Version 2.3 - 08.09.2026
This Privacy Policy covers the Loopelo app, website, newsletter and provider tools. It describes processing by NexTechnologies OÜ under the GDPR and applicable supplementary rules. Independent organisers, providers and external services also supply their own information about their processing.
German is the authoritative version. English, French and Dutch translations assist understanding. A user may simultaneously be a consumer, provider and community administrator; the relevant processing, not merely the account role, determines the applicable information.
The controller is NexTechnologies OÜ, Tartu mnt 67/1-13b, Kesklinna linnaosa, Tallinn, 10115 Harju maakond, Estonia, Äriregister 17533344, represented by Dr. M. Amin Yazdi. Privacy contact: [email protected]; telephone: +49 176 34691656.
For an account, we process email address, internal account identifier, username, language, login and verification information, account status and Terms acceptance. For email login we store a salted password hash, not the plaintext password. For Apple or Google login, our authentication service provider supplies the relevant identifier and, where applicable, email address, not your password for the external service.
The checkbox confirms a minimum age of 18, acceptance of the Terms and acknowledgement of this Privacy Policy. We record the confirmed document versions, time, source, language and any app version, plus the declared minimum age for the new declaration. Earlier evidence is not retrospectively treated as an 18+ declaration. This is not verified age assurance or consent to all processing.
Without necessary account and authentication details we cannot provide a personal account. Optional profile details are separate; without them, recommendations are less individual.
Child profiles are optional. They may contain a nickname, birth year and optional gender. The birth year yields an approximate age range; interests and household information support family recommendations. Nicknames remain personal data when associated with an account and family context.
The child profile is not displayed as a public individual profile. When using Lena, these details may form part of the AI context. Broad age groups may contribute to aggregate provider statistics. Booking information is separate: child ages and notes you enter there may be shown to the selected provider to handle the booking.
Location permission may be withdrawn at any time in your device's system settings. The Service will fall back to your manually entered zip code.
If you choose to verify a phone number, we process and store the number for the purpose of verification and identity assurance. Verification messages are delivered via an external SMS delivery provider. Phone verification is optional. If you remove your phone number, the stored value and any verification metadata are deleted.
We store listings, descriptions, photos, credits and estimated environmental values, messages and attachments, delivery/read status, reviews, and events you create or join. Optional flyer extraction supports event creation.
Community messages are visible to community members, including later members. Leaving a community does not erase earlier messages. Community administrators can remove messages. Join/leave notices identify the account; push notifications may show the sender and a short excerpt. Personal read positions are not shown to other members. Lena does not receive the community conversation as conversation history. Reports about chat content are handled as described in section 5.4.
Chat text and images are encrypted during transport and at application level in storage. Human moderation access is limited to a specific report and the content and context necessary to handle it; it does not permit browsing unrelated conversations. We use authentication, access controls and recovery measures appropriate to processing risks. See section 11.
We store credit balances and transactions, subscription plans, entitlement periods, store transaction references and the pseudonymous account identifier held by our subscription-management provider to fulfil and reconcile purchases. Loopelo does not receive payment-card details from in-app purchases. Apple/Google handle the store payment flow; the contracting and payment roles follow the purchase confirmation and applicable store terms. Turning off a mandatory subscription paywall does not turn off voluntary purchases.
Safety records include image-check results, user and system reports, affected account/content references, report notes, decisions, reasons and administrative unlock records. For chats, moderation is initiated by user reports, not automatic image screening. A report does not give reviewers general access to a conversation; access is limited to the content and context necessary for that specific report. Block lists support your contact preferences. We may retain necessary evidence of credible abuse or infringement, its assessment and action taken. Reporting someone or working for another business is not proof of misconduct.
If you use the Service professionally, you must self-declare that status through the account function provided for this purpose or, if it is temporarily inaccessible to you, by email to [email protected]. We process the declaration, its date and source, and the business and contact details you provide. Where applicable law requires trader traceability, this can also include a business address, VAT identification number, commercial-register or equivalent registration number, and a self-certification or supporting evidence. No discretionary prior approval by Loopelo is required. We may carry out checks required by law, request the information or evidence the law requires, and display the fields legally required to identify you as a trader. The legal bases are Article 6(1)(b) GDPR (performance of the Service contract) and, where applicable, Article 6(1)(c) GDPR (compliance with legal obligations, including Article 30 DSA where it applies).
