Skip to content

Data processing agreement

Last updated

Plain English summary

We act as a processor for the customer content your workspace sends and receives. This says what we do with it, who else touches it, what happens when you delete it, and how quickly we tell you if something goes wrong. It has not been reviewed by outside counsel, and it deliberately does not promise a data residency guarantee, complete deletion, or an audit right, because the product cannot deliver those and a contract that says otherwise is worse than none.

Roles

Loonext (BytechLabs) acts as a processor in respect of the customer content a workspace sends and receives — messages, contacts, call recordings, voicemail — and as a controller in respect of its own account and billing records. The customer is the controller of their workspace's content and is responsible for having a lawful basis to contact the people in it. That responsibility is already stated in the acceptable use policy and is not softened here.

Subject matter, duration, nature and purpose

Categories of data subject: the customer's own crew members, and the customer's customers who text or call the workspace's number. Types of personal data: enumerated per field and per platform, with the reason for each, in docs/DATA-INVENTORY.md. That document rather than this clause is the authoritative list, because it is maintained against the schema.

  • Subject matter: operating a shared business phone number — sending and receiving SMS/MMS, placing and answering calls, storing the resulting conversation history, and the automated messages the workspace configures.
  • Duration: for as long as the workspace exists, plus the deletion window in §9.
  • Nature and purpose: providing the service the customer subscribed to. Not for our own analytics beyond the counts described in §5, and not for training models — see §7.

Processing on documented instructions

We process customer content to provide the service and on the customer's instructions, which for this product are expressed through the workspace's own settings — who is on the crew, which automations are on, what the away message says. We do not sell customer content, and we do not use message bodies to build profiles or advertising audiences.

Confidentiality

Access to production data is limited to people who need it to operate the service. Credentials are held as encrypted secrets and never in the repository; the database key is independently revocable and the payment key is restricted to billing scope. The size of that population is not stated here, because no document in this repository records it and a number invented for a contract is the kind of clause this document exists to avoid. It is a fair question for a buyer to ask and it should be answered from fact before this is signed.

Security measures

One historical note, and why it is not a disclosure clause. Between 2026-07-01 and 2026-08-09 our error-reporting breadcrumbs recorded full outbound URLs including query strings. The cause is fixed, nothing is being added, and those events age out by 2026-11-07 at the outside. The product was not publicly available in that window, so the data involved is our own test traffic and that of workspaces the founder controls — there is no customer whose data this concerns and therefore nothing for this contract to disclose to one. Recorded as R10 in docs/ACCEPTED-RISKS.md, which is the honest place for it.

  • Encryption in transit and at rest.
  • Message content is excluded from analytics and from error reporting. This is enforced rather than intended: Sentry's beforeSend strips request bodies and redacts phone numbers, sendDefaultPii is off, and there is no session replay on conversation pages.
  • Tenant isolation is performed by the API on every request. It is one layer, not two — the Worker's database key bypasses row-level security, so an unscoped query in our own code would be executed as written. SPEC §10 says so in those words rather than calling it defence-in-depth.
  • Analytics hold UUIDs, counts and feature events only.

Sub-processors

Current list, kept public and current: Cloudflare, OpenAI, PostHog, Resend, Sentry, Stripe, Supabase, Telnyx, and Cloudflare Workers AI. We will publish changes to that list on the same page. A customer who objects to a new sub-processor may terminate; there is no mechanism by which we could run the service for one workspace on a different set of vendors, and pretending otherwise would be a clause we could not honour.

AI processing

Customer message text and voicemail audio are processed by Cloudflare Workers AI and OpenAI for the features the workspace has enabled. The disclosure states the routing rather than implying containment, because inference cannot be confined to a country. Customer content is not used to train models. Cloudflare states this for Workers AI in terms we quote verbatim rather than paraphrase.

Personal data breach

We notify affected workspaces within 72 hours of confirming a breach of security safeguards that creates a real risk of significant harm, with what we know and what we do not yet know. Where we are a processor for the customer's data, we notify the customer and the customer notifies the people affected and the regulator.

Deletion and return

  • A customer can delete their workspace. Deletion is reversible for 30 days and irreversible after that.
  • Deletion is not complete in every store, and the exceptions are enumerated rather than implied. Today that is one: a message sent through the website contact form is held outside any workspace, is deleted on its own schedule after a year, and can be removed sooner on request.
  • Contacts can be exported. A broader export does not exist yet (#304).

Audits and information

We will answer a security questionnaire and provide the information in docs/SECURITY-QUESTIONNAIRE.md and the documents it cites. We do not offer on-site audits or penetration tests of production by customers, and there is no SOC 2 or ISO 27001 report to substitute for one. A clause granting audit rights we have no way to service would be the kind of promise this whole document is written to avoid.

International transfers

Data is stored in the United States. This is a statement of where it is, not a residency guarantee — we do not offer one, and AI inference in particular cannot be confined to a country. The cross-border disclosure required under PIPEDA and Quebec's Law 25 is on the privacy page.

What this document does not do

---

  • It does not claim a certification we do not hold.
  • It does not promise a residency, an audit right, or a completeness of deletion that the product cannot deliver.
  • It does not replace the terms of service; where the two disagree, that is a bug in this document and the terms win until it is fixed.

Contact

Questions about this agreement, or a redline from your legal team, go to support@loonext.com. A buyer whose counsel wants to mark this up is welcome to; the facts in it are checkable and will survive the exercise.