Skip to content
  • Platform
  • aXcelerate
  • Pricing
  • Contact
Sign Up
Sign Up
Always on, anytime, everywhere

AI agents for your business, with your team in control.

© Copyright 2026 Rockhawk Pty Ltd trading as Leagen. All Rights Reserved.

Product
  • Platform
  • aXcelerate
  • Pricing
Resources
  • FAQ
  • Blog
About
  • Contact
Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Agreement

06 / A different kind of ambition

More room.
More possibility.

Bold horizons. Human scale.
Technology that gives you space.

Sign up
LeagenAlways on. Anytime. Everywhere.

01 / Product01 / PRODUCT

PlatformaXceleratePricing

02 / Explore02 / EXPLORE

FAQsInsights

03 / Connect03 / CONNECT

Contact usSign in
© 2026 Rockhawk Pty Ltd trading as Leagen. All rights reserved.
PrivacyTermsCookiesData processing

LegalClarity, from the start

Leagen Platform Data Processing Agreement

Controller / Processor framework governing use of the Leagen platform — sub-processors, data categories, security architecture, and update process.

Privacy PolicyTerms of ServiceCookiesData processing

On this page

  1. 011 — Parties
  2. 022 — Definitions
  3. 033 — Scope and Purpose
  4. 044 — Categories of Personal Information
  5. 055 — Data Subjects
  6. 066 — Processor Obligations
  7. 077 — Customer Obligations
  8. 088 — Sub-processors
  9. 098.1 — Infrastructure
  10. 108.2 — AI Models
  11. 118.3 — Per-app sub-processors
  12. 129 — Security Measures
  13. 1310 — International Data Transfers
  14. 1411 — Personal Data Breach Notification
  15. 1512 — Data Subject Rights
  16. 1613 — Audit Rights
  17. 1714 — Term and Termination
  18. 1815 — Updates to this DPA
  19. 1916 — Governing Law
Have a question?↗
On this page
  1. 011 — Parties
  2. 022 — Definitions
  3. 033 — Scope and Purpose
  4. 044 — Categories of Personal Information
  5. 055 — Data Subjects
  6. 066 — Processor Obligations
  7. 077 — Customer Obligations
  8. 088 — Sub-processors
  9. 098.1 — Infrastructure
  10. 108.2 — AI Models
  11. 118.3 — Per-app sub-processors
  12. 129 — Security Measures
  13. 1310 — International Data Transfers
  14. 1411 — Personal Data Breach Notification
  15. 1512 — Data Subject Rights
  16. 1613 — Audit Rights
  17. 1714 — Term and Termination
  18. 1815 — Updates to this DPA
  19. 1916 — Governing Law

Rockhawk Pty Ltd trading as Leagen · ABN 17 673 537 123

Controller / Processor framework governing use of the Leagen platform — sub-processors, data categories, security architecture, and update process.

Version dpa-v1 — effective 8 September 2026

This is the Leagen platform DPA. Each GenX integration the workspace enables (for example, the aXcelerate integration) is governed by an additional App DPA accepted at integration setup time. App DPAs are visible inside the workspace, behind sign-in.

Document content SHA-256: a555ead998f31dda99650467a15a23e48fad6de9d0bf071b375f9a62871c938c

This hash is computed at publication time over the exact markdown source above. When a workspace accepts this DPA in-app, the hash is recorded against the acceptance — so the workspace can later confirm that the text shown to them at acceptance time is the same text published here.

Back to top ↑

Leagen Platform Data Processing Agreement

Version: dpa-v1
Effective: 1 May 2026
Document type: Platform DPA (covers the Leagen platform itself; integration-specific data flows are covered by separate per-app DPAs accepted at integration setup time.)


1 — Parties

This Data Processing Agreement ("DPA") is entered into between:

  • Controller — the workspace organisation that has accepted this DPA (the "Customer"), acting as the controller of Personal Information processed by the Leagen platform on its behalf; and
  • Processor — Leagen ("Leagen"), acting as the processor of that Personal Information.

This DPA forms part of, and is incorporated into, the Leagen Terms of Service. It governs Leagen's processing of Personal Information that the Customer's workspace transmits to, stores in, or generates within the Leagen platform.

2 — Definitions

  • "Personal Information" means any information relating to an identified or identifiable natural person, as defined under the Australian Privacy Act 1988, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).
  • "Platform" means the Leagen software-as-a-service platform, including web application, APIs, AI agents, knowledge bases, chat widgets, and supporting infrastructure.
  • "Sub-processor" means any third party engaged by Leagen to process Personal Information on Leagen's behalf, as listed in Section 8.
  • "Workspace" means the Customer's tenant within the Platform — the unit of multi-tenant isolation enforced by row-level security in the Platform database.
  • "App DPA" means a separate per-integration data processing agreement that the Customer accepts when enabling a specific GenX app (for example, the aXcelerate Integration DPA). App DPAs supplement, and do not replace, this Platform DPA.

