On this page
In short
When Loopmerce handles the marketplace and customer data you send through our products, we do so as your processor, under your instructions, with the Article 28 obligations set out below. For our own account, billing and security data, we act as an independent controller.
1.Definitions
Terms such as "controller", "processor", "personal data", "processing", "data subject", "supervisory authority" and "personal data breach" have the meanings given in the applicable data protection law, including the EU General Data Protection Regulation (GDPR). "Applicable Data Protection Law" means the data protection laws that apply to the processing under this DPA, including the GDPR, the UK GDPR, and applicable U.S. state privacy laws. "Customer Personal Data" means personal data that Loopmerce processes on the Customer's behalf under the agreement. "Subprocessor" means a processor engaged by Loopmerce to process Customer Personal Data.
2.Scope and application
This DPA applies where and to the extent Loopmerce processes Customer Personal Data on the Customer's behalf in providing the services. It supplements the Terms and Conditions and the Privacy Policy. If the Customer is itself a processor acting for another controller, this DPA applies on a processor-to-processor basis.
3.Roles of the parties
The Customer generally acts as a controller, a business, or a processor acting for another controller. Loopmerce generally acts as a processor, service provider or contractor in respect of Customer Personal Data. For Loopmerce's own account, billing and security data, Loopmerce acts as an independent controller and its processing is governed by the Privacy Policy rather than this DPA.
4.Customer instructions
Loopmerce processes Customer Personal Data only on the Customer's documented instructions, including as set out in this DPA and the agreement and as necessary to provide the services, unless required to act otherwise by law (in which case Loopmerce will inform the Customer unless legally prohibited). Loopmerce will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. The Customer is responsible for the lawfulness of its instructions and of the data it provides.
5.Processing details
The subject matter, duration, nature and purpose of the processing, the categories of data subjects and personal data, and the treatment of special categories, are set out in Annex 1.
6.Confidentiality
Loopmerce ensures that persons authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed.
7.Security measures
Loopmerce implements appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to individuals. Those measures are described in Annex 2. Loopmerce may update its measures provided the level of protection is not materially reduced.
8.Subprocessors
The Customer provides general authorization for Loopmerce to engage subprocessors to process Customer Personal Data, subject to this section. Loopmerce imposes data protection obligations on each subprocessor that are substantially the same as those in this DPA, and remains responsible for its subprocessors' performance. The current subprocessors are listed in Annex 3. Loopmerce will give the Customer notice of material new subprocessors as described in Annex 3, and the Customer may object on reasonable data protection grounds.
9.International transfers
Where processing of Customer Personal Data involves a transfer from the EEA, the UK or Switzerland to a country without an adequacy decision, the parties rely on the transfer mechanism set out in Annex 4, which incorporates the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with any applicable UK or Swiss addenda and appropriate supplementary measures. Loopmerce does not rely on the EU-US Data Privacy Framework.
10.Data-subject requests
Taking into account the nature of the processing, Loopmerce assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. If Loopmerce receives such a request directly, it will, unless legally prohibited, refer the data subject to the Customer and inform the Customer.
11.Regulatory assistance
Loopmerce assists the Customer, taking into account the nature of processing and the information available to Loopmerce, in ensuring compliance with the Customer's obligations relating to security, breach notification, data protection impact assessments and prior consultation with supervisory authorities.
12.Data protection impact assessments
Where the Customer is required to carry out a data protection impact assessment or to consult a supervisory authority, Loopmerce provides reasonable information and assistance relevant to the processing it performs under this DPA.
13.Security incidents
Loopmerce notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides information reasonably available to it to help the Customer meet its own notification obligations. Notification is not an acknowledgement of fault or liability.
14.Deletion and return
On termination of the services, and at the Customer's choice, Loopmerce deletes or returns Customer Personal Data, and deletes existing copies, unless retention is required by law. Data held in routine backups is deleted on the normal backup cycle.
15.Audits and information rights
Loopmerce makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, frequency limits and protection of other customers' data and Loopmerce's security.
16.Liability and order of precedence
The limitations and exclusions of liability in the Terms and Conditions apply to this DPA. In the event of a conflict, this DPA prevails over the Terms with respect to the processing of Customer Personal Data, and the Standard Contractual Clauses prevail over this DPA to the extent of any conflict regarding transfers they govern.
17.Duration
This DPA takes effect when it becomes part of the agreement and continues for as long as Loopmerce processes Customer Personal Data, after which the deletion and return obligations in section 14 apply.
18.Governing terms
Except as stated in this DPA, the governing law and venue provisions of the Terms and Conditions apply. Nothing in this DPA limits obligations that Applicable Data Protection Law imposes directly on either party.
