Loopback プライバシーポリシー / Privacy Policy
発効日:2026-07-14 ・ 最終更新:2026-07-22 ・ バージョン:v1.2
言語と正式版について:本ポリシーは読みやすさのため多言語版を提供しており、表示言語は Loopback でお選びいただいたインターフェース言語に応じて切り替わります。対応言語が用意されていない場合は、英語版が表示されます。正式版は英語版です。その他の言語版は参考用であり、内容に相違がある場合は英語版が優先されます。
0. 用語の定義
- 「Loopback」/「当社」:HAKKO AI PTE. LTD.(登録地:シンガポール、所在地:120 Robinson Road #13-01 Singapore 068913)を指し、Loopback フィードバック分析サービスの提供者です。
- 「サービス」:Loopback が提供する、複数チャネルからのユーザーフィードバックの収集・集約・AI分析プラットフォームを指します(ウェブアプリケーション、API および関連機能を含む)。
- 「お客様」/「あなた」:本サービスを契約または利用する企業・組織、およびその許可を受けた利用者を指します。
- 「エンドユーザー」:お客様が連携した各チャネル上でレビュー、評価、フィードバックを投稿する第三者個人を指します(例:App Store のレビュアー、コミュニティメンバーなど)。
- 「個人情報/パーソナルデータ」:直接的または間接的に特定の個人を識別できる情報を指します。
1. データ処理における当社の2つの役割
Loopback は企業向け(B2B)ソフトウェアサービスであり、性質の異なる2種類のデータを取り扱うため、当社の役割もそれぞれ異なります。
| シナリオ | データの種類 | 当社の役割 |
|---|
| お客様による登録、ログイン、請求、プラットフォームの利用 | アカウント・利用データ | データコントローラー/処理者(Controller)(GDPR)/個人情報処理者(PIPL) |
| お客様がチャネルを連携した後、プラットフォームがお客様に代わってエンドユーザーのフィードバックを収集・分析 | フィードバックデータ | データ受託処理者/処理者(Processor)(GDPR)/受託処理者(PIPL)として、お客様に代わって処理 |
フィードバックデータについては、処理の目的および方法はお客様が決定し、当社はお客様の指示に基づいてのみ処理を行います。関連する権利義務については「データ処理契約(DPA)」をご参照ください(第12節)。
2. 当社が収集する情報
2.1 アカウント・利用データ(当社がコントローラーとなる場合)
- アカウント情報:企業名、ご担当者名、業務用メールアドレス、パスワード(暗号化保存)、ロール/権限。
- お支払い情報:サブスクリプションプラン(Free / Pro / Max)、請求先住所、取引履歴。実際のカード情報はStripeが処理し、当社では完全なカード番号を保存しません。
- 設定情報:連携チャネル、APIキーまたは認証トークン(暗号化保存、詳細は第5節をご参照ください)。
- 利用・ログデータ:ログイン履歴、操作ログ、IPアドレス、ブラウザ/デバイス情報、機能利用統計。セキュリティ、トラブルシューティング、製品改善のために使用します。
- プロダクト利用データ:ページ閲覧や機能利用などのプロダクト行動イベント(例:レポートの表示、チャネル連携)。これらには当社独自の匿名識別子(Cookie
lb_aid)が付随し、公式サイトとアプリ間の匿名アトリビューションに使用されます。これらのデータは製品改善のみを目的とし、当社独自のデータベースに保存されます(第三者分析サービスとの連携はありません)。フィードバック本文やお客様の入力内容は含まれず、保存期間は最長180日間です。 - Cookieおよび類似技術:詳細は第9節をご参照ください。
2.2 フィードバックデータ(当社が受託処理者として、お客様に代わって処理する情報)
お客様が以下のチャネルを連携すると、当プラットフォームはお客様の許可に基づき、公開または許可された範囲でフィードバック内容を収集します。これには個人情報が含まれる場合があります。
- アプリストア:Apple App Store(公開RSS)、Google Play(Play Developer API)など;
- コミュニティ・チケット:Reddit、Discord、Slack、Telegram、Lark/企業微信(WeCom)、Zendesk、Intercom;
- 調査・口コミ:Typeform、Lark調査フォーム、Trustpilotなど。
