← Back to home

Terms of Service

Last updated: 14 September 2026

These terms ("Agreement") between you and Loya Ltd. ("Company", "Us", "We") govern your use of our websites and services (collectively, our "Services"). By using our Services, you ("Customer") agree to these terms and our Policies, including our Privacy Notice. Company and Customer are each a "Party" and together the "Parties".

Please make sure to read the Applicable Law and Limitation of Liability sections below, which explain how any disputes will be resolved via arbitration and the extent of our liability to you.

The Agreement comes into effect from the moment Customer uses Company's Services ("Effective Date").

If you are using the Services on behalf of a business or organization, you represent that you have authority to bind that entity to the Agreement.

1. Definitions

1.1 "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where "control" means ownership of more than 50% of voting interests.

1.2 "Authorized User" means an individual (for example an employee, contractor, or other person under Customer's control) who is authorized by Customer to use the Services and who has been supplied user credentials by Customer or Company at Customer's request.

1.3 "Customer Data" means any data, content, or materials (including personal data) that Customer or its Authorized Users submit to or generate within the Services, but excluding Usage Data and Company Materials.

1.4 "Documentation" means the then-current technical and functional documentation for the Services made available by Company (for example online help or API documentation).

1.5 "Order" means an order to obtain services from Company, either in an order form, statement of work or email confirmation message that references these terms and conditions and sets out the Services, subscription terms, quantities, and pricing.

1.6a "Applicable Data Protection Law" means all applicable federal, state, territorial, and local laws, rules, directives, regulations, and governmental requirements currently in effect, or as they become effective, relating in any way to the privacy, confidentiality, or security of Personal Data, including, to the extent relevant, the European Union's General Data Protection Regulation 2016/679 (GDPR), the United Kingdom's Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection of 2020, the Personal Data Protection Act 2012 (Singapore), Japan's Act on the Protection of Personal Information, Brazil's General Data Protection Law, the KSA PDPL, and any laws implementing, replacing or supplementing any of them, as amended, consolidated, re‑enacted, or replaced from time to time.

1.6b "Personal Data" has the meaning prescribed to it by the Applicable Data Protection Law.

1.7 "Third-Party Services" means any third-party applications, products, services, or integrations that interoperate with the Services and are not supplied by Company.

1.8 "Usage Data" means data relating to the use and performance of the Services, including logs, metrics, and analytics, in de-identified form.

1.9 "Company Materials" means the Services, Documentation, underlying software, know-how, designs, and any other technology, materials, or data (excluding Customer Data) provided by or on behalf of Company.

1.10 "Software" means the object code form of the software products that form part of the Services if such are identified in the applicable Order, including any updates that Company makes available to Customer under this Agreement, but excluding Third-Party Software and Open Source Software.

1.11 "Intellectual Property Rights" means all patents, utility models, rights to inventions, copyrights, database rights, trade marks, service marks, trade names, domain names, trade secrets, know-how, and all other intellectual property rights, whether registered or unregistered, and all applications, renewals and extensions of such rights.

2. Services

2.1 Description of Services. The Services are an online platform called "MagicTerms" that lets Customers generate, customize, and export website and app legal documents (including terms and conditions, privacy notices, cookie policies and related legal content) by answering questionnaires and using automated templates and tools.

2.2 Access Model. The Services are provided on a subscription and/or pay‑per‑use basis, as described on our website or in an applicable Order. Features, limits, and pricing for each plan are described in the applicable Order or on our website.

2.3 Accounts. If you create an account, you must provide accurate and complete information and keep your login credentials private. You are responsible for all activities conducted through your account.

2.4 No Legal Advice. We are not a law firm and do not provide legal advice, legal representation, or a lawyer–client relationship. The documents and information our Services produce are general templates and tools only. They may not be suitable or complete for your specific situation. You are solely responsible for reviewing any documents generated through the Services, obtaining independent legal advice where needed, and ensuring that your use of such documents complies with all applicable laws and regulations in your jurisdiction.

