Legal
Data Processing Agreement
Last updated: July 30, 2026
What this is. When we automate your systems, we handle personal data that belongs to you — your customers, your employees. This agreement sets out what we may do with it, what we must protect it against, and what happens to it when we're done. You are the controller; we are the processor acting on your instructions.
Need a countersigned copy for your records? Email contact@logicloop.agency and we'll execute one.
1. Scope and relationship to other agreements
This Data Processing Agreement ("DPA") forms part of the written agreement between LogicLoop LLC ("Processor," "we") and the client ("Controller," "you") for the provision of services (the "Services Agreement"). It applies to the extent we process Personal Data on your behalf. Where this DPA conflicts with the Services Agreement on the subject of data protection, this DPA controls.
2. Definitions
- Personal Data — information relating to an identified or identifiable person that we process on your behalf under the Services Agreement.
- Processing — any operation performed on Personal Data, including access, storage, transmission, alteration, and deletion.
- Controller / Processor — the party determining the purposes and means of processing, and the party processing on its behalf. Under US state privacy laws these correspond to "business" and "service provider" or "processor."
- Sub-processor — a third party engaged by us to process Personal Data.
- Data Subject — the individual the Personal Data relates to.
- Security Incident — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
3. Roles of the parties
You are the Controller and determine the purposes and means of processing. We are the Processor and act only on your documented instructions. You are responsible for the lawfulness of the Personal Data you provide and of the instructions you give us, including having any necessary notices, consents, or other legal bases in place.
4. Our obligations
We will:
- Process Personal Data only on your documented instructions, including the instructions contained in the Services Agreement and this DPA, unless required otherwise by law — in which case we'll tell you first unless the law forbids it.
- Not sell or share Personal Data, and not retain, use, or disclose it for any purpose other than performing the Services, or outside the direct business relationship between us. We certify that we understand and will comply with these restrictions.
- Not combine your Personal Data with data from other sources, except as needed to perform the Services.
- Ensure that anyone we authorise to process Personal Data is bound by an appropriate obligation of confidentiality.
- Implement and maintain appropriate technical and organisational security measures — see Annex B and our Security Policy.
- Tell you promptly if, in our opinion, an instruction infringes applicable data protection law.
5. Sub-processors
You give general authorisation for us to engage Sub-processors. We remain responsible for their performance as if it were our own.
Sub-processors typically fall into these categories: cloud hosting and storage; email delivery; the automation and integration platforms used in your build; AI service providers where a build includes an AI component (see our AI Usage Policy); and accounting or invoicing tools. We will identify the specific Sub-processors for your engagement in writing, and in most builds these run inside your own accounts under your own vendor relationships.
We'll give you reasonable prior notice — at least thirty (30) days — before adding or replacing a Sub-processor that will process your Personal Data. If you reasonably object on data protection grounds within that period, we'll work with you on an alternative; if none is workable, either of us may terminate the affected Services without penalty.
6. Data Subject requests
Taking into account the nature of the processing, we'll provide reasonable assistance to help you respond to requests from Data Subjects exercising their rights — access, correction, deletion, portability, objection. If a Data Subject contacts us directly about your data, we will not respond substantively; we'll forward the request to you promptly.
7. Security Incidents
We will notify you without undue delay, and in any case within seventy-two (72) hours, after becoming aware of a Security Incident affecting your Personal Data. The notice will describe, to the extent known: the nature of the incident, the categories and approximate number of records and Data Subjects affected, the likely consequences, and the measures taken or proposed. We'll provide updates as more becomes known and cooperate reasonably with your own notification obligations.
Our notification isn't an admission of fault or liability.
8. Assistance with assessments
Taking into account the nature of the processing and the information available to us, we'll provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, at your cost where the effort is substantial.
9. Return and deletion
On termination of the Services, and at your choice, we will delete or return the Personal Data we hold, and delete existing copies, within thirty (30) days of your request — except to the extent we're required by law to retain it, in which case we'll continue to protect it and process it only as required.
Note that in most engagements the Personal Data lives in your own systems and accounts, which remain under your control throughout and are unaffected by termination. Our own copies are typically limited to working materials and correspondence.
10. Audits and information
We'll make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable written notice, allow for and contribute to audits conducted by you or an independent auditor you appoint. Audits will be limited to no more than once per twelve months (unless required by a supervisory authority or following a Security Incident), conducted during business hours, subject to confidentiality, and carried out so as not to unreasonably disrupt our operations. You bear the cost of audits you initiate.
11. International transfers
We are based in the United States and process Personal Data there. If you transfer Personal Data subject to the laws of another jurisdiction that restricts international transfers, the parties will put an appropriate transfer mechanism in place — including the European Commission's Standard Contractual Clauses, or the UK Addendum, as applicable — and those clauses are incorporated into this DPA by reference where required.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Services Agreement and our Terms of Service.
Annex A — Details of processing
Subject matter. Provision of business process automation, systems integration, internal tooling, and related support services.
Duration. For the term of the Services Agreement, plus any retention period described in section 9.
Nature and purpose. Accessing, configuring, transmitting, transforming, and testing data within your systems in order to build, operate, and support automated workflows.
Categories of Data Subjects (as determined by your systems and instructions): your employees and contractors; your customers, clients, and prospects; your suppliers and other business contacts.
Categories of Personal Data (typical): names; business and personal contact details; job titles and employer; account and customer identifiers; transaction, order, and invoice records; correspondence content; and system metadata such as timestamps and user IDs.
Special category data. Not processed by default. We do not process health, biometric, genetic, financial account, precise geolocation, or other sensitive data, or data subject to sector-specific regimes such as HIPAA, PCI-DSS, GLBA, or FERPA, unless separately agreed in writing with appropriate safeguards in place.
Annex B — Technical and organisational measures
A summary follows; the current detail is maintained in our Security Policy.
- Access control — unique named accounts, multi-factor authentication, least-privilege and scoped service accounts, credentials held in a password manager, access revoked at the end of an engagement.
- Encryption — data encrypted in transit using current TLS; full-disk encryption on all devices used for client work.
- Data minimisation — we work inside your systems wherever possible and avoid taking copies; where extracts are needed they're limited in scope and deleted when the work is done.
- Secrets handling — API keys and credentials stored in a secrets manager, never in source code, tickets, or plain email.
- Endpoint security — maintained operating systems and security updates, automatic screen lock, and current endpoint protection.
- Organisational — confidentiality obligations for anyone with access, documented incident response, and vendor review before a new Sub-processor is engaged.
Contact
Questions about this policy:
LogicLoop LLC1805 Robin Ave
Fort Worth, TX 76164
contact@logicloop.agency