For listing-claim requests, we collect name, contact details, listing, explanation, necessary authority evidence and technical security data to check management access and prevent abuse.
Provider statistics record opens, shares, saves, contact referrals, navigation starts and QR interactions with time, content, source and, where available, account association. Known internal provider traffic is excluded. An interaction proves neither an actual visit nor a booking.
Family age groups are derived from optional child profiles and eligible interactions. Privacy acknowledgement is taken into account but does not replace consent where required. Results require at least ten contributing families; if any nonempty age group is smaller, the age distribution and family total are withheld. Statistics contain no individual profiles. You may object to processing based on legitimate interests at [email protected].
For referrals through provider links, we may link a time-limited attribution record to a later account and qualifying activities to attribute a referral or reward and prevent abuse. Hashed identifiers are not automatically anonymous. Providers receive the referral or reward status needed for handling, not your private chats. Attribution records are generally retained for 30 days; associated abuse and reward evidence is retained for 730 days.
If you request our personalized weekend newsletter during email or social registration, in Settings, or on the website, selecting the option records only a request. We send a confirmation email and do not send marketing newsletters until you use its confirmation link (double opt-in). We store your email address, language, request source, consent-copy version, request and confirmation timestamps, double-opt-in status and delivery counters, unsubscribe or suppression timestamps, bounce/complaint state and the last-send timestamp. A website-only subscription is not linked to an account unless an account is later created with the same email address.
For each newsletter edition we keep a minimal delivery ledger containing the edition, broad region key, locale and template version, selected teaser-card snapshot, delivery status and attempts, provider message identifier and redacted delivery/bounce/complaint events. The newsletter is personalized inside Loopelo using your approximate area, family age ranges and interests, and relevant interaction or saved-content signals. Our email delivery provider receives only the email address and the finished email, including the selected Adventures, events, items and articles; it does not receive your child profiles, interests, interaction history or the underlying personalization profile.
Every newsletter contains a one-click unsubscribe link. Account holders can also withdraw their newsletter consent in Settings. Unsubscribe takes effect for future newsletters without requiring you to sign in; a later subscription requires a new double-opt-in confirmation. Deleting an account removes its account-linked newsletter record. Website-only subscribers may use the unsubscribe link or ask us to erase their record.
Authorised Provider Toolbox users may optionally connect a Meta account to discover and select Facebook Pages and professional Instagram accounts that they are permitted to manage. We store the connected person's Meta app-scoped user identifier and display name; granted permissions and token-health timestamps; encrypted user and destination access tokens; and the identifiers, names, usernames, management tasks and selection state of discovered destinations. Tokens are held only on our server and are never returned to the browser or shown to another provider.
Loopelo does not publish automatically when an event or Adventure is saved. A provider must select an eligible event, approved visual and destinations, review the exact image, caption and Loopelo link, and explicitly confirm each publication. For this workflow we record the acting Loopelo account, selected content and destinations, image hashes and dimensions, timestamps, publication status, attempts, Meta container/post identifiers, permalinks and sanitized error codes. The temporary JPEG made available for Meta delivery is protected by an unguessable time-limited address and expires after 48 hours. Completed publication history is retained for 365 days unless deleted earlier as described below.
When an authorised provider explicitly loads Meta performance, Loopelo retrieves aggregate reactions or likes, comments, shares and available reach only for posts that Loopelo published. We do not retrieve audience demographics. The aggregate response is held in a transient server cache for up to 15 minutes and is not added to a permanent analytics database.
Disconnecting Meta, Meta deauthorization, deletion of the relevant Loopelo account or Adventure, or a valid Meta data-deletion callback removes the local connection, encrypted credentials, destinations and associated publication history. A verified Meta deletion request leaves only one-way/keyed hashes, status, timestamps and a removal count for 90 days so that its confirmation code can be checked. Loopelo does not use that callback to delete the Loopelo account or Adventure. Posts already published on Facebook or Instagram are controlled on those services and are not deleted by disconnecting or deleting the local connection; they must be managed directly on the relevant Meta destination.
