Privacy Policy
Version 2026-09-16.4 · Last updated September 16, 2026
This privacy policy explains how Labelloop processes personal data when you create an account, join or create an organization, use the platform, communicate with partners, upload files, manage transactions, or contact support.
Labelloop is designed for business users in Germany and other European markets. Personal data is processed in accordance with the GDPR and applicable German data protection law.
1. Controller identity and contact
WhiteNode Holding GmbH, Volmerswerther Str. 32, 40221 Düsseldorf, Germany, is the controller for the personal data processing described in this privacy policy, unless a specific workflow expressly states otherwise.
For privacy questions or to exercise your rights, you can contact us at info@labelloop.app. If a dedicated data protection officer is appointed or required for a specific processing arrangement, the applicable contact details will be communicated through the service or on request.
2. Controller, processor, and counterparty roles
Labelloop normally acts as controller for account administration, authentication, platform security, legal acceptance, billing administration, support, product operation, and its own compliance documentation.
For business content that an organization uploads, imports, sends, or manages for its own commercial relationship, the organization may remain an independent controller or Labelloop may process the content on the organization's behalf, depending on the agreed contractual setup and the specific workflow.
Connected brands, retailers, showrooms, agencies, payment providers, and other counterparties may act as independent controllers for their own use of information they receive through a shared workflow. Where a data processing agreement or other privacy arrangement is required for a specific customer setup, it must be agreed separately before production use.
3. Categories of personal data
Depending on your role and usage, Labelloop may process the following categories of personal data:
- account and identity data such as name, email address, login identifiers, role, and organization assignment
- organization and profile data such as company details, business contacts, addresses, VAT-related information, showroom and brand profile content
- placeholder organization data such as placeholder customer or placeholder showroom names, contact details, addresses, notes, creator information, merge history, and replacement organization references
- operational data such as appointments, orders, reorders, preorders, invoices, credit notes, transactions, requests, claims, and delivery-related records
- communication data such as messages, support content, comments, reactions, mentions, invitation emails, and attached files
- uploaded content and metadata such as images, screenshots, PDFs, invoice documents, claim documents, brand assets, filenames, upload references, and file types
- import, parsing, and translation data such as extracted document text, parsed fields, matching candidates, confidence signals, warnings, review decisions, source document references, translation cache entries, and correction history where such features are enabled
- email-import data where mailbox import is enabled, such as sender and recipient information, message metadata, attachments, provider message identifiers, processing labels, review status, and error state
- payment and subscription data where billing or payment functions are used, including payment provider identifiers, checkout references, payment status, mandate or subscription references, and invoice payment history
- technical usage and session data such as browser metadata, IP addresses and IP-derived security signals, authentication tokens, essential cookies, device and request logs, and platform activity timestamps
- security and audit data such as session events, rate-limiting signals, approval records, permission changes, impersonation or admin support events, and legal acceptance evidence including the accepted versions, timestamps, document snapshots and hashes, interface locale, user agent, request IP address, and actor, role, and organization context
- integration, delivery, and notification data such as catalog and product data, integration account identifiers and configuration, push tokens and notification payloads, carrier tracking numbers, link-preview URLs and retrieved metadata, webhook identifiers, delivery state, and provider error records where the corresponding feature is enabled
4. Sources of personal data
We collect personal data directly from you when you register, sign in, complete profiles, upload files, send messages, create records, or contact support.
We may also receive data from your organization administrators, connected counterparties, users who create placeholder organizations or invitations, authentication providers, email and mailbox providers, payment providers, import sources, and technical systems that record session, security, and audit events required for operating the service.
Where Labelloop collects personal data from other sources as controller for its own processing purposes, we provide the information required by Article 14 GDPR within the applicable statutory period—normally no later than one month, or at the first communication or disclosure if earlier—unless a documented statutory exception applies. For customer data processed solely on behalf of an organization, that organization is responsible for informing affected persons; Labelloop assists it within the contractually agreed scope. Organizations and counterparties that provide personal data must have a lawful basis and meet their applicable information obligations.
5. Purposes of processing
We process personal data to provide and secure the platform, connect users to the correct organizations, enable collaboration and transaction workflows, maintain records, communicate service-related information, send invitations and operational notifications, process payments where applicable, and comply with legal obligations.
