Data Processing Agreement

Version 1.1 — 5 January 2026

DPA between Loony / Bonnard Ltd. (Processor) and Customer (Controller).

1. Compliance with Data Protection Laws

EU GDPR, UK GDPR, UK DPA 2018.

2. Processing Scope

Solely to provide Services. Categories: names, emails, phones, IPs, device IDs.

3. Controller/Processor Roles

Controller and Processor roles defined per applicable law. Contact: privacy@loony.dev

4. Confidentiality

Confidentiality obligations for all personnel.

5. Technical Measures

6. Sub-processors

ProviderRegionPurpose
SupabaseEUDatabase
VercelEUHosting
AWS/AnthropicEUAI
ClerkUS (DPF)Auth
SentryEUErrors
PostHogEUAnalytics
Fly.ioUKApp Hosting
AxiomEULogging

7. Data Subject Requests

Forwarded within 5 business days.

8. Breach Notification

Notification within 48 hours.

9. DPIA Assistance

Data Protection Impact Assessment assistance provided upon request.

10. Audit Rights

Annual audit rights with 30 days notice.

11. Data Return & Deletion

Return or deletion within 30 days post-termination.

12. Data Location

Data stored in EU/EEA/UK only.

13. Governing Law

English law governs.

© 2026 Loony (a Bonnard.dev app)