LoopPilot — "we" on this page — operates looppilot.io and is the data controller for the personal data described here; reach us at [email protected]. This page covers two things: what this website handles, and how data is treated in client engagements. The short version: apart from the IP address every web host necessarily sees, the site collects nothing that identifies you unless you use the contact form, we run no advertising and no cross-site tracking, the only analytics is a cookieless page-view count, and we do not use client data to train models.
What we collect
What you type into the contact form is the only personal data this website asks for:
- Name and email address — required, so we can reply
- Company — optional
- Your message — required
- Where you came from — the page sends, with your message, the site that referred you, any campaign tags or advertising click identifiers in the address you arrived on — utm_source or gclid, say — and which section of the page that address pointed at, so we know which link brought you. Nothing else about your visit is attached, and nothing is stored in your browser to do it.
Two things reach us without you typing them. When the contact form's bot check runs, your IP address is passed to Cloudflare so it can score the request — we don't store it. And Cloudflare, as the host, processes your IP address to serve and protect the site, as any web host does.
We use this information for one purpose: responding to your inquiry and, if you ask us to, scoping an engagement. We do not add you to a mailing list, and we do not sell or share your details for marketing. Where the GDPR applies, we rely on two legal bases: taking steps at your request before entering a contract, GDPR Art. 6(1)(b), and our legitimate interest in answering messages sent to us, Art. 6(1)(f).
Processors we use
- Web3Forms · form delivery — when you submit the contact form, the contents are transmitted through Web3Forms, which delivers them to our inbox. Web3Forms' own policy says it keeps a copy of each submission for up to three years unless it is deleted earlier, on AWS-hosted infrastructure, and that its spam filters — CleanTalk and Akismet — may receive the sender's email address and IP address; see Web3Forms' privacy policy.
- Cloudflare · hosting and bot protection — the site is served by Cloudflare Pages, and the contact form uses Cloudflare Turnstile to tell humans from bots. Turnstile evaluates browser signals for that purpose and may set its own functional cookie; see Cloudflare's privacy policy.
- Cloudflare Web Analytics · traffic counts — every page loads a small Cloudflare script that reports the page view. It sets no cookie and builds no cross-site identifier: it records which page was loaded, the referring site, and coarse device and country information derived from the request. We use it only to see which pages get read.
Form submissions pass through our Cloudflare Pages function, which verifies the Turnstile token, before Web3Forms delivers them. Both providers operate globally, so a submission may be processed outside your country, including in the United States or India; both state in their own terms that they cover such transfers with standard contractual clauses. If you'd rather not involve them at all, email [email protected] directly — then only our email provider is involved.
Client engagements
When we build and operate automation for a client, the workflow data the agents touch — orders, invoices, tickets, and so on — is handled differently from this website:
- Your records stay in your systems. Agents act through scoped credentials you grant in your own tools; we don't copy your records into a platform of ours. To make a decision, an agent sends the working context of that step — an order, an invoice line, a ticket — to the model provider named in your engagement agreement.
- No training on your data. We do not use client data to train or fine-tune models, and we don't permit our model providers to either.
- Terms are set per engagement. Each engagement's written agreement names the sub-processors involved — such as the model provider — plus retention and deletion, agreed before any data flows. Every agent action is logged to an audit trail you can inspect.
What we don't do
- No advertising and no cross-site tracking scripts — nothing here follows you to other sites.
- No marketing cookies. The site stores two flags in your browser's session storage — whether the intro animation has already played, and your background-motion preference. They identify nothing and disappear when the tab closes.
- Fonts are self-hosted — no requests to font CDNs.
Retention
Messages you send us live in our email inbox for at most 24 months after our last exchange, unless the conversation has become an engagement — then the engagement agreement's retention terms apply. A copy also sits with our form processor for as long as their own policy allows — currently up to three years unless deleted sooner; see Processors above. Ask us to delete a thread sooner and we will.
Your rights
You can ask us at any time to access, correct, or delete the personal data you've sent us, or to stop processing it. Write to [email protected] and we'll act on it promptly. Depending on where you live — under the GDPR, for example — you may also have the right to complain to your local data-protection authority.
Changes
If we change how the site handles data — for example by adding a new processor — we'll update this page and its date before the change goes live.