Data controller: ROFFI Oy, Business ID 3500046-5, Vantaa, Finland
In Brief
Cloop is built and operated in Finland by ROFFI Oy. Your content and our databases are stored in the EU. We collect only what we need to run the service, we do not sell your data, and we do not use your content to train AI models.
For most of what Cloop does we are a processor, acting on our customers' instructions. There are two places where we decide the purpose ourselves and are therefore a controller: the company register (section 2.5) and identifying the organization behind a visitor's IP address (section 2.3.1). Those are the sections to read if you did not sign up for Cloop but have found yourself in our data.
Some processing involves providers outside the EEA — the Subprocessor List names each one and what it receives.
1. Who We Are
ROFFI Oy ("we", "us", "Cloop") is a Finnish customer experience consultancy that builds and operates the Cloop platform.
Our role depends on the data:
| Data | Our role |
|---|---|
| Your account and usage data | Controller |
| Visitor data collected through your Widget | Processor — you are the controller (see our DPA) |
| Outbound email you send through Cloop | Processor — you are the controller |
| The company register, including professional person data | Controller |
| Identifying the organization behind a visitor IP address | Controller |
Contact: Email: privacy@cloop.io Address: ROFFI Oy, Vantaa, Finland
We do not currently have a designated Data Protection Officer. For any data protection questions, contact privacy@cloop.io.
2. What Data We Collect
2.1 Account Data (You as a Customer)
| Data | Source | Purpose |
|---|---|---|
| Name, email, profile picture | Google OAuth (or other identity provider) | Account creation and authentication |
| Organization name | You provide during setup | Multi-tenant workspace |
| Role within tenant | Assigned by tenant owner | Access control |
| Preferences (theme, language) | You set in dashboard | Personalization |
| Email addresses of invited team members | You provide via team management | Sending invitations |
2.2 Content Data
| Data | Source | Purpose |
|---|---|---|
| Website pages (text, URLs, titles) | Crawled from your website | Building your knowledge base |
| Uploaded documents (PDF, DOCX, TXT, MD) | You upload | Building your knowledge base |
| Vector embeddings | Generated from your content | Enabling semantic search |
| Agent persona instructions | You configure | Customizing AI behavior |
| Widget settings (title, colors, language) | You configure | Widget appearance |
2.3 Visitor Data (Collected Through Your Widget)
When visitors interact with the chat widget on your website, we collect the following on your behalf (you are the data controller; we are the data processor):
| Data | Source | Purpose |
|---|---|---|
| Chat messages | Visitor types in widget | Generating AI responses |
| Visitor ID (random UUID) | Generated by widget, stored in visitor's browser (localStorage) | Recognizing returning visitors |
| Email address | Visitor provides voluntarily | Lead capture |
| Entry page URL | Browser | Context for conversation |
| Conversation phase | System-generated | Tracking conversation progression (discovery, value demonstration, lead capture, call-to-action) |
| Session metadata (timestamps, message count, lead status) | System-generated | Analytics and lead funnel |
| AI confidence scores | System-generated | Quality monitoring |
| Content source references | System-generated | Tracking which knowledge base content was cited in responses |
| Behavioral events (only when the customer enables Visitor Intelligence) | Widget | Pages viewed on the customer's site, time on page, scroll depth, chat interactions |
| Learned facts (only when the customer enables Visitor Intelligence) | AI analysis of chat and browsing | Sales context for the customer's team, personalization, lead scoring |
| Visitor-to-contact linkage | Email capture or personalized campaign link | Connecting a returning visitor to the customer's CRM contact |
| Lead scores and account summaries | System-generated | Prioritizing leads for the customer's team |
| Visitor IP address | Connection metadata | Identifying the organization behind the visit (see 2.3.1) |
We do not collect: precise geolocation, device fingerprints, or any browsing activity outside the single website where the widget is embedded. Activity on that website (pages viewed, time on page) is collected only where the website owner has enabled the Visitor Intelligence feature, and is described in their own privacy notice.
