Data Processing Addendum
Last updated: 13 July 2026
This DPA governs how Ownloop processes subscriber and entrant personal data on behalf of Creators, as a processor under the GDPR and equivalent laws. It supplements the Terms of Service and Privacy Policy.
1. Introduction and relationship to the Terms
This Data Processing Addendum ("DPA") forms part of, and is subject to, the Terms of Service between Gildium, UAB ("Ownloop", "Processor", "we") and the customer ("Customer", "Creator", "Controller", "you") (together the "Agreement"). It governs our processing of personal data on your behalf when you use the Service.
This DPA applies where, and to the extent that, we process Subscriber Data (personal data relating to Entrants and Subscribers) as a processor on your behalf, and where such processing is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, the Lithuanian Law on Legal Protection of Personal Data, or equivalent data-protection laws ("Data Protection Laws").
For personal data where Ownloop is itself the controller (e.g. your account and billing data), our Privacy Policy applies, not this DPA. In the event of a conflict between this DPA and the rest of the Agreement regarding the processing of Subscriber Data, this DPA prevails.
2. Definitions
Capitalised terms not defined here have the meaning given in the Terms of Service. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings in the GDPR. "Sub-processor" means any processor engaged by us to process Subscriber Data. "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission in Decision (EU) 2021/914.
3. Roles of the parties
The parties acknowledge that, in respect of Subscriber Data, you are the Controller (or a processor acting on behalf of another controller) and Ownloop is the Processor (or sub-processor). Where you are yourself a processor for a third-party controller, you warrant that you are authorised to instruct us and to enter into this DPA on that controller's behalf.
Each party will comply with its obligations under Data Protection Laws. You are responsible for the lawfulness of the Subscriber Data and of your instructions, including having a valid legal basis, providing required notices to Data Subjects, and obtaining and recording any required consents.
4. Scope, subject matter, and details of processing
The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1 (Details of Processing) below.
We will process Subscriber Data only for the duration of the Agreement and as necessary to provide and support the Service, and thereafter as set out in Section 11.
5. Processing on documented instructions
We will process Subscriber Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member-State law to which we are subject (in which case we will inform you, unless the law prohibits it). Your instructions are set out in the Agreement, this DPA, and your configuration and use of the Service (e.g. the Campaigns you run, channels you connect, segments you build, and messages you send).
We will inform you if, in our opinion, an instruction infringes Data Protection Laws. We will not sell Subscriber Data and will not use it for our own purposes, including for advertising or model training.
6. Confidentiality
We ensure that persons authorised to process Subscriber Data are bound by an appropriate obligation of confidentiality and are trained on their data-protection responsibilities. Access is limited to personnel who need it to provide the Service.
7. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to Data Subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2 (Security Measures) below (Article 32 GDPR). We may update these measures provided the level of protection is not materially reduced.
8. Sub-processing
You provide a general authorisation for us to engage Sub-processors to process Subscriber Data. Our current Sub-processors are listed in Annex 3 below. We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable for their performance.
We will inform you of any intended addition or replacement of a Sub-processor (e.g. by updating Annex 3 and/or by email or in-app notice), giving you the opportunity to object on reasonable data-protection grounds within 14 days. If you reasonably object and we cannot provide a commercially reasonable alternative, you may, as your sole remedy, terminate the affected part of the Service.
9. Assistance with data-subject rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests by Data Subjects exercising their rights under Data Protection Laws. The Service provides self-service tools (e.g. to search, edit, export, and delete Subscriber records) that enable you to respond to most requests directly. If we receive a request from a Data Subject regarding Subscriber Data, we will, where legally permitted, refer them to you and not respond directly except on your instruction.
10. Assistance with security, breaches, and DPIAs
We will assist you, taking into account the nature of processing and the information available to us, in ensuring compliance with your obligations regarding security (Art. 32), personal-data-breach notification (Arts. 33–34), data-protection impact assessments (Art. 35), and prior consultation (Art. 36).
Breach notification
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Subscriber Data, and will provide information reasonably available to us to help you meet your own notification obligations. Our notification is not an acknowledgement of fault or liability. You are responsible for notifying Supervisory Authorities and affected Data Subjects where required.
