LegalSubprocessors
Subprocessors
The third parties that process Service Data on our behalf, how we vet them, the safeguards they must meet, and how you are notified before anything changes.
Table of contents
What is a Subprocessor
A subprocessor is a third-party data processor engaged by ClosedLoop Labs LLC, doing business as "ClosedLoop AI" ("ClosedLoop AI," "we," "us," or "our") that has or potentially will have access to or process Service Data (which may contain Personal Data) on our behalf. ClosedLoop Labs LLC engages different types of subprocessors to perform various functions as explained in the tables below.
ClosedLoop Labs LLC refers to third parties that do not have access to or process Service Data but who are otherwise used to provide the Services as "subcontractors" and not subprocessors. Such subcontractors are not listed on this page.
Sources you connect to ClosedLoop AI under your own credentials, such as your call recording, CRM, support or product management tools, are also not our subprocessors. You engage those providers directly and they process your data on your instructions, not ours. We read from them at your direction; we do not send Service Data to them. Tools we use purely to run our own business, such as our own call recording, are likewise not listed here, because they do not process Service Data. Where such a tool does hold records about your account or your support interactions with us, we list it, because that is the same category of content as the support mailbox we already list; our customer relationship management platform appears in the list below for that reason.
Due Diligence
ClosedLoop AI undertakes to use a commercially reasonable selection process by which it evaluates the security, privacy, and confidentiality practices of proposed subprocessors that will or may have access to or process Service Data. We assess each subprocessor's compliance certifications, security controls, data handling practices, and contractual commitments before engagement.
Contractual Safeguards
ClosedLoop AI requires its subprocessors to satisfy equivalent obligations as those required from ClosedLoop AI (as a Data Processor) as set forth in ClosedLoop AI's Data Processing Agreement ("DPA"), including but not limited to the requirements to:
- Process Personal Data in accordance with data controller's (i.e., Subscriber's) documented instructions (as communicated in writing to the relevant subprocessor by ClosedLoop AI).
- In connection with their subprocessing activities, use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable, pursuant to applicable data protection laws.
- Provide regular training in security and data protection to personnel to whom they grant access to Personal Data.
- Implement and maintain appropriate technical and organizational measures (including measures consistent with those to which ClosedLoop AI is contractually committed to adhere insofar as they are equally relevant to the subprocessor's processing of Personal Data on ClosedLoop AI's behalf) and maintain appropriate compliance certifications (such as SOC 2, ISO 27001, or equivalent) that evidence compliance with this obligation. ClosedLoop AI reviews subprocessors' security documentation, certifications, and audit reports as part of our due diligence process.
- Promptly inform ClosedLoop AI about any actual or potential security breach.
- Cooperate with ClosedLoop AI in order to deal with requests from data controllers, data subjects, or data protection authorities, as applicable.
The list of subprocessors in Sections 07 and 08 is the agreed list for the purposes of Clause 9 of the EU Standard Contractual Clauses, where those Clauses have been executed, and is binding to that extent. The remainder of this policy describes ClosedLoop AI's engagement process and does not itself create rights or remedies beyond those set out in your Data Processing Agreement and Order Form.
If you are a ClosedLoop AI Subscriber and wish to enter into our Data Processing Agreement (DPA), please review our Data Processing Agreement or contact us at support@closedloop.sh.
Process to Engage New Subprocessors
For all Subscribers who have executed ClosedLoop AI's standard DPA, ClosedLoop AI will provide notice of updates to the list of subprocessors that are utilized or which ClosedLoop AI proposes to utilize to deliver its Services. Notice is given by email to the Subscriber's designated privacy contact or, where none has been designated, to the owner and administrators of the Subscriber's workspace, at least thirty (30) days before the subprocessor is engaged. This policy is updated at the same time, so that Subscribers can stay informed of the scope of subprocessing associated with the ClosedLoop AI Services.
Pursuant to the DPA, a Subscriber can object in writing to the processing of its Personal Data by a new subprocessor within thirty (30) days after receiving that notice, and shall describe its legitimate reasons to object. Where an objection is raised within that period, ClosedLoop AI will not engage the subprocessor in respect of that Subscriber's Personal Data until the objection has been resolved. If Subscriber does not object during such time period, the new subprocessor(s) shall be deemed accepted.
If a Subscriber objects to the use of a subprocessor pursuant to the process provided under the DPA, ClosedLoop AI shall have the right to cure the objection through one of the following options (to be selected at ClosedLoop AI's sole discretion):
- ClosedLoop AI will cease to use the subprocessor with regard to Personal Data
- ClosedLoop AI will take the corrective steps requested by Subscriber in its objection (which remove Subscriber's objection) and proceed to use the subprocessor to process Personal Data
- ClosedLoop AI may cease to provide or Subscriber may agree not to use (temporarily or permanently) the particular aspect of a ClosedLoop AI Service that would involve the use of the subprocessor to process Personal Data
Termination rights, as applicable and agreed, are set forth in the DPA and in your Order Form. Where an Order Form grants a termination right for an unresolved subprocessor objection, that right applies in addition to the options above.