Where placeholder organizations are used, we process the related data to let a brand or showroom work with a provisional customer or showroom record and, where selected by an authorized user, to merge or reassign related business records to the real organization that later joins or is connected.
Where import, mailbox, parsing, AI-assisted analysis, OCR, or translation features are enabled, we process the relevant documents, extracted content, and metadata to create reviewable suggestions, translations, matching candidates, warnings, and audit trails. Manual uploads and imports requiring review need confirmation; authorized mailbox imports may also create business records automatically under the safeguards described below.
Where the AI analysis assistant (copilot) is enabled, we process the business records already visible to your role (such as invoice, order, delivery, claim, transaction, and appointment summaries) together with your questions to generate answers and explanations within the platform.
We may also process limited data to prevent abuse, investigate incidents, improve reliability, maintain internal auditability, measure feature health, and document acceptance of legal information.
6. Legal bases under Article 6 GDPR
Article 6(1)(b) GDPR applies only where you are personally a party to the contract or processing is necessary to take pre-contractual steps at your request. Where you use Labelloop for an organization that is the contracting party, Article 6(1)(f) GDPR ordinarily supports provision of the B2B service, including account and workflow communications, subject to the required balancing of interests and your rights.
We may also rely on Article 6(1)(c) GDPR for legal obligations, including accounting, tax, and compliance retention duties, and on Article 6(1)(f) GDPR for legitimate interests such as service security, fraud prevention, system stability, access control, internal documentation, and enforcement of platform rules.
For account and workflow communications, import review, support, auditability, and platform improvement, the legal basis may include Article 6(1)(b) GDPR or Article 6(1)(f) GDPR depending on the context. Where data is processed to meet statutory accounting, tax, commercial, or security obligations, Article 6(1)(c) GDPR may apply.
Where a specific processing activity legally requires consent, we will request it separately. Your acknowledgement of this privacy policy does not replace separate consent where consent is the correct legal basis.
Access to or storage of information on your device is based on the applicable terminal-device rules. Strictly necessary storage is used to provide a service you expressly request; optional analytics or comparable non-essential storage remains disabled until separate informed consent has been given.
7. Recipients and processors
We may use specialized service providers to operate the platform and related functions. Depending on the active feature set, this may include hosting, authentication, email delivery, payments, database hosting, file handling, and AI-assisted processing.
Connected business counterparties may receive personal data where this is necessary for the collaboration workflow they participate in. Depending on the context, those counterparties may act as separate controllers for their own use of the information they receive.
- your organization, its authorized administrators, and its approved members according to role-based permissions
- connected counterparties and their authorized users where this is necessary for the business workflow you initiate or participate in
- hosting and application infrastructure providers: Vercel for application hosting, server functions and private Blob file/object storage; Neon for the managed PostgreSQL database and legacy database-backed file records where applicable; and Upstash for rate limiting and related infrastructure
- authentication providers such as Auth0
- email and notification providers such as Brevo, including for invitations and transactional platform emails
- mailbox and email import providers such as Google/Gmail where an import mailbox or customer-authorized mailbox workflow is enabled
- payment provider Stripe where payment features are enabled: Stripe Connect for retailer invoice payments to brands and a separate Stripe Billing account for Labelloop software subscriptions; Mollie only where required to read, reconcile, or retain payment and subscription artifacts created before the Stripe-only transition during supervised decommissioning
- AI service providers: processing through Requesty as a gateway and separately selected model providers for document import analysis (document files, page images or extracted text, related email text and limited business context), the AI analysis assistant / copilot (records visible to your role plus your questions) and content translation; see section 13
- file-security providers: Cloudmersive where the production malware-scan configuration is active, or another specifically configured scan endpoint after review; the file content, filename, and file type are transmitted for malware analysis before release
- commerce and catalog providers such as Shopify, where an organization enables the integration, for catalog synchronization, product media retrieval, account connection, and configured webhook events
- notification delivery providers: Expo Push Service, which forwards mobile notifications to Apple Push Notification service or Google Firebase Cloud Messaging; Apple Push Notification service directly for the macOS app; and the endpoint supplied by the user's browser for Web Push, where the respective notification feature is enabled
- carrier, tracking, and link-preview destinations where the corresponding feature is enabled or initiated by the user; this can involve tracking numbers, requested URLs, retrieved preview metadata, credentials configured by the organization, and limited technical request data
- analytics providers: Vercel Web Analytics and PostHog only where the relevant feature is configured and the user has separately consented; account-linked first-party usage telemetry is likewise disabled without separate consent
- professional advisors, authorities, courts, or counterparties where disclosure is legally required or necessary to establish, exercise, or defend legal claims
8. International data transfers
Labelloop selects and configures infrastructure regions with the objective of processing core platform data in the EEA where the relevant provider and product permit this. The exact storage or processing region, support access, subprocessor chain, and deletion behavior depend on the active production account and provider configuration and are verified as part of provider approval; they are not inferred from a code default.
