Privacy Policy
Effective: 2026-09-18
1. Introduction
Looptro (the “Service”) is a retrospective tool for engineering teams. The Service is operated by Looptro (TBD legal entity) (“Looptro”), which acts as the data controller for the Personal Data described in this Privacy Policy except where it acts as a processor on behalf of a Team, as set out in section 11.
This Privacy Policy describes the Personal Data Looptro collects, the purposes for which it is processed, the lawful bases on which Looptro relies, the periods for which Personal Data is retained, the parties with which Personal Data is shared, and the rights available to individuals whose data is processed. Where a specific legal provision is relevant, it is cited inline.
Throughout this document, “Personal Data” means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the UK GDPR and EU GDPR. “User” means an individual who creates an Account and accesses the Service. “Account” means the credentials and profile associated with a User. “Team” means a workspace created within the Service to which one or more Users belong. “Subprocessor” means a third party engaged by Looptro to process Personal Data on its behalf.
Questions about this Privacy Policy, and requests to exercise any of the rights described below, may be directed to privacy@looptro.dev. Where Looptro (TBD legal entity) has appointed a Data Protection Officer, they may be contacted at .
2. Who we are
Looptro is provided by Looptro (TBD legal entity), the entity responsible for determining the purposes and means of processing the Personal Data described in this Privacy Policy. References in this Privacy Policy to “Looptro” should be read as references to Looptro (TBD legal entity) in its capacity as operator of the Service.
3. Personal Data collected
Looptro collects only the Personal Data required to operate the Service. The categories of Personal Data processed are described below.
Account Data comprises the email address and display name provided by the User at registration, together with the User’s password (stored only in irreversible, salted, hashed form using industry-standard hashing; Looptro never holds the password in plaintext and cannot recover it).
Retrospective Content comprises the posts, votes, comments, and action items that Users and their teammates contribute during retrospectives. Retrospective Content is associated with the Account of its author and with the Team in which it was created.
Session Records comprise the records that allow a User to remain signed in across visits without re-entering their password. Each Session Record is associated with the User’s Account and is created when the User signs in.
Security-Event Records comprise records of significant Account events: sign-in, sign-out, password change, role change, deletion, anonymous-participant join, anonymous-participant self-erase, and similar events. These records are used to investigate suspected abuse, account takeover, and other security incidents. For anonymous-participant events the record carries the participant identifier and the affected retrospective; for events triggered by a registered User the record carries the User identifier.
Network and Device Information comprises the User’s IP address and browser user-agent string at the time a Session Record is created. This information is recorded alongside the Session Record and is used solely to detect unusual sign-in activity and possible session hijacking. It is not used for analytics, profiling, or marketing.
Team Membership Records comprise the association between a User’s Account and the Teams to which the User belongs, together with the role held within each Team.
Looptro does not seek to collect special-category data within the meaning of Article 9 of the UK GDPR and EU GDPR. Users are asked not to place special-category data into Retrospective Content.
Data obtained from other individuals. In one circumstance Looptro obtains Personal Data about a person from someone other than that person: where a Team administrator invites a new participant to a Team, Looptro receives the invitee’s email address from the administrator in order to deliver the invitation. Where Looptro processes Personal Data obtained in this indirect way, it provides the information required by Article 14 of the UK GDPR and EU GDPR through this Privacy Policy, a link to which is included in the invitation. The categories of Personal Data obtained in this way are limited to the invitee’s email address and the identity of the Team to which they have been invited.
4. Lawful basis for processing
Looptro relies on the following lawful bases under Article 6(1) of the UK GDPR and EU GDPR.
Processing of Account Data, Retrospective Content, Team Membership Records, and Session Records is necessary for the performance of the contract between the User and Looptro under Article 6(1)(b); without this Personal Data, Looptro cannot authenticate the User, present their workspace, or deliver the Service for which they registered.
Processing of Security-Event Records and the Network and Device Information associated with Session Records is carried out in reliance on Looptro’s legitimate interests under Article 6(1)(f), namely the interest in keeping the Service secure, detecting and investigating abuse, and preventing account takeover. Looptro has assessed this interest against the rights and freedoms of the individuals concerned and considers the processing proportionate, given that the data is retained for limited periods (see section 6), is not used for any secondary purpose, and is necessary to protect Users from intrusion.