これらの内容には、コメント/レビュー本文、評価スコア、投稿日時、プラットフォーム上に表示される投稿者のニックネームまたは識別情報、および投稿者が自ら記載したその他の情報が含まれる場合があります。当社は、エンドユーザーの身分証明書、正確な位置情報、その他の機密性の高い個人情報を積極的に取得することはありません。フィードバック本文に偶発的にこうした情報が含まれる場合も、お客様の指示に従って処理するのみで、他の目的には使用しません。
3. 情報の利用方法
- サービスの提供・維持:アカウント管理、チャネル連携、フィードバックの収集・集約、AIによる分類・インサイト生成、ダッシュボード表示。
- AI分析処理:フィードバック内容を大規模言語モデルに送信し、分類、要約、感情分析、テーマ分析を行います(利用モデルの一覧は第6節をご参照ください)。
- お支払い処理・カスタマーサポート。
- セキュリティ、不正防止・コンプライアンス:異常検知、アクセス監査、法的義務の履行。
- 製品改善:集約・匿名化された利用統計に基づき、機能を最適化します。お客様の書面による同意がない限り、当社はお客様のフィードバックデータを当社独自の汎用モデルの学習に使用しません(第三者モデルの学習ポリシーについては第6節をご参照ください)。
処理の法的根拠(GDPR/PIPL)
- 契約の履行:ご契約いただいたサービスを提供するために必要な範囲で処理します;
- 正当な利益:安全性の確保、不正防止、プロダクト改善のため(利益のバランスを検討済み);
- 同意:適用される場合(オプションの Cookie、マーケティングメール等);
- 法的義務:法令の要求に基づく場合。
- フィードバックデータについては、その適法性はお客様がデータ管理者としてその取得・説明責任を負います。
4. データの越境移転と保管地
データの保存・処理は Google Cloud(us-central1、米国)で行われます。EU/英国にお住まいの場合、越境データ移転は標準契約条項(SCCs)などの適法な仕組みに基づいて実施されます。
デプロイ形態によって、データの流れが異なります:
- SHARED_SAAS(共有ホスティング):データは Loopback のホスティング環境に保存されます;
- BYO_KEY(お客様独自のキー):お客様独自のモデル/クラウドキーを使用し、AI 呼び出しは指定されたプロバイダーへ送信されます;
- SELF_HOSTED(プライベートデプロイ):データはお客様自身の環境に保存され、Loopback は通常お客様のフィードバックデータにアクセスしません。
5. データセキュリティ
- 通信は TLS で暗号化されます。パスワードや第三者 API キー / OAuth トークンなどの機密フィールドは暗号化して保存されます。
- ロールベースの4段階アクセス制御(RBAC)を採用し、最小権限の原則に基づいてアクセスを監査しています。
- データの機密性に応じた階層的な保護を提供します(L1 のデータ匿名化から L4 の機密計算まで、デプロイ形態やプランによって異なります)。
- 当社は合理的な技術的・管理的措置を講じておりますが、いかなるシステムも完全な安全性を保証することはできません。個人データの漏洩が発生した場合は、適用法および契約に基づき、法定期間内に関係者へ通知いたします。
6. 第三者プロバイダー(サブプロセッサー / Subprocessors)
サービス提供のため、必要なデータを以下のカテゴリーのサブプロセッサーに委託しています。使用する AI モデルは、お客様の地域およびメンバーシップランク:
| カテゴリー | プロバイダー(例) | 用途 |
|---|
| クラウド基盤 | Google Cloud 等 | ホスティング、ストレージ、コンピューティング |
| AI モデル | Anthropic(Claude)、OpenAI(GPT / Embedding)、Google(Gemini) | フィードバックの分類、要約、ベクトル化 |
| 決済 | Stripe 等 | サブスクリプション課金 |
| メール/通知 | Resend | トランザクションメール |
- 当社は再委託先(サブプロセッサ)とデータ処理条項を締結し、本ポリシーに劣らない保護水準の提供を義務付けています。
- モデルプロバイダーに送信されるコンテンツは、以下の目的にのみ使用されます:分析結果の生成。また、当社は顧客データをモデルの学習に使用しない商用APIチャネルを優先的に採用し、契約上もこれを義務付けています。
- 最新の完全なサブプロセッサ一覧は https://loopbackagent.com/subprocessors.html をご覧ください。一覧を更新する際は、DPAの規定に従いお客様にご通知します。
