LooppBack to Loopp

LOOPP LEGAL

Data processing agreement

Pilot-stage UK GDPR processor terms that apply where a business customer uses Loopp to process personal data.Last updated: 27 August 2026
Pilot-stage documentLoopp’s final legal entity name, registered or business address and company number (if applicable) must be inserted before paid commercial launch. This document should be reviewed by a UK solicitor.

1. Roles and scope

The customer is the controller and Loopp is the processor for customer personal data submitted to the service. Processing lasts for the customer’s use of Loopp plus the agreed return, deletion and backup period. Processing supports maintenance reporting, allocation, evidence, communications, quotations, invoicing and related administration.

2. People and information

Data may concern customer staff, contractors, tenants, residents, property contacts, suppliers and other people named in maintenance records. It may include identity and contact details, job and property information, photographs, notes, access information, account records and documents. Customers must not upload special-category or criminal-offence data unless expressly agreed and lawfully managed.

3. Loopp’s commitments

  • Process personal data only on documented lawful instructions.
  • Ensure authorised people are subject to confidentiality.
  • Apply appropriate technical and organisational security measures.
  • Assist with data-subject requests, security duties, breach response and impact assessments where reasonably possible.
  • Provide information reasonably needed to demonstrate compliance and support proportionate audits.
  • Notify the customer without undue delay after becoming aware of a qualifying personal-data breach.

4. Sub-processors

The customer gives general authorisation for Loopp to use sub-processors needed to operate the service, currently including Supabase, Cloudflare, OpenAI Sites and Resend. Loopp will impose appropriate data-protection obligations and provide reasonable notice of material changes so customers can raise a genuine data-protection objection.

5. International transfers

Loopp will not make a restricted transfer unless an adequacy regulation or an appropriate UK safeguard applies, together with any required assessment and supplementary measures.

6. End of service

At the customer’s choice, Loopp will return or delete customer personal data after the service ends, unless law requires retention. Data in protected backups may remain beyond immediate deletion but will be placed beyond normal use and removed through the applicable backup cycle.

7. Customer responsibilities

The customer determines lawful purposes, provides privacy information to individuals, manages user permissions, keeps account information accurate and gives lawful documented instructions.

PrivacyTermsCookiesData Processinghello@loopp.co.uk