Some active providers, subprocessors, or support teams may process personal data outside the EEA or access it from a third country. Such transfers require an applicable mechanism under Chapter V GDPR, such as an adequacy decision (including the EU-U.S. Data Privacy Framework only for a currently certified recipient) or EU Standard Contractual Clauses with a transfer assessment and supplementary measures where required.
Transfer scope is limited to the data necessary for the relevant function. You may request information about a specific recipient, destination country, and applicable safeguard, and a copy or description of the safeguard where Article 13, 14, or 15 GDPR requires this, subject to protected confidential information.
9. Retention
We retain personal data only for as long as necessary for the service relationship, the relevant workflow, legitimate business documentation, and statutory retention obligations.
When a placeholder organization is merged into a real organization, Labelloop may retain merge metadata and audit history where necessary to preserve business records, explain record history, and prevent accidental loss or unauthorized reassignment.
Import suggestions, extracted document text, mailbox-import records, correction history, and review decisions may be retained for as long as needed to complete the review workflow, prevent duplicate processing, preserve provenance, and support later auditability of records created from imports.
For the AI features, Labelloop configures requests to Requesty to disable response storage and automatic prompt caching. These settings alone do not guarantee that Requesty or the selected model provider retains no data, excludes training, or processes data only in the EU. The retention and deletion of content, metadata, security logs, and internal caches depend on the applicable rules and account configuration of Requesty and the selected model provider.
Disabling push notifications stops further delivery; it does not automatically delete the device registration or token. Registration data may continue to be retained only where necessary for security or to document the registration and its deactivation.
Optional analytics identifiers and events are collected only with separate consent. Withdrawal stops further collection but does not automatically delete data already collected. Any continued retention requires an applicable legal basis. Commercial and tax-relevant records may be retained for periods required by applicable law. Security, audit, and support records may be retained where necessary to investigate incidents, establish or defend legal claims, or protect the platform.
Legal acceptance evidence, including request IP address and user agent, is access-restricted and retained only for as long as necessary to demonstrate the accepted text, authority, and acceptance, resolve disputes, and comply with applicable limitation or legal-retention duties. Account deletion does not automatically delete this evidence. Your rights under section 11 remain unaffected.
10. Required data and consequences of non-provision
Some personal data is required to create and secure your account, assign you to the correct organization, and operate the core B2B workflows of the platform.
If required data is not provided or becomes inaccurate, we may be unable to create an account, connect you to an organization, process transactions, send operational notices, or maintain secure access to the service.
11. Your GDPR rights
Subject to the legal requirements, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection.
Where processing is based on consent, you may withdraw that consent at any time as easily as it was given, without affecting the lawfulness of processing before withdrawal. Optional processing will stop for the future after a valid withdrawal, subject to data that must still be retained on another legal basis.
Where processing is based on legitimate interests, you may object on grounds relating to your particular situation under Article 21 GDPR. You may object to direct marketing at any time without giving reasons; Labelloop will then stop using the data for that purpose.
You also have the right to lodge a complaint with a competent supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. For our German operating entity, this may include the supervisory authority in North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2-4, 40213 Düsseldorf, poststelle@ldi.nrw.de).
To exercise your rights, please contact info@labelloop.app. We may request reasonable information to verify your identity and your connection to the relevant organization before processing a request.
12. Security, cookies, and platform communications
We use technical and organizational measures appropriate to the risk, including authenticated access controls, session protection, rate limiting, logging, and role-based permission checks.
Labelloop uses strictly necessary cookies or similar device storage for authentication, session protection, security, language and theme choices, accessibility and display preferences, role and organization context, consent choices, and user-requested drafts or workflow state. Depending on the purpose, these entries last for the browser session, for the configured secure login period, or until you change or delete the relevant preference. Blocking or deleting necessary storage can prevent requested functions from working.
