Contents

  1. Who We Are
  2. Scope of This Policy
  3. Personal Data We Collect
  4. How We Use Your Data
  5. Legal Basis for Processing (GDPR)
  6. Sharing and Disclosure
  7. International Data Transfers
  8. Security
  9. Data Retention
  10. Cookies and Session Data
  11. Your Rights
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact Us

1. Who We Are

Loom is a project and resource management platform developed and operated by Konnecta Systems ("we", "us", or "our"). Each client organisation is assigned a dedicated subdomain.

Konnecta Systems acts as the data controller for personal data processed through the Loom platform, and as a data processor on behalf of the organisations ("Clients") that subscribe to and configure Loom for their employees and contractors.

For any privacy-related enquiries, please contact us at hello@loom-eu.com.

2. Scope of This Policy

This Privacy Policy applies to all personal data collected, stored, or processed through:

It does not apply to third-party websites or services that may be linked from within Loom.

3. Personal Data We Collect

What Loom collects depends entirely on which product your organisation uses:

If you are only using Loom Reporting, only the Account & Authentication Data and Usage & Audit Data sections below are directly relevant to you.

Reporting-only users: you can skip to Section 4 — the HR, financial, and identity categories below do not apply to your use of Loom.

Identity & Contact Information

Government & Identity Documents

Collected only where required by law or your organisation's HR policies:

Professional & Employment Information

Time & Leave Data

Financial Information

Account & Authentication Data

Usage & Audit Data

Files & Attachments

Sensitive data note: Fields marked encrypted above are stored with application-level encryption in addition to standard database security controls. Access to sensitive employee data is further restricted by role-based permissions within Loom.

4. How We Use Your Data

We use personal data collected through Loom for the following purposes:

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without human oversight.

6. Sharing and Disclosure

We do not sell your personal data. We may share data with the following categories of recipients:

Your Organisation (the Client)

Data entered into Loom is accessible to authorised personnel within your organisation (managers, HR, finance) according to the roles and permissions configured by your organisation's Loom administrator.

Third-Party Service Providers

We engage sub-processors to help deliver the service:

Legal Requirements

We may disclose personal data if required by law, court order, or lawful request by a public authority, and only to the extent necessary.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.

7. International Data Transfers

Loom is operated primarily within the European Economic Area. Where personal data is transferred outside the EEA (for example, to Microsoft Azure services or Sentry), we ensure that appropriate safeguards are in place, such as:

8. Security

We take the security of your personal data seriously and implement the following technical and organisational measures:

No system is 100% secure. If you believe your data has been compromised, please contact us immediately at security@loom-eu.com.

9. Data Retention

We retain personal data for as long as:

When data is no longer required, we take reasonable steps to delete or anonymise it securely. Specific retention schedules may be defined by your organisation in accordance with their own retention policies. Please contact your organisation's administrator for details applicable to your account.

10. Cookies and Session Data

Loom uses cookies and similar technologies to maintain your authenticated session and ensure the secure operation of the platform.

Session Cookie

A session cookie is set upon login to identify your authenticated session. This cookie expires after 24 hours of inactivity (or when you log out). It does not track you across third-party websites.

JWT Tokens

Loom uses JSON Web Tokens (JWTs) with a 2-hour validity period for API access, and refresh tokens valid for up to 30 days to maintain seamless sessions.

Static Content Caching

Browser caching is used for static assets (images, scripts, styles) to improve performance. These caches do not contain personal data.

Loom does not use advertising, tracking, or analytics cookies from third parties. If you disable cookies in your browser, you will not be able to log in to the platform.

11. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

To exercise any of these rights, please contact your organisation's Loom administrator or reach us directly at hello@loom-eu.com. We will respond within 30 days.

Note that some requests may be subject to verification of your identity and may be limited where processing is required by law or by your employment relationship.

12. Children's Privacy

Loom is an enterprise application intended for use by adults in a professional employment context. We do not knowingly collect personal data from individuals under the age of 16. If you believe a minor's data has been entered into the platform, please contact us immediately.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the platform, our data practices, or applicable law. When we make material changes, we will notify you via the email address associated with your account or by posting a notice within the Loom platform. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of Loom after the effective date of an updated policy constitutes acceptance of the revised terms.

14. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us:

If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.