Data Retention Policies
ClosedLoop AI maintains the following data retention policies for Service Data processed by our subprocessors:
- Raw Customer Data, Processed Insights and Pattern Recognition Data: Retained for the duration of the Subscription Term. On termination, deleted or returned at the Subscriber's choice, unless retention is required by applicable law. A certificate of deletion is available on request
- Audit Logs: Retained for the duration of the Subscription Term and deleted alongside the Subscriber's other data on termination, except where retention is required by applicable law
- Account Data: Retained for the duration of the Subscription Term and deleted within thirty (30) days of account termination, unless a longer retention period is required by law
Subscribers may request deletion of their data at any time through their account settings or by contacting support@closedloop.sh. Data deletion requests will be processed promptly in accordance with our DPA and applicable data protection laws.
Security Measures
ClosedLoop AI implements comprehensive technical and organizational security measures to protect Service Data processed by our subprocessors:
- Encryption in Transit: All data transmitted to and from subprocessors is encrypted using TLS 1.3 or higher protocols
- Encryption at Rest: All data stored by subprocessors is encrypted using industry-standard encryption mechanisms, including Azure's encryption-at-rest capabilities
- Access Controls: Access to Service Data is restricted to authorized personnel only, with role-based access control (RBAC) and multi-factor authentication (MFA) where applicable
- Authentication: JWT-based authentication for API access, with optional two-factor authentication (2FA) for enhanced security
- Audit Logging: Comprehensive audit logging of all data access, modifications, and system activities, retained for the duration of the Subscription Term for security monitoring and compliance
- Secret Management: All API keys, credentials, and sensitive configuration data are stored in Azure Key Vault, with no hardcoded secrets in application code
- Network Security: Network-level security controls including firewalls, intrusion detection, and DDoS protection
- Regular Security Assessments: Ongoing security assessments, vulnerability scanning, and penetration testing
All subprocessors are contractually required to maintain equivalent security measures and to promptly notify ClosedLoop AI of any security incidents affecting Service Data.
Infrastructure Subprocessors - Service Data Storage
ClosedLoop AI owns or controls access to the infrastructure that ClosedLoop AI uses to host Service Data submitted to the Services, other than as set forth below. ClosedLoop AI production systems for the Services are hosted in Microsoft Azure cloud facilities in the United States and the European Union. Each Subscriber's Service Data is stored and processed in the region selected during onboarding and does not leave that region during normal operations. The Subscriber's Service Data may be shifted among data centers within a region to ensure performance and availability of the Services. The following table describes the countries and legal entities engaged in the storage of Service Data by ClosedLoop AI.
| Entity Name | Entity Type | Entity Country |
|---|---|---|
| Microsoft Corporation | Cloud Service Provider (Azure) | United States, European Union |
| Cloudflare, Inc. | Content delivery, DDoS protection, DNS and security logging; may process IP addresses | United States, European Union |
Service-Specific Subprocessors
ClosedLoop AI works with certain third parties to provide specific functionality within the Services. These providers are the Subprocessors set forth below. In order to provide the relevant functionality, these Subprocessors access Service Data. Their use is limited to the indicated Services.
| Entity Name | Entity Type | Entity Country |
|---|---|---|
| Microsoft Corporation (Azure OpenAI) | Generative AI services provider | United States, European Union |
| Stripe, Inc. | Payment processing and billing service | United States |
| Resend (Plus Five Five, Inc.) | Transactional and notification email delivery; message bodies may include insight text and recipient contact data | United States |
| New Relic, Inc. | Application performance monitoring and log aggregation; log payloads may include technical identifiers and, in error conditions, response content from connected sources | United States |
| PostHog, Inc. | Product analytics for the ClosedLoop AI application; processes authenticated user identifiers, team identifiers and in-app page paths | United States |
| Wikimedia Foundation, Inc. | Public reference lookup used to verify vendor identities; queries may include vendor names derived from customer content | United States |
| Google LLC (Google Workspace) | Customer support communications and account administration by email | United States, European Union |
| Attio Ltd | Customer relationship management; account, subscription and support-interaction records for administrative contacts | United Kingdom |
| Serper (serper.dev) | Web search API used to verify vendor and competitor identities; queries may include vendor names derived from customer content | United Kingdom |
Questions about our subprocessors?
support@closedloop.sh