LebSource

Legal

GDPR & Data Processing

For European clients assessing us: how data protection works in an engagement, as distinct from how this website works.

Last updated 12 August 2026

The privacy policy covers this website. This page covers the thing your legal team actually needs to assess: what happens to personal data inside an engagement, when our people are working in your systems.

Who is controller and who is processor

In a typical engagement you are the data controller for personal data in your systems, and LebSource acts as a processor, acting on your documented instructions. Where we determine purposes ourselves, our own recruitment, our own client correspondence, we are the controller, and the privacy policy applies.

The data processing agreement

We sign a DPA before any engagement that involves personal data. It sets out the subject matter and duration, the nature and purpose of processing, the categories of data subject and personal data, and the obligations on both sides, as Article 28 requires.

Our standard DPA is available on request from contact@lebsource.com, and we are equally willing to work from yours. It incorporates the sub-processor list set out below, which is the current one.

International transfers

Data is hosted and stored in European regions rather than exported to Lebanon. Our team works from Lebanon, outside the EEA and without a current adequacy decision, so their access to it is a transfer in its own right and is covered by the European Commission's Standard Contractual Clauses, together with a transfer impact assessment and the supplementary measures it identifies. We would rather raise this early in a procurement conversation than have it surface late.

How we limit exposure in practice

  • Access is scoped to what the engagement actually requires, and removed at ramp-down
  • People work in your systems under your access controls rather than copying data into ours
  • Production personal data is not used for testing where a synthetic or masked set will do
  • Access changes are documented so you can evidence them in an audit

Sub-processors

Our current sub-processors are Vercel, which hosts and serves this website from European regions; Supabase, which stores applications submitted to our hiring portal; Resend, which delivers transactional email; and Google, which runs the calendar behind the booking page. You are notified before any addition or replacement, with the opportunity to object. This list is the same one named in our privacy policy, so the two cannot drift apart.

Breach notification

If we become aware of a personal data breach affecting your data, we notify you within 48 hours so you can meet your own obligations, and we support your assessment and any notification you have to make. Forty-eight hours is a contractual commitment, and it is deliberately shorter than the 72 hours the GDPR gives you to notify a supervisory authority, so that the clock we start still leaves you time to act.

Ask us the awkward questions early

If your compliance function has a hard requirement we cannot meet, data residency inside the EU, for instance, the useful time to discover that is the first call. We will tell you, and if the answer is that an EU-based partner suits you better, we will say that too.

Next step

Ready to build or scale your team?

Tell us what you need and we will match you with pre-vetted Lebanese professionals ready to integrate with your team.