5. How Personal Data is used
Personal Data collected through the Service is used to (i) provide the Service to the User and the User’s Team; (ii) authenticate the User and maintain the User’s signed-in session; (iii) protect the Service against abuse, intrusion, and account takeover; (iv) respond to support enquiries; and (v) comply with applicable legal obligations.
Personal Data is not sold to any third party. Personal Data is not shared with advertisers, data brokers, or any party for behavioural-advertising purposes. Looptro does not build marketing profiles of Users and does not subject Users to automated decision-making producing legal or similarly significant effects within the meaning of Article 22 of the UK GDPR and EU GDPR. Retrospective Content is not used to train artificial-intelligence or machine-learning models.
6. Data retention
Looptro retains Personal Data only for as long as it is necessary for the purposes for which it was collected, or for as long as required by applicable law. The specific retention periods applied are as follows.
Account Data is retained until the User deletes their Account. Retrospective Content is retained as part of the relevant Team’s data and may be deleted by the Team owner at any time. Session Records, together with the Network and Device Information associated with them, are retained for 30 days past expiry, after which they are purged. Security-Event Records are retained for 2 years. Team Membership Records are retained until the User leaves the Team or deletes their Account.
Anonymous-participation identities for guests joining a retrospective without an Account are retained for 90 days after the retrospective closes and then deleted. While the guest’s session cookie remains valid, the guest may also remove their own contributions at any time through the “Leave retro” action on the retrospective page; that erasure deletes the guest’s posts and votes immediately and clears their session cookie.
Anonymous retrospectives — retrospectives created via the “Start a retro” entry on the marketing site, with no Account required — are retained for 24 hours from the moment they are created, after which they are deleted automatically together with all their content. The 24-hour window is fixed at creation; activity inside the retrospective does not extend it. The creator of an anonymous retrospective may, at any point during its life, save it permanently to a Team by signing up for a paid plan from inside the retrospective; from that point the saved retrospective follows the standard team-owned retention rules above. A signed-in User following the share link to an anonymous retrospective is prompted to save it to a Team they administer, or to sign out and join as a guest. Anonymous retrospectives are the entire free tier; no Account is created for them and no Personal Data beyond the chosen display name is collected.
The claim of an anonymous retrospective to a Team is recorded as a Security-Event Record (retro.claimed_from_anonymous) carrying the original creator-participant identifier so the lineage of the retrospective is preserved in the audit log under the standard 2 years retention. Security-Event Records referencing a deleted anonymous retrospective remain in the audit log for the standard 2 years window, in the same way that the audit history of a deleted retrospective survives the retrospective itself.
Account deletion is confirmed by email. The request made in Settings sends a confirmation link to the email address on the Account, and nothing is deleted until that link is used; the link is valid for one hour and may be used once, and the same message carries a link that cancels the request. Once confirmed, account deletion results in the permanent removal of the User’s Account Data and Session Records. Retrospective Content authored by the deleted User remains in the Team’s retrospectives so that the Team’s collective record is preserved, but the authorship link is severed (the author identifier is set to null). The same approach applies to any action items owned by the deleted User. Where the deleted User was the sole owner and the only member of a Team, that Team is deleted together with the Account, and all of its retrospectives, posts, votes, and action items are deleted with it; no other person holds a record in such a Team. Where a Team has other members, the User must first transfer ownership, and the Team and its content are unaffected by the deletion.
7. Cookies and similar technologies
Looptro sets three cookies, all of which are strictly necessary for the Service to function. Under Regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR), strictly necessary cookies do not require prior consent, but their use must be disclosed. The cookies set by the Service are described in the table below. All three cookies are first-party (set by the Service’s own domain), and none is used for analytics, marketing, or any third-party purpose.
| Cookie | Purpose | Retention | Lawful basis |
|---|---|---|---|
access_token |
Authenticates each request the User makes to the Service. | 15 minutes | Strictly necessary (PECR Reg. 6(4)) |
refresh_token |
Issues a new short-lived access cookie so the User does not have to sign in again on every visit. | 30 days | Strictly necessary (PECR Reg. 6(4)) |
looptro_anon_device |
An opaque random identifier (UUID) for the visitor’s browser, used to enforce the free anonymous-tier limits (no more than 5 anonymous retrospectives per browser per day; only one active anonymous retrospective per browser at a time). The cookie holds no Personal Data, is not associated with any Account, and is clearable from the browser at any time. | 12 months | Strictly necessary (PECR Reg. 6(4)) |
The looptro_anon_device cookie is set by JavaScript at the first visit to any page of the Service (including the marketing site) and is read only by the Service’s own API to evaluate the anonymous-tier limits. Clearing the cookie resets those limits but otherwise has no effect on the visitor’s experience. The Service does not link the cookie’s value to any Account, IP address, or other identifier it stores.
