# Data Processing Agreement

Last updated 2026-10-01.

This Data Processing Agreement (the “DPA”) forms part of the agreement, Terms of Service, order form, statement of work, or other written or electronic agreement (the “Agreement”) between:

AY Automate LLC, a limited liability company organised under the laws of the State of Wyoming, United States, with its registered address at 312 W 2nd St, Unit #A4881, Casper, WY 82601, United States (“looot”, “Processor”, “we”, “us”); and

the customer identified in the applicable Agreement (“Customer” or “Controller”).

For customers using the looot.ai Services under the standard terms, the Agreement is the looot Terms of Service at https://looot.ai/terms, or any signed order form.

This DPA governs looot's Processing of Personal Data on behalf of Customer in connection with Customer’s use of the looot.ai services (the “Services”).

This DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (“GDPR”) and, where applicable, other Data Protection Laws.

## 1. Definitions

For purposes of this DPA:

“Customer Data” means data, content, information, prompts, documents, files, records, instructions, or other material submitted to, accessed by, transmitted to, or otherwise Processed through the Services by or on behalf of Customer.

“Customer Personal Data” means any Personal Data contained in Customer Data that looot Processes on behalf of Customer in connection with the Services.

“Data Protection Laws” means all laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR and applicable national legislation implementing or supplementing it.

“Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Processor”, “Controller”, and “Supervisory Authority” have the meanings given to them under the GDPR.

“Subprocessor” means a third party engaged by looot to Process Customer Personal Data on behalf of Customer.

“EEA” means the European Economic Area.

## 2. Roles and Scope of Processing

### 2.1 Roles

To the extent looot Processes Customer Personal Data on behalf of Customer in connection with the Services:

- Customer acts as Controller or, where Customer itself acts as a Processor for another Controller, as Processor; and
- looot acts as Processor or Subprocessor, respectively.

Each party is responsible for complying with the obligations applicable to it under Data Protection Laws.

### 2.2 Customer Instructions

looot shall Process Customer Personal Data only:

1. on documented instructions from Customer;
2. as necessary to provide, maintain, secure, and support the Services;
3. as otherwise permitted by the Agreement and this DPA; or
4. where required by applicable law.

The Agreement, this DPA, Customer's configuration and use of the Services, and other documented instructions agreed between the parties constitute Customer's documented instructions to looot.

If applicable law requires looot to Process Customer Personal Data contrary to Customer's instructions, looot shall inform Customer of that legal requirement before Processing unless prohibited by law.

### 2.3 Unlawful Instructions

looot shall inform Customer without undue delay if, in looot's reasonable opinion, an instruction infringes applicable Data Protection Laws.

## 3. Details of Processing

The subject matter, nature, purpose, duration, categories of Personal Data, and categories of Data Subjects are described in Annex I to this DPA.

Customer determines the categories of Personal Data submitted to or made accessible through the Services and is responsible for ensuring that it has an appropriate legal basis for such Processing.

Unless expressly agreed otherwise in writing, Customer shall not intentionally submit to the Services Personal Data subject to additional regulatory requirements beyond those contemplated by the Agreement, including health data, payment card data, government identification numbers, biometric data, or other special-category data.

## 4. Confidentiality

looot shall ensure that persons authorised to Process Customer Personal Data:

1. are subject to an appropriate duty of confidentiality;
2. Process Customer Personal Data only as necessary to perform their duties in connection with the Services; and
3. receive appropriate data protection and security guidance relevant to their responsibilities.

looot shall limit access to Customer Personal Data to personnel and contractors who require such access for legitimate purposes connected with providing, securing, maintaining, or supporting the Services.

## 5. Security of Processing

### 5.1 Security Measures

Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, looot shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

The technical and organisational measures currently applicable to the Services are described in Annex III.

### 5.2 Security Programme

Where appropriate to the risks presented by the Processing, looot's measures shall include controls relating to:

- access control and authentication;
- least-privilege access;
- encryption in transit and, where applicable, at rest;
- logical separation of customer environments and data;
- secure software development practices;
- vulnerability and dependency management;
- logging and monitoring;
- backup and recovery;
- incident response;
- personnel security and confidentiality; and
- periodic review of the effectiveness of relevant security measures.

