Skip to content
loopwynloopwyn home
Security

How your data is held and protected.

loopwyn handles business contact data on your behalf. This page states what we do about that, precisely enough for your security review to check it.

Controls

What is in place.

Tenant isolation, enforced by the database

Every row of company, contact and message data carries the account it belongs to, and Postgres row-level security filters on it. Isolation isn't a WHERE clause a developer has to remember — a query that omits the account scope returns nothing rather than someone else's data. We hold our own accounts to the same rule; there is no privileged path for us.

Encryption in transit and at rest

All traffic to the application and the API is TLS 1.2 or better, with HTTPS enforced. Databases and backups are encrypted at rest by the hosting provider. Credentials and API keys are held as environment secrets, never in the codebase.

Access control

Access to client data is limited to the personnel who operate your account, on named individual accounts — no shared logins. Authentication to the platform is per-user and account-scoped: your team sees your offerings and nothing else. Administrative access to production is limited to the engineering team and is logged.

Your sending accounts are never ours to touch

We do not hold your WhatsApp or LinkedIn credentials, because we never send on those channels — you do, from your own account. For cold email, sending runs on a domain dedicated to you, separate from your transactional and product email, so nothing we do can affect the deliverability of the mail your business depends on.

Audit trail

Every stage of the daily run is recorded per account: what was discovered, what was verified, what was drafted, what was sent and by whom. You can see the provenance of any lead in your queue, and so can we if you ask.

Backups and availability

Databases are backed up daily with point-in-time recovery. loopwyn is a daily-batch service rather than a real-time dependency: if a run is delayed, no data is lost and the queue catches up the following morning.

Roles

Who is responsible for what.

For the contact data we process on your behalf, you are the data controller and we are the processor. You decide who is contacted and what is said; we prepare it under your instruction. Every external client signs a Data Processing Addendum before we begin, and it governs this relationship.

For your own account — the people on your team who log in, your billing details, your correspondence with us — we are the controller, and the privacy policy covers it.

The lawful basis for processing publicly available business-contact data, per jurisdiction, is set out on where our data comes from.

Retention

How long we keep it.

Your account data is kept for as long as your account is active. On termination, we delete or return the contact data we processed for you on request, and delete it as a matter of course within the period set out in your DPA.

Two things outlive the account, deliberately. Opt-outs are kept permanently — a suppression record is the only way to guarantee someone who asked not to be contacted never is again. And records we are required to retain for tax and accounting are kept for the statutory period.

Anyone can ask what we hold about them, or ask to be removed, at privacy@loopwyn.com. We action removals whether or not the person is a client of ours.

Sub-processors

Who else touches the data.

Named by category, because the specific vendors change. The current named list, with entities and locations, is an annexe to the DPA and is shared before you sign.

CategoryWhat it doesProcessing location
Cloud hostingApplication, database and object storageIndia / EU region, depending on the client's requirement
Email infrastructureCold-email delivery on your dedicated sending domain, and platform notificationsEU / US
AI drafting providerGenerates the first-message drafts. Receives business context about the target company — never your customer lists, and never data from another client's account.US
Email verificationConfirms an address is deliverable before it is usedSelf-hosted by us; a third-party service is used only as a tie-breaker

We notify clients in advance of adding a sub-processor that touches their data, and the DPA sets out your right to object.

If something goes wrong

If we become aware of a breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware, with what we know at the time: what happened, which data was affected, what we have done, and what you may need to do. We will not wait until the picture is complete to tell you.

Report a suspected vulnerability or incident to privacy@loopwyn.com. We will acknowledge within one working day, and we will not pursue anyone who reports a genuine issue in good faith.

What we don’t claim

We are not ISO 27001 or SOC 2 certified. We are a small engineering company and those audits are not something we can honestly claim today. What we can do is answer a security questionnaire in full, walk your team through the isolation model, and put the controls above into your contract. If a certification is a hard requirement for your procurement process, tell us early and we will say plainly whether we can meet it.

Questions your security review needs answered?

Send the questionnaire. We'll complete it, and we'll tell you where the honest answer is no.

Free trial available · Cancel anytime, no notice period · External clients sign a DPA before we begin