The Data Controller for personal data collected through the ReachLoop platform is:
Under art. 37 of EU Regulation 2016/679 (GDPR), the Data Controller is not required to appoint a Data Protection Officer (DPO) as it is a small-to-medium enterprise that does not carry out large-scale processing of special categories of data. All data protection requests can be directed to privacy@reachloop.io.
ReachLoop collects and processes the following categories of personal data:
a) Account data (via Clerk)
b) LinkedIn data (via Unipile)
c) Prospect data
d) Message data
e) Usage data
f) Payment data (via Polar)
g) Technical data
Each processing activity is grounded in a specific legal basis under art. 6 of the GDPR:
a) Contract performance — art. 6(1)(b) GDPR
b) Explicit consent — art. 6(1)(a) GDPR
c) Legitimate interest — art. 6(1)(f) GDPR
d) Legal obligation — art. 6(1)(c) GDPR
Under art. 22 of the GDPR, we inform you that the service involves automated decision-making:
Your rights:
User control: you maintain full control and can:
Some of our sub-processors are located outside the European Economic Area (EEA). For each transfer, appropriate safeguards are in place under Chapter V of the GDPR:
You may request information on the specific safeguards in place by writing to privacy@reachloop.io.
Personal data is retained only for as long as necessary for the purposes for which it was collected:
At the end of the retention period, data is securely deleted or irreversibly anonymized.
Under articles 15-22 of the GDPR, you have the right to:
Response time: within 30 days from receipt of the request, extendable by an additional 60 days for complex requests, with prior notice.
How to exercise your rights: send an email to privacy@reachloop.io or use the Settings page in your account.
To deliver the service, we rely on the following sub-processors:
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Clerk Inc. | Authentication & user management | USA | SCCs + additional safeguards |
| Convex Inc. | Database & backend | EU-West | EU hosting |
| OpenAI LLC | AI message generation | USA | SCCs (EU Decision 2021/914) |
| Unipile SAS | LinkedIn API integration | France/EU | EU hosting |
| Polar Sh | Payment processing | EU | EU hosting |
| Vercel Inc. | Application hosting | USA | SCCs |
The Data Controller ensures that all sub-processors provide sufficient guarantees to implement appropriate technical and organizational measures in compliance with the GDPR.
We implement appropriate technical and organizational measures to ensure a level of security proportionate to the risk, in accordance with art. 32 of the GDPR:
ReachLoop is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, such data will be deleted immediately and without delay. If you believe we have collected data relating to a minor, please contact us at privacy@reachloop.io.
We reserve the right to update this Privacy Policy. Changes will be handled as follows:
The date of the last update is always visible at the top of this page.
ReachLoop is a product of NuMa Menu S.r.l.
Registered Office: Corso XXII Marzo, 4 — 20135 Milano (MI), Italia
VAT Number: IT14573500965