Data processing agreement
Version of October 4, 2026
This agreement applies when Loopback processes personal data on behalf of a customer, under Article 28 of the GDPR. It is part of the terms of service.
Roles
The customer is the controller; Omniselect di Nicola Alessi is the processor. For an agency, the agency is the processor of its clients and we are its sub-processor.
Subject matter and scope
| Item | Detail |
|---|---|
| Subject matter | Receiving support requests, diagnosing them in the customer’s code and logs, drafting replies, preparing and releasing fixes, notifying end users. |
| Nature and purpose | Storage, analysis with AI models, transmission of emails and status pages, on the customer’s instructions. |
| Duration | For the term of the service, then until deletion as described below. |
| Data subjects | The customer’s end users who write to support or use the widget; the customer’s team members. |
| Categories of data | Names and email addresses, the content of messages and reports, technical data of the widget after masking, user identifiers as salted hashes, error events after masking. |
Instructions
We process personal data only on the customer’s documented instructions, given by the settings of the service and these terms, and tell the customer if an instruction seems to breach the law.
Confidentiality
People authorized to process the data are bound by confidentiality.
Security measures
- Secrets encrypted at rest with envelope encryption; connections encrypted in transit.
- Row-level security in the database for every organization.
- In Managed, one ephemeral container per job, with network access only to a list of allowed hosts, and the clone deleted at the end of the job.
- Secrets and personal data masked in logs and before they reach a model.
- Access limited by role and by workspace; tokens scoped to one workspace and with an expiry.
- An audit log of approvals, merges, tags, emails sent, configuration and consent changes, and access to secrets.
- In the widget, masking in the browser and consent before screenshots and technical details. Details on the security page.
Sub-processors
The customer authorizes these sub-processors:
| Company | Service | Data | Location | Used |
|---|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, object storage and key management. | All the data the service stores. | European Union (Ireland) | Always |
| Anthropic, PBC | Language models for Managed jobs, the onboarding demo and the anonymization of shared patterns. | Ticket content, log excerpts and code sent in prompts, after masking. | United States | Always |
| OpenAI, L.L.C. | Language models for Managed jobs when configured, and text embeddings when configured. | Ticket content, log excerpts and code sent in prompts, after masking. | United States | Only when enabled for Managed |
| OpenRouter, Inc. | Routing of language model requests for Managed jobs. | Ticket content, log excerpts and code sent in prompts, after masking. | United States | Only when enabled for Managed |
| Google Cloud EMEA Limited | Language models through Vertex AI for Managed jobs. | Ticket content, log excerpts and code sent in prompts, after masking. | European Union or United States, by the configured region | Only when enabled for Managed |
| Amazon Web Services EMEA SARL | Language models through Amazon Bedrock for Managed jobs. | Ticket content, log excerpts and code sent in prompts, after masking. | European Union or United States, by the configured region | Only when enabled for Managed |
| Resend, Inc. | Sending and receiving emails. | Emails to and from your customers, team notifications. | United States | Always |
| Stripe Payments Europe, Ltd. | Billing and payments. | Billing contacts, payment methods, invoices. | European Union (Ireland) and United States | Always |
| GitHub, Inc. | Repository integration through the GitHub App, sign-in of GitHub Actions jobs. | Repository metadata, issues, pull requests and comments. | United States | Always |
| Google LLC | Delivery of the font a brand profile sets, on status pages, subscription pages, public changelogs and in the widget. | IP address and browser user agent of the people who open those pages or a page that hosts the widget. | United States | Only when a brand profile sets a font |
A sub-processor marked “Only when enabled for Managed” processes personal data only after we route Managed requests through it; we announce that change as described below for a new sub-processor.
A sub-processor marked “Only when a brand profile sets a font” processes the IP address and browser user agent of the visitors of the customer’s status pages, subscription pages and public changelogs, and of the pages where the customer installed the widget, only while one of the customer’s brand profiles sets a font from Google Fonts. The customer starts it by choosing that font and stops it by removing it.
The code-understanding engine, vexp, is developed by the same company and runs inside our infrastructure or the customer’s: it is an internal component, not a sub-processor. If it is ever operated by a separate company, it will be listed here.
When the customer runs the analysis in its own runner or agent, the model provider is chosen and contracted by the customer and is not our sub-processor.
We announce a new sub-processor to account owners by email at least 30 days in advance; the customer can object, and if we cannot address the objection, terminate the affected service.
International transfers
Transfers outside the European Economic Area rely on the EU-US Data Privacy Framework where the recipient is certified under it, and otherwise on the standard contractual clauses of the European Commission.
Assistance
- We help the customer answer data subjects’ requests: when the customer asks at privacy@loopback.dev, we export or delete a data subject’s data within 30 days.
- We notify the customer of a personal data breach without undue delay, with the information available.
- We provide the information the customer needs for impact assessments and consultations.
Shared memory
The shared memory is off by default. With the customer’s explicit consent, it stores abstract patterns of errors and solutions, without code, names or personal data; a pattern is shown to others only after equivalent patterns come from at least 3 organizations, and withdrawing consent removes the customer’s contributions.
Deletion and return
Clones are deleted at the end of each job, error events after 30 days, prompts and outputs after the retention period of the organization, 30 days by default. When the service ends, we hand the customer a copy of its data if it asks at privacy@loopback.dev, and we delete the data within 30 days of the account’s closure, unless the law requires us to keep it.
Audits
We make available the information needed to demonstrate compliance and allow audits by the customer or an auditor it appoints, with reasonable notice and confidentiality.