Legal
Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains how Loonar ApS processes personal data in connection with the website at loonar-ai.com.
It covers the website only. The Loonar platform is governed by a separate agreement and data processing agreement with each customer, under which Loonar acts as a data processor rather than a data controller. Nothing in this policy applies to documents or data our customers upload to the platform.
1. Who is responsible for your data
The data controller is:
Loonar ApSVesterbrogade 192, 2.10.
1800 Frederiksberg C
Denmark
CVR / VAT: DK46064933
Email: gianlorenzo@loonar-ai.com
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Privacy enquiries go to the address above and are handled by the management of Loonar ApS.
2. What we collect, why, and on what legal basis
We keep data collection on this website deliberately minimal. There is no advertising technology, no profiling, no cross-site tracking and no sale of personal data.
2.1 Request access and contact enquiries
What: Your name, business email address, company name, job title, and anything else you choose to write in the message field.
Why: To respond to you, assess whether Loonar is a fit for your organisation, arrange a demonstration, and manage the resulting commercial conversation.
Legal basis: Article 6(1)(b) GDPR, steps taken at your request prior to entering into a contract. Where you contact us on behalf of an organisation that is not yet in discussion with us, we rely on Article 6(1)(f), our legitimate interest in responding to business enquiries and maintaining commercial relationships.
Retention: Up to 24 months after our last meaningful contact with you, unless your organisation becomes a customer, in which case the data is retained for the duration of the contractual relationship and as required by the Danish Bookkeeping Act.
2.2 Email correspondence
What: The content of emails you send us, including any attachments, together with your email address and signature details.
Why: To conduct and document the correspondence.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in communicating with the people who contact us and keeping a record of what was agreed.
Retention: Up to 24 months, or longer where the correspondence forms part of a contractual or accounting record.
2.3 Job applications
What: Applications sent to us by email, including your CV, cover letter, contact details, employment history, education, and anything else you choose to include.
Why: To assess your application and run the recruitment process.
Legal basis: Article 6(1)(b) GDPR, steps taken at your request prior to entering into an employment contract.
Retention: Six months after the position is filled or the process is closed. If we would like to keep your application on file beyond that, we will ask for your consent and you may withdraw it at any time.
Please do not include sensitive personal data in your application, such as health information, trade union membership, political or religious beliefs, or your Danish CPR number. We do not need it and do not ask for it.
2.4 Website analytics
What: We use Vercel Web Analytics to understand which pages are visited and how people navigate the site. Vercel Web Analytics is cookieless: it does not set cookies, does not store an identifier on your device, and does not track you across other websites. It derives a temporary, non-persistent hash from request data, including your IP address, to distinguish one visit from another, and that hash is not retained or linked back to you.
Why: To understand which content is useful and improve the site.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in understanding how our website is used. We have weighed this against your interests and consider the impact minimal, given that the data is aggregated, cookieless, non-persistent, and not used to build any profile of you.
Retention: Aggregated statistics are retained for up to 12 months. No individual-level record is created.
2.5 Hosting and security logs
What: Our hosting provider records technical information about requests to the site, including IP address, browser type, referring page, and timestamps.
Why: To deliver the website, protect it against abuse and attack, and diagnose faults.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest in the security and availability of our own systems.
Retention: Short-term, in line with our hosting provider's log retention settings, and normally no longer than 30 days.
3. Cookies
This website does not use cookies for analytics, advertising, personalisation or profiling. Our analytics provider is cookieless, and we do not run advertising pixels, tag managers, session recording, heatmapping or third-party chat widgets.
For that reason you will not see a cookie consent banner on this site. If our hosting or security infrastructure sets a strictly necessary cookie in order to deliver a page or protect the site against abuse, that cookie is exempt from the consent requirement in the Danish cookie order and is not used for any other purpose.
If we introduce any non-essential cookie or similar technology in future, we will publish a cookie policy and ask for your consent before it is set, with rejecting made as straightforward as accepting.
4. Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing purposes. We use a small number of service providers who process data on our instructions under Article 28 GDPR data processing agreements:
| Provider | Role | Location of processing |
|---|---|---|
| Vercel Inc. | Website hosting, content delivery, and cookieless web analytics | EU region; company established in the United States |
| Google Ireland Limited | Business email (Google Workspace) | EU, with Google LLC as sub-processor |
| Attio Ltd. | Customer relationship management for business enquiries | United Kingdom |
Beyond these, we may disclose personal data to our professional advisers, or to public authorities and courts where we are legally required to do so.
5. Transfers outside the EU/EEA
Our website and its data are hosted in an EU region. However, Vercel Inc. is established in the United States, and access from the United States cannot be entirely excluded for support and maintenance purposes. Where such a transfer occurs, it is covered by the European Commission's Standard Contractual Clauses and, where applicable, the provider's certification under the EU-U.S. Data Privacy Framework, together with supplementary technical and organisational measures.
Attio Ltd. is established in the United Kingdom, which the European Commission has recognised as providing an adequate level of data protection. No additional transfer safeguards are required for that transfer.
You may request a copy of the relevant safeguards by writing to gianlorenzo@loonar-ai.com.
6. Automated decision-making
We build artificial intelligence software, so we want to be explicit about this: we do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR, in relation to visitors to this website or people who contact us through it. No AI system is applied to your enquiry to decide whether we respond to you.
Personal data collected through this website is not used to train any machine learning model.
7. Do you have to provide your data
You are not obliged to provide any personal data to browse this website. If you choose to contact us or request access to the platform, we need at minimum your name and a business email address in order to reply. Without them we cannot respond.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy of it
- Rectify data that is inaccurate or incomplete
- Erasure of your data in the circumstances set out in Article 17
- Restrict our processing in the circumstances set out in Article 18
- Data portability, receive data you provided to us in a structured, commonly used, machine-readable format
- Object to processing based on our legitimate interests, on grounds relating to your particular situation
- Withdraw consent at any time, where we have relied on your consent, without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, email gianlorenzo@loonar-ai.com. We will respond within one month. If your request is complex or you have made several requests, we may extend that period by up to two further months and will tell you if we do.
There is no charge for exercising your rights. We may ask for information to confirm your identity where we cannot otherwise be confident who is making the request.
9. Complaints
If you are unhappy with how we handle your personal data, we would like to hear from you first so we can put it right. You also have the right to complain directly to the Danish Data Protection Agency:
DatatilsynetCarl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control on a need-to-know basis, multi-factor authentication on the systems that hold personal data, and the use of established infrastructure providers operating certified environments.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and we will notify Datatilsynet where required within 72 hours.
11. Children
This website is directed at business users and is not intended for children. We do not knowingly collect personal data from anyone under the age of 15, the age of digital consent in Denmark.
12. Changes to this policy
We may update this policy as our website or the applicable law changes. The date at the top shows when it was last revised. Where a change materially affects how we process your personal data, we will take reasonable steps to bring it to your attention.
13. Contact
Loonar ApSVesterbrogade 192, 2.10.
1800 Frederiksberg C
Denmark
CVR: 46064933
gianlorenzo@loonar-ai.com