Legal
Data Processing Addendum
Version v2 · Last updated August 12, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer”) and APP STUDIO (“Reeloop”, “we”) and governs how we process personal data when providing the Reeloop service, where the GDPR, the UK GDPR, or an equivalent data-protection law applies.
When it applies
This DPA applies when a business customer determines the purposes and means of processing Customer Data through the Service. It becomes effective when the Customer accepts the Terms of Service on behalf of a business, enters into an order form incorporating this DPA, or countersigns this DPA — whichever occurs first. A separate signature is not required for an online subscription; a countersigned copy is available on request.
Roles
For Customer Data (prompts, scripts, reference media, voice and likeness assets, social-publishing tokens and schedules, API/MCP requests, webhook endpoints and generated content), Reeloop acts as processor. Where you act as a processor for your own client, you appoint Reeloop as your sub-processor and represent that you are authorised to do so. For account administration, billing, fraud prevention, security and consent-gated analytics, Reeloop remains an independent controller under the Privacy Policy.
Our commitments as processor
- Process Customer Data only on your documented instructions, and tell you if an instruction appears unlawful.
- Never sell Customer Data, use it for advertising, or use it to train a general AI model.
- Apply the technical and organisational measures on our Security page.
- Assist you with data-subject requests and with your own GDPR Articles 32–36 obligations.
- Notify you of a personal-data breach without undue delay, with initial notice targeted within 48 hours.
- Delete or return Customer Data at the end of the service, including all existing copies, per the retention schedule.
- Flow these obligations down to each sub-processor and remain responsible for their performance.
Sub-processors & international transfers
The current list of sub-processors is maintained on the sub-processors page. For EEA customers, the Customer-to-Reeloop processing takes place within the EEA (Reeloop is established in France). Where we transfer Customer Data onward to a sub-processor in a country without an adequacy decision, Reeloop acts as data exporter and implements the appropriate safeguard — for processor-to-sub-processor transfers the applicable SCC module (Module 3), and for UK-restricted transfers the UK Extension, UK Addendum or IDTA as applicable.
Acceptance evidence
When this DPA is accepted electronically, we retain the account or workspace identifier, the accepting user, the timestamp, and the Terms and DPA versions accepted. Material changes are notified to the account holder before they take effect.
Questions about this DPA, or need a countersigned copy? Email support@reeloop.ai.