Data Processing Addendum
Last updated: August 12, 2026
Scope and roles
This Data Processing Addendum applies when LookTwice processes personal data submitted by a customer through the Service. The customer is the controller or business, and LookTwice is the processor or service provider, except where LookTwice independently controls account, security, and billing records.
Instructions and purpose
LookTwice processes customer personal data only on documented instructions embodied in the Terms, API requests, watch configuration, and support requests, and only to provide, secure, monitor, and support the Service. We will inform the customer if an instruction appears unlawful unless prohibited from doing so.
Confidentiality and security
People authorized to process customer data are subject to confidentiality obligations. Security controls include TLS, secret hashing, encryption at rest where supported, least-privilege access, log redaction, backups, deletion procedures, dependency management, monitoring, and incident response appropriate to the risk.
Subprocessors
The customer authorizes LookTwice to use subprocessors for hosting, database, queue, storage, authentication, email, AI extraction, monitoring, analytics, support, and related infrastructure. LookTwice remains responsible for requiring protections consistent with this Addendum. A current subprocessor list is available from privacy@looktwice.dev, and material changes will be communicated where required.
International transfers
Where personal data is transferred across borders and a transfer mechanism is legally required, the parties will use the applicable standard contractual clauses or another valid safeguard. Supplementary measures will be applied where appropriate to the risk.
Data-subject requests
Taking into account the nature of processing, LookTwice will reasonably assist the customer with verified requests to access, correct, delete, restrict, or export personal data. If a request concerns data controlled by the customer, LookTwice may direct the requester to the customer.
Incidents and compliance assistance
LookTwice will notify affected customers without undue delay after confirming a personal-data breach involving customer data and will provide information reasonably available for required notifications. We will reasonably assist with risk assessments, audits, and regulator inquiries, subject to confidentiality and proportional cost controls.
Deletion and return
On verified request or termination, LookTwice will delete customer data from active systems according to documented retention periods unless law requires retention. Residual backup copies remain protected and expire through normal rotation. Customers should export required records before deleting an account or watch.