Privacy Policy
This Privacy Policy explains how Loopion collects, uses and protects personal data when you visit our website, communicate with us, create an account or use the Loopion service.
Last updated: 20 August 2026
1. Who we are
Loopion is a trading name of Shahforge Ltd, a company registered in England and Wales under company number 17332576.
Registered office:
Suite RA01
195–197 Wood Street
London
E17 3NU
United Kingdom
Privacy contact: privacy@loopion.ai
Shahforge Ltd is registered with the UK Information Commissioner's Office under registration reference ZC201889.
Loopion acts as a controller for personal data processed for its own purposes, including account administration, billing, website activity, security, support and marketing.
Where Loopion processes meeting content through a customer workspace, the customer generally acts as the controller and Loopion acts as its processor under our Data Processing Agreement.
2. Personal data we collect
Account and workspace information
We may collect:
- Name and business contact details;
- Authentication identifiers and sign-in records;
- Organisation, workspace and team membership information;
- Account settings and communication preferences;
- Subscription, billing and transaction information; and
- Information you provide when contacting us.
Certain account and billing information is required for us to provide the service. If it is not provided, we may be unable to create or administer your account.
Meeting and customer content
When a customer uses Loopion to process a meeting, we may process:
- Meeting and participant details;
- Calendar and integration information;
- Meeting audio and captions;
- Transcripts, summaries and decisions;
- Actions, owners, deadlines and completion status;
- Questions submitted through Ask Loopion and generated responses; and
- Related content and metadata.
Meeting content may contain personal, confidential or sensitive information depending on what participants discuss.
Loopion does not create biometric voiceprints or voice profiles.
Website, device and usage information
We may collect:
- IP address;
- Browser, device and operating-system information;
- Account, session and feature activity;
- Security, service and error logs;
- Pages viewed and links or buttons selected;
- Referral source and advertising campaign information;
- Pricing, registration and checkout activity;
- Cookie and tracking preferences; and
- General website and service-usage information.
Marketing information
Where permitted, we may process:
- Business contact information;
- Communication and marketing preferences;
- Marketing emails sent, delivered or rejected;
- Email opens and link selections;
- Advertising interactions and conversion information; and
- Hashed contact information used for conversion matching where enabled and permitted.
Payment information
Payments are processed by Stripe or another approved payment provider.
Loopion does not receive or store your complete payment-card number. We may retain your billing contact details, subscription, payment status, invoices and transaction records.
3. Where personal data comes from
We may receive personal data:
- Directly from you;
- From the organisation providing your Loopion workspace;
- From meeting organisers, invitees and participants;
- From calendar, authentication and meeting services you connect;
- From payment, support and service providers;
- Automatically when you use our website or service;
- From advertising and marketing partners; and
- From publicly available professional or business sources where permitted for business-to-business communications.
4. How and why we use personal data
Providing and administering the service
We use personal data to:
- Create and administer accounts and workspaces;
- Provide subscriptions and requested functionality;
- Process payments and manage billing;
- Provide customer support;
- Send meeting, action and service notifications; and
- Maintain customer relationships.
We generally rely on performance of a contract or our legitimate interests in administering the service and our customer relationships.
Processing customer meeting content
Where Loopion acts as a processor, meeting content is processed under the customer's documented instructions to provide the Loopion service.
The customer is responsible for determining the appropriate lawful basis, providing required notices and ensuring that meetings are captured and processed lawfully.
Security and service operation
We use personal data to:
- Operate and maintain the service;
- Authenticate users;
- Protect accounts and workspaces;
- Detect and prevent fraud, misuse and security incidents;
- Investigate faults and service problems; and
- Enforce our contractual rights.
We generally rely on legitimate interests in protecting and operating Loopion, our customers and users.
Analytics and service improvement
With consent where required, we may analyse website and non-meeting usage information to understand how the website and service are used and to improve performance, usability and the customer journey.
This includes our own first-party marketing-attribution analytics, which records which marketing source (such as a campaign, referral link or outreach email) led to a website visit, and, where you go on to create an account, links that source to your resulting account and workspace so we can understand which activity produced paying customers. This uses randomly generated, non-identifying visitor and session identifiers, never your email address directly.
Advertising and conversion measurement
With consent where required, we may use website, advertising and checkout information to:
- Measure advertising performance;
- Attribute registrations and purchases to advertising interactions;
- Understand which campaigns generate customers;
- Measure conversion value; and
- Improve and optimise our campaigns.
