netloop.ai

Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

Version: September 27, 2026

between

Data Controller („Customer") — the controller within the meaning of Art. 4(7) GDPR

and

Processor — Tobias Heer, Friedrichshafener Str. 5, 70329 Stuttgart, Germany (netloop.ai), E-Mail: legal@netloop.ai

1. Subject matter and duration

  1. The subject matter is the processing of personal data by the Processor in the context of the netloop.ai service (CLI-based management of network switches with AI-assisted querying), including all associated contractual and pre-contractual relationships.
  2. The duration corresponds to the term of the underlying service agreement (Terms). Obligations under this agreement, in particular the deletion or return of data and confidentiality, continue beyond termination.

2. Nature and purpose of processing

  1. Nature of processing: collection, storage, use, transmission, restriction and erasure of personal data in the context of the use of the service.
  2. Purpose: provision of the service, in particular switch administration, AI-assisted querying, troubleshooting, support, security and operation of the platform.
  3. Categories of data and data subjects: see Annex 1. In particular users and administrators of the Customer as well as the Customer's employees (devices appearing in ARP/MAC tables, IP addresses, host names) and contact data.
  4. The Processor processes personal data only on documented instructions of the Customer and not for its own purposes.

3. Instructions of the controller

  1. Instructions are documented and implemented by the Processor without undue delay.
  2. The abstract instructions on processing are set out in this agreement as well as in the Processor's Terms and Privacy Policy.
  3. If the Processor considers an instruction unlawful, it informs the Customer without undue delay and may suspend the processing in question until the instruction is confirmed or amended.

4. Sub-processors

  1. The current sub-processors are listed in Annex 2.
  2. The Customer grants its general authorisation to engage the sub-processors listed in Annex 2 (Art. 28(2) GDPR).
  3. If the Processor intends to engage, replace or substitute a sub-processor, it informs the Customer in due time. In case of a material impact, the Customer may object.
  4. Each sub-processor is bound to at least the data-protection standards set out in this agreement (Art. 28(4) GDPR). Transfer occurs only on the basis of a data processing agreement.

5. Rights of data subjects (Art. 15–22 GDPR)

  1. The Processor assists the Customer in fulfilling the data subjects' rights of access, rectification, erasure, restriction, data portability and objection, in accordance with Art. 28(3)(e) GDPR.
  2. Requests from data subjects addressed directly to the Processor are forwarded to the Customer without undue delay and without being asked.

6. Technical and organisational measures (Art. 32 GDPR)

  1. The Processor implements technical and organisational measures appropriate to the risk in order to ensure a level of security appropriate to the risk. The implemented categories of measures include in particular:
    • Confidentiality: access concept with role-based permissions; pseudonymisation of personal values (in particular IP and MAC addresses, e-mail addresses, phone numbers, host names) before transfer to AI providers; encryption of data in transit and at rest.
    • Integrity: measures against unauthorised alteration; logging without raw data (hashed values only). Deliberate plaintext exceptions (network devices, no personal data): target IPs of network devices and the SSH device account username (structured, login events only, never the password, opt-out via `log_usernames`).
    • Availability and resilience: redundancy, recovery procedures, limited retention periods with automatic deletion.
    • Processes: regular review and update of measures, support for data protection impact assessments, procedures for handling data protection incidents.
  2. The concrete measures are evidenced upon request within the framework of the audit rights (§ 7). A full detailed technical documentation is not published publicly.

7. Audit obligations and notifications

  1. The Customer may request reasonable evidence of compliance with data protection requirements. Audits are permissible upon prior notice and within a reasonable scope, but no more than once per calendar year unless there is a specific reason. Audits shall be conducted remotely (questionnaire, provision of evidence) where possible. On-site inspections are excluded as no relevant processing takes place at the Processor's premises. The Customer bears any costs exceeding what is reasonable.
  2. The Processor notifies the Customer without undue delay, at the latest within 24 hours of becoming aware, of personal data breaches (Art. 33 GDPR) by email to the contact address provided by the Customer. The notification contains the information required under Art. 33(3)(a)-(d) GDPR (nature of the breach, categories and approximate number of data subjects, likely consequences, measures taken). The Processor assists the Customer in notifying the supervisory authority (within 72 hours) and in informing the affected individuals (Art. 33, 34 GDPR). The Processor's central contact point for incidents is legal@netloop.ai.
  3. Incidents relating exclusively to data processed by the Processor in its own capacity as controller (in particular account data and audit logs) are not subject to this notification entitlement; in that respect the Processor reports independently in accordance with Art. 33, 34 GDPR.

8. Deletion and return

  1. Upon termination, personal data is — unless statutory retention obligations prevail — deleted or returned to the Customer. The retention periods set out in the Privacy Policy apply (standard: 90 days).
  2. On the Customer's express request, the Processor provides evidence of deletion.

9. Liability and miscellaneous

  1. Liability is governed by the Terms.
  2. The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
  3. If any provision of this agreement is or becomes invalid, the validity of the remaining provisions remains unaffected.

Annex 1 — Processing activities (excerpt of Art. 30)

ActivityDataRetention
Switch dataConfigurations, VLANs, interfaces, ARP/MAC/IP caches, host namesRaw data transient; no persistence
Chat/prompt dataQueries and responses in the context of AI querying90 days (automatic deletion)
Audit metadataLog entries (hashed values, no raw content); deliberate plaintext exceptions (network devices, no personal data): target IPs of network devices + SSH device account username (no password)90 days
Connector – Target dataManagement IPs of queried network devices (no personal endpoints)Audit log (server): 90 days, readable
Customer machine: no server persistence
Connector – CredentialsSSH username and password for switch accessPassword customer only: RAM (volatile), config (optionally encrypted)
Never on server, never in audit log.
The username is additionally recorded server-side in the audit log (see Audit metadata), opt-out via log_usernames
Connector – Network data (SSH output)ARP tables, MAC addresses, IP addresses of endpoints, host names, switch configurationsChat history (server): 90 days, plaintext
Before AI transfer: pseudonymisation of IP/MAC/host names/email/phone

Annex 2 — Sub-processors

Sub-processorPurposeLocationContractual basis
Amazon Web Services (AWS)Hosting and infrastructureEU (eu-central-1, Frankfurt)AWS DPA + SCC
Mistral AIAI LLM inferenceEU (France)Mistral DPA