Loopback 개인정보 처리방침 / Privacy Policy
시행일: 2026-07-14 · 최종 업데이트: 2026-07-22 · 버전: v1.2
언어 및 정본: 본 방침은 이해를 돕기 위해 여러 언어로 제공되며, 표시 언어는 Loopback에서 선택하신 인터페이스 언어에 따라 달라집니다. 제공되지 않는 언어는 기본적으로 영문판으로 표시됩니다.정본은 영문판입니다. 그 외 언어 번역본은 참고용이며, 번역본과 영문판 간 의미 차이나 충돌이 있을 경우 영문판이 우선합니다.
0. 용어 정의
- "Loopback" / "당사": HAKKO AI PTE. LTD.(등록지: 싱가포르, 주소: 120 Robinson Road #13-01 Singapore 068913)를 의미하며, Loopback 피드백 분석 서비스의 제공자입니다.
- "서비스": Loopback이 제공하는 멀티채널 사용자 피드백 수집·통합 및 AI 분석 플랫폼(웹 애플리케이션, API 및 관련 기능 포함)을 의미합니다.
- "고객" / "귀하": 본 서비스를 구독하거나 이용하는 기업 또는 조직 및 그로부터 권한을 부여받은 사용자를 의미합니다.
- "최종 사용자": 고객이 연동한 각 채널에 리뷰, 평점, 피드백을 남기는 제3자 개인(예: App Store 리뷰어, 커뮤니티 멤버 등)을 의미합니다.
- "개인정보 / 개인데이터": 특정 자연인을 직접적으로 또는 간접적으로 식별할 수 있는 정보를 의미합니다.
1. 데이터 처리에서 당사의 두 가지 역할
Loopback은 기업 대상(B2B) 소프트웨어 서비스로, 성격이 다른 두 종류의 데이터를 다루며 이에 따라 당사의 역할도 달라집니다.
| 시나리오 | 데이터 유형 | 당사의 역할 |
|---|
| 고객의 가입, 로그인, 결제, 플랫폼 이용 | 계정 및 이용 데이터 | 데이터관리자 / 처리자(Controller)(GDPR) / 개인정보처리자(PIPL) |
| 고객이 채널을 연동하면 플랫폼이 이를 대신하여 최종 사용자 피드백을 수집·분석 | 피드백 데이터 | 데이터수탁처리자 / 처리자(Processor)(GDPR) / 수탁처리자(PIPL), 고객을 대신하여 처리 |
피드백 데이터의 경우, 처리 목적과 방식은고객이(가) 결정하며, 당사는 고객의 지시에 따라서만 처리합니다. 관련 권리·의무는 별도로 《데이터 처리 계약(DPA)》(제12절 참조)을 확인하시기 바랍니다.
2. 당사가 수집하는 정보
2.1 계정 및 이용 데이터(당사가 관리자인 경우)
- 계정 정보: 기업명, 담당자 성명, 업무용 이메일, 비밀번호(암호화 저장), 역할/권한.
- 결제 정보: 구독 등급(Free / Pro / Max), 청구지 주소, 거래 내역. 실제 결제 카드 번호는 Stripe에서 처리하며, 당사는 전체 카드 번호를 저장하지 않습니다.
- 구성 정보: 연동된 채널, API 키 또는 인증 토큰(암호화 저장, 5절 참조).
- 사용 및 로그 데이터: 로그인 기록, 작업 로그, IP 주소, 브라우저/기기 정보, 기능 사용 통계로, 보안·문제 해결·제품 개선에 활용됩니다.
- 제품 사용 데이터: 페이지 조회, 기능 사용 등 제품 행동 이벤트(예: 리포트 열기, 채널 연동)로, 퍼스트파티 익명 식별자(Cookie
lb_aid)와 함께 수집되어 웹사이트와 앱 간 익명 어트리뷰션에 사용됩니다. 이러한 데이터는 제품 개선 목적으로만 사용되며, 자체 데이터베이스에 저장되고(제3자 분석 서비스와 연동하지 않음) Review 본문이나 귀하의 입력 내용을 포함하지 않으며, 180일을 초과하여 보관하지 않습니다. - Cookie 및 유사 기술: 9절 참조.