### 5.3 Customer Responsibilities

Customer acknowledges that security is a shared responsibility. Customer is responsible for appropriately configuring the Services, managing its users and credentials, controlling the information it submits to the Services, and taking reasonable measures to prevent unauthorised access through Customer-controlled systems or accounts.

## 6. Customer-Controlled Integrations

The Services may permit Customer to connect third-party systems, applications, APIs, MCP servers, data sources, or other integrations.

Where an integration is selected, configured, supplied, or authorised by Customer, Customer instructs looot to transmit and Process Customer Data as reasonably necessary to operate that integration.

To the extent a third-party service is contracted directly by Customer and does not Process data on looot's behalf, that service is not a Subprocessor of looot and its Processing is governed by Customer's agreement with that third party.

When Customer runs an endpoint in the looot catalog, Customer selects that provider and instructs looot to transmit the request to it and return its response. The provider Processes the data under its own terms and is not a Subprocessor of looot, whether the call uses Customer's credentials or looot's platform credentials. Customer is responsible for having a lawful basis to use that provider and the data it returns.

## 7. Personal Data Breaches

### 7.1 Notification

looot shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

### 7.2 Information

To the extent information is reasonably available to looot, the notification shall include:

- the nature of the Personal Data Breach;
- the categories and approximate number of affected Data Subjects;
- the categories and approximate number of affected Personal Data records;
- the likely consequences of the Personal Data Breach;
- measures taken or proposed to address the breach and mitigate its possible adverse effects; and
- an appropriate contact point for further information.

Where all information is not available at the same time, looot may provide it in phases as it becomes available.

### 7.3 Cooperation

looot shall take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and shall reasonably cooperate with Customer in meeting Customer's applicable breach-notification obligations.

looot's notification of a Personal Data Breach shall not be construed as an acknowledgement of fault or liability.

## 8. Subprocessors

### 8.1 General Authorisation

Customer provides looot with general written authorisation to engage Subprocessors to Process Customer Personal Data in connection with the Services, subject to this Section.

The current list of Subprocessors is set out in Annex II, at https://looot.ai/dpa#annex-ii.

### 8.2 Subprocessor Obligations

looot shall enter into a written agreement with each Subprocessor imposing data-protection obligations that provide a level of protection for Customer Personal Data substantially equivalent to the obligations applicable to looot under this DPA, to the extent relevant to the services performed by that Subprocessor.

looot shall remain responsible for the performance of its Subprocessors' data-protection obligations to the extent required by applicable Data Protection Laws.

### 8.3 Changes to Subprocessors

looot shall provide Customer with reasonable prior notice of the intended addition or replacement of a Subprocessor that will Process Customer Personal Data.

Such notice shall be given at least 15 days before the new Subprocessor begins to Process Customer Personal Data.

Customer may object to a new Subprocessor on reasonable grounds relating to data protection by notifying looot within 15 days after receiving notice.

The parties shall work in good faith to resolve a reasonable objection. If the parties cannot resolve the objection, looot may, where reasonably possible, make available an alternative configuration or Customer may discontinue the affected portion of the Services in accordance with the Agreement.

## 9. International Data Transfers

### 9.1 Transfers

looot shall ensure that transfers of Customer Personal Data outside the EEA, Switzerland, or the United Kingdom, as applicable, are made in accordance with applicable Data Protection Laws.

### 9.2 Adequacy

Where Customer Personal Data is transferred to a country recognised by the relevant authority as providing an adequate level of protection, the parties may rely on the applicable adequacy decision.

### 9.3 Standard Contractual Clauses

Where a transfer subject to the GDPR cannot rely on an adequacy decision or another valid transfer mechanism, the parties agree that the then-current Standard Contractual Clauses approved by the European Commission pursuant to Article 46 GDPR (“EU SCCs”) shall apply to the relevant transfer.

The appropriate module shall apply according to the parties' respective roles.