Labelloop may send operational or account-related communications that are necessary for account security, onboarding, access management, billing, import review, support, and core workflow notifications.
If you separately opt in to an email about the mobile app launch, we store your choice and its update time with your account. This optional notification is based on your consent under Article 6(1)(a) GDPR. You can withdraw it at any time through the same setting, without affecting the lawfulness of earlier processing. After signing in, you can also withdraw under /legal/preferences on a computer or mobile device, including without accepting updated terms. Requesting a desktop login link or receiving necessary service messages does not subscribe you to launch emails. Launch-notification sending has not yet been activated.
Optional first-party usage analytics starts only after a separate, voluntary choice. It measures page visits, defined actions and device categories to improve the service and evaluate reach. Core, Desktop and Mobile activity can be linked to the signed-in account and organization; Shop measurement uses a pseudonymous session identifier. You can allow or decline analysis separately in the legal notice flow and change or withdraw your choice at any time through Analytics settings, including without accepting updated terms. Essential functions remain available when you decline. The versioned choice is stored separately for each browser or app origin for 180 days; it is not a cross-site identifier. Do Not Track and analytics opt-out stop collection. New events recorded under this consent version have a 365-day retention period, followed by regular automatic cleanup; this change does not additionally delete historical records. Withdrawal stops further collection and removes local analytics identifiers, but does not automatically erase previously stored events. Vercel Web Analytics, PostHog and session replay remain separately disabled. Accepting the terms or acknowledging this policy does not grant analytics consent.
Automatic transmission of client diagnostics is also protected by an independent closed release lock. It remains off until a reviewed field allowlist, access model, retention and deletion rule, documented legitimate-interest assessment, and matching notice have been approved. Accepting these terms or acknowledging this policy does not activate it.
Session replay: PostHog session recording has an additional release lock and remains disabled unless a separately reviewed replay feature is enabled and the user has explicitly consented. If released, text, inputs, sensitive document areas, iframes, and canvas content are masked or blocked by default.
If further non-essential technologies are introduced or enabled for external users, the related information, masking settings, legal basis, and consent or objection mechanism will be provided separately where required.
13. AI-assisted features, sensitive data, and automated processing
Labelloop offers three configurable AI-assisted features through Requesty as a gateway and separately selected model providers: (i) document import analysis, where uploaded or mail-imported business documents (document files, page images or extracted text, related email text and limited business context such as partner names and order references) are analyzed to create import suggestions; (ii) the AI analysis assistant (copilot), where business records already visible to your role are processed with your questions to generate answers; and (iii) content translation, where message and comment text is translated.
Requesty operates the gateway; a separately selected provider runs the model. An EU gateway alone does not guarantee model processing in the EU or exclude access from other jurisdictions. The applicable contracts, processing locations, subprocessors, transfer safeguards, retention and deletion rules, training restrictions, and account settings depend on Requesty and the selected model provider and must be assessed separately for each.
Labelloop is not intended for the routine storage of special categories of personal data under Article 9 GDPR or comparable highly sensitive data unless this is strictly necessary and lawfully supported for a specific workflow. Users should avoid uploading such data unless they are clearly authorized and legally permitted to do so.
Labelloop does not use fully automated decision-making with legal or similarly significant effects on users within the meaning of Article 22 GDPR based on the information currently available for the platform.
AI-assisted import analysis, OCR, matching, copilot, and translation features are intended to create reviewable suggestions, answers, or language support, not final automated decisions with legal or similarly significant effects. Manually uploaded documents always require review and confirmation before business records are created. For the mailbox import, documents from senders approved by the organization may be imported automatically where the analysis meets strict confidence requirements. Such records remain visible for review by authorized users. Corrections follow the available business procedures and depend on permissions, payment status, and retention requirements; invoices in particular cannot be deleted at will. Such imports do not produce legal or similarly significant effects on individuals within the meaning of Article 22 GDPR. If this changes for a specific workflow, the relevant information will be provided separately.
Where a user interacts directly with an AI system, Labelloop identifies the function as AI-assisted unless this is already obvious from the context. Users must not present AI-generated content as independently verified output and remain responsible for human review before relying on it in a business process.