For a booking we process account, selected provider, resource or event, time, participant counts, booking name, any child ages, phone sharing, notes, status and changes. The selected provider and its authorised people see information intended for fulfilment and may enter administration notes. This visibility is separate from aggregate statistics.
The toolbox processes organisation and role association, authority evidence, uploaded images and documents, extraction and design results, publishing instructions, delivery information and usage and cost metadata for requested tools. For provider document imports, AI processing is performed exclusively in Germany (Frankfurt); image generation may use external AI service providers. Do not upload unnecessary data about children, customers or workers. Raw document-extraction files generally have a scheduled 30-day period; saved results and published content remain until removal or the relevant account-deletion procedure.
Business and contact details in public provider and event directories may come from providers, organiser websites, public directories and mapping services. This can include personal data of sole traders and contacts. The purpose is information about local offers, based on our legitimate interest under GDPR Article 6(1)(f). Request correction or object at [email protected].
We process account, login, listing and communication services, requested bookings, credit administration and purchased services to perform your agreement or take pre-contractual steps at your request (GDPR Article 6(1)(b)). For contacts acting for an organisation, necessary contact and authority information relies on our interest in performing the agreement and secure administration (Article 6(1)(f)).
Optional child information for age-appropriate family recommendations, interaction-based recommendations, aggregate provider statistics, quality assurance, security logs and abuse prevention rely on Article 6(1)(f) where separate consent is not required. Our interests are a useful local family service, meaningful limited statistics and protection of users and systems; children’s interests and rights require particular consideration. You may object under Article 21.
Lena, the requested personalised newsletter and consent-requiring analytics rely on Article 6(1)(a). Consent can be withdrawn prospectively at any time. Necessary device storage for an expressly requested feature falls under TDDDG section 25(2); other consent-requiring access falls under section 25(1). An operating-system permission, privacy notice or general Terms acceptance does not automatically replace every required consent.
We process necessary data under Article 6(1)(c) to fulfil legal duties, particularly rights requests, applicable accounting and tax duties and DSA Articles 16 to 18. Article 6(1)(f) may apply to asserting or defending claims. Private communications also require compliance with special statutory conditions, particularly communications secrecy; Article 6 alone does not authorise general inspection.
We do not specifically request health data, religious beliefs or other GDPR Article 9 categories for family profiles. Free text can nevertheless contain them. Voluntary entry or Terms acceptance alone does not prove explicit Article 9 consent. Such cases require an applicable Article 9(2) exception and, where appropriate, erasure or restriction.
Lena is an optional AI assistant. It is enabled only after separate confirmation in the app. Consent under GDPR Article 6(1)(a) is recorded with its version and time and can be withdrawn in Lena settings. The rest of the app remains usable without Lena.
For replies, the AI service provider receives your current message, relevant conversation history and context from optional family information: nicknames, approximate child ages, any gender, interests, household tags, city and country, preferred age ranges and any community name and type. Membership does not prove a child attends a particular school. Lena may perform supported profile actions at your request and use summaries, recurring themes and notable facts from earlier conversations in later replies.
Free text may include sensitive details if you enter them. Such details may enter conversation history and memory. Do not enter diagnoses, religious beliefs, confidential third-party information or unnecessary identifying details. For accidental entries, request erasure or correction at [email protected]. This warning alone is not a technical filtering guarantee.
For Lena, your inputs and the generated responses are not used by the AI provider to improve its products under the applicable service terms. Security and abuse processing under those terms remains possible. Information about recipients and international processing is provided in sections 6 and 7. Lena’s answers may be wrong; it does not replace professional advice or emergency services.
When you upload photos for an item listing, we send the images to an external AI service to suggest a category, an approximate weight, a material classification, and an environmental-impact (carbon-footprint) estimate. Suggestions are advisory; you can edit them before publishing.
