Privacy Policy
Data protection matters greatly to us. In accordance with Art. 13 GDPR, this policy informs you about the nature, scope and purpose of the processing of personal data on loomup.io.
This page is a carefully prepared template based on applicable German law (§5 DDG, §18 MStV, GDPR, TTDSG, BDSG). Before going live, we recommend a legal review, as legal changes can take effect quickly. Fields marked with [PLACEHOLDER] must be replaced with your company details.
1. Controller
The party responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Loomup [PLACEHOLDER: legal form]
[PLACEHOLDER: street and house number]
[PLACEHOLDER: postal code, city]
Germany
Email: datenschutz@loomup.io
2. Data Protection Officer
Where required by law (in particular with at least 20 employees regularly processing personal data pursuant to § 38 BDSG), the following person is appointed as data protection officer:
[PLACEHOLDER: name and contact details of the data protection officer]. If not required, please contact the address listed above directly.
3. Your rights as a data subject
You have the right at any time to:
- Access to the personal data concerning you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Objection to the processing (Art. 21 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of a given consent with effect for the future (Art. 7(3) GDPR)
- Lodging a complaint with a supervisory authority (Art. 77 GDPR). The competent body is the data protection supervisory authority of the federal state of your residence or our company's registered office
4. General information on data processing
4.1 Provision of the website & server log files
When you access our website, your browser automatically sends information to the server. This is stored temporarily in what's known as a log file. The following data is recorded:
- IP address (anonymized after 7 days)
- Date and time of access
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (the specific page)
- Access status / HTTP status code
- Amount of data transferred in each case
- Website from which the request originates (referrer)
- Browser, operating system and its interface, language and version of the browser software
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a technically error-free presentation and optimization). Storage period: 14 days, after which it is deleted automatically.
4.2 Hosting
Our website is hosted by [PLACEHOLDER: name of hosting provider, address, country if applicable], server location: Germany/EU. A data processing agreement (DPA) under Art. 28 GDPR has been concluded with the hosting provider.
4.3 SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognize an encrypted connection by the “https://” prefix and the padlock icon in your browser bar.
5. Cookies and comparable technologies
We use cookies and similar technologies (e.g. localStorage) on our website in accordance with § 25 of the German Telecommunications-Telemedia Data Protection Act (TTDSG).
5.1 Technically necessary cookies
These cookies are strictly required for the operation of the website (session management, security functions, storing cookie settings). Legal basis: § 25(2) TTDSG, Art. 6(1)(f) GDPR. Consent is not required.
5.2 Functional, statistical and marketing cookies
These cookies are only set with your explicit consent (§ 25(1) TTDSG, Art. 6(1)(a) GDPR). You can withdraw your consent at any time under Cookie Settings.
6. Contact form and email contact
If you send us enquiries via the contact form or by email, the details from your enquiry form, including the contact data you provide there, are stored with us for the purpose of processing the enquiry and in case of follow-up questions.
- Legal basis: Art. 6(1)(b) GDPR (initiation of a contract) or Art. 6(1)(f) GDPR (legitimate interest)
- Storage period: until the enquiry has been fully processed, after which it is deleted, unless statutory retention obligations apply (under commercial and tax law, generally 6 or 10 years)
- Recipients: where applicable, our processors (email provider, CRM provider)
7. Visibility check and consulting enquiries
As part of the free visibility check, we process:
- Contact details (name, email, phone if provided, company)
- Website URL and voluntary industry information
- On request: read access to Google Search Console, Google Analytics and SEO tools (Ahrefs/Semrush)
Legal basis: Art. 6(1)(b) GDPR (initiation of a contract). Data access is read-only and only for the duration of the analysis. No transfer to third parties takes place.
8. Web analytics (where used)
This website may use Google Analytics 4 (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). This requires your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG).
- IP anonymization is enabled
- Data processing partly takes place on US servers. Data transfer to the USA is based on the EU-US Data Privacy Framework (EU Commission decision of 10 July 2023)
- Standard Contractual Clauses (SCC) as an additional safeguard
- A data processing agreement (DPA) has been concluded with Google
- Retention period: 14 months
You can withdraw your consent at any time via the Cookie Settings.
9. Newsletter (where offered)
If you subscribe to our newsletter, we process your email address and any other data you provide voluntarily for the purpose of sending it. Dispatch uses the double opt-in procedure: you receive a confirmation email, and your subscription becomes effective once you confirm it.
Legal basis: Art. 6(1)(a) GDPR. You can withdraw your consent at any time via the unsubscribe link in every newsletter email.
10. Integrated services and processors
We use the following services, with which we have concluded data processing agreements (DPAs) under Art. 28 GDPR:
- [PLACEHOLDER: hosting provider] – hosting
- [PLACEHOLDER: email provider] – email communication
- [PLACEHOLDER: CRM/helpdesk tool, if used] – customer management
- Google Ireland Ltd. – where Analytics is enabled
- Microsoft Ireland Operations Limited – where Microsoft 365/Outlook is used
11. Data transfer to third countries
A transfer of personal data to third countries (in particular the USA) only takes place:
- on the basis of an adequacy decision by the EU Commission (e.g. the EU-US Data Privacy Framework)
- on the basis of EU Standard Contractual Clauses (SCC)
- or with your explicit consent
12. Security of data processing
We take appropriate technical and organizational measures (TOMs) to protect your personal data against unauthorized access, loss and manipulation. These measures are reviewed regularly and adapted to the current state of the art.
13. Changes to this privacy policy
We reserve the right to amend this privacy policy so that it always complies with current legal requirements, or to reflect changes to our services. The new privacy policy then applies to your next visit.
As of: June 2026