Privacy Policy
Version 2026-07-09 · Last updated July 9, 2026
This privacy policy explains how Labelloop processes personal data when you create an account, join or create an organization, use the platform, communicate with partners, upload files, manage transactions, or contact support.
Labelloop is designed for business users in Germany and other European markets. Personal data is processed in accordance with the GDPR and applicable German data protection law.
1. Controller identity and contact
WhiteNode Holding GmbH, Volmerswerther Str. 32, 40221 Düsseldorf, Germany, is the controller for the personal data processing described in this privacy policy, unless a specific workflow expressly states otherwise.
For privacy questions or to exercise your rights, you can contact us at info@labelloop.app. If a dedicated data protection officer is appointed or required for a specific processing arrangement, the applicable contact details will be communicated through the service or on request.
2. Controller, processor, and counterparty roles
Labelloop normally acts as controller for account administration, authentication, platform security, legal acceptance, billing administration, support, product operation, and its own compliance documentation.
For business content that an organization uploads, imports, sends, or manages for its own commercial relationship, the organization may remain an independent controller or Labelloop may process the content on the organization's behalf, depending on the agreed contractual setup and the specific workflow.
Connected brands, retailers, showrooms, agencies, payment providers, and other counterparties may act as independent controllers for their own use of information they receive through a shared workflow. Where a data processing agreement or other privacy arrangement is required for a specific customer setup, it must be agreed separately before production use.
3. Categories of personal data
Depending on your role and usage, Labelloop may process the following categories of personal data:
- account and identity data such as name, email address, login identifiers, role, and organization assignment
- organization and profile data such as company details, business contacts, addresses, VAT-related information, showroom and brand profile content
- placeholder organization data such as placeholder customer or placeholder showroom names, contact details, addresses, notes, creator information, merge history, and replacement organization references
- operational data such as appointments, orders, reorders, preorders, invoices, credit notes, transactions, requests, claims, and delivery-related records
- communication data such as messages, support content, comments, reactions, mentions, invitation emails, and attached files
- uploaded content and metadata such as images, screenshots, PDFs, invoice documents, claim documents, brand assets, filenames, upload references, and file types
- import, parsing, and translation data such as extracted document text, parsed fields, matching candidates, confidence signals, warnings, review decisions, source document references, translation cache entries, and correction history where such features are enabled
- email-import data where mailbox import is enabled, such as sender and recipient information, message metadata, attachments, provider message identifiers, processing labels, review status, and error state
- payment and subscription data where billing or payment functions are used, including payment provider identifiers, checkout references, payment status, mandate or subscription references, and invoice payment history
- technical usage and session data such as browser metadata, IP-derived security signals, authentication tokens, essential cookies, device and request logs, and platform activity timestamps
- security and audit data such as session events, rate-limiting signals, approval records, legal acceptance records, permission changes, impersonation or admin support events, and change history
4. Sources of personal data
We collect personal data directly from you when you register, sign in, complete profiles, upload files, send messages, create records, or contact support.
We may also receive data from your organization administrators, connected counterparties, users who create placeholder organizations or invitations, authentication providers, email and mailbox providers, payment providers, import sources, and technical systems that record session, security, and audit events required for operating the service.
5. Purposes of processing
We process personal data to provide and secure the platform, connect users to the correct organizations, enable collaboration and transaction workflows, maintain records, communicate service-related information, send invitations and operational notifications, process payments where applicable, and comply with legal obligations.
Where placeholder organizations are used, we process the related data to let a brand or showroom work with a provisional customer or showroom record and, where selected by an authorized user, to merge or reassign related business records to the real organization that later joins or is connected.
Where import, mailbox, parsing, AI-assisted analysis, OCR, or translation features are enabled, we process the relevant documents, extracted content, and metadata to create reviewable suggestions, translations, matching candidates, warnings, and audit trails for manual confirmation.
Where the AI analysis assistant (copilot) is enabled, we process the business records already visible to your role (such as invoice, order, delivery, claim, transaction, and appointment summaries) together with your questions to generate answers and explanations within the platform.
We may also process limited data to prevent abuse, investigate incidents, improve reliability, maintain internal auditability, measure feature health, and document acceptance of legal information.