Looptro does not set analytics cookies, advertising cookies, or any third-party cookies.
Marketing-site analytics. The public marketing site at looptro.dev uses Cloudflare Web Analytics, a cookieless measurement service provided by Cloudflare, Inc., to count page views and understand which pages visitors read and where they arrived from. It sets no cookie, writes nothing to the visitor’s browser storage, and does not fingerprint the visitor’s device. Because it neither stores information on, nor gains access to information already stored on, the visitor’s device, Regulation 6 of PECR is not engaged and no consent is required; the processing is disclosed here instead. For each page view it records the page address, the referring address where the browser supplies one, the country the request came from, the browser and device type, and page-load timing measurements. The output is aggregate counts. It does not identify the visitor, does not follow the visitor between visits or across other websites, and is never combined with an Account. Looptro relies on its legitimate interest under Article 6(1)(f) in understanding how its public website performs; that interest has been weighed against the interests of visitors and is considered proportionate because no visitor is identified and no profile is built. The authenticated Service at app.looptro.dev carries no browser-side analytics measurement: no analytics script runs in the User’s browser, no analytics cookie is set, and nothing is written to browser storage for measurement purposes. The Service does record server-side telemetry about its own operation, described immediately below.
Service telemetry and product analytics. The Service records telemetry about its own operation so that Looptro can keep it running, diagnose faults, and understand which parts of the product are used. This telemetry is generated on Looptro’s servers, not in the User’s browser, so it sets no cookie and stores nothing on the User’s device; Regulation 6 of PECR is not engaged and no consent is required. It comprises request traces (the endpoint called, the response status, and how long the request took), aggregate performance metrics, application logs, and a stream of product events recording that an action of a given type happened (for example a retrospective was created, a post was added, a vote was cast, or a phase advanced). Product events carry the internal identifiers of the User, Team, retrospective, and participant involved. Those identifiers are random values (UUIDs) that mean nothing on their own and can be linked back to a person only by Looptro, using the Account records it already holds; the telemetry stream contains no email address, no display name, no password material, and no Retrospective Content. The telemetry is processed on Looptro’s behalf by the Subprocessor identified in section 12 and is not used for advertising, profiling, or cross-site tracking, and is not sold or shared. Looptro relies on its legitimate interest under Article 6(1)(f) in operating a reliable service and improving the product; that interest has been weighed against the rights of Users and is considered proportionate because the identifiers are pseudonymous, the data cannot identify a User to the Subprocessor, no Retrospective Content is included, and the telemetry is held only for the rolling retention window operated by the Subprocessor rather than kept indefinitely. A User may object to this processing under Article 21 by contacting privacy@looptro.dev.
8. How Personal Data is shared
Looptro shares Personal Data only with the Subprocessors identified in section 12, and only to the extent necessary for those Subprocessors to provide the services for which they have been engaged. Personal Data may also be disclosed where Looptro is required to do so by law, by a court of competent jurisdiction, or by a competent regulatory authority, and where disclosure is necessary to establish, exercise, or defend legal claims.
Within a Team, Retrospective Content contributed by a User is visible to other members of the same Team. This is an inherent characteristic of the Service: a retrospective is, by design, a shared workspace.
9. International data transfers
The Service is hosted in United Kingdom (London) — Fly.io + Neon Postgres (aws-eu-west-2). For Personal Data transferred from the European Economic Area to the United Kingdom, Looptro relies on the European Commission’s adequacy decision in respect of the United Kingdom. For Personal Data of Users located in the United Kingdom, no cross-border transfer arises within the United Kingdom leg of the Service’s hosting.
Where a Subprocessor processes Personal Data outside the United Kingdom or the European Economic Area, Looptro relies on an appropriate transfer mechanism under Article 46 of the UK GDPR and EU GDPR, including (as applicable) the United Kingdom International Data Transfer Addendum to the EU Standard Contractual Clauses or the EU Standard Contractual Clauses themselves. Copies of the relevant transfer mechanisms are available on request at privacy@looptro.dev.