2.2 피드백 데이터(당사는 수탁 처리자로서 고객을 대신하여 처리)
고객이 아래 채널을 연동하면, 플랫폼은 고객의 승인 범위 내에서 공개되거나 승인을 통해 얻을 수 있는 피드백 콘텐츠를 수집하며, 여기에는 개인정보가 포함될 수 있습니다:
- 앱 스토어: Apple App Store(공개 RSS), Google Play(Play Developer API) 등;
- 커뮤니티 및 티켓: Reddit, Discord, Slack, Telegram, Lark / WeCom, Zendesk, Intercom;
- 설문 및 리뷰: Typeform, Lark 설문, Trustpilot 등.
이러한 콘텐츠에는 Review 본문, 평점, 게시 시간, 플랫폼 내 표시되는 작성자 닉네임 또는 식별자, 그리고 작성자가 콘텐츠에 직접 기재한 기타 정보가 포함될 수 있습니다.당사는 최종 사용자의 신분증, 정확한 위치 정보 또는 기타 민감한 개인정보를 능동적으로 요청하지 않습니다; 다만 Review 본문에 이러한 정보가 우연히 포함된 경우, 고객의 지시에 따라서만 처리하며 그 외 다른 목적으로 사용하지 않습니다.
3. 당사의 정보 이용 방법
- 서비스 제공 및 유지: 계정 관리, 채널 연동, 피드백 수집 및 집계, AI 분류 및 인사이트 생성, 대시보드 표시.
- AI 분석 처리: 피드백 콘텐츠를 대규모 언어 모델에 전달하여 분류, 요약, 감성 및 주제 분석을 수행합니다(모델 목록은 6절 참조).
- 결제 및 고객 지원。
- 보안, 부정 사용 방지 및 컴플라이언스: 이상 탐지, 접근 감사, 법적 의무 이행.
- 제품 개선: 집계되고 비식별화된 사용 통계를 기반으로 기능을 최적화합니다.고객의 서면 동의 없이는, 고객의 피드백 데이터를 당사 자체 범용 모델 학습에 사용하지 않습니다 (제3자 모델 학습 정책은 6절 참조).
처리의 법적 근거(GDPR / PIPL)
- 계약 이행: 귀하가 구독한 서비스를 제공하기 위해 필요함;
- 정당한 이익: 보안 확보, 부정 사용 방지, 제품 개선(이해관계 균형 검토 완료);
- 동의: 해당하는 경우(예: 선택적 쿠키, 마케팅 이메일);
- 법적 의무: 법령상 요구에 따름.
- 피드백 데이터의 경우, 처리 근거는고객가 컨트롤러로서 확보하고 안내할 책임이 있습니다.
4. 데이터의 국외 이전 및 보관
데이터는 Google Cloud(us-central1, 미국)에서 저장 및 처리됩니다. EU/영국에 소재한 경우, 국외 이전은표준계약조항(SCCs)등 적법한 메커니즘에 따라 이루어집니다.
배포 형태에 따라 데이터 흐름이 다릅니다:
- SHARED_SAAS(공유 호스팅): 데이터는 Loopback 호스팅 환경에 저장됩니다;
- BYO_KEY(자체 키 사용): 귀사의 모델/클라우드 키를 사용하며, AI 호출은 귀사가 지정한 공급업체로 전송됩니다;
- SELF_HOSTED(자체 호스팅): 데이터는귀사 자체 환경에 저장되며, Loopback은 일반적으로 귀사의 피드백 데이터에 접근하지 않습니다.
5. 데이터 보안
- 전송 구간은 TLS로 암호화되며, 민감 항목(비밀번호, 제3자 API 키/OAuth 토큰)은 암호화하여 저장합니다.
- 역할 기반 4단계 접근 제어(RBAC)를 적용하며, 최소 권한 원칙과 접근 감사를 시행합니다.
- 민감도에 따라 계층적 보호를 제공합니다(배포 형태와 요금제에 따라 L1 데이터 난독화부터 L4 기밀 컴퓨팅까지).
- 당사는 합리적인 기술적·관리적 조치를 취하고 있으나, 어떠한 시스템도 절대적인 보안을 보장할 수는 없습니다. 개인정보 유출 발생 시, 관련 법령 및 계약에 따라 법정 기한 내에 관계자에게 통지합니다.
