Data Processing Agreement
Last updated: September 2026 (version 1)
Who this agreement is between
This Data Processing Agreement is between the business that uses neonloops ("you", the controller) and Ender Yildirim e.U., Vienna, Austria ("we", the processor). It forms part of our Terms of Service at neonloops.com/terms and applies whenever we process personal data in your workspace content. Where it conflicts with the Terms on data protection, this agreement wins.
What we process
Subject matter and purpose: hosting your workspace and running your workflows, Studio and connected agents, as described in the Terms.
Duration: for as long as the agreement lasts, plus the retrieval and deletion periods below.
Nature: storing, organising, retrieving, transmitting and deleting data, and sending it to the AI models and connected apps your workflows use.
Types of data: whatever personal data you put into workflows, tables, files, skills, run inputs and outputs — typically names, contact details, and the contents of documents and messages. You should not put special categories of personal data into neonloops unless you have a lawful basis and the safeguards it requires.
People concerned: your members, and anyone whose data your workflows process — for example your customers, suppliers and employees.
Your instructions
We process personal data only on your documented instructions — the Terms, this agreement, and how you configure your workspace and workflows — including for transfers outside the EU, unless the law requires otherwise. If we believe an instruction breaks data protection law, we tell you.
Confidentiality and security
Everyone who can access your data on our side is bound to confidentiality.
We protect your data with at least these measures: servers in the EU; all connections encrypted in transit; workflow secrets encrypted at rest with AES-256; access limited by workspace roles; access tokens for external agents that expire after 7 days and can be renewed for up to 60; a record of every external agent call; and administrative access limited to what running the service needs.
Sub-processors
You give us general authorisation to use sub-processors. We bind each one to data protection obligations equivalent to this agreement, and we remain responsible for them. The current sub-processors are:
Hetzner Online GmbH — Hosting. Helsinki, Finland; EU.
Anthropic Ireland Ltd — AI models, agent sessions and agent memory. United States; Standard Contractual Clauses.
OpenAI Ireland Ltd — AI models. United States; Standard Contractual Clauses.
Google — AI models (Gemini API). United States; EU–US Data Privacy Framework.
Sampark, Inc. (Composio) — Connected apps: stores their sign-ins and makes the calls workflows request. United States; Standard Contractual Clauses.
Plus Five Five, Inc. (Resend) — Transactional email. United States; EU–US Data Privacy Framework.
Migadu-Mail GmbH — Support mailbox. Switzerland; Adequacy decision.
Another AI model provider receives data only when a workflow in your workspace is set to use it.
We publish any change on this page and email workspace owners at least 14 days before adding or replacing a sub-processor. If you object on reasonable data protection grounds, tell us at hi@neonloops.com before the change; if we cannot resolve it, you can end the agreement at no cost before the change takes effect.
Transfers outside the EU
Where a sub-processor processes data outside the EU, the transfer relies on an adequacy decision, the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses between us and that sub-processor, as listed above. You can ask us for a copy of the relevant clauses.
Helping you
We help you, as far as we reasonably can, to answer requests from people exercising their data protection rights, and with security, breach notification, data protection impact assessments and consulting the authority. If someone sends such a request to us about your workspace, we pass it to you.
Personal data breaches
If we become aware of a breach affecting personal data in your workspace, we tell the workspace owner without undue delay, with the information we have about what happened, the data and people affected, and what we are doing about it.
When the agreement ends
You can retrieve your data as described in the Terms under “Ending the agreement and taking your data”. After the retrieval period we delete your personal data, unless the law requires us to keep it, and confirm the deletion to you.
Information and audits
We make available the information you need to show that we meet our obligations under Art. 28 GDPR. If that information is not enough, you can audit us — or have an independent auditor bound to confidentiality do so — once a year, with 30 days' notice, at your own cost, in a way that does not disrupt the service or expose other customers' data. Contact hi@neonloops.com.