10. Security
Looptro applies technical and organisational measures appropriate to the risks presented by the processing, including encryption of Personal Data in transit, storage of passwords in irreversible hashed form, isolation of Account and Team data per tenant, and least-privilege access controls for personnel. No system, however, can be guaranteed to be fully secure; Users are encouraged to choose a strong, unique password and to notify Looptro promptly of any suspected unauthorised access.
11. Controller and processor roles
For the purposes of the UK GDPR and EU GDPR, the allocation of controller and processor roles depends on how the Service is used.
Where a User registers individually and uses the Service on their own behalf, Looptro is the controller of that User’s Account Data, Session Records, Security-Event Records, and the Network and Device Information associated with their Session Records. Looptro determines the purposes and means of that processing and is accountable for it under this Privacy Policy.
Where a User contributes Retrospective Content inside a Team, the Team owner is the controller of that Retrospective Content and Looptro processes it as a processor on behalf of the Team owner. Business customers who require a Data Processing Agreement (DPA) covering this processor relationship may request one by emailing privacy@looptro.dev.
12. Subprocessors
Looptro engages the following Subprocessors to provide the Service:
| Subprocessor | Function |
|---|---|
| Fly.io, Inc. | Application hosting (Fly Apps, Fly Secrets, Fly Proxy) and edge networking. |
| Neon, Inc. | Managed PostgreSQL database hosting and point-in-time-recovery backups. |
| AgileBits Inc. (1Password) | Operator secrets vault (KEK backup keyring and key custodian records). 1Password processes operator-side records about the system that holds Personal Data; it does not process customer content directly. |
| Pydantic Services, Inc. (Pydantic Logfire) | Service telemetry and product analytics (traces, metrics, application logs, and product events), as described in section 7. Receives the pseudonymous User, Team, retrospective, and participant identifiers carried on those records. It does not receive Retrospective Content, email addresses, display names, or password material. |
The authoritative, continuously maintained Subprocessor list, including each Subprocessor’s region of processing, public security attestation, and cross-border transfer mechanism, is published at https://app.looptro.dev/legal/subprocessors. The summary above is provided as a convenience and is updated together with the canonical list; in the event of any discrepancy, the canonical list controls.
Cloudflare, Inc. serves the public marketing site at looptro.dev and provides the cookieless site analytics described in section 7. It processes marketing-site visitor data only; it does not process Account Data, Retrospective Content, Session Records, or any other Personal Data held inside the Service, which is why it appears in the canonical list among the vendors that are not Subprocessors of customer data rather than in the table above.
Pydantic Services, Inc. provides the telemetry service described in section 7 from its European data region, hosted in the Netherlands. Telemetry from the Service is sent only to that European region; the provider operates its European and United States regions as separate deployments with no transfer of data between them. Personal Data on this leg therefore stays within the United Kingdom and European Economic Area adequacy arrangements and no Article 46 transfer mechanism is required for the telemetry itself. The provider is incorporated in the United States, so any access to the European region by its own personnel, for example to provide support, is a transfer for which Looptro relies on the Article 46 mechanisms described in section 9 under the data processing terms of its contract with the provider. Those terms are available on request at privacy@looptro.dev.
Each Subprocessor is bound by a written contract requiring it to process Personal Data only on Looptro’s documented instructions, to apply appropriate security measures, and to assist Looptro in meeting its obligations under the UK GDPR and EU GDPR. Looptro notifies affected Users of Subprocessor additions, removals, and changes at least thirty (30) days in advance of the change taking effect, in accordance with the procedure described in section 25.
13. Personal data breaches
In the event that Looptro becomes aware of a Personal Data breach, it will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, as required by Article 33 of the UK GDPR and EU GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where a breach is likely to result in a high risk to those rights and freedoms, Looptro will communicate the breach to affected individuals without undue delay, as required by Article 34. Where applicable local law (for example Quebec Law 25 or the LGPD) imposes additional or different notification obligations, Looptro will comply with those obligations in addition to the obligations under the UK and EU GDPR.
14. Rights of Users under the UK GDPR and EU GDPR
Users located in the United Kingdom or the European Economic Area have the following rights in relation to their Personal Data:
- Right of access under Article 15: to obtain a copy of the Personal Data held about them.
- Right to rectification under Article 16: to have inaccurate or incomplete Personal Data corrected.