7. データの保存期間
- アカウント・課金データ:サービス提供期間中および提供終了後、法令(税務・監査等)で求められる期間、必要な範囲で保存します。
- フィードバックデータ:お客様がプラットフォーム上で設定した内容、またはDPAの規定に従って保存します。お客様はエクスポートまたは削除をリクエストできます。
- サービス終了後、当社は合意された期限(デフォルトでは30日)内に顧客データを削除または匿名化します。法令上の保存義務がある場合はこの限りではありません。
8. お客様(および エンドユーザー)の権利
適用法(GDPR/英国GDPR/カリフォルニア州CCPA・CPRA/中国PIPL等)の範囲内において、お客様には以下の権利があります:アクセス、訂正、削除、処理の制限、データポータビリティ、処理への異議、同意の撤回、および権利行使を理由に不利な扱いを受けないこと。
- 顧客アカウントデータ:第13節の連絡先より当社にご連絡のうえ、権利を行使してください。
- エンドユーザー:フィードバックデータの管理者(コントローラー)はお客様であるため、エンドユーザーからの権利行使請求は、原則として該当するお客様宛てに行われるべきものとします。当社は、お客様がこうした請求に対応する際、技術的な支援を行います。
- 当社は法定期間内に対応いたします。また、お客様は所在地の監督機関に申し立てを行う権利も有します。
9. Cookieおよび類似技術
当社は、ログイン状態の維持およびセキュリティ確保のため必須Cookieを使用し、同意を得た場合には製品利用状況を把握するための分析Cookieを使用します。当社のプロダクト利用分析は自社開発によるファーストパーティ方式であり(ページ上でサードパーティの分析スクリプトは読み込まれません)、そのファーストパーティの匿名識別子はlb_aid匿名アトリビューションのみに使用されます(第2.1節「プロダクト利用データ」参照)。ブラウザの設定からこれを消去またはブロックすることができます。必須ではないCookieについても、ブラウザの設定から管理いただけます。欧州地域からアクセスされる方については、公式サイトの匿名統計用Cookie(lb_aid)は、Cookie通知で「同意する」を選択するまで書き込まれることはなく、その間は統計イベントも収集されません。「拒否する」を選択した場合は統計は行われず、既存の識別子も削除されます。地域を問わず、フッターの「Cookie設定」からいつでも選択を変更いただけます。
10. 児童のプライバシー
本サービスは企業向けであり、16歳未満(または適用法で定められた年齢未満)の個人を対象としていません。当社は児童の個人情報を意図的に収集することはありません。
11. ポリシーの変更
当社は本ポリシーを随時更新する場合があります。重要な変更については、サービス内通知またはメールにてお知らせするとともに、ページ上部の「最終更新日」を更新します。変更後も本サービスの利用を継続された場合、当該変更に同意されたものとみなされます。
12. データ処理契約(DPA)
フィードバックデータを処理者(プロセッサ)として処理する部分については、当社は企業のお客様と別途「データ処理契約(DPA)」を締結し、処理範囲、サブプロセッサ、セキュリティ対策、協力義務、データ漏洩通知、監査権、および越境移転の仕組み(SCCsを含む)を定めています。企業のお客様は、第13節の連絡先よりお申し付けください。
13. お問い合わせ
Loopback Privacy Policy
Effective date: 2026-07-14 · Last updated: 2026-07-14 · Version: v1.0
Language & governing version: This Policy is offered in multiple languages for your convenience; the language shown follows the interface language you select in Loopback, and any language not provided defaults to this English version. The governing version is this English version. Other translations are for reference only; in case of ambiguity or conflict between a translation and the English version, the English version prevails.