2.3.1 Company identification from IP address
When a visitor loads a customer's website, we attempt to identify the organization the visit comes from — not the individual. This is how a customer sees "someone from Acme Oy is on your pricing page".
- Country and city are resolved locally, from a database file on our own servers. No third party is contacted.
- The organization requires an external lookup. The IP address is sent to an IP-intelligence provider (ipapi.is, with IPLocate.io and ipinfo.io as fallbacks). These providers are outside the EEA — see the Subprocessor List.
- Results are cached for 12 hours, so a given address is looked up once rather than on every page view.
- Connections identified as consumer ISPs are discarded, because a home broadband address identifies a household, not a business.
- The result is company-level: organization name, domain, and whether the address belongs to a VPN or hosting provider. It is not used to identify a person.
Legal basis: legitimate interests (Art. 6(1)(f)) — identifying business visitors to a business website. Where a customer's configuration requires it, identification is gated on a recorded legal basis before it runs. A visitor can object; see section 9.
Previous versions of this policy stated that we did not collect visitor IP addresses beyond server logs. That was inaccurate once IP-based company identification shipped, and this section corrects it.
2.4 Demo/Trial Data
When a visitor uses the free trial on cloop.io:
| Data | Source | Purpose |
|---|---|---|
| Website URL pasted | Visitor provides | Crawling and demo |
| Email address | Visitor provides voluntarily | Lead follow-up |
| Demo chat messages | Visitor types | Demo experience |
Trial data is automatically deleted after 24 hours.
2.5 Company Register Data (Cloop as controller)
Separately from anything we process on a customer's behalf, Cloop maintains a company register — a database of companies, mostly Finnish, built from open registries and public company websites. Customers use it to find and research prospects.
For this register Cloop is the controller, not a processor. It is the one place in the product where we decide the purposes ourselves.
| Data | Source | Purpose |
|---|---|---|
| Company name, business ID, address, industry, revenue, website | Open registries (Finnish PRH, Traficom, EU VIES and similar) | Company search and firmographics |
| Company website content | Crawling the company's own public site | Firmographics and company summaries |
| Professional contact details of named individuals — name, job title, work email, work phone, public professional profile link | The company's own public website | Helping customers reach the right person at a company |
The last row is personal data, and it is governed separately and more strictly:
- Legal basis: legitimate interests (Art. 6(1)(f)), assessed in the Legitimate Interest Assessment.
- Limits: work-role fields only. No private-life data, no special categories. Email addresses are read from published pages, never constructed from a name.
- Retention: six months from last collection, enforced automatically.
- Provenance: every record stores where it came from and whether that source permits passing it on.
- Rights: individuals in the register have a dedicated notice — the Company Register Privacy Notice — and can object or request erasure at privacy@cloop.io without holding an account.
When a customer copies a register record into their own CRM, they become a controller for their copy and their own privacy notice governs it from that point.
2.6 Outbound Email Sent by Customers
Customers can send outbound email sequences through Cloop, using their own mailbox (Gmail, Microsoft 365, or another provider they connect). For this processing the customer is the controller and Cloop is the processor.
| Data | Source | Purpose |
|---|---|---|
| Recipient name, title, company, email | Customer's own CRM or the company register | Addressing and personalizing the message |
| Message content | Customer's templates, or AI-drafted from their brief | The email itself |
| Delivery and engagement events | Sending and tracking | Deliverability, reply handling, reporting |
| Suppression and do-not-contact lists | Customer configuration, replies, bounces | Ensuring people who opted out are not contacted again |
The recipient's name, title and employer are sent to our AI subprocessor when a message is drafted. Secret patterns are stripped first. Customers are responsible for having a lawful basis to contact their recipients; the Acceptable Use Policy sets out what we require.
