LoadBear
Platform Front Office Who It's For Security
Sign in Book a call →
Legal

Data Processing Addendum

Effective: August 28, 2026 Version: 2.1 Contact: hello@loadbear.co
Privacy Policy Terms of Service DPA Acceptable Use

1. Introduction and Scope

This Data Processing Addendum (the "DPA") forms part of the Agreement between LoadBear ("LoadBear," "Processor") and the Customer ("Customer," "Controller") governing the processing of Personal Data in connection with Customer's use of the LoadBear Platform (the "Services"). This DPA is intended to satisfy the requirements of (a) the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the "GDPR"); (b) the UK General Data Protection Regulation as implemented by the Data Protection Act 2018 (the "UK GDPR"); (c) the Swiss Federal Act on Data Protection of 25 September 2020 (the "FADP"); (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the "CCPA/CPRA"); and (e) other applicable U.S. state privacy laws including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, and the comprehensive privacy laws of Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Minnesota, Maryland, and Rhode Island, as in effect from time to time (collectively, "Applicable Privacy Laws").

This DPA is incorporated into and forms part of the Terms of Service or other written agreement between the parties governing Customer's use of the Services (the "Agreement"). To the extent of any conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.

2. Definitions

Capitalized terms not defined here have the meanings given in the Agreement, the GDPR, the UK GDPR, the CCPA/CPRA, or other Applicable Privacy Laws, as the context requires.

  • "Approved Subprocessor" means a Subprocessor authorized under Section 7.
  • "Customer Personal Data" means Personal Data contained in Customer Data that LoadBear processes on behalf of Customer in providing the Services.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
  • "EEA" means the European Economic Area.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
  • "Restricted Transfer" means a transfer of Customer Personal Data from a jurisdiction whose Applicable Privacy Laws restrict cross-border transfers to a jurisdiction not deemed to provide adequate protection.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended.
  • "Sub-User" has the meaning set out in Section 8 of the Terms.

3. Roles of the Parties

With respect to Customer Personal Data:

  • Under the GDPR, UK GDPR, and FADP: Customer is the Controller (or, where Customer acts on behalf of a third party, a Processor) and LoadBear is the Processor (or Sub-Processor, as applicable).
  • Under the CCPA/CPRA: Customer is the Business and LoadBear is a Service Provider acting on Customer's behalf.
  • Under other Applicable Privacy Laws: Customer is the Controller (or analogous role) and LoadBear is the Processor (or analogous role).

LoadBear acts as an independent Controller (or Business) only with respect to its own business operations, including account administration, billing, security, and product analytics; such processing is governed by our Privacy Policy, not this DPA.

4. Scope, Duration, and Subject Matter of Processing

The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex 1 below. LoadBear shall process Customer Personal Data only for the duration of the Agreement and only for the purposes set out in Annex 1, the Agreement, and any documented instructions from Customer.

5. Customer's Instructions and Compliance

LoadBear shall process Customer Personal Data only on documented instructions from Customer, including with regard to Restricted Transfers, except where required to do so by applicable law to which LoadBear is subject (in which case LoadBear shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest). The Agreement, including this DPA, the Documentation, Customer's configuration and use of the Services, and any subsequent written instructions agreed by both parties, constitute Customer's complete and final instructions to LoadBear in relation to Customer Personal Data. Additional instructions outside the scope of the Agreement require a separate written agreement and may incur additional fees.

Customer represents and warrants that: (a) it has provided all required notices and obtained all required consents and authorizations to enable the lawful processing of Customer Personal Data under the Agreement; (b) Customer's instructions to LoadBear comply with Applicable Privacy Laws; and (c) Customer's use of the Services does not violate any third-party rights.

6. LoadBear's Obligations

6.1 Confidentiality of personnel

LoadBear shall ensure that personnel authorized to process Customer Personal Data are bound by appropriate written confidentiality obligations or are under a statutory obligation of confidentiality, and have received appropriate training on their responsibilities.

