Privacy Policy
Lokidrop — Changelog as a Service · Effective date: March 5, 2026 · Version 1.0
Privacy is a core principle at Lokidrop, not an afterthought. We collect only what we need, we don't sell your data, and we give you full control over what you share with us.
1. Who We Are
Lokidrop - Phenomenal Development Oy Ltd.
Business ID: 3137224-5
Address: Savilankatu 2, 26100 Rauma, Finland
Email: [email protected]
Loki operates lokidrop.com and is the data controller for all personal data processed in connection with the Service.
2. What Data We Collect
2.1 Account Information
When you create a Lokidrop account, we collect:
- Email address (for authentication and service communications)
- Your name
- Password (hashed — never stored in plaintext)
- Organisation information
2.2 Usage Data
We automatically collect limited technical data when you use the Service:
- IP address (for security logging and abuse prevention)
- Browser type and version
- Request timestamps and accessed endpoints
- Changelog entries you create or publish within the Service
2.3 Payment Data
For paid subscriptions, payments are processed by a third-party payment provider Stripe. We do not store card numbers or other sensitive payment credentials on our servers. We retain only transaction identifiers and billing records required by law.
3. Legal Bases for Processing (GDPR Art. 6)
We process your personal data on the following legal grounds:
- Contract performance (Art. 6(1)(b)): Account creation, authentication, and delivery of the Service.
- Legitimate interests (Art. 6(1)(f)): Maintaining service security, preventing abuse, and improving the product.
- Legal obligation (Art. 6(1)(c)): Compliance with applicable laws, including accounting and tax legislation.
- Consent (Art. 6(1)(a)): Marketing communications, where you have explicitly opted in.
4. How We Use Your Data
We use the data we collect solely for the following purposes:
- Providing, maintaining, and supporting the Service
- Managing your account and authenticating access
- Improving the Service and user experience
- Detecting and responding to security incidents and abuse
- Processing billing and subscription management
- Sending service-related notifications (e.g. downtime alerts, policy updates)
- Sending marketing communications where you have given consent
5. Data Sharing
We do not sell, rent, or trade your personal data to third parties for commercial purposes. We share data only in the following limited circumstances:
- Subprocessors and service providers: We use trusted third-party services (e.g. cloud hosting, payment processing, transactional email). All subprocessors are bound by a Data Processing Agreement (DPA) in accordance with GDPR requirements.
- Legal obligations: We may disclose data to competent authorities when required by law, court order, or to protect our legal rights.
- Business transfers: In the event of a merger, acquisition, or sale of substantially all assets, personal data may transfer to the new controller. We will notify you in advance of any such change and your rights in relation to it.
6. International Data Transfers
We store and process personal data primarily within the EU/EEA. Where data is transferred outside the EU/EEA (for example, to service providers in the United States), we ensure the transfer is lawful through:
- EU Standard Contractual Clauses (SCCs) as approved by the European Commission
- An adequacy decision applicable to the destination country, where available
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy or to meet legal obligations:
| Data type |
Retention period |
| Active account data | Duration of account |
| Post-deletion cleanup | 30 days after account deletion |
| Billing and accounting records | 7 years (statutory requirement) |
| Security and access logs | Maximum 12 months |
After the applicable retention period, data is securely deleted or irreversibly anonymised.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): Request deletion of your data where there is no longer a lawful basis for processing.
- Right to restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw any previously given consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days as required by the GDPR.
You also have the right to lodge a complaint with a supervisory authority. In Finland, the competent authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).
9. Cookies
We use cookies and similar technologies to operate the Service and understand how it is used. We use two categories:
- Strictly necessary cookies: Session tokens and CSRF protection. These are required for the Service to function and do not require your consent.
- Analytics cookies: Used to collect aggregated, anonymised usage statistics to improve the Service. These require your consent and can be declined without affecting core functionality.
You can manage cookie preferences through your browser settings at any time.
10. Security
We apply appropriate technical and organisational measures to protect your personal data:
- All traffic is encrypted using TLS 1.2 or higher
- Passwords are stored using bcrypt or an equivalent strong hashing algorithm
- Access to production systems is restricted and requires multi-factor authentication
- We conduct regular security reviews
In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Art. 33–34.
11. Minors
The Service is intended for users aged 18 or older. We do not knowingly collect personal data from children under 18. If we become aware that we have inadvertently collected such data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy as the Service evolves or as legislation requires. For material changes, we will notify you on our Changelog at this site.
The effective date at the top of this document will always reflect the current version. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
For all privacy-related questions or to exercise your rights:
Email: [email protected]