We do not use meeting recordings, transcripts, actions, participant details or Ask Loopion content for advertising.
Marketing communications
We may send business-related marketing communications where permitted by applicable law.
Depending on the circumstances, we rely on consent or our legitimate interests in promoting Loopion to relevant business contacts.
Every marketing email provides a way to unsubscribe or object.
Legal obligations
We may process and retain personal data where necessary to comply with legal, tax, accounting, regulatory or law-enforcement requirements.
5. Artificial intelligence and customer content
Loopion does not use customer meeting content to train or fine-tune its own artificial-intelligence models. Where specialist AI providers process customer content, their processing is governed by applicable contractual safeguards and the data controls configured for Loopion.
AI-generated content may contain errors. Loopion does not make solely automated decisions about individuals that produce legal or similarly significant effects.
6. Google user data (Google API Services)
This section applies when you connect a Google account to Loopion. Loopion's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What Google user data we access
With your permission, Loopion accesses:
- Google Calendar events (read-only): event titles, dates and times, organiser and attendee details, and meeting join links contained in events;
- Basic profile information when you sign in with Google: your name, email address and profile identifier.
Loopion does not create, modify or delete events in your Google Calendar, and does not access Gmail, Drive, Contacts or any other Google service.
How we use Google user data
Calendar data is used solely to display your upcoming meetings in Loopion and to schedule the Loopion meeting assistant for eligible meetings you choose to capture. Profile information is used solely to authenticate you and identify your account. We do not use Google user data for advertising, profiling unrelated to the service, or any purpose other than providing and improving these user-facing features.
How we share Google user data
We do not sell or transfer Google user data to third parties. It is stored and processed only by the infrastructure providers that host the Loopion service (listed on our Subprocessors page) acting on our behalf, or where required by law. Google user data is never used to develop, improve or train generalised artificial-intelligence or machine-learning models. Where limited meeting details originating from a calendar event (such as a meeting title) are processed by our AI providers to generate meeting outputs you have requested, those providers act on our behalf and do not use the data to train their models.
How we protect Google user data
Google account tokens are stored encrypted, transmitted only over encrypted connections, and are accessible only to the service components that require them. Access within Loopion is restricted and workspace-scoped.
Retention and deletion of Google user data
Calendar event details are retained only while your calendar connection is active and are refreshed from Google rather than archived. When you disconnect your Google account in Loopion Settings, or revoke Loopion's access via your Google Account security settings, stored Google tokens are deleted and Loopion stops accessing your Google data. You may also request deletion at any time via privacy@loopion.ai.
7. Who we share personal data with
We may share personal data with:
- Hosting, infrastructure and storage providers;
- Transcription and artificial-intelligence providers;
- Authentication, meeting, calendar and integration providers;
- Payment and billing providers;
- Email, support and communication providers;
- Analytics and advertising providers where permitted;
- Security and operational service providers;
- Professional advisers, insurers and auditors;
- Regulators, courts, law-enforcement bodies or other authorities where required; and
- A purchaser, investor or successor in connection with a proposed or completed corporate transaction.
Providers processing personal data on our behalf are subject to appropriate contractual obligations.
Our current providers and their purposes are listed on our Subprocessors page.
Loopion does not sell personal information.
8. International transfers
Loopion and its service providers may process personal data in countries outside the United Kingdom or European Economic Area.
Where additional transfer protection is required, we use an appropriate legal mechanism. Depending on the transfer, this may include:
- An applicable adequacy regulation or decision;
- The UK Extension to the EU–US Data Privacy Framework;
- The EU–US Data Privacy Framework;
- The UK International Data Transfer Agreement;
- The UK Addendum to the European Commission Standard Contractual Clauses;
- The European Commission Standard Contractual Clauses; or
- Another mechanism permitted by applicable law.
Where required, appropriate transfer assessments and supplementary safeguards are also used.
You may contact privacy@loopion.ai for further information about the safeguards applying to a particular transfer.
9. How long we retain personal data
We retain personal data only for as long as reasonably necessary for the relevant purpose.
Meeting audio
Loopion operates zero post-processing audio retention.
Meeting audio is processed only for as long as necessary to produce the requested meeting outputs and is deleted when processing is complete or can no longer be completed. It is not retained as part of the customer's meeting history.
Meeting content
Transcripts, summaries, actions, decisions and related meeting content are retained according to the customer's workspace settings, subscription and our Data Retention Policy.
Account and service information
Account, support and service information is retained while needed to provide the service and for a limited period afterwards where necessary for security, disputes, fraud prevention or legal obligations.
