GDPR and Data Protection
How Loopion approaches its obligations under the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR.
Our approach
Loopion is operated by Shahforge Ltd, a company registered in the United Kingdom.
We process personal data in accordance with the data-protection laws that apply to our processing. We maintain technical and organisational measures designed to protect the confidentiality, integrity and availability of personal data.
This page provides an overview of our approach. Full details about the personal data we collect, how we use it, the lawful bases we rely on and who we share it with are provided in our Privacy Policy.
Controller and processor roles
Loopion acts as a controller for personal data processed for its own purposes, including:
- Account and workspace administration;
- Billing and payment records;
- Website analytics and marketing;
- Security and fraud prevention;
- Customer support;
- Service communications; and
- Legal and regulatory compliance.
For meeting content processed through a customer workspace, the customer generally acts as the controller and Loopion acts as the processor. We process that information under the customer's instructions and our Data Processing Agreement.
Customers are responsible for ensuring that their use of Loopion is lawful, including having an appropriate lawful basis and providing meeting participants with any notices required by applicable law.
Data-protection principles
Lawfulness, fairness and transparency
We identify an appropriate lawful basis for the personal data we process and explain our processing through our privacy documentation.
Purpose limitation
We use personal data only for specified purposes, compatible purposes or where otherwise permitted by law.
Customer meeting content is processed to provide, operate, secure and support the Loopion service in accordance with the customer's instructions.
Data minimisation
We limit the personal data we collect and process to what is reasonably necessary for the relevant purpose.
Meeting audio is deleted after processing in accordance with our Data Retention Policy.
Accuracy
We take reasonable steps to maintain accurate personal data. Authorised users can review and correct meeting information, speaker attribution and AI-generated content through the service.
Storage limitation
We retain personal data only for as long as reasonably necessary for the relevant purpose, subject to applicable legal, security and contractual requirements.
Further information is available in our Privacy Policy and Data Retention Policy.
Integrity and confidentiality
We use technical and organisational measures designed to protect personal data. These include measures such as encryption, authentication, access controls, security monitoring and controlled deletion procedures.
Your data-protection rights
Depending on the circumstances and applicable law, you may have the following rights.
Access
Ask whether we process your personal data and request a copy of it.
Rectification
Ask us to correct inaccurate or incomplete personal data.
Erasure
Ask us to delete your personal data where the legal conditions for deletion apply.
Restriction
Ask us to restrict the processing of your personal data in certain circumstances.
Portability
Receive certain personal data in a structured, commonly used and machine-readable format where the right applies.
Objection
Object to certain processing based on legitimate interests and object at any time to processing for direct-marketing purposes.
Withdraw consent
Withdraw your consent at any time where consent is the lawful basis for processing.
Complain
Raise a concern with Loopion or lodge a complaint with the data-protection authority responsible for your country or region.
To exercise a right relating to personal data for which Loopion acts as controller, contact:
Where your request concerns meeting content controlled by a Loopion customer, you should normally contact that customer first. Loopion will assist the customer in responding where required.
We normally respond without undue delay and within one month after verifying the request. Where permitted by law, this period may be extended where a request is complex or multiple requests have been made. Individual rights apply according to their legal conditions and are not absolute in every circumstance.
International transfers
Loopion and its service providers may process personal data in countries outside the United Kingdom or European Economic Area.
Where an international transfer requires additional protection, we use an appropriate legal transfer mechanism. Depending on the transfer, this may include:
- An applicable adequacy regulation or decision;
- The UK Extension to the EU-US Data Privacy Framework;
- The EU-US Data Privacy Framework;
- The UK International Data Transfer Agreement;
- The UK Addendum to the European Commission Standard Contractual Clauses;
- The European Commission Standard Contractual Clauses; or
- Another transfer mechanism permitted by applicable law.
Where required, we also carry out or rely on appropriate transfer-risk assessments and supplementary safeguards.
Our current service providers, processing locations and applicable transfer arrangements are listed on our Subprocessors page. UK restricted transfers not covered by adequacy generally require an appropriate safeguard and, where applicable, a transfer-risk assessment.
Personal data breaches
Where Loopion processes personal data as a processor for a customer, we notify the affected customer without undue delay after becoming aware of a personal data breach involving that customer's personal data.
Where Loopion acts as controller, we assess the potential risk to individuals and notify the relevant supervisory authority where required by applicable law.
For reportable breaches governed by the UK GDPR, we notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where a breach is likely to result in a high risk to affected individuals, we also notify those individuals without undue delay where required by law.
We maintain records of personal data breaches and the assessments made in response to them.
Supervisory authorities
The Information Commissioner's Office is Loopion's UK data-protection supervisory authority.
Shahforge Ltd is registered with the Information Commissioner's Office.
Individuals may also have the right to lodge a complaint with the data-protection authority responsible for their country or region.
Contact us
Questions about this page or Loopion's processing of personal data can be sent to:
Shahforge Ltd trading as Loopion
Email: privacy@loopion.ai
Registered office: Suite RA01, 195–197 Wood Street, London, E17 3NU
Questions about this page?
We're happy to help — get in touch any time.