Cloop
Discovery Agent Etsii teille sopivat yritykset Outbound Agent Oma viesti jokaiselle vastaanottajalle Inbound Agent Tunnistaa kävijän ja avaa keskustelun CRM Yritykset, ihmiset ja kaupat yhdessä Booking Agent Chat-keskustelusta myyjän kalenteriin Analytiikka Mitä asiakashankinta maksaa Tietosuoja EU ja yksityisyys keskiössä Seuraava siirto Kertoo mitä tehdä seuraavaksi

Aloita pilotti

Käyttöönotto 2 viikkoa. Kolme kuukautta tuottavuuden kasvua ilman sitoutumista.

Varaa demo
Resurssit
Meistä
ManifestiMiksi Cloop on olemassa UraAvoimet paikat
Sisältö
BlogiKestomanteinen sisältö MuutoslokiProduct moves fast
Hinnoittelu
Kirjaudu
Varaa demo Aloita ilmaiseksi
Cloop
Ominaisuudet
Discovery Agent Etsii teille sopivat yritykset Outbound Agent Oma viesti jokaiselle vastaanottajalle Inbound Agent Tunnistaa kävijän ja avaa keskustelun CRM Yritykset, ihmiset ja kaupat yhdessä Booking Agent Chat-keskustelusta myyjän kalenteriin Analytiikka Mitä asiakashankinta maksaa Tietosuoja EU ja yksityisyys keskiössä Seuraava siirto Kertoo mitä tehdä seuraavaksi
Resurssit
Manifesti Miksi Cloop on olemassa Ura Avoimet paikat Blogi Kestomanteinen sisältö Muutosloki Product moves fast
Hinnoittelu Legal
Aloita ilmaiseksi Kirjaudu Cloopiin
← Kaikki legal-dokumentit
GDPR-tietosuojaseloste

Privacy Policy

Viimeksi päivitetty: 15.2.2026

In Brief

Cloop is built and operated in Finland by ROFFI Oy. All data is stored and processed in the EU. We collect only what we need to run the service, we do not sell your data, and we do not use your content to train AI models. This policy explains the details.

1. Who We Are

ROFFI Oy ("we", "us", "Cloop") is a Finnish customer experience consultancy that builds and operates the Cloop platform. We are the data controller for your account and usage data, and data processor for visitor data collected through your Widget (see our DPA).

Contact:

  • Email: privacy@cloop.io
  • Address: ROFFI Oy, Vantaa, Finland

We do not currently have a designated Data Protection Officer. For any data protection questions, contact privacy@cloop.io.

2. What Data We Collect

2.1 Account Data (You as a Customer)

DataSourcePurpose
Name, email, profile pictureGoogle OAuth (or other identity provider)Account creation and authentication
Organization nameYou provide during setupMulti-tenant workspace
Role within tenantAssigned by tenant ownerAccess control
Preferences (theme, language)You set in dashboardPersonalization
Email addresses of invited team membersYou provide via team managementSending invitations

2.2 Content Data

DataSourcePurpose
Website pages (text, URLs, titles)Crawled from your websiteBuilding your knowledge base
Uploaded documents (PDF, DOCX, TXT, MD)You uploadBuilding your knowledge base
Vector embeddingsGenerated from your contentEnabling semantic search
Agent persona instructionsYou configureCustomizing AI behavior
Widget settings (title, colors, language)You configureWidget appearance

2.3 Visitor Data (Collected Through Your Widget)

When visitors interact with the chat widget on your website, we collect the following on your behalf (you are the data controller; we are the data processor):

DataSourcePurpose
Chat messagesVisitor types in widgetGenerating AI responses
Visitor ID (random UUID)Generated by widget, stored in visitor's browser (localStorage)Recognizing returning visitors
Email addressVisitor provides voluntarilyLead capture
Entry page URLBrowserContext for conversation
Conversation phaseSystem-generatedTracking conversation progression (discovery, value demonstration, lead capture, call-to-action)
Session metadata (timestamps, message count, lead status)System-generatedAnalytics and lead funnel
AI confidence scoresSystem-generatedQuality monitoring
Content source referencesSystem-generatedTracking which knowledge base content was cited in responses

We do not collect: IP addresses of widget visitors (beyond standard server logs), precise geolocation, device fingerprints, or browsing history.

2.4 Demo/Trial Data

When a visitor uses the free trial on cloop.io:

DataSourcePurpose
Website URL pastedVisitor providesCrawling and demo
Email addressVisitor provides voluntarilyLead follow-up
Demo chat messagesVisitor typesDemo experience

Trial data is automatically deleted after 24 hours.

2.5 Technical and Usage Data

DataSourcePurpose
Server access logs (IP, user agent, timestamp)NginxSecurity, debugging
API request metadataApplicationRate limiting, abuse prevention
AI usage (model, token counts, cost)ApplicationBudget enforcement
Audit log events (login, logout, settings changes)ApplicationSecurity audit trail

3. Legal Basis for Processing (GDPR Article 6)

Processing ActivityLegal BasisDetails
Account managementContract (Art. 6(1)(b))Necessary to provide the service you signed up for
Content processing (crawl, embed, search)Contract (Art. 6(1)(b))Core service functionality
Visitor data processingContract (Art. 6(1)(b)) + your instructions as controllerWe process as your data processor per the DPA
Security logging and abuse preventionLegitimate interest (Art. 6(1)(f))Protecting the service and users
Demo/trialConsent (Art. 6(1)(a))User initiates the trial voluntarily
Email communications about the serviceLegitimate interest (Art. 6(1)(f))Service updates, security alerts

