1. Roles and scope
The customer is the controller and Loopp is the processor for customer personal data submitted to the service. Processing lasts for the customer’s use of Loopp plus the agreed return, deletion and backup period. Processing supports maintenance reporting, allocation, evidence, communications, quotations, invoicing and related administration.
2. People and information
Data may concern customer staff, contractors, tenants, residents, property contacts, suppliers and other people named in maintenance records. It may include identity and contact details, job and property information, photographs, notes, access information, account records and documents. Customers must not upload special-category or criminal-offence data unless expressly agreed and lawfully managed.
3. Loopp’s commitments
- Process personal data only on documented lawful instructions.
- Ensure authorised people are subject to confidentiality.
- Apply appropriate technical and organisational security measures.
- Assist with data-subject requests, security duties, breach response and impact assessments where reasonably possible.
- Provide information reasonably needed to demonstrate compliance and support proportionate audits.
- Notify the customer without undue delay after becoming aware of a qualifying personal-data breach.
4. Sub-processors
The customer gives general authorisation for Loopp to use sub-processors needed to operate the service, currently including Supabase, Cloudflare, OpenAI Sites and Resend. Loopp will impose appropriate data-protection obligations and provide reasonable notice of material changes so customers can raise a genuine data-protection objection.
5. International transfers
Loopp will not make a restricted transfer unless an adequacy regulation or an appropriate UK safeguard applies, together with any required assessment and supplementary measures.
6. End of service
At the customer’s choice, Loopp will return or delete customer personal data after the service ends, unless law requires retention. Data in protected backups may remain beyond immediate deletion but will be placed beyond normal use and removed through the applicable backup cycle.
7. Customer responsibilities
The customer determines lawful purposes, provides privacy information to individuals, manages user permissions, keeps account information accurate and gives lawful documented instructions.
Back to Loopp