Data Processing Agreement

Version 2026-09-05

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Bytloop ("Bytloop", "Processor") and the customer identified in the associated account ("Customer", "Controller") when Customer uses Bytloop Mail (the "Service") to process personal data on behalf of individuals. Customers subject to GDPR (EU 2016/679), UK GDPR, or similar frameworks are entering into this DPA by their continued use of the Service; a signed copy can be requested at hello@bytloop.com.

1. Definitions

"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data that Customer submits to, or that is generated by Customer's use of, the Service. "Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the GDPR, the UK GDPR, the Swiss FADP, and applicable US state privacy laws.

2. Roles

Customer is the Controller of Customer Personal Data. Bytloop is the Processor, acting only on Customer's documented instructions. Bytloop is a Controller for its own account, billing, and audit records — that processing is governed by our Privacy Policy, not this DPA.

3. Scope, subject-matter & duration

Subject-matter: processing Customer Personal Data as necessary to provide the Service.
Duration:for as long as Customer's account is active, plus a limited post-termination retention window per § 10.
Nature and purpose:hosting, transmitting, storing, and analysing Customer's email content, contact lists, and related metadata to send / receive email, manage mailboxes, run campaigns, and produce reports.
Types of Personal Data: contact names, email addresses, user agents, IP addresses, message headers and bodies, attachments, engagement metrics.
Categories of Data Subjects:Customer's employees, contractors, end users, subscribers, prospects, and recipients.

4. Customer instructions

Bytloop will process Customer Personal Data only on Customer's documented instructions, which include (a) the Terms of Service, (b) this DPA, (c) Customer's configuration and API calls, and (d) any additional written instructions the parties agree to. If Bytloop believes an instruction infringes Data Protection Laws, it will inform Customer.

5. Confidentiality

Bytloop will ensure that personnel authorised to process Customer Personal Data are bound by written confidentiality obligations and receive appropriate data-protection training.

6. Security measures

Bytloop will implement and maintain the technical and organisational measures described in Annex II below, taking into account the state of the art, cost of implementation, and the risks presented by the processing.

7. Sub-processors

Customer provides general authorisation for Bytloop to engage sub-processors, subject to this DPA. The current list of sub-processors is published in the Privacy Policy and reproduced in Annex III. Bytloop will notify Customer at least fifteen (15) days before appointing a new sub-processor by email to the account's billing contact or by dashboard notice. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if no resolution is possible Customer may terminate the affected part of the Service. Bytloop imposes obligations on each sub-processor no less protective than this DPA.

8. Data Subject requests

Bytloop will, taking into account the nature of the processing, provide reasonable assistance to help Customer fulfil its obligation to respond to Data Subject requests. The Service's built-in export, deletion, and rectification tools satisfy most requests without additional work. Where a Data Subject contacts Bytloop directly, Bytloop will forward the request to Customer.

9. Personal-data breach notification

Bytloop will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data breach affecting Customer Personal Data. The notification will include the nature of the breach, categories and approximate numbers of Data Subjects and records concerned, likely consequences, and measures taken or proposed. Bytloop will cooperate with Customer's investigation and any Supervisory Authority notification obligations.

10. Return & deletion

On termination or expiry, Customer may export Customer Personal Data through the Service for at least thirty (30) days. After that period, Bytloop will delete Customer Personal Data from active systems within ninety (90) days, subject to backup rotation of up to a further ninety (90) days, unless retention is required by law.

11. Audits

Bytloop will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including (where available) up-to-date third- party audit reports (e.g. SOC 2, ISO 27001) covering our sub-processors. Customer may conduct additional audits at its own cost, on reasonable notice, at most once per year, subject to confidentiality and to minimise disruption. Regulator audits are exempt from these limits.

12. International transfers

For transfers of Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree to the European Commission's Standard Contractual Clauses (Module 2 — Controller to Processor) and, for UK transfers, the UK International Data Transfer Addendum. Where Bytloop transfers Customer Personal Data onwards to a sub-processor, the SCC Module 3 (Processor to Sub-processor) will apply. The SCCs are incorporated by reference; the operative details for their Annexes are supplied by Annex I, II, and III below.

13. Liability

The limitations of liability set out in the Terms of Service apply to each party's obligations under this DPA. Nothing in this DPA excludes or limits any liability that cannot be excluded or limited under applicable law.

14. Order of precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of Customer Personal Data.

Annex I — Description of Processing

The parties are identified in the associated account. Contact for the Data Exporter is the account owner; contact for the Data Importer is hello@bytloop.com. The subject-matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are as set out in § 3 of this DPA.

Annex II — Technical & Organisational Measures

  • Encryption in transit (TLS 1.2+) for all customer traffic and API calls.
  • Encryption at rest for the primary database and attachment storage using AES-256.
  • Per-tenant logical isolation; row-level tenant_id enforcement in the data layer.
  • Role-based access control for Bytloop personnel with least-privilege by default, MFA required for administrative access.
  • Immutable audit log of security-relevant events (authentication, role changes, data exports).
  • Regular automated dependency scanning, static code analysis, and secret detection on every merge.
  • Documented incident-response plan with 24-hour internal triage and 72-hour Customer notification target for confirmed breaches.
  • Regular restore-tests of backups; time-limited retention on backup media.
  • Personnel background checks (where legally permitted) and mandatory data-protection training on hire and annually.

Annex III — Sub-processors

The current sub-processor list is maintained in the Privacy Policy § 5 and updated as sub-processors change.

Bytloop
Dhaka, Bangladesh
Jurisdiction: Bangladesh
Data protection contact: hello@bytloop.com

Terms of Service · Privacy Policy · Acceptable Use Policy · SLA