6.2 Security

LoadBear shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Annex 2 (Technical and Organizational Measures). LoadBear may update these measures from time to time, provided that the updated measures do not materially diminish the level of protection.

6.3 Personal Data Breach notification

LoadBear shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall include, to the extent then available: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the breach and mitigate possible adverse effects; and (d) the name and contact details of LoadBear's data protection contact. Notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability by LoadBear.

6.4 Assistance with Data Subject rights

Taking into account the nature of the processing, LoadBear shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Applicable Privacy Laws (including rights of access, rectification, erasure, restriction of processing, data portability, and objection). If LoadBear receives a request directly from a Data Subject regarding Customer Personal Data, LoadBear shall not respond to the request (other than to direct the Data Subject to Customer or confirm receipt) and shall promptly forward the request to Customer.

6.5 Assistance with impact assessments and consultations

LoadBear shall provide reasonable assistance to Customer with any data protection impact assessments or prior consultations with supervisory authorities required under Articles 35 and 36 of the GDPR or analogous provisions, taking into account the nature of the processing and the information available to LoadBear.

6.6 Records of processing

LoadBear shall maintain records of processing activities carried out on behalf of Customer as required by Article 30(2) of the GDPR.

7. Subprocessors

7.1 General authorization

Customer provides general written authorization for LoadBear to engage Subprocessors to process Customer Personal Data, subject to this Section 7. The current list of Subprocessors is set out in Annex 3.

7.2 Notice of new Subprocessors

LoadBear shall update the Subprocessor list before engaging any new Subprocessor and provide notice via email to the address designated by Customer (or, if no address is designated, by posting an updated list on loadbear.co with a mechanism to subscribe to changes). LoadBear shall provide such notice at least thirty (30) days before the new Subprocessor processes Customer Personal Data, except in the case of replacement of an existing Subprocessor where a shorter period is required for urgent operational, security, or legal reasons.

7.3 Right to object

Customer may object to the appointment of a new Subprocessor on reasonable grounds related to data protection by giving written notice within ten (10) business days of LoadBear's notice. The parties shall discuss the objection in good faith and seek a commercially reasonable solution. If no resolution is reached within thirty (30) days, Customer may terminate the affected Services on written notice with a refund of any prepaid fees for the unused portion of the Subscription Term as Customer's exclusive remedy.

7.4 Subprocessor agreements and liability

LoadBear shall enter into written agreements with each Subprocessor that impose data protection obligations no less protective than those in this DPA. LoadBear remains liable for the acts and omissions of its Subprocessors that cause LoadBear to breach this DPA, to the same extent LoadBear would be liable if performing the obligations directly.

8. International Data Transfers

8.1 Restricted Transfers from the EEA

To the extent that LoadBear's processing of Customer Personal Data involves a Restricted Transfer from the EEA, the SCCs are hereby incorporated by reference and apply, with the following selections: (a) Module Two (Controller-to-Processor) shall apply where Customer is a Controller and LoadBear is a Processor; (b) Module Three (Processor-to-Processor) shall apply where Customer is a Processor; (c) Clause 7 (Docking Clause) is included; (d) Clause 9(a) Option 2 (general written authorization) shall apply with the time period in Section 7.2 above; (e) Clause 11(a) optional language is excluded; (f) Clause 17 Option 1 shall apply, governed by the laws of the Republic of Ireland; (g) Clause 18(b) shall designate the courts of Ireland; and (h) Annexes I, II, and III to the SCCs shall be deemed completed with the information set out in Annexes 1, 2, and 3 of this DPA.

8.2 Restricted Transfers from the United Kingdom

To the extent that LoadBear's processing involves a Restricted Transfer from the UK, the parties incorporate the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner ("UK Addendum"). Tables 1, 2, and 3 of the UK Addendum are deemed completed with the corresponding information from this DPA and the SCCs. Table 4 is completed by selecting "neither party."