6. 제3자 공급업체(하위 처리자/Subprocessors)
서비스 제공을 위해, 당사는 다음 카테고리의 하위 처리자에게 필요한 데이터를 위탁합니다. AI 모델 선택은 귀사의지역및멤버십 등급:
| 카테고리 | 공급업체(예시) | 용도 |
|---|
| 클라우드 인프라 | Google Cloud 등 | 호스팅, 스토리지, 컴퓨팅 |
| AI 모델 | Anthropic(Claude)、OpenAI(GPT / Embedding)、Google(Gemini) | 피드백 분류, 요약, 벡터화 |
| 결제 | Stripe 등 | 구독 결제 |
| 이메일/알림 | Resend | 거래 알림 이메일 |
- 당사는 하위 처리자와 데이터 처리 조항을 체결하여 본 정책 수준 이상의 보호를 제공하도록 요구합니다.
- 모델 제공업체에 전달되는 콘텐츠는 다음 용도로 사용됩니다: 분석 결과 생성당사는 다음 조건을 우선적으로 고려하여 API 채널을 선택합니다: 고객 데이터를 모델 학습에 사용하지 않는상용 API를 우선적으로 선택하며, 이를 계약상의 의무로 명시합니다.
- 전체 실시간 하위 처리자 목록은https://loopbackagent.com/subprocessors.html 에서 확인하실 수 있습니다. 목록이 업데이트되면 DPA에 따라 고객에게 통지합니다.
7. 데이터 보관
- 계정 및 결제 데이터: 서비스 기간 및 이후에도 법적 요구사항(세무, 감사 등)에 따라 필요한 기간 동안 보관합니다.
- 피드백 데이터: 고객이 플랫폼에서 설정한 구성 또는 DPA 약정에 따라 보관하며, 고객은 데이터 내보내기 또는 삭제를 요청할 수 있습니다.
- 서비스 종료 후 당사는 약정된 기간(기본 30일) 내에 고객 데이터를 삭제하거나 익명화하며, 법적으로 보관이 요구되는 경우는 예외로 합니다.
8. 귀하(및 최종 사용자)의 권리
관련 법률(GDPR, 영국 GDPR, 캘리포니아 CCPA/CPRA, 중국 PIPL 등)이 적용되는 범위 내에서 귀하는 다음과 같은 권리를 갖습니다: 접근, 정정, 삭제, 처리 제한, 데이터 이동성, 처리 반대, 동의 철회, 그리고 이러한 권리 행사로 인해 차별받지 않을 권리를 포함합니다.
- 고객 계정 데이터: 제13조에 명시된 연락처를 통해 요청해 주시기 바랍니다.
- 최종 사용자: 피드백 데이터는 고객이 컨트롤러로서 관리하므로, 최종 사용자의 권리 요청은 원칙적으로해당 고객에게 제기해야 하며, 당사는 고객이 이러한 요청에 대응할 수 있도록 기술적으로 지원합니다.
- 당사는 법정 기한 내에 응답하며, 귀하는 소재지 관할 감독기관에 이의를 제기할 권리도 있습니다.
9. 쿠키 및 유사 기술
당사는 로그인 유지 및 보안을 위해 필수 쿠키를 사용하며, 동의를 받은 경우 제품 사용 현황 파악을 위한 분석 쿠키를 사용합니다. 당사의 제품 사용 분석은 자체 개발한 퍼스트파티 방식으로, 페이지에는 어떠한 서드파티 분석 스크립트도 로드되지 않습니다. 여기서 사용되는 퍼스트파티 익명 식별자는 lb_aid 익명 어트리뷰션 용도로만 사용되며(제2.1조 "제품 사용 데이터" 참조), 브라우저 설정을 통해 삭제하거나 차단할 수 있습니다. 필수적이지 않은 쿠키는 브라우저 설정을 통해 관리할 수 있습니다. 유럽 지역 방문자의 경우, 웹사이트의 익명 통계 쿠키(lb_aid)는 쿠키 안내에서 "수락"을 선택하기 전까지는 기록되지 않으며, 그 사이에는 어떠한 통계 이벤트도 수집하지 않습니다. "거부"를 선택하면 통계가 수집되지 않으며 기존 식별자도 삭제됩니다. 지역과 관계없이 언제든지 하단의 "쿠키 설정"에서 선택을 변경할 수 있습니다.
10. 아동 개인정보 보호
본 서비스는 기업을 대상으로 하며, 만 16세 미만(또는 관련 법률이 정한 연령 미만)의 개인을 대상으로 하지 않습니다. 당사는 아동의 개인정보를 고의로 수집하지 않습니다.
