Legal

Data Processing Agreement

Available on request · Last updated April 2026

When you use ValueWE to process personal data of your employees, customers, or prospects, you act as the controller and Double Loop GmbH acts as the processor within the meaning of Art. 4 (7) and (8) GDPR. Art. 28 GDPR requires that this relationship be governed by a written data processing agreement ("DPA").

We provide a standard DPA to every customer on request, at no cost. It is based on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and adapted to the specifics of the ValueWE Service.

How to request the DPA

Send an email to [email protected] from the billing contact on your ValueWE account (or, for prospective customers, the person handling procurement on your side) with the subject line "DPA request". Please include:

  • the legal name and address of the contracting entity;
  • the name and email of the authorised signatory;
  • whether you would like us to sign our template or review your own template.

We will send a countersigned copy back within five business days. Larger customers with a template of their own are welcome to share it — we will review and either counter-sign or suggest redlines.

What our DPA covers

  • Roles. You are the controller; Double Loop GmbH is the processor. We only process personal data on your documented instructions.
  • Subject-matter, duration, nature, purpose. Providing the ValueWE platform for the duration of your subscription.
  • Categories of data subjects and personal data. Your Authorised Users and anyone you reference in case workspaces (typically professional contacts at customer and prospect companies). No special categories (Art. 9 GDPR) are processed beyond what you voluntarily enter.
  • Confidentiality obligations on everyone at Double Loop with access to your data.
  • Security measures under Art. 32 GDPR — a detailed list of technical and organisational measures (TOMs) is attached as Annex 2.
  • Subprocessors. General written authorisation for the subprocessors listed below, with prior notice of any new subprocessor and the right to object on reasonable data-protection grounds.
  • International transfers. EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, together with a transfer impact assessment.
  • Assistance with data subject requests (Art. 15–22 GDPR), data breach notifications (Art. 33–34 GDPR), and Data Protection Impact Assessments (Art. 35 GDPR).
  • Audit rights — annual documentation-based audits, with on-site audits available on reasonable notice.
  • Return and deletion of personal data at the end of the agreement, subject to statutory retention obligations.

Current subprocessors

The following subprocessors are used to deliver the ValueWE Service. This list forms part of Annex 3 of the DPA and is kept up to date here. We notify customers of any additions or replacements in advance.

Subprocessor Purpose Location Transfer safeguard
Hetzner Online GmbH Hosting, compute, managed PostgreSQL, backups Germany (EU) Not applicable — within EU
Cloudflare, Inc. CDN, DNS, bot protection, object storage (R2, EU jurisdiction) for attachments and exports US / global edge; EU jurisdiction for R2 EU SCCs + technical measures
Stripe Payments Europe Ltd. / Stripe, Inc. Subscription billing, invoicing, payment processing Ireland (EU) / United States EU–US Data Privacy Framework + SCCs
Resend, Inc. Transactional email (sign-up, password reset, notifications) United States EU SCCs
Anthropic, PBC Large language model inference (Claude) — no-training contract United States EU SCCs
OpenAI, LLC Large language model inference (GPT) — no-training contract United States EU SCCs
Google LLC Large language model inference (Gemini) — no-training contract United States EU–US Data Privacy Framework + SCCs

Technical and organisational measures (summary)

The TOMs annex attached to the DPA covers, at minimum:

  • Pseudonymisation and encryption — TLS 1.2+ in transit, AES-256 at rest, encrypted backups, encrypted 2FA secrets at the database level.
  • Confidentiality — strict per-tenant data isolation, role- based access control, least-privilege principle, server-side prompt and configuration confidentiality, written confidentiality undertakings by every person with access.
  • Integrity — audit logging, version-controlled deployments, integrity checks on backups.
  • Availability and resilience — monitored uptime, regular backup verification, documented incident response procedures.
  • Authentication — mandatory two-factor authentication on every account, password hashing with modern algorithms, session binding.
  • Physical security — EU data centres operated by our hosting provider with ISO 27001-certified operational security.
  • No-training commitment — we do not use Customer Data to train, fine-tune, or improve AI models, and we contractually require the same of every LLM provider.
  • Evaluation — periodic review of access rights, security controls, and subprocessor compliance.

Notifications and changes

We will notify customers under an active DPA of:

  • any intended addition or replacement of a subprocessor, with at least 30 days' notice and an opportunity to object on reasonable grounds;
  • any personal data breach affecting their Customer Data without undue delay and in any event within 72 hours of becoming aware of it;
  • any material update to our TOMs or to the DPA template itself.

Related documents

For full context, please also read our Privacy Policy and Terms of Service. The DPA supplements, and in the event of conflict in relation to personal data processing, prevails over the Terms of Service.