6. Legal bases under Article 6 GDPR
Where Labelloop is used as a contractual business service, the main legal basis is Article 6(1)(b) GDPR where processing is necessary to perform or prepare the contractual service relationship.
We may also rely on Article 6(1)(c) GDPR for legal obligations, including accounting, tax, and compliance retention duties, and on Article 6(1)(f) GDPR for legitimate interests such as service security, fraud prevention, system stability, access control, internal documentation, and enforcement of platform rules.
For account and workflow communications, import review, support, auditability, and platform improvement, the legal basis may include Article 6(1)(b) GDPR or Article 6(1)(f) GDPR depending on the context. Where data is processed to meet statutory accounting, tax, commercial, or security obligations, Article 6(1)(c) GDPR may apply.
Where a specific processing activity legally requires consent, we will request it separately. Your acknowledgement of this privacy policy does not replace separate consent where consent is the correct legal basis.
7. Recipients and processors
We may use specialized service providers to operate the platform and related functions. Depending on the active feature set, this may include hosting, authentication, email delivery, payments, database hosting, file handling, and AI-assisted processing.
Connected business counterparties may receive personal data where this is necessary for the collaboration workflow they participate in. Depending on the context, those counterparties may act as separate controllers for their own use of the information they receive.
- your organization, its authorized administrators, and its approved members according to role-based permissions
- connected counterparties and their authorized users where this is necessary for the business workflow you initiate or participate in
- hosting and application infrastructure providers: Vercel (application hosting and privacy-preserving web analytics; server functions run in the Frankfurt, Germany region), Neon (managed PostgreSQL database hosted in an EU region, which also stores uploaded files and documents), and Upstash (managed rate-limiting infrastructure in the Frankfurt, Germany region)
- authentication providers such as Auth0
- email and notification providers such as Brevo, including for invitations and transactional platform emails
- mailbox and email import providers such as Google/Gmail where an import mailbox or customer-authorized mailbox workflow is enabled
- payment providers such as Mollie where payment features are enabled, including where a brand connects its own Mollie account for invoice payments
- AI service providers, currently OpenAI (contracting entity for EEA customers: OpenAI Ireland Ltd), where AI features are enabled by configuration: document import analysis (document files, page images, or extracted document text, including related email text for mailbox imports and limited business context such as partner names and order references), the AI analysis assistant / copilot (business records visible to your role plus your questions), and content translation (message and comment text); see section 13 for the applicable safeguards
- analytics providers: Vercel (privacy-preserving web analytics as part of hosting) and PostHog where product analytics / opt-in session replay is enabled by configuration
- professional advisors, authorities, courts, or counterparties where disclosure is legally required or necessary to establish, exercise, or defend legal claims
8. International data transfers
Core application data is stored and processed with managed infrastructure providers in the European Union: server functions run in the Frankfurt, Germany region (Vercel), the primary database is hosted in an EU region (Neon), and rate-limiting infrastructure runs in the Frankfurt, Germany region (Upstash).
Some service providers are headquartered in the United States or may process personal data in, or with access from, countries outside the EEA. This applies in particular to OpenAI (AI features), Auth0 (authentication), Google (mailbox import, where enabled), Vercel (infrastructure), and PostHog (product analytics, where enabled). For such transfers we rely on an appropriate transfer mechanism under Chapter V GDPR, in particular EU Standard Contractual Clauses agreed in the respective data processing agreements and, where the provider is certified, the EU-U.S. Data Privacy Framework.
Where AI-assisted, mailbox import, payment, authentication, or third-party infrastructure features are enabled, transfer scope is limited to what is necessary for the relevant function. Information about the applicable safeguard for a specific provider can be requested from us where legally required.
9. Retention
We retain personal data only for as long as necessary for the service relationship, the relevant workflow, legitimate business documentation, and statutory retention obligations.
When a placeholder organization is merged into a real organization, Labelloop may retain merge metadata and audit history where necessary to preserve business records, explain record history, and prevent accidental loss or unauthorized reassignment.
Import suggestions, extracted document text, mailbox-import records, correction history, and review decisions may be retained for as long as needed to complete the review workflow, prevent duplicate processing, preserve provenance, and support later auditability of records created from imports.