11. 정책 변경
당사는 본 정책을 수시로 업데이트할 수 있습니다. 중대한 변경 사항은 서비스 내 알림 또는 이메일을 통해 안내하며, 상단의 "최근 업데이트" 날짜를 갱신합니다. 변경 사항이 적용된 이후 서비스를 계속 이용하시면 이에 동의한 것으로 간주됩니다.
12. 데이터 처리 계약(DPA)
피드백 데이터를 수탁 처리자로서 처리하는 부분에 대해, 당사는 기업 고객과 별도로 데이터 처리 계약(DPA)을 체결하여 처리 범위, 하위 처리자, 보안 조치, 협조 의무, 데이터 유출 통지, 감사권 및 국외 이전 메커니즘(SCCs 포함)을 규정합니다. 기업 고객은 제13조를 통해 이를 요청할 수 있습니다.
13. 문의하기
Loopback Privacy Policy
Effective date: 2026-07-14 · Last updated: 2026-07-14 · Version: v1.0
Language & governing version: This Policy is offered in multiple languages for your convenience; the language shown follows the interface language you select in Loopback, and any language not provided defaults to this English version. The governing version is this English version. Other translations are for reference only; in case of ambiguity or conflict between a translation and the English version, the English version prevails.
0. Definitions
- "Loopback" / "we" / "us": HAKKO AI PTE. LTD. (place of registration: Singapore, address: 120 Robinson Road #13-01 Singapore 068913), the provider of the Loopback feedback-analytics service.
- "Service": the Loopback platform for multi-channel collection, aggregation and AI analysis of user feedback (including the web application, API and related features).
- "Customer" / "you": the business or organization that subscribes to or uses the Service, and its authorized users.
- "End User": a third-party individual who leaves comments, ratings or feedback on the channels connected by a Customer (e.g. App Store reviewers, community members).
- "Personal information / personal data": information that can directly or indirectly identify a natural person.
1. Our two roles in data processing
Loopback is a business-to-business (B2B) software service involving two categories of data with different natures, in which our role differs:
| Scenario | Data type | Our role |
|---|
| Customer sign-up, login, billing, platform use | Account & usage data | Data Controller (GDPR) / personal information handler (PIPL) |
| Collecting and analyzing End-User feedback on the Customer's behalf after channels are connected | Feedback data | Data Processor (GDPR) / entrusted party (PIPL), processing on the Customer's instructions |
For Feedback data, the purposes and means of processing are determined by the Customer; we process it only on the Customer's instructions. The respective rights and obligations are further set out in the Data Processing Agreement (DPA) (see Section 12).
2. Information we collect
2.1 Account & usage data (where we are the Controller)
- Account information: company name, contact name, work email, password (stored encrypted), roles/permissions.
- Billing information: subscription tier (Free / Pro / Max), billing address, transaction records. Full card numbers are handled by Stripe; we do not store full card numbers.
- Configuration: connected channels, API keys or authorization tokens (stored encrypted, see Section 5).
- Usage & log data: login records, activity logs, IP address, browser/device information, feature-usage statistics, used for security, troubleshooting and product improvement.
- Cookies and similar technologies: see Section 9.
2.2 Feedback data (where we are the Processor, on the Customer's behalf)
Once a Customer connects the following channels, the platform collects public or authorized feedback content from them as authorized by the Customer, which may contain personal information:
- App stores: Apple App Store (public RSS), Google Play (Play Developer API), etc.;
- Community & ticketing: Reddit, Discord, Slack, Telegram, Feishu / WeCom, Zendesk, Intercom;
- Surveys & reputation: Typeform, Feishu Forms, Trustpilot, etc.
Such content may include: the body of comments/reviews, ratings, publication time, the author's display name or identifier as shown on the platform, and any other information the author voluntarily includes in the content. We do not actively solicit End Users' identity documents, precise location or other sensitive personal information; where feedback content incidentally contains such information, we process it only on the Customer's instructions and for no other purpose.
3. How we use information
- Provide and maintain the Service: account management, channel connection, feedback collection and aggregation, AI classification and insight generation, dashboards.
- AI analysis: sending feedback content to large language models for classification, summarization, sentiment and topic analysis (provider list in Section 6).
- Billing and customer support.
- Security, fraud prevention and compliance: anomaly detection, access auditing, legal obligations.
- Product improvement: optimizing features based on aggregated, de-identified usage statistics. We do not use Customers' Feedback data to train our own general-purpose models without the Customer's written consent (for third-party models' training policies, see Section 6).