Where looot transfers Customer Personal Data to a Subprocessor in a third country, looot shall implement an appropriate transfer mechanism as required by Data Protection Laws.

### 9.4 Supplementary Measures

Where required, looot shall reasonably cooperate with Customer regarding transfer impact assessments and shall implement supplementary safeguards appropriate to the relevant transfer risks.

## 10. Data Subject Requests

Taking into account the nature of the Processing, looot shall provide reasonable assistance to Customer, through appropriate technical and organisational measures where possible, to enable Customer to respond to requests by Data Subjects exercising their rights under Data Protection Laws.

If looot receives a request directly from a Data Subject relating to Customer Personal Data, looot shall, unless legally prohibited:

1. inform Customer of the request; and
2. not respond substantively to the request except on Customer's documented instructions or as required by law.

## 11. Regulatory Assistance and DPIAs

Taking into account the nature of the Processing and information available to looot, looot shall provide reasonable assistance to Customer with:

- Customer's obligations under Articles 32–36 GDPR;
- data protection impact assessments;
- prior consultations with Supervisory Authorities;
- security-of-processing assessments; and
- information reasonably necessary to demonstrate compliance with Customer's obligations relating to looot's Processing.

Such assistance shall take into account the nature and complexity of the request and may be subject to reasonable fees where the request requires material resources beyond those ordinarily required to provide the Services, unless the assistance is required due to looot's breach of this DPA.

## 12. Audits and Compliance Information

### 12.1 Information

looot shall make available to Customer information reasonably necessary to demonstrate compliance with the obligations imposed on Processors by Article 28 GDPR and this DPA.

Where available, looot may satisfy reasonable audit requests by providing relevant third-party audit reports, certifications, security documentation, penetration-test summaries, or other compliance materials.

### 12.2 Audits

Where the information provided under Section 12.1 is insufficient to demonstrate compliance, Customer may conduct an audit of looot's relevant Processing activities, subject to the following conditions:

- reasonable prior written notice;
- no more than once in any 12-month period unless required by a Supervisory Authority or following a material Personal Data Breach;
- during normal business hours;
- in a manner that does not unreasonably interfere with looot's operations;
- subject to appropriate confidentiality obligations; and
- limited to systems, records, and facilities relevant to Processing Customer Personal Data.

Customer shall bear its audit costs unless the audit identifies a material breach of this DPA by looot.

Nothing in this Section requires looot to disclose information that would compromise the security or confidentiality of another customer, expose trade secrets beyond what is reasonably necessary for the audit, or create a security vulnerability.

## 13. Return and Deletion of Customer Personal Data

Upon termination or expiration of the Agreement, and at Customer's choice where required by applicable law, looot shall delete or return Customer Personal Data and delete existing copies, unless applicable law requires continued storage.

Customer acknowledges that residual copies may remain temporarily in backup systems until overwritten or deleted in accordance with looot's ordinary backup-retention procedures, provided such data remains protected under this DPA and is not actively Processed except for restoration, security, or legal purposes.

Operational retention periods: see Annex I, Part H.

Backup retention period: see Annex I, Part H.

## 14. Government and Law-Enforcement Requests

Unless prohibited by applicable law, looot shall notify Customer of a legally binding request from a public authority seeking disclosure of Customer Personal Data.

Where reasonably possible and legally permitted, looot shall:

- redirect the requesting authority to Customer;
- assess whether the request is legally valid and appropriately scoped;
- challenge requests that looot reasonably considers unlawful or disproportionate; and
- disclose only the minimum Customer Personal Data legally required.

## 15. Customer Obligations

Customer represents and warrants that:

1. its Processing instructions comply with applicable Data Protection Laws;
2. it has all necessary rights, notices, consents, and legal bases required to provide Customer Personal Data to looot for Processing under the Agreement;
3. its use of the Services will comply with applicable Data Protection Laws; and
4. it will not instruct looot to Process Personal Data in a manner that violates applicable law.

Customer remains responsible for determining whether the Services are appropriate for its intended Processing activities.

