GDPR Compliance

Last updated: June 17, 2026

Looms is committed to protecting the personal data of individuals in the European Economic Area (EEA), the United Kingdom, and other regions covered by the General Data Protection Regulation (GDPR). This page explains how we meet our obligations and how you can exercise your rights.

1. Our Role Under the GDPR

When you use Looms to manage your own medical records, we act as a data controller for the account and profile information you provide to us. When a medical center, laboratory, or clinician uses Looms to issue documents to their patients, that organization is the controller for the records they create, and Looms acts as a data processor on their behalf.

2. Lawful Bases for Processing

We only process personal data where we have a lawful basis to do so, including:

  • Consent — for example, when you provide health profile details or request AI-generated insights.
  • Contract — to provide the account and services you have signed up for.
  • Legal obligation — where we must retain or disclose data to comply with the law.
  • Legitimate interests — to secure the platform and prevent fraud, balanced against your rights.

Health data is treated as a special category of personal data and is processed only where an additional condition under Article 9 applies, such as your explicit consent or the provision of health care.

3. Your Rights

If the GDPR applies to you, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Data portability — receive a copy of your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting processing carried out before withdrawal.

You can exercise most of these rights directly from your account settings, or by contacting us. We respond to verified requests within one month, as required by the GDPR.

4. International Data Transfers

Where personal data is transferred outside the EEA or the UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, and we take additional measures to ensure your data continues to receive an equivalent level of protection.

5. Data Retention

We keep personal data only for as long as necessary to provide the Service and to meet legal requirements. When data is no longer needed, it is deleted or anonymized. You may request deletion of your account and associated data at any time.

6. Security Measures

We apply technical and organizational measures appropriate to the sensitivity of health data, including role-based access controls, encryption in transit, and restricted access to records based on your relationships with medical centers. See our Privacy Policy for more detail.

7. Data Breaches

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and we will inform affected individuals without undue delay.

8. Lodging a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority. We would, however, appreciate the chance to address your concerns first — please reach out to us before doing so.

9. Contact

For any GDPR or data protection request, contact our data protection team through our Contact page or at privacy@looms.app.