Privacy policy

Last updated: 2 October 2026 · Version 1.5

This translation is provided for information only. Only the German version is legally binding.

This policy explains which personal data we process when you use loomira.ai and the Loomira portal, for which purposes, on which legal basis and for how long. It applies to website visitors, prospects and business customers.

1. Controller

The controller for the processing described here is Staqmind UG (haftungsbeschränkt), Gilgaustraße 36, 51149 Köln, Germany, represented by Mirko Rossbach, Montassar Zaroui.

A data protection officer has not been appointed; the requirements of § 38 BDSG are not met. Please direct privacy requests to datenschutz@loomira.ai.

Where the Loomira assistant answers calls on behalf of our customers, the respective customer is the controller. We process that data as a processor under Art. 28 GDPR on the basis of a data processing agreement.

2. What we collect — and why

Server logs

When you visit our website we process technically necessary access data (IP address, timestamp, requested page, user agent) to keep the service running and to fend off attacks. Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in secure operation). Deleted after 30 days at the latest.

Web analytics (Plausible)

To understand how our website is used we employ Plausible Analytics, a privacy-first analytics service by Plausible Insights OÜ (Västriku tn 2, 50403 Tartu, Estonia; an EU company — data is processed and stored exclusively on servers in the EU). Plausible works without cookies and does not track visitors across websites or devices: the IP address and user agent are used only transiently to derive a daily-changing pseudonymous identifier and are not stored. We only ever see aggregated statistics (pages visited, referrers, countries, device types). Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in measuring reach); a data processing agreement under Art. 28 GDPR is in place. You may object to this processing at any time (Art. 21 GDPR).

Demo call

If you request a demo call via our website, we use your phone number solely to place that call and to prevent abuse (rate limiting via hashed values; phone numbers never appear in logs in plain text). Legal basis: Art. 6 (1)(b) GDPR. No marketing use takes place.

Booking a demo

If you book a demo on our website, we process your name, your email address and, if you provide them, your company and notes, to arrange and hold the video call. The booking is created by our scheduling provider Cal.com, Inc. (USA), which sends the calendar invitation and reminders on our behalf. Your browser does not connect to Cal.com: our server transmits the booking. Cal.com is bound as a processor under Art. 28 GDPR; the transfer to the USA is based on EU standard contractual clauses (Art. 46 GDPR). Legal basis: Art. 6 (1)(b) GDPR. Deleted after 12 months at the latest, unless a contract follows.

Contacting us

If you contact us by email, we process your details to handle the enquiry. Legal basis: Art. 6 (1)(b) GDPR for (pre-)contractual enquiries, otherwise (f). Deleted after 12 months at the latest, unless statutory retention duties apply.

Account and contract data

For your Loomira account we process registration and contract data (name, email address, company, configuration). Login runs through our self-hosted Zitadel instance in the EU. Legal basis: Art. 6 (1)(b) GDPR. Deleted 30 days after the contract ends, unless statutory retention duties apply.

Payment data

Payments are processed by Stripe. Payment data (e.g. card details) is processed exclusively by Stripe and is not stored by us. Legal basis: Art. 6 (1)(b) GDPR. We retain invoices for ten years pursuant to § 147 AO.

Transactional email

System emails (e.g. account confirmation, invoices) are sent via Scaleway (Paris region, EU). Legal basis: Art. 6 (1)(b) GDPR.

AI phone calls (on behalf of our customers)

Where the Loomira assistant answers calls for a business, we process call content on behalf of that business (Art. 28 GDPR). Call audio is not stored — it is processed transiently for real-time handling only. Transcripts are anonymised after 30 days; callers’ phone numbers are stored only as salted hashes. At the start of each call the assistant identifies itself as an AI. The respective customer, as controller, is responsible for the lawfulness of this processing; its legal basis arises from the customer’s relationship with the callers (usually Art. 6 (1)(b) GDPR).

We provide our customers with a template privacy notice for callers: View the template

3. Cookies and local storage

We use strictly necessary cookies only (§ 25 (2) no. 2 TDDDG). They are essential for operating the website and the portal and require no consent:

  • i18n_redirectedRemembers your language choice (German, English or French).
  • loomira-sessionKeeps you signed in to the portal (encrypted session, only after login).
  • loomira-auth-flowSecures the login and signup flow.
  • loomira-csrfProtects forms against cross-site request forgery.