When you create an event, you may optionally upload a photo of a printed flyer or poster. Before extraction, an external image-checking service screens the image for adult, suggestive, or otherwise inappropriate content. A rejected image is not forwarded for AI extraction. If the image passes this check, we send it to an external AI service, which extracts event details (such as name, description, date, time, location and suitable ages) and returns the result for you to review and edit before saving. The extraction is advisory; nothing is published without your confirmation. If, after creating the event, you choose to attach the flyer image as the event's display picture, it is then treated as ordinary User Content under our Terms of Service. If you do not attach it, the image is discarded after extraction.
Third-party data on flyers. A flyer may incidentally contain personal data of third parties (for example, an organiser's name, telephone number or email address that has been printed publicly on the flyer). To the extent we process such data through the extraction step, we rely on Article 6(1)(f) GDPR (our legitimate interest in providing the event-creation feature, balanced against the manifestly public nature of the data on the flyer). You are responsible for ensuring that you have the right to use the flyer image and that uploading it does not infringe third-party copyright, trade-mark, personality or other rights (see Section 8 of the Terms of Service).
For applicable uploads outside chats, such as the flyer extraction described in section 5.3, we use an external image-checking service to identify certain image categories, such as nudity or violence. The image-checking service receives the image submitted for that check. This classification does not reliably identify every legal breach and is not a specialised system for identifying child sexual abuse material.
We do not automatically screen images in chats, including 1:1 and community group chats. Chat moderation relies on user reports. Authorised reviewers may inspect only the reported content and context necessary to handle the specific report, where lawful and proportionate. Their access is restricted to that case, not unrelated conversations.
A report alone does not establish a breach or criminal offence. Where lawful and necessary, suspected content may be secured with restricted access and protective measures taken under Terms section 10. We fulfil applicable statutory reporting duties; not every report is a child-safety case or requires referral to authorities. We do not promise to detect every violation or manually check all communications.
Recommendations use approximate location, selected interests and household tags, child age ranges, past interactions and the freshness and distance of content. You can influence them through your profile and interactions. Sponsored Adventures are labelled and may be selected by distance, interests, family age suitability and promotion level. Selection does not disclose individual family profiles to sponsors. Separately, providers receive information you supply for bookings and sufficiently grouped statistics described in sections 3.11 and 3.14.
Carbon-footprint values shown for items are AI-generated estimates and have not been independently verified. They are provided for orientation only and should not be relied upon for any commercial or regulatory purpose.
Recommendations and image classification are automated. The image check can prevent publication; it does not establish a criminal offence. You may ask for review using the contact in section 14. Account suspension is an administrative decision, not an automatic consequence of a model label. GDPR Article 22 rights apply where its statutory conditions are met.
The optional translation and language-detection feature uses a translation component on your device. The text you translate and the resulting translation are processed locally and are not sent to an external service for translation. Before first use for a language pair, the app downloads the required language model from the translation service provider; a model is approximately 30 MB. Because you start the download explicitly, it may use Wi-Fi or mobile data and may continue in the background. Downloaded models remain on the device until you remove them in the app's translation settings or remove the app data/application; the built-in English model cannot be removed through this control.
The translation component may contact its service provider to obtain models, bug fixes, model updates and hardware-accelerator compatibility information. It also sends non-linked SDK performance and utilization metrics used for app functionality, analytics, debugging, maintenance, improvement and abuse detection. According to the privacy manifests supplied with the installed iOS SDK, these may include a non-linked device identifier, product-interaction, performance, diagnostic and other SDK data. The text and translation output are not included in those metrics.
Where personal data is involved, recipients depend on the features you use. The following service providers receive the data needed for their tasks, as described in sections 3 and 5:
Selected identity providers, app stores and connected social networks receive the account, transaction or publication data needed for the function you request. These services operate in the EEA and US and also process data under their own privacy notices. Processors act on our instructions; independent recipients determine their own processing purposes.
Other users, community members and booking providers receive the information you share with them or supply for bookings. Authorities, courts and professional advisers may receive necessary data where legally justified. We do not sell personal data.
Provider location does not determine where every processing operation occurs; section 7 explains international processing. You can request the identities of recipients of your personal data at [email protected].
The application, database and user-generated media are hosted in Germany. This does not mean all processing occurs in Germany. Services listed in section 6 may process data in countries including the United States and United Kingdom. Authorised administrative access within the controller company may temporarily also occur from outside the European Economic Area (EEA).
