Data Processing Agreement
Last updated: 19 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Shahforge Ltd, trading as Loopion, company number 17332576(“Loopion”, “we”, “us” or “Processor”), and the person or organisation purchasing or using the Loopion service for business purposes ("Customer").
This DPA applies only where Loopion processes Customer Personal Data on the Customer's behalf.
1. Definitions
1.1 Applicable Data Protection Law
"Applicable Data Protection Law" means privacy and data-protection laws that apply directly to Loopion's processing of Customer Personal Data under the Agreement, including where applicable:
- The UK GDPR and Data Protection Act 2018;
- The EU GDPR;
- The California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"); and
- Other applicable United States state privacy laws.
Applicable Data Protection Law does not include sector-specific laws or obligations that apply solely because of the Customer's industry, regulated status or particular use of the service, unless Loopion expressly agrees otherwise in writing.
1.2 Customer Personal Data
"Customer Personal Data" means personal data, personal information or equivalent regulated information processed by Loopion on the Customer's behalf through the service.
1.3 Agreement
"Agreement" means the Terms of Service, this DPA, the Customer's subscription and any written order form agreed between the parties.
Terms such as "controller", "processor", "personal data", "processing", "personal data breach", "business", "service provider", "contractor" and "consumer" have the meanings given under Applicable Data Protection Law.
2. Roles of the parties
For Customer Personal Data:
- The Customer acts as the controller, business or equivalent party determining the purposes and means of processing; and
- Loopion acts as the processor, service provider, contractor or equivalent party processing Customer Personal Data on the Customer's behalf.
The Customer retains all rights, responsibilities and decision-making authority applicable to it as controller or business.
Loopion acts as an independent controller for personal data processed for its own purposes, including account administration, billing, fraud prevention, service security, legal compliance, service communications and Loopion's own marketing. Those activities are governed by Loopion's Privacy Policy and are not covered by this DPA.
3. Processing details
| Subject matter | Provision of Loopion's meeting capture, transcription, summarisation, action extraction, accountability tracking, search, notifications, integrations and related services |
| Duration | The duration of the Customer's use of the service and any applicable retention, export or deletion period |
| Nature of processing | Collecting, receiving, recording, organising, transcribing, analysing, structuring, storing, retrieving, consulting, translating, transmitting, restricting, exporting and deleting Customer Personal Data |
| Purposes | Providing, operating, securing, maintaining and supporting the service in accordance with the Customer's documented instructions |
| Personal data | Names, email addresses, account information, participant information, calendar and meeting metadata, audio, captions, transcripts, summaries, decisions, actions, owners, deadlines, Ask Loopion questions, prompts and generated responses, notifications and related Customer content |
| Data subjects | Workspace users, meeting organisers, invitees, attendees, participants and other individuals whose personal data appears within Customer content |
| Sensitive information | Meeting content may incidentally contain confidential, sensitive, special-category or otherwise protected personal data depending on what meeting participants discuss |
4. Customer instructions
The Customer instructs Loopion to process Customer Personal Data as necessary to:
- Capture meetings authorised through the Customer's workspace;
- Process meeting audio, captions and related information;
- Generate transcripts, summaries, decisions and action items;
- Identify action owners and deadlines;
- Track, remind and resurface outstanding commitments;
- Provide meeting search and question-answering functionality;
- Translate or localise authorised content;
- Send summaries, reminders and notifications;
- Operate integrations enabled by the Customer;
- Store, retrieve, export and delete Customer content;
- Detect and prevent misuse, fraud and security incidents; and
- Provide technical and customer support.
The Agreement, Customer workspace settings, Customer-enabled integrations and documented support requests together constitute the Customer's documented instructions.
The Customer's instructions include the international transfers reasonably necessary to provide the service using the approved subprocessors and safeguards identified on Loopion's Subprocessors page.
Loopion will process Customer Personal Data only:
- In accordance with the Customer's documented instructions;
- As necessary to provide, secure and support the service; or
- Where required by applicable law.
Where legally permitted, Loopion will inform the Customer before processing Customer Personal Data under a legal requirement.
Loopion will inform the Customer if it reasonably believes an instruction infringes Applicable Data Protection Law.
5. Customer responsibilities
The Customer is responsible for:
- The lawfulness, accuracy and appropriateness of its instructions;
- Establishing an appropriate lawful basis for processing;
- Providing meeting participants and other individuals with legally required information;
- Obtaining consent where consent is legally required;
- Ensuring meetings are captured and processed lawfully;
- Determining whether the service is appropriate for the Customer's intended use;
- Managing workspace permissions and authorised users;
- Preventing unauthorised access through its accounts;
- Responding to requests from individuals concerning Customer Personal Data; and
- Ensuring its users comply with the Agreement and applicable law.