Campaign recipient lists. A customer can also upload a list of campaign recipients (email address, and optionally name, company and the customer's own reference) and send each person a personal link to their website, for example in their own newsletter. Cloop processes this as the customer's processor. The list is stored encrypted and is matched only through a keyed digest of each person's link identifier. When a recipient opens their personal link and sends a message in the chat, Cloop records that this recipient arrived and links the conversation to them for the customer's campaign results. Opening the page without chatting records nothing. When the customer ends the campaign, personal links stop identifying anyone, and the list is deleted automatically after the retention period the customer sets (90 days unless changed). The customer can also delete the list at any time.
2.7 Technical and Usage Data
| Data | Source | Purpose |
|---|---|---|
| Server access logs (IP, user agent, timestamp) | Nginx | Security, debugging |
| API request metadata | Application | Rate limiting, abuse prevention |
| AI usage (model, token counts, cost) | Application | Budget enforcement |
| Audit log events (login, logout, settings changes) | Application | Security audit trail |
2.8 Marketing Website Visitors
Our marketing website, www.cloop.io, uses Google Tag Manager to load HubSpot's analytics and cookie banner. If you accept cookies in the banner, HubSpot records your visits for us: the page address and title, the page you came from, your browser language and screen size, HubSpot's cookie identifiers, and, as with any web request, your IP address and browser details. We use this to understand how the website is used.
Before you choose, and if you decline, HubSpot still counts each page view anonymously. It receives the same page and browser details and your IP address, but no cookie is set and nothing links one page view to the next, so your visits are not recognised as the same person. Google consent signals start as denied on every page. See our Cookie & Storage Policy for the full list.
This applies to our own website only. The Widget on customers' websites loads none of these tools.
3. Legal Basis for Processing (GDPR Article 6)
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Account management | Contract (Art. 6(1)(b)) | Necessary to provide the service you signed up for |
| Content processing (crawl, embed, search) | Contract (Art. 6(1)(b)) | Core service functionality |
| Visitor data processing | Contract (Art. 6(1)(b)) + your instructions as controller | We process as your data processor per the DPA |
| Security logging and abuse prevention | Legitimate interest (Art. 6(1)(f)) | Protecting the service and users |
| Demo/trial | Consent (Art. 6(1)(a)) | User initiates the trial voluntarily |
| Email communications about the service | Legitimate interest (Art. 6(1)(f)) | Service updates, security alerts |
| Company identification from visitor IP | Legitimate interest (Art. 6(1)(f)) | Identifying the organization visiting a business website. See 2.3.1 |
| Company register — company data | Not personal data | Companies are not natural persons |
| Company register — person data | Legitimate interest (Art. 6(1)(f)) | Assessed in the LIA; six-month retention; objection honoured without condition |
| Outbound email sent by customers | Controller is the customer | We process on their documented instructions under the DPA |
| Marketing website analytics with cookies (2.8) | Consent (Art. 6(1)(a)) | Given in the cookie banner; withdraw at any time from the cookie settings link in the site footer |
| Anonymous page counts on the marketing website (2.8) | Legitimate interest (Art. 6(1)(f)) | Knowing how the website is used, without cookies or anything that links page views together |
4. How We Use AI
4.1 AI Providers
We use Nebius AI Studio (Nebius B.V., Netherlands) for:
- Embedding generation — converting your content into vector representations for semantic search
- Chat response generation — producing answers to visitor questions based on your content
4.2 What We Send to AI Providers
When a visitor asks a question, we send:
- The visitor's question
- Relevant chunks of your content (retrieved via vector search)
- System instructions (persona, phase, language settings)
- Recent conversation history (within the same session)
- For sites where the customer has enabled Visitor Intelligence: conversation transcripts for fact extraction (secret patterns such as API keys and payment card numbers stripped before sending), and learned-fact summaries as conversation context
4.3 What We Do NOT Do
- We do not send visitor personal data (email, name) to AI providers
- We do not use your content or visitor conversations to train AI models
- We do not allow AI providers to use the data for model training (confirmed via Nebius AI Studio terms)
- We do not use AI to make automated decisions with legal or significant effects on individuals
5. Data Sharing
5.1 Subprocessors
We use third-party services to operate Cloop. Rather than repeat the list here and risk the two drifting apart, the authoritative version — who they are, what each receives, where they are, and the safeguards that apply — is the Subprocessor List.