8.3 Restricted Transfers from Switzerland

To the extent that LoadBear's processing involves a Restricted Transfer from Switzerland, the SCCs apply with the following modifications: (a) references to "GDPR" are deemed to include the FADP; (b) references to the European Commission and supervisory authorities are amended to include the Swiss Federal Data Protection and Information Commissioner ("FDPIC"); (c) the term "member state" is amended to include Switzerland; (d) Clause 17 designates Swiss law; and (e) Clause 18(b) designates the courts of Switzerland.

8.4 Alternative transfer mechanisms

If a competent court or supervisory authority determines that the SCCs or UK Addendum are no longer a valid transfer mechanism, or if LoadBear adopts an alternative recognized transfer mechanism (such as Binding Corporate Rules or an approved certification), the parties shall cooperate in good faith to implement such alternative mechanism.

9. Audit Rights

LoadBear shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. Upon reasonable prior written notice (at least thirty (30) days, except in the event of a Personal Data Breach or where required by a supervisory authority), and no more than once per twelve-month period (except where required by a supervisory authority), Customer may, at its own expense, conduct or commission an audit of LoadBear's compliance with this DPA, subject to the following:

  • The audit shall be conducted during normal business hours, in a manner that does not unreasonably interfere with LoadBear's business operations, and in accordance with reasonable security and confidentiality requirements;
  • Customer (or its auditor) shall sign customary confidentiality agreements before any audit;
  • The auditor shall not be a competitor of LoadBear;
  • LoadBear may satisfy its audit obligations by providing Customer with copies of any recent third-party audit reports or certifications it holds, or a completed security questionnaire. For the avoidance of doubt, and stated here rather than left to be discovered: LoadBear does not currently hold a SOC 2 Type II report or an ISO 27001 certification, and has not undergone a third-party penetration test. Until it does, LoadBear will satisfy this Section by responding to Customer's security questionnaire and providing the information in Annex 2;
  • If a regulator requires more detailed audit, LoadBear shall cooperate with the regulator's lawful requirements.

10. Return or Deletion of Customer Personal Data

Within thirty (30) days after termination or expiration of the Agreement, LoadBear shall, at Customer's choice (made by written notice within that period), return or delete all Customer Personal Data, unless retention is required by applicable law. Where retention is required, LoadBear shall protect the retained Customer Personal Data with the same security measures and limit further processing to what is required by law.

11. CCPA-Specific Provisions

To the extent LoadBear processes Personal Information (as defined in the CCPA/CPRA) on behalf of Customer:

  • LoadBear is a "Service Provider" and Customer is a "Business" as those terms are defined under the CCPA/CPRA;
  • LoadBear shall not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than for the specific business purpose of providing the Services as set forth in the Agreement, or as otherwise permitted by the CCPA/CPRA; (c) retain, use, or disclose Personal Information outside the direct business relationship between LoadBear and Customer; or (d) combine Personal Information that LoadBear receives from or on behalf of Customer with Personal Information that LoadBear receives from or on behalf of any other person, or collects from its own interaction with the consumer, except as permitted by Section 7050(b) of the CCPA Regulations;
  • LoadBear certifies that it understands these restrictions and will comply with them;
  • LoadBear shall notify Customer if it determines it can no longer meet its obligations under the CCPA/CPRA;
  • Customer has the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information.

12. Limitation of Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set forth in the Agreement. Any reference in such limitations to liability under "the Agreement" includes liability under this DPA. For the avoidance of doubt, LoadBear's total cumulative liability under the Agreement and this DPA, taken together, shall not exceed the cap set forth in the Agreement.

13. Order of Precedence

If there is any conflict between this DPA and any other agreement between the parties, the order of precedence is: (a) the SCCs and UK Addendum (where applicable); (b) this DPA; (c) the Agreement.

14. Updates to this DPA

LoadBear may update this DPA from time to time to reflect changes in Applicable Privacy Laws, Subprocessors, or LoadBear's processing operations, provided that no update shall materially diminish Customer's protections under this DPA without Customer's consent. Updates will be posted at loadbear.co/dpa with an updated "Effective" date.