Loopion does not determine whether the Customer is legally permitted to capture or process a particular meeting.
The Customer must not instruct Loopion to process Customer Personal Data in a manner that is unlawful, infringes another person's rights or materially compromises the security of the service.
6. Restricted and regulated uses
Unless Loopion has expressly agreed otherwise in writing and any required additional agreement has been signed, the Customer must not intentionally use Loopion:
- To create, receive, maintain or transmit protected health information subject to HIPAA, unless Loopion has entered into a valid Business Associate Agreement with the Customer;
- To collect or store complete payment-card details outside Loopion's approved payment provider;
- To process government-classified information;
- To process information subject to specialist criminal-justice or defence-security requirements;
- For any use requiring mandatory data localisation not supported by Loopion; or
- For processing that would require Loopion to satisfy sector-specific contractual or security obligations beyond those expressly contained in the Agreement.
This section does not prohibit incidental references to sensitive subjects during ordinary business meetings.
7. Confidentiality
Loopion will ensure that employees, contractors and other persons authorised to process Customer Personal Data:
- Access it only where reasonably necessary for their authorised duties; and
- Are subject to appropriate confidentiality obligations.
These confidentiality obligations will continue after the relevant person's access or engagement ends.
8. Security
Loopion will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The measures will be proportionate to the nature, scope, context and purposes of the processing and the risks to individuals.
They may include, as appropriate:
- Identity and access controls;
- Authentication and least-privilege access;
- Encryption and secure transmission;
- Security monitoring and logging;
- Incident-management procedures;
- Resilience, backup and recovery controls;
- Vulnerability and dependency management;
- Secure development practices; and
- Processes for reviewing the effectiveness of security measures.
Loopion may update its security measures to reflect changes in technology, risk and the service, provided that it does not materially reduce the overall protection of Customer Personal Data during the Customer's subscription.
9. Suspension of processing
Loopion may suspend affected processing, functionality or access where it reasonably believes that:
- A Customer instruction infringes applicable law;
- Processing creates a material security or privacy risk;
- The Customer's use infringes another person's rights;
- The Customer is using the service for a restricted use under Section 6;
- The Customer has materially breached the Agreement; or
- Suspension is reasonably necessary to protect Loopion, the service, other customers or affected individuals.
Where reasonably practicable, Loopion will notify the Customer and provide an opportunity to remedy the issue before suspension.
Loopion is not required to continue processing while a reasonably suspected legal or security risk is being investigated.
10. Subprocessors
The Customer gives Loopion general written authorisation to use the subprocessors identified on Loopion's Subprocessors page.
Loopion will:
- Enter into a binding written or electronic agreement with each subprocessor;
- Require each subprocessor to provide protections substantially equivalent to the relevant protections in this DPA;
- Restrict each subprocessor's processing to the services it provides to Loopion;
- Use subprocessors only to provide, operate, secure or support the service; and
- Remain responsible to the Customer for the subprocessor's performance of its applicable data-protection obligations.
A binding electronic agreement may include online terms, a data-processing agreement or equivalent contractual terms validly accepted on behalf of Loopion.
Loopion will provide reasonable advance notice of an intended addition or replacement of a subprocessor that will process Customer Personal Data. Notice may be provided by email, through the service or through another reasonable electronic method.
The Customer may object during the notice period only where it identifies a specific and material data-protection risk associated with the proposed subprocessor.
Loopion may address an objection through:
- Additional safeguards;
- Clarification of the subprocessor's processing;
- Modification of the affected functionality; or
- An alternative provider where commercially reasonable.
Where no reasonable resolution is available, the Customer may stop using or terminate the affected service. Any refund will be determined under the Terms of Service.
11. Individual rights requests
Taking account of the nature of the processing, Loopion will provide reasonable assistance through appropriate technical and organisational measures to help the Customer respond to valid requests from individuals concerning Customer Personal Data.
Where Loopion receives such a request directly, Loopion will:
- Refer the requester to the Customer;
- Inform the Customer where appropriate; or
- Respond as instructed by the Customer or required by law.
Loopion will not independently determine the validity of a request concerning Customer Personal Data unless legally required to do so.
12. Compliance assistance
Taking account of the nature of the processing and the information available to Loopion, Loopion will reasonably assist the Customer with its applicable obligations concerning:
- Security of processing;
- Assessment and notification of personal data breaches;
- Communications to affected individuals;
- Data protection impact or risk assessments;
- Automated decision-making assessments where applicable;
- Cybersecurity audits where applicable; and
- Consultation with a supervisory or regulatory authority.
