carloop
Data processing addendum

How we handle data on your behalf.

EFFECTIVE September 10, 202613 SECTIONS6 MIN READ
The short version

In plain words, before the legal ones.

This summary is not the addendum and does not replace it. If the full text and this box ever disagree, the full text wins — and tell us, because one of them is wrong.

  • You are the controller of your customers' data. We are the processor, and we act only on your instructions. (§2, §3)
  • We tell you about a data breach without undue delay, and we hand you what you need for your own notifications. (§9)
  • You get at least 14 days' notice before we add a subprocessor, and you can object on data-protection grounds. (§6)
  • If a data subject writes to us instead of you, we refer them to you rather than answering for you. (§7)
  • When you leave, we delete or return the data — your choice — and copies go with the backup rotation. (§10)
  • EU transfers run on the Commission's Standard Contractual Clauses, Module Two, with UK and Swiss addenda where they apply. (§12)
  • Where this addendum and the main agreement disagree about personal data, this one wins. (§13)

This Data Processing Addendum ("DPA") forms part of the agreement between q2o, Inc., a Delaware corporation doing business as Carloop ("Processor," "Carloop"), and the customer identified in the applicable account or order ("Controller," "Dealer") governing the Dealer's use of the Carloop services (the "Agreement"). This DPA applies to the extent Carloop processes Personal Data subject to the EU GDPR, UK GDPR, Swiss FADP, or similar data protection laws ("Data Protection Laws") on the Dealer's behalf.

01

Definitions

"Personal Data," "processing," "data subject," "controller," "processor," "supervisory authority," and "personal data breach" have the meanings given in Data Protection Laws. "Subprocessor" means a third party engaged by Carloop to process Personal Data on the Dealer's behalf.

02

Roles and Scope

The Dealer is the controller and Carloop is the processor of Personal Data processed in the course of providing the services, as described in Annex 1. Each party will comply with Data Protection Laws applicable to it. The Dealer is responsible for the lawfulness of the Personal Data it makes available (including notices and legal bases toward its own customers and website visitors) and warrants it has the right to instruct the processing described in this DPA.

03

Instructions

Carloop will process Personal Data only on the Dealer's documented instructions, which consist of: the Agreement, this DPA, the Dealer's use and configuration of the services, and any additional written instructions the parties agree. Carloop will inform the Dealer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing. Carloop may process Personal Data where required by law, informing the Dealer unless legally prohibited.

04

Confidentiality and Personnel

Carloop ensures that persons authorized to process Personal Data are bound by confidentiality obligations and access Personal Data only as needed to provide the services.

05

Security

Carloop implements appropriate technical and organizational measures, taking into account the state of the art, costs, and the nature and risks of the processing, including those described in Annex 2. Carloop may update these measures, provided security is not materially diminished.

06

Subprocessors

The Dealer grants general authorization for Carloop's use of Subprocessors. The current list is set out in Annex 3 (or at a URL Carloop maintains). Carloop will provide at least fourteen (14) days' notice of new Subprocessors (email or in-product); the Dealer may object on reasonable data-protection grounds, in which case the parties will work in good faith toward a solution and, failing one, the Dealer may terminate the affected services with a pro-rata refund of prepaid fees. Carloop imposes data protection obligations on Subprocessors no less protective than this DPA and remains liable for their performance.

07

Data Subject Requests

Taking into account the nature of the processing, Carloop will assist the Dealer with appropriate technical and organizational measures, insofar as possible, in fulfilling the Dealer's obligation to respond to data subject requests. If a data subject contacts Carloop directly, Carloop will (unless legally prohibited) refer the request to the Dealer without responding substantively.

08

Assistance

Carloop will provide reasonable assistance to the Dealer with data protection impact assessments, consultations with supervisory authorities, and compliance with security obligations under Data Protection Laws, in each case taking into account the nature of the processing and the information available to Carloop. Carloop may charge reasonable fees for assistance materially exceeding standard support.

