Skip to main content

Data Processing Addendum

How Brandloop processes personal data on your instructions when you use the product for business purposes. This addendum forms part of the Terms of Service and applies automatically to every customer — you do not need to request or sign it.

1. Parties and scope

This Data Processing Addendum ("DPA") is entered into between the customer identified in the Brandloop account ("Customer") and Meritocra LLC, a Delaware limited liability company at 8 THE GREEN, STE R, DOVER, DE 19901, United States("Brandloop"). It applies where Brandloop processes personal data on Customer's behalf in providing the service, and it takes effect on the date Customer accepts the Terms of Service.

This DPA applies to the extent the GDPR, the UK GDPR, or a comparable data protection law applies to the processing. Where it conflicts with the Terms of Service on the processing of personal data, this DPA controls. Everything else in the Terms of Service continues to apply, including its limitations of liability, which apply to this DPA as a single aggregate cap.

No signature is required. If your procurement process needs a countersigned copy, email legal@brandloop.app with your legal entity name and address and we will return one.

2. Roles of the parties

For personal data contained in workspace content — brand sources, briefs, drafts, generated assets, calendars, connected channel data, and end-user records Customer uploads or imports — Customer is the controller and Brandloop is the processor.

For account administration, billing, security, fraud prevention, and Brandloop's own service operation and improvement, Brandloop acts as an independent controller under its Privacy Policy. Stripe also acts as an independent controller for payment data it collects directly.

3. Details of processing (Annex I)

  • Subject matter and nature. Hosting, storing, generating, transmitting, and otherwise processing workspace content so Customer can produce, approve, schedule, and publish brand content, and so Customer can use the API and MCP surfaces.
  • Purpose. Providing the service under the Terms of Service and on Customer's documented instructions.
  • Duration. For the term of Customer's subscription, plus the deletion windows in section 11.
  • Categories of data subjects. Customer's personnel and workspace members; individuals appearing in brand sources, uploaded assets, or content Customer submits; audiences of published content on connected networks.
  • Categories of personal data. Names, email addresses, user and workspace identifiers, authentication data, role and permission records, connected channel identifiers and access tokens, content and media Customer submits or generates, usage and audit records, and technical metadata such as IP addresses and timestamps.
  • Special category data. The service is not designed for special categories of personal data (Art. 9), children's data, government identifiers, health data, or payment card numbers. Customer must not submit them.
  • Frequency. Continuous, for the duration of the subscription.

4. Customer instructions

Brandloop processes personal data only on Customer's documented instructions, which consist of this DPA, the Terms of Service, and Customer's use of the product's features — including the generation, publishing, and integration actions Customer or its agents trigger. Consistent with the Terms of Service, actions taken through API keys, MCP clients, automations, or connected agents are treated as account actions.

Brandloop will tell Customer if, in its opinion, an instruction infringes applicable data protection law, and may suspend the affected processing until the instruction is changed. Brandloop may also process personal data where required by law, and will inform Customer of that requirement first unless the law prohibits it.

Customer is responsible for having a lawful basis for the personal data it submits, for the accuracy of that data, and for any notices or consents its own data subjects require.

5. Model training and confidentiality

Brandloop does not sell customer personal data and does not use workspace content to train its own models. Content submitted for generation is sent to the model providers listed in Subprocessors under those providers' API terms; the AI-Content Disclosure describes what each provider does with API inputs and is part of the instructions under section 4.

Access to customer personal data is limited to personnel who need it to operate or support the service, who are bound by confidentiality obligations.

6. Security measures (Annex II)

Brandloop implements the following technical and organizational measures. This is a description of what the product does today, not a certification or an audited attestation.

  • Transport encryption (HTTPS/TLS) for traffic to the application, the API, and provider integrations.
  • Encryption at rest as provided by the managed database, storage, and hosting providers listed in Subprocessors.
  • Tenant isolation enforced in the database with row-level security policies, so workspace data is scoped to its account.
  • Authentication with per-user sessions and role-based permissions (owner, admin, editor, approver) inside each account.
  • Scoped, revocable API keys for programmatic access; secrets are stored hashed and never returned after creation.
  • Signature verification on inbound provider webhooks and separate secrets per internal worker endpoint.
  • Error and diagnostics monitoring, and audit records of billing and publishing actions.
  • Backups and restore capability provided by the managed database provider, retained up to 90 days.
  • Secrets held in environment configuration rather than source control, with automated secret scanning in continuous integration.