3 — Scope and Purpose

Leagen processes Personal Information solely to provide the Platform to the Customer in accordance with the Customer's documented instructions. Those instructions are given through:

  • The Customer's configuration of the workspace (knowledge bases, agents, chat widgets, automations);
  • The Customer's use of the Platform's user interface and APIs;
  • This DPA and any App DPA the Customer accepts.

Leagen will not process Personal Information for any purpose other than providing the Platform to the Customer, except as required by applicable law.

4 — Categories of Personal Information

Personal Information processed by Leagen on the Customer's behalf may include:

  • Workspace member data — name, email address, role, account preferences, authentication metadata, IP address, and user-agent strings collected for security and audit purposes.
  • End-user data — names, email addresses, phone numbers, and any other Personal Information the Customer or its end-users submit through chat widgets, forms, or knowledge-base ingestion.
  • Conversational data — messages exchanged with AI agents, including any Personal Information embedded in those messages, the AI model's responses, and tool-call inputs and outputs.
  • Knowledge-base content — documents, web pages, and other materials the Customer uploads or imports for retrieval-augmented generation, including any Personal Information embedded in that content.
  • Compliance audit data — DPA acceptance records (timestamp, accepting user, IP, user-agent, document SHA-256 hash), tool-call logs, and consent records.

5 — Data Subjects

The categories of data subjects whose Personal Information may be processed include:

  • The Customer's authorised users (workspace members, administrators, agents).
  • The Customer's end-users (chat widget visitors, form submitters, students, learners, customers, prospects).
  • Any natural person whose Personal Information appears in content the Customer ingests into the Platform.

6 — Processor Obligations

Leagen will:

  • Process Personal Information only in accordance with the Customer's documented instructions;
  • Ensure that personnel authorised to process Personal Information are bound by appropriate confidentiality obligations;
  • Implement and maintain the technical and organisational measures described in Section 9;
  • Not engage additional sub-processors without notifying the Customer and providing a reasonable opportunity to object (consent to current sub-processors listed in Section 8 is granted upon acceptance of this DPA);
  • Assist the Customer in fulfilling its obligations to respond to data-subject requests under applicable law;
  • Notify the Customer without undue delay of any Personal Data Breach affecting the Customer's data (Section 11);
  • On termination, delete or return all Personal Information to the Customer, subject to legal retention requirements.

7 — Customer Obligations

The Customer is responsible for:

  • Establishing a lawful basis for processing the Personal Information it submits to the Platform;
  • Providing the notices and obtaining the consents required by applicable law from its workspace members and end-users;
  • Configuring its workspace, agents, and integrations consistently with applicable data-protection law;
  • Accepting any App DPA required for an integration before enabling that integration in the workspace.

8 — Sub-processors

Leagen engages the following sub-processors to assist in providing the Platform. The Customer's acceptance of this DPA constitutes consent to these sub-processors. Leagen will notify the Customer of intended changes to this list with a reasonable opportunity to object.

8.1 — Infrastructure

Sub-processor Supabase
Purpose Primary database, authentication, storage, realtime
Region Australia (ap-southeast-2)
Sub-processor Vercel
Purpose Application hosting, serverless compute, edge network
Region Global edge, Sydney (syd1) primary
Sub-processor Upstash
Purpose Rate limiting, ephemeral cache, durable queues (Redis + QStash)
Region Closest available region (configurable)
Sub-processor Resend
Purpose Transactional email delivery (invitations, notifications, security alerts)
Region United States / European Union
Sub-processor Stripe
Purpose Subscription billing and payment processing
Region Australia / United States

8.2 — AI Models

All AI model traffic is routed through the Vercel AI Gateway (United States, with regional inference). The Gateway is configured for zero data retention and acts as a routing layer between the Platform and downstream model providers. The Gateway operator does not train models on traffic and does not retain prompt or response content beyond the operational period required to deliver the response.

The Customer may select from any of the following providers and models for AI features (chat agents, summarisation, structured extraction, embeddings):

Provider Anthropic
Models Claude 4.6 Opus / 4.6 Sonnet / 4.5 Opus / 4.5 Sonnet / 4.5 Haiku
Provider region United States
Notes Zero data retention via Gateway. Anthropic does not train on API traffic.
Provider OpenAI
Models GPT-5.4 / GPT-5.4 Mini / o4 Mini
Provider region United States
Notes Zero data retention via Gateway. OpenAI does not train on API traffic.
Provider Google
Models Gemini 3 Pro / 3 Flash / 2.5 Pro / 2.5 Flash
Provider region United States
Notes Zero data retention via Gateway.
Provider xAI
Models Grok 4 / Grok 3 / Grok 3 Mini
Provider region United States
Notes Zero data retention via Gateway.
Provider Meta
Models Llama 4 Maverick / Llama 4 Scout
Provider region United States (model hosting via Gateway)
Notes Open-weight models hosted by the Gateway operator, not by Meta directly.
Provider DeepSeek
Models DeepSeek-V3 / DeepSeek-R1
Provider region People's Republic of China
Notes Cross-border transfer to China. The Customer is responsible for assessing whether this provider is appropriate for its data; the Customer may disable DeepSeek models for its workspace at any time.
Provider Moonshot AI
Models Kimi K2
Provider region People's Republic of China
Notes Cross-border transfer to China. Same notice as DeepSeek above.

