Draft for review. Written under the law of England and Wales, not yet checked by a solicitor. Words in brackets are still to be filled in.

Privacy notice

What we collect about you on The Loop platform, why, who else handles it, how long we keep it, and your rights under UK data protection law (the UK GDPR and the Data Protection Act 2018).

1. Who is responsible

The Loop is run by [company legal name], registered in England and Wales under number [company number], at [registered address]. We are registered with the Information Commissioner's Office under number [ICO registration number]. Contact us about your data at [privacy contact email].

We have two roles:

  • For your programme (your answers, scores, conversation notes, project work and the reports about your company), your employer decides what the programme is for and we act on its behalf. Your employer is the controller and we are its processor, under a data processing agreement. Questions about how your employer uses your results are best asked of them; we will help.
  • For running the platform itself (your account, security, keeping the service working, monitoring how it is used, and talking to business contacts), we are the controller.

Drafting note: Confirm this split with a solicitor, especially for self-serve sign-ups and for consultancies that run programmes in their own workspace, who may be controllers or processors in their own right.

2. What we collect

  • Who you are at work: name, work email, job title, department, who you report to and whether you manage people. Usually from your employer; sometimes from you.
  • Your programme: questionnaire answers, scores and how they change, notes and transcripts from conversations with our consultants, insights drawn from them, your project plans and updates, posts in the community, and session attendance.
  • Trainers and consultants: profile, specialisms, availability, quotes, and ratings from completed work.
  • How you use the platform: pages visited, clicks, timings, device and browser type, and anonymised session recordings (see section 5).
  • Error reports when something breaks, without names, emails or what you typed.
  • Emails we send you and whether they were delivered.

We do not ask for special category data (such as health, religion or ethnicity). Please do not put it in free-text answers.

3. Why we use it, and our lawful basis

What forLawful basis
Running your programme: scoring, reports, coaching, projectsYour employer's legitimate interests in developing its people (we process on its behalf)
Your account, sign-in, invitations, reminders and notificationsLegitimate interests in providing a service your employer has asked for
Introducing vetted specialists when your company asks for delivery helpLegitimate interests; briefs are anonymised and your company is named only after your programme lead signs off
Security, preventing misuse, fixing errorsLegitimate interests in keeping the platform and your data safe
Monitoring and improving the platform with PostHogLegitimate interests in a service that works well; anonymised, and you can turn it off
Contracts with trainers and consultantsPerformance of a contract
Keeping records the law requires (such as invoices)Legal obligation

We do not make decisions about you that have legal or similarly significant effects using automated processing alone. Scores and AI summaries support the people running your programme; they do not replace them.

4. AI on the platform

Alfie, our assistant, and some summaries and themes are produced by AI models we reach through OpenRouter. To do that, the relevant text (for example a question you ask Alfie, or notes from a conversation) is sent to the model provider and the answer returned. We send only what the task needs.

Drafting note: Confirm OpenRouter's data policy settings for the account (no prompt logging, providers that do not train on inputs) before relying on this, then add a sentence saying so.

5. Monitoring with PostHog

We use PostHog to understand how the platform is used and to improve it. It is anonymised: you appear as a random reference number, never your name or email; your IP address is discarded; everything you type is masked in session recordings and your answers, notes and transcripts are hidden from them; recordings are deleted after 30 days. The data is held in the EU. It is on by default, and you can turn it off at any time on the cookies page.

6. Who else handles your data

We use these suppliers to run the platform. Each acts only on our instructions under a written contract.

SupplierWhat they doWhere
SupabaseDatabase, sign-in and file storageUK (London)
VercelHosting the platformUK (London), with a global network for delivery
ResendSending emailsUnited States
PostHogAnonymised product analytics and session recordingsEU (Germany)
SentryError reportsEU (Germany)
OpenRouter, and the AI model providers it routes to (Anthropic, OpenAI)AI features such as Alfie and summariesUnited States

Your answers are seen by you and the consultants working on your programme. Your company's programme leads and line managers see grouped results, not your individual answers, and company reports break results down only for groups of at least five people. A trainer or consultant chosen for work sees what that work needs. We never sell your data.

7. Transfers outside the UK

Where a supplier processes data outside the UK, we rely on UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework where the supplier is certified) or the ICO's International Data Transfer Agreement or Addendum, together with the supplier's security measures.

Drafting note: Check each US supplier's certification or transfer terms and list the mechanism per supplier.

8. How long we keep it

  • Your programme data is kept for as long as your employer has agreed with us. By default: if you are deactivated, it is erased after the number of days set for your company; when your company's programme closes, everything about the company is erased after the number of months set for it. We keep a log that something was erased, with no names.
  • Session recordings: 30 days. Error reports: up to 90 days.
  • Contracts and invoices: six years after the end of the financial year they relate to.

9. Your rights

You have the right to:

  • ask for a copy of your data, and have it corrected if it is wrong;
  • ask for it to be erased, or for its use to be restricted;
  • object to our use of it where we rely on legitimate interests, including the monitoring in section 5;
  • receive data you gave us in a portable format.

Email [privacy contact email]. For programme data we will pass your request to your employer, as the controller, and help them answer it. We reply within one month. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113, though we would like the chance to put it right first.

10. Keeping it safe

Data is encrypted in transit and at rest. Access is controlled row by row in the database, so people see only what their role allows. Staff access is limited to those who need it. Error reports and analytics are stripped of personal details before they leave the platform.

11. Changes

We will update this notice when how we use data changes, and tell programme leads about anything significant.

Draft of 6 October 2026 · © 2026 The Loop