Keeping customer data safe and secure is a huge responsibility and a top priority for us. Here’s how we make it happen.
- We never have and never will sell customer data.
- We don’t run ads for other services in our products.
- We limit the data we collect: if we don’t need it, we don’t ask for it.
- We put a lot of security measures into place including in-transit encryption and encryption at-rest.
- We do not access customer data unless granted permission by customer to support resolution of a problem, or if necessary to maintain the service.
Employee and contractor agreements for people working at Loomio include confidentiality clauses to protect Loomio and customer confidential information. We treat all customer information and data as confidential, except for situations where a customer has explicitly made the information publicly accessible.
Loomio Limited is a for-profit social enterprise owned by worker-owned Loomio Cooperative. Loomio staff are either cooperative members or on a path to cooperative membership, and share the values and responsibilities of Loomio as business co-owners. You can read about us here.
Access to data is tightly controlled and protected internally within Loomio.
All data are written to multiple disks instantly, backed up daily, and stored in multiple secure locations. Files that our customers upload are stored on servers that use modern techniques to remove bottlenecks and points of failure.
This means the code is open to view, but your data is not. There are many benefits including that many people have read our code and review changes as they go in. We've got nothing to hide - there are no backdoors in Loomio. We do not hold your data to ransom, you can export your data at any time and run your own Loomio server.
Loomio software is licensed under the GNU Affero General Public License v3.0
Loomio Limited operate services using Loomio software goverened by our Terms of Service.
loomio.com is our most widely used service and available globally. Loomio.com is hosted on servers based in the USA operated by DigitalOcean, LLC.
More information can be found at DigitalOceans’s security page.
Backup data and Recovery
Loomio.com backup and data recovery is managed by DigitalOcean. The software and data is automatically backed up on secure, access controlled, and redundant storage.
loomio.nz is a service running in DigitalOcean's Sydney datacenter.
This service is available only on request and approved for use for New Zealand Government data processing.
The service holds a Tier 3 security status. For more information read New Zealand Government cloud services Security Risk and Assurance.
loomio.eu is a service running in DigitalOcean's Amsterdam datacenter.
Loomio operates private hosted services for organizations around the world. A private database (non-shared) that is set up on a server and location of customer choice, configured to customer brand, logo and color palette, under customer domain name.
Loomio offers direct support for customers self-hosting Loomio. Contact us for more information.
Private and Self-host services ensure the highest level of security, configuration and flexibility for your organization.
We’ve been operating loomio since 2013. Security isn’t just about technology, it’s about trust. We’ve worked hard to earn the trust of hundreds of thousands of people world wide in tens of thousands Loomio groups. We’ll continue to work hard every day to maintain that trust. Longevity and stability is core to our mission at Loomio.