Loopback 子處理者清單 / Subprocessor List
最近更新:2026-07-14 · 版本:v1.0
本清單揭露 Loopback 為提供服務而委託的第三方子處理者,以及其處理的資料類別、用途與所在地。清單隨服務變化更新;重大變更將按《資料處理協議(DPA)》約定通知企業客戶。子處理者的選用取決於客戶所選功能與部署形態。
一、基礎設施與平台
| 子處理者 | 用途 | 處理的資料 | 所在地/地區 | 適用地區 |
|---|
| Google Cloud Platform(GCP) | 託管、儲存、運算(專案loopback-500616) | 帳戶資料、設定、意見回饋資料 | 美國 us-central1 | 全部 |
| Stripe | 訂閱計費與付款 | 聯絡人、帳單資訊(不含完整卡號) | 美國 | 全部 |
| Resend | 交易型電子郵件、通知 | 聯絡人電子郵件 | 美國 | 全部 |
二、AI 模型供應商
呼叫取決於客戶會員等級;用於意見回饋分類、摘要、情感/主題分析與向量化。
| 子處理者 | 用途 | 處理的資料 | 所在地 |
|---|
| Anthropic(Claude) | 意見回饋分類、摘要、洞察生成 | 意見回饋內容文字 | 美國 |
| OpenAI(GPT / Embeddings) | 意見回饋分類、摘要、向量化(embedding) | 意見回饋內容文字 | 美國 |
| Google(Gemini) | 意見回饋分類、摘要 | 意見回饋內容文字 | 美國/全球 |
三、說明
- BYO_KEY / SELF_HOSTED 部署:客戶自帶模型/雲端金鑰時,AI 呼叫將發送至客戶指定的供應商,相應供應商由客戶自行選擇並承擔揭露義務;私有部署下 Loopback 通常不會接觸意見回饋資料。
- 不用於模型訓練:我們優先選用不將客戶資料用於其模型訓練的商用 API 通道,並在合約中訂立此限制。
- 渠道平台:客戶主動串接的第三方渠道(App Store、Google Play、Steam、Reddit、Discord、Slack、Telegram、Lark/企業微信、Zendesk、Intercom、Typeform、Trustpilot 等)是資料來源,其資料處理受客戶與各渠道之間的關係及各渠道條款約束,不屬於本清單意義上的 Loopback 子處理者。
四、變更通知
新增或更換子處理者前,我們將依 DPA 約定提前通知企業客戶;客戶如有合理異議,可依 DPA 約定的機制處理。
訂閱變更通知:[email protected]
Loopback Subprocessor List
Last updated: 2026-07-14 · Version: v1.0
This list discloses the third-party subprocessors Loopback engages to provide the Service, together with the categories of data they process, the purposes and their locations. The list is updated as the Service changes; material changes are notified to business Customers as provided in the Data Processing Agreement (DPA). Which subprocessors are used depends on the features and deployment model selected.
1. Infrastructure and platform
| Subprocessor | Purpose | Data processed | Location/region | Applicable region |
|---|
| Google Cloud Platform (GCP) | Hosting, storage, compute (project loopback-500616) | Account data, configuration, feedback data | us-central1, United States | All |
| Stripe | Subscription billing and payments | Contact, billing info (no full card numbers) | United States | All |
| Resend | Transactional email, notifications | Contact email | United States | All |
2. AI model providers
Invocation depends on the Customer's membership tier; used for feedback classification, summarization, sentiment/topic analysis and vectorization.
| Subprocessor | Purpose | Data processed | Location |
|---|
| Anthropic (Claude) | Feedback classification, summarization, insight generation | Feedback content text | United States |
| OpenAI (GPT / Embeddings) | Feedback classification, summarization, vectorization (embeddings) | Feedback content text | United States |
| Google (Gemini) | Feedback classification, summarization | Feedback content text | United States/global |
4. Notes
- BYO_KEY / SELF_HOSTED deployments: where the Customer brings its own model/cloud keys, AI calls are sent to the provider designated by the Customer, who selects that provider and bears the disclosure obligation; in self-hosted deployments Loopback generally does not access feedback data.
- No training use: we prioritize commercial API channels that do not use Customer data to train their models, and impose this by contract.
- Channel platforms: the third-party channels a Customer connects (App Store, Google Play, Steam, Reddit, Discord, Slack, Telegram, Feishu/WeCom, Zendesk, Intercom, Typeform, Trustpilot, etc.) are data sources; their data processing is governed by the relationship between the Customer and each channel and by each channel's terms, and they are not Loopback subprocessors within the meaning of this list.
5. Change notifications
Before adding or replacing a subprocessor, we will give business Customers advance notice as provided in the DPA; Customers with a reasonable objection may proceed under the mechanism set out in the DPA.
Subscribe to change notifications: [email protected]