List of Subprocessors

LeanIX may rely on different entities to process Customer Data. With “Customer Data” we refer to any data uploaded to the LeanIX subscription services by Customer. Below you will find a list of such entities, as well as information on the purpose of such processing, the place of processing and what LeanIX customers are interested by this subprocessor.

Note that it is a priority for LeanIX to ensure that all transfers of Customer Data to the above entities are fully compliant with all applicable regulations. In particular, LeanIX relies on Standard Contract Clauses - or on equivalent appropriate safeguards under art. 45 and 46 of the General Data Protection Regulation (Regulation (EU) 2016/679) – to ensure a valid legal basis for the transfer.

For additional information, please check your Order Form with LeanIX or reach out to your LeanIX Account Executive. If you are interested in receiving notifications of any changes to this list, please subscribe here.

Subscribe for Updates

LeanIX Affiliates

Legal entity Purpose of subprocessing Place of data processing Personal Data processed    Active for Safeguards 

LeanIX GmbH
Friedrich-Ebert-Allee 37-39, 53113 Bonn, Germany

Mother company of LeanIX group, providing user support, maintenance and development.

Germany

All the Personal Data included in the Customer Data

 

Customers of LeanIX Inc.

Data Processing Exhibit in accordance with Article 28 GDPR 

LeanIX Privacy Standards
LeanIX Intragroup EU SCC Module 3

Data Security Exhibit 
LeanIX Security Standards

Encryption at rest and in transit of all data

LeanIX Inc
1 Kingsbury Avenue Watertown, MA 02472, United States

100% owned entity of the LeanIX group, providing user support, maintenance and development.

USA

All the Personal Data included in the Customer Data

Customers of LeanIX GmbH

Data Processing Exhibit in accordance with Article 28 GDPR 

LeanIX Privacy Standards
LeanIX Intragroup EU SCC Module 3

Transfer Impact Assessment 

Data Security Exhibit 

LeanIX Security Standards

Encryption at rest and in transit of all data

LeanIX B.V.
Prins Bernhardplein 200
1097 JB Amsterdam, Netherlands

100% owned entity of the LeanIX Group providing User Support, maintenance and development.

Netherlands

All the Personal Data included in the Customer Data

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR 

LeanIX Privacy Standards

LeanIX Intragroup EU SCC Module 3

Data Security Exhibit 

LeanIX Security Standards

Encryption at rest and in transit of all data

LeanIX France SARL 
Wojo La Défense
110 Espl. du Général de Gaulle
92400 Courbevoie, France

100% owned entity of the LeanIX Group providing User Support, maintenance and development.

France

All the Personal Data included in the Customer Data

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR

LeanIX Privacy Standards

LeanIX Intragroup EU SCC Module 3

Data Security Exhibit 

LeanIX Security Standards

Encryption at rest and in transit of all data

LeanIX UK Limited 
Mindspace Shoreditch
9 Appold St
London EC2A 2AP, United Kingdom

100% owned entity of the LeanIX Group providing User Support, maintenance and development.

UK 

All the Personal Data included in the Customer Data

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR 

LeanIX Privacy Standards

LeanIX Intragroup EU SCC Module 3

Data Security Exhibit 

LeanIX Security Standards

Encryption at rest and in transit of all data

LeanIX Sl d.o.o.
Mala ulica 5
1000 Ljubljana, Slovenia

100% owned entity of the LeanIX Group providing User Support, maintenance and development.

Slovenia 

All the Personal Data included in the Customer Data

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR

LeanIX Privacy Standards

LeanIX Intragroup EU SCC Module 3

Data Security Exhibit 

LeanIX Security Standards

Encryption at rest and in transit of all data

SAP Australia Pty Ltd.
Level 13, 1 Denison Street
North Sydney, NSW 2060
Australia

(Effective as of 26 April 2024)

Subprocessor is providing user support, maintenance and development.

Australia

Personal Data included in the 
Customer 
Data

All Customers

Intragroup Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914 or Adequacy decision + Data Security Exhibit, detailing Technical and Organisational measures: https://www.leanix.net/en/legal/commercial  

ISO 27001, SOC 2 Type 2

SAP ASIA Pte Ltd.
30 Pasir Panjang Road 
#03-32 Mapletree Business City
Singapore 117440

(Effective as of 26 April 2024)

Subprocessor is providing user support, maintenance and development.