The Customer's workspace administrators control which models are available for use in the workspace. The default model is Claude 4.6 Sonnet (Anthropic, United States). The Customer can restrict the available providers per workspace through the Platform settings.

8.3 — Per-app sub-processors

When the Customer enables a GenX integration (for example, aXcelerate), the corresponding App DPA discloses the additional sub-processors specific to that integration. Those App DPAs are accepted separately at integration setup time and supplement the list above.

9 — Security Measures

Leagen implements the following technical and organisational measures:

  • Tenant isolation — every workspace's data is logically isolated by PostgreSQL row-level security policies enforced at the database layer.
  • Encryption in transit — all Platform traffic is served over TLS 1.2 or higher.
  • Encryption at rest — primary database storage is encrypted at rest by the infrastructure provider.
  • Authentication — workspace member authentication uses industry-standard OAuth, password (with bcrypt or stronger), and optional multi-factor authentication (MFA) flows.
  • Access control — Leagen personnel access to production systems is restricted on a least-privilege basis and logged.
  • Audit logging — security-relevant events (authentication, role changes, integration credential updates, DPA acceptances, AI tool calls) are logged and retained for a minimum of 90 days.
  • Vulnerability management — Leagen tracks dependency advisories and applies security patches on a risk-prioritised cadence.
  • Backups — daily backups of the primary database are retained by the infrastructure provider for 7 days.

10 — International Data Transfers

The Platform stores primary Customer data in Australia (ap-southeast-2). Personal Information may be transferred to other jurisdictions where sub-processors operate, including:

  • United States — for AI inference (Anthropic, OpenAI, Google, xAI, Meta), email delivery (Resend), payment processing (Stripe), and global edge delivery (Vercel).
  • European Union — for some Resend regions when the Customer's deliverability profile is EU-based.
  • People's Republic of China — only if the Customer's workspace expressly permits the use of DeepSeek or Moonshot AI models. By default, the Customer should consider these providers opt-in.

Where a transfer falls outside the jurisdictions for which an adequacy decision exists, Leagen relies on the EU Standard Contractual Clauses (Module 2 — Controller to Processor; Module 3 — Processor to Sub-processor) and equivalent mechanisms recognised under the Australian Privacy Act and CCPA/CPRA. The Customer accepts these mechanisms by accepting this DPA.

11 — Personal Data Breach Notification

Leagen will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting the Customer's data. The notification will include, to the extent reasonably available at the time:

  • The nature of the breach, including the categories and approximate number of data subjects affected;
  • The likely consequences;
  • The measures taken or proposed to address the breach.

12 — Data Subject Rights

Leagen will assist the Customer, by appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under applicable law (including rights of access, rectification, erasure, restriction, portability, and objection).

The Platform provides the Customer with self-service tools to export and delete workspace data; Leagen will provide additional assistance on reasonable request.

13 — Audit Rights

On reasonable written request, Leagen will make available to the Customer information necessary to demonstrate compliance with this DPA. Audits beyond the provision of such information are subject to mutual agreement on scope, timing, and confidentiality.

14 — Term and Termination

This DPA takes effect on the Customer's acceptance and continues for so long as Leagen processes Personal Information on behalf of the Customer. On termination of the Customer's use of the Platform, Leagen will delete or return all Customer Personal Information within 30 days, subject to any longer retention required by law.

15 — Updates to this DPA

Leagen may update this DPA from time to time. Material changes (for example, the addition of a sub-processor in a new jurisdiction, a change in the categories of Personal Information processed, or a change in retention periods) will be notified to the Customer at least 30 days before the new version takes effect, and the Customer will be required to re-accept the updated DPA on next sign-in. Non-material changes (typographical corrections, clarifications) will be versioned and logged but will not require re-acceptance.

The currently-effective version of this DPA is identified by the version field at the top of this document and by a SHA-256 content hash recorded against the Customer's acceptance.

16 — Governing Law

This DPA is governed by the laws of New South Wales, Australia. Any dispute arising under this DPA is subject to the non-exclusive jurisdiction of the courts of New South Wales.


Acceptance of this DPA is recorded against the workspace at the time of acceptance, including the accepting user, the timestamp, the IP address from which acceptance was made, the user-agent string, and the SHA-256 hash of the document content shown at acceptance time. The Customer can view and download its accepted version of this DPA at any time from the workspace settings.