Content submitted to OpenAI for AI features is transmitted with storage disabled, is not used to train OpenAI's models, and is retained by OpenAI at most temporarily for abuse monitoring (currently up to 30 days) before deletion, in accordance with OpenAI's API data usage commitments.
Commercial and tax-relevant records may be retained for the periods required under applicable law. Security, audit, legal acceptance, and support records may also be retained where necessary to investigate incidents, document permissions, or protect the platform.
10. Required data and consequences of non-provision
Some personal data is required to create and secure your account, assign you to the correct organization, and operate the core B2B workflows of the platform.
If required data is not provided or becomes inaccurate, we may be unable to create an account, connect you to an organization, process transactions, send operational notices, or maintain secure access to the service.
11. Your GDPR rights
Subject to the legal requirements, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection.
You also have the right to lodge a complaint with a competent supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. For our German operating entity, this may include the supervisory authority in North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2-4, 40213 Düsseldorf, poststelle@ldi.nrw.de).
To exercise your rights, please contact info@labelloop.app. We may request reasonable information to verify your identity and your connection to the relevant organization before processing a request.
12. Security, cookies, and platform communications
We use technical and organizational measures appropriate to the risk, including authenticated access controls, session protection, rate limiting, logging, and role-based permission checks.
Labelloop uses essential session and security cookies or similar technical storage where required to keep you signed in, protect sessions, and maintain secure platform operation. These mechanisms are not used as a substitute for any separate cookie consent that may become necessary for non-essential technologies in the future.
Labelloop may send operational or account-related communications that are necessary for account security, onboarding, access management, billing, import review, support, and core workflow notifications.
Usage analytics: Labelloop uses Vercel Web Analytics (privacy-preserving, cookie-free aggregate page metrics) and a first-party usage log (page views and interaction events within the dashboard, stored on our own infrastructure) to understand product usage, improve workflows, and diagnose issues. The first-party usage log is linked to your account; you can object at any time via the support contact above, and a do-not-track browser setting is honored for third-party analytics.
Product analytics / session replay (PostHog): where enabled, Labelloop uses PostHog for product analytics. Session replay is strictly opt-in: it stays disabled unless you have given explicit consent, and recordings mask all text and input content by default.
If further non-essential technologies are introduced or enabled for external users, the related information, masking settings, legal basis, and consent or objection mechanism will be provided separately where required.
13. AI-assisted features, sensitive data, and automated processing
Labelloop uses OpenAI as an AI service provider for three configurable features: (i) document import analysis, where uploaded or mail-imported business documents (as document files, page images, or extracted text, together with related email text and limited business context such as partner names and order references) are analyzed to create import suggestions; (ii) the AI analysis assistant (copilot), where business records already visible to your role are processed together with your questions to generate answers; and (iii) content translation, where message and comment text is translated.
For all AI features, requests to OpenAI are transmitted with storage disabled (the provider is instructed not to persist request content), the content is not used to train OpenAI's models, and OpenAI retains request data at most temporarily for abuse monitoring (currently up to 30 days). The processing takes place on the basis of a data processing agreement with OpenAI that includes EU Standard Contractual Clauses; the contracting entity for EEA customers is OpenAI Ireland Ltd.
Labelloop is not intended for the routine storage of special categories of personal data under Article 9 GDPR or comparable highly sensitive data unless this is strictly necessary and lawfully supported for a specific workflow. Users should avoid uploading such data unless they are clearly authorized and legally permitted to do so.
Labelloop does not use fully automated decision-making with legal or similarly significant effects on users within the meaning of Article 22 GDPR based on the information currently available for the platform.
AI-assisted import analysis, OCR, matching, copilot, and translation features are intended to create reviewable suggestions, answers, or language support, not final automated decisions with legal or similarly significant effects. Manually uploaded documents always require review and confirmation before business records are created. For the mailbox import, documents from senders approved by the organization may be imported automatically where the analysis meets strict confidence requirements; such records remain visible, editable, and reversible by authorized users and do not produce legal or similarly significant effects on individuals within the meaning of Article 22 GDPR. If this changes for a specific workflow, the relevant information will be provided separately.