0. Definitions
- "Loopback" / "we" / "us": HAKKO AI PTE. LTD. (place of registration: Singapore, address: 120 Robinson Road #13-01 Singapore 068913), the provider of the Loopback feedback-analytics service.
- "Service": the Loopback platform for multi-channel collection, aggregation and AI analysis of user feedback (including the web application, API and related features).
- "Customer" / "you": the business or organization that subscribes to or uses the Service, and its authorized users.
- "End User": a third-party individual who leaves comments, ratings or feedback on the channels connected by a Customer (e.g. App Store reviewers, community members).
- "Personal information / personal data": information that can directly or indirectly identify a natural person.
1. Our two roles in data processing
Loopback is a business-to-business (B2B) software service involving two categories of data with different natures, in which our role differs:
| Scenario | Data type | Our role |
|---|
| Customer sign-up, login, billing, platform use | Account & usage data | Data Controller (GDPR) / personal information handler (PIPL) |
| Collecting and analyzing End-User feedback on the Customer's behalf after channels are connected | Feedback data | Data Processor (GDPR) / entrusted party (PIPL), processing on the Customer's instructions |
For Feedback data, the purposes and means of processing are determined by the Customer; we process it only on the Customer's instructions. The respective rights and obligations are further set out in the Data Processing Agreement (DPA) (see Section 12).
2. Information we collect
2.1 Account & usage data (where we are the Controller)
- Account information: company name, contact name, work email, password (stored encrypted), roles/permissions.
- Billing information: subscription tier (Free / Pro / Max), billing address, transaction records. Full card numbers are handled by Stripe; we do not store full card numbers.
- Configuration: connected channels, API keys or authorization tokens (stored encrypted, see Section 5).
- Usage & log data: login records, activity logs, IP address, browser/device information, feature-usage statistics, used for security, troubleshooting and product improvement.
- Cookies and similar technologies: see Section 9.
2.2 Feedback data (where we are the Processor, on the Customer's behalf)
Once a Customer connects the following channels, the platform collects public or authorized feedback content from them as authorized by the Customer, which may contain personal information:
- App stores: Apple App Store (public RSS), Google Play (Play Developer API), etc.;
- Community & ticketing: Reddit, Discord, Slack, Telegram, Feishu / WeCom, Zendesk, Intercom;
- Surveys & reputation: Typeform, Feishu Forms, Trustpilot, etc.
Such content may include: the body of comments/reviews, ratings, publication time, the author's display name or identifier as shown on the platform, and any other information the author voluntarily includes in the content. We do not actively solicit End Users' identity documents, precise location or other sensitive personal information; where feedback content incidentally contains such information, we process it only on the Customer's instructions and for no other purpose.
3. How we use information
- Provide and maintain the Service: account management, channel connection, feedback collection and aggregation, AI classification and insight generation, dashboards.
- AI analysis: sending feedback content to large language models for classification, summarization, sentiment and topic analysis (provider list in Section 6).
- Billing and customer support.
- Security, fraud prevention and compliance: anomaly detection, access auditing, legal obligations.
- Product improvement: optimizing features based on aggregated, de-identified usage statistics. We do not use Customers' Feedback data to train our own general-purpose models without the Customer's written consent (for third-party models' training policies, see Section 6).
Legal bases for processing (GDPR / PIPL)
- Performance of a contract: necessary to provide the subscribed Service;
- Legitimate interests: security, fraud prevention, product improvement (balancing test performed);
- Consent: where applicable (e.g. optional cookies, marketing emails);
- Legal obligation: where required by law.
- For Feedback data, the legal basis is obtained and represented by the Customer as Controller.