- Right to erasure under Article 17: to have Personal Data deleted, sometimes called the right to be forgotten.
- Right to restriction of processing under Article 18: to have processing paused in defined circumstances.
- Right to data portability under Article 20: to receive Personal Data in a structured, commonly used, machine-readable format.
- Right to object under Article 21: to object to processing carried out in reliance on legitimate interests.
These rights are not absolute and are subject to the conditions and limits set out in the UK GDPR and EU GDPR themselves. In addition, Users have the right under Article 77 to lodge a complaint with a supervisory authority, as set out in section 16.
Most of these rights can be exercised directly within the Service. Rectification of display name or email address is available in Settings under Profile. A machine-readable copy of the User’s Personal Data, which satisfies both the right of access and the right to data portability, can be obtained in Settings under Privacy and Data by selecting “Download my data”. Account deletion, which satisfies the right to erasure, is available in the same area by selecting “Delete account”. Selecting it does not delete anything by itself: Looptro sends a confirmation link to the email address on the Account, and the Account is deleted only when that link is used. The link is valid for one hour, may be used once, and the same message carries a second link that cancels the request. This single procedure applies to every Account, whether the User signs in with a passphrase or with a connected account. For requests relating to restriction, objection, or any other right not covered by these in-product controls, Users may contact privacy@looptro.dev. Looptro will respond to any such request without undue delay and in any event within one month of receipt, as required by Article 12(3); where a request is complex or where Looptro has received a large number of requests, that period may be extended by up to two further months, in which case the User will be informed within the first month and given the reasons for the extension.
15. California residents (CCPA and CPRA)
Users who are residents of California have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. These include the right to know what categories of personal information Looptro has collected and the purposes for which it is used; the right to delete personal information, subject to the exceptions provided by law; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; the right to limit the use and disclosure of sensitive personal information; and the right not to receive discriminatory treatment for exercising any of these rights.
Looptro does not sell personal information and does not share personal information for cross-context behavioural advertising within the meaning of the CCPA and CPRA. Looptro does not use sensitive personal information for any purpose other than providing the Service requested by the User. California residents may exercise their rights using the in-product controls described in section 14 or by emailing privacy@looptro.dev. Further information about California privacy rights is available from the California Attorney General at https://oag.ca.gov/privacy/ccpa.
Because Looptro does not sell or share personal information, there is no sale or sharing of personal information for a consumer to opt out of. Looptro nonetheless recognises opt-out preference signals sent by a User’s browser, including the Global Privacy Control (GPC), and will treat any such signal as a valid opt-out request should its practices ever change. Looptro does not track Users across third-party websites or services and therefore does not behave differently in response to a browser “Do Not Track” signal — it undertakes no such cross-site tracking in the first place.
16. Right to lodge a complaint
Users who consider that Looptro has mishandled their Personal Data have the right to lodge a complaint with a supervisory authority. Users may lodge a complaint with the supervisory authority of their habitual residence, of their place of work, or of the place of the alleged infringement.
Users in the United Kingdom may lodge a complaint with the Information Commissioner’s Office at https://ico.org.uk. Users in the European Economic Area may lodge a complaint with the data protection authority of their Member State; a directory of national authorities is maintained by the European Data Protection Board at https://edpb.europa.eu.
17. Brazil residents (LGPD)
Users located in Brazil have rights under the Lei Geral de Proteção de Dados (Law No. 13,709/2018). These include the right to obtain confirmation that their Personal Data is being processed; the right to access their Personal Data; the right to correct incomplete, inaccurate, or out-of-date data; the right to anonymisation, blocking, or deletion of data that is unnecessary, excessive, or processed in breach of the LGPD; the right to portability of Personal Data to another service provider; the right to deletion of Personal Data processed with consent; the right to be informed of the public and private entities with which Personal Data has been shared; the right to be informed of the possibility of refusing consent and of the consequences of refusal; and the right to revoke consent at any time. These rights may be exercised through the in-product controls described in section 14 or by emailing privacy@looptro.dev. The Brazilian National Data Protection Authority (ANPD) may be contacted at https://www.gov.br/anpd/pt-br.
18. Canada residents (PIPEDA and Quebec Law 25)
Users located in Canada have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA). These include the right to access the personal information held about them, the right to request correction of inaccurate personal information, and the right to withdraw consent to processing, subject to legal or contractual restrictions. Users located in Quebec additionally have rights under An Act to modernize legislative provisions as regards the protection of personal information (Law 25), including the right to data portability in a structured, commonly used technological format and the right to be notified of any confidentiality incident presenting a risk of serious injury.