Brandloop does not hold a SOC 2, ISO 27001, or HIPAA attestation and does not publish penetration-test reports. The Trust center and security documentation describe the current boundaries.

7. Sub-processors

Customer gives general written authorization for Brandloop to engage sub-processors. The current list — naming each provider, what it does, and what personal data reaches it — is at /legal/subprocessors and currently contains 16 providers. That page is incorporated into this DPA by reference.

Brandloop imposes data protection obligations on each sub-processor that are materially equivalent to those in this DPA, and remains responsible to Customer for its sub-processors' performance. Brandloop gives at least 30 days' notice before a new sub-processor begins processing customer personal data, by updating that page and emailing customers who have subscribed to notice. Customer may object on reasonable data protection grounds within the notice period; if no workable alternative is available, Customer may terminate the affected subscription and receive a refund of prepaid fees for the unused remainder of the term.

8. Data subject requests and assistance

The product gives Customer the ability to access, correct, export, and delete workspace content directly. Where Customer cannot fulfil a data subject request through the product, Brandloop will provide reasonable assistance, taking into account the nature of the processing. If Brandloop receives a request directly from a data subject relating to Customer's workspace, it will not respond on Customer's behalf and will forward the request to Customer without undue delay.

Brandloop will also provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, limited to information about Brandloop's processing that is not otherwise available in this DPA, the Privacy Policy, or the security documentation.

9. Personal data breach notification

Brandloop will notify Customer without undue delay after becoming aware of a personal data breach affecting customer personal data, by email to the account's owner and admin addresses. The notification will describe what is known at the time: the nature of the breach, the categories and approximate volume of data and data subjects affected where known, the likely consequences, the measures taken or proposed, and a contact point. Brandloop will provide further information as the investigation progresses, and reasonable assistance with Customer's own notification obligations. Notification is not an admission of fault.

10. International transfers

Brandloop operates from the United States and its sub-processors process data in the United States or in the regions those providers operate. Customer personal data transferred from the EEA, the UK, or Switzerland is therefore processed outside those jurisdictions.

Where a transfer mechanism is required for that processing, Brandloop will enter into the European Commission's Standard Contractual Clauses (Module Two, controller to processor) with Customer, together with the UK International Data Transfer Addendum where the UK GDPR applies. Request them from legal@brandloop.app. Brandloop does not currently self-certify under the EU-U.S. Data Privacy Framework.

11. Return and deletion of data

Customer can export workspace content at any time during the subscription through the product and API. On termination, or on Customer's written request, Brandloop deletes customer personal data within 30 days where reasonably feasible, except where retention is required by law. Residual copies persist in backups for up to 90 days and are deleted on that cycle; while they exist they remain subject to this DPA.

Records Brandloop retains as a controller keep their own periods: security logs up to 12 months, support and legal records up to 3 years, and billing, tax, and accounting records up to 7 years.

12. Audits and demonstrating compliance

Brandloop makes available the information necessary to demonstrate compliance with Article 28 through this DPA, the subprocessor list, the Privacy Policy, the security documentation, and written responses to reasonable security questionnaires, no more than once in any twelve-month period unless a supervisory authority or a personal data breach requires otherwise.

Brandloop does not hold third-party audit reports to distribute. Where applicable law entitles Customer to an on-site audit that these materials do not satisfy, the parties will agree its scope, timing, and cost in advance; it must be conducted during business hours, without unreasonable interference with operations, under confidentiality, and at Customer's expense. Brandloop's sub-processors are audited by Brandloop, not by Customer directly.

13. Term and contact

This DPA remains in force for as long as Brandloop processes customer personal data. Brandloop may update it to reflect changes in the service or the law; material changes are announced on this page with a new "last updated" date, and where the change reduces Customer's protections it takes effect no sooner than 30 days after posting.

Privacy and data protection contact: privacy@brandloop.app. Contractual and DPA execution requests: legal@brandloop.app. Meritocra LLC, 8 THE GREEN, STE R, DOVER, DE 19901, United States.