Legal bases for processing (GDPR / PIPL)
- Performance of a contract: necessary to provide the subscribed Service;
- Legitimate interests: security, fraud prevention, product improvement (balancing test performed);
- Consent: where applicable (e.g. optional cookies, marketing emails);
- Legal obligation: where required by law.
- For Feedback data, the legal basis is obtained and represented by the Customer as Controller.
4. Cross-border transfers and data residency
Data is stored and processed at Google Cloud (us-central1, United States). If you are in the EU/UK, cross-border transfers rely on lawful mechanisms such as the Standard Contractual Clauses (SCCs).
Data flows differ by deployment form:
- SHARED_SAAS (shared hosting): data is stored in the Loopback-hosted environment;
- BYO_KEY (bring your own key): your own model/cloud keys are used, and AI calls are sent to the provider you designate;
- SELF_HOSTED: data is stored in your own environment, and Loopback generally does not access your Feedback data.
5. Data security
- TLS encryption in transit; sensitive fields (passwords, third-party API keys / OAuth tokens) stored encrypted.
- Role-based access control with four tiers (RBAC), least-privilege principle, access auditing.
- Tiered protection by sensitivity (from L1 data obfuscation to L4 confidential computing, depending on deployment form and plan).
- We apply reasonable technical and organizational measures, but no system can guarantee absolute security. In the event of a personal-data breach, we will notify the relevant parties within the statutory time limits in accordance with applicable law and contract.
6. Third-party providers (Subprocessors)
To provide the Service we entrust necessary data to the following categories of subprocessors. The AI model used depends on your region and membership tier:
| Category | Providers (examples) | Purpose |
|---|
| Cloud infrastructure | Google Cloud etc. | Hosting, storage, compute |
| AI models | Anthropic (Claude), OpenAI (GPT / Embedding), Google (Gemini) | Feedback classification, summarization, vectorization |
| Payments | Stripe etc. | Subscription billing |
| Email/notifications | Resend | Transactional email |
- We enter into data-processing terms with subprocessors requiring protection no lower than this Policy.
- Content sent to model providers is used to generate analysis results; we prioritize commercial API channels that do not use Customer data to train their models, and impose this by contract.
- The complete, up-to-date subprocessor list is available at: https://loopbackagent.com/subprocessors.html. We notify Customers of changes as provided in the DPA.
7. Data retention
- Account & billing data: retained during the service term and thereafter for the period required by law (e.g. tax, audit).
- Feedback data: retained as configured by the Customer in the platform or as agreed in the DPA; Customers may request export or deletion.
- After termination, we will delete or anonymize Customer data within the agreed period (default 30 days), except where retention is required by law.
8. Your (and End Users') rights
To the extent provided by applicable law (GDPR / UK GDPR / California CCPA/CPRA / China PIPL, etc.), you have the right to: access, rectification, erasure, restriction of processing, data portability, objection to processing, and withdrawal of consent, and not to be discriminated against for exercising these rights.
- Customer account data: please contact us via Section 13 to exercise these rights.
- End Users: because Feedback data is controlled by the Customer as Controller, End-User requests should in principle be directed to the relevant Customer; we will provide technical assistance to help Customers respond to such requests.
- We will respond within statutory time limits; you also have the right to lodge a complaint with your local supervisory authority.
9. Cookies and similar technologies
We use necessary cookies to maintain login and security, and, with consent, analytics cookies to understand product usage. You can manage non-essential cookies through your browser settings.
10. Children's privacy
The Service is intended for businesses and not for individuals under 16 (or the age specified by applicable law). We do not knowingly collect children's personal information.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated via in-service notice or email, and the "Last updated" date at the top will be revised. Continued use after changes take effect constitutes acceptance.
12. Data Processing Agreement (DPA)
For the portion where we act as Processor of Feedback data, we enter into a separate Data Processing Agreement (DPA) with business Customers, covering the scope of processing, subprocessors, security measures, assistance obligations, breach notification, audit rights and cross-border mechanisms (including SCCs). Business Customers may request it via Section 13.
13. Contact us
- Data protection / privacy matters: [email protected]
- General contact: [email protected]
- Mailing address: 120 Robinson Road #13-01 Singapore 068913
- EU/UK Representative (if applicable): to be designated and published separately
- Data protection matters: [email protected]