Roles
For customer content, you are the controller and we are the processor. For account and usage data we are a controller for the limited purposes of running and securing the service and billing for it.
Processing instructions
We process customer content only on your documented instructions — which in practice means the requests your users make and the connections your administrators authorize. We do not process it for our own purposes, including model training.
Security measures
Encryption in transit and at rest, per-tenant key derivation for credentials, role-based access control, immutable audit logging, annual third-party penetration testing and quarterly access reviews. The full list is in our security documentation.
Breach notification
We notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with the information needed for you to meet your own obligations.
Sub-processing and audits
Sub-processors are published and subject to 30 days' advance notice. Customers may request our current SOC 2 Type II report and penetration test summary annually under NDA, and Enterprise customers may request an audit on reasonable notice.
Questions about this document? Write to legal@hoopi.com. This page is a plain-language summary provided for convenience and is not itself legal advice.

