Trust Center - Leapwork

A New AI Mindset For Test Automation

Build, maintain and scale automation faster with our AI-powered visual test automation platform.

FAQ

Introduction

What is Leapwork’s Trust Center FAQ?

Our Trust Center FAQ is a resource designed to address customer concerns about data privacy, security, and compliance. It reflects Leapwork’s commitment to transparency and provides detailed answers about how we handle and protect your data in line with global data protection regulations, including GDPR and CCPA.

Compliance

Is Leapwork GDPR and CCPA compliant?

Yes, Leapwork is fully compliant with GDPR and CCPA. We process data in accordance with privacy laws, implement Privacy by Design principles, and maintain a Data Processing Addendum (DPA) to outline our obligations as a data processor/service provider. Learn more about GDPR and CCPA compliance in our Privacy Policy.

What certifications does Leapwork hold?

Leapwork is ISO 27001 certified, reflecting our adherence to stringent information security standards. Additionally, we hold a SOC 2 Type 2 attestation.

How do Leapwork On-Premises and Leapwork Cloud differ in terms of compliance needs?

Leapwork offers two primary products:

Both products emphasize privacy and security by design, but the choice depends on whether the customer prefers on-premise control or a scalable cloud-based solution with robust vendor-managed compliance measures.

Security

How does Leapwork secure customer data?

We employ robust security measures, including:

What happens if a data breach occurs?

Leapwork has a comprehensive incident response plan. In the unlikely event of a breach, we notify affected customers and relevant authorities within 72 hours, as required by GDPR. We also perform a root cause analysis and implement corrective actions.

Where is Leapwork’s data stored?

All EU customer data is stored securely in Microsoft Azure data centers located in the North EU region, ensuring compliance with data residency requirements.

Privacy

How does Leapwork support data subject rights?

Our platform includes features to help customers comply with GDPR rights, such as data access, rectification, and deletion. Customers can manage these rights directly through the Customer Portal.

Does Leapwork use customer data for training AI models?

No, Leapwork ensures that customer data processed through our AI Blocks is not used to train AI models. Our integration with OpenAI adheres to strict contractual terms ensuring data security and compliance.

How long does Leapwork retain customer data?

Leapwork retains customer data only as long as necessary for providing services or as required by law. Customers can request data deletion at any time through our support team as well as set various retention periods directly on the platform.

Third-Party Integrations

Does Leapwork share data with subprocessors?

Yes, Leapwork collaborates with vetted subprocessors, such as Microsoft Azure, OpenAI, and Cloudmersive. These providers meet stringent security and privacy standards. Customers are notified of new subprocessors with the option to object.

How are international data transfers handled?

Leapwork employs Standard Contractual Clauses (SCCs) and Transfer Impact Assessments (TIAs) to ensure secure and lawful international data transfers. When we use US-based subprocessors we strive to use vendors certified under the EU-US Data Privacy Framework.

Support for Custom Compliance

Can Leapwork accommodate unique compliance requirements?

Yes, Leapwork supports customer-specific compliance needs. For instance, customers can disable features like AI Blocks or Cloud Blocks to align with their internal data governance policies.

Conclusion

Additional Information

For additional questions, please refer to our Privacy Policy, review our Data Processing Addendum, or contact our legal and compliance teams at:

Leapwork is committed to helping you achieve your data protection and security goals while delivering exceptional automation solutions.

Q&A

Why Leapwork does not sign BAAs

Leapwork does not require nor is designed to be used to store Personal Health Information (PHI). In addition, Leapwork does not desire or need to receive, process, store, transact or otherwise possess PHI in order to provide our software and service. As such, Leapwork does not meet, or desire to meet, the definition of a "Business Associate" as defined under the Health Insurance Portability and Accountability Act (HIPAA).