Data Processing Addendum (DPA) — Enterprise Template (LoomCAD)
Effective date: 12 February 2026
Last updated: 12 February 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and LoomCAD (“Provider”) governing Customer’s use of the Service (the “Agreement”). If there is a conflict between this DPA and the Agreement regarding processing of personal data, this DPA controls.
1. Roles
Customer is the Controller and Provider is the Processor for personal data processed on behalf of Customer in connection with the Service.
2. Processing instructions
Provider will process personal data only on documented instructions from Customer, including the use of the Service features and configurations chosen by Customer.
3. Confidentiality
Provider ensures that persons authorized to process personal data are bound by confidentiality obligations.
4. Security measures
Provider implements appropriate technical and organizational measures designed to protect personal data, including:
- encryption in transit (TLS);
- logical access controls and least privilege;
- administrative access logging;
- operational log retention controls;
- protections for stored secrets such as third-party API keys (where stored).
5. Subprocessors
Customer authorizes Provider to use subprocessors to provide the Service. Provider remains responsible for subprocessors’ compliance.
Provider maintains an up-to-date list of subprocessors at:
loomcad.com/subprocessors
Provider will provide at least 10 business days notice of material changes to subprocessors (for example via the Service or email). Customer may object to a new subprocessor within 30 days of notice on reasonable grounds related to data protection.
6. Assistance
To the extent required by applicable law and taking into account the nature of processing, Provider will assist Customer with:
- responding to data subject requests (where Customer cannot do so through the Service);
- security and DPIA information reasonably required;
- breach information.
7. Personal data breach
Provider will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data and, where feasible, within 72 hours of awareness. Provider will provide information reasonably necessary for Customer’s compliance.
8. International transfers and SCCs
Where GDPR applies and personal data is transferred outside the EU/EEA, Provider will use appropriate safeguards, such as SCCs, and rely on certified transfer frameworks where applicable.
If SCCs are required for a particular transfer, Provider will make SCCs available and execute them on request, including completing relevant annexes with reasonable cooperation from Customer.
9. Deletion and return
Upon termination of the Agreement or upon verified instruction from Customer, Provider will delete Customer personal data within 30 days, except to the extent retention is required by law or necessary for security/fraud prevention consistent with the Service’s retention policy.
10. Audit
Provider will make available information reasonably necessary to demonstrate compliance. Audit requests will be subject to reasonable confidentiality, scope, timing, and cost arrangements.
Annex A — Details of processing
- Subject matter: provision of CAD collaboration, storage, AI assistance (if enabled), and related features.
- Duration: term of the Agreement plus retention period.
- Nature/purpose: hosting, collaboration, authentication, analytics (if enabled), AI processing (if used), security and fraud prevention.
- Data subjects: Customer’s authorized users (employees/contractors), workspace collaborators.
- Personal data: identifiers (email, auth IDs), access roles, logs (IP/UA), and any personal data included in Customer Content.
- Special categories: not intended; Customer should avoid submitting special categories unless agreed and legally permitted.