1. Who we are
This Privacy Policy explains how 021 OÜ, trading as LLOOP ("LLOOP", "we", "us", "our"), collects, uses, shares and protects personal data.
| Legal entity | 021 OÜ |
| Registration number | 11728851 |
| Registered address | Kaupmehe 7-A10, 10114 Tallinn, Estonia |
| Website | https://www.lloop.com |
| Privacy contact | privacy@lloop.com |
| Data Protection Officer | Not appointed. We have assessed our processing against Art. 37 GDPR and concluded that mandatory designation does not apply. Privacy enquiries are handled at the address above. |
| EU representative | Not applicable — we are established in the European Union. |
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus), and other applicable national law.
2. What LLOOP does, and why that matters for your data
LLOOP is a business software platform. We provide local service businesses — driving schools, wellness centres, salons, hospitality venues and similar merchants (each a "Merchant") — with the tools to sell and manage their services online: a website and booking engine, order and reservation management, payment and point-of-sale functionality, gift cards and prepaid services, and the transactional messaging that accompanies those transactions.
We are the infrastructure behind the Merchant's brand. A customer booking a driving lesson or a spa treatment is interacting with the Merchant's website and receiving the Merchant's emails. LLOOP operates the system underneath, and in normal operation the customer will never see our name.
This has a direct legal consequence, and it is the most important thing to understand in this document:
We act in different roles depending on whose data is involved.
| Role | Whose data | Who decides how it is used |
|---|---|---|
| Controller | Our Merchants and their staff — the businesses that buy our platform, the people who administer their accounts, visitors to our own website | LLOOP |
| Processor | The Merchant's own customers — the student booking a driving lesson, the guest booking a treatment, the buyer of a gift card | The Merchant, who is the controller. We process only on their documented instructions. |
Section 5 covers the data we control. Section 6 covers the data we process on a Merchant's behalf.
If you are an end customer of a business that uses LLOOP and you want to exercise your data protection rights, contact that business directly — they are the controller of your data. If you contact us instead, we will forward your request to the relevant Merchant without undue delay and assist them in responding.
3. Privacy and compliance by design
Most of our Merchants are small or medium businesses without a legal department or a data protection officer. We therefore do not rely on each Merchant configuring privacy and messaging correctly. The platform is designed so that compliant behaviour is the default:
- Transactional messaging only. Our messaging serves messages triggered by an individual customer's own transaction. The platform does not offer bulk, campaign or newsletter sending, and does not accept external contact lists.
- Collection at source only. Customer contact details enter the system when the customer provides them while making a booking or purchase. There is no import, purchase or acquisition path.
- Consent where consent is required. Where a feature requires consent under GDPR or the ePrivacy Directive, the platform captures and records it, and the feature does not operate without it.
- Retention and suppression by default. Retention periods, and the suppression of bounced addresses and of anyone who has objected, are applied at platform level.
These are design commitments, reflected in binding obligations on Merchants in our Terms of Service.
4. Data we never collect
To be explicit, because it is a frequent question:
- We do not buy, rent, scrape, harvest, append or otherwise acquire contact lists from third parties.
- We do not sell, rent or trade personal data to anyone, for any purpose.
- We do not use Merchant end-customer data to build cross-Merchant advertising profiles.
- We do not send unsolicited commercial email to end customers, and our Terms of Service prohibit Merchants from using our infrastructure to do so.
- We do not process special category data (health, biometrics, political opinions and similar) as a matter of design. Where a Merchant's own service inherently involves such data, that requires prior written agreement and is governed by our Data Processing Agreement.
PART A — WHERE LLOOP IS THE CONTROLLER
5. Merchant, staff and website-visitor data
5.1 Categories of data and why we hold them
| Category | Examples | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account and identity data | Name, business name, business email, phone, job role, login credentials | Create and operate the Merchant account; authenticate users | Performance of a contract — Art. 6(1)(b) |
| Business and billing data | Company registration number, VAT number, registered address, bank details, subscription tier, invoices | Bill for the service; meet accounting and tax obligations | Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) |
| Product usage data | Features used, session timestamps, device and browser type, IP address | Operate, secure, support and improve the platform | Legitimate interests — Art. 6(1)(f) |
| Support and communications | Support tickets, emails, chat transcripts, call notes | Provide support; maintain a record of what was agreed | Contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) |
| Security and audit logs | Login attempts, IP addresses, administrative actions, API access records | Detect and investigate fraud, abuse and unauthorised access; meet audit and record-keeping duties | Legitimate interests — Art. 6(1)(f); Legal obligation — Art. 6(1)(c) |
| Marketing contact data | Business email, marketing preferences, prospect records | Send product news and commercial communications to businesses and prospects | Consent — Art. 6(1)(a), or Legitimate interests — Art. 6(1)(f) for existing customers, subject to an opt-out in every message |
| Website and cookie data | Cookie identifiers, referral source, pages viewed on our public website | Measure and improve our own site | Consent — Art. 6(1)(a) for non-essential cookies; Legitimate interests for strictly necessary cookies |
5.2 Our legitimate interests, balanced
Where we rely on legitimate interests, we have assessed our interest against the rights of the individual. In short: operating a secure, functioning, billable platform requires knowing who is using it and how. We limit that processing to what is needed, we do not use it to make decisions with legal effects about individuals, and we honour objections under Art. 21. You may request a summary of the relevant balancing test at the contact address in Section 1.
