Data Processing Addendum
Last updated: 2026-06-06
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies to the extent Lolopi processes personal data on behalf of a customer in the role of a data processor under the EU General Data Protection Regulation (GDPR) or equivalent laws.
1. Roles
The customer is the data controller. Lolopi is the data processor. Each party shall comply with its respective obligations under applicable data protection laws.
2. Scope and purpose
Lolopi processes personal data only for the purpose of providing the Service to the customer, in accordance with the customer's documented instructions.
3. Sub-processors
A current list of sub-processors is available on our Trust Center. Customers may subscribe to notifications of changes.
4. Security measures
Lolopi implements industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logging, regular backups, and incident response procedures.
5. International transfers
Where personal data is transferred outside the EEA, UK, or Switzerland, Lolopi relies on Standard Contractual Clauses (SCCs) or equivalent legal mechanisms, supplemented by additional safeguards where required.
6. Data subject requests
Lolopi will assist the customer in responding to data subject requests. Customers may also submit requests through the in-app export and deletion tools.
7. Breach notification
Lolopi will notify the customer of any confirmed personal data breach without undue delay and in any case within 72 hours of becoming aware of it.
8. Contact
DPA questions: dpa@lolopi.dataservices-ltd.com.