11. Return and deletion of Subscriber Data
On termination or expiry of the Agreement, and at your choice, we will delete or return Subscriber Data and delete existing copies, unless EU or Member-State law requires storage. You may export Subscriber Data via the Service (e.g. CSV export) before termination. Following a reasonable wind-down period, we will delete or anonymise Subscriber Data in the ordinary course, subject to backups that are overwritten on a rolling basis and to legal retention requirements.
12. Audits and information
We will make available to you information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits will occur no more than once per year (unless required by a Supervisory Authority or following a breach), on reasonable prior notice, during business hours, subject to confidentiality, and without unreasonably disrupting our operations. We may satisfy audit requests by providing relevant certifications, third-party audit reports, or a written response to a security questionnaire.
13. International transfers
We will not transfer Subscriber Data outside the EU/EEA, or to a Sub-processor located outside the EU/EEA, without ensuring appropriate safeguards under Data Protection Laws. Where required, the parties agree that the Standard Contractual Clauses apply and are incorporated by reference: for controller-to-processor transfers, Module Two; for processor-to-processor transfers, Module Three; with docking, and with the optional clauses selected as reasonably necessary. For transfers subject to UK law, the UK International Data Transfer Addendum applies. Annex 1 and Annex 2 of this DPA populate the corresponding annexes of the SCCs; the supervisory authority and governing law are those of Lithuania.
14. Liability and miscellaneous
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA is governed by the same law and jurisdiction as the Agreement. If any provision is invalid, the remainder continues in effect. This DPA may be updated to reflect changes in Data Protection Laws or the SCCs.
15. Annex 1 - Details of Processing
- Data exporter / Controller: the Customer (Creator) identified in the Account.
- Data importer / Processor: Gildium, UAB, Polocko g. 17-113, LT-01205 Vilnius, Lithuania.
- Subject matter: provision of the Ownloop Service (giveaway/subscriber-management platform).
- Duration: the term of the Agreement, plus the wind-down period in Section 11.
- Nature and purpose: collecting, storing, organising, verifying, deduplicating, segmenting, exporting, and (where configured) messaging Subscribers, and generating analytics, all to provide the Service on the Controller's instructions.
- Categories of Data Subjects: the Controller's Entrants, Subscribers, campaign participants, and referred contacts.
- Types of Personal Data: name/username, email address, channel identifiers and handles (e.g. Telegram/Discord), entry and verification status, referral attribution, engagement, winner status, consent records, tags, notes, IP-derived and technical data, and any other data the Controller chooses to collect via the Service.
- Special categories: none intended or required; the Controller must not submit special-category data unless lawful and necessary.
- Frequency: continuous, for the duration of the Agreement.
16. Annex 2 - Security Measures
We maintain appropriate technical and organisational measures, which may include:
- encryption of Personal Data in transit (TLS) and at rest where appropriate;
- access controls, authentication, and least-privilege / role-based access;
- network security, firewalls, and segregation of environments;
- logging, monitoring, and alerting for security events;
- secure software-development practices and change management;
- regular backups and tested restoration procedures;
- vendor/sub-processor due diligence and contractual safeguards;
- personnel confidentiality obligations and security awareness; and
- an incident-response process for detecting, handling, and notifying breaches.
17. Annex 3 - Authorised Sub-processors
We use the following categories of Sub-processors to provide the Service. This list may be updated in accordance with Section 8.
- Stripe (Stripe, Inc. / Stripe Payments Europe) - payment and subscription processing.
- Cloud hosting & infrastructure provider(s) - application hosting, storage, and databases (EU/EEA regions where available).
- Google (Google Ireland Ltd.) - Google Tag Manager and Google Analytics, subject to consent.
- Email / communications provider(s) - transactional and campaign email delivery.
- Support, error-monitoring, and logging tool(s) - customer support and operational monitoring.
18. Contact
Gildium, UAB · Polocko g. 17-113, LT-01205 Vilnius, Lithuania
Data-protection contact: support@ownloop.io · Website: ownloop.io
Questions about this document? Contact us at support@ownloop.io.