Call trackingForms & chatAttributionReportingLoop AIAgent TrainerOutboundEmail ingestionFor agenciesPricingSecurity DocsSign in
Book a demo
Security & data

Built in the UK.
Your data stays here.

Loop was designed around UK GDPR from day one — not retrofitted for it. We Are Intrinsic Limited is registered with the ICO as a data controller (registration ZC198477). Here’s exactly how your data, and your clients’ callers’ data, is handled.

Residency

London, end to end.

The database, all processing and every call recording live in UK data centres.

  • Call audio is copied to UK storage within seconds of a call ending
  • The telephony provider’s copy is deleted the moment ours lands
  • Nothing sits in overseas storage — not even transiently archived
Where your data lives London
Database & processing London 🇬🇧
Call recordings London 🇬🇧
Transcripts & AI reads London 🇬🇧
Telephony provider copy retained deleted →
Isolation

Client separation, enforced by the database.

Row-level security means every query is tenant-scoped by the database engine itself — not just by application code.

  • A client portal login can see their own site’s data and mathematically nothing else
  • Isolation holds even if application code has a bug — the database refuses
  • Verified with adversarial cross-tenant tests
Row-level security
client-a@… → SELECT leads (site A) ✓ 214 rows
client-a@… → SELECT leads (site B) ✗ 0 rows
client-b@… → UPDATE site A config ✗ denied
policy: owner_id = auth.uid() enforced by Postgres
Minimisation

12-month retention, automatic, by default.

Every account runs a nightly retention sweep. Recordings and transcripts are destroyed on schedule, personal details are anonymised — and anonymised statistics survive forever, so dashboards and year-on-year trends never break.

  • Extend to 24 or 36 months, or compliance-grade up to 7 years for regulated sectors
  • Recordings, transcripts and personal details on independent dials
  • Every policy change and every sweep is audit-logged
Data lifecycle nightly sweep
0–12 mo · full detail
then · auto-redacted
stats · forever
extend: 24 mo · £25  ·  36 mo · £40  ·  compliance 7 yr · £75
Subject requests

Access & erasure, built into the product.

Search any caller by phone or email, export everything held as a right-of-access bundle, or erase them with typed confirmation.

  • Erasure destroys recordings everywhere they exist — including the telephony provider’s copy
  • Anonymised skeleton preserved, so reporting never corrupts
  • Every search, export and erasure audit-logged with masked identifiers
Privacy tooling
🔍 07•••••032
16 leads · 9 calls · 2 recordings found
Export JSONType ERASE to confirm
✓ erased · logged to audit trail
Hardening

Defence as standard.

A-grade security headers

Independently verifiable — CSP, HSTS-preload, frame and MIME protections.

Rate-limited endpoints

Public endpoints throttle abuse automatically; webhooks are signature-validated.

Encrypted throughout

TLS in transit, encryption at rest, MFA-protected infrastructure accounts.

Consent-aware tracking

The tag can be gated behind your consent tool — nothing fires before permission.

Incident-ready

Tested response runbook with UK breach-notification procedures (72-hour ICO rule).

Audit trail

Privacy actions, retention sweeps and policy changes — all logged, all reviewable.

Questions?

Ask us anything about data handling.

DPAs, sub-processor lists and retention schedules available for review — we like these conversations.

Talk to us