Loopyback

Legal

Data Processing Agreement

How Loopyback processes personal data on behalf of business customers.

Last updated: July 2026

Scope

This Data Processing Agreement (“DPA”) applies where Loopyback processes personal data on behalf of a customer’s organization (the “Controller”) in the course of providing the Service, and forms part of our Terms of Service. For that processing, Loopyback acts as a processor within the meaning of Article 28 GDPR.

Nature of the processing

Loopyback hosts, stores, and displays the workflow guides your team captures, including screenshots and step descriptions, along with workspace member details (name, email, role) needed to operate your workspace. The duration of processing is the term of your subscription, plus a short deletion window after termination.

Our commitments

Subprocessors

You authorise the following subprocessors. Where a subprocessor processes data outside the EEA, transfers are protected by Standard Contractual Clauses or an adequacy decision. We will give notice before adding or replacing subprocessors, giving you the opportunity to object.

ProviderPurposeLocation
SupabaseDatabase, authentication, and file storage for your workspace and guidesEU (Frankfurt)
NetlifyWeb application hosting and content deliveryEU/US (CDN)
StripePayment processing and subscription billingEU/US
ResendTransactional email (invites, sharing, account emails)EU/US
OpenRouterAI model routing for AI-assisted capture (only when you use AI features)US
Google / MicrosoftSign-in with Google or Microsoft (only if you choose that sign-in method)EU/US

Signed copy

Enterprise customers who require a countersigned DPA, or have questions about this agreement, can contact legal@loopyback.com.