## 16. Processing Records and Supervisory Authorities

looot shall maintain records of Processing activities as required by Article 30 GDPR.

looot shall cooperate, on request, with competent Supervisory Authorities in the performance of their tasks to the extent required by applicable Data Protection Laws.

## 17. Liability

The liability of each party arising out of or relating to this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement, except to the extent such limitation is prohibited by applicable Data Protection Laws. The Agreement is the looot Terms of Service at https://looot.ai/terms, or any signed order form.

## 18. Term and Termination

This DPA takes effect when looot begins Processing Customer Personal Data and remains in effect for as long as looot Processes Customer Personal Data on Customer's behalf.

Termination of the Agreement shall automatically terminate this DPA, except for provisions that by their nature must survive termination, including confidentiality, deletion obligations, and provisions concerning previously transferred Personal Data.

## 19. Order of Precedence

If there is a conflict between this DPA and the Agreement regarding the Processing or protection of Customer Personal Data, this DPA shall prevail to the extent of that conflict.

Where applicable Standard Contractual Clauses conflict with this DPA or the Agreement, the Standard Contractual Clauses shall prevail.

## 20. Governing Law

Unless Data Protection Laws require otherwise, this DPA shall be governed by the governing-law and jurisdiction provisions of the Agreement.

## Annex I — Details of Processing

### A. Subject Matter

Processing of Customer Personal Data as necessary to provide the looot.ai Services to Customer.

### B. Duration

For the duration of the Agreement and any limited period thereafter during which looot retains Customer Personal Data in accordance with the Agreement, this DPA, Customer's instructions, or applicable law.

### C. Nature and Purpose of Processing

Depending on Customer's use and configuration of the Services, Processing may include:

- receiving Customer Data;
- accessing and retrieving information from Customer-authorised data sources;
- transmitting information between Customer-authorised systems;
- storing and retrieving information;
- indexing and searching information;
- executing Customer-requested workflows or agent operations;
- connecting to Customer-authorised tools, APIs, MCP servers, or integrations;
- authentication and account management;
- security monitoring and abuse prevention;
- troubleshooting and customer support; and
- other Processing reasonably necessary to provide functionality requested by Customer.

### D. Categories of Data Subjects

Depending on Customer's use of the Services, Data Subjects may include:

- Customer's employees;
- contractors;
- representatives;
- customers and prospective customers;
- suppliers and business partners;
- users of Customer systems;
- individuals whose information is contained in Customer-authorised data sources; and
- other individuals whose Personal Data Customer elects to Process through the Services.

### E. Categories of Personal Data

Depending on Customer's use of the Services, Customer Personal Data may include:

- names;
- business contact information;
- email addresses;
- job titles and organisational information;
- account and user identifiers;
- communications and correspondence;
- documents and textual content;
- application and system metadata;
- information retrieved from Customer-authorised systems and integrations; and
- other Personal Data submitted by Customer or Processed at Customer's instruction.

### F. Special Categories of Personal Data

Not intentionally required by the Services.

Unless expressly agreed otherwise, Customer should not intentionally use the Services to Process special categories of Personal Data under Article 9 GDPR or data relating to criminal convictions and offences under Article 10 GDPR.

### G. Frequency of Processing

Processing occurs on a continuous or occasional basis, depending on Customer's use of the Services and the functionality initiated, configured, or authorised by Customer.

### H. Retention

Customer Personal Data is retained only for as long as reasonably necessary to provide the Services, comply with Customer's documented instructions, meet applicable legal obligations, and maintain appropriate security, backup, and disaster-recovery processes.

Specific retention periods applicable to the Services are:

- Active Customer Data: kept while the Customer's account exists. If the Customer deletes its account, looot deletes the data tied to it on request.
- Application and operational logs: kept only as long as reasonably necessary for security and troubleshooting. looot does not currently set a fixed log-retention period.
- Backups: held by looot's database provider under that provider's backup schedule. looot does not currently set a separate backup-retention period.
- Support records: kept for as long as reasonably necessary to handle the request. looot does not currently set a fixed retention period.

Where technically feasible, deletion of the underlying Customer Data shall include deletion of derived representations that can reasonably be associated with or reconstructed into Customer Personal Data.

