This Privacy Policy explains how Hiloop, Inc. (“hiloop”, “we”, “us”) handles personal data. It covers our website, and our products as used on a self-serve basis. Where we process personal data on behalf of a business customer, that customer is the controller and our Data Processing Addendum and their agreement govern.
Our two roles
- Controller — for personal data we collect about website visitors, prospects, account holders, and support contacts (e.g. name, email, billing, usage analytics). This policy describes that processing.
- Processor / service provider — for data a customer submits to the product (their code, datasets, prompts, outputs, logs). We process it only on the customer’s instructions under their agreement and our DPA, not as described in this policy.
Information we collect
- You provide: account and contact details, billing information, support communications, and anything you submit through forms.
- Automatically: usage and device/log data. We aim to avoid non-essential cookies and do not currently use third-party product analytics; see Cookies.
- From third parties: identity/SSO providers and payment processors, as applicable.
How we use personal data
To provide, secure, and improve the service; to communicate with you; to process payments; to comply with legal obligations; and to detect and prevent abuse. Where required, we rely on a lawful basis under GDPR: performance of a contract, our legitimate interests, consent (where applicable), or a legal obligation.
Data retention
We keep personal data only as long as needed for the purposes above or as required by law. Self-serve product data is retained for a limited operational window described in your in-product terms. Enterprise customers may contract for stricter handling, including custom retention periods and zero data retention; those commitments live in the customer agreement, not this policy.
Use of data for model training
We treat training use differently by tier, and we describe it conspicuously rather than burying it:
- Self-serve: by default we may use your inputs and outputs to improve and train our models. You can opt out at any time in your account settings; opting out is honored going forward and is reversible.
- Public-data route: content you choose to designate as public may be used more broadly; where it contains personal data, we still rely on a lawful basis.
- Enterprise: we do not train on enterprise customer data. This is the default and is committed in the customer agreement.
We will not make training the hidden default for any tier that has not clearly agreed to it.
Sharing and sub-processors
We share personal data with service providers who help us run the business (hosting, email, authentication, and observability), under contracts that restrict their use. Our current sub-processors are listed at /subprocessors. We may also disclose data to comply with law or protect rights, and in a corporate transaction. We do not sell personal data.
International transfers
We may process data in the United States and other countries. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum where applicable).
Your rights
Depending on where you live (EEA/UK under GDPR, California under CCPA/CPRA, and other US states), you may have rights to access, correct, delete, port, or restrict your personal data, to opt out of certain processing, and to appeal. To exercise these, contact privacy@hiloop.ai. We will not discriminate against you for exercising your rights.
Security
We use technical and organizational measures including encryption in transit and at rest, access controls, and workload isolation. See our Security page. No system is perfectly secure.
Cookies
We aim to use only essential cookies and do not currently use third-party product analytics. If we introduce non-essential cookies in a region that requires consent, we will request it.
Children
The service is not directed to children under 16, and we do not knowingly collect their data.
Changes
We may update this policy and will revise the “Last updated” date above; material changes will be communicated as required.
Contact
Hiloop, Inc. (Delaware). Privacy questions: privacy@hiloop.ai. An EU/UK representative (GDPR Art. 27) will be appointed once EU traffic is recurring.