Data Processing Agreement
Last updated: February 21, 2026
1. Introduction
This Data Processing Agreement ("DPA") supplements the Lilith Terms of Service and Privacy Policy. It applies to the processing of personal data of users located in the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK), in compliance with the General Data Protection Regulation (GDPR) and the UK GDPR.
2. Definitions
- "Controller" refers to the individual user who determines the purposes and means of processing their personal data through the Service.
- "Processor" refers to Oshun Synthetics LTD, the operator of Lilith, which processes personal data on behalf of the Controller.
- "Personal Data" has the meaning given in Article 4(1) of the GDPR.
- "Sub-processor" refers to any third party engaged by Lilith to process Personal Data.
3. Scope and Purpose of Processing
Lilith processes personal data solely for the purpose of providing the Service as described in the Terms of Service. This includes:
- Account management and authentication
- Delivering personalized experiences across Tara, Veritas, Nyx, Arete, Nisaba, and Metis domains
- Generating cross-domain recommendations and activity insights
- Service improvement through anonymized analytics
- Communication regarding the Service (updates, security notices)
4. Data Subject Rights
Lilith will assist users in exercising their rights under Chapter III of the GDPR, including:
- Right of access (Article 15): Obtain a copy of your personal data
- Right to rectification (Article 16): Correct inaccurate data
- Right to erasure (Article 17): Request deletion of your data
- Right to restriction (Article 18): Limit processing in certain circumstances
- Right to data portability (Article 20): Receive your data in a structured, machine-readable format
- Right to object (Article 21): Object to processing based on legitimate interests
Requests can be submitted via email to privacy@oshunsynthetics.com or through the data management tools in your profile settings. We will respond within 30 days.
5. Legal Basis for Processing
We process personal data under the following legal bases:
- Contract performance (Article 6(1)(b)): Processing necessary to provide the Service
- Consent (Article 6(1)(a)): For optional analytics and marketing cookies
- Legitimate interests (Article 6(1)(f)): For security, fraud prevention, and service improvement
- Legal obligations (Article 6(1)(c)): Compliance with applicable laws
6. Security Measures
Lilith implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. These include:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Access controls and role-based permissions for internal systems
- Regular security assessments and penetration testing
- Incident response procedures with breach notification within 72 hours
- Employee training on data protection and security best practices
- Automated monitoring for unauthorized access attempts
7. Sub-processors
Lilith may engage sub-processors to assist in providing the Service. We will maintain an up-to-date list of sub-processors and provide notice before engaging new sub-processors. All sub-processors are bound by contractual obligations that provide at least the same level of data protection as this DPA.
Users may object to the engagement of a new sub-processor by emailing privacy@oshunsynthetics.com within 30 days of notification. If the objection cannot be reasonably accommodated, the user may terminate their account.
8. International Transfers
When personal data is transferred outside the EU/EEA, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR. These include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfer Impact Assessments where required by Schrems II requirements
- Supplementary measures to ensure the effectiveness of the transfer mechanism
9. Data Breach Notification
In the event of a personal data breach, Lilith will notify affected users without undue delay and in any event within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR. The notification will include the nature of the breach, likely consequences, and measures taken to address it.
10. Data Protection Officer
For data protection inquiries, you may contact our Data Protection Officer:
Lilith Data Protection Officer
Email: dpo@oshunsynthetics.com