Logo links to homepage
Copy logo as SVG
Download logo
Media kit
ProductWidgetsCustomers
Customers
Pricing
Resources

Learn

Blog IconA notepad icon symbolizing blog posts and articles
Blog

Explore the latest announcements, product updates, and more

Academy IconA graduation cap icon representing educational video tutorials
Academy

Video tutorials, tips, and tricks to get the most from Loox

Help Center Iconicon representing pen and paper for a blog
Help Center

Getting started, how-to-articles, and step-by-step instructions

Case Study IconA document icon symbolizing a case study
Case Studies

See how great brands use Loox

Video player IconA play button icon for video demonstrations
Watch a demo

View a 5-ish minute overview of the Loox platform

Palette IconA palette icon representing ideas and inspiration
Widget Inspiration

See how stores across industries customize their Loox widgets

Store Icon A store front icon for a sample store preview
Demo Store

See Loox widgets in action on our example store

Email IconAn envelope icon representing email design ideas
Email Inspiration

Get some ideas for branding and customizing your Loox emails

Connect

Partners IconAn icon with 2 people symbolizing partnership opportunities
Partners

Learn more about our partnership program

Integrations IconAn icon representing integrations between systems
Integrations & API

Connect Loox with your favorite tools and apps

Reviewers.com

Get high-quality video reviews on demand

Headphones with microphone IconA headphone with a mic icon for contact and support services.
Get in touch

Fast and dedicated 24/7 support

Get started free
Get started

Data Processing Addendum

Last updated:
August 2026

This Data Processing Addendum ("Addendum") adds onto the Loox's terms of service (the "Agreement") between Loox Online Ltd. ("Loox") and merchants who use Loox’s services (the "Merchant").

WHEREAS, Merchant has entered into an Agreement with Loox;

WHEREAS, pursuant to the Agreement, Loox provides Merchant access to use Loox's platform (the “Service”)

WHEREAS, the Service involves processing certain personal data of the Merchant and the clients who interact with Merchant and use Loox Service (“Merchant’s Customers”), and the parties wish to regulate Loox’s processing of such personal data, through this Addendum.

THEREFORE, the parties have agreed to this Addendum, consisting of these parts:

{{dpa-table1="/drafts/cms-tables"}}

‍

In the event of any conflicting provisions between this Addendum and the terms or any other agreement in place between the parties, the provisions of this Addendum shall prevail, except where explicitly agreed otherwise in writing.

‍

Part One (General Provisions)

  1. Interpretation. Capitalized terms used herein but not defined in this Addendum shall have the meaning ascribed to them in applicable privacy laws or in the Agreement.
  2. Scope. This Addendum applies only where Loox is processing Merchant's Customers personal data on behalf of the Merchant and under the Merchant’s instructions that are provided through the Service’s various control and configuration options. It does not apply to Loox’s processing of data for the purpose of separately operating its Service, marketing or promoting its services, or to administer the business or contractual relationship between Loox and the Merchant, as further covered in Loox Privacy Policy (for Merchants and Website Visitors) available here. Merchant and Loox processing shall be always in compliance with Loox Privacy Policy (for Merchant’s Customers) available here.
  3. Order of Precedence. In the event of any conflicting provisions between this Part One and the provisions of Part Two,  Part Three or Part Four, the provisions of Part Two, Part Three or Part Four shall prevail (accordingly).
  4. Processing. Loox is prohibited from retaining, using or disclosing the Merchant's Customers personal data for: (a) any purpose other than providing the Service to Merchant, or for any commercial purpose other than as reasonably necessary to perform Merchant’s processing instructions; (b) selling the Merchant's Customers personal data; and (c) retaining, using or disclosing the Merchant's Customers personal data outside of the direct business relationship between the parties.
  5. Merchant Responsibility. If Merchant imports reviews into the Service from an external source, Merchant represents and warrants that it has obtained and maintains valid, any and all authorizations, permissions and informed consents necessary under applicable laws and regulations, in order to: (a) import those reviews and their accompanying data into Loox, and (b) to allow Loox lawfully collect, handle, retain, process and use the processed data within the scope of the Service. Merchant may use the Service’s certain control and configuration options to assist it in connection with its obligations under the GDPR. In light of the GDPR’s requirement under Articles 13 and 14 to have a privacy notice pursuant to the ‘transparency’ and ‘accountability’ principles of the GDPR, Loox will maintain for the benefit of Data Subjects a dedicated Privacy Notice.
  6. Data Subject Requests. Loox will follow Merchant’s instructions to accommodate data subjects’ requests to exercise their rights in relation to their information within the Merchant's Customers personal data, including accessing their data, correcting it, restricting its processing or deleting it. Loox will pass on to Merchant requests that it receives (if any) from data subjects regarding their information processed by Loox. Loox shall notify Merchant of the receipt of such request as soon as possible, together with the relevant details.
  7. Disclosure. Unless legally prohibited, Loox will provide Merchant with prompt notice of any request it receives from authorities to produce or disclose Merchant's Customers personal data processed on Merchant’s behalf, so that Merchant (or its Customers) may contest or attempt to limit the scope of the production or disclosure request.
  8. Data security. Considering the state of the art, the costs of implementation and the nature, scope, context and purposes of Loox’s processing of Merchant's Customers personal data, Loox shall implement and maintain reasonable security procedures and practices appropriate to the nature of the Merchant's Customers personal data, to protect such personal data from unauthorized access, destruction, use, modification, or disclosure (including data breaches).
  9. Data Breaches. Loox shall without undue delay, notify Merchant of any actual or reasonably suspected accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Merchant's Customers personal data, of which Loox becomes aware. Loox will thoroughly investigate the breach and take all available measures to mitigate the breach and prevent its recurrence. Loox will cooperate in good faith with Merchant on issuing any statements or notices regarding such breaches, to authorities and data subjects.
  10. Subcontracting to suppliers. Merchant authorizes Loox to engage other sub-processors for carrying out specific processing activities, provided that Loox informs Merchant at least 7 days in advance of any new or substitute sub-processor, in which case Merchant shall have the right to object, on reasoned grounds, to that new or substitute sub-processor. If Merchant so objects, Loox may not engage that new or substitute sub-processor for the purpose of Processing Personal Data, and Loox may either select another sub-processor in which case the above procedure shall repeat, or if it so chooses, terminate the Agreement with no liability to Merchant for such premature termination. At the outset, Merchant authorizes Loox to engage with the sub-processors listed in Schedule I below.
    Without limiting the foregoing, in any event where Loox engages another sub-processor, Loox will ensure that the same data protection obligations as set out in this Addendum are likewise imposed on that other sub-processor by way of a contract, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the Data Protection Law. Loox shall remain fully liable to Merchant for the performance of its sub-processors' obligations‍
  11. Data Deletion. Upon the termination of the Agreement or upon Merchant request, Loox will delete the Merchant's Customers personal data that it has processed on Merchant’s behalf under this Addendum from its own and its sub-processor’s systems, or, at Merchant’s choice, return such Merchant's Customers personal data and delete existing copies. Upon Merchant’s request, Loox will furnish written confirmation that the Merchant's Customers personal data has been deleted or returned pursuant to this section.

‍

Part Two (US State Laws)

  1. Definitions
    In this Part Two:
    <rte-indent>a. “Applicable State Privacy Laws” means the CCPA and CPRA, and other applicable state privacy laws in the United States, such as (but not limited to): Virginia Consumer Data Protection Act, Connecticut Act Concerning Personal Data Privacy and Online Monitoring, Utah Consumer Privacy Act, and the Colorado Privacy Act, as relevant.<rte-indent> <rte-indent>b. “Consumer” means a natural person, including a natural person in their professional or work capacity.<rte-indent> <rte-indent>c. “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.<rte-indent> <rte-indent>d. “Collect” (and its cognate terms) means buying, renting, gathering, obtaining, receiving, or accessing any Personal Information pertaining to a Consumer by any means. This includes obtaining information from the Consumer, either actively or passively, or by observing the Consumer’s behavior or interaction.<rte-indent> <rte-indent>e. “Process” (and its cognate terms) means any operation or set of operations that are performed on Personal Information or on sets of personal information, whether or not by automated means.<rte-indent> <rte-indent>f. “Sell” (and its cognate terms) means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's Personal Information for monetary or other valuable consideration.<rte-indent> <rte-indent-last>g. "Share” (and its cognate terms) means sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer's Personal Information for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions for cross-context behavioral advertising in which no money is exchanged.<rte-indent-last>
  2. Loox’s Obligations. The Parties acknowledge and agree that Loox is a ‘service provider’ and ‘processor’ within the meaning of the terms in Applicable State Privacy Laws. To that end, and unless otherwise required by law:
    <rte-indent>a. Loox must not Sell or Share any Personal Information it Collects.<rte-indent> <rte-indent>b. The parties agree that Merchant is disclosing the Personal Information to Loox only for the following limited and specified business purposes: to provide and support the operation of the Service.<rte-indent> <rte-indent>c. Loox is prohibited from retaining, using, or disclosing the Personal Information that it Collects for any commercial purpose other than the foregoing business purposes, unless expressly permitted by Applicable State Privacy Laws and this Part Two. Additionally, Loox is prohibited from retaining, using, or disclosing the Personal Information that it Collects pursuant to this Agreement outside the direct business relationship between Loox and Merchant, unless expressly permitted by Applicable State Privacy Laws and this Part Two.<rte-indent> <rte-indent>d. Loox shall comply with all relevant sections of Applicable State Privacy Laws and shall provide, with respect to Personal Information it Collects, the same level of privacy protection as required by Applicable State Privacy Laws.<rte-indent> <rte-indent>e. Loox grants Merchant the right to take reasonable and appropriate steps to ensure that Loox uses the Personal Information it Collects in a manner consistent with the obligations under this Part Two and Applicable State Privacy Laws.<rte-indent> <rte-indent>f. Loox must promptly notify Merchant if it makes a determination that it can no longer meet its obligations under this Part One or Applicable State Privacy Laws.<rte-indent> <rte-indent>g. Loox grants Merchant the right, upon notice, to take reasonable and appropriate steps to stop and remediate Loox’s unauthorized use of Personal Information.<rte-indent> <rte-indent-last>h. If Loox receives a request from a Consumer about his or her Personal information, Loox shall not comply with the request itself and inform the Consumer that Loox’s basis for denying the request is that the Loox is merely a service provider that follows Merchant’s instructions. Loox shall provide the Consumer with the Merchant’s contact information and instruct the Consumer to submit the request directly to the Merchant.<rte-indent-last>
  3. Assistance in responding to Consumer requests. Loox shall assist Merchant by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Merchant’s obligation to respond to requests for exercising the Consumer rights under Applicable State Privacy Laws.

Part Three (GDPR)

  1. Capitalized terms used in this Part Three but not defined herein or in the Agreement shall have the meaning ascribed to them in the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) applicable as of 25 May 2018 and any national law supplementing the GDPR (collectively referred to in this Part Three as “Data Protection Law”).
  2. Merchant commissions, authorizes and requests that Loox Process Merchant's Customers Personal Data, under the instructions of Merchant as the Data Controller. Loox shall Process such Personal Data as a processor, only on Merchant’s behalf. Loox and Merchant are each responsible for complying with the Data Protection Law as applicable to their roles.
  3. Loox will Process the Personal Data only on instructions from Merchant documented in this Addendum, provided through the Service’s various control and configuration options or otherwise provided in writing, which instructions must be consistent with the nature and characteristics of the Service. The foregoing applies unless Loox is otherwise required by law to which it is subject (and in such a case, Loox shall inform Merchant of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest). Loox shall immediately inform Merchant if, in Loox's opinion, an instruction violates the Data Protection Law.
  4. The nature and purpose of the Processing activities is the provision of the Service to the Merchant. The Personal Data Processed may include the categories described in Schedule I below. The Data Subjects, as defined in the Data Protection Law, are the Merchant's Customers, about whom Personal Data is Processed.
  5. Loox will make available to Merchant as the Data Controller all information at its disposal that is necessary to demonstrate compliance with the obligations under Data Protection Law. Furthermore, Loox shall maintain all records required by Article 30(2) of the GDPR, and make them available to the Merchant upon request.
  6. Loox shall forward to Merchant any request from Data Subjects arising out of the processing of Personal Data by Loox, and Merchant shall be solely liable for responding to Data Subjects on such requests. Notwithstanding the foregoing, where applicable considering the nature of the Personal Data Processed, Loox will follow Merchant’s instructions to accommodate Data Subjects’ requests to exercise their rights in relation to their Personal Data, including accessing their data, correcting it, restricting its processing or deleting it, to the extent reasonable in relation to the Service. If such instructions entail costs or expenses to Loox, the parties shall first come to agreement on Merchant reimbursing Loox for such costs and expenses. Loox will pass on to Merchant requests that it receives from Data Subjects regarding their Personal Data Processed by Loox.
  7. Loox and its sub-processors will only Process the Personal Data in Member States of the European Economic Area, in territories or territorial sectors recognized by an adequacy decision of the European Commission (or as applicable, the UK ICO), as providing an adequate level of protection for Personal Data pursuant to Article 45 of the GDPR or using adequate safeguards as required under Data Protection Law governing cross-border data transfers (e.g., Standard Contractual Clauses).
  8. Loox will ensure that its staff authorized to Process the Personal Data are contractually bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
  9. Within 30 days of Merchant’s written request, Loox shall allow for and contribute to audits, including carrying out inspections conducted by Merchant or another auditor mandated by Merchant in order to establish Loox's compliance with this Addendum and the provisions of the applicable Data Protection Law, with regards to the Personal Data that Loox processes on behalf of Merchant. Such audits or inspections shall be carried out during Loox's ordinary business hours, not more than one business day per year (unless Data Protection Law or a supervisory authority mandate more frequent audits or inspections), shall be conducted with minimal disruption to Loox's business activities, and be subject to confidentiality undertakings satisfactory to Loox.

Part Four (Israel)

  1. Definitions. In this Part, the following terms shall be interpreted as follows:
    <rte-indent>1.1 "Applicable Laws” means Israeli Privacy Protection Law, 5741-1981 (hereinafter – the “Privacy Law”) and the regulations promulgated thereunder (and in particular the Privacy Protection Regulations (Information Security), 5777 - 2017), as well as any legislative or administrative provision or directive that will apply to the Processor in connection with the provision of the Service under the Agreement.<rte-indent>
    <rte-indent>1.2 "Controller” means the Merchant.<rte-indent>
    <rte-indent>1.3 "Database" means a collection of personal data held by physical, magnetic or optical means.<rte-indent>
    <rte-indent>1.4 “Personal Data” means information, data and data sets that relates to Merchant's Customers, and which identifies such them, or which may be reasonably used in order to identify them, regardless of the medium in which such data is being presented, and which the Processor Processes for and on behalf of the Controller within the scope of the Service.<rte-indent>
    <rte-indent>1.5 "Personal Data Breach” means an of actual or reasonably suspected incident: (a) of unauthorized access to or use of Personal Data, or such access or use exceeding authorization, or (b) impacting the integrity of the Personal Data in a manner that is not authorized or exceeds authorization.<rte-indent>
    <rte-indent>1.6 "Processing" (and its derivatives, including, but not limited to "Process") means the collection, access, retention, modification, use, disclosure and transfer of Personal Data.<rte-indent>
    <rte-indent-last>1.7 “Processor” means Loox.<rte-indent-last>
  2. Processor’s obligations regarding the Processing of Personal Data
    <rte-indent>2.1 The Processor shall process the Personal Data for Merchant solely to provide the Service under the Agreement, and only in the manner determined in the Agreement and in this Part 4, and for no other purpose, unless expressly instructed by Merchant to do so.<rte-indent>
    <rte-indent>2.2 Processor undertakes to manage access rights to Personal Data, including by way of providing its users with ‘Least Privileges’ based on their ‘Need to Know’, for the purpose of carrying out their tasks, and shall take measures in order prevent access by unauthorized individuals to Personal Data. In addition, Processor will maintain an up-to-date listing of all individuals authorized to access or use the Database and will use measures designed to prevent access to any individual who does not have a need to be exposed to the Personal Data.<rte-indent>
    <rte-indent>2.3 Processor shall not grant access to the Personal Data to its employees, consultants or anyone else acting on its behalf, before reviewing and confirming, within the boundaries of applicable law, that their background, integrity, and reliability are suitable for a position granting them access to Personal Data.<rte-indent>
    <rte-indent>2.4 Processor shall grant its employees access to the Database, subject to conduct of training activities regarding privacy protection and information security obligations applicable to the Processor by virtue of the Applicable Laws and this Part 4.<rte-indent>
    <rte-indent>2.5 Processor will implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, as set forth in this Part 4.<rte-indent>
    <rte-indent>2.6 Processor shall develop, implement, and enforce an information security policy that covers at least the following topics (“Information Security Policy”):<rte-indent>
    <rte-indent-sub>2.6.1 Guidelines regarding the physical protection of the Database systems and the sites in which they are located;<rte-indent-sub>
    <rte-indent-sub>2.6.2 Guidelines regarding the management and monitoring of access authorizations and actions taken in the Database;<rte-indent-sub>
    <rte-indent-sub>2.6.3 Mapping of all the of the security measures taken by Processor regarding the Database;<rte-indent-sub>
    <rte-indent-sub>2.6.4 Guidelines for individuals authorized to access Personal Data and Database;<rte-indent-sub>
    <rte-indent-sub>2.6.5 A review of the risks to which the Personal Data is exposed to as part of Processor’s ongoing activities including instructions regarding the means of recording, monitoring, and identifying threats to which the Database systems are exposed;<rte-indent-sub>
    <rte-indent-sub>2.6.6 Instructions and procedures regarding the mitigation and management of a Personal Data Breach;<rte-indent-sub>
    <rte-indent-sub>2.6.7 Instructions and procedures regarding the use of removable devices.<rte-indent-sub>
    <rte-indent-last>2.7 Processor shall map the operational environment of the Database. In this regard, Processor shall prepare an inventory list that includes all the systems, software, interfaces, infrastructures of hardware components and communications components that Processor operates in the Database environment for the ongoing operation of the Database (the “Database Systems”). Processor shall update the list of inventories specified in this section from time to time and shall only disclose the document to those individuals who require access to it for the performance of their job functions. However, Processor shall update the foregoing list in any case in which substantial changes to the operating environment are implemented in the Database or in the manner in which Personal Data is Processed.<rte-indent-last>
  3. Disclosure and transfer of Personal Data
    <rte-indent-last>3.1 Processor shall not disclose Personal Data in the scope of Processing Personal Data on behalf of Merchant to any entity, unless Merchant has provided its prior written consent, except as follows:<rte-indent-last>
    <rte-indent-sub>3.1.1 As strictly necessary for the provision of Services;<rte-indent-sub>
    <rte-indent-sub>3.1.2 Where such disclosure is required by Applicable Law or during a legal proceedings, in which case Processor shall notify Merchant in writing immediately upon receipt of the request and before fulfilling the disclosure request, and will cooperate and disclose the minimum Personal Data necessary to comply with Applicable Law or legal proceedings;<rte-indent-sub>
    <rte-indent-sub>3.1.3 When using a subcontractor or service provider to Process Personal Data (each, a "Sub-contractor"), Processor shall provide a prior notice and objection period in accordance with Part 1 and enter into a written, valid, and enforceable agreement with the Sub-Contractor containing adequately protective terms on data security consistent with this Part 4. Processor shall provide Merchant any information reasonably requested by Merchant about the Processor’s use of Sub-contractors, about the Sub-contractors’ Processing activities for the Processor and their data security practices. Processor shall take reasonable measures to monitor Sub-contractor’s compliance with data security obligations.<rte-indent-sub>
    <rte-indent-sub>3.1.4 Processor shall use conventional encryption mechanisms for any transfer of Personal Data to a third party and for any remote connection to the Database Systems.<rte-indent-sub>
  4. Storing, Deletion and Return of Personal Data
    <rte-indent>4.1 Processor undertakes to implement appropriate security measures designed to ensure the integrity of the Personal Data, its availability, confidentiality, and reliability.<rte-indent>
    <rte-indent>4.2 Processor shall maintain logical separation between the Database Systems and the computer systems used by Processor that are not directly related to the Processing or Personal Data for Merchant. In the event the Database Systems is connected to the Internet or to another public network, Processor shall install appropriate means of protection against information security incidents, such as firewalls and anti-virus tools.<rte-indent>
    <rte-indent>4.3 Processor shall retain the Personal Data only as strictly necessary to provide the Service to Merchant, or as mandatory under Applicable Laws.<rte-indent>
    <rte-indent>4.4 Processor shall regularly update the Database Systems, including the software installed in the Database Systems, with information security updates. When operating the Database Systems, Processor will not use software and/or hardware components that the manufacturer does not support in terms of their security aspects.<rte-indent>
    <rte-indent>4.5 Processor will implement measures to prevent the connection of removable devices to the Database Systems or devices Processing Personal Data (to the extent those Database Systems or devices are located in the Processor’s premises or assigned to its employees, consultants, and anyone on its behalf). Notwithstanding the foregoing, portable devices such as laptops and smartphones Processing Personal Data may be used so long as they are encrypted with appropriate, industry-customary encryption.<rte-indent>
    <rte-indent-last>4.6 In accordance with the Agreement and without prejudice to its generality, Processor shall return, delete or destroy all Personal Data to which this Part 4 applies following the termination of the Agreement or upon Merchant request.<rte-indent-last>
  5. Cross-Border Data Transfers
    <rte-indent>5.1 Processor shall comply with the law applicable to the transfer of Personal Data to foreign jurisdictions, including but not limited, to the Protection of Privacy Regulations (Transfer of Information to Databases Outside of Israel), 5761-2001.<rte-indent>
    <rte-indent-last>5.2 In addition, Processor shall not transfer Personal Data to a foreign jurisdiction without 7 days prior advanced notice to Merchant, and Merchant shall be entitled to object to such transfer, on reasonable grounds, within 7 days from receipt of the notice.<rte-indent-last>
  6. Breach of information security
    <rte-indent>6.1 Processor will notify Merchant without undue delay after becoming aware of a Personal Data Breach, and provide Merchant with sufficient information to allow Merchant to meet any obligations to report or inform affected individuals or a supervisory authority of the Personal Data Breach.
    Such notice shall include, at the time of initial notification or without undue delay after the initial notification, details of the nature of the Personal Data Breach, number of records affected, the category and approximate number of affected individuals, anticipated consequences of the Personal Data Breach and any actual or proposed remedies for mitigating the possible adverse effects of the Personal Data Breach.<rte-indent>
    <rte-indent>6.2 In any case of a Personal Data Breach affecting Merchant Personal Data, Processor also will cooperate with Merchant and/or anyone on its behalf to investigate the Personal Data Breach.<rte-indent>
    <rte-indent-last>6.3 In the event of a Personal Data Breach, the parties will discuss the matter and reach an agreement regarding the measures required to repair the Personal Data Breach and the schedule for their implementation.<rte-indent-last>
  7. Audit & Documentation
    <rte-indent>7.1 Processor shall provide Merchant, at least in every 12 month, a written approval according to which it performs and fulfills its obligations pursuant to this Part 4 and the provisions of the Applicable Law.<rte-indent>
    <rte-indent>7.2 Processor shall fully cooperate with Merchant in providing all information and assistance reasonably requested by Merchant in connection with data security issues and practices and supplementary documents, so as to allow Merchant to properly address information security, privacy and regulatory matters relating to the Database.<rte-indent>
    <rte-indent-last>7.3 Processor undertakes to allow the representatives of Merchant and/or any person or entity acting on Merchant’s behalf to carry out, through a 30 days advance notice and once per year (unless legally required otherwise or following a Data Breach) surveys and audits regarding the performance of Processor’s obligations under this Part 4. It is hereby clarified that as a pre-condition for the performance of such surveys and audits, surveyor and auditor on behalf of Merchant shall be required to sign an undertaking in order to maintain confidentiality of Processor’s data to which such surveyor or auditors will be exposed to in the course of the survey or audit.<rte-indent-last>
  8. Term & Termination
    All the clauses in this Part 4 that are bound by and required under, the Applicable Law will continue to apply even after the expiration or termination of the Agreement between the parties, provided that Processor continues to retain Merchant Personal Data.
  9. Governing Law and Interpretation
    To the extent that there is no contradiction to the foregoing, the relevant clauses of the Agreement shall apply to this Part 4. In the event of a conflict between the provisions of this Part 4 and the provisions of the Agreement, the terms of this Part 4 shall prevail.

Schedule I – Details of Processing

  1. Data Exporter: Merchant.
    <rte-indent>1.1 Activities relevant to the data transferred under these Clauses: using the review management Service, including maintenance, support, enhancement and deployment of the same (as described in the Agreement).<rte-indent><rte-indent>1.2 Role: Controller.<rte-indent>
  2. Data Importer: Loox.
    <rte-indent>2.1 Activities relevant to the data transferred under these Clauses: provider and operator of the Service (as described in the Agreement).<rte-indent><rte-indent>2.2 Role: Processor.<rte-indent>
  3. Description of Transfer: provision, hosting, operation, maintenance, support, enhancement and deployment of the Service.
  4. Categories of personal data transferred: The Merchant's Customers Personal Data Processed may include, without limitation: email address, full name, physical address, purchase amount, purchase date, item purchased, reviews submitted to Merchant's website, images, videos, text, recordings, meta data, statistic and analytic information about Merchant's Customers use of the Service and/or the Merchant's, all in accordance with the Merchant’s preferences.
  5. Categories of data subjects whose personal data is transferred: The Merchant's Customers.
  6. The frequency of the transfer: ongoing.
  7. Nature of the processing: storing, organizing, accessing, using, transmitting, retrieving, backing up, securing, troubleshooting and deleting or returning personal data.
  8. Purpose(s) of the data transfer and further processing: provision of the Service to the data exporter.
  9. The period for which the personal data will be retained: personal data will be retained for the duration of the Agreement.
  10. Transfers to (sub-) processors: Loox uses the following sub-processors to Process Personal Data: https://loox.app/legal/service-providers.
  11. Loox will implement appropriate technical and organizational measures to protect the Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access. Loox will ensure that its staff authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.

Alleged infringement notice

If you believe that the Service was used to infringe your copyrights, you may send our designated copyright agent (the "Agent") a written notification that includes substantially the following: 

  1. A physical or electronic signature of the person authorized to act on behalf of the owner of the right that is allegedly infringed;
    1. Loox Privacy Policy for end users available here (the "Privacy Policy")
    2. Loox Terms of Service available here
  2. Identification of the copyrighted work claimed to be infringed, or if copyrighted works are covered by a single notification, a representative list of such elements; 
  3. Identification of the content that is claimed to infringe or to be the subject of infringing activity and the access to which is to be disabled, and information reasonably sufficient to permit us to locate the content, including the exact Service page in which you discovered the allegedly infringing content; 
  4. Information reasonably sufficient to permit us to contact you, such as an address, telephone number, and, if available, an electronic mail address at which you may be contacted; 
  5. A statement that you have a good faith belief that the use of the material, in the manner complained of, is not authorized by the owner of the copyrighted work, its agent, or the law; 
  6. A statement that the information in the notification is accurate, and under penalty of perjury, that you are authorized to act on behalf of the owner of the copyrighted work that is allegedly infringed.

Upon your notification, we may remove or disable access to the content that you claim to be infringing. We may ask you to provide further or supplemental information, prior to removing or disabling access to any content displayed on the Service, as we deem necessary to comply with the law. We may also provide the Service user who submitted the allegedly infringing content, with your contact details, in order for that person to be able to contact you and challenge your claim.

Counter notification

If we’ve removed or disabled access to content that you submitted, pursuant to a notification of claimed infringement that we received, then you have an opportunity to respond to the notice and takedown by submitting a counter-notification to our Agent. To be effective, your counter notification must be a written communication that includes substantially the following:

  1. Your physical or electronic signature;
  2. Identification of the removed content, or of the content to which access has been disabled and the location at which the content appeared before its removal or before access to it was disabled;
  3. A statement, under penalty of perjury, that you have a good faith belief that the content was removed or disabled as a result of mistake or misidentification of the content;
  4. Your name, address, and telephone number, and a statement that you consent to the jurisdiction of the competent courts in any judicial district in which your address is located or in which you may be found, and that you will accept service of process from the person who provided notification or an agent of such person.

After receipt of a counter notification, we will provide the person who submitted the claimed infringement notification, with a copy of the counter notification.

Subject to the applicable law, we may then replace the removed content and cease disabling access to it within 10 to 14 business days following receipt of the counter notice, unless our Agent first receives notice from the person who notified us of the claimed infringement that such person has filed an action seeking a court order to restrain the user from engaging in infringing activity relating to the content on the Service.

Heading

‍

This is some text inside of a div block.
Logo at the footer leads to the homepage
Loox helps over 130,000 brands and 3,000 Shopify Plus stores grow their business effortlessly with the unmatched power of visual reviews – the strongest form of social proof.
Shopify plus partner badge
Meta official partner badge
Navigation
Home
Pricing
Product
Referrals and Rewards
Integrations & API
Widget LibraryCustomers
Partners
Reviewers.com
Resources
Blog
Growth tips
Help CenterAcademyWidget Inspiration
Snippets Inspiration
Email Inspiration
AI Convert
Compare to Judge.me
Compare to Yotpo
Media Kit
Careers
Hiring
Get in Touch
Status
Legal
Privacy Policy
Terms of Service
Copyright Policy
Data Processing Agreement
Website Terms of UseAccessibility Statement
Review Integrity & Fraud PreventionCookies PolicyBug Bounty Policy
Accessibility
© [year] Loox