15. Governing Law and Notices

Except where Section 8 designates a different governing law for the purpose of a specific transfer mechanism, this DPA is governed by the law that governs the Agreement — the laws of the State of Ohio, United States — and disputes are resolved as set out in Section 25 of the Terms of Service. Nothing in this Section limits a Data Subject's rights or a supervisory authority's jurisdiction under Applicable Privacy Laws, or the third-party beneficiary rights conferred by the Standard Contractual Clauses.

Notices under this DPA, including notices of a Personal Data Breach and of new Subprocessors, are given to the email address designated by Customer on its account, and to LoadBear at hello@loadbear.co with the subject line "DPA Notice." Customer is responsible for keeping a monitored address on file.

Where Customer Personal Data of Ohio residents is involved, LoadBear's notice obligation to Customer under Section 6.3 (72 hours) runs in addition to, and is intended to enable Customer to meet, the statutory notification deadline under Ohio Rev. Code § 1349.19.

Annex 1 — Description of Processing

Subject matterProvision of the LoadBear Platform under the Agreement.
DurationFor the term of the Agreement, plus any retention period required by law or specified in the Agreement.
Nature and purposeHosting, storage, processing, and presentation of Customer Personal Data necessary to operate AI agents and workflows configured by Customer; security; access management; backup; support.
Categories of Data SubjectsAs determined by Customer; may include Customer's employees, contractors, agents, customers, prospects, suppliers, applicants, end users, and other individuals whose Personal Data Customer chooses to submit to the Services.
Types of Personal DataAs determined by Customer; commonly includes contact details (name, phone number, email address, postal address), professional information, communications content and metadata (SMS message bodies and delivery status; email addresses, subjects, bodies and delivery/bounce events; caller and recipient telephone numbers, call times and durations; call audio where a line records; call transcripts where a Customer has enabled a transcribing feature), appointment and calendar entries, quotes, invoices and transaction records, and business documents Customer uploads. Where Customer enables the live inbound AI receptionist, call audio is streamed to a model subprocessor in real time and is not stored by LoadBear as audio or transcript; only call metadata and the structured result of the call are retained. Customer is responsible for not submitting categories of Personal Data the Services are not designed to process (including special categories of Personal Data under GDPR Article 9 or "sensitive personal information" under U.S. state laws) without first ensuring suitability and entering into any required additional agreements.
Frequency of transferContinuous for the duration of the Agreement.
SubprocessorsSee Annex 3.
RetentionCustomer Personal Data is retained for the life of the workspace and is deleted on Customer's instruction, on account or workspace deletion, or under Section 10 of this DPA. LoadBear does not operate an automated time-based expiry that ages out Customer Personal Data after a fixed period. Where Customer requires a defined maximum retention period for a data category, that period must be agreed in the Order Form and configured; it is not a platform default.

Annex 2 — Technical and Organizational Measures (TOMs)

These are the measures actually in place, described at the level of detail a reviewer can check. Where a control commonly listed in a TOM annex is not implemented, it is named as not implemented rather than omitted.

Access control and authentication

  • Two-factor authentication on every sign-in, mandatory and not disableable: after password verification, a six-digit code is delivered by email and required to complete the session. There is no account, including administrative accounts, that authenticates on a password alone. Codes are stored as hashes, expire in ten minutes, are rate-limited, and are capped on resends;
  • Role-based access control with least-privilege principles; session tokens are HttpOnly, Secure and SameSite-scoped, and state-changing requests require a CSRF token;
  • Workspace isolation: each Customer's data is logically segregated, access is scoped to the owning workspace on every request path, and an automated tenant-scope check runs against new code before release and fails the build where a query reaching tenant data is not workspace-scoped;
  • Administrative access to production is limited to LoadBear's principal; access rights are reviewed on change rather than on a fixed calendar cycle, and LoadBear does not claim a periodic access-review cadence it does not run.

Encryption

  • Data in transit: TLS 1.2 or higher for all external communications; HTTPS enforced with HSTS;
  • Data at rest: encryption at rest as provided by the managed cloud platform on which Customer Personal Data is stored (see Annex 3). LoadBear does not operate its own storage hardware and inherits the platform's at-rest encryption rather than implementing a separate application-layer encryption scheme;
  • Secrets management: API keys and credentials are held in the platform's encrypted secret store, never in source control, and are redacted by name pattern from data exports.

