SECURITY

security at looopoi

Venue operators ask us how their data is handled. Here is the straight answer, including what we have not done yet.

where your data lives

looopoi runs on enterprise cloud infrastructure holding SOC 2 Type II and ISO 27001 certification. Data is encrypted in transit using TLS 1.2 or above, and encrypted at rest.

We are happy to name our specific infrastructure providers during a security review. A current list of sub-processors is available on request.

keeping clients separate

Every venue, staff member and guest record is tagged to your account. Your data is never visible to another looopoi client, and we do not combine client data for any purpose.

who can see what

Access is by code, scoped to a role. Staff, venue managers, department heads and group leadership each see only what their role permits. Every access attempt — successful or not — is logged with a timestamp.

You control your own codes. You can issue, extend, disable or delete access at any time, and each code carries its own expiry.

guest data

We collect only what a guest chooses to give: a rating, a service category, a comment, and optionally their name and contact details so you can follow up. Providing contact details is always optional for the guest.

DataRetention
Guest feedback with contact details24 months, then contact details removed
Guest feedback without contact detailsRetained anonymously
Staff recordsSubscription term plus 12 months
Performance reviews24 months
Access and security logs12 months

We never sell guest data, never share it with other clients, and never use it to train external AI models.

staff reviews

looopoi lets staff review their managers as well as the other way around. Where a review is submitted anonymously, the reviewer's identity is not stored against it — not hidden from view, not stored at all. We record only that a submission was made, so nobody can submit twice.

Results stay hidden until enough people have responded that no individual reviewer can be identified. On a small crew, "anonymous" means nothing without that threshold, so we enforce it.

our AI assistant

Logan processes operational questions through a secure proxy. Conversations are not used to train external models.

AI-generated wash-up reports and summaries are decision support, not decisions. Output may be inaccurate. You remain responsible for operational, health and safety, and employment outcomes, and every AI-generated report is editable before it is issued.

deleting your data

You can request an export or deletion of your data at any time by emailing privacy@looopoi.com. We respond within 20 working days, as required by the New Zealand Privacy Act 2020.

If you close your account, we retain your data for 90 days so you can retrieve it, then delete or anonymise it.

what we do internally

where we are on certification

looopoi is an early-stage company and is not yet SOC 2 or ISO 27001 certified as an organisation. Our infrastructure providers are. We would rather tell you that plainly than imply otherwise.

We are happy to complete your security questionnaire, sign a Data Processing Agreement, and discuss exactly what your procurement process requires. If certification is a condition of working together, tell us and we will give you an honest timeframe.

Security or privacy question?

privacy@looopoi.com
LAST UPDATED: AUGUST 2026