Transfers to a separate recipient outside the EEA must meet GDPR Articles 44 et seq. An Article 45 adequacy decision may apply; for US recipients this particularly requires EU-US Data Privacy Framework participation that covers the specific recipient and data. Where no applicable adequacy decision exists, appropriate Article 46 safeguards, especially EU Standard Contractual Clauses and necessary supplementary measures, are relevant. A US address or EU server region alone does not replace that assessment.
For information on the transfer mechanism used for a recipient and a copy of accessible safeguards, contact [email protected]. Access within the same controller company differs from transfers to another legal entity; security and other data-protection duties also apply to such access.
We generally retain account and optional profile data during account use. Child profiles can be removed separately. An inactivity reminder is scheduled at 22 months and erasure or scrubbing at 24 months. Verification codes have limited validity; expiry is not the same as immediate physical deletion of every record.
Account deletion removes or scrubs child profiles, personal links and associated content through the deletion procedure. Your message text is cleared; empty message entries may remain for consistency of other conversations. Hiding a message or leaving a community is not immediate erasure. Reviews and events may remain without account association; if free text still identifies someone, you may request a review.
For bookings, account deletion removes account association, booking name, individual child ages, parent and provider notes and phone-sharing information. Operational details such as time, status and capacity counts may remain. Data independently stored by a provider must also be addressed with that provider.
Media cleanup starts with account deletion; failed attempts are retried and, where needed, followed up manually. Seven days is an operational target, not a guarantee for every technical outage. Residual personal data may remain in restricted recovery copies for approximately 30 days before deletion. These copies serve recovery, not continued ordinary use of deleted accounts. Erasures must be reapplied following restoration.
Lena history and memory may remain until deletion or withdrawal under the Lena deletion procedure. Evidence after consent withdrawal, closed reports and administrative decryption unlocks generally have a three-year evidence period in the deletion plan. Secured evidence may remain only for a necessary investigation, legal proceedings or binding retention duty; its continued need must be reviewed regularly.
Transaction and accounting evidence is currently retained by the system for up to ten years. The applicable accounting, tax or claims-related reasons govern each case; not every credit activity is a tax record. Ordinary security logs rotate by volume. Separate abuse case files generally have a scheduled period up to three years after closure, longer only where a legal reason persists.
Newsletter delivery logs are cleaned after 90 days. Subscription, consent and suppression records remain only for active delivery or necessary evidence and respect for opt-out. Provider requests and authority evidence remain during handling and, where necessary, subsequently for traceability or abuse prevention. Rights requests and contractual correspondence are retained for handling and a specifically necessary statutory or claims-related evidence period. Necessary retention limits further use to its respective purpose.
Subject to the conditions set out in the GDPR, you have the following rights regarding your personal data:
You may request access under GDPR Article 15 and a copy of your personal data at [email protected]. The existing in-app export facilitates access to account data. It does not replace a full assessment of an access request: additional required information, such as bookings, provider tools, website contacts or external recipients, is supplied where needed. Other people’s rights and lawful protective limits must be respected.
Most profile information is editable in the app. For data you cannot edit yourself (for example, the email associated with your account), contact [email protected]. Reviews you have published cannot be self-edited after admin approval; if a published review contains inaccurate personal data, please contact us and we will rectify or delete it as appropriate.
You can delete your account from within the app, or via our web form at https://loopelo.com/delete-account.php. On account deletion, your personal data is deleted or - where this is required to preserve the integrity of shared content (for example, reviews or your messages on another user's thread) or for statutory retention reasons - anonymized, as set out in Section 8.
Provider Toolbox users can remove Meta data without deleting their Loopelo account by using Disconnect Meta. Meta may also send Loopelo a signed deauthorization or data-deletion request; a successful data-deletion request returns a confirmation code and status address. These actions remove Loopelo's local Meta credentials and history but do not remove posts already published on Facebook or Instagram.
You may request restriction of processing in the cases listed in Article 18 GDPR by emailing [email protected].
The in-app export described in Section 9.1 is provided in a structured, commonly used, machine-readable JSON format suitable for transmission to another controller of your choice.