## Annex II — Authorised Subprocessors

Customer provides general authorisation for looot to use the following Subprocessors in accordance with Section 8 of this DPA.

| Subprocessor | Purpose | Processing Location | Personal Data Processed / Notes |
|---|---|---|---|
| Supabase | Database and authentication | Ireland (EU), AWS region eu-west-1 | Customer Data, account information, application data, account identifiers and authentication data |
| Stripe | Payments | Determined by Stripe; looot does not fix a region in its configuration | Billing and payment-related information; payment-card data is processed directly by Stripe |
| Resend | Transactional email | Determined by Resend; looot does not fix a region in its configuration | Name, email address and communication metadata |
| Vercel | Dashboard hosting | Frankfurt, Germany (EU) | Customer Data displayed in the dashboard, account identifiers and service metadata |
| Render | Gateway hosting | Frankfurt, Germany (EU) | Customer Data and service metadata |
| Tinybird | Usage analytics | London, United Kingdom (GCP europe-west2) | Technical and usage metadata (workspace and run identifiers, run status, cost). Run inputs and provider results are not sent. |

### Customer-Configured Third Parties

Third-party applications, MCP servers, APIs, data sources, or other services connected directly by Customer are not looot Subprocessors where the relevant third party provides its service directly to Customer.

In such cases, Customer instructs looot to transmit Customer Data to and from the applicable third party as necessary to perform the Customer-configured integration.

The same applies to every provider in the looot catalog: when Customer runs one of its endpoints, Customer selects that provider and instructs looot to transmit the request to it and return its response. The provider Processes the data under its own terms and is not a Subprocessor of looot, whether the call uses Customer's credentials or looot's platform credentials. Customer is responsible for having a lawful basis to use that provider and the data it returns.

### Subprocessor Updates

looot maintains the Subprocessor list in this Annex II (https://looot.ai/dpa#annex-ii) and in the Subprocessors section of the privacy policy (https://looot.ai/privacy).

Customer may subscribe to notifications of new or replacement Subprocessors by emailing walid@ayautomate.com to be added to the recipients of Subprocessor notices.

## Annex III — Technical and Organisational Measures

The following describes the technical and organisational measures maintained by looot to protect Customer Personal Data.

### 1. Access Control

looot applies access controls designed to ensure that Customer Personal Data is accessible only to persons and systems with an appropriate business or technical need.

Measures include, as applicable:

- unique user accounts;
- role-based access control;
- least-privilege principles;
- restrictions on production-system access;
- prompt revocation of access when no longer required; and
- authentication controls appropriate to the sensitivity of the applicable systems.

### 2. Data Segregation

Customer Data is logically segregated between customers through application and infrastructure controls appropriate to the architecture of the Services.

Customer Data is not intentionally exposed to other looot customers.

Every request is scoped to one workspace, and tenant data in the database is protected by Postgres row-level security keyed to that workspace.

### 3. Encryption

looot uses industry-standard encrypted communication protocols for Customer Data transmitted across public networks.

Measures include:

- TLS/HTTPS encryption for data in transit;
- encryption at rest where provided by the relevant infrastructure platform;
- appropriate management and protection of cryptographic keys and credentials; and
- secure storage of secrets and API credentials, including AES-256-GCM encryption of stored provider credentials in the gateway's secrets vault.

### 4. Credentials and Secrets

looot applies controls intended to prevent unauthorised access to credentials, tokens, API keys, and other secrets.

Such controls may include:

- dedicated secret-management mechanisms;
- separation of secrets from application source code;
- restricted access to production credentials;
- credential rotation where appropriate;
- prevention of unnecessary exposure of secrets in logs; and
- revocation or replacement of compromised credentials.

### 5. Software Development Security

looot maintains software-development practices designed to reduce security vulnerabilities before changes reach production.

These include, as applicable:

- version control;
- code review;
- dependency management;
- automated testing;
- separation of development and production environments; and
- remediation of identified vulnerabilities according to risk.

