Legal
Data Processing Agreement
Last updated: September 29, 2026
This Data Processing Agreement ("DPA") is between Loomrail, an MSME registered in India ("Loomrail", the processor), and the company or organisation that has a Loomrail company account ("Customer", the data fiduciary / controller). It forms part of the Terms of Service or any signed order between them, and applies whenever Loomrail processes personal data on the Customer's behalf.
To sign a copy with your company details, write to grievance@loomrail.com.
1. Roles and scope
The Customer decides why and how its members' data, and data about people it adds (such as candidates or test-takers), is processed. Loomrail processes that data only to provide the service and only on the Customer's documented instructions — the Terms, this DPA, the Customer's settings in the app, and its members' use of the product. Loomrail tells the Customer if it believes an instruction breaks the law. The applicable laws include India's Digital Personal Data Protection Act, 2023 and its Rules, and where relevant the EU/UK GDPR.
2. Confidentiality and people
Only Loomrail staff who need access to run or support the service can reach Customer data, under a duty of confidentiality, with least-privilege roles, and every staff action on an account is logged.
3. Security
Loomrail keeps the technical and organisational measures in Annex 2 and on the Security page, and may improve them but will not reduce the overall level of protection.
4. Sub-processors
The Customer authorises the sub-processors listed on the Sub-processors page. Loomrail binds each to data protection terms at least as protective as this DPA and remains responsible for them. Loomrail gives the Customer at least 30 days' notice of a new sub-processor; the Customer may object on reasonable data protection grounds, and if it can't be resolved, end the affected service and get a pro-rata refund of prepaid fees for it.
5. Transfers outside India
Data is stored in Singapore and processed by the sub-processors in the locations listed. Loomrail transfers data only to countries the Government of India has not restricted. For personal data subject to the EU or UK GDPR, the parties agree to the European Commission's Standard Contractual Clauses (and the UK Addendum), which are incorporated by reference.
6. Helping with people's rights
Loomrail gives the Customer tools to find, export, correct and delete data (in the app and through its admin console) and helps with requests from data principals that the Customer can't handle with those tools. Requests Loomrail receives directly about Customer data are passed to the Customer.
7. Personal data breaches
Loomrail notifies the Customer without undue delay and within 48 hours of becoming aware of a breach affecting Customer data, with what is known — nature, data and people affected, likely consequences, and measures taken — and updates as it learns more, so the Customer can meet its own duties (including the DPDP 72-hour report to the Data Protection Board). Loomrail also meets its own reporting duties, including to CERT-In.
8. Deletion and return
The Customer can export or delete its data at any time. When the Customer's account ends, Loomrail deletes Customer data within 30 days, except where the law requires keeping it (such as invoices), and on request confirms deletion in writing. Backups age out on their normal cycle.
9. Audits
Loomrail answers reasonable security questionnaires and shares its current security documentation and, when available, third-party audit or penetration-test reports under confidentiality. If those aren't enough to show compliance, the Customer may audit once a year with 30 days' notice, at its own cost, during business hours, without access to other customers' data.
10. Liability, term and law
Each party's liability under this DPA is subject to the limits in the Terms or signed order. This DPA lasts as long as Loomrail processes Customer data. It is governed by the laws of India, and the courts named in the Terms have jurisdiction. If this DPA and the Terms conflict on data protection, this DPA wins.
Annex 1 — Details of processing
| Subject matter | Providing Loomrail's AI agents, chat, Spaces, integrations and company administration |
| Duration | The Customer's subscription, plus up to 30 days for deletion |
| Nature and purpose | Storing, organising, retrieving and transmitting data; sending it to AI models to generate answers; acting in connected apps at a member's request |
| People concerned | The Customer's members; people whose data members add (candidates, test-takers, contacts in messages and files) |
| Kinds of data | Names, emails and account details; chats, files and agent settings; data from connected apps as members request; usage and security logs |
| Sensitive data | Not intended. The Customer can switch on masking of ID, financial and contact details before text reaches AI models |
Annex 2 — Security measures
- Encryption in transit (HTTPS / TLS) everywhere; encryption at rest by the hosting providers; app-level AES-256-GCM encryption of connected-app tokens, with the key in Google Secret Manager.
- Passwords stored only as salted bcrypt hashes; sign-out of every device on demand and after a password, email or role change.
- Company single sign-on (Google Workspace, Microsoft Entra or any SAML identity provider), SCIM user provisioning and de-provisioning, and admin roles for company accounts; two-factor sign-in with an authenticator app, required for Loomrail admins and available for the Customer to require of its members.
- Least-privilege staff roles; every staff action on accounts recorded in an audit log; company admins see an audit log of their members' activity.
- Human approval before an AI agent sends email, posts, or sends invitations; per-person send limits; defences against instructions hidden in outside content, including approval before opening a site the member didn't name after outside content was read, and images from other sites loading only on click.
- Secrets masked before text reaches AI models; Customer-selected masking of contact, ID and financial details.
- Company retention settings, deletion and export; deletion of an account removes its files from storage; the company audit log is kept for 3 years.
- Application logs kept 365 days, stored in India; a written breach-response plan covering DPDP and CERT-In timelines.
- AI model providers used through business APIs that do not train on API data.