You may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. Contact [email protected].
Direct marketing. Where we process personal data to send you promotional communications, you have an absolute right to object under Article 21(2) GDPR. You can exercise this right at any time, with no need to email us, by switching off the relevant toggles in your in-app notification settings. The opt-out is as easy as opt-in.
Where processing is based on your consent (see the table in Section 4), you can withdraw it at any time, with no effect on the lawfulness of processing prior to withdrawal. Withdrawal mechanisms include the OS-level location permission (for GPS-derived zip lookup), the in-app notification toggles (for promotional communications), and dedicated in-app controls for AI features such as Lena.
You may lodge a complaint with the data protection supervisory authority of your habitual residence, workplace, or the location of the alleged infringement. The principal authorities are listed in Section 14.
We generally respond to rights requests within one month of receipt. Where there are reasonable doubts, we may request necessary additional identity-confirmation information. For complexity or number of requests, GDPR Article 12(3) permits an extension of up to two months; we explain the extension and reasons within the first month.
Loopelo accounts are reserved for adults aged 18 or older. Children may nevertheless be data subjects when adults provide optional family details, images, booking data or free text about them. The account holder’s minimum age does not remove children’s data-protection rights.
Prefer nicknames and limit information to the relevant purpose. We do not ask for a separate school-affiliation field, but community membership may permit inferences. A community can equally be a private group unrelated to an institution.
Individual child profiles are not public. Family context for Lena, booking information sent to the selected provider and aggregate age statistics are distinct processing activities described in sections 3 and 5. Sponsored recommendations to adults may consider family age suitability. It would therefore be inaccurate to claim that no child data are processed or used.
Parents authorised to represent a child may exercise the child’s rights at [email protected]. The child’s own rights remain; we take account of age, understanding and authority to represent.
Chat text and images are encrypted during transport and at application level in storage. This is not end-to-end encryption: the service can decrypt content for delivery. Human moderation access is limited to a specific report and the content and context necessary to handle it. We use authentication, access controls and recovery measures appropriate to processing risks.
We assess personal-data breaches under GDPR Articles 33 and 34. Where notification is required, we notify the competent authority without undue delay and, where feasible, within 72 hours of awareness. Affected people are informed without undue delay where a breach is likely to create a high risk, subject to statutory exceptions.
The app stores login tokens in protected device storage. Settings and cached account data are also kept locally; not every local cache has the same protection as token storage. You can remove local app data through device controls; this does not automatically delete your server account.
At app launch, our app-delivery service provider processes a pseudonymous installation identifier, project identifier, app version, platform and operating-system version for launch and version statistics. Model and update requests and technical SDK metrics may create additional network connections as described in section 6. These processes are distinct from Lena consent and the website cookie choice. Nonessential device access is subject to TDDDG section 25 consent requirements; including an SDK does not itself make its access necessary.
The website stores language preferences and necessary provider-session cookies. Google Analytics 4 and optional first-party provider engagement measurement start only after analytics consent. GA cookies identify a browser; their duration depends on Google’s cookie configuration, generally up to two years and renewed on use. This is distinct from the Analytics property’s event-retention setting.
Before consent or after refusal, the consent loader does not connect to Google Analytics or Google Tag Manager. Use Cookie Settings in the footer to withdraw consent. This stops new Analytics events and removes cookies under our control where technically possible; it does not erase information already received by Google. The legal bases are TDDDG section 25(1) and GDPR Article 6(1)(a); necessary session/storage access falls under TDDDG section 25(2)(2).
We update this information when processing changes or clarification is needed. We give timely information about material new processing. Acknowledging an updated notice is not a new legal basis; required consents are handled separately. Changes to the service agreement follow the Terms. Earlier versions are available on request.
Privacy questions and rights requests: [email protected]. General contact: [email protected]. Under GDPR Article 77 you may complain to a supervisory authority, particularly where you habitually live, work or where the suspected infringement occurred.
Users in North Rhine-Westphalia may contact the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (ldi.nrw.de); in Estonia, Andmekaitse Inspektsioon (aki.ee). Competence and lead-authority status depend on statutory rules, not solely the registered address.