Loopclub Ltd View as Markdown

Data processing agreement

Last updated: 26 September 2026

This Data Processing Agreement ("DPA") is part of the Terms of service between the customer ("Controller") and Loopclub Ltd, Delaware, USA ([REGISTERED ADDRESS]) ("Processor"). It applies when Loopclub Ltd processes personal data for the customer through Double Agent. If this DPA and the terms conflict about personal data, this DPA wins. For a countersigned copy, write to legal@doubleagent.so.

1. Definitions

"Data Protection Law" means the laws that apply to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws such as the CCPA/CPRA. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given there. Under the CCPA, the Controller is the "business" and the Processor is the "service provider".

2. Details of processing

Subject matterClassifying sessions on the Controller's websites as human, bot or AI agent, and passing labels to tools the Controller connects
DurationAs long as the Controller uses the service, plus the retention periods below
Data subjectsVisitors to the Controller's websites, and the Controller's users of the dashboard
Personal dataSession id; pages viewed, timing, scroll, referrer and campaign tags; browser, OS, device and screen details, languages, time zone, graphics renderer, client hints; interaction timing and movement (never typed content); IP address, full user agent and an allow-list of request headers; country, region, city and location rounded to about 11 km; network operator; classification result; identifiers the Controller links (such as an analytics client id or order id). For edge reporting: request method, host, path, status, user agent, IP address and allow-listed headers.
Special categoriesNone intended. The Controller must not send them.
Nature and purposeCollection, storage, analysis, classification, transmission of labels to Controller-chosen tools, deletion. Purpose: bot, scraper and AI-agent detection; fraud and abuse prevention; analytics labelling.
RetentionRaw IP, user agent, headers and device details: 30 days. Session detail and edge request records: 90 days (30 days for unclaimed sites). Hourly aggregates without individual data: 365 days. Live presence: 1 hour.

3. Processor obligations

The Processor will:

  1. Process only on documented instructions. The Controller's instructions are these terms, this DPA and the Controller's configuration of the service. The only exception is where the law requires otherwise, and then the Processor will tell the Controller first unless that is prohibited.
  2. Confidentiality. Ensure that people authorised to process the data are bound by confidentiality.
  3. Security. Apply the measures in Annex 2.
  4. Subprocessors. Use only the subprocessors on the subprocessors page, which the Controller authorises generally. The Processor will announce new subprocessors on that page, and by email to customers who subscribe, at least 30 days in advance. The Controller may object on reasonable data protection grounds; if the parties can't resolve the objection, the Controller may terminate the affected service. Each subprocessor will be bound by data protection terms no less protective than these, and the Processor stays responsible for them.
  5. Data subject requests. Help the Controller answer requests, including through the dashboard and API (session lookup, export and site deletion). The Processor will forward requests it receives directly.
  6. Breaches. Notify the Controller of a personal data breach without undue delay and in any case within 48 hours of becoming aware of it, with the information the Controller needs to meet its own obligations.
  7. Assessments. Give reasonable help with data protection impact assessments and consultations with authorities.
  8. Deletion. When the service ends, or when the Controller deletes a site, delete the personal data within 30 days, unless the law requires it to be kept. Copies in backups expire within the backup cycle.
  9. Audits. Make available the information needed to show compliance. Where that isn't enough, allow an audit by the Controller or an independent auditor it appoints, at most once a year, with 30 days' notice, during business hours, under confidentiality, and at the Controller's cost (more often after a breach or when a supervisory authority requires it).
  10. CCPA. Not sell or share the personal data; not retain, use or disclose it outside the direct business relationship or for any purpose other than the services, except as allowed by the CCPA; not combine it with personal data from other sources except as allowed; and tell the Controller if it can no longer meet these obligations.

4. Processor's permitted own uses

The Controller authorises the Processor to use the personal data to:

Published statistics never describe groups of fewer than ten sites. The Controller may opt out of aggregated statistics at legal@doubleagent.so.

5. Controller obligations

The Controller confirms it has a lawful basis for the processing and has given visitors the notices, and obtained any consents, that Data Protection Law requires. That includes deciding between the service's analytics mode (for labelling marketing data, usually behind consent) and security mode (for fraud and abuse prevention). The Controller decides which third-party tools receive labels; those tools are not the Processor's subprocessors.

6. International transfers

The Processor is in the United States. For personal data transferred from the EEA, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), with:

Annexes I and II are sections 2 and Annex 2 of this DPA. For the UK, the parties incorporate the UK International Data Transfer Addendum (version B1.0), with the tables completed from this DPA and neither party able to end it under Section 19. For Switzerland, the SCCs apply with the FDPIC as the competent authority and Swiss law references where needed.

7. Liability and term

Liability under this DPA is subject to the limits in the terms, except where Data Protection Law does not allow a limit. This DPA lasts as long as the Processor processes personal data for the Controller.

Annex 1. Parties

Annex 2. Technical and organisational measures