Data Processing Agreement

Last updated: 13 July 2026.

EU-hostedGDPRNo third-party AINever used for trainingNo accountDeleted within 7 days

This page summarises how Loupe processes the websites you submit for audit, for business and enterprise customers who need data-processing terms on file. A countersigned DPA is available on request at [email protected].

Roles

For the URLs you submit and the pages we fetch, you (the customer) are the data controller and Loupe — operated by Docutati (Netherlands, KvK 42095190, BTW-id NL005492040B03) — is the data processor. It processes them only to produce the audit you request.

Where processing happens

All processing runs on private infrastructure that Loupe owns and operates in the EU, including the model that writes the recommendations. Fetched page content is never sent to any third-party AI provider, and is never transferred outside the EU. Because there is no transfer to a third country, Standard Contractual Clauses are not required.

Sub-processors

The fetched page content has no AI sub-processor — it is processed only on Loupe's own EU hardware. Stripe processes payment data only (never the pages you audit) as an independent processor, and an email provider delivers your result link (your email address only).

Retention & deletion

Submitted URLs and generated reports are automatically and permanently deleted within 7 days. Only minimal order records (e.g. payment reference, email) are kept as required for accounting and legal obligations.

Security

Pages are fetched and parsed by an isolated worker restricted to outbound public-web access — it cannot reach our internal network, and every target is validated first so it cannot be pointed at private or internal addresses. Traffic is encrypted in transit, and only minimal technical logs (retained up to 90 days) are kept to secure the service and prevent abuse. No profiling and no cross-site tracking.

No training, no profiling

The pages you submit are never used to train any model, and there is no account or user profile — nothing to aggregate, sell or leak.

Assisting your GDPR obligations

Because reports are deleted within 7 days and never leave the EU, most data-subject requests are satisfied by design. Loupe will assist with access, correction or deletion requests at [email protected].

← Back · Privacy · Terms · DPA

Audit my website →