Cloop
Discovery Agent Etsii teille sopivat yritykset Outbound Agent Oma viesti jokaiselle vastaanottajalle Inbound Agent Tunnistaa kävijän ja avaa keskustelun CRM Yritykset, ihmiset ja kaupat yhdessä Booking Agent Chat-keskustelusta myyjän kalenteriin Analytiikka Mitä asiakashankinta maksaa Tietosuoja EU ja yksityisyys keskiössä Seuraava siirto Kertoo mitä tehdä seuraavaksi

Aloita pilotti

Käyttöönotto 2 viikkoa. Kolme kuukautta tuottavuuden kasvua ilman sitoutumista.

Varaa demo
Resurssit
Meistä
ManifestiMiksi Cloop on olemassa UraAvoimet paikat
Sisältö
BlogiKestomanteinen sisältö MuutoslokiProduct moves fast
Hinnoittelu
Kirjaudu
Varaa demo Aloita ilmaiseksi
Cloop
Ominaisuudet
Discovery Agent Etsii teille sopivat yritykset Outbound Agent Oma viesti jokaiselle vastaanottajalle Inbound Agent Tunnistaa kävijän ja avaa keskustelun CRM Yritykset, ihmiset ja kaupat yhdessä Booking Agent Chat-keskustelusta myyjän kalenteriin Analytiikka Mitä asiakashankinta maksaa Tietosuoja EU ja yksityisyys keskiössä Seuraava siirto Kertoo mitä tehdä seuraavaksi
Resurssit
Manifesti Miksi Cloop on olemassa Ura Avoimet paikat Blogi Kestomanteinen sisältö Muutosloki Product moves fast
Hinnoittelu Legal
Aloita ilmaiseksi Kirjaudu Cloopiin
← Kaikki legal-dokumentit
Kolmannet osapuolet

Subprocessor List

Viimeksi päivitetty: 3.8.2026

How to Read This List

A subprocessor is any third party that processes personal data on our behalf when we deliver the service. This list names all of them. It is grouped by whether a service is always in use or only runs once you switch something on, because that difference decides whether it belongs in your own record of processing.

  • Always in use. Running Cloop at all means these process data.
  • On when you enable it. Off until an administrator connects the integration or turns the feature on.
  • Company data sources. Queried while we build and enrich company records. Most receive a business identifier or a domain name, not a person.

If a service is not on this list, we do not send it your data. See What We Do Not Use for the ones customers ask about most often.

Always in Use

SubprocessorPurposeData receivedLocationSafeguards
Hetzner Online GmbH Servers, database, object storage for uploaded documents, backups All service data Finland and Germany (EU) Hetzner DPA, German company, EU data centres
Nebius B.V. AI inference: chat replies, embeddings, reranking, classification, drafted messages Message text, passages from your own content, system instructions Netherlands (EU) Nebius AI Studio terms; input and output not used for model training and not retained after the response
DB-IP City-level IP database, downloaded to our servers once a month Nothing. Lookups run locally against the downloaded file Download only No personal data leaves our infrastructure
Let's Encrypt (ISRG) TLS certificates Domain names only Global No personal data processed

Nebius B.V.

  • What we send: the message text, the relevant passages from your own content, and our system instructions.
  • What we do not send: visitor email addresses, visitor identifiers, account credentials.
  • Retention: transient processing only. Nebius does not store input or output after generating the response.
  • Model training: Nebius does not use API data to train models.
  • Why them: an EU company with EU data centres, so model calls do not leave the EU.

On When You Enable It

Each of these is off until someone in your organisation connects it. Connecting one is your decision, and you can disconnect it at any time.

Signing in

SubprocessorPurposeData receivedLocation
GoogleSign in with Google (OpenID Connect)Name, email address, profile pictureEU / US
Microsoft (Entra ID)Sign in with MicrosoftName, email addressEU / US
GitHubSign in with GitHubName, email addressUS

You only meet these if your organisation chooses that sign-in method. Authentication happens at your existing identity provider; we never receive your password.

Calendar and booking

SubprocessorPurposeData receivedLocation
Google Calendar and Google MeetReading free and busy times, creating meetings and video linksMeeting time, participants, meeting subjectEU / US
CalendlyBooking through your own Calendly accountMeeting time, participant name and email addressUS
Cal.comBooking through your own Cal.com accountMeeting time, participant name and email addressEU or US, depending on your Cal.com account

CRM

SubprocessorPurposeData receivedLocation
HubSpotTwo-way sync of contacts and companiesContact name, email address, company detailsEU / US

HubSpot is the only CRM with a working sync today. Pipedrive, Salesforce and Dynamics are not connected.