2.5 Law Firm Collaboration. If a specific legal review is purchased in addition to the use of software tools, this constitutes a relationship between you and the respective legal practitioner. Our Services in this context are solely the provision of a platform to connect you to legal practitioners and help you administer the relationship with them.

2.6 Service Changes. We may modify, improve, or discontinue features of the Services from time to time, provided that we do not materially reduce the core functionality of any paid plan during the applicable subscription term without offering you a right not to renew.

3. Use of Services

3.1 Authorized Use. Subject to Customer's compliance with this Agreement and relevant Orders, Company grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Services during the Subscription Term, solely for Customer's internal business purposes and in accordance with the Documentation. Customer must ensure that all user credentials are kept confidential and not shared between individuals.

Except as expressly permitted by this Agreement, Customer must not use the Services to:

  • copy, modify, distribute, sell, or lease any part of the software, designs, trademarks, logos, algorithms, tools, user-generated or uploaded content unless we expressly authorize it;
  • reverse engineer, decompile, disassemble, or otherwise attempt to derive any source code of the Services, except to the extent such restriction is prohibited by Applicable Law;
  • sell, resell, rent, lease, or provide access to the Services to any third party;
  • interfere with or disrupt the integrity or performance of the Services or circumvent any usage or technical limits;
  • remove or obscure any proprietary or other notices contained in the Services or Documentation;
  • access or use the Services to build or support products or services that compete with Company; or
  • interfere with or disrupt the integrity or performance of the Services or circumvent any usage or technical limits.

3.2 Restrictions. Customer must not, and must ensure Authorized Users do not, use the Services to:

  • store, transmit, or process any content that is unlawful, harmful, defamatory, infringing, or otherwise objectionable;
  • send spam or unsolicited communications, or violate applicable marketing or anti‑spam laws (for example CAN-SPAM);
  • introduce malware, viruses, or other harmful code;
  • attempt unauthorized access to any systems, networks, or data;
  • violate the rights of any third party (including privacy and intellectual property rights); or
  • violate any applicable laws or regulations.

3.3 Acceptable Use Policy. Company's Acceptable Use Policy (if any) is incorporated by reference and may be updated from time to time. If there is a conflict between this Agreement and the Acceptable Use Policy, this Agreement governs.

3.4 Change Orders. Any material change to the scope of any professional services must be agreed in writing in a change Order.

3.5 Support. Company's technical support services are limited to Company's then-current support policy or as otherwise agreed in an Order.

3.6 Affiliate Use. Customer may permit its Affiliates to use the Services under this Agreement, provided that: (i) such Affiliates are identified in the applicable Order or notified in writing to Company; (ii) Customer ensures that all Affiliates comply with this Agreement; and (iii) Customer remains fully responsible for all acts and omissions of its Affiliates.

4. Customer Responsibilities

4.1 Customer Systems. Customer is responsible for obtaining and maintaining any hardware, software, network connectivity, and other infrastructure required to access and use the Services.

4.2 Cooperation. Customer must provide all cooperation and information reasonably required by Company to deliver the Services (including any necessary access to Customer systems or third‑party systems).

4.3 Compliance with Laws. Customer is solely responsible for its compliance with applicable laws in its use of the Services, including (without limitation) data protection, consumer protection, employment, financial, export control, and telecommunications laws.

5. Fees and Payment

5.1 Fees. Customer must pay all fees specified in the respective Order ("Fees"). Except where expressly stated, all payment obligations are non‑cancelable and Fees are non‑refundable.

5.2 Invoicing and Payment Terms. Unless stated otherwise in the Order, Fees are invoiced in advance (for subscriptions) and in arrears (for usage‑based or professional services) and are due within 30 days from the invoice date.

5.3 Late Payments. Company may charge interest on overdue amounts at the lesser of 1.5% per month or the maximum rate permitted by law, plus reasonable costs of collection.

5.4 Taxes. Fees are exclusive of all taxes, levies, duties, or similar governmental assessments ("Taxes"). Customer is responsible for all Taxes associated with its purchases under this Agreement, excluding Company's income taxes.

5.5 Fee Adjustments. Company may increase Fees for any renewal Subscription Term by providing Customer with at least 30 days' prior written notice. If Customer does not agree to the increase, Customer may elect not to renew.

