Effective date: 16 July 2026 · Version 2
This Privacy Policy explains how LOFT PRESS LTD (“LoftPress”, “we”), a company registered in England and Wales under number 16676296 with registered office at Unit 501 Leroy House, 434-436 Essex Road, London, England, N1 3FY, processes personal data when you use the LoftPress API platform at loftpress.shop (the “Service”). LOFT PRESS LTD is the controller of that personal data.
This notice is written for people protected by the UK GDPR and the Data Protection Act 2018, by the EU GDPR where applicable, and by the Turkish Personal Data Protection Law (KVKK) for users in Turkey.
Contact for privacy matters: support@loftpress.shop.
1. What personal data we process
- Account and contact data: name, email, chosen language, account role, password hash (we never store your password in the clear).
- Authentication and security: session cookies, JWTs, IP address of login, user-agent, timestamps, brute-force protection state.
- Billing metadata from Creem: order ID, amount, currency, VAT/tax lines Creem calculated for the transaction, invoice URL, subscription status, refund/dispute events. We do not receive or store full card numbers. Card data stays with Creem and its processors.
- API usage: API-key identifiers (keys themselves are stored hashed), endpoint called, timestamp, HTTP status, response latency, credits consumed, request IP, request ID.
- Support communications: your messages to support@loftpress.shop and any attachments you send.
- Consent evidence: legal document slug, version, content hash, language, IP, user-agent and timestamp for every consent you give.
- Cookies and analytics: strictly-necessary cookies always; optional analytics only after you opt in through the cookie banner. See § 8.
- Marketing: only if you actively opt in.
2. Where the data comes from
Directly from you (registration, dashboard actions, forms), automatically from your use of the Service (usage logs, security events), and from Creem for transactions you complete at checkout.
3. Why we process it (purposes) and legal bases
| Purpose | UK/EU GDPR basis | