Back to Legal Hub

Data Processing Agreement

Last updated: May 6, 2025

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Locomoo, Inc. ("Locomoo," "we," "us," or "our") and users of our mobile application (the "App"), our website at locomoo.app (the "Site"), and related services (collectively, the "Services").

This DPA applies where and only to the extent that Locomoo processes Personal Data on behalf of a user (as "Processor") in the course of providing the Services and where the processing of such Personal Data is subject to Data Protection Laws. For the purposes of this DPA, the user is the "Controller."

This DPA is designed to help the Controller and Processor comply with their respective obligations under applicable Data Protection Laws, including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy regulations.

2. Definitions

For the purposes of this DPA, the following terms shall have the following meanings:

  • "Controller" means the entity that determines the purposes and means of the processing of Personal Data.
  • "Data Protection Laws" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including but not limited to the GDPR, CCPA, and other applicable privacy regulations.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "GDPR" means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
  • "Personal Data" means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
  • "Processing" means any operation or set of operations which is performed on Personal Data, whether or not by automated means.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller.
  • "Sub-processor" means any processor engaged by Locomoo to process Personal Data on behalf of Controller.

3. Scope and Purpose of Processing

3.1 Scope

This DPA applies to the processing of Personal Data by Locomoo on behalf of the Controller in the course of providing the Services.

3.2 Purpose of Processing

Locomoo shall process Personal Data only for the purpose of providing the Services as set out in the Terms of Service and in accordance with the Controller's documented instructions, including with regard to transfers of Personal Data to a third country or an international organization.

3.3 Duration of Processing

Locomoo shall process Personal Data for the duration of the Terms of Service, unless otherwise agreed in writing or required by applicable law.

4. Processor Obligations

4.1 Confidentiality

Locomoo shall ensure that all personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.2 Security Measures

Locomoo shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, among others:

  • The pseudonymization and encryption of Personal Data;
  • The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
  • The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
  • A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

4.3 Sub-processors

Locomoo shall not engage another processor (Sub-processor) without prior specific or general written authorization of the Controller. In the case of general written authorization, Locomoo shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, thereby giving the Controller the opportunity to object to such changes.

Where Locomoo engages a Sub-processor for carrying out specific processing activities on behalf of the Controller, the same data protection obligations as set out in this DPA shall be imposed on that Sub-processor by way of a contract, providing sufficient guarantees to implement appropriate technical and organizational measures.

Locomoo shall remain fully liable to the Controller for the performance of that Sub-processor's obligations.

5. Data Subject Rights

Taking into account the nature of the processing, Locomoo shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the Data Subject's rights under the applicable Data Protection Laws, including but not limited to:

  • The right of access
  • The right to rectification
  • The right to erasure ('right to be forgotten')
  • The right to restriction of processing
  • The right to data portability
  • The right to object to processing
  • Rights related to automated decision-making and profiling

6. Personal Data Breach

In the event of a Personal Data Breach, Locomoo shall notify the Controller without undue delay after becoming aware of the breach and shall provide the Controller with sufficient information to allow the Controller to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.

Such notification shall at a minimum:

  • Describe the nature of the Personal Data Breach, including where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • Communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
  • Describe the likely consequences of the Personal Data Breach;
  • Describe the measures taken or proposed to be taken by Locomoo to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

7. Data Protection Impact Assessment

Upon the Controller's request, Locomoo shall provide the Controller with reasonable assistance in carrying out data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to Locomoo.

8. Deletion or Return of Personal Data

At the choice of the Controller, Locomoo shall delete or return all the Personal Data to the Controller after the end of the provision of Services relating to processing, and delete existing copies unless applicable law requires storage of the Personal Data.

9. Audit Rights

Locomoo shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

Locomoo shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Data Protection Laws.

10. International Data Transfers

Locomoo shall not transfer Personal Data to a third country or an international organization unless authorized by the Controller, and unless one of the following conditions is met:

  • The transfer is to a country or organization that the European Commission has decided provides an adequate level of protection;
  • The transfer is covered by appropriate safeguards, such as binding corporate rules, standard contractual clauses, or approved codes of conduct;
  • The Data Subject has explicitly consented to the proposed transfer after having been informed of the possible risks;
  • The transfer is necessary for the performance of a contract between the Data Subject and the Controller or for the implementation of pre-contractual measures taken at the Data Subject's request;
  • The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the Data Subject between the Controller and another natural or legal person;
  • The transfer is necessary for important reasons of public interest;
  • The transfer is necessary for the establishment, exercise, or defense of legal claims;
  • The transfer is necessary in order to protect the vital interests of the Data Subject or of other persons, where the Data Subject is physically or legally incapable of giving consent.

11. Liability

Each party shall be liable to the other party for damages it causes by any breach of this DPA. Processor shall be liable to the Controller for the damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors or where it has acted outside or contrary to lawful instructions of the Controller.

12. Changes to this DPA

Locomoo reserves the right to modify this DPA at any time in accordance with this provision. If we make changes to this DPA, we will post the revised DPA on our website and update the "Last updated" date at the top of this DPA. If the changes are significant, we may provide additional notice, such as sending an email notification.

Your continued use of our Services after any change to this DPA will constitute your acceptance of such change.

13. Contact Information

If you have any questions about this DPA or our data processing practices, please contact us at:

Bingo Labs Private Limited.

Attn: Legal Department

Pokhara, 20

Nepal, 33700

Nepal

Email: [email protected]