Last updated September 26, 2026
Data Processing Addendum
How Reloop Labs processes customer personal data on Reloop Cloud as a data processor under the GDPR.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Reloop Labs (“Reloop”, “we”, “us”, or “our”) and the customer using Reloop Cloud (the “Customer”, “you”, or “your”). It applies whenever Reloop processes personal data on your behalf in providing the hosted service. Our Privacy Policy describes how we handle data as a controller on reloop.sh.
1. Definitions
- “Data Protection Laws” means the EU General Data Protection Regulation (2016/679) (“GDPR”), the UK GDPR as retained in UK law, and any other applicable data-protection or privacy laws.
- “Customer Personal Data” means personal data that Reloop processes on behalf of the Customer in providing Reloop Cloud, including account data, contact and recipient data, message content and metadata, and delivery and engagement events.
- “Controller”, “Processor”, “Data Subject”, “Processing”, and “Personal Data Breach” have the meanings given in the GDPR.
- “Sub-processor” means a third party engaged by Reloop to process Customer Personal Data. Reloop Cloud runs on infrastructure operated by Reloop Labs itself; the systems involved are listed on our Subprocessors page.
2. Roles and scope
For Customer Personal Data processed in providing Reloop Cloud, the Customer acts as Controller (or as Processor where it processes data on behalf of its own customers) and Reloop Labs acts as Processor (or sub-processor, as applicable). This DPA does not apply to data Reloop processes as a Controller as described in our Privacy Policy, nor to self-hosted deployments, where the Customer is solely responsible for processing.
3. Details of processing
- Subject matter: provision of hosted email infrastructure—sending, receiving, and managing email, including transactional messages, campaigns, automations, analytics, and related support.
- Duration: for the term of the Customer’s use of Reloop Cloud, plus applicable deletion windows described in section 10.
- Nature and purpose: transmitting, storing, and analyzing email and associated data as instructed by the Customer through its use of the service, API calls, and configuration.
- Types of personal data: account identifiers (name, email address, company), recipient addresses and contact attributes, message content including attachments, delivery and engagement events (sends, deliveries, bounces, complaints, opens, clicks, unsubscribes), authentication records (SPF, DKIM, DMARC, BIMI), and support correspondence.
- Categories of data subjects: the Customer’s personnel and end users, email recipients, and individuals whose data appears in messages or contact lists uploaded by the Customer.
4. Customer obligations
The Customer is responsible for establishing a lawful basis for processing (including recipient consent for marketing mail), providing required notices to Data Subjects, respecting objection, opt-out, and erasure requests, and using the service in compliance with Data Protection Laws and our Terms of Service, including acceptable use and sending practices.
5. Processor obligations
Reloop Labs will:
- Process Customer Personal Data only on the Customer’s documented instructions—given through use of the service, support requests, or this DPA—unless required otherwise by applicable law, in which case we will inform the Customer where permitted.
- Ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations.
- Maintain appropriate technical and organizational measures described in section 7.
- Assist the Customer, as described in sections 8 and 9, in meeting its obligations relating to Data Subject rights, breach notification, and impact assessments.
- Delete or return Customer Personal Data as described in section 10.
6. Sub-processors
Reloop Cloud operates on infrastructure and systems run by Reloop Labs. The current list of systems that may process Customer Personal Data is published on our Subprocessors page. We will update that page before engaging any new third-party sub-processor that processes Customer Personal Data, and the Customer may object on reasonable data-protection grounds by contacting reloop.sh@gmail.com. Where we engage sub-processors, we impose data-protection obligations no less protective than those in this DPA and remain liable for their compliance.
7. Security measures
We maintain technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest where applicable, network segmentation between service components, authentication and least-privilege access controls, audit logging of administrative access, backups and recovery procedures, and abuse, spam, and phishing detection on shared sending infrastructure.
8. Personal Data Breaches
Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, we will notify the Customer without undue delay and provide information reasonably available to us to assist the Customer in meeting its notification obligations, including the nature of the breach, categories and approximate numbers of Data Subjects and records concerned, likely consequences, and measures taken or proposed.
9. Data Subject rights and assistance
We provide self-service capabilities (contact management, suppression lists, export, and deletion) to help the Customer respond to Data Subject requests. Where a request is directed to Reloop but relates to Customer Personal Data, we will forward it to the Customer where identifiable and assist by appropriate technical measures. We will also reasonably assist with data-protection impact assessments and prior consultations relating to the hosted service.
10. Deletion and return
During active use, the Customer may export and delete Customer Personal Data through the dashboard and API. Upon termination of the hosted service, we will, at the Customer’s choice, return or delete Customer Personal Data within ninety (90) days, except where retention is required by applicable law. Backups are deleted on their regular rotation cycle thereafter.
11. International transfers
Where Customer Personal Data is transferred outside the European Economic Area, the United Kingdom, or another jurisdiction requiring an adequacy mechanism, the parties rely on the EU Standard Contractual Clauses (as applicable, including the UK Addendum) which are incorporated into this DPA by reference, with the Customer as data exporter and Reloop Labs as data importer.
12. Audit
Upon reasonable written request and no more than once per twelve-month period (except following a Personal Data Breach), the Customer may audit Reloop’s compliance with this DPA through a mutually agreed independent auditor, subject to confidentiality and minimal disruption to the service and other customers.
13. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. In the event of conflict between this DPA and the Terms or the Privacy Policy with respect to processing of Customer Personal Data, this DPA prevails.
14. Changes and contact
We may update this DPA to reflect changes in the service or applicable law; material changes will be posted on this page with a revised “Last updated” date. Questions about this DPA or requests under it may be sent to reloop.sh@gmail.com.