Privacy Policy

Lokidrop — Changelog as a Service · Effective date: March 5, 2026 · Version 1.0

Privacy is a core principle at Lokidrop, not an afterthought. We collect only what we need, we don't sell your data, and we give you full control over what you share with us.


1. Who We Are

Lokidrop - Phenomenal Development Oy Ltd.
Business ID: 3137224-5
Address: Savilankatu 2, 26100 Rauma, Finland
Email: [email protected]

Loki operates lokidrop.com and is the data controller for all personal data processed in connection with the Service.


2. What Data We Collect

2.1 Account Information

When you create a Lokidrop account, we collect:

  • Email address (for authentication and service communications)
  • Your name
  • Password (hashed — never stored in plaintext)
  • Organisation information

2.2 Usage Data

We automatically collect limited technical data when you use the Service:

  • IP address (for security logging and abuse prevention)
  • Browser type and version
  • Request timestamps and accessed endpoints
  • Changelog entries you create or publish within the Service

2.3 Payment Data

For paid subscriptions, payments are processed by a third-party payment provider Stripe. We do not store card numbers or other sensitive payment credentials on our servers. We retain only transaction identifiers and billing records required by law.


3. Legal Bases for Processing (GDPR Art. 6)

We process your personal data on the following legal grounds:

  • Contract performance (Art. 6(1)(b)): Account creation, authentication, and delivery of the Service.
  • Legitimate interests (Art. 6(1)(f)): Maintaining service security, preventing abuse, and improving the product.
  • Legal obligation (Art. 6(1)(c)): Compliance with applicable laws, including accounting and tax legislation.
  • Consent (Art. 6(1)(a)): Marketing communications, where you have explicitly opted in.

4. How We Use Your Data

We use the data we collect solely for the following purposes:

  • Providing, maintaining, and supporting the Service
  • Managing your account and authenticating access
  • Improving the Service and user experience
  • Detecting and responding to security incidents and abuse
  • Processing billing and subscription management
  • Sending service-related notifications (e.g. downtime alerts, policy updates)
  • Sending marketing communications where you have given consent

5. Data Sharing

We do not sell, rent, or trade your personal data to third parties for commercial purposes. We share data only in the following limited circumstances:

  • Subprocessors and service providers: We use trusted third-party services (e.g. cloud hosting, payment processing, transactional email). All subprocessors are bound by a Data Processing Agreement (DPA) in accordance with GDPR requirements.
  • Legal obligations: We may disclose data to competent authorities when required by law, court order, or to protect our legal rights.
  • Business transfers: In the event of a merger, acquisition, or sale of substantially all assets, personal data may transfer to the new controller. We will notify you in advance of any such change and your rights in relation to it.

6. International Data Transfers

We store and process personal data primarily within the EU/EEA. Where data is transferred outside the EU/EEA (for example, to service providers in the United States), we ensure the transfer is lawful through:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission
  • An adequacy decision applicable to the destination country, where available

7. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy or to meet legal obligations:

Data type Retention period
Active account dataDuration of account
Post-deletion cleanup30 days after account deletion
Billing and accounting records7 years (statutory requirement)
Security and access logsMaximum 12 months

After the applicable retention period, data is securely deleted or irreversibly anonymised.


8. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your data where there is no longer a lawful basis for processing.
  • Right to restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests.
  • Right to withdraw consent: Withdraw any previously given consent at any time, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days as required by the GDPR.

You also have the right to lodge a complaint with a supervisory authority. In Finland, the competent authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).


9. Cookies

We use cookies and similar technologies to operate the Service and understand how it is used. We use two categories:

  • Strictly necessary cookies: Session tokens and CSRF protection. These are required for the Service to function and do not require your consent.
  • Analytics cookies: Used to collect aggregated, anonymised usage statistics to improve the Service. These require your consent and can be declined without affecting core functionality.

You can manage cookie preferences through your browser settings at any time.


10. Security

We apply appropriate technical and organisational measures to protect your personal data:

  • All traffic is encrypted using TLS 1.2 or higher
  • Passwords are stored using bcrypt or an equivalent strong hashing algorithm
  • Access to production systems is restricted and requires multi-factor authentication
  • We conduct regular security reviews

In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Art. 33–34.


11. Minors

The Service is intended for users aged 18 or older. We do not knowingly collect personal data from children under 18. If we become aware that we have inadvertently collected such data, we will delete it promptly.


12. Changes to This Policy

We may update this Privacy Policy as the Service evolves or as legislation requires. For material changes, we will notify you on our Changelog at this site.

The effective date at the top of this document will always reflect the current version. Continued use of the Service after the effective date constitutes acceptance of the updated policy.


13. Contact

For all privacy-related questions or to exercise your rights:

Email: [email protected]