Legal · Data Processing Addendum

Data Processing Addendum (DPA).

How ASOLOOP processes personal data on your behalf, the subprocessors we engage, and how to obtain the current DPA template for your procurement and security review.

Last updated: 2026-05-09

Need the DPA template now?

Email [dpa] DPA request.

We respond within 3 business days with the current DPA template, the subprocessor list, and any procurement-review materials your security team needs.

Email it@asoloop.com

1.What this page covers

A Data Processing Addendum (DPA) is the contractual instrument that defines how ASOLOOP processes personal data on your behalf when you use the ASOLOOP Service. It complements the Terms of Service and the Privacy Policy, and is required reading for any procurement, security, or legal-review process where personal data is in scope.

This page summarises the DPA structure and tells you how to request the current DPA template. Teams contracts include a negotiated DPA by default.

2.Controller and Processor roles

Under EU GDPR, UK GDPR, and equivalent data-protection regimes, the parties play two distinct roles depending on the dataset:

  • Customer Data (ASOLOOP as Processor). For experiment definitions, metadata variants, signals, evidence library entries, and MMP-derived attribution data inside your Workspace, you are the Controller and ASOLOOP acts as Processor on your documented instructions.
  • Account Data (ASOLOOP as Controller). For login email, billing contact, support correspondence, and basic account metadata that ASOLOOP collects to operate the Service, ASOLOOP acts as Controller. See the Privacy Policy.

3.Subprocessors

The current subprocessor list is maintained on the Security page. Teams customers receive 30-day prior notice of new subprocessors with the right to object. Subscribe to subprocessor notifications by emailing it@asoloop.com with the subject line Subprocessor notifications.

4.International data transfers

Personal data may be transferred outside your local jurisdiction in connection with the operation of the Service. The current DPA includes the European Commission’s Standard Contractual Clauses (Module 2: Controller-to-Processor) and the UK Addendum to the SCCs, where applicable, as the transfer mechanism for EU and UK personal data exported to ASOLOOP infrastructure in the United States.

5.Data subject rights flow

When a data subject (one of your end users or employees) exercises a GDPR-equivalent right (access, rectification, erasure, portability, objection) and the data is inside your Workspace, you handle the request as Controller. ASOLOOPprovides reasonable assistance to respond — export tools, deletion endpoints, and direct support.

Forward subject-rights requests that you cannot fulfil yourself to it@asoloop.com with subject line [dsr]. We respond within 30 days.

6.Breach notification

ASOLOOP commits to notify affected Workspace Owners without undue delay and in any event within 72 hours of becoming aware of a confirmed personal-data breach affecting your Customer Data, per GDPR Article 33. Notification includes the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address it.

7.Retention and deletion

ASOLOOP retains Customer Data only for the duration of your active subscription. On termination, your Workspace is retained in read-only mode for 30 days for export, then permanently deleted along with all Customer Data. Backups are purged within an additional 30 days.

Earlier deletion can be requested at any time by emailing it@asoloop.com with subject line [dpa] early deletion request.

8.Requesting the DPA template

The current DPA template is available on request for Starter and Pro customers. Teams contracts include a negotiated DPA by default; redlines are accommodated within reason for SCC modules, audit-rights scope, and breach-notification timing.

To request a DPA template, email it@asoloop.com with subject line [dpa] DPA request. Include your legal entity name, jurisdiction, and the Workspace email on file. We respond within 3 business days with the current template.

9.Updates to the DPA

The DPA template is reviewed at least annually and updated when subprocessor lists, transfer mechanisms, or breach-notification timings change. Material updates are announced to existing customers at least 30 days before they take effect. The version in your executed agreement supersedes the published template for your subscription.