Weloop
La solution Mesure Résultats Tarifs
🇫🇷 🇪🇺 100% souverain Réserver une démo →
La solution Mesure Résultats Tarifs
Réserver une démo →

🇫🇷 🇪🇺 100% souverain — hébergé en France & en Europe

Legal

Data protection

Weloop processes personal data on behalf of your organization, which stays the controller under the GDPR. This page lists the providers Weloop relies on, the technical and organizational measures that protect the data, the record of processing, and what Weloop commits to when a personal data breach happens. The Data Processing Agreement (DPA) that binds these commitments is available from gdpr@weloop.ai.

Data protection officer

Weloop has appointed an external data protection officer: Cabinet DPO 101, registered with the CNIL under reference DPO-172500. Contact the officer at privacy@weloop.io.

Your data protection contact

Name the mailbox Weloop writes to about a breach or a provider change in Settings > Data protection of the Weloop dashboard. Only organization owners and operators can set it. Without a contact, notices go to the organization owners.

Sub-processors

The providers listed here receive personal data when Weloop works for you. A provider marked optional only receives data once you turn the matching feature or integration on. Weloop tells your data protection contact about a new or replaced provider at least 30 days before the change, so you can object under the terms of the DPA.

ProviderPurposeLocationOptional
ScalewayHosting, database, and file storageFranceNo
Bunny.netDelivery of attachments and widget filesEuropean UnionNo
SMTP relaySending notification and sign-in emailsEuropean UnionNo
LettermintReceiving replies sent by emailEuropean UnionNo
Mistral AIAI answers, summaries, and reading of attachmentsEuropean UnionNo
DeepLMachine translation of messagesEuropean UnionYes
Weloop AI agentWeloop’s feedback assistantFranceNo
GoogleSign in with GoogleUnited StatesYes
SlackSlack integrationUnited StatesYes
Microsoft TeamsMicrosoft Teams integrationEuropean UnionYes
Atlassian JiraJira integrationEuropean UnionYes
ServiceNowServiceNow integrationEuropean UnionYes

An organization that configures its own SMTP server replaces the SMTP relay row with its own provider. Self-hosted deployments choose every provider themselves; this list describes the cloud service.

Record of processing

Weloop keeps this record as a processor (Article 30(2)).

ProcessorWeloop, contact gdpr@weloop.ai
ControllersEach organization using the cloud service
Processing on behalfCollecting feedback through the widget, answering it with an AI assistant and staff, turning it into tickets, notifying people by email, publishing announcements and surveys
Data subjectsEnd users of your websites and applications, your staff
Categories of dataIdentity (name, email, job title), messages and attachments, page URL and title, browser and device, approximate location derived from the IP address, session recordings when turned on
Transfers outside the EUOnly through the optional providers marked United States, once you turn them on
RetentionData stays until you delete the thread, the project, or the organization; inbound email copies are removed after 90 days
Security measuresThe technical and organizational measures later on this page

Technical and organizational measures

These measures apply to the cloud service. The sovereignty and security page describes the hosting and the controls in more detail.

  • Encryption in transit. TLS 1.2 or higher on every connection, certificates renewed automatically.
  • Encryption at rest. Organization SMTP passwords, extension keys, and integration credentials are encrypted with keys that can be rotated. The database runs on a managed service on a private network.
  • Access control. Role-based access at the organization and project level, checked server-side on every request. SSO through your identity provider for staff.
  • Data minimization. The raw IP address is never stored; only the derived country and city are. Application logs mask email addresses, IP addresses, and tokens. Session replay is off by default, masks every input, and each visitor can opt out per submission.
  • Confidentiality. Access to production is limited to the engineers who need it and reviewed yearly. Every employee completes security training.
  • Availability. Daily backups, a tested disaster recovery plan, and a public status page.
  • Provider oversight. Every provider is bound by a written contract with equivalent obligations and listed in the table earlier on this page.

Personal data breach

When Weloop becomes aware of a personal data breach that affects your data, Weloop tells your data protection contact within 48 hours. The notice describes what happened, which data and how many people are affected, the likely consequences, and the measures taken. It is updated as the investigation continues, so you can notify your supervisory authority within the 72 hours Article 33 gives you.

Report a suspected breach or a security vulnerability to security@weloop.ai.

Related

  • Privacy policy
  • Terms of use
  • Help and documentation
Weloop

Le Proxy PM IA de vos interactions internes.

Produit
  • La solution
  • NPS & CSAT
  • Résultats
Confiance
  • Souveraineté
  • RGPD
  • Sécurité
  • Mistral AI
Entreprise
  • Réserver une démo
  • Aide & documentation
  • Contact
  • Carrières
© 2026 Weloop. Tous droits réservés. Politique de confidentialité CGU Gérer les cookies 🇫🇷 Hébergé en France · RGPD par conception