HourLoop legal and trust
Data processing overview
This overview helps organisations evaluate HourLoop’s early-access data flows. A signed data-processing agreement should govern production use where required.
Roles
The organisation generally determines why employee workspace data is processed, while HourLoop processes that data to provide the contracted platform. The parties should confirm their legal roles for each pilot.
Processing scope
Authentication, organisation membership, execution records, shared support workflows, service security, backups, troubleshooting, and agreed product analytics.
Security controls
Server-side bridge secrets, signed sessions, role and organisation scoping, prepared SQL statements, audit events, restricted CORS, no-store private responses, and protected administrator provisioning.
Subprocessors and incidents
Applicable hosting, database, analytics, and email providers should be listed in the signed pilot documentation. Incident notification duties and contacts should be agreed before production use.
Deletion and export
Custom automated retention is not yet claimed as generally available. Required retention, export, and deletion procedures must be confirmed during pilot contracting.