Loopion will not charge for assistance:
- Available through the service's standard functionality; or
- Required because of Loopion's material breach of this DPA.
Loopion may charge reasonable fees for bespoke, excessive, repetitive or unusually burdensome assistance. Where practicable, those fees will be agreed before the relevant work begins.
13. Personal data breaches
Loopion will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
Where available, the notification will describe:
- The nature of the breach;
- The categories of information and individuals affected;
- The likely consequences;
- The measures taken or proposed to investigate, contain and mitigate the breach; and
- An appropriate contact point.
Where complete information is not immediately available, Loopion may provide information in stages as its investigation progresses.
Loopion will provide reasonable cooperation to help the Customer assess and comply with its applicable reporting and notification obligations.
A notification under this section does not constitute an admission of fault, liability or breach of the Agreement.
14. International transfers
The Customer authorises Loopion and its approved subprocessors to process Customer Personal Data in the locations identified on Loopion's Subprocessors page.
Where Applicable Data Protection Law restricts an international transfer, Loopion will ensure that an appropriate transfer mechanism is used.
Depending on the transfer, this may include:
- An applicable adequacy regulation or decision;
- The UK Extension to the EU-US Data Privacy Framework;
- The EU-US Data Privacy Framework;
- The UK International Data Transfer Agreement;
- The UK Addendum to the European Commission Standard Contractual Clauses;
- The European Commission Standard Contractual Clauses; or
- Another legally recognised transfer mechanism.
Where required, Loopion or the relevant data exporter will carry out an appropriate transfer-risk or transfer-impact assessment and implement supplementary safeguards.
15. United States privacy requirements
Where Applicable United States Data Protection Law applies, Loopion will process Customer Personal Data only on the Customer's behalf and for the limited and specified purposes set out in Sections 3 and 4.
Loopion will not:
- Sell Customer Personal Data;
- Share Customer Personal Data for cross-context behavioural advertising;
- Retain, use or disclose Customer Personal Data for purposes other than those specified in this DPA or otherwise permitted by applicable law;
- Retain, use or disclose Customer Personal Data outside the direct business relationship between Loopion and the Customer, except as permitted by applicable law;
- Combine Customer Personal Data with personal information obtained from another customer, source or direct interaction with an individual, except where permitted by applicable law and reasonably necessary to provide or secure the service; or
- Use Customer Personal Data to advertise Loopion or another organisation's products to meeting participants.
Loopion will:
- Comply with obligations applicable to processors, service providers and contractors;
- Provide the level of privacy protection required under Applicable United States Data Protection Law;
- Process Customer Personal Data only where reasonably necessary and proportionate for the specified purposes;
- Implement reasonable security procedures appropriate to the nature of the information;
- Assist the Customer with applicable consumer requests;
- Provide information reasonably required for applicable risk assessments, cybersecurity audits or automated decision-making assessments;
- Notify the Customer if Loopion determines that it can no longer meet its applicable legal obligations;
- Allow the Customer to take reasonable and appropriate steps to verify that processing is consistent with Applicable United States Data Protection Law; and
- Cooperate with reasonable steps taken by the Customer to stop and remediate unauthorised use of Customer Personal Data.
Loopion certifies that it understands and will comply with the restrictions in this section.
16. Return and deletion
At the end of the service, the Customer may choose to have Customer Personal Data returned or deleted, unless applicable law requires continued storage.
The Customer may request return through:
- Loopion's standard export functionality; or
- A written request made during the retention period stated in Loopion's Data Retention Policy.
Exports will be provided in the formats reasonably available through the service. Loopion is not required to create bespoke export formats or reconstruct information that has already been lawfully deleted.
Where the Customer does not request return during the applicable retention period, the Customer instructs Loopion to delete the Customer Personal Data in accordance with the Data Retention Policy.
Where immediate deletion from backup or archival systems is not reasonably possible, the affected data will:
- Be placed beyond ordinary use;
- Remain protected under this DPA;
- Not be processed for any other purpose; and
- Be deleted through Loopion's normal backup-deletion cycle.
Loopion may retain information where required by law, but only for the required period and purpose.
17. Compliance information, audits and inspections
Loopion will make available all information necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits and inspections conducted by the Customer or an auditor appointed by the Customer, subject to the safeguards and procedures set out in this section.
