Subprocessors
Effective date: 2026-08-18
This is the authoritative, continuously maintained list of the Subprocessors Looptro engages to process personal data. The Privacy Policy carries a summary table for convenience; where the two differ, this page controls.
Looptro notifies customers of Subprocessor additions, removals, and changes at least 30 days before the change takes effect, and publishes the change in the archive at the foot of this page at the same time. Customers may object during that window by writing to privacy@looptro.dev.
Subprocessors in production
| Subprocessor | Role | Region of processing | Security posture | Transfer mechanism |
|---|---|---|---|---|
| Fly.io, Inc. | Application hosting (Fly Apps, Fly Secrets, Fly Proxy) and edge networking. | Primary region declared in the deployment configuration. | SOC 2 Type II. | Standard Contractual Clauses Module 3 where a transfer occurs outside the EEA. |
| Neon, Inc. | Managed PostgreSQL: primary database, point-in-time-recovery backups, WAL streaming. | Primary region per the Neon project; EU-only residency available on request. | SOC 2 Type II; ISO 27001:2022. | Standard Contractual Clauses Module 3 where a transfer occurs outside the EEA. |
| AgileBits Inc. (1Password) | Operator secrets vault holding the key-encryption-key backup keyring and key custodian records. Processes operator-side records about the system that holds customer content, not the content itself. | 1Password’s published regions. | SOC 2 Type II; ISO 27001. | Standard Contractual Clauses Module 3. |
| Resend, Inc. | Transactional email delivery: signup verification, password reset, email-change verify and cancel, and account-security notifications. Processes the recipient address and the display name and single-use token rendered into each message. No retrospective content is sent through Resend. | US-incorporated; the EU sending region is selected so the message-content and recipient-metadata path is EU-hosted. | SOC 2 Type II; DPA incorporating EU Standard Contractual Clauses. | Standard Contractual Clauses, narrowed by the EU sending region. |
| Pydantic Services, Inc. (Pydantic Logfire) | Service telemetry and product analytics: request traces, aggregate metrics, application logs, and product events. Receives the pseudonymous User, Team, retrospective, and participant identifiers carried on those records. Does not receive Retrospective Content, email addresses, display names, or password material. | European data region, hosted in the Netherlands. The provider operates its European and United States regions as separate deployments with no transfer of data between them. | SOC 2 Type II. | None required for the telemetry itself, which stays within the UK and EEA. The provider is US-incorporated, so access to the European region by its own personnel relies on the Article 46 mechanisms in its data processing terms. |
The five Subprocessors above are always engaged. The two below are engaged only for teams that opt into the corresponding connector; nothing is sent until an administrator connects the provider and a member exports or promotes an item.
| Subprocessor | Role | Region of processing | Security posture | Transfer mechanism |
|---|---|---|---|---|
| Slack Technologies, LLC (Salesforce, Inc.) | Conditional. Retro-summary export: posts the summary, including post text, cluster and vote counts, and action-item titles and assignee display names, to the team-chosen channel. | Salesforce published regions, US-based. | SOC 2 Type II; ISO/IEC 27001; ISO/IEC 27701. | Standard Contractual Clauses Module 3. |
| Linear Orbit, Inc. (Linear) | Conditional. Action-item sync: creates and updates issues from action items and reads issue state back. | Customer-selected EU or US, chosen when the customer creates their Linear workspace. | SOC 2 Type II; ISO/IEC 27001:2022. | Standard Contractual Clauses Module 3 on the US leg. No restricted transfer where the workspace is EU-hosted. |
Content exported through either connector is field-encrypted at rest inside Looptro. Export decrypts it and sends it to the provider on the customer’s explicit instruction, which places it outside Looptro’s at-rest encryption boundary.
Vendors that are not Subprocessors of customer data
These vendors process Looptro operator-side or business-side data only. They are listed for transparency, not as Article 28 Subprocessors.
- Cloudflare, Inc. Authoritative DNS, and hosting plus CDN for the public marketing site at
looptro.dev, including its cookieless Web Analytics. It sees marketing-site visitors only. The authenticated Service atapp.looptro.devis DNS-only and served from Fly, so no Account Data, Retrospective Content, or Session Records reach Cloudflare. - GitHub, Inc. Source code hosting, issue tracking, and CI for the Looptro application code. No customer content lives in GitHub.
- Linear. Internal product planning. Operators are instructed not to paste customer personal data into Linear. This operator-side use is distinct from the customer-facing Linear connector above, which is a conditional Subprocessor.
- Have I Been Pwned (Superlative Enterprises Pty Ltd). Verifier only; no personal data is transmitted. Breached-passphrase checking uses a k-anonymity range query: Looptro computes the hash locally and sends only its first five hexadecimal characters, so the passphrase, its full hash, and the user’s address are never transmitted.
AI providers reached through the MCP endpoint are not Looptro Subprocessors. Looptro’s server does not call an AI provider on its own; the endpoint is the customer’s connection point for a provider the customer chooses, and the customer’s own agreement with that provider governs that leg. If Looptro later ships a server-initiated AI feature, the relevant provider is added to this list with at least 30 days’ notice before the feature ships.
What has changed
| Published | Effective | Change | Subprocessor | Reason |
|---|---|---|---|---|
| 2026-08-18 | 2026-06-11 | Corrected | Pydantic Services, Inc. (Pydantic Logfire) | Service telemetry and product analytics. Not a new engagement: this Subprocessor has been in use since 2026-06-11 and was omitted from this list. The effective date shown is when the processing began. |
| 2026-08-18 | 2026-08-18 | Clarified | Cloudflare, Inc. | Recorded as a non-Subprocessor vendor when cookieless analytics was enabled on the marketing site. |