09

Personal Data Breach

Carloop will notify the Dealer without undue delay after becoming aware of a personal data breach affecting the Dealer's Personal Data, and will provide information reasonably available to help the Dealer meet its notification obligations, followed by updates as the investigation progresses. Notification is not an admission of fault.

10

Deletion and Return

Upon termination of the services, Carloop will, at the Dealer's choice, delete or return Personal Data (and delete copies) within a reasonable period, unless retention is required by law. Backup copies are deleted per Carloop's backup rotation schedule.

11

Audits

Carloop will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party audits or certifications where available. Where an audit is required by Data Protection Laws, the Dealer (or an independent auditor bound to confidentiality, not a Carloop competitor) may audit on at least thirty (30) days' notice, at most once per twelve (12) months absent a supervisory-authority requirement or evidence of breach, during business hours, without disrupting operations, at the Dealer's expense.

12

International Transfers

Where processing involves a transfer of Personal Data from the EU/EEA to a country without an adequacy decision, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller-to-processor), with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 14 days); Clause 11 optional language excluded; Clause 17 governed by Irish law; Clause 18 courts of Ireland; and Annexes I–III completed by the Annexes to this DPA. For UK transfers, the UK International Data Transfer Addendum applies with the tables completed by the Annexes. For Swiss transfers, the SCCs apply with the adaptations required by the FDPIC. In case of conflict, the SCCs prevail over this DPA.

13

Liability and Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, to the maximum extent permitted by Data Protection Laws. In case of conflict between this DPA and the Agreement regarding processing of Personal Data, this DPA prevails.

ANNEX 1

Description of Processing

  • Subject matter and nature: hosting and normalization of vehicle inventory data; generation of marketing assets including short-form video; publishing of those assets to social media accounts connected by the Dealer, on the Dealer's instructions; hosting and syndication of inventory feeds to advertising platforms designated by the Dealer; hosting of shareable vehicle pages/links and measurement of interactions with them; campaign configuration assistance within the Dealer's own platform accounts; reporting.
  • Duration: the term of the Agreement plus the wind-down period in Section 10.
  • Categories of data subjects: the Dealer's personnel and authorized users; the Dealer's website visitors and advertising audiences (to the limited extent processed by Carloop); recipients of shared vehicle links; individuals incidentally appearing in inventory content.
  • Categories of Personal Data: business contact data of Dealer personnel; technical and interaction data (IP address, device/browser information, timestamps, link-open and viewing events); identifiers processed in connection with advertising configuration on the Dealer's instructions; incidental personal data contained in inventory imagery or listings. No special categories of data are intended to be processed; the Dealer will not submit them.
  • Purpose: provision of the services described in the Agreement.
ANNEX 2

Technical and Organizational Measures

Encryption of data in transit (TLS); encryption at rest for primary data stores; role-based access control and least-privilege access; unique credentials and multi-factor authentication for administrative access; logical separation of customer data; logging and monitoring of production systems; vulnerability management and timely patching; secure software development practices; regular backups with tested restoration; vendor security review for Subprocessors; personnel confidentiality obligations and security awareness; incident response procedures; physical security provided by audited cloud infrastructure providers.

ANNEX 3

Subprocessors

PurposeSubprocessorLocation
Hosting and computeVercel, Inc.USA
DatabaseNeon, Inc.USA
File storage and content deliveryCloudflare, Inc.USA (global edge)
Billing and paymentsStripe, Inc.USA
Transactional email (contact form)Resend, Inc.USA
Publishing to connected social accountsUpload-PostEU/USA
Product analyticsPostHog, Inc.USA
Questions

Need this signed, or have a question?

Email us and a person answers, not a form. Carloop is a service of q2o, Inc., a Delaware corporation, 2035 Sunset Lake Road, Suite B-2, Newark, DE 19702.

contact@carloophq.com