Data Processing Addendum

Last updated: July 20, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Loona Brands LLC ("IPzest") and applies where IPzest processes personal data on Customer's behalf in the course of providing the Service.

This DPA applies automatically to every customer subject to the GDPR, UK GDPR, or Swiss FADP โ€” no signature is required. If your procurement process needs a countersigned copy, email info@ipzest.app and we will provide one.

1. Roles of the Parties

For personal data that Customer submits to the Service, and for personal data the Service collects from public sources at Customer's direction (for example listings, advertisements, and competitor records tied to Customer's monitoring configuration), Customer is the controller and IPzest is the processor. IPzest acts as an independent controller for its own account, billing, security, and product-improvement data, which is governed by our Privacy Policy rather than by this DPA.

2. Subject Matter and Details of Processing

  • Subject matter: provision of the IPzest brand protection Service.
  • Duration: the term of the Terms of Service, plus the deletion period in Section 9.
  • Nature and purpose: hosting, storage, scanning of public sources, automated analysis, evidence capture, generation of takedown documentation, and support.
  • Types of personal data: Customer's user account data (names, business email addresses, roles); and data about third parties gathered from public sources (seller and shop names, advertiser names, applicant and registrant names, associated public content and identifiers).
  • Categories of data subjects: Customer's authorized users; marketplace sellers; advertisers; domain registrants; trademark applicants and registrants; and personnel of monitored competitors.
  • Special category data: none. The Service is not designed for and must not be used to process special category data under Art. 9 GDPR.

3. IPzest's Obligations

  • Process personal data only on Customer's documented instructions, which include the Terms of Service, this DPA, and Customer's configuration of the Service โ€” unless required otherwise by law, in which case IPzest will notify Customer unless that law prohibits it.
  • Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
  • Implement the technical and organizational measures in Section 5.
  • Assist Customer, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations under Arts. 32โ€“36 GDPR.
  • Notify Customer if, in its opinion, an instruction infringes applicable data protection law.

4. Customer's Obligations

  • Customer warrants that it has a valid legal basis for the processing it instructs, including for monitoring of public sources, and that it has completed any balancing assessment its own legitimate-interest reliance requires.
  • Customer is responsible for the accuracy of the data it submits and for the lawfulness of any enforcement action it takes.
  • Customer must not use the Service to process special category data or data relating to criminal convictions.

5. Security Measures

IPzest maintains the following measures, which are those described in Privacy Policy ยง8:

  • Encryption of data in transit using TLS, and encryption at rest by our infrastructure providers
  • Authentication and role-based access control, with production data access limited to personnel who require it
  • Server-enforced authorization rules ensuring records are accessible only to the owning account
  • Payment card data segregated to Stripe, a PCI-DSS Level 1 provider; IPzest never receives full card numbers
  • Logging and monitoring of access, errors, and administrative actions
  • Regular application of security updates to dependencies and infrastructure

6. Subprocessors

Customer provides general authorization for IPzest to engage subprocessors. IPzest imposes data protection obligations on each subprocessor no less protective than those in this DPA and remains liable for their performance. The current subprocessors are:

SubprocessorPurposeLocation
Google Cloud / FirebaseAuthentication, Firestore database, file storage, hostingUnited States
Google Cloud Vertex AI (Gemini)AI detection, competitor profiling, and drafting assistanceUnited States
VercelWebsite and application hosting, product analyticsUnited States / global edge network
StripePayment processing and subscription billingUnited States
FirecrawlWeb crawling and page capture for infringement scanningUnited States
eBay, Etsy, Meta Ad Library, Google Ads Transparency, USPTOPublic marketplace, advertising and trademark data sourcesUnited States / global

IPzest will give at least 30 days' notice before adding or replacing a subprocessor that processes Customer personal data. To receive that notice, email info@ipzest.app asking to be added to the subprocessor notification list. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service and receive a prorated refund of prepaid fees for the unused term.

7. International Transfers

IPzest is established in the United States and processes personal data there. Where Customer transfers personal data from the EEA, United Kingdom, or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer, with:

  • Clause 7 (docking) included
  • Clause 9 option 2 (general written authorization) with the 30-day notice period in Section 6
  • Clause 11 optional redress mechanism excluded
  • Clause 17 governing law and Clause 18 forum: Ireland
  • Annexes I, II, and III populated by Sections 2, 5, and 6 of this DPA respectively

For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with the Information Commissioner as competent authority and UK law and courts governing. For Swiss transfers, references to the GDPR are read as references to the FADP and the Federal Data Protection and Information Commissioner is the competent authority.

8. Personal Data Breaches

IPzest will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. IPzest will provide reasonable assistance with Customer's own notification obligations under Arts. 33 and 34 GDPR.

9. Deletion and Return of Data

Customer may export its data at any time through the Service. On termination, IPzest deletes or anonymizes Customer personal data within 30 days, except where retention is required by law, and purges backups on a rolling basis within 90 days. On written request made before deletion, IPzest will return a copy of Customer personal data in a commonly used machine-readable format.

10. Audits

On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, IPzest will make available the information necessary to demonstrate compliance with this DPA and respond to a reasonable security questionnaire. Where Customer requires an on-site audit, the parties will agree scope, timing, and cost in advance, and the audit will be conducted in a manner that does not disrupt the Service or compromise the confidentiality of other customers' data.

11. Order of Precedence

In the event of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service and the Privacy Policy, in each case only as to the processing of personal data on Customer's behalf.

12. Contact

For privacy questions, subprocessor notifications, audit requests, or a countersigned copy of this DPA:

IPzest Privacy Team

Loona Brands LLC

Email: info@ipzest.app

14359 Miramar Pkwy #262, Miramar, FL 33027, United States