Data Processing Addendum
Last updated: July 20, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Loona Brands LLC ("IPzest") and applies where IPzest processes personal data on Customer's behalf in the course of providing the Service.
This DPA applies automatically to every customer subject to the GDPR, UK GDPR, or Swiss FADP โ no signature is required. If your procurement process needs a countersigned copy, email info@ipzest.app and we will provide one.
1. Roles of the Parties
For personal data that Customer submits to the Service, and for personal data the Service collects from public sources at Customer's direction (for example listings, advertisements, and competitor records tied to Customer's monitoring configuration), Customer is the controller and IPzest is the processor. IPzest acts as an independent controller for its own account, billing, security, and product-improvement data, which is governed by our Privacy Policy rather than by this DPA.
2. Subject Matter and Details of Processing
- Subject matter: provision of the IPzest brand protection Service.
- Duration: the term of the Terms of Service, plus the deletion period in Section 9.
- Nature and purpose: hosting, storage, scanning of public sources, automated analysis, evidence capture, generation of takedown documentation, and support.
- Types of personal data: Customer's user account data (names, business email addresses, roles); and data about third parties gathered from public sources (seller and shop names, advertiser names, applicant and registrant names, associated public content and identifiers).
- Categories of data subjects: Customer's authorized users; marketplace sellers; advertisers; domain registrants; trademark applicants and registrants; and personnel of monitored competitors.
- Special category data: none. The Service is not designed for and must not be used to process special category data under Art. 9 GDPR.
3. IPzest's Obligations
- Process personal data only on Customer's documented instructions, which include the Terms of Service, this DPA, and Customer's configuration of the Service โ unless required otherwise by law, in which case IPzest will notify Customer unless that law prohibits it.
- Ensure that personnel authorized to process personal data are bound by confidentiality obligations.
- Implement the technical and organizational measures in Section 5.
- Assist Customer, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations under Arts. 32โ36 GDPR.
- Notify Customer if, in its opinion, an instruction infringes applicable data protection law.
4. Customer's Obligations
- Customer warrants that it has a valid legal basis for the processing it instructs, including for monitoring of public sources, and that it has completed any balancing assessment its own legitimate-interest reliance requires.
- Customer is responsible for the accuracy of the data it submits and for the lawfulness of any enforcement action it takes.
- Customer must not use the Service to process special category data or data relating to criminal convictions.
5. Security Measures
IPzest maintains the following measures, which are those described in Privacy Policy ยง8:
- Encryption of data in transit using TLS, and encryption at rest by our infrastructure providers
- Authentication and role-based access control, with production data access limited to personnel who require it
- Server-enforced authorization rules ensuring records are accessible only to the owning account
- Payment card data segregated to Stripe, a PCI-DSS Level 1 provider; IPzest never receives full card numbers
- Logging and monitoring of access, errors, and administrative actions
- Regular application of security updates to dependencies and infrastructure
6. Subprocessors
Customer provides general authorization for IPzest to engage subprocessors. IPzest imposes data protection obligations on each subprocessor no less protective than those in this DPA and remains liable for their performance. The current subprocessors are:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Authentication, Firestore database, file storage, hosting | United States |
| Google Cloud Vertex AI (Gemini) | AI detection, competitor profiling, and drafting assistance | United States |
| Vercel | Website and application hosting, product analytics | United States / global edge network |
| Stripe | Payment processing and subscription billing | United States |
| Firecrawl | Web crawling and page capture for infringement scanning | United States |
| eBay, Etsy, Meta Ad Library, Google Ads Transparency, USPTO | Public marketplace, advertising and trademark data sources | United States / global |
IPzest will give at least 30 days' notice before adding or replacing a subprocessor that processes Customer personal data. To receive that notice, email info@ipzest.app asking to be added to the subprocessor notification list. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service and receive a prorated refund of prepaid fees for the unused term.
7. International Transfers
IPzest is established in the United States and processes personal data there. Where Customer transfers personal data from the EEA, United Kingdom, or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer, with:
- Clause 7 (docking) included
- Clause 9 option 2 (general written authorization) with the 30-day notice period in Section 6
- Clause 11 optional redress mechanism excluded
- Clause 17 governing law and Clause 18 forum: Ireland
- Annexes I, II, and III populated by Sections 2, 5, and 6 of this DPA respectively
For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with the Information Commissioner as competent authority and UK law and courts governing. For Swiss transfers, references to the GDPR are read as references to the FADP and the Federal Data Protection and Information Commissioner is the competent authority.
8. Personal Data Breaches
IPzest will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. IPzest will provide reasonable assistance with Customer's own notification obligations under Arts. 33 and 34 GDPR.
9. Deletion and Return of Data
Customer may export its data at any time through the Service. On termination, IPzest deletes or anonymizes Customer personal data within 30 days, except where retention is required by law, and purges backups on a rolling basis within 90 days. On written request made before deletion, IPzest will return a copy of Customer personal data in a commonly used machine-readable format.
10. Audits
On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, IPzest will make available the information necessary to demonstrate compliance with this DPA and respond to a reasonable security questionnaire. Where Customer requires an on-site audit, the parties will agree scope, timing, and cost in advance, and the audit will be conducted in a manner that does not disrupt the Service or compromise the confidentiality of other customers' data.
11. Order of Precedence
In the event of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service and the Privacy Policy, in each case only as to the processing of personal data on Customer's behalf.
12. Contact
For privacy questions, subprocessor notifications, audit requests, or a countersigned copy of this DPA:
IPzest Privacy Team
Loona Brands LLC
Email: info@ipzest.app
14359 Miramar Pkwy #262, Miramar, FL 33027, United States