4. How We Use AI

4.1 AI Providers

We use Nebius AI Studio (Nebius B.V., Netherlands) for:

  • Embedding generation, converting your content into vector representations for semantic search
  • Chat response generation, producing answers to visitor questions based on your content

4.2 What We Send to AI Providers

When a visitor asks a question, we send:

  • The visitor's question
  • Relevant chunks of your content (retrieved via vector search)
  • System instructions (persona, phase, language settings)
  • Recent conversation history (within the same session)

4.3 What We Do NOT Do

  • We do not send visitor personal data (email, name) to AI providers
  • We do not use your content or visitor conversations to train AI models
  • We do not allow AI providers to use the data for model training (confirmed via Nebius AI Studio terms)
  • We do not use AI to make automated decisions with legal or significant effects on individuals

5. Data Sharing

5.1 Subprocessors

We use the following third-party services to operate Cloop (see Subprocessor List for details):

SubprocessorPurposeLocation
Hetzner Online GmbHServer hosting, object storageHelsinki, Finland (EU)
Nebius B.V.AI inference (embeddings, LLM)EU data centers
Let's EncryptTLS certificatesGlobal (no personal data)

5.2 No Data Sales

We do not sell, rent, or trade personal data to anyone.

5.3 Legal Requirements

We may disclose data if required by Finnish or EU law, court order, or to protect the rights, safety, or property of our users or the public.

6. International Data Transfers

All data is stored and processed within the EU/EEA:

  • Server infrastructure: Hetzner Helsinki, Finland
  • AI processing: Nebius EU data centers
  • Database: Self-managed on our Finnish server

We do not transfer personal data outside the EU/EEA. If this changes in the future (e.g., adding a CDN or analytics provider), we will update this policy and ensure appropriate safeguards (Standard Contractual Clauses or adequacy decision) are in place.

7. Data Retention

Data TypeRetention PeriodDeletion Method
Account dataUntil you delete your accountPermanent deletion upon request
Content (pages, documents, embeddings)Until you delete the content or your accountPermanent deletion
Visitor chat sessionsUntil you delete them or your accountPermanent deletion
Lead dataUntil you delete it or your accountPermanent deletion
Demo/trial data24 hoursAutomatic deletion
Server access logs90 daysAutomatic rotation
Audit logs12 monthsAutomatic rotation
AI usage logs12 monthsAutomatic rotation

When you delete your account, all associated data (content, sessions, leads, settings) is permanently deleted within 30 days.

8. Data Security

We implement appropriate technical and organizational measures:

  • Encryption in transit: TLS 1.2+ for all connections (HSTS enforced)
  • Encryption at rest: Full-disk encryption on our servers
  • Access control: Role-based access, JWT authentication with token revocation
  • Multi-tenant isolation: All database queries scoped by tenant/site
  • Input validation: Parameterized queries, SSRF protection, file type validation
  • Rate limiting: Multi-tier rate limiting to prevent abuse
  • Infrastructure hardening: Hardened service configuration, mandatory access control, minimal attack surface
  • Audit logging: Structured logging of authentication and administrative events
  • Budget controls: Daily AI cost cap preventing runaway expenses

For more detail, see our Security Overview document.

9. Your Rights (GDPR Articles 15-22)

As a data subject, you have the right to:

RightHow to Exercise
Access your dataEmail privacy@cloop.io or export from dashboard
Rectify inaccurate dataEdit in dashboard or email us
Erase your data ("right to be forgotten")Delete your account, or email us for specific deletions
Restrict processingEmail privacy@cloop.io
Data portabilityEmail us for a machine-readable export
Object to processingEmail privacy@cloop.io
Withdraw consentWhere consent is the basis, withdraw anytime via dashboard or email

We will respond within 30 days (extendable by 60 days for complex requests, with notice).

If you believe we have violated your data protection rights, you may file a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu):

  • Website: https://tietosuoja.fi/en
  • Email: tietosuoja@om.fi

10. Cookies and Browser Storage

Cloop does not use cookies. The dashboard stores authentication tokens in localStorage. The embeddable Widget stores a random visitor identifier in localStorage (not cookies). All visitor interaction data (messages, session metadata, conversation phase) is stored server-side in our EU-hosted database. See our Cookie & Storage Policy for details.

11. Children

Cloop is a business-to-business service. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact privacy@cloop.io and we will delete it.

12. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or dashboard notification at least 30 days before the effective date. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For any privacy-related questions or requests:

ROFFI Oy
Vantaa, Finland
Email: privacy@cloop.io

For security concerns: security@cloop.io

Kysyttävää tästä dokumentista? Vastaamme 48 tunnin sisällä, suoraan Tapiolta. tapio@cloop.io

Cloop

Rakennettu Suomen kaupparekisterin päälle.

Ominaisuudet
  • Discovery Agent
  • Outbound Agent
  • Inbound Agent
  • CRM
  • Booking Agent
  • Analytiikka
  • Tietosuoja
  • Seuraava siirto
Resurssit
  • Manifesti
  • Ura
  • Blogi
  • Muutosloki
  • Hinnoittelu
  • Varaa demo
Yhteys
  • tapio@cloop.io
Trust · Legal
  • Trust center
  • Kaikki dokumentit
  • DPA
  • Tietosuoja
  • Käyttöehdot
  • Evästeet
  • Sub-processorit
  • Security
Cloop on ROFFI Oy:n tuote · Y-tunnus 3500046-5 · Helsinki · Rakennettu Euroopassa Tietosuoja Evästeet Käyttöehdot Legal