Legal

Data Processing Agreement

Terms governing GetLoopLoop’s processing of personal data on behalf of customers (controller–processor relationship).

Effective: March 22, 2026

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and GetLoopLoop (“Processor”) for the GetLoopLoop service.

Controller determines the purposes and means of processing personal data submitted to the service. Processor processes such data only to provide the service and as documented in this DPA.

Where the parties are joint controllers for specific processing, they will document that separately; default product operation is processor for Customer Content that includes personal data.

2. Details of processing

Subject matter: hosting and processing workspace content and account data to deliver visibility analysis, loops, reports, and related features.

Duration: for the term of the customer agreement and any post-termination retention period required for backups or law.

Nature and purpose: storage, transmission, analysis (including AI-assisted), display, and deletion per Controller instructions.

Types of personal data: may include names, emails, job titles, and any personal data Controllers choose to include in prompts, knowledge bases, or reports.

Data subjects: Controller’s personnel, collaborators, and any individuals whose data Controller submits.

3. Processor obligations

Process personal data only on documented instructions from Controller, including via product configuration, unless required by law.

Ensure persons authorized to process personal data are bound by confidentiality.

Implement appropriate technical and organizational security measures.

Assist Controller with data subject requests, DPIAs, and breach notifications, taking into account the nature of processing.

Delete or return personal data on termination at Controller’s choice, subject to legal retention duties.

Make available information necessary to demonstrate compliance and allow reasonable audits under agreed procedures.

4. Subprocessors

Controller authorizes Processor to engage subprocessors for infrastructure, email, analytics, payments, and AI model inference.

Processor will impose data protection terms no less protective than this DPA and remains responsible for subprocessors’ performance.

Processor will provide notice of material subprocessor changes and an objection window for enterprise customers where contractually agreed.

5. International transfers

Where personal data is transferred from the EEA/UK/Switzerland to a third country lacking an adequacy decision, Processor will ensure a valid transfer mechanism (e.g., SCCs) is in place with the relevant party.

6. Security incidents

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data, and will provide information reasonably available to help Controller meet legal obligations.

7. Controller responsibilities

Controller warrants it has a lawful basis to submit personal data and will not instruct Processor to process data unlawfully.

Controller is responsible for end-user notices and rights responses where it is the controller.

8. Order of precedence

If there is a conflict between this DPA and other commercial terms regarding data protection, this DPA controls for that subject matter.

9. Contact

privacy@getlooploop.com for DPA and subprocessor inquiries.

This document is provided for transparency and does not replace advice from your counsel. Enterprise customers may execute a signed order form with supplemental terms.