Operational security

  • Automated pre-release gates: a test suite, a syntax and bundle-compile check, a tenant-scope check, and a route-equivalence check must pass before a release is accepted; a post-deploy smoke suite and scheduled runtime checks exercise the live product;
  • Logging and monitoring of authentication events, administrative actions, and security-relevant events to an append-only audit log, queryable by Customer for its own workspace;
  • Rate limiting and origin checks on authentication and state-changing endpoints; outbound request URL validation at a single chokepoint to mitigate server-side request forgery;
  • Dependencies are pinned and updated on review. LoadBear does not currently operate a scheduled automated vulnerability-scanning or patch-management program, and does not claim one. Where a Customer requires evidence of such a program, LoadBear will say so rather than assert it;
  • Incident response: LoadBear maintains a defined notification path and the 72-hour commitment in Section 6.3. A formally documented incident response plan with assigned roles is not yet in place and is not claimed.

Personnel

  • LoadBear currently has no employees. Access to production and to Customer Personal Data is limited to LoadBear's principal. Statements about workforce-scale controls — background-check programs, staff security-awareness training curricula, periodic recertification — are therefore not made here, because there is no workforce to apply them to;
  • Any future personnel or contractor with access to Customer Personal Data will be bound by written confidentiality obligations before access is granted, and access will be revoked on role change or termination. LoadBear will update this Annex before, not after, that access is granted;
  • Subprocessor personnel are covered by the confidentiality and security obligations in each subprocessor's own agreement (Section 7.4).

Physical security

  • LoadBear operates no data centers or server hardware of its own. Customer Personal Data is stored on managed cloud infrastructure (see Annex 3) whose providers publish their own physical-security certifications and controls; physical security is inherited from those providers and is evidenced by their certifications, not by LoadBear's.

Resilience and continuity

  • Application compute runs on a globally distributed edge platform; Customer Personal Data is held on that platform's managed database, object storage and key-value services and inherits their durability and redundancy properties. LoadBear does not operate an independent secondary region or maintain its own off-platform backup copy, and does not claim a recovery time or recovery point objective;
  • Customer may export its entire workspace at any time, unilaterally, from within the product. The export enumerates the live database schema rather than a fixed allowlist, so every workspace-scoped table is included and newly added tables are covered automatically. Secret-bearing columns are redacted, session and security tables are excluded, stored files are included as a manifest of keys retrievable through authenticated routes, and the export declares what it contains and anything it skipped or truncated;
  • Customer may delete its account and any workspace it solely owns from within the product. Deletion cascades to workspace-scoped records, stored objects, and search indexes, and is not reversible.

Vendor management

  • Subprocessors are reviewed against their published security and privacy documentation before onboarding, and are engaged on their standard data processing terms, which impose obligations no less protective than those in this DPA (Section 7.4);
  • The current Subprocessor list is maintained in Annex 3 and is the authoritative list; LoadBear does not maintain a competing shorter summary elsewhere.

AI-specific measures

  • LoadBear does not use Customer Personal Data to train any AI model, general-purpose or otherwise;
  • Model subprocessors are accessed through their business or API tiers, whose standard terms provide that data submitted through the API is not used to train their models. LoadBear relies on those standard terms and has not negotiated bespoke zero-retention agreements with each model provider; each provider's own abuse-monitoring retention window applies. LoadBear will identify, on request, which model providers are in the processing path for a given feature;
  • Where a call is answered by the live inbound AI receptionist, audio is streamed to the model subprocessor for real-time processing and is not stored by LoadBear (Annex 1);
  • Per-workspace controls to disable prompt logging or to set an output-retention window are not implemented today and are not claimed. A Customer requiring such a control should agree it in the Order Form before onboarding.