Singapore

Personal Data included in the 
Customer 
Data

All Customers

Intragroup Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914 or Adequacy decision + Data Security Exhibit, detailing Technical and Organisational measures: https://www.leanix.net/en/legal/commercial  

ISO 27001, SOC 2 Type 2

SAP México S.A. de C.V.
Paseo de la Reforma 509 - Piso 20, Col.
Cuauhtémoc,  Alcaldía Cuauhtémoc
C.P. 06500 Ciudad de México

(Effective as of 26 April 2024)

Subprocessor is providing user support, maintenance and development.

Mexico

Personal Data included in the 
Customer 
Data

All Customers

Intragroup Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914 or Adequacy decision + Data Security Exhibit, detailing Technical and Organisational measures: https://www.leanix.net/en/legal/commercial  

ISO 27001, SOC 2 Type 2

SAP Brasil Ltda.
Av. das Nações Unidas, nº 14.171 - Marble Tower - 7º andar 
Vila Almeida - São Paulo 

(Effective as of 26 April 2024)

Subprocessor is providing user support, maintenance and development.

Brazil

Personal Data included in the 
Customer 
Data

All Customers

Intragroup Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914 or Adequacy decision + Data Security Exhibit, detailing Technical and Organisational measures: https://www.leanix.net/en/legal/commercial  

ISO 27001, SOC 2 Type 2

 

Third Parties

Legal entity Purpose of subprocessing Place of data processing Personal Data processed Active for Safeguards 

Microsoft Ireland Operations, Ltd.
One Microsoft Place South County Business Park Leopardstown Dublin 18, D18 P521, Ireland

Hosting of LeanIX application and database (including backup)

(different geographical regions available, depending on Customer choice; Please make reference to the Agreement)

All the Personal Data on the workspace 

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR 
Standard Contractual Clauses (2021/914/EC)

ISO 27001, 27002, 27018 

SOC 2 Type 2

Encryption at rest and in transit of all data 

Mailjet SAS
13-13 bis, rue de l’Aubrac 75012 Paris, France

SMTP Relay Service, sending of e-mails (outbound only), e.g. in invitation process

France

 

Email Address
+ Name (fore-and-surname)
+ Text in Email 

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR 
Standard Contractual Clauses (2021/914/EC) 

ISO 27001, 27701

SOC 2 Type 2

Encryption at rest and in transit of all data

Zendesk, Inc.
989 Market Street, Suite 300 San Francisco, CA 94103, USA

Input channel and administration of support requests, e.g. via email or support button in LeanIX.

Ireland and Germany

Email address + text in ticket 

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR 
Standard Contractual Clauses (2021/914/EC)

Binding Corporate Rules (BCR)

ISO 27001, 27018

SOC 2 Type 2 

Encryption at rest and in transit of all data

The Rocket Science Group, LLC/ Mailchimp
512 Means Street, Suite 404, Atlanta, GA 30318; USA

Sending of e-mail newsletters, e.g. regarding new features of LeanIX.

USA

Email address
+ User role in LeanIX 
+ Name (fore-and-surname) 

All Customers

Data Processing Exhibit in accordance with Article 28 GDPR 
Standard Contractual Clauses (2021/914/EC) 

EU/US Data Privacy Framework

ISO 27001

SOC 2 Type 2

Encryption at rest and in transit of all data

Twilio/Sendgrid
375 Beale Stree, Suite 300, San Francisco, CA 94105, USA

SMTP Relay Service, sending of e-mails (outbound only)

USA

Email Address

Customers hosted in the US / Canada having subscribed SMP product or VSM product

Data Processing Exhibit in accordance with Article 28 GDPR 
Standard Contractual Clauses (2021/914/EC)

EU/US Data Privacy Framework

ISO 27001, 27017 and 27018

SOC 2 Type 2

Encryption at rest and in transit of all data

ServiceNow Nederland BV

(Effective as of 26 April 2024)

Subprocessor is providing ticketing system for user support.

Netherlands

Personal Data included in tickets submitted by Users

All Customers

Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914

ISO 27001, SOC 2 Type 2

Gainsight Inc 

(Effective as of 26 April 2024)

Subprocessor is providing ticketing system and support in customer success management.

USA

User names, Contact details, Customer success requests

All Customers

Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914

ISO 27001, SOC 2 Type 2

Tech Mahindra Ltd.

(Effective as of 26 April 2024)

Subprocessor is providing first level user support.

India

Personal Data included in tickets submitted by Users

All Customers

Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914

ISO 27001, SOC 2 Type 2

Snowflake Inc.

(Effective as of 26 April 2024)

Subprocessor is providing data warehouse services.

USA

Personal Data included in the Customer Data

All Customers

Data Processing Agreement + New Standard Contractual Clauses by European Commission, reference 2021/914

ISO 27001, SOC 2 Type 2