Loopclub Ltd View as Markdown
Data processing agreement
Last updated: 26 September 2026
This Data Processing Agreement ("DPA") is part of the Terms of service between the customer ("Controller") and Loopclub Ltd, Delaware, USA ([REGISTERED ADDRESS]) ("Processor"). It applies when Loopclub Ltd processes personal data for the customer through Double Agent. If this DPA and the terms conflict about personal data, this DPA wins. For a countersigned copy, write to legal@doubleagent.so.
1. Definitions
"Data Protection Law" means the laws that apply to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws such as the CCPA/CPRA. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given there. Under the CCPA, the Controller is the "business" and the Processor is the "service provider".
2. Details of processing
| Subject matter | Classifying sessions on the Controller's websites as human, bot or AI agent, and passing labels to tools the Controller connects |
|---|---|
| Duration | As long as the Controller uses the service, plus the retention periods below |
| Data subjects | Visitors to the Controller's websites, and the Controller's users of the dashboard |
| Personal data | Session id; pages viewed, timing, scroll, referrer and campaign tags; browser, OS, device and screen details, languages, time zone, graphics renderer, client hints; interaction timing and movement (never typed content); IP address, full user agent and an allow-list of request headers; country, region, city and location rounded to about 11 km; network operator; classification result; identifiers the Controller links (such as an analytics client id or order id). For edge reporting: request method, host, path, status, user agent, IP address and allow-listed headers. |
| Special categories | None intended. The Controller must not send them. |
| Nature and purpose | Collection, storage, analysis, classification, transmission of labels to Controller-chosen tools, deletion. Purpose: bot, scraper and AI-agent detection; fraud and abuse prevention; analytics labelling. |
| Retention | Raw IP, user agent, headers and device details: 30 days. Session detail and edge request records: 90 days (30 days for unclaimed sites). Hourly aggregates without individual data: 365 days. Live presence: 1 hour. |
3. Processor obligations
The Processor will:
- Process only on documented instructions. The Controller's instructions are these terms, this DPA and the Controller's configuration of the service. The only exception is where the law requires otherwise, and then the Processor will tell the Controller first unless that is prohibited.
- Confidentiality. Ensure that people authorised to process the data are bound by confidentiality.
- Security. Apply the measures in Annex 2.
- Subprocessors. Use only the subprocessors on the subprocessors page, which the Controller authorises generally. The Processor will announce new subprocessors on that page, and by email to customers who subscribe, at least 30 days in advance. The Controller may object on reasonable data protection grounds; if the parties can't resolve the objection, the Controller may terminate the affected service. Each subprocessor will be bound by data protection terms no less protective than these, and the Processor stays responsible for them.
- Data subject requests. Help the Controller answer requests, including through the dashboard and API (session lookup, export and site deletion). The Processor will forward requests it receives directly.
- Breaches. Notify the Controller of a personal data breach without undue delay and in any case within 48 hours of becoming aware of it, with the information the Controller needs to meet its own obligations.
- Assessments. Give reasonable help with data protection impact assessments and consultations with authorities.
- Deletion. When the service ends, or when the Controller deletes a site, delete the personal data within 30 days, unless the law requires it to be kept. Copies in backups expire within the backup cycle.
- Audits. Make available the information needed to show compliance. Where that isn't enough, allow an audit by the Controller or an independent auditor it appoints, at most once a year, with 30 days' notice, during business hours, under confidentiality, and at the Controller's cost (more often after a breach or when a supervisory authority requires it).
- CCPA. Not sell or share the personal data; not retain, use or disclose it outside the direct business relationship or for any purpose other than the services, except as allowed by the CCPA; not combine it with personal data from other sources except as allowed; and tell the Controller if it can no longer meet these obligations.
4. Processor's permitted own uses
The Controller authorises the Processor to use the personal data to:
- keep the service secure;
- maintain and improve its detection: the models, likelihood weights and the catalog of bots and agents;
- create aggregated or de-identified statistics that cannot reasonably identify any person or Controller.
Published statistics never describe groups of fewer than ten sites. The Controller may opt out of aggregated statistics at legal@doubleagent.so.
5. Controller obligations
The Controller confirms it has a lawful basis for the processing and has given visitors the notices, and obtained any consents, that Data Protection Law requires. That includes deciding between the service's analytics mode (for labelling marketing data, usually behind consent) and security mode (for fraud and abuse prevention). The Controller decides which third-party tools receive labels; those tools are not the Processor's subprocessors.
6. International transfers
The Processor is in the United States. For personal data transferred from the EEA, the parties incorporate the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), with:
- Clause 7 (docking) applying;
- Option 2 of Clause 9 (general authorisation, 30 days' notice);
- no optional wording in Clause 11;
- Clauses 17 and 18: the law and courts of Ireland.
Annexes I and II are sections 2 and Annex 2 of this DPA. For the UK, the parties incorporate the UK International Data Transfer Addendum (version B1.0), with the tables completed from this DPA and neither party able to end it under Section 19. For Switzerland, the SCCs apply with the FDPIC as the competent authority and Swiss law references where needed.
7. Liability and term
Liability under this DPA is subject to the limits in the terms, except where Data Protection Law does not allow a limit. This DPA lasts as long as the Processor processes personal data for the Controller.
Annex 1. Parties
- Controller: the customer named in the account, acting through its account owner. Contact: the account owner's email.
- Processor: Loopclub Ltd, [REGISTERED ADDRESS], USA. Contact: privacy@doubleagent.so.
Annex 2. Technical and organisational measures
- Encryption: TLS for all traffic to and from the service and between it and its data stores; secrets encrypted at rest; secret API keys stored only as hashes.
- Separation: every read is scoped to the customer's sites. Raw data (IP, user agent, headers) is stored separately, readable only with a dedicated key through an owner/admin route, and every read is written to an audit log.
- Access: role-based access (owner, admin, viewer); separate least-privilege keys for reading, writing, maintenance and raw access; keys rotate at least every 90 days.
- Minimisation: no cookies; no typed content; no listeners on payment fields; ad click ids stored as presence only; the enriched tier keeps location rounded to about 11 km and a network hash instead of the raw IP.
- Retention: enforced by index lifecycle policies and scheduled deletion jobs (section 2); site and account deletion purge all stores.
- Abuse protection: rate limits on every public route, adaptive proof-of-work, validation of every beacon, and quarantine of low-trust data.
- Monitoring: Worker logs and traces; logged refusals from data stores; a dead-letter queue for failed writes.
- Incidents: breach response with Controller notification within 48 hours.
- People: access limited to people who need it, under confidentiality.