Data Processing Addendum
Last updated: August 11, 2026
These launch-ready product policies must be reviewed for the final operating entity and governing law before production billing is enabled.
Roles
For customer-provided personal data, the customer is controller and LookTwice is processor. LookTwice processes data only to provide, secure, support, and document the service.
Security measures
Controls include TLS, secret hashing, encryption at rest where supported, least-privilege access, log redaction, backups, deletion procedures, and incident response.
Subprocessing and transfers
LookTwice may use subprocessors in the United States and other locations. A production subprocessor list and applicable transfer mechanism must be published before general availability.
Deletion
On verified request or account termination, customer data is deleted from active systems according to documented retention schedules, subject to legal and backup retention.