How RetentionLoom processes personal data under the EU/UK General Data Protection Regulation. Last updated June 2026.
Your role & ours
When you use RetentionLoom to build and send retention emails, your customers' personal data (email addresses, purchase history, engagement events) is processed. You are the data controller; RetentionLoom acts as a data processor acting only on your documented instructions. Your connected ESP (Klaviyo, Salesforce Marketing Cloud, Mailchimp or Customer.io) is a separate processor under its own terms.
Lawful basis
Retention and marketing emails generally rely on consent or legitimate interest. You are responsible for ensuring a valid lawful basis exists for each contact before adding them to a flow, and for honouring opt-outs. Every email RetentionLoom drafts includes an unsubscribe and preference link.
Data subject rights
Your customers can exercise their rights to access, rectify, erase, restrict, port, and object to processing. Because RetentionLoom stores only the audit inputs and generated content you create — not your full customer list — most subject requests are fulfilled directly in your ESP. We will assist with any request that touches data held in RetentionLoom within 30 days.
What we store & for how long
We store your account details, brand audit inputs, generated strategies, flows and email copy. This is retained for the lifetime of your subscription plus a 3-week grace period, after which it can be deleted on request. We do not sell personal data or use your customers' data to train third-party models.
Sub-processors & transfers
We use vetted sub-processors for hosting, AI generation and your chosen ESP. Where data leaves the EEA/UK, transfers are covered by Standard Contractual Clauses or an adequacy decision. A current sub-processor list and a Data Processing Agreement (DPA) are available on request.
Cookies
This app uses only essential storage to keep you signed in and remember your workspace. No advertising or cross-site tracking cookies are set.
Contact
For data protection questions or to request a DPA, contact privacy@retentionloom.com. EU/UK users may also lodge a complaint with their local supervisory authority.
This summary is provided for transparency and is not legal advice. Configure your own DPA and privacy policy before processing live customer data.