19.Contact
Loopmerce LLC30 N Gould St Ste R, Sheridan, Wyoming 82801, United States of America
Email: info@loopmerce.com
Telephone: +1 (325) 202-4817
WhatsApp: Message Loopmerce on WhatsApp
20.United States service-provider and contractor terms
Where Loopmerce acts as a "service provider" or "contractor" under U.S. state privacy law, the following apply, in each case where applicable:
- Loopmerce processes personal information only for the specified business purposes and to provide the services;
- Loopmerce does not sell personal information;
- Loopmerce does not share personal information for cross-context behavioral advertising, unless specifically agreed and legally permitted;
- Loopmerce does not retain, use or disclose personal information outside the direct business relationship except as permitted by law;
- Loopmerce does not combine personal information across unrelated customers except where legally permitted;
- Loopmerce assists the Customer with consumer requests as described in section 10;
- Loopmerce maintains appropriate security;
- Loopmerce notifies the Customer if it determines it can no longer meet its obligations under applicable law;
- The Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
These terms use "where applicable" because U.S. state coverage depends on legal thresholds and the circumstances of the processing.
Annex 1: Processing details
Subject matter
Providing the Loopmerce Customer Rep, Shipping and Invoicing services to the Customer.
Duration
For the term of the services and the applicable retention or deletion period.
Nature and purpose of processing
- Reading marketplace support context;
- Preparing AI-assisted drafts, summaries and recommendations;
- Processing marketplace orders;
- Creating shipping labels;
- Syncing tracking;
- Logging operational records;
- Creating invoices and credit notes;
- Uploading documents;
- Exporting records;
- Providing support and security.
Categories of data subjects
- Customer personnel;
- Marketplace buyers;
- Shipping recipients;
- Support-ticket participants;
- Business contacts.
Categories of personal data
- Names;
- Contact details;
- Addresses;
- Order details;
- Customer messages;
- Shipping and tracking details;
- Product details;
- IMEI or serial identifiers;
- Invoice and credit-note details;
- Account identifiers;
- Usage and log data.
Special categories of personal data
Loopmerce does not intentionally require special-category data to provide the services. Customers should avoid submitting unnecessary special-category information through the products.
Annex 2: Technical and organisational measures
Loopmerce applies the following measures, which describe the controls in place. This list does not claim any external certification.
- Encryption of marketplace and carrier credentials at rest using AES-256;
- Encryption of data in transit using TLS;
- Account and tenant isolation;
- Authentication and email verification;
- Access control on a least-privilege basis;
- Secure session handling;
- Logging and monitoring;
- Backup procedures and restore testing;
- Incident-response procedures;
- Vulnerability and patch management;
- Data minimisation;
- Retention and deletion controls;
- Staff confidentiality obligations;
- Subprocessor controls.
Scope of these measures
These measures describe controls that are in place. They are not a certification and are not a guarantee that a security incident can never occur. Loopmerce does not claim end-to-end encryption, zero-knowledge encryption, that every database field is AES-256 encrypted, or SOC 2, ISO 27001 or PCI DSS certification, unless separately and specifically stated.
Annex 3: Subprocessors
Loopmerce maintains the current list of subprocessors that process Customer Personal Data. Loopmerce engages subprocessors under written contracts requiring appropriate protection and remains responsible for their performance.
| Provider | Purpose | Data categories | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Google (Google Fonts) | Serving the website typography | IP address, browser information | Global content delivery network | Standard Contractual Clauses, where the importer is outside the EEA |
Additional subprocessors used to operate the products (for example hosting, payment processing, email delivery and AI processing) are added to this appendix as each is confirmed, together with its purpose, data categories, location and transfer mechanism, and a link to the provider's privacy information.
Notice of new subprocessors
Loopmerce will give the Customer advance notice of material new subprocessors by updating this appendix with a dated entry and, where the Customer has subscribed to subprocessor notifications, by notifying the account contact. The Customer may object on reasonable data protection grounds within a reasonable period, and the parties will work in good faith to address the objection.
Annex 4: International transfers
Where required, the parties incorporate by reference the European Commission's Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914, as follows:
- Module Two (controller to processor) where the Customer is a controller and Loopmerce is a processor;
- Module Three (processor to processor) where the Customer is a processor acting for another controller and Loopmerce is a subprocessor.
For the purposes of the clauses:
- Data exporter: the Customer;
- Data importer: Loopmerce LLC;
- Competent supervisory authority: determined in accordance with the clauses and the Customer's establishment;
- Docking clause: the optional docking clause applies;
- Annexes: the descriptions in Annex 1 (processing) and Annex 2 (security) of this DPA populate the corresponding annexes of the clauses; the subprocessor list in Annex 3 applies.
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum applies to the clauses; for transfers subject to Swiss law, the clauses apply as adapted for Switzerland. The official text of the Standard Contractual Clauses is published by the European Commission and is not reproduced or altered here. Loopmerce does not claim participation in the EU-US Data Privacy Framework.
This document is provided for general information and is not legal advice. The Standard Contractual Clauses must be executed and their annex information completed as part of the agreement.