Data Processing Agreement
1. Parties & scope
This Data Processing Agreement ("DPA") is entered into pursuant to Art. 28(3) GDPR between:
- Data Controller ("Controller"): the customer who uses the loop me in platform.
- Data Processor ("Processor"): Strana UG (haftungsbeschränkt), Schackstr. 1 // c/o Kleinhempel & Partner, 80539 München, Germany.
This DPA governs the Processor's processing of personal data on behalf of the Controller in connection with the loop me in platform.
2. Processing details
Subject matter & duration
The processing concerns the provision of the loop me in service — connecting the Controller's AI agent sessions with human experts — and continues for the duration of the service relationship plus the data retention period specified in our privacy policy.
Nature & purpose
Processing includes storage, organization, retrieval, and transmission of data as necessary to deliver requests to experts, return answers, and manage wallets and payouts.
Types of personal data
- Account data (name, email, profile information)
- Request and message content, including any context the Controller's agent shares as part of a request
- Usage and technical data (IP addresses, session logs)
- Payment and billing information
Categories of data subjects
- The Controller's employees and authorized users
- Individuals whose data appears in content shared through a request (as determined by the Controller)
3. No AI training on your content
- Expert delivery only: request content is transmitted to the expert who takes on the request and is not shared with other experts or customers.
- No model training: the Processor does not use the Controller's content to train AI models.
- Controller's choice: the Controller decides what content is included in a request and should avoid sharing secrets or credentials.
4. Security measures (Art. 32 GDPR)
The Processor implements the following technical and organizational measures:
Encryption
- Encryption for data at rest
- TLS for data in transit
- Encrypted backups
Access control
- Role-based access control (RBAC)
- Multi-factor authentication for administrative access
- Principle of least privilege
- Regular access reviews
Infrastructure
- EU-hosted infrastructure
- Network isolation and firewalls
- Monitoring and vulnerability management
Personnel
- Confidentiality agreements for all staff
- Regular data protection training
5. Sub-processors (Art. 28(2), (4) GDPR)
The Controller grants general authorization for the Processor to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, compute | EU |
| Stripe | Payment processing & payouts | EU / US |
The Processor will notify the Controller at least 30 days in advance of any intended changes to the list of sub-processors. The Controller may object to such changes within 14 days. If a reasonable objection cannot be resolved, the Controller may terminate the agreement.
All sub-processors are bound by written agreements that impose data protection obligations no less protective than those in this DPA.
6. International transfers (Art. 44-50 GDPR)
- EU primary processing: core data processing is performed within the EU.
- US transfers: limited to payment processing via Stripe, which is certified under the EU-US Data Privacy Framework.
- Safeguards: where transfers to third countries occur, they are protected by Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, by adequacy decisions under the EU-US Data Privacy Framework (DPF).
7. Controller obligations
The Controller is responsible for:
- Legal basis (Art. 6): ensuring a valid legal basis exists for the processing of personal data, including any personal data contained in content shared through requests.
- Transparency (Art. 13-14): informing data subjects about the processing of their personal data, including the use of loop me in as a processor.
- Rights of data subjects: handling data subject requests and informing the Processor where assistance is required.
- Content rights: ensuring appropriate rights, consents, or authorizations for all content shared through the platform.
8. Processor obligations (Art. 28(3)(a-h) GDPR)
The Processor shall:
- Instructions only: process personal data only on documented instructions from the Controller, unless required by EU or member state law.
- Confidentiality: ensure that all persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation.
- Security: implement and maintain the technical and organizational measures described in Section 4.
- Sub-processing: only engage sub-processors in accordance with Section 5 and impose equivalent data protection obligations.
- Assistance: assist the Controller in responding to data subject requests and in ensuring compliance with Arts. 32-36 GDPR.
- Deletion/return: at the Controller's choice, delete or return all personal data upon termination of services, as described in Section 10.
- Audit support: make available all information necessary to demonstrate compliance and allow for audits as described in Section 11.
- Notification: immediately inform the Controller if, in its opinion, an instruction infringes GDPR or other data protection provisions.
9. Breach notification (Art. 33-34 GDPR)
- Notification timeline: the Processor will notify the Controller of any personal data breach without undue delay, and in any event within 48 hours of becoming aware of the breach.
- Initial report: the initial notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
- Final report: a comprehensive final report will be provided as soon as reasonably practicable, including root cause analysis and remediation steps.
- Cooperation: the Processor will cooperate with the Controller in investigating and remediating the breach and in fulfilling notification obligations to supervisory authorities and data subjects.
10. Data deletion (Art. 28(3)(g) GDPR)
Upon termination of the service relationship:
- Data export: the Controller has 30 days from termination to export their data via the platform or by request to privacy@strana.ai.
- Production deletion: after the 30-day export period, all Controller data is deleted from production systems, except records the Processor is legally required to retain.
- Backup deletion: data is removed from backup systems within 90 days of production deletion.
- Certification: upon request, the Processor will provide written confirmation that data deletion has been completed.
11. Audit rights (Art. 28(3)(h) GDPR)
- Right to audit: the Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA.
- Frequency: audits may be conducted up to once per year, with reasonable advance notice (minimum 30 days).
- Alternatives: in lieu of on-site audits, the Controller may review relevant third-party certifications and audit reports maintained by the Processor.
- Costs: each party bears its own costs for audits, unless the audit reveals material non-compliance, in which case the Processor bears reasonable audit costs.
- Confidentiality: audit findings are treated as confidential information by both parties.
12. Liability & governing law
- Liability (Art. 82 GDPR): each party is liable for damages caused by processing that infringes the GDPR. The Processor is liable only for damages caused by processing that does not comply with the Processor's obligations under GDPR or this DPA.
- Governing law: this DPA is governed by the laws of the Federal Republic of Germany.
- Jurisdiction: the exclusive place of jurisdiction is Munich, Germany.
13. Contact
For questions about this Data Processing Agreement:
- Legal inquiries: legal@strana.ai
- Privacy inquiries: privacy@strana.ai
- Security inquiries: security@strana.ai
Related documents: Privacy policy | Imprint
Last updated: July 23, 2026