In summary: hosting and storage in Finland, AI inference in the EU, sign-in providers, a web-search provider, and IP-intelligence providers for organization identification.
5.2 No Data Sales
We do not sell, rent or trade personal data.
One thing worth being precise about, because it could look like an exception. Cloop's customers pay for the Service, and the Service includes access to our company register. What they are paying for is the product; we do not operate a data-brokerage business, we do not sell the register or extracts of it to third parties, and we do not license it to other data vendors.
The register's professional contact data may not be resold or redistributed in bulk by customers either — see the Terms of Service §5.7. Individuals in the register can have their details removed at any time, which is not something a data broker's business model tolerates.
5.3 Sharing With Your Own Organization
Data inside your organization is visible according to the roles you assign. Members see the records they own; owners and admins see everything in the organization. This is your configuration, not our disclosure.
5.4 Legal Requirements
We may disclose data if required by Finnish or EU law, court order, or to protect the rights, safety, or property of our users or the public.
6. International Data Transfers
Everything we store stays in the EU. Your content, our databases, uploaded documents and backups are held on servers in Helsinki, Finland, and AI processing runs in EU data centres.
Some lookups leave the EEA. These are the exceptions, and they are limited:
| Processing | Provider location | What is sent |
|---|---|---|
| Identifying the organization behind a visitor IP (2.3.1) | USA | The IP address only |
| Web search during company enrichment | USA (Brave) | Company names and domains |
| Sign-in with GitHub, where a user chooses it | USA | Account identifiers |
| Marketing website analytics (2.8) | HubSpot account in its EU data region; HubSpot, Inc. is based in the USA | Page and browser details and the IP address; HubSpot cookie identifiers only with consent |
Nothing else is transferred. In particular, no chat content, no customer content, no documents and no CRM data leave the EU.
Where a transfer happens, we rely on the safeguards named for that provider in the Subprocessor List — Standard Contractual Clauses or an adequacy decision. If we add a new transfer we will update this policy and the subprocessor list, and notify customers 30 days in advance.
Previous versions of this policy said we did not transfer personal data outside the EU/EEA at all. That stopped being true when IP-based company identification shipped, and this section corrects it.
7. Data Retention
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Account data | Until you delete your account | Permanent deletion upon request |
| Content (pages, documents, embeddings) | Until you delete the content or your account | Permanent deletion |
| Visitor chat sessions | Until you delete them or your account | Permanent deletion |
| Lead data | Until you delete it or your account | Permanent deletion |
| Demo/trial data | 24 hours | Automatic deletion |
| Visitor behavioral events (Visitor Intelligence) | 90 days | Automatic deletion |
| Superseded learned-fact versions (Visitor Intelligence) | 12 months | Automatic deletion |
| Learned facts of never-identified visitors (Visitor Intelligence) | 12 months after last activity | Automatic deletion |
| Server access logs | 90 days | Automatic rotation |
| Audit logs | 12 months | Automatic rotation |
| AI usage logs | 12 months | Automatic rotation |
| IP-to-company lookup cache | 12 hours | Automatic expiry |
| Campaign recipient lists (2.6) | Until the customer deletes them, and at most the customer-set retention period (default 90 days) after the campaign ends | Automatic deletion |
| Website analytics cookies (HubSpot, 2.8) | 6 months in your browser | Expire automatically; delete them or withdraw consent at any time |
| Company register — person data | 6 months from last collection | Automatic nightly deletion, including the source page content it was extracted from |
| Company register — company data | Kept while the company is active in the register | Not personal data |
When you delete your account, all associated data (content, sessions, leads, settings) is permanently deleted within 30 days.