5.6 Suspension for Non‑Payment. Company may suspend Services for any undisputed overdue Fees that remain unpaid 30 days after written notice.

6. Term and Termination

6.1 Term. This Agreement starts on the Effective Date and continues until all subscription terms under all Orders have expired or been terminated.

6.2 Subscription Term. Each subscription term is as stated in the relevant Order. Unless otherwise stated, each subscription term automatically renews for successive periods equal to the initial subscription term (or 12 months, whichever is shorter) unless either Party gives the other at least 30 days' written notice of non‑renewal before the end of the then‑current term.

6.3 Termination for Cause. Either Party may terminate this Agreement (and all Orders) for material breach by the other Party if such breach remains uncured 30 days after written notice describing the breach.

6.4 Termination for Insolvency. Either Party may terminate this Agreement immediately upon written notice if the other Party (i) becomes insolvent; (ii) enters into bankruptcy; or (iii) ceases to operate in the ordinary course of business.

6.5 Effect of Termination. Upon expiry or termination of this Agreement or an applicable subscription term:

  • all rights granted under such subscription term end immediately;
  • Customer must stop all access to and use of the Services; and
  • each Party must return or delete the other Party's Confidential Information, subject to Sections 7 and 8 regarding retention where required.

6.6 Data Export and Deletion. For 30 days following expiry or termination of the applicable subscription term, Company will make Customer Data available for export in a commercially reasonable format. After such period, Company may delete or anonymize Customer Data, except to the extent retention is required by law or for Company's legitimate business purposes (for example backup, audit, or dispute resolution), subject to data protection commitments.

6.7 Suspension. Company may suspend Customer's access to the Services if (i) Customer's account is overdue by more than 30 days; (ii) Customer's use of the Services poses a security risk; or (iii) Company reasonably believes Customer's use is in violation of this Agreement or applicable law. Company will use reasonable efforts to limit any suspension in scope and duration.

7. Confidentiality

7.1 Definition. "Confidential Information" means any information disclosed by a Party ("Disclosing Party") to the other Party ("Receiving Party") that is marked as confidential or that should reasonably be understood to be confidential given the nature of the information and circumstances of disclosure, including business, technical, financial, and product information, Customer Data, Company Materials, and the terms of this Agreement.

7.2 Obligations. The Receiving Party must:

  • use Confidential Information only to exercise its rights and perform its obligations under this Agreement;
  • protect Confidential Information with at least the same degree of care it uses to protect its own confidential information of similar importance, and no less than reasonable care; and
  • not disclose Confidential Information to any third party, except to its employees, contractors, or advisors who have a strict "need to know" and are bound by confidentiality obligations no less protective than those in this Agreement.

7.3 Exclusions. Confidential Information does not include information that:

  • is or becomes publicly available through no fault of the Receiving Party;
  • is lawfully known to the Receiving Party without restriction before disclosure;
  • is lawfully disclosed to the Receiving Party by a third party without restriction; or
  • is independently developed by the Receiving Party without use of or reference to the Disclosing Party's Confidential Information.

7.4 Compelled Disclosure. The Receiving Party may disclose Confidential Information to the extent required by law or court order, provided it (where legally permitted) gives reasonable prior notice to the Disclosing Party and cooperates, at the Disclosing Party's expense, in any effort to limit or oppose the disclosure.

7.5 Injunctive Relief. The Parties acknowledge that unauthorized disclosure of Confidential Information may cause irreparable harm; the Disclosing Party is therefore entitled to seek injunctive relief (in addition to other remedies) for any breach of this Section.

8. Data Protection and Security

To the extent Company processes Personal Data on behalf of Customer, the data processing addendum ("DPA") attached as Schedule B is incorporated into this Agreement by reference and sets out the Parties' obligations with respect to Personal Data.

9. Intellectual Property

9.1 Ownership. Company and its licensors retain all right, title, and interest (including all Intellectual Property Rights) in and to the Services, Company Materials, Usage Data, and all improvements, modifications, and derivative works of them. Customer acquires no rights to the Software other than the rights expressly granted in this Agreement.