Billing information
Billing, transaction and accounting records are retained for the periods required by applicable tax and accounting law.
Website and marketing information
Website, analytics and advertising information is retained according to the relevant consent settings, provider configuration and the period reasonably required for measurement and reporting.
Marketing information is retained until it is no longer required, you withdraw consent or you object to further marketing.
Limited suppression information may be retained to ensure that an opt-out continues to be respected.
Backups
Information in backups may remain until it is deleted through our normal backup-deletion cycle. It is protected and not used for unrelated purposes during that period.
Further details are available in our Data Retention Policy.
10. Your rights
Depending on the circumstances and applicable law, you may have the right to:
- Request access to your personal data;
- Correct inaccurate or incomplete personal data;
- Request deletion where the legal conditions apply;
- Restrict certain processing;
- Object to certain processing;
- Receive certain data in a structured, commonly used and machine-readable format;
- Withdraw consent where processing is based on consent; and
- Complain to the relevant data-protection authority.
These rights are subject to applicable legal conditions and are not absolute in every circumstance.
Direct marketing
You may object at any time to the use of your personal data for direct marketing. When you object, we will stop using it for that purpose.
To exercise your rights, contact:
Where your request concerns meeting content controlled by a Loopion customer, we may refer the request to that customer and assist it in responding.
We normally respond without undue delay and within one month after receiving and verifying a request. Where permitted by law, that period may be extended for complex or multiple requests.
11. United States privacy rights
Where a comprehensive United States state privacy law applies to Loopion, residents may have additional rights, including the right to:
- Know or access personal information;
- Correct inaccurate information;
- Request deletion;
- Obtain a portable copy;
- Opt out of certain targeted advertising, sale or sharing;
- Appeal a decision concerning a request; and
- Exercise their rights without unlawful discrimination.
Loopion does not sell personal information.
Loopion does not use or disclose customer meeting content for targeted advertising.
Where applicable law treats disclosures of website or advertising information to advertising providers as sharing or targeted advertising, you may manage your choices through and any additional privacy controls made available on our website.
Requests may be sent to privacy@loopion.ai.
12. Cookies and tracking technologies
Loopion uses essential cookies and similar technologies to operate and secure its website and service.
With permission where required, we may also use:
- Website analytics;
- Advertising and conversion measurement;
- Advertising attribution;
- Enhanced conversion matching;
- Tracking pixels;
- Tags and scripts; and
- Similar storage or access technologies.
Non-essential technologies are controlled through our consent settings and are not activated before consent where consent is legally required.
You can change your choices through the link on our website.
Further information is available in our Cookie and Tracking Technologies Policy.
13. Email tracking
Marketing emails may contain tracked links or pixels that help us understand:
- Whether an email was delivered;
- Whether it appears to have been opened;
- Whether a link was selected; and
- Whether engagement resulted in a website visit, registration or purchase.
We use this information only where permitted and in accordance with applicable consent requirements.
Email-open information may be inaccurate because some email services block, cache or automatically load images.
You can unsubscribe or object to marketing at any time using the link in the email or by contacting privacy@loopion.ai.
We may continue to process basic delivery and bounce information for essential service communications.
14. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental loss, misuse, unauthorised access, alteration or disclosure.
No online service can guarantee absolute security.
We do not publish detailed system architecture, security configurations, credentials, detection rules or internal operational procedures in this Privacy Policy.
15. Children
Loopion is a business service. It is not directed at children, and we do not knowingly collect personal data from them.
Accounts may only be created and used by individuals aged 18 or over. Customers must not provision anyone under 18 as a user of their workspaces.
Customers are responsible for ensuring that any processing involving children through the service is lawful and appropriate.
If we become aware that we hold the personal data of a person under 18 who has created an account, we will delete it. If you believe a child has provided us with personal data, contact us using the details in section 17.
16. Changes to this policy
We may update this Privacy Policy to reflect changes in the service, our practices or applicable law.
Where required, we will provide reasonable notice of material changes.
The date at the top shows when this policy was last updated.
17. Contact and complaints
Questions, requests or complaints may be sent to:
Shahforge Ltd trading as Loopion
Suite RA01
195–197 Wood Street
London
E17 3NU
United Kingdom
Email: privacy@loopion.ai
You may also complain to the Information Commissioner's Office or, where applicable, the data-protection authority responsible for your country or region.
Questions about this page?
We're happy to help — get in touch any time.