### 6. Vulnerability Management

looot takes reasonable measures to identify and address vulnerabilities affecting systems used to provide the Services.

These measures may include:

- timely application of security updates proportionate to risk; and
- remediation prioritised according to severity and exploitability.

### 7. Logging and Monitoring

looot maintains logging and monitoring appropriate to supporting security, troubleshooting, and operation of the Services.

Where feasible, logs are designed to avoid unnecessary inclusion of Customer Personal Data.

Access to logs containing Customer Personal Data is restricted consistently with the access-control principles set out in this Annex.

Log retention: see Annex I, Part H.

### 8. Availability and Resilience

looot uses infrastructure and operational measures designed to maintain an appropriate level of availability and resilience of the Services.

Measures may include:

- infrastructure monitoring;
- managed cloud infrastructure;
- backup mechanisms;
- restoration procedures;
- redundancy provided by infrastructure providers; and
- incident-response procedures.

### 9. Backup and Recovery

Customer Data may be included in backups maintained for resilience and disaster-recovery purposes.

Backups containing Customer Personal Data:

- remain subject to this DPA;
- are protected against unauthorised access;
- are not used for unrelated purposes; and
- are deleted or overwritten according to established backup-retention schedules.

Backup retention: see Annex I, Part H.

### 10. Security Incident Management

looot maintains procedures for responding to suspected security incidents.

These are designed to support:

1. identification;
2. containment;
3. investigation;
4. remediation;
5. recovery;
6. documentation; and
7. notification where required under applicable law or this DPA.

Security incidents involving Customer Personal Data are handled in accordance with Section 7 of this DPA.

### 11. Personnel Security and Confidentiality

Personnel and contractors with access to Customer Personal Data are required to maintain appropriate confidentiality.

Access is granted only where reasonably necessary for the individual's responsibilities.

looot provides security and privacy guidance appropriate to relevant personnel responsibilities.

### 12. Subprocessor Security

Before engaging a Subprocessor that will Process Customer Personal Data, looot shall take reasonable measures to assess whether the Subprocessor provides appropriate data-protection and security guarantees having regard to the nature and risk of the relevant Processing.

Subprocessors Processing Customer Personal Data are subject to contractual data-protection obligations in accordance with Section 8 of this DPA.

### 13. MCP and External Tool Security

Where the Services permit AI agents or other components to access external systems or tools, looot uses technical controls appropriate to the architecture of the Services to limit such access to authorised connections and credentials.

As applicable, such measures may include:

- scoped credentials;
- explicit tool configuration;
- least-privilege permissions;
- separation of credentials by Customer;
- controlled storage of connection secrets;
- validation of tool and integration configuration; and
- logging of relevant tool interactions.

Customer remains responsible for permissions granted to Customer-controlled external services, MCP servers, APIs, and other integrations.

### 14. Data Minimisation

looot seeks to Process only Customer Personal Data reasonably necessary to provide, secure, maintain, and support the Services in accordance with Customer's instructions.

Where feasible, systems are designed to avoid unnecessary persistence of Customer Data in logs, debugging systems, observability tooling, or intermediate processing layers.

## Annex IV — Contact Details

### Processor

**Legal name:** AY Automate LLC  
**Trading name:** looot.ai  
**Registered address:** 312 W 2nd St, Unit #A4881, Casper, WY 82601, United States  
**Privacy contact:** walid@ayautomate.com  
**Security contact:** walid@ayautomate.com  

### Controller

As specified in the Agreement, applicable Order Form, or other document through which Customer subscribes to the Services.

## Execution

This DPA forms part of the Agreement between the parties and may be executed electronically, incorporated into the Agreement by reference, or otherwise accepted in a manner permitted under applicable law.

Where signature is required:

### For looot

**Legal entity / contracting person:** __________________________  
**Trading as:** looot.ai  
**Name:** __________________________  
**Title:** __________________________  
**Date:** __________________________  
**Signature:** __________________________  

### For Customer

**Legal entity:** __________________________  
**Name:** __________________________  
**Title:** __________________________  
**Date:** __________________________  
**Signature:** __________________________
