Loopback サブプロセッサ一覧 / Subprocessor List
最終更新日:2026-07-14 · バージョン:v1.0
本一覧は、Loopbackがサービス提供にあたり委託する第三者サブプロセッサ、およびその処理するデータの種類、利用目的、所在地を開示するものです。本一覧はサービスの変化に応じて更新されます。重要な変更については、データ処理契約(DPA)の定めに従い企業のお客様に通知します。サブプロセッサの選定は、お客様が選択された機能および導入形態によって異なります。
一、インフラストラクチャおよびプラットフォーム
| サブプロセッサ | 用途 | 処理するデータ | 所在地・リージョン | 適用リージョン |
|---|
| Google Cloud Platform(GCP) | ホスティング、ストレージ、コンピューティング(プロジェクトloopback-500616) | アカウントデータ、設定情報、フィードバックデータ | 米国 us-central1 | すべて |
| Stripe | サブスクリプション課金・決済 | 連絡先情報、請求情報(カード番号全体は含みません) | 米国 | すべて |
| Resend | トランザクションメール、通知 | 連絡先メールアドレス | 米国 | すべて |
二、AI モデルプロバイダー
呼び出しはお客様のプランレベルにより異なり、フィードバックの分類、要約、感情・トピック分析、ベクトル化に使用されます。
| サブプロセッサ | 用途 | 処理するデータ | 所在地 |
|---|
| Anthropic(Claude) | フィードバックの分類、要約、インサイト生成 | フィードバック本文テキスト | 米国 |
| OpenAI(GPT / Embeddings) | フィードバックの分類、要約、ベクトル化(embedding) | フィードバック本文テキスト | 米国 |
| Google(Gemini) | フィードバックの分類、要約 | フィードバック本文テキスト | 米国/グローバル |
三、補足説明
- BYO_KEY/SELF_HOSTED 導入:お客様がご自身のモデル/クラウドキーを使用される場合、AI呼び出しはお客様が指定するプロバイダーへ送信されます。当該プロバイダーの選定および開示義務はお客様側の責任となります。プライベート導入の場合、Loopback は通常フィードバックデータに触れません。
- モデル学習への不使用:当社は、お客様のデータをモデル学習に使用しない商用API経路を優先的に採用し、契約上もその旨を制約として明記しています。
- チャネルプラットフォーム:お客様が自らご連携される第三者チャネル(App Store、Google Play、Steam、Reddit、Discord、Slack、Telegram、Lark/企業微信、Zendesk、Intercom、Typeform、Trustpilot など)はデータソースであり、そのデータ処理はお客様と各チャネルとの関係および各チャネルの規約に基づいて行われます。本リストにおける Loopback のサブプロセッサには該当しません。
四、変更に関する通知
サブプロセッサの新規追加または変更を行う際は、DPAの定めに従い、事前に企業のお客様へ通知いたします。お客様に合理的な異議がある場合は、DPAで定められた手続きに基づき対応いたします。
サブスクリプション変更に関するお問い合わせ:[email protected]
Loopback Subprocessor List
Last updated: 2026-07-14 · Version: v1.0
This list discloses the third-party subprocessors Loopback engages to provide the Service, together with the categories of data they process, the purposes and their locations. The list is updated as the Service changes; material changes are notified to business Customers as provided in the Data Processing Agreement (DPA). Which subprocessors are used depends on the features and deployment model selected.
1. Infrastructure and platform
| Subprocessor | Purpose | Data processed | Location/region | Applicable region |
|---|
| Google Cloud Platform (GCP) | Hosting, storage, compute (project loopback-500616) | Account data, configuration, feedback data | us-central1, United States | All |
| Stripe | Subscription billing and payments | Contact, billing info (no full card numbers) | United States | All |
| Resend | Transactional email, notifications | Contact email | United States | All |
2. AI model providers
Invocation depends on the Customer's membership tier; used for feedback classification, summarization, sentiment/topic analysis and vectorization.
| Subprocessor | Purpose | Data processed | Location |
|---|
| Anthropic (Claude) | Feedback classification, summarization, insight generation | Feedback content text | United States |
| OpenAI (GPT / Embeddings) | Feedback classification, summarization, vectorization (embeddings) | Feedback content text | United States |
| Google (Gemini) | Feedback classification, summarization | Feedback content text | United States/global |
4. Notes
- BYO_KEY / SELF_HOSTED deployments: where the Customer brings its own model/cloud keys, AI calls are sent to the provider designated by the Customer, who selects that provider and bears the disclosure obligation; in self-hosted deployments Loopback generally does not access feedback data.
- No training use: we prioritize commercial API channels that do not use Customer data to train their models, and impose this by contract.
- Channel platforms: the third-party channels a Customer connects (App Store, Google Play, Steam, Reddit, Discord, Slack, Telegram, Feishu/WeCom, Zendesk, Intercom, Typeform, Trustpilot, etc.) are data sources; their data processing is governed by the relationship between the Customer and each channel and by each channel's terms, and they are not Loopback subprocessors within the meaning of this list.
5. Change notifications
Before adding or replacing a subprocessor, we will give business Customers advance notice as provided in the DPA; Customers with a reasonable objection may proceed under the mechanism set out in the DPA.
Subscribe to change notifications: [email protected]