Controller elects to upload to the Controller's Ledidi account.
6. Categories of data subjects
The data subjects could include the Controller's employees, patients, healthy controls, suppliers, collaborators and end-users (including, where applicable, children and other vulnerable individuals, for whom the Controller is responsible for any additional safeguards and consents required by law) or any other categories of data subjects as identified in the data (User Content) that is uploaded to and processed in connection with use of the Services by the Controller.
AI processing in Ledidi Suite
Ledidi Suite offers optional AI Features (including the study-design assistant and any successor features) that operate on a defined subset of User Content known as Project Metadata. Project Metadata includes variable definitions, project names and descriptions, schedule structures, form elements (labels, types, category options, validations, visibility conditions), and analysis configuration. AI Features do not access participant records, form responses, health data, or personal identifiers. This scope boundary is enforced architecturally through the set of tools made available to the AI.
Opt-in and Controller instruction
AI Features are disabled by default. They must be opted in at the Controller (organisation) level and again at each individual project. The Controller's instruction to enable AI Features constitutes the Controller's documented instruction under Article 28(3)(a) GDPR for Ledidi to process the Project Metadata of the relevant project through Ledidi's AI sub-processor.
Controller warranty on metadata content
When the Controller enables AI Features on a project, the Controller shall use reasonable efforts to ensure that the Project Metadata of that project does not contain Personal Data, special category data within the meaning of Article 9 GDPR, or other data that must not be subject to AI processing.
The Controller's documented instruction for AI Features to process Project Metadata applies only to the extent that the Project Metadata in scope contains Personal Data. Where the Project Metadata consists solely of non-personal project configuration data, the AI Features operate on that non-personal data outside the scope of Article 28(3) GDPR, without prejudice to the technical and organisational safeguards set out below.
Notification at the point of use
When AI Features are enabled on a project, Ledidi presents an in-product notification to the User immediately before the AI is invoked. The notification reminds the User that the User and the Controller are responsible for ensuring that the Project Metadata in scope does not contain Personal Data, special category data within the meaning of Article 9 GDPR, or other content that the Controller has not authorised for AI processing. The notification is shown on first use of AI Features in a project and is re-surfaced on a periodic basis and whenever the scope of AI Features materially changes. Ledidi does not perform automated content inspection of Project Metadata for the purpose of detecting or preventing Personal Data; the responsibility for the content of Project Metadata sits with the Controller and its Users, as set out above.
Human oversight
Ledidi Suite AI Features operate only in foreground mode. A User must initiate each interaction and approve each AI-generated change before it takes effect. Every AI action is recorded in the project audit trail, attributed to both the AI agent and the instructing User.
Zero retention and no training
Ledidi's AI sub-processor operates under zero-retention terms: prompts and completions are not stored, logged, or used to train, fine-tune, or improve any machine-learning model. Ledidi is contractually prohibited from using User Content to train AI models and extends the same prohibition to its AI sub-processors.
AI features in supporting systems
Ledidi uses AI-enabled features in separate supporting business systems (such as CRM, customer support, billing, and marketing-measurement and analytics platforms) where Ledidi acts as controller. These systems do not have access to User Content processed under this DPA. These supporting-system AI features process data classified by Ledidi as OPEN or INTERNAL only, and do not process Sensitive Personal Data within the meaning of Article 9 GDPR or data classified by Ledidi as CONFIDENTIAL or RESTRICTED. The processing of data in those systems is governed by Ledidi's Privacy Policy, not by this DPA.
The Controller's data in Ledidi Suite is classified and handled in accordance with Ledidi's Data Classification Scheme. Data entered into Ledidi Suite may include data classified at any level and all such data is protected by the security measures described in this DPA.
Sub-processors
Ledidi uses Amazon Web Services, Inc. (AWS) as the only sub-processor under this DPA. All data stored and processed by Ledidi resides on AWS data centres located in Frankfurt, Germany with backup in Stockholm, Sweden. Service providers that Ledidi engages for its own controller-side purposes (such as CRM, analytics, advertising, support and billing) do not process User Content and are not sub-processors under this DPA; those providers are described in Ledidi's Privacy Policy.
Ledidi's use of AWS as a sub-processor includes Amazon Bedrock, used solely to provide AI inference for the AI Features described above. Bedrock is consumed within Ledidi's existing AWS VPC via interface endpoints (AWS PrivateLink) and uses EU-scoped cross-Region inference profiles. No additional sub-processor is engaged for AI inference. Foundation-model providers hosted on Bedrock do not have access to Ledidi's Bedrock accounts or to the Controller's data. Ledidi's engagement with AWS for Bedrock is covered by the AWS Data Processing Agreement with Standard Contractual Clauses referenced elsewhere in this DPA.
For the avoidance of doubt: Ledidi's AI inference supplier for the AI Features is AWS (Amazon Bedrock). The foundation-model providers available through Amazon Bedrock do not receive or access the Controller's prompts, completions, or other User Content, and are therefore not engaged by Ledidi as separate sub-processors for the AI Features. This position is reflected in the Ledidi sub-processor register and Trust Centre.
Ledidi will notify the Controller by email with a minimum of three months' notice in advance of any planned change or replacement of its sub-processor(s) to allow an evaluation of the technical and legal effects of such a change. Ledidi will ensure that the new sub-processor is subject to obligations and limitations at least as strict as those imposed on Ledidi according to this DPA. Ledidi will remain fully liable towards the Controller for the performan ce of the sub-processor's obligations.
The Controller has the opportunity to oppose the change in question. If the Controller has not opposed the change within the end of such a notice period, the change shall be deemed accepted. If the Controller opposes the change and Ledidi is not able to fulfil the Controller's requirements with measures that are commercially reasonable and technically feasible, Ledidi has the right to terminate the Subscription Agreement with one month's written notice.
International data transfer
For any transfer of Personal Data to sub-processors located in a country which is deemed not to provide an adequate level of protection for Personal Data within the meaning of GDPR (a "third country"), Ledidi will enter the EU Standard Contractual Clauses ("SCC") with such sub-processors (acting as data importers).
Ledidi is currently only using AWS as a sub-processor under this DPA and has entered into a data processing agreement with AWS which includes the SCC, and which is available to the Controller upon request. The Controller accepts Ledidi's use of AWS as a sub-processor.
All User Content is stored and processed exclusively within the European Economic Area (Frankfurt, Germany and Stockholm, Sweden). User Content is not routinely transferred to third countries as part of the ordinary provision, storage, and processing of the Services. Limited access to Personal Data from outside the EEA may occur in narrowly defined circumstances — for example, remote technical support performed by Ledidi personnel travelling outside the EEA, incident response, or break-glass engineering access — in which case any such access is governed by appropriate safeguards (including Standard Contractual Clauses where applicable), is limited to what is strictly necessary, and is logged. AWS and its sub-processors may provide support from locations outside the EEA under the terms of the AWS Data Processing Agreement.
AI inference for Ledidi Suite AI Features is performed on EU-scoped AWS Bedrock model deployments. No Project Metadata is transferred to AI model deployments outside the EEA as part of the provision of the AI Features.
Assistance
Ledidi will assist the Controller as necessary to ensure compliance with its legal obligations under applicable data protection laws, such as in connection with the Controller's compliance with the Data Subjects' rights pursuant to GDPR chapter 3, and with the Controller's compliance with GDPR articles 32 to 36. Compensation for such assistance shall be subject to a reasonable compensation based on Ledidi's standard hourly rates for such assistance, or if no such standard rates exist, based on an hourly rate as agreed between the parties. Ledidi will keep accurate records of the Processing activities performed on behalf of the Controller in compliance with this DPA and applicable data protection laws.
Security
Ledidi will, in accordance with GDPR Article 32, implement planned, systematic, and appropriate technical and organisational measures to ensure a level of security appropriate to the risk regarding the confidentiality, integrity and accessibility of the Processing of Personal Data. Information about Ledidi's security measures is provided on Ledidi's website. A more detailed description is available to the Controller upon request.
User Content is protected by encryption in transit (TLS 1.2+) and at rest (AES-256). Access to User Content is restricted to authorised Ledidi personnel operating under strict access controls and confidentiality obligations.
The following additional safeguards apply to AI Features processing Project Metadata:
- Tool-surface enforcement: the AI agent is restricted to a defined set of tools that can only read and modify Project Metadata, and cannot read participant records, form responses, or any data classified as CONFIDENTIAL or RESTRICTED.
- Bounded permissions: the AI's effective permissions are the intersection of the invoking User's permissions and the AI's tool surface. The AI cannot perform any action that the User could not perform manually.
- Audit trail: every AI action is recorded in the project's audit trail, attributed to both the AI agent and the instructing User. Token usage, tool calls, and completion status are logged and monitored.
- Transport security: inference traffic runs on the AWS private network via VPC interface endpoints (AWS PrivateLink) and is encrypted in transit with TLS 1.2+.
- Prompt-injection and scope-breach monitoring: Ledidi monitors AI invocations for anomalous tool usage, prompt-injection patterns, and attempts to access data outside the permitted Project Metadata surface. Ledidi reserves the right to suspend or disable AI Features, for a specific project or across the platform, where such monitoring indicates a material risk to the integrity of the tool-surface boundary. Material findings are reported in the incident register and, where applicable, notified to the Controller in accordance with the Personal Data Breach Notification provisions of this DPA.
Confidentiality
Ledidi will not access or use, or disclose to any third party, any of the Controller's Data, except on the Controller's instruction or as necessary to comply with the law or a valid and binding order of a governmental body.
Ledidi will ensure that persons authorised to Process Personal Data keep confidential all Personal Data and other confidential information provided to them under the Terms of Service and this DPA.
Personal data breach notification
Ledidi shall notify the Controller without undue delay upon Ledidi becoming aware of a Personal Data Breach affecting Controller's Personal Data and provide the Controller with sufficient information to allow the Controller to meet any obligations to report or inform relevant Supervisory Authorities and Data Subjects of the Personal Data Breach under applicable data protection laws.
In parallel, Ledidi will notify the Norwegian Data Protection Authority (Datatilsynet) within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR, where Ledidi determines such notification is required.
Audits
Ledidi will, by itself or through a third-party auditor, regularly conduct security audits on its organisational and technical measures relevant for the Processing of Personal Data pursuant to this Data Processing Addendum.
The Controller has the right to demand security audits performed by an independent third party at the Controller's cost. Ledidi will allow for and contribute to the performance of such third-party audits. Ledidi shall be entitled to claim reasonable compensation for assisting the third-party auditor in accordance with an hourly rate as agreed between the Parties.
The results of any audits shall be documented and made available to the Controller upon request. The Controller is entitled to submit the results of the audit to the Supervisory Authority.
Ledidi will make available to the Controller all information necessary to demonstrate compliance with this DPA upon request.
Changes
Ledidi may change the terms of this DPA upon written notice to the Controller in accordance with the terms regarding changes in the Terms of Service.
Duration
This DPA shall apply for as long as Personal Data is processed by Ledidi on the Controller's instruction.
After termination of the Subscription Agreement, Ledidi will irreversibly delete all Personal Data and all backups in accordance with the data retention policy as set out in the Terms of Service.