Voice

SubprocessorPurposeData receivedLocation
ElevenLabsSpeech to text and text to speech in the voice widgetThe visitor's audio and the assistant's reply textUS

Voice is off by default on every site. If you turn it on, visitor audio leaves to ElevenLabs, and your own visitor notice needs to say so.

Identifying visiting companies

SubprocessorPurposeData receivedLocation
ipapi.isResolving a visitor's IP address to a companyThe visitor's IP addressEU
iplocate.ioThe same, used when the first lookup returns nothingThe visitor's IP addressUS

Visitor identification is off by default. It is set per site and requires you to choose a legal basis, either consent or legitimate interest. Global Privacy Control is honoured either way. While identification is off, no visitor IP address leaves our servers.

Sending email

Cloop uses no bulk email service. Mail leaves in one of two ways:

  • Service email such as invitations and notifications goes through our own SMTP relay.
  • Sales email goes from your own mailbox. Each seller connects their own account, and messages are sent and read directly through it. For most customers that mailbox is Google Workspace or Microsoft 365, in which case your existing provider carries the mail under your own agreement with them.

Company Data Sources

These are queried while building and enriching company records. They receive a business identifier, a company name or a domain, and most of them are public registers.

SourcePurposeLocation
PRH and YTJ, avoindata.prh.fiFinnish trade register: company details, addresses, financial statementsFinland (EU)
Traficom, odata.domain.fiRegister of .fi domainsFinland (EU)
BrønnøysundregistreneNorwegian company registerNorway (EEA)
CVR, cvrapi.dkDanish company registerDenmark (EU)
European Commission, VIESVAT number validationEU
GLEIFLegal Entity Identifier recordsGlobal
WikidataHeadcount, logo, public social media accountsGlobal
OpenCorporatesRegisters for countries we have no direct connection toUnited Kingdom
Brave SearchWeb search for company informationEU / US
ClearoutResolving a company name to a domainEU / India
crt.shFinding domains from certificate transparency logsGlobal

These queries concern companies rather than named people. Where a sole trader's business details are also personal data, the same rights apply as to anything else we hold.

What We Do Not Use

To be explicit, we do not use:

  • Google Analytics or any other visitor analytics service
  • Advertising platforms such as Meta or Google Ads
  • Bulk email services such as Mailchimp, SendGrid or Resend
  • Error tracking services such as Sentry
  • Customer support platforms such as Intercom or Zendesk
  • A payment processor. Subscriptions are agreed and invoiced directly, and no card details are processed anywhere in the service

If we add any of these, this list is updated and customers are notified as described below.

Your Own AI Keys

You may supply your own OpenAI or Anthropic API key, in which case model calls for your workspace go to that provider under your own agreement with them. This stays off unless you add a key. Nothing goes to OpenAI or Anthropic otherwise.

Changes to This List

We notify customers at least 30 days before a new subprocessor begins processing data, by:

  • email to account owners
  • a notice in the dashboard
  • an update to this document

If you object to a new subprocessor, you may terminate the affected service within 30 days of the notice, as set out in the DPA.

Change History

DateChange
2026-08-03Rewritten against the shipping code. Added the identity providers, Calendly, Cal.com, HubSpot, ElevenLabs, the visitor identification services and the company data sources, all of which were in use but unlisted. Recorded that no payment processor is in use.
2026-02-15Initial list published

Contact

Questions about our subprocessors: privacy@cloop.io

Kysyttävää tästä dokumentista? Vastaamme 48 tunnin sisällä, suoraan Tapiolta. tapio@cloop.io

Cloop

Rakennettu Suomen kaupparekisterin päälle.

Ominaisuudet
  • Discovery Agent
  • Outbound Agent
  • Inbound Agent
  • CRM
  • Booking Agent
  • Analytiikka
  • Tietosuoja
  • Seuraava siirto
Resurssit
  • Manifesti
  • Ura
  • Blogi
  • Muutosloki
  • Hinnoittelu
  • Varaa demo
Yhteys
  • tapio@cloop.io
Trust · Legal
  • Trust center
  • Kaikki dokumentit
  • DPA
  • Tietosuoja
  • Käyttöehdot
  • Evästeet
  • Sub-processorit
  • Security
Cloop on ROFFI Oy:n tuote · Y-tunnus 3500046-5 · Helsinki · Rakennettu Euroopassa Tietosuoja Evästeet Käyttöehdot Legal