The Office of the Privacy Commissioner of Canada may be contacted at https://www.priv.gc.ca. The Commission d’accès à l’information du Québec may be contacted at https://www.cai.gouv.qc.ca.
19. India residents (DPDP Act 2023)
Users located in India have rights as Data Principals under the Digital Personal Data Protection Act 2023. These include the right to obtain information about the Personal Data being processed; the right to correction, completion, updating, and erasure of Personal Data; the right of grievance redressal; and the right to nominate another person to exercise these rights in the event of death or incapacity. These rights may be exercised through the in-product controls described in section 14 or by emailing privacy@looptro.dev. The Indian Data Protection Board may be contacted at https://www.meity.gov.in.
20. Japan residents (APPI)
Users located in Japan have rights under the Act on the Protection of Personal Information (APPI). These include the right to request disclosure of retained Personal Data; the right to request correction, addition, or deletion of inaccurate retained Personal Data; the right to request suspension of use or deletion of retained Personal Data processed in breach of the APPI; the right to request suspension of provision of retained Personal Data to third parties; and the right to request disclosure of records of third-party provision. These rights may be exercised through the in-product controls described in section 14 or by emailing privacy@looptro.dev. The Personal Information Protection Commission may be contacted at https://www.ppc.go.jp/en/.
21. Singapore residents (PDPA)
Users located in Singapore have rights under the Personal Data Protection Act 2012. These include the right to access the Personal Data held about them and to be informed of the ways in which that Personal Data has been used or disclosed in the preceding year; the right to correct an error or omission in their Personal Data; and the right to withdraw consent to the collection, use, or disclosure of their Personal Data. These rights may be exercised through the in-product controls described in section 14 or by emailing privacy@looptro.dev. The Personal Data Protection Commission may be contacted at https://www.pdpc.gov.sg.
22. Australia residents (Privacy Act and APPs)
Users located in Australia have rights under the Privacy Act 1988 and the thirteen Australian Privacy Principles (APPs). These include the right to access the personal information held about them under APP 12; the right to request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading under APP 13; and the right to complain about a suspected breach of the Privacy Act or the APPs. These rights may be exercised through the in-product controls described in section 14 or by emailing privacy@looptro.dev. The Office of the Australian Information Commissioner may be contacted at https://www.oaic.gov.au.
23. Other jurisdictions
Users located in jurisdictions other than those listed above whose local law grants privacy rights similar to those described in this Privacy Policy may exercise equivalent rights using the in-product controls described in section 14. Where those controls do not cover the request, the User may contact privacy@looptro.dev and Looptro will respond in accordance with applicable law.
24. Children’s privacy
The Service is a workplace tool and is not directed at children. The Service is not intended for, and Looptro does not knowingly collect Personal Data from, any individual under the age of 13. If Looptro becomes aware that it has collected Personal Data from a person under that age, it will delete the relevant data within 30 days of becoming aware. Anyone with reason to believe that a child has provided Personal Data to the Service is asked to contact privacy@looptro.dev.
25. Changes to this Privacy Policy
Looptro may amend this Privacy Policy from time to time. Where an amendment is material — including any addition, removal, or change of Subprocessor, any new purpose of processing, any change to the lawful basis on which Personal Data is processed, any change to the retention periods, any change to the categories of Personal Data collected, and any expansion of cross-border transfers — Looptro will provide affected Users with at least thirty (30) days’ advance notice before the amendment takes effect. Notice is given through an in-product banner displayed on next sign-in for every Account associated with an affected Team, and, where a current email address is held, by email to that address. The in-product banner persists across sessions until the User has acknowledged it or the amendment’s effective date has passed, whichever is sooner.
Non-material amendments — including clarifications, corrections of typographical errors, formatting changes, and updates to non-substantive links — may be made without advance notice, but the effective-date field at the top of this Privacy Policy is updated in every case so the version in force is always identifiable.
The version of this Privacy Policy currently in force is effective from 2026-09-18. Continued use of the Service after the effective date of an amended Privacy Policy constitutes acknowledgement of the amended terms; Users who do not wish to accept a material amendment may close their Account during the notice window without penalty in accordance with the rights described in section 14.