Loopion may initially satisfy an audit or verification request by providing relevant:
- Policies;
- Security documentation;
- Compliance questionnaire responses;
- Technical information;
- Subprocessor information; or
- Summaries of independent assessments or certifications available to Loopion.
Where that information is not reasonably sufficient, the Customer may request a further audit or inspection.
Before a further audit, Loopion may require:
- Verification of the Customer's legal identity;
- Verification of the requester's authority;
- A written explanation of the data-protection concern;
- A defined and proportionate audit scope;
- At least 30 days' written notice;
- Execution of appropriate confidentiality terms; and
- Agreement on reasonable security and operational procedures.
A shorter notice period may apply where required by a competent regulatory authority or following a material personal data breach affecting the Customer.
Further audits must:
- Be limited to Loopion's processing of Customer Personal Data and compliance with this DPA;
- Normally be conducted remotely;
- Take place during normal business hours;
- Avoid unnecessary disruption;
- Protect Loopion's confidential information;
- Protect the information of other customers;
- Normally occur no more than once in any 12-month period; and
- Be conducted by a suitably qualified and independent auditor where access to non-public systems or confidential materials is requested.
An appointed auditor must not be a direct competitor of Loopion. Loopion may reasonably object to a proposed auditor and require the Customer to appoint a suitable replacement.
Where Loopion reasonably determines that the Customer is a competitor or that direct access by Customer personnel would create a security or confidentiality risk, Loopion may require the review to be conducted solely by an agreed independent auditor.
An audit will not provide access to:
- Other customers' information;
- Source code;
- Passwords, encryption keys or credentials;
- Production-system administration;
- Information that could facilitate an attack on the service;
- Legally privileged material;
- Internal pricing or financial information unrelated to compliance; or
- Trade secrets unrelated to the processing of Customer Personal Data.
Loopion may withhold or redact information where disclosure would breach applicable law, compromise security, reveal another customer's information or disclose legally privileged material. Loopion will provide reasonable alternative evidence where available.
The Customer will bear its own audit costs and Loopion's reasonable costs of supporting the audit unless the audit identifies a material breach of this DPA by Loopion.
Nothing in this section restricts the lawful powers of a competent supervisory or regulatory authority.
18. Deidentified and anonymous data
Where Loopion creates information that is legally considered anonymous or deidentified, Loopion will:
- Take reasonable measures to prevent it from being associated with an identifiable individual;
- Maintain and use it in anonymous or deidentified form; and
- Not attempt to reidentify it except where permitted by law to test or validate the deidentification process.
Nothing in this section permits Loopion to treat identifiable Customer Personal Data as anonymous or deidentified.
Loopion will not use Customer Personal Data to train or fine-tune its own artificial-intelligence models.
19. Liability
Each party's liability arising from or relating to this DPA is subject to the exclusions, limitations and aggregate liability cap set out in the Terms of Service, except where applicable law prohibits such exclusion or limitation.
For the avoidance of doubt:
- Claims under this DPA do not create a separate or additional liability cap;
- Claims concerning subprocessors are included within the same aggregate liability cap; and
- Nothing in this DPA increases Loopion's liability beyond that agreed in the Terms of Service.
Nothing in this section limits any liability that cannot lawfully be excluded or limited.
20. Order of precedence
Where documents conflict concerning Customer Personal Data, the following order of priority applies:
- Any mandatory Standard Contractual Clauses, UK Addendum, International Data Transfer Agreement or other mandatory transfer instrument;
- This DPA;
- The Terms of Service;
- Any other document forming part of the Agreement.
A higher-priority document takes precedence only to the extent of the relevant conflict.
21. Changes to this DPA
Loopion may update this DPA where reasonably necessary to:
- Comply with changes in applicable law;
- Reflect changes to the service or processing;
- Adopt updated transfer mechanisms; or
- Improve data-protection safeguards.
Loopion will not materially reduce the overall protection of Customer Personal Data during an active subscription.
Loopion will provide reasonable notice of any material change that adversely affects the Customer's rights under this DPA.
22. Governing terms and third-party rights
The governing-law and jurisdiction provisions in the Terms of Service apply to this DPA.
Except where a mandatory transfer instrument or applicable law expressly provides otherwise, no person other than Loopion and the Customer has any right to enforce this DPA.
23. Acceptance and signed copies
This DPA becomes binding when the Customer accepts the Terms of Service incorporating it.
A handwritten signature or separately negotiated document is not required. Acceptance through checkout, account registration, an electronic order form or another legally binding electronic process is sufficient.
Customers requiring a countersigned copy may contact:
Questions about this page?
We're happy to help — get in touch any time.