9.2 Customer Data. As between the Parties, Customer retains all right, title, and interest in and to Customer Data.

9.3 License to Customer Data. Customer grants Company a worldwide, non‑exclusive, royalty‑free license to host, copy, use, process, transmit, and display Customer Data as reasonably necessary to provide and improve the Services and perform Company's obligations under this Agreement.

9.4 Usage Data and Aggregated Data. Company may collect and use Usage Data and other de‑identified or aggregated data related to the performance and usage of the Services for analytics, reporting, benchmarking, and product improvement, provided such data does not identify Authorized Users or individual data subjects.

9.5 Feedback. If Customer provides suggestions, comments, or other feedback ("Feedback") relating to the Services, Company may use such Feedback without restriction and without obligation to Customer. Feedback does not obligate Company to implement any feature or enhancement.

11. Warranties, Disclaimers and Liability

11.1 Warranty. Company warrants that:

  • SaaS Warranty. During the applicable subscription term, the Services will perform in all material respects in accordance with the Documentation; and
  • Professional Services Warranty. Any professional services will be performed in a professional and workmanlike manner by appropriately skilled personnel.

11.2 Remedies. If Customer notifies Company of a breach of the warranties in Section 11.1, Company's sole obligation and Customer's exclusive remedy is for Company to use commercially reasonable efforts to correct the non‑conformity, or, if Company is unable to do so within a reasonable time, Customer may terminate the affected Services and receive a pro‑rated refund of any prepaid Fees for the remainder of the subscription term.

11.3 Disclaimers. Except as expressly provided in this Agreement:

  • the Services, Software and any professional services are provided "as is" and "as available";
  • Company and its licensors disclaim all other warranties of any kind, whether express, implied, statutory, or otherwise, including any implied warranties of merchantability, fitness for a particular purpose, title, and non‑infringement, and any warranties arising from course of dealing or usage of trade; and
  • Company does not warrant that the Services will be error‑free or uninterrupted or that they will meet Customer's requirements.

11.4 Beta and Free Services. From time to time, Company may make free, trial, or beta features available ("Beta/Free Services"). Beta/Free Services are provided "as is", without warranty or service‑level agreement, may be modified or discontinued at any time, and are excluded from any uptime or support commitments. Company has no liability arising from or in connection with Beta/Free Services.

11.5 Limitation of Liability. To the maximum extent permitted by law, each Party's total aggregate liability arising out of or related to this Agreement (whether in contract, tort, or otherwise) will not exceed the total Fees paid or payable by Customer under this Agreement in the 12‑month period immediately before the event giving rise to the claim.

11.6 Exclusion of Damages. To the maximum extent permitted by law, neither Party is liable for any:

  • indirect, incidental, special, consequential, or punitive damages; or
  • loss of profits, revenue, goodwill, or anticipated savings,

even if advised of the possibility of such damages.

11.7 Carve‑outs. The limitations in this Section 11 do not apply to: (a) Customer's obligation to pay Fees; (b) a Party's indemnification obligations under Section 12; (c) Customer's violation of Company's intellectual property rights; or (d) breaches of confidentiality obligations.

11.8 Risk Allocation. The Parties agree that the limitations and exclusions in this Section 11 are fundamental elements of the basis of the bargain and would not have entered into this Agreement without them.

12. Indemnities

12.1 Customer Indemnity. Customer will defend Company from any third‑party claim arising from:

  • Customer Data or Customer's use of the Services in violation of this Agreement or applicable law;
  • Customer's use of Third‑Party Services; or
  • any allegation that Customer's products or services (other than the Services) infringe or misappropriate any intellectual property or other rights,

and will indemnify Company against any damages and costs finally awarded by a court or agreed in settlement that are attributable to such claim, subject to Company complying with the standard notice and cooperation obligations normally required for indemnities.

12.2 Exclusive Remedy. This Section 12 sets out each Party's entire liability and exclusive remedy with respect to intellectual property infringement claims regarding the Services.