Annex 3 — Subprocessors

LoadBear engages the following Subprocessors to provide the Services. Not every Subprocessor processes every Customer's data. Several are engaged only where Customer enables the corresponding feature or connects the corresponding account; where that is the case, the row says so. Cloudflare, Stripe and Resend are engaged for every Customer, because every Customer is hosted, billed and emailed.

SubprocessorService providedLocation of processing
Cloudflare, Inc.Primary infrastructure: edge compute, the managed database holding Customer Personal Data, object storage, key-value storage, vector search, DNS, content delivery, web application firewall, and Workers AI inference for certain in-product featuresGlobal edge network, primary storage in the U.S.
Anthropic, PBCLarge language model API for AI agent functionalityUnited States.
Google LLC (Gemini API)Large language model API for certain generation featuresUnited States.
Stripe, Inc.Payment processing and subscription billingUnited States.
Resend, Inc.Transactional and notification email deliveryUnited States.
Cal.com, Inc.Booking and schedulingUnited States.
Google LLC (Workspace)Gmail and Google Calendar content, only where connected by Customer via OAuth and only within the scopes grantedUnited States.
Twilio Inc.Telephony and SMS — inbound and outbound calls and messages, including caller and recipient numbers, message bodies, delivery status, and call audio and recordings where a line records; engaged only where Customer enables phone or SMS featuresUnited States.
OpenAI, L.L.C.Realtime speech model for the voice receptionist — receives live call audio in real time; engaged only where Customer enables voice answeringUnited States.
Composio Inc.Third-party integration brokerage and OAuth connection managementUnited States.
Nango AGOAuth token management for Customer-authorized integrationsUnited States / Switzerland.
Bright Data Ltd.Web data retrieval performed on Customer instructionIsrael / United States.
Microsoft CorporationMicrosoft Graph — calendar content (Calendars.ReadWrite scope only), where connected by CustomerUnited States.
ElevenLabs Inc.Speech synthesis for generated audio contentUnited States.
HeyGen Ltd.Generated video contentUnited States.
Ideogram AI Inc.Generated image contentUnited States / Canada.
FAL.AI, Inc.Generated image and media contentUnited States.
X.AI LLCGenerated image content (Grok image models)United States.
Intuit Inc.QuickBooks — accounting and financial records, where connected by CustomerUnited States.
Meta Platforms, Inc.Publishing to Facebook / Instagram / Threads on Customer's instructionUnited States.
X Corp.Publishing to X on Customer's instructionUnited States.
LinkedIn CorporationPublishing to LinkedIn on Customer's instructionUnited States.
TikTok Inc.Video publishing on Customer's instructionUnited States / Singapore.
Apple Inc.iCloud CalDAV — calendar read/write, where connected by CustomerUnited States.
PostizSocial post schedulingEuropean Union.
ManyChat, Inc.Messaging automation, where connected by CustomerUnited States.
Buttondown, LLCNewsletter / waitlist subscriber emailUnited States.
Higgsfield AIGenerated image and video contentUnited States.
Yelp Inc.Business listing and review dataUnited States.
DataForSEO LLCSearch-ranking data for SEO featuresEuropean Union / United States.
Mapbox, Inc.Mapping and geocoding of property addressesUnited States.
ATTOM Data Solutions, Regrid, Zoneomics, PropertyRadarProperty, parcel, zoning and owner records for commercial-real-estate featuresUnited States.

Processing locations reflect each provider's principal place of business. Providers may process in additional regions in accordance with their own current documentation; consult the provider's sub-processor list for regional detail.

The current Subprocessor list is maintained at loadbear.co/dpa. Customer may subscribe to subprocessor change notifications by emailing hello@loadbear.co with the subject line "Subprocessor Updates."

LoadBear

The white-label AI Operations Platform for businesses ready to run themselves like software.

hello@loadbear.co
Product
  • Platform
  • Front Office
  • Cora
  • What It's Worth
Company
  • Who It's For
  • Security
  • Book a call
  • hello@loadbear.co
Legal
  • Privacy
  • Terms
  • DPA
  • Acceptable Use
  • SMS Terms
© 2026 LoadBear. All rights reserved. loadbear.co