A cookie consent banner is therefore not required: our web analytics (Plausible, section 2) works without cookies and without cross-site tracking, we use no advertising services, we self-host our fonts, and no third-party content is loaded.

The portal additionally stores interface preferences (e.g. dark mode) locally in your browser; this data never leaves your device.

4. Processors and recipients

We use carefully selected service providers that process personal data on our behalf, contractually bound under Art. 28 GDPR. Processing takes place in the EU; for providers with a US parent company, EU standard contractual clauses (Art. 46 GDPR) and supplementary assessments (transfer impact assessment) are in place.

  • Amazon Web Services EMEA SARL — Cloud hosting: compute (ECS Fargate, EC2), databases (Aurora PostgreSQL), cache, storage, encryption (AWS KMS), logging and monitoring (Region eu-central-1 (Frankfurt am Main, Germany))
  • Google Cloud EMEA Limited — AI inference via Vertex AI: language model (Gemini) for call and message replies, and embeddings for the knowledge base (Vertex AI: EU multi-region (language model) and region europe-west1, Belgium (embeddings))
  • Soniox, Inc. — Speech recognition (speech-to-text) for the AI phone assistant (EU endpoint (processing in the EU))
  • ElevenLabs, Inc. — Speech synthesis (text-to-speech) — processes only the spoken response text (Global API endpoint — processing may take place outside the EU (USA); a switch to the EU residency endpoint is planned)
  • Telnyx Ireland Limited — Telephony: phone numbers, call routing (SIP) (EU (Frankfurt); EU API endpoints)
  • Stripe Payments Europe, Ltd. — Payment processing and invoicing (Dublin, Ireland (transfers to the US possible))
  • Scaleway SAS — Transactional email (e.g. account confirmation, invoices) (Paris, France (fr-par region))

We operate authentication (Zitadel) and the voice infrastructure (LiveKit) ourselves in our own AWS environment in the eu-central-1 region (Frankfurt) — they are not separate sub-processors.

Our web analytics provider Plausible (section 2) processes website usage data only and is not part of the sub-processor chain for customer call data.

Our scheduling provider Cal.com (section 2) processes demo bookings only and is not part of the sub-processor chain for customer call data.

We maintain the complete, current list — with purpose, location and third-country basis — publicly: List of sub-processors

5. Retention periods

Unless stated otherwise above, the following periods apply:

  • Server logs30 days at the latest
  • Contact enquiries12 months
  • Account and contract data30 days after the contract ends
  • Invoices10 years (§ 147 AO)
  • Business correspondence6 years (§ 257 HGB)
  • Call audionot stored
  • Call transcriptsanonymised after 30 days

6. Your rights

You have the rights under Art. 15 to 21 GDPR:

  • Access to your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)

You may withdraw any consent you have given at any time with effect for the future.

To exercise these rights, contact datenschutz@loomira.ai.

You also have the right to lodge a complaint with a data protection supervisory authority. Competent for us: State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestr. 2–4, 40213 Düsseldorf, www.ldi.nrw.de.

7. Automated decision-making

No profiling within the meaning of Art. 4 no. 4 GDPR takes place.

Where the assistant automatically accepts or declines appointment requests on behalf of a customer, this is done to perform or initiate a contract between the caller and the customer (Art. 22 (2)(a) GDPR). The safeguards of Art. 22 (3) GDPR apply: callers can request human handling at any time and contest the decision — the customer remains reachable through the usual channels.

8. Data security

We take technical and organisational measures pursuant to Art. 32 GDPR, including:

  • Encrypted transport (TLS) for all connections
  • Hosting in EU data centres (AWS region eu-central-1, Frankfurt am Main); deviations by individual sub-processors are listed in the sub-processor list
  • Encryption of stored data (AWS KMS)
  • Role-based access on a need-to-know basis with multi-factor authentication
  • Salted hashes instead of plain-text phone numbers for recognising returning callers
  • Data minimisation: only the response text reaches speech synthesis; call audio is not stored
  • No storage of payment data — card details are processed exclusively by Stripe (PCI-DSS)

9. Data breaches

In the event of a personal data breach we notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and inform affected persons without undue delay where there is a high risk (Art. 34 GDPR). Where we act as a processor, we notify the responsible customer without undue delay (Art. 33 (2) GDPR).

10. Changes to this policy

We update this policy when the legal situation or our processing changes. The version published here applies; you can find its date at the top of this page.