This Privacy Policy explains how Hiloop, Inc. (“hiloop”, “we”, “us”) handles personal data. It covers our website, and our products as used on a self-serve basis. Where we process personal data on behalf of a business customer, that customer is the controller and our Data Processing Addendum and their agreement govern.

Our two roles

Information we collect

How we use personal data

To provide, secure, and improve the service; to communicate with you; to process payments; to comply with legal obligations; and to detect and prevent abuse. Where required, we rely on a lawful basis under GDPR: performance of a contract, our legitimate interests, consent (where applicable), or a legal obligation.

Data retention

We keep personal data only as long as needed for the purposes above or as required by law. Self-serve product data is retained for a limited operational window described in your in-product terms. Enterprise customers may contract for stricter handling, including custom retention periods and zero data retention; those commitments live in the customer agreement, not this policy.

Use of data for model training

We treat training use differently by tier, and we describe it conspicuously rather than burying it:

We will not make training the hidden default for any tier that has not clearly agreed to it.

Sharing and sub-processors

We share personal data with service providers who help us run the business (hosting, email, authentication, and observability), under contracts that restrict their use. Our current sub-processors are listed at /subprocessors. We may also disclose data to comply with law or protect rights, and in a corporate transaction. We do not sell personal data.

International transfers

We may process data in the United States and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum where applicable).

Your rights

Depending on where you live (EEA/UK under GDPR, California under CCPA/CPRA, and other US states), you may have rights to access, correct, delete, port, or restrict your personal data, to opt out of certain processing, and to appeal. To exercise these, contact privacy@hiloop.ai. We will not discriminate against you for exercising your rights.

Security

We use technical and organizational measures including encryption in transit and at rest, access controls, and workload isolation. See our Security page. No system is perfectly secure.

Cookies

We aim to use only essential cookies and do not currently use third-party product analytics. If we introduce non-essential cookies in a region that requires consent, we will request it.

Children

The service is not directed to children under 16, and we do not knowingly collect their data.

Changes

We may update this policy and will revise the “Last updated” date above; material changes will be communicated as required.

Contact

Hiloop, Inc. (Delaware). Privacy questions: privacy@hiloop.ai. An EU/UK representative (GDPR Art. 27) will be appointed once EU traffic is recurring.