Version 2026-09-05
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Bytloop ("Bytloop", "Processor") and the customer identified in the associated account ("Customer", "Controller") when Customer uses Bytloop Mail (the "Service") to process personal data on behalf of individuals. Customers subject to GDPR (EU 2016/679), UK GDPR, or similar frameworks are entering into this DPA by their continued use of the Service; a signed copy can be requested at hello@bytloop.com.
"Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data that Customer submits to, or that is generated by Customer's use of, the Service. "Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the GDPR, the UK GDPR, the Swiss FADP, and applicable US state privacy laws.
Customer is the Controller of Customer Personal Data. Bytloop is the Processor, acting only on Customer's documented instructions. Bytloop is a Controller for its own account, billing, and audit records — that processing is governed by our Privacy Policy, not this DPA.
Subject-matter: processing Customer Personal Data as necessary to provide the Service.
Duration:for as long as Customer's account is active, plus a limited post-termination retention window per § 10.
Nature and purpose:hosting, transmitting, storing, and analysing Customer's email content, contact lists, and related metadata to send / receive email, manage mailboxes, run campaigns, and produce reports.
Types of Personal Data: contact names, email addresses, user agents, IP addresses, message headers and bodies, attachments, engagement metrics.
Categories of Data Subjects:Customer's employees, contractors, end users, subscribers, prospects, and recipients.
Bytloop will process Customer Personal Data only on Customer's documented instructions, which include (a) the Terms of Service, (b) this DPA, (c) Customer's configuration and API calls, and (d) any additional written instructions the parties agree to. If Bytloop believes an instruction infringes Data Protection Laws, it will inform Customer.
Bytloop will ensure that personnel authorised to process Customer Personal Data are bound by written confidentiality obligations and receive appropriate data-protection training.
Bytloop will implement and maintain the technical and organisational measures described in Annex II below, taking into account the state of the art, cost of implementation, and the risks presented by the processing.
Customer provides general authorisation for Bytloop to engage sub-processors, subject to this DPA. The current list of sub-processors is published in the Privacy Policy and reproduced in Annex III. Bytloop will notify Customer at least fifteen (15) days before appointing a new sub-processor by email to the account's billing contact or by dashboard notice. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if no resolution is possible Customer may terminate the affected part of the Service. Bytloop imposes obligations on each sub-processor no less protective than this DPA.
Bytloop will, taking into account the nature of the processing, provide reasonable assistance to help Customer fulfil its obligation to respond to Data Subject requests. The Service's built-in export, deletion, and rectification tools satisfy most requests without additional work. Where a Data Subject contacts Bytloop directly, Bytloop will forward the request to Customer.
Bytloop will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data breach affecting Customer Personal Data. The notification will include the nature of the breach, categories and approximate numbers of Data Subjects and records concerned, likely consequences, and measures taken or proposed. Bytloop will cooperate with Customer's investigation and any Supervisory Authority notification obligations.
On termination or expiry, Customer may export Customer Personal Data through the Service for at least thirty (30) days. After that period, Bytloop will delete Customer Personal Data from active systems within ninety (90) days, subject to backup rotation of up to a further ninety (90) days, unless retention is required by law.
Bytloop will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including (where available) up-to-date third- party audit reports (e.g. SOC 2, ISO 27001) covering our sub-processors. Customer may conduct additional audits at its own cost, on reasonable notice, at most once per year, subject to confidentiality and to minimise disruption. Regulator audits are exempt from these limits.
For transfers of Customer Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree to the European Commission's Standard Contractual Clauses (Module 2 — Controller to Processor) and, for UK transfers, the UK International Data Transfer Addendum. Where Bytloop transfers Customer Personal Data onwards to a sub-processor, the SCC Module 3 (Processor to Sub-processor) will apply. The SCCs are incorporated by reference; the operative details for their Annexes are supplied by Annex I, II, and III below.
The limitations of liability set out in the Terms of Service apply to each party's obligations under this DPA. Nothing in this DPA excludes or limits any liability that cannot be excluded or limited under applicable law.
In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of Customer Personal Data.
The parties are identified in the associated account. Contact for the Data Exporter is the account owner; contact for the Data Importer is hello@bytloop.com. The subject-matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are as set out in § 3 of this DPA.
The current sub-processor list is maintained in the Privacy Policy § 5 and updated as sub-processors change.
Bytloop
Dhaka, Bangladesh
Jurisdiction: Bangladesh
Data protection contact: hello@bytloop.com
Terms of Service · Privacy Policy · Acceptable Use Policy · SLA