5.3 Retention
| Data | Retention period |
|---|---|
| Account data | For the life of the account, then 12 months after termination |
| Invoices and accounting records | 7 years, per the Estonian Accounting Act (Raamatupidamise seadus), or longer where applicable tax law requires it |
| Product usage data | Up to 24 months, pseudonymised earlier where feasible |
| Security and audit logs | 12 months, or longer where required for an active investigation |
| Support communications | 3 years from last contact |
| Marketing data | Until consent is withdrawn or 3 years of inactivity, whichever comes first |
PART B — WHERE LLOOP IS THE PROCESSOR
6. End-customer data processed on behalf of Merchants
When an individual buys a service, books an appointment, purchases a gift card or makes a reservation through a Merchant using LLOOP, that individual's data is processed by us solely on that Merchant's instructions, under a Data Processing Agreement concluded pursuant to GDPR Art. 28.
6.1 What we typically process
- Identity and contact data provided by the customer at the point of purchase or booking: name, email address, phone number, and where the Merchant's service requires it, postal address
- Transaction data: what was purchased or booked, when, at what price, for which date and location, and the payment status
- Booking and reservation data: appointment times, assigned staff or resources, modifications, cancellations, no-shows
- Gift card and prepaid data where applicable: balances, top-ups, redemptions and expiry
- Communication records: the transactional messages sent to that customer and their delivery status
We process this data only to deliver the platform functions the Merchant has enabled, and to send the transactional messages described in Section 7.
6.2 Our obligations as processor
Under our Data Processing Agreement we commit to:
- Process personal data only on the Merchant's documented instructions
- Ensure that personnel with access are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Engage sub-processors only under the conditions in Section 9, and remain fully liable for their performance
- Assist the Merchant in responding to data subject requests and in meeting their obligations under GDPR Arts. 32–36
- Notify the Merchant without undue delay on becoming aware of a personal data breach
- Delete or return all personal data at the end of the service, subject to Section 6.3
- Make available the information necessary to demonstrate compliance and allow for audits
6.3 Retention, and an honest word about deletion
End-customer data is retained for as long as the Merchant's account is active and the Merchant instructs us to retain it. On termination, we delete or return end-customer data within 90 days.
There is an important exception, which we would rather state plainly than bury. Accounting and fiscal law in the markets we serve requires records of completed transactions to be retained for a defined period — in some countries up to ten years — and to be preserved in a form that cannot be altered after the fact. Where a record is subject to such an obligation, neither we nor the Merchant can delete it on request.
What we do instead, on a valid erasure request:
- Personal identifiers are erased or irreversibly pseudonymised, so the retained record no longer identifies you
- The financial facts of the transaction — amount, date, tax treatment — are preserved as the law requires
- Marketing preferences, profile data and communication history are deleted in full
This reflects Art. 17(3)(b) GDPR: the right to erasure does not apply where processing is necessary for compliance with a legal obligation.
6.4 Optional features and joint controllership
Certain optional features, which a Merchant must deliberately enable and which are switched off by default, may involve LLOOP determining a purpose of processing rather than acting purely on instructions. Where that is the case, we and the participating Merchant act as joint controllers under Art. 26 GDPR, and the essence of that arrangement is set out in an addendum to our Data Processing Agreement, made available to data subjects on request.
Any such feature that would involve your data being shared beyond the Merchant you transacted with requires your explicit prior consent. Absent that consent, your data remains with that Merchant.
7. Transactional email and messaging
Because this is central to how the platform works, we describe it separately.
LLOOP sends transactional messages only. A transactional message is one triggered by a specific action a customer has just taken, sent to that individual customer, containing information they need about that specific transaction. In practice:
- Purchase and payment confirmations, and receipts
- Booking, appointment and reservation confirmations
- Modification, rescheduling and cancellation notices
- Reminders for an upcoming confirmed appointment
- Gift card and prepaid balance delivery and updates
- Account and security notices, such as password resets
Recipients are individuals who supplied their own email address directly in the course of completing that transaction, in order to receive that confirmation. There is no list, no subscription and no import. No one receives a message from us without having personally initiated the transaction that triggered it, and recipients are not added to any marketing audience as a consequence.
Our Terms of Service prohibit Merchants from using the platform's transactional infrastructure to send marketing, promotional or bulk messaging, and prohibit the use of purchased, rented or scraped contact lists. As described in Section 3, this is a matter of how the platform is built and not of policy alone. We may suspend accounts that attempt to breach it.
Delivery infrastructure. Transactional email is delivered through Sinch Mailgun, configured to the EU region, so message content and delivery metadata are stored on EU infrastructure. We retain delivery metadata — recipient address, timestamp, and delivery, bounce or complaint status — for troubleshooting and deliverability management. Message content retention is minimised.
