Data Processing Agreement
Last updated: September 18, 2026
1. Parties and Scope
This Data Processing Agreement ("DPA") is between the customer that subscribes to Loopency ("Customer", the controller) and Jowgik (Business Registration Number 459-10-03101), Sujeong-gu, Seongnam-si, Gyeonggi-do, Republic of Korea ("Processor"). It applies whenever the Processor processes personal data contained in Customer Data on the Customer's behalf, and forms part of the Master Service Agreement. It takes effect when the Customer accepts the Master Service Agreement; no separate signature is needed.
It is written to meet Article 28 of the EU General Data Protection Regulation, the UK GDPR, and the outsourcing (entrustment) requirements of the Korean Personal Information Protection Act, to the extent each applies.
2. Details of the Processing
- Subject matter: providing the Service described in the Master Service Agreement.
- Duration: the subscription term, plus the deletion period in section 11.
- Nature and purpose: hosting, storing, organizing, displaying, analyzing and transmitting Customer Data to operate the Service, including AI features the Customer uses.
- Categories of data subjects: the Customer's users, employees and contractors, and the customers, suppliers and contacts whose details the Customer records.
- Types of personal data: contact details, identifiers, employment and payroll information, transaction and communication records, and any other personal data the Customer chooses to store.
- Special categories: only if the Customer chooses to store them, in which case the Customer is responsible for having a lawful basis.
3. Customer Instructions
The Processor processes personal data only on the Customer's documented instructions, which are this DPA, the Master Service Agreement and the Customer's use and configuration of the Service. If the Processor believes an instruction breaks data protection law, it will say so. If the law requires other processing, the Processor will tell the Customer first, unless the law forbids that.
4. Confidentiality
Everyone the Processor authorizes to process personal data is bound by confidentiality obligations, and has access only to what their role requires.
5. Security
The Processor implements the technical and organizational measures described in its Security overview, including tenant isolation enforced by the database, role-based access to fields and records, encryption in transit, an audit trail of changes, and masking of personal data before it is sent to AI model providers. The Processor may improve these measures, but will not reduce the overall level of protection.
6. Subprocessors
The Customer authorizes the Processor to use the subprocessors listed on the Subprocessors page. Each is bound by written data protection terms at least as protective as this DPA, and the Processor remains responsible for them.
The Processor will update that page at least 30 days before a new subprocessor processes Customer Data. The Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for it.
7. International Transfers
Customer Data is stored on servers in Malaysia and may be processed by subprocessors in other countries, as listed on the Subprocessors page. Where the law requires a transfer mechanism, such as the European Commission's Standard Contractual Clauses, the Processor and its subprocessors rely on it. For Korean data subjects, the Processor discloses the destination country, recipient, purpose and data items of each transfer on the Subprocessors page.
8. Assisting the Customer
Taking into account the nature of the processing, the Processor will help the Customer respond to requests from data subjects to exercise their rights, and with security, breach notification, data protection impact assessments and prior consultations. If a data subject contacts the Processor directly about Customer Data, the Processor will pass the request to the Customer and not respond itself, unless the law requires it.
9. Personal Data Breaches
The Processor will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information the Customer reasonably needs to meet its own obligations, and will keep the Customer updated as more becomes known.
10. Audits
The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA. The Customer may request it at [email protected]. Where that information is not sufficient, the Customer may carry out an audit, at its own cost, on reasonable notice, during business hours, no more than once a year, subject to confidentiality.
11. Return and Deletion
When the Service ends, the Customer may request a copy of Customer Data within 30 days. After that the Processor deletes Customer Data, including personal data, unless the law requires it to be kept.
12. Contact
Data protection questions and requests: [email protected]