Privacy Policy
Last updated: August 2026. Lojycal is GDPR-aligned and architected for Privacy-by-Design. All data flows are processed lojycally utilizing Row-Level Security (RLS), hardware-gated MFA (AAL2), and tamper-proof WORM audit logs to ensure that your organization's data remains isolated, immutable, and under your absolute control.
1. Controller
Wesley Vincent Thomas Blake, trading as “Lojycal”, Katbachstraße 24, 10965 Berlin, Germany, is the data controller for personal data processed through this website and the Lojycal platform. Contact: privacy@lojycal.com.
2. Data we process
Account data (name, email, role), workspace telemetry (assets, contracts, governance events), and security logs required to operate the IT operations console.
3. Legal basis
Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (legitimate interest in security).
4. Who we share data with
We share personal data only with the following categories of recipients:
- Merchant of Record — Paddle.com Market Limited. Paddle is the reseller and Merchant of Record for all orders and receives the personal data needed to complete the sale, manage subscriptions, process payments and refunds, handle tax compliance, and issue invoices. Paddle acts as an independent controller for that processing; see the Paddle Privacy Notice. We never store full card details.
- Service providers / sub-processors: hosting, database, email delivery, analytics, and support tooling.
- Professional advisers (legal, accounting) under confidentiality obligations.
- Public authorities where disclosure is required by law.
5. Storage & transfers
Data is stored within the EU. Sub-processors are listed in your workspace under Admin → Regional Compliance and on our public Sub-processors page. Where a recipient processes data outside the EEA/UK, transfers are safeguarded by EU Standard Contractual Clauses or an adequacy decision.
6. Data retention
Account and workspace data is retained for the life of the subscription and deleted or anonymised within 90 days of account closure. Security and audit logs are retained for 12 months. Billing and invoicing records held by us or by Paddle are retained for 10 years to meet German commercial and tax law obligations (§ 147 AO, § 257 HGB). Marketing contact data is deleted on withdrawal of consent.
7. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent per Art. 15–22 GDPR, plus the right to lodge a complaint with a supervisory authority. Contact privacy@lojycal.com to exercise them; we respond within one month.
8. Security
TLS in transit, encryption at rest, MFA, RBAC, and continuous audit logging. See the Audit Evidence Center for current posture.