13. Compliance, Export, and Anti‑Corruption

13.1 Sanctions Compliance. To use the Services, Customer and its Authorized Users must not be located in or a resident of: Cuba, Iran, Syria, North Korea, Russia, Venezuela, the Crimea, Donetsk, Kherson, Zaporizhzhia, or Luhansk regions of Ukraine; and must not be on any list of prohibited or restricted persons, such as those maintained by OFAC, BIS, the European Consolidated Sanctions List or EU Sanctions Map.

13.2 Export Control. Customer must not export, re‑export, or use the Services in any jurisdiction in violation of applicable export control or sanctions laws. Customer represents that neither it nor its Authorized Users are listed on any government denied‑party or sanctions list.

13.3 Anti‑Corruption. Each Party must comply with all applicable anti‑corruption laws, including the UK Bribery Act and the U.S. Foreign Corrupt Practices Act. Neither Party may offer, promise, or provide any improper financial or other advantage in connection with this Agreement.

13.4 Regulated Data. Absent express written authorization, Customer must not use the Services to process: (a) health information subject to HIPAA; (b) payment card data subject to PCI DSS; (c) special categories of personal data; or (d) any other regulated data requiring specific controls.

15. Publicity; References

Company may identify Customer as a customer of the Services and use Customer's name and logo in Company's marketing materials, website, and investor presentations, subject to Customer's reasonable brand guidelines. Any other public statements about the relationship require mutual written consent. Customer may opt out from being used as a reference by sending written notice to Company.

16. Dispute Resolution and Arbitration

16.1 Governing Law. This Agreement and any dispute or claim (including non‑contractual disputes or claims) arising out of or in connection with it or its subject matter or formation is governed by and construed in accordance with the laws of England and Wales, excluding its conflict‑of‑laws rules.

16.2 Agreement to Arbitrate. Any dispute, controversy, or claim arising out of or in connection with this Agreement, including any question regarding its existence, validity, interpretation, performance, breach, or termination, is finally resolved by arbitration subject to the terms set out in Schedule A (Arbitration Agreement).

17. Miscellaneous

17.1 Independent Contractors. The Parties are independent contractors. Nothing in this Agreement is to be construed as creating a partnership, joint venture, or agency relationship.

17.2 Assignment. Neither Party may assign or transfer this Agreement without the other Party's prior written consent, except that either Party may assign this Agreement to an Affiliate or in connection with a merger, acquisition, or sale of substantially all of its assets, provided that the assignee is not a direct competitor of the non‑assigning Party. Any unauthorized assignment is void.

17.3 Force Majeure. Neither Party is liable for any delay or failure to perform its obligations (except payment obligations) due to events beyond its reasonable control, including acts of God, natural disasters, armed conflict, terrorism, riots, labor disputes, contamination, collapse of buildings, fires or explosions, epidemics or pandemics, failures of utilities or telecommunications, or applicable governmental actions such as orders or tariffs.

17.4 Entire Agreement. This Agreement, together with the DPA, Orders, and any additional policies or schedules expressly incorporated in it, constitutes the entire agreement between the Parties relating to its subject matter and supersedes all prior or contemporaneous agreements, proposals, and communications, written or oral.

17.5 Amendments. Any amendment or modification to this Agreement must be in writing and signed by both Parties, except that Company may update its online policies (for example acceptable use policy, service levels, DPA references) from time to time, provided that such updates do not materially reduce Customer's rights under this Agreement. Company may revise this Agreement for online, self‑serve customers by posting an updated version on its website and notifying Customer. For existing subscription terms, material changes become effective on the next renewal, unless otherwise agreed in writing.

17.6 Severability. If any provision of this Agreement is held invalid or unenforceable, the remaining provisions remain in full force and effect.

17.7 No Waiver. The failure of either Party to enforce any provision is not a waiver of future enforcement of that or any other provision.

17.8 Notices. All notices under this Agreement must be in writing and are deemed given when: (a) delivered personally; (b) sent by reputable overnight courier; (c) sent by registered or certified mail, postage prepaid; or (d) sent by email with confirmation of receipt, to the addresses stated in the applicable Order or any updated address notified in writing.

