Controller and scope
Loopika AI is operated by The Station Group Holdings Co., Ltd. (“Company,” “we,” “us”). The Company acts as controller for our website, user accounts, sales, support, and service operations. When we process an organization's customer data only on that customer's instructions, we act as a processor under the applicable agreement.
This policy applies to loopika.ai, the Loopika AI application, product demonstrations, sales communications, and our support channels.
Data we collect
- Account and contact data, such as name, email address, telephone number, organization, role, and authentication information.
- Business and Brand DNA data, such as products, services, prices, communication guidelines, knowledge-base materials, and uploaded files.
- Data from connected social channels, such as messages, comments, sender profiles, account identifiers, content, and engagement data within the permissions granted by each platform.
- Lead, conversation, booking, order, and CRM data submitted by you or end users through the service.
- Usage and device data, such as IP address, browser type, event logs, timestamps, viewed pages, preferences, and diagnostic data.
- Subscription, billing, plan status, and transaction history. Payment providers may collect payment-card details directly rather than sharing them with us.
- Communications with our team, including contact forms, emails, support requests, and feedback.
Sources of data
We receive data directly from you, your account or organization administrator, end users who contact your brand, platforms you connect, our service providers, and automatically through use of our website or service. If you provide another person's data, you must have the rights and lawful basis required to provide it to us.
Purposes and lawful bases
- Provide the service, create accounts, connect platforms, process messages, generate content, manage leads, and perform our contract.
- Authenticate users, secure the service, prevent fraud, spam, and misuse, and protect users and legal rights.
- Process billing, manage subscriptions, provide support, and send service communications.
- Analyze performance, fix errors, and develop or improve features using aggregated, de-identified, or otherwise permitted data.
- Send marketing communications where you consent or the law otherwise permits; you may opt out at any time.
- Comply with law and government orders and establish, exercise, or defend legal claims.
Artificial intelligence processing
The service uses AI to generate content, classify intent, recommend replies, summarize information, score leads, and support automation. Relevant data may be sent to model or infrastructure providers acting as processors under contractual and security safeguards.
AI output can be incomplete or inaccurate. Account administrators should review output before using it for important decisions, particularly those involving prices, health, law, finance, credit, employment, or individual rights.
International transfers
Some providers may process data outside Thailand. Where the destination does not provide adequate protection, we use safeguards recognized by applicable law, such as data-protection clauses, security controls, and purpose limitations, or obtain consent where required.
Retention
We retain data only as long as needed for the stated purposes, the contract, support, security, and legal retention periods. We then delete, destroy, or de-identify it. Backup copies may remain temporarily until normal rotation and are access-restricted.
Organization customers control retention of their end-user data within their accounts, subject to product settings, the subscribed plan, and applicable law.
Security
We use organizational, technical, and physical measures appropriate to risk, including access controls, encryption in transit, event logging, backups, organization-level data separation, and vendor review. No system is completely secure. Users must protect passwords and connection tokens and notify us promptly of suspected unauthorized access.
Your data protection rights
Subject to applicable law, you may withdraw consent, request access and a copy, request correction, deletion or destruction, restrict processing, request portability, object to processing, and complain to the Personal Data Protection Committee.
We may verify your identity and may refuse a request where permitted by law. If an organization customer controls the data, contact that organization first; we will assist it as required in our role as processor.
Children's data
The service is intended for businesses and persons able to enter a contract. We do not intentionally collect data directly from children without an appropriate lawful basis or consent. If you believe child data was submitted unlawfully, notify us so we can take appropriate action.
Changes to this policy
We may update this policy as the service, law, or our practices change. We will update the date above and, for material changes, provide notice through the website, service, or email.
Contact us about personal data
To exercise a right or ask a question or make a complaint about personal data, contact our privacy team.