Privacy Policy

Last updated 16 June 2026

ProgramLoop is designed to support privacy-by-design practices and to help organizations meet their data protection obligations. This policy explains what data we process, how AI is used, what we minimize and redact, and the rights available to users and organizations. It is not legal advice and does not by itself constitute a determination of compliance with any specific law.

1. Personal data we collect

We collect the minimum personal data needed to operate the platform: account data (name, email, authentication identifiers) and, where an organization records it, limited contact details for founders and programme participants (e.g. name, email, phone, professional profile links). Organizations are the controllers of the participant data they enter; ProgramLoop processes it on their behalf.

2. Startup and programme data we process

To run assessments, follow-ups, metrics and reports, we process non-identifying programme data such as startup name, sector, stage, business model, assessment scores, dimension scores, follow-up status, metrics, notes and uploaded documents. This data is stored per organization and isolated by row-level security.

3. AI-assisted processing

Some features use AI models to draft reports, recommendations and insights. AI is positioned as a decision-support tool; every AI feature has a deterministic, non-AI fallback so the product never depends on a model being available. All AI requests pass through a single internal AI gateway that applies the controls described below before any data leaves the platform.

4. Data minimization

We minimize what is sent to AI providers. Fields are classified by sensitivity (public, internal, confidential, personal). Under the default Safe AI mode, personal fields are removed or redacted before a prompt is built, confidential fields are sanitized, and only internal/public programme data is used. Organizations should not submit personal or sensitive data that is not necessary for the task.

5. PII redaction

A no-bypass sanitizer runs on every prompt before it reaches an AI provider. It redacts obvious personal data — email addresses, phone numbers, LinkedIn and social profile URLs, other URLs, physical addresses, and explicitly-flagged personal names — replacing them with neutral placeholders. The sanitizer records only a count of redactions; it never stores the redacted values.

6. Organization-level AI policy

Each organization controls how AI is used through an AI policy set by an owner or admin:

  • Full AI — richest context; explicitly-authorized personal context may be used. The regex PII sanitizer still runs as a last safety net.
  • Safe AI (default) — personal data removed/redacted, confidential data sanitized.
  • No AI — AI generation is disabled and deterministic, non-AI fallbacks are used; no data is sent to an AI provider.

7. AI audit logging

We keep an audit trail of AI usage for security, cost governance and accountability. ProgramLoop does not intentionally store raw prompts or raw AI completions in these audit logs. Each audit record stores only metadata such as the feature, the AI provider and model, request status, token counts, duration, the applied policy mode, a redaction count, and a timestamp — never the prompt text, the generated content, or personal-data values.

8. Subprocessors

We use a small set of infrastructure and AI subprocessors to deliver the service. The active AI provider depends on the organization configuration and deployment environment. See our Subprocessors page for the current list.

9. Data retention

Programme and account data are retained for as long as an organization maintains its workspace, and then deleted or anonymized on request or after account closure, subject to legitimate retention needs. AI audit metadata is retained on a rolling basis for security and cost analysis and contains no prompt, completion or personal-data values.

10. Security measures

We apply organization-based tenant isolation enforced by database row-level security, server-side authorization checks, hashed and expiring tokens for public links, and server-only handling of provider API keys. No security measure is perfect; we continuously improve our controls.

11. User and organization rights

Depending on your role and applicable law, you may request access, correction, export or deletion of personal data, and organizations may configure data minimization through the AI policy. Requests are handled through the organization administrator and our contact channel below.

12. Contact

For privacy questions or data requests, contact contact@programloop.co.