4. Cross-border transfers and data residency
Data is stored and processed at Google Cloud (us-central1, United States). If you are in the EU/UK, cross-border transfers rely on lawful mechanisms such as the Standard Contractual Clauses (SCCs).
Data flows differ by deployment form:
- SHARED_SAAS (shared hosting): data is stored in the Loopback-hosted environment;
- BYO_KEY (bring your own key): your own model/cloud keys are used, and AI calls are sent to the provider you designate;
- SELF_HOSTED: data is stored in your own environment, and Loopback generally does not access your Feedback data.
5. Data security
- TLS encryption in transit; sensitive fields (passwords, third-party API keys / OAuth tokens) stored encrypted.
- Role-based access control with four tiers (RBAC), least-privilege principle, access auditing.
- Tiered protection by sensitivity (from L1 data obfuscation to L4 confidential computing, depending on deployment form and plan).
- We apply reasonable technical and organizational measures, but no system can guarantee absolute security. In the event of a personal-data breach, we will notify the relevant parties within the statutory time limits in accordance with applicable law and contract.
6. Third-party providers (Subprocessors)
To provide the Service we entrust necessary data to the following categories of subprocessors. The AI model used depends on your region and membership tier:
| Category | Providers (examples) | Purpose |
|---|
| Cloud infrastructure | Google Cloud etc. | Hosting, storage, compute |
| AI models | Anthropic (Claude), OpenAI (GPT / Embedding), Google (Gemini) | Feedback classification, summarization, vectorization |
| Payments | Stripe etc. | Subscription billing |
| Email/notifications | Resend | Transactional email |
- We enter into data-processing terms with subprocessors requiring protection no lower than this Policy.
- Content sent to model providers is used to generate analysis results; we prioritize commercial API channels that do not use Customer data to train their models, and impose this by contract.
- The complete, up-to-date subprocessor list is available at: https://loopbackagent.com/subprocessors.html. We notify Customers of changes as provided in the DPA.
7. Data retention
- Account & billing data: retained during the service term and thereafter for the period required by law (e.g. tax, audit).
- Feedback data: retained as configured by the Customer in the platform or as agreed in the DPA; Customers may request export or deletion.
- After termination, we will delete or anonymize Customer data within the agreed period (default 30 days), except where retention is required by law.
8. Your (and End Users') rights
To the extent provided by applicable law (GDPR / UK GDPR / California CCPA/CPRA / China PIPL, etc.), you have the right to: access, rectification, erasure, restriction of processing, data portability, objection to processing, and withdrawal of consent, and not to be discriminated against for exercising these rights.
- Customer account data: please contact us via Section 13 to exercise these rights.
- End Users: because Feedback data is controlled by the Customer as Controller, End-User requests should in principle be directed to the relevant Customer; we will provide technical assistance to help Customers respond to such requests.
- We will respond within statutory time limits; you also have the right to lodge a complaint with your local supervisory authority.
9. Cookies and similar technologies
We use necessary cookies to maintain login and security, and, with consent, analytics cookies to understand product usage. You can manage non-essential cookies through your browser settings.
10. Children's privacy
The Service is intended for businesses and not for individuals under 16 (or the age specified by applicable law). We do not knowingly collect children's personal information.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated via in-service notice or email, and the "Last updated" date at the top will be revised. Continued use after changes take effect constitutes acceptance.
12. Data Processing Agreement (DPA)
For the portion where we act as Processor of Feedback data, we enter into a separate Data Processing Agreement (DPA) with business Customers, covering the scope of processing, subprocessors, security measures, assistance obligations, breach notification, audit rights and cross-border mechanisms (including SCCs). Business Customers may request it via Section 13.
13. Contact us
- Data protection / privacy matters: [email protected]
- General contact: [email protected]
- Mailing address: 120 Robinson Road #13-01 Singapore 068913
- EU/UK Representative (if applicable): to be designated and published separately
- Data protection matters: [email protected]