Legal

Data Processing Addendum

Last updated: 2026-06-06

This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies to the extent Lolopi processes personal data on behalf of a customer in the role of a data processor under the EU General Data Protection Regulation (GDPR) or equivalent laws.

1. Roles

The customer is the data controller. Lolopi is the data processor. Each party shall comply with its respective obligations under applicable data protection laws.

2. Scope and purpose

Lolopi processes personal data only for the purpose of providing the Service to the customer, in accordance with the customer's documented instructions.

3. Sub-processors

A current list of sub-processors is available on our Trust Center. Customers may subscribe to notifications of changes.

4. Security measures

Lolopi implements industry-standard security measures including encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logging, regular backups, and incident response procedures.

5. International transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, Lolopi relies on Standard Contractual Clauses (SCCs) or equivalent legal mechanisms, supplemented by additional safeguards where required.

6. Data subject requests

Lolopi will assist the customer in responding to data subject requests. Customers may also submit requests through the in-app export and deletion tools.

7. Breach notification

Lolopi will notify the customer of any confirmed personal data breach without undue delay and in any case within 72 hours of becoming aware of it.

8. Contact

DPA questions: dpa@lolopi.dataservices-ltd.com.

    Lolopi — Legal | Data Services