Cloop

Cloop Privacy Policy

Effective date: 2026-03-01 Last updated: 2026-02-15 Data controller: ROFFI Oy, Business ID 1234567-8, Vantaa, Finland


In Brief

Cloop is built and operated in Finland by ROFFI Oy. All data is stored and processed in the EU. We collect only what we need to run the service, we do not sell your data, and we do not use your content to train AI models. This policy explains the details.


1. Who We Are

ROFFI Oy ("we", "us", "Cloop") is a Finnish customer experience consultancy that builds and operates the Cloop platform. We are the data controller for your account and usage data, and data processor for visitor data collected through your Widget (see our DPA).

Contact: Email: privacy@cloop.io Address: ROFFI Oy, Vantaa, Finland

We do not currently have a designated Data Protection Officer. For any data protection questions, contact privacy@cloop.io.


2. What Data We Collect

2.1 Account Data (You as a Customer)

DataSourcePurpose
Name, email, profile pictureGoogle OAuth (or other identity provider)Account creation and authentication
Organization nameYou provide during setupMulti-tenant workspace
Role within tenantAssigned by tenant ownerAccess control
Preferences (theme, language)You set in dashboardPersonalization
Email addresses of invited team membersYou provide via team managementSending invitations

2.2 Content Data

DataSourcePurpose
Website pages (text, URLs, titles)Crawled from your websiteBuilding your knowledge base
Uploaded documents (PDF, DOCX, TXT, MD)You uploadBuilding your knowledge base
Vector embeddingsGenerated from your contentEnabling semantic search
Bot persona instructionsYou configureCustomizing AI behavior
Widget settings (title, colors, language)You configureWidget appearance

2.3 Visitor Data (Collected Through Your Widget)

When visitors interact with the chat widget on your website, we collect the following on your behalf (you are the data controller; we are the data processor):

DataSourcePurpose
Chat messagesVisitor types in widgetGenerating AI responses
Visitor ID (random UUID)Generated by widget, stored in visitor's browser (localStorage)Recognizing returning visitors
Email addressVisitor provides voluntarilyLead capture
Entry page URLBrowserContext for conversation
Conversation phaseSystem-generatedTracking conversation progression (discovery, value demonstration, lead capture, call-to-action)
Session metadata (timestamps, message count, lead status)System-generatedAnalytics and lead funnel
AI confidence scoresSystem-generatedQuality monitoring
Content source referencesSystem-generatedTracking which knowledge base content was cited in responses

We do not collect: IP addresses of widget visitors (beyond standard server logs), precise geolocation, device fingerprints, or browsing history.

2.4 Demo/Trial Data

When a visitor uses the free trial on cloop.io:

DataSourcePurpose
Website URL pastedVisitor providesCrawling and demo
Email addressVisitor provides voluntarilyLead follow-up
Demo chat messagesVisitor typesDemo experience

Trial data is automatically deleted after 24 hours.

2.5 Technical and Usage Data

DataSourcePurpose
Server access logs (IP, user agent, timestamp)NginxSecurity, debugging
API request metadataApplicationRate limiting, abuse prevention
AI usage (model, token counts, cost)ApplicationBudget enforcement
Audit log events (login, logout, settings changes)ApplicationSecurity audit trail

3. Legal Basis for Processing (GDPR Article 6)

Processing ActivityLegal BasisDetails
Account managementContract (Art. 6(1)(b))Necessary to provide the service you signed up for
Content processing (crawl, embed, search)Contract (Art. 6(1)(b))Core service functionality
Visitor data processingContract (Art. 6(1)(b)) + your instructions as controllerWe process as your data processor per the DPA
Security logging and abuse preventionLegitimate interest (Art. 6(1)(f))Protecting the service and users
Demo/trialConsent (Art. 6(1)(a))User initiates the trial voluntarily
Email communications about the serviceLegitimate interest (Art. 6(1)(f))Service updates, security alerts

4. How We Use AI

4.1 AI Providers

We use Nebius AI Studio (Nebius B.V., Netherlands) for:

4.2 What We Send to AI Providers

When a visitor asks a question, we send:

4.3 What We Do NOT Do


5. Data Sharing

5.1 Subprocessors

We use the following third-party services to operate Cloop (see Subprocessor List for details):

SubprocessorPurposeLocation
Hetzner Online GmbHServer hosting, object storageHelsinki, Finland (EU)
Nebius B.V.AI inference (embeddings, LLM)EU data centers
Let's EncryptTLS certificatesGlobal (no personal data)

5.2 No Data Sales

We do not sell, rent, or trade personal data to anyone.

5.3 Legal Requirements

We may disclose data if required by Finnish or EU law, court order, or to protect the rights, safety, or property of our users or the public.


6. International Data Transfers

All data is stored and processed within the EU/EEA:

We do not transfer personal data outside the EU/EEA. If this changes in the future (e.g., adding a CDN or analytics provider), we will update this policy and ensure appropriate safeguards (Standard Contractual Clauses or adequacy decision) are in place.


7. Data Retention

Data TypeRetention PeriodDeletion Method
Account dataUntil you delete your accountPermanent deletion upon request
Content (pages, documents, embeddings)Until you delete the content or your accountPermanent deletion
Visitor chat sessionsUntil you delete them or your accountPermanent deletion
Lead dataUntil you delete it or your accountPermanent deletion
Demo/trial data24 hoursAutomatic deletion
Server access logs90 daysAutomatic rotation
Audit logs12 monthsAutomatic rotation
AI usage logs12 monthsAutomatic rotation

When you delete your account, all associated data (content, sessions, leads, settings) is permanently deleted within 30 days.


8. Data Security

We implement appropriate technical and organizational measures:

For more detail, see our Security Overview document.


9. Your Rights (GDPR Articles 15-22)

As a data subject, you have the right to:

RightHow to Exercise
Access your dataEmail privacy@cloop.io or export from dashboard
Rectify inaccurate dataEdit in dashboard or email us
Erase your data ("right to be forgotten")Delete your account, or email us for specific deletions
Restrict processingEmail privacy@cloop.io
Data portabilityEmail us for a machine-readable export
Object to processingEmail privacy@cloop.io
Withdraw consentWhere consent is the basis, withdraw anytime via dashboard or email

We will respond within 30 days (extendable by 60 days for complex requests, with notice).

If you believe we have violated your data protection rights, you may file a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu):


10. Cookies and Browser Storage

Cloop does not use cookies. The dashboard stores authentication tokens in localStorage. The embeddable Widget stores a random visitor identifier in localStorage (not cookies). All visitor interaction data (messages, session metadata, conversation phase) is stored server-side in our EU-hosted database. See our Cookie & Storage Policy for details.


11. Children

Cloop is a business-to-business service. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact privacy@cloop.io and we will delete it.


12. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or dashboard notification at least 30 days before the effective date. The "Last updated" date at the top reflects the most recent revision.


13. Contact

For any privacy-related questions or requests:

ROFFI Oy Vantaa, Finland Email: privacy@cloop.io

For security concerns: security@cloop.io