1. Who is responsible for your data?
LoopRx is the data controller for the personal data described in this notice. You can contact us at admin@looprx.dk.
2. Personal data we handle
We limit collection to the data needed to provide and protect the service:
- Account data: your name, email address, password hash, account status, access expiry date, and the number of devices allowed.
- Subscription data: Stripe customer, subscription, and Price identifiers; billing interval; subscription status; renewal date; and whether cancellation is scheduled. Payment-card details are collected by Stripe and are not received or stored by LoopRx.
- Device and session data: device name, a protected device identifier, login token hash, session creation time, last activity, expiry time, and revocation status.
- Security data: protected versions of email addresses and IP addresses used to prevent repeated login attempts, together with the time and outcome of an attempt.
- Technical service data: IP address, request time, user agent, error details, and similar server-log information generated when the website, account service, or audio stream is accessed.
- Communications: messages and contact details you provide if you ask us for support.
The app analyses the audio signal level on your device to indicate an active transmission. This processing happens locally; LoopRx does not use it to record or upload your audio.
LoopRx does not use advertising trackers and the iOS app does not request access to your location, contacts, camera, or microphone.
3. Why we use personal data
| Purpose | Legal basis |
|---|---|
| Create and administer your account, send a password-setup link, sign you in, provide streaming access, and enforce the configured device limit. | Performance of a contract or steps requested before entering one — GDPR Article 6(1)(b). |
| Take payment, administer monthly or annual subscriptions, provide billing self-service, and meet accounting and tax obligations. | Performance of a contract and compliance with legal obligations — GDPR Article 6(1)(b) and (c). |
| Protect accounts, prevent abuse, investigate errors, maintain availability, and keep the service secure. | Our legitimate interests in operating and protecting LoopRx — GDPR Article 6(1)(f). |
| Respond to support requests and service-related communications. | Performance of a contract and our legitimate interest in supporting users — GDPR Article 6(1)(b) and (f). |
| Comply with binding legal requirements and lawful authority requests. | Compliance with a legal obligation — GDPR Article 6(1)(c). |
Providing your name, email address, password, and device information is necessary to create an account and provide protected streaming access. Without it, we cannot provide the account service.
The two-device limit is applied automatically as an access-control rule. LoopRx does not make automated decisions that produce legal or similarly significant effects as described in GDPR Article 22.
5. How long we keep personal data
- Account data is kept while your account is active and afterwards only for as long as reasonably needed for account closure, disputes, security, or legal obligations.
- Subscription records and transaction-related correspondence are kept for the duration of the subscription and afterwards as required for accounting, tax, disputes, and legal compliance. Stripe applies its own retention obligations to data it processes.
- Failed-login records used for rate limiting are deleted after one day.
- A password-setup link becomes unusable after 24 hours or once used.
- An app session must remain active to retain a device slot; an abandoned slot normally becomes available after 15 minutes. Authentication credentials can expire no later than 30 days after issue. Related security records may remain until they are no longer needed or the account is deleted.
- Technical and hosting logs are kept for a limited operational and security period, according to the configuration and requirements of the relevant provider.
- Support correspondence is kept only as long as needed to resolve the request and document the outcome.
We may retain limited information for longer where required by law or necessary to establish, exercise, or defend legal claims. We then delete or anonymise it when it is no longer needed.
6. Cookies and storage on your device
The account pages use strictly necessary session storage to keep forms and administrator access secure. The iOS app stores its login credential and a device identifier in Apple Keychain so that you can remain signed in and so the device limit can be enforced.
Stripe Checkout and the Stripe customer portal may use strictly necessary storage for secure payment, fraud prevention, and billing functions. LoopRx does not use browser local storage for account passwords or payment details.
We do not use advertising or cross-site tracking cookies.
7. How we protect personal data
Passwords handled by the production account backend are stored as password hashes rather than readable passwords. Login tokens and device identifiers are also stored in protected or hashed form. We use access controls, rate limiting, expiring sessions, revocation controls, and encrypted HTTPS connections for the account service. No internet service can be guaranteed completely secure, but we review safeguards as the service changes.
8. Your data-protection rights
Depending on the circumstances, you may have the right to:
- receive information about and a copy of your personal data;
- correct inaccurate or incomplete personal data;
- request deletion or restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests; and
- withdraw consent at any time where processing is based on consent.
These rights can be limited by law. To exercise a right, email admin@looprx.dk. We may ask for information needed to verify that the request concerns your account.
9. Questions and complaints
For privacy questions or requests, contact LoopRx at admin@looprx.dk.
You may also complain to your local data-protection authority. In Denmark, this is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark, telephone +45 33 19 32 00, email dt@datatilsynet.dk.
10. Changes to this notice
We may update this notice when the service, providers, or legal requirements change. The date at the top shows when it was last revised. Material changes will be communicated through an appropriate service channel.