Draft for review. Written under the law of England and Wales, not yet checked by a solicitor. Words in brackets are still to be filled in.

Data processing agreement

This agreement forms part of the agreement between [company legal name] ("The Loop", the processor) and each client company ("the Client", the controller) for a programme on The Loop platform. It sets out the terms required by Article 28 of the UK GDPR. If it conflicts with the main agreement on data protection, this agreement wins.

1. The processing

Subject matterRunning the Client's AI capability programme on the platform: diagnosis, scoring, coaching, learning, projects, reporting and, if the Client asks, introducing specialists to deliver work.
DurationThe term of the main agreement, then until the data is erased under section 8.
Nature and purposeCollecting, storing, analysing, scoring, summarising (including with AI models), reporting and deleting, to deliver the programme.
Personal dataName, work email, job title, department, reporting line, whether someone manages people; questionnaire answers and scores; conversation notes and transcripts; project plans and updates; community posts; attendance; platform usage.
Data subjectsThe Client's employees and workers taking part in the programme, and its programme leads.
Special category dataNone is requested. The Client will ask participants not to include it in free text.

2. The Loop's obligations

The Loop will:

  1. process the personal data only on the Client's documented instructions (the main agreement, this agreement, and the Client's use and settings of the platform), unless the law requires otherwise, in which case it will tell the Client first unless the law forbids that;
  2. tell the Client straight away if it thinks an instruction breaks data protection law;
  3. make sure everyone authorised to process the data is bound by confidentiality;
  4. take the security measures in Annex 1;
  5. help the Client, taking into account the nature of the processing, to respond to requests from individuals exercising their rights;
  6. help the Client with security, breach notification, data protection impact assessments and prior consultation with the ICO;
  7. notify the Client without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Client's data, with the information the Client reasonably needs;
  8. make available the information needed to show it meets these obligations, and allow audits by the Client or an auditor it appoints, on reasonable notice, no more than once a year unless there has been a breach.

3. Sub-processors

The Client gives general authorisation for The Loop to use the sub-processors below. The Loop will give at least 30 days' notice by email to the Client's programme leads before adding or replacing one; the Client may object on reasonable data protection grounds, and if the parties cannot resolve it, the Client may end the affected part of the agreement. The Loop puts the same data protection obligations on each sub-processor and remains responsible for them.

Sub-processorPurposeLocation
Supabase Inc.Database, authentication, file storageUK (London)
Vercel Inc.HostingUK (London), global delivery network
Resend (Plus Five Five, Inc.)Transactional emailUnited States
PostHog Inc.Anonymised product analytics and session recordingsEU (Germany)
Functional Software, Inc. (Sentry)Error reports, with personal details removedEU (Germany)
OpenRouter, Inc., and the model providers it routes to (Anthropic PBC, OpenAI, L.L.C.)AI assistant, summaries and themesUnited States

Drafting note: Confirm each supplier's legal entity name and that a DPA is signed with each.

4. International transfers

The Loop will transfer personal data outside the UK only where a transfer mechanism recognised by UK law is in place, such as UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework) or the ICO's International Data Transfer Agreement or Addendum.

5. Confidentiality inside the Client

The platform shows programme leads and line managers grouped results, and breaks company results down only for groups of at least five people. The Client will not use the platform or its reports to make decisions about an individual's employment.

6. Specialists

If the Client chooses to have The Loop find someone to deliver work, The Loop may share an anonymised summary of the Client's diagnosis with vetted trainers and consultants. The Client is named, and personal data shared, only with the specialist the Client's programme lead signs off, who is bound by confidentiality and uses it only for that work.

7. The Client's obligations

The Client is responsible for having a lawful basis for the programme, for telling participants about it (it may point them to The Loop's privacy notice), and for the accuracy of the data it provides.

8. At the end

The Client sets retention on the platform: data about a deactivated person is erased a set number of days after deactivation, and all of the Client's data a set number of months after its programme closes. At the end of the main agreement, The Loop will, at the Client's choice, return the data in a common format or erase it, and will erase remaining copies unless the law requires it to keep them. Backups are overwritten in the normal cycle of [backup retention period].

9. Liability and law

Liability under this agreement is subject to the limits in the main agreement. This agreement is governed by the law of England and Wales.

Annex 1: Security measures

  • Encryption of data in transit (TLS) and at rest.
  • Row-level security in the database: each request sees only the rows the signed-in person's role allows, enforced by the database rather than the application.
  • Role-based access for the Client's people, consultants and specialists; specialists see only work they are given.
  • Service keys held only on the server; staff access limited to those who need it.
  • Small-group suppression in reports (groups under five are not broken down).
  • Analytics with IP addresses discarded and typed text masked; error reports stripped of request bodies, cookies, sign-in links and contact details.
  • Deactivated people lose access immediately; erasure on schedule or on request, logged without names.
  • Hosting in the UK for the database and application.

Drafting note: Add backup, incident response and staff training arrangements once confirmed.

Draft of 6 October 2026 · © 2026 The Loop