Schedule A – Arbitration Agreement

1. Agreement to Arbitrate

Any dispute, controversy, or claim arising out of or in connection with this Agreement, including any question regarding its existence, validity, interpretation, performance, breach, or termination as well as any non‑contractual obligations arising out of or in connection with it (a "Dispute"), is finally resolved by arbitration administered by the London Court of International Arbitration (LCIA) under this Schedule.

2. Governing Law

This Arbitration Agreement is governed by and construed in accordance with the laws of England and Wales.

3. Rules and Seat

The arbitration is conducted in accordance with the LCIA Rules in force at the time the arbitration is commenced (the "Rules"), which are deemed incorporated by reference into this clause, except as modified here. The seat (legal place) of arbitration is London, England.

4. Tribunal

The arbitral tribunal consists of one arbitrator, appointed in accordance with the Rules. However, if the amount in dispute (excluding interest and costs) exceeds £1,000,000 at the time the Notice of Arbitration is submitted, the tribunal consists of three arbitrators.

5. Language

The language of the arbitration is English. All submissions, documents, and hearings are in English. Any witness whose native language is not English may testify with the assistance of an interpreter at that Party's cost, unless the tribunal orders otherwise.

6. Confidentiality

The Parties agree that the existence of the arbitration, the arbitration proceedings, and all related materials and information, including any settlement negotiations, are kept strictly confidential and are not disclosed beyond the tribunal, the LCIA, the Parties, their respective legal and other professional advisers, and any person necessary for the conduct of the arbitration, except: (a) to the extent required by applicable law or regulatory authority; or (b) to enforce or challenge an arbitral award.

7. Interim and Conservatory Measures

Nothing in this Agreement prevents either Party from applying to any court of competent jurisdiction for interim or conservatory measures (including injunctive or equitable relief) in support of the arbitration, and any such application is not incompatible with this agreement to arbitrate or a waiver of this agreement to arbitrate.

8. Small Claims and Uncontested Collections

Either Party may bring an action for the collection of Fees or other uncontested liquidated amounts due and payable under this Agreement in any court of competent jurisdiction, and such actions are not subject to arbitration under this clause.

9. Costs

The arbitral tribunal has the power to allocate the costs of the arbitration, including the fees and expenses of the arbitrators and the Parties' reasonable legal fees and expenses, in such manner as it deems appropriate, taking into account the relative success of the Parties and other relevant circumstances.

10. Final and Binding Award

The decision in a Dispute and the award of the arbitral tribunal are final and binding upon the Parties and may be enforced in any court of competent jurisdiction. Judgment upon the award may be entered in any such court.

Schedule B – Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") forms part of the Agreement between Company and Customer (also referred to as "Controller") if and insofar as Personal Data is processed.

1. Subject of the DPA

In the course of fulfilling the Agreement, Company (the "Processor") may process Personal Data on behalf of Customer. This DPA specifies the data protection obligations and rights of the Parties in connection with the Processor's use of Personal Data to provide the Services.

2. Scope of the Processing

2.1 The Processor processes Personal Data on behalf of and in accordance with the documented instructions of the Customer. The Customer remains the data controller.

2.2 The processing of Personal Data by the Processor occurs in the manner, scope, and for the purposes determined in Annex 1 to this DPA; the processing relates to the types of personal data and categories of data subjects specified there. The duration of processing corresponds to the term of the Agreement.

2.3 The Processor may anonymize or aggregate Personal Data so that it is no longer possible to identify individual data subjects and may use such data for purposes such as product improvement, machine learning, optimization, and provision of the Services. The Parties agree that such anonymized or aggregated data is not Personal Data for the purposes of this DPA.

2.4 The Processor may process and use Personal Data for the Processor's own purposes as an independent controller to the extent legally permitted by data protection law. This DPA does not apply to such processing.

2.5 The processing of Personal Data by the Processor generally takes place in the locations defined by the respective Order. The Processor may process Personal Data in other locations in accordance with this DPA if it informs the Customer in advance about the place of data processing and the transfer complies with Applicable Data Protection Law.