8. Payments, gift cards and prepaid balances
Payments are processed by licensed payment institutions, currently Stripe. Full payment card numbers never reach LLOOP systems — they are captured directly by the payment provider. We receive only a token, the last four digits, the card brand, and the transaction outcome. The payment provider acts as an independent controller for its own regulatory purposes, including fraud prevention and anti-money-laundering, under its own privacy policy.
Gift cards and prepaid balances issued through LLOOP are redeemable only against the issuing Merchant's services, or those of a group that Merchant has expressly joined. They are not electronic money, are not transferable between individuals, cannot be exchanged for cash, and are not covered by any deposit guarantee scheme. Because of these limitations, no identity verification is required, and we do not collect identity documents from purchasers or holders.
9. Sub-processors and third-party recipients
We use a limited set of vendors to operate the platform. Each is bound by a written contract imposing GDPR-compliant obligations.
| Sub-processor | Function | Location of processing |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, storage and content delivery | EU |
| Sinch Mailgun | Transactional email delivery | EU region |
| Stripe Payments Europe Ltd | Payment processing and Merchant settlement | EU / US (SCCs + DPF) |
This list is current as of the date at the top of this policy. An up-to-date list is maintained at https://www.lloop.com/subprocessors. Merchants may subscribe to notifications of changes and may object to a new sub-processor as set out in the Data Processing Agreement.
We may also disclose personal data to professional advisers, to a purchaser in connection with a merger or acquisition (subject to equivalent protections), and to public authorities where required by law and after verifying the legality of the request.
10. International transfers
Our primary processing takes place within the European Economic Area. Where a sub-processor processes data outside the EEA, we rely on one or more of:
- An adequacy decision of the European Commission
- Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented where our transfer impact assessment identifies a need
- The EU–US Data Privacy Framework, where the recipient is certified
A copy of the relevant safeguards can be requested at the contact address in Section 1.
11. Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, strict isolation of each Merchant's data from every other Merchant's, role-based and least-privilege access control, audit logging of administrative actions, separation of production and development environments with no production personal data used in development, regular tested backups, ongoing vulnerability management, and a documented incident response procedure.
Where a personal data breach occurs, we notify affected controllers without undue delay, and supervisory authorities within 72 hours where Art. 33 applies.
No system is perfectly secure and we do not claim otherwise. We do commit to being prompt and honest if something goes wrong. Security researchers may contact us at security@lloop.com.
12. Your rights
Where we are the controller, you have the right to:
| Right | What it means |
|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your data, and a copy of it |
| Rectification (Art. 16) | Have inaccurate data corrected |
| Erasure (Art. 17) | Have your data deleted, subject to Section 6.3 |
| Restriction (Art. 18) | Have processing limited in certain circumstances |
| Portability (Art. 20) | Receive data you provided in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interests, and to direct marketing at any time |
| Withdraw consent (Art. 7(3)) | Withdraw consent at any time, without affecting prior lawful processing |
| Complain (Art. 77) | Lodge a complaint with a supervisory authority |
To exercise a right, write to privacy@lloop.com. We respond within one month, extendable by two further months for complex requests, and will tell you if we need the extension. We may ask for information to verify your identity.
Supervisory authority. You may complain to the authority in your country of residence or workplace. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — info@aki.ee — www.aki.ee.
Where we act as processor, direct your request to the Merchant that collected your data. We will assist them in responding.
13. Cookies
Our own website and the Merchant storefronts we host use cookies. Strictly necessary cookies — session management, authentication, load balancing and security — are set without consent, as permitted by Art. 5(3) of the ePrivacy Directive. Analytics and any other non-essential cookies are set only after consent, collected through our consent banner and withdrawable at any time.
Full detail is in our Cookie Policy at https://www.lloop.com/cookies.
14. Children
The platform is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. Where a Merchant's service involves minors — a driving school enrolling a 17-year-old learner, for example — the Merchant is the controller and is responsible for the lawful basis, including any parental consent required under national law. If you believe a child's data has reached us without a proper basis, contact us and we will act on it.
15. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects about individuals based solely on automated processing.
Where a Merchant enables them, some features analyse a customer's own history with that Merchant in order to present relevant options more conveniently. This affects convenience only: it does not determine what an individual is charged, and it does not restrict access to any service. Where such analysis stays within a single Merchant, the legal basis is that Merchant's legitimate interest and you may object under Art. 21. Anything extending beyond a single Merchant requires your explicit consent — see Section 6.4.
16. Changes to this policy
We may update this policy. Material changes are notified to Merchants by email at least 30 days before taking effect, and the version and date at the top are updated. Continued use after the effective date constitutes acceptance where the change concerns processing for which we are the controller; where consent is required, we will ask for it separately.
17. Contact
| Privacy enquiries | privacy@lloop.com |
| Security disclosures | security@lloop.com |
| General and legal | legal@lloop.com |
| Postal | 021 OÜ, Kaupmehe 7-A10, 10114 Tallinn, Estonia |