8. Data Security
We implement appropriate technical and organizational measures:
- Encryption in transit: TLS 1.2+ for all connections (HSTS enforced)
- Encryption at rest: Full-disk encryption on our servers
- Access control: Role-based access, JWT authentication with token revocation
- Multi-tenant isolation: All database queries scoped by tenant/site
- Input validation: Parameterized queries, SSRF protection, file type validation
- Rate limiting: Multi-tier rate limiting to prevent abuse
- Infrastructure hardening: Hardened service configuration, mandatory access control, minimal attack surface
- Audit logging: Structured logging of authentication and administrative events
- Budget controls: Daily AI cost cap preventing runaway expenses
For more detail, see our Security Overview document.
9. Your Rights (GDPR Articles 15-22)
As a data subject, you have the right to:
| Right | How to Exercise |
|---|---|
| Access your data | Email privacy@cloop.io or export from dashboard |
| Rectify inaccurate data | Edit in dashboard or email us |
| Erase your data ("right to be forgotten") | Delete your account, or email us for specific deletions |
| Restrict processing | Email privacy@cloop.io |
| Data portability | Email us for a machine-readable export |
| Object to processing | Email privacy@cloop.io |
| Withdraw consent | Where consent is the basis, withdraw anytime via dashboard or email |
We will respond within 30 days (extendable by 60 days for complex requests, with notice).
If you do not have a Cloop account
Most people covered by this policy never signed up for anything. Two cases in particular:
- You are in our company register. Your professional details may be listed because your employer published them. You can be removed permanently — email privacy@cloop.io and say so. No account, no form, no justification. Full detail in the Company Register Privacy Notice.
- You visited a website using Cloop's widget. The website owner is the controller for your chat and activity data, so contact them first; we will help them respond. For the IP-based company identification described in 2.3.1, where Cloop decides the purpose, you can object to us directly.
You do not need to prove who you are before we will act on a removal request. If we can identify the record from what you tell us, we will remove it. We ask for identification only where a request would disclose personal data to the requester, such as an access request.
If you believe we have violated your data protection rights, you may file a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu):
- Website: https://tietosuoja.fi/en
- Email: tietosuoja@om.fi
10. Cookies and Browser Storage
The Cloop dashboard and the embeddable Widget do not use cookies. Our marketing website uses HubSpot's analytics cookies only with your consent (2.8), and bot-protection cookies set for Calendly's and HubSpot's servers. The dashboard stores authentication tokens in localStorage. The embeddable Widget stores a random visitor identifier in localStorage (not cookies). All visitor interaction data (messages, session metadata, conversation phase) is stored server-side in our EU-hosted database. See our Cookie & Storage Policy for details.
11. Children
Cloop is a business-to-business service. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact privacy@cloop.io and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or dashboard notification at least 30 days before the effective date. The "Last updated" date at the top reflects the most recent revision.
Change history
| Date | Change |
|---|---|
| 2026-09-24 | Added campaign recipient lists and personal campaign links (2.6), with their retention. |
| 2026-09-22 | Added analytics on our marketing website (2.8): cookies only with consent, anonymous page counts without cookies otherwise; legal bases, where it is processed and how long its cookies last. |
| 2026-08-05 | Corrected the statement that we do not collect visitor IP addresses — we do, to identify the visiting organization (2.3.1). Added the company register as processing where Cloop is controller, including professional person data, its legal basis and six-month retention (2.5). Added outbound email sent by customers (2.6). Added a route for people without a Cloop account to exercise their rights. |
| 2026-06-11 | Visitor Intelligence: behavioral events, learned facts, identity linkage. |
| 2026-02-15 | Initial policy published. |
13. Contact
For any privacy-related questions or requests:
ROFFI Oy Vantaa, Finland Email: privacy@cloop.io
For security concerns: security@cloop.io