Data Processing Addendum

Effective: 7 September 2026 · Part of the Lath Terms of Service

This Addendum applies when Lath processes personal data of your end users on your behalf.

1. Roles

You are the controller of end-user personal data. Lath is your processor. Where Lath processes data about you, the account holder, Lath is a controller under its Privacy Policy.

2. Instructions

Lath processes end-user data only to provide the service as configured by you through the API, MCP server, CLI or dashboard, and as required by law. Every configuration change you make is an instruction and is recorded in your activity log. If Lath believes an instruction violates data protection law, it will tell you.

3. Details of processing (Annex I)

Item Description
Subject matter sign-in, email and SMS delivery for your product
Duration for the term of the account, plus the deletion window in the Privacy Policy
Nature and purpose authenticating users; storing identities, sessions and consent; composing, sending and tracking messages you direct
Categories of data email addresses, phone numbers, names and profile fields from identity providers, message content, delivery events, consent records, IP address and device type at sign-in
Data subjects your end users and contacts
Special categories none intended; you must not send special-category data through the service

4. Confidentiality and personnel

Lath limits access to personnel who need it, binds them to confidentiality, and logs production access.

5. Security (Annex II)

Encryption in transit (TLS 1.2+) and at rest; tenant isolation enforced by database row-level security; API keys stored hashed; secrets envelope-encrypted with a managed key service; multi-factor authentication for production access; append-only activity and event logs; automated backups with point-in-time recovery; vulnerability management and dependency updates; incident response procedure with notification per section 8.

6. Subprocessors

You authorise the subprocessors named below and will be notified by email at least 14 days before one is added; you may object on reasonable data-protection grounds, and if the objection cannot be resolved you may terminate the affected service. Lath remains responsible for its subprocessors.

Named subprocessors, current as of 2026-09-11 (Annex I(B) to the SCCs):

Subprocessor What it does for Lath Data it can reach Where
Amazon Web Services, Inc. Email delivery; the PostgreSQL databases holding all service data Message content and recipients; all stored personal data United States (us-east-1)
Twilio Inc. SMS delivery and receipt, and carrier registration Phone numbers, message content, delivery status United States
Stripe, Inc. Payment processing for Customer accounts Account holder billing details. No end-user data. United States
Fly.io, Inc. Compute for the API, worker, hosted pages and dashboard Data in transit through the application United States (iad)
Cloudflare, Inc. Authoritative DNS for trylath.com No personal data — DNS records only United States
Functional Software, Inc. (Sentry) Records application errors so faults are grouped, counted and traced to the release that introduced them By configuration, only: the exception type, message and stack trace; the release; the environment identifier; the operation name; and the activity identifier. Request bodies, headers, cookies, query strings, IP addresses and user identifiers are not sent. Free-text fields are additionally redacted for email addresses, phone numbers, API keys and bearer tokens before transmission. No message content, no recipient addresses, no credentials. United States

On the Sentry entry specifically. An error tracker is normally given the whole request context, which for an authentication product would mean tokens, addresses and message bodies. Lath does not do that. The event is rebuilt from an allow-list of the fields named above rather than filtered down from what the library collects, so a future version of that library cannot widen what is sent by adding a field. The activity identifier is what ties an error back to the full record, and that record stays in Lath's own database.

Lath sends mail from via.trylath.com and its per-project subdomains. Card details are entered directly with the payment processor and never reach Lath's systems.

7. Assistance

Lath will help you respond to data-subject requests by providing the API operations to search, export, correct and delete end-user data, and by routing any request that reaches Lath directly to you. Lath will provide reasonable assistance with data-protection impact assessments and consultations with authorities, at your cost where the assistance is extensive.

8. Personal data breach

Lath will notify you without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting your end-user data, with the information you need for your own notification obligations, updated as it becomes available.

9. Deletion and return

On termination, you have 30 days to export end-user data through the API. After that Lath deletes it, except where law requires retention, and confirms deletion on request.

10. Audit

Lath will provide, on request no more than once per year, its current security documentation and any third-party audit reports it holds. Where these do not reasonably satisfy a legal requirement, you may audit at your cost, with 30 days' notice, during business hours, without disrupting the service.

11. International transfers (Annex III)

Where end-user data is transferred from the EEA, UK or Switzerland to the United States, the parties rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two, controller to processor, and the UK International Data Transfer Addendum (IDTA), incorporated by reference, with Lath as data importer.

The annex details those clauses require are completed here:

SCC annex field Value
Data exporter The Customer, acting as controller for its end users. Contact and role as given on the account.
Data importer Lath, acting as processor. Contact: privacy@trylath.com
Activities relevant to the transfer Authenticating end users; storing identities, sessions and consent; composing, sending, receiving and tracking messages the Customer directs
Categories of data subject, data, and special categories As set out in section 3 (Annex I) above
Frequency of transfer Continuous, for the term of the account
Retention As set out in section 9 and the Privacy Policy
Subprocessors and their processing As named in section 6 above
Technical and organisational measures As set out in section 5 (Annex II) above
Competent supervisory authority Determined under Clause 13 by the exporter's establishment or representative
Clause 7 (docking) Included
Clause 9 (subprocessors) Option 2, general written authorisation, with the 14 days' notice given in section 6
Clause 11 (redress) Optional independent dispute-resolution body not included
Clause 17 (governing law) Law of the exporter's EU Member State; where none applies, Ireland
Clause 18 (forum) Courts of that same Member State; where none applies, Ireland
UK IDTA Applies where the transfer is subject to UK GDPR, with the same annex content
Switzerland The SCCs apply with the Swiss FDPIC as supervisory authority and references to the GDPR read as the Swiss FADP

12. Precedence

If this Addendum conflicts with the Terms of Service on a matter of data protection, this Addendum prevails.