3. Right of the Customer to Issue Instructions

3.1 The Processor processes Personal Data in accordance with the instructions of the Customer, unless the Processor is legally required to do otherwise. In that case, the Processor will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

3.2 The Customer's instructions are generally documented in this DPA. Individual instructions that deviate from this DPA or impose additional requirements require the Processor's consent.

3.3 If the Processor believes that an instruction given by the Customer infringes this DPA or applicable data protection law, the Processor, after informing the Customer, may suspend execution of the instruction until the Customer confirms or changes the instruction. The Parties agree that the Customer is solely responsible for processing Personal Data in accordance with its instructions.

4. Legal Responsibility of the Customer

4.1 The Customer is solely responsible for the permissibility of the processing of Personal Data and for safeguarding data subjects' rights in the relationship between the Parties. If third parties assert claims against the Processor based on processing Personal Data in accordance with this DPA, the Customer must indemnify the Processor from all such claims upon first request.

4.2 The Customer is responsible for providing the Processor with Personal Data in time for the rendering of services and for the quality of the Personal Data. The Customer must inform the Processor immediately and completely if, during review of Processor's results, the Customer finds errors or irregularities regarding data protection provisions or Customer's instructions.

4.3 Upon request, the Customer must provide the Processor with the information specified in Article 30(2) GDPR, insofar as it is not already available to the Processor.

4.4 If the Processor is required to provide information to a governmental body or person on the processing of Personal Data or to cooperate with these bodies, the Customer must support the Processor upon first request in providing such information and fulfilling such cooperation obligations.

5. Requirements for Personnel and Systems

The Processor must commit all persons engaged in processing Personal Data to confidentiality with respect to the processing of Personal Data.

6. Security of Processing

6.1 The Processor takes appropriate technical and organizational measures, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to data subjects' rights and freedoms, in order to ensure a level of security appropriate to the risk. The measures are listed in Annex 2.

6.2 The Processor may modify the technical and organizational measures during the term of this DPA, as long as the level of protection is not reduced and the measures continue to comply with statutory requirements.

7. Engagement of Further Processors (Sub‑processors)

7.1 The Customer grants the Processor a general authorization to engage further processors regarding the processing of Personal Data. No separate authorization is required for service providers that examine or maintain data processing systems or provide related services, even if access to Personal Data cannot be excluded, provided the Processor takes reasonable steps to protect the confidentiality of the Personal Data. To receive notifications about adding or replacing sub‑processors, Customer may subscribe to a mailing list by messaging Company at hello@loya.tech. Sub‑processor notifications will occur no later than 14 days before any changes, to allow Customer to object. An objection may only be raised for important, substantiated reasons. If Customer does not object within 14 days after receipt of the notification, the right to object to that engagement lapses. If the Customer objects, the Processor may terminate the Agreement and this DPA with three months' notice.

7.2 The agreement between the Processor and any sub‑processor must impose the same data protection obligations as those in this DPA. This requirement is satisfied if the sub‑processor's contract provides a level of protection corresponding to this DPA.

8. Data Subjects' Rights

8.1 The Processor will support the Customer, within reason and by appropriate technical and organizational measures, in fulfilling Customer's obligation to respond to data subjects' requests to exercise their rights.

8.2 If a data subject submits a request directly to the Processor, the Processor will forward this request to the Customer without undue delay.

8.3 The Processor will inform the Customer of information relating to the stored Personal Data and recipients of Personal Data where the Processor discloses it in accordance with Customer's instructions, to the extent the Customer does not already have this information and cannot obtain it itself.

8.4 The Processor will, within reasonable limits, enable the Customer to correct, delete, or restrict processing of Personal Data, or, at Customer's instruction, correct, block, or restrict processing itself, if the Customer cannot do so alone. The Processor is entitled to reimbursement of reasonable costs incurred for such assistance.

8.5 Where data subjects have a right to data portability, the Processor will support the Customer, within reasonable limits, in handing over Personal Data in a structured, commonly used, and machine‑readable format if the Customer cannot obtain such data elsewhere. The Processor is entitled to reimbursement of reasonable costs incurred.

9. Notification and Support Obligations of the Processor

9.1 If Customer is subject to a statutory notification obligation due to a breach of security regarding Personal Data, the Processor will inform the Customer without undue delay of any reportable events in the Processor's area of responsibility and will assist the Customer, to a reasonable extent, in fulfilling any notification obligations. The Processor is entitled to reimbursement of reasonable costs incurred.

9.2 The Processor will reasonably assist the Customer with any required data protection impact assessments and, if necessary, subsequent consultations with supervisory authorities. The Processor is entitled to reimbursement of reasonable costs incurred.

10. Deletion and Return of Personal Data

Upon termination of this DPA, the Processor will, at Customer's choice: (a) delete or return Personal Data; and (b) delete existing copies, unless the Processor is required by law to store the Personal Data further. The Processor may retain documentation needed as evidence of proper processing of Personal Data, even after termination.

11. Evidence and Audits

11.1 The Processor will provide the Customer, on request, with all information reasonably required to demonstrate compliance with this DPA.

11.2 The Customer is entitled to audit (including on‑site inspections) the Processor with regard to compliance with this DPA, especially implementation of technical and organizational measures, subject to reasonable notice and limits.

11.3 Audits must be conducted during normal business hours, without disrupting business operations, and under strict confidentiality regarding the Processor's business secrets and trade secrets. The Customer may not conduct more than one audit per year, unless legally required.

11.4 The Processor may, at its discretion, withhold information that is particularly sensitive or whose disclosure would breach statutory or contractual duties. The Customer is not entitled to access data or information about other customers, cost information, quality control or contract management reports, or other confidential data not directly relevant to the audit.

11.5 If the Customer appoints a third party to carry out the audit, the Customer must bind that third party to the same obligations of confidentiality and data protection as set out in this DPA and may not appoint a competitor of the Processor.

11.6 At the Processor's discretion, proof of compliance may be provided instead of an on‑site inspection by presenting up‑to‑date audit reports, certifications, or similar evidence from independent bodies, if such documentation reasonably demonstrates the Processor's compliance with this DPA.

12. Contract Term and Termination

The term and termination of this DPA are governed by the term and termination provisions of the Agreement. Termination of the Agreement automatically ends this DPA. Separate termination of this DPA alone is not permitted.

13. Liability

13.1 The Processor's liability under this DPA is governed by the disclaimers and limitations of liability in the Agreement, to the extent permitted by law. If third parties assert claims against the Processor caused by the Customer's culpable breach of this DPA or of its obligations as controller under data protection law, the Customer must indemnify the Processor upon first request.

13.2 The Customer must indemnify the Processor upon first request against all fines imposed on the Processor to the extent such fines result from the Customer's responsibility for the underlying infringement.

14. Final Provisions

14.1 If any provision of this DPA is or becomes invalid or incomplete, the remaining provisions remain unaffected. The Parties undertake to replace any invalid provision by a valid one that comes closest to its commercial purpose and satisfies the requirements of Article 28 GDPR.

14.2 In case of conflicts between this DPA and other arrangements of the Parties, in particular the Agreement, the provisions of this DPA prevail unless a different hierarchy is expressly agreed.

Annex 1 – Further Information on the Processing of Customer Data

a) Parties: Customer as Controller and Company as Processor.

b) Purpose and extent of processing: Providing and improving the Services as described in Section 2 of the Agreement.

c) Types of personal data: contact data, account data, usage metadata, and Customer end‑user data contained in Customer Data.

d) Categories of data subjects: Customer employees and other Authorized Users, and Customer end users whose data Customer includes in Customer Data.

Annex 2 – Technical and Organizational Measures

The Processor uses, among others, the following measures:

  • Encryption of data in transit and at rest.
  • Access control to prevent unauthorized access to systems and data, with access rights limited on a need‑to‑know basis and subject to regular review.
  • Confidentiality obligations and training for personnel handling Personal Data.
  • Regular backups to prevent loss of data and ensure integrity.
  • Internal policies governing secure handling of Personal Data.
  • Careful selection and contractual control of sub‑processors and service providers, including appropriate data protection terms and security certifications.