Current availability of Lumail's GDPR DPA, SCCs, and transfer documentation
Last reviewed: 2026-08-23
This page is not a Data Processing Agreement and cannot be signed or incorporated into a contract.
Lumail is an early-stage service operated by Codelynx, LLC. Lumail does not currently provide a customer DPA that satisfies GDPR Article 28.
At this time:
If your organization acts as a controller or processor and requires an Article 28 DPA, SCCs, or another transfer mechanism, do not use Lumail to process the affected EEA, UK, or Swiss personal data until the necessary terms have been issued and executed.
The product and its infrastructure are still evolving. Publishing a template that says "DPA" before the processing instructions, audit terms, deletion commitments, breach process, subprocessor notice procedure, transfer modules, and technical measures are ready would create a misleading contract. This status page states the present limitation instead.
The Privacy Policy and GDPR in Lumail describe current practices for transparency, but neither document substitutes for an executed DPA.
Lumail intends to prepare:
This is a roadmap, not a binding promise or release date. The final documents may change after legal and infrastructure review.
If your legal or procurement team needs a DPA now, the accurate answer is that Lumail cannot currently provide one. You can contact [email protected] to register interest and describe your requirements, but contacting us does not authorize EEA processing or create contractual safeguards.
When a signable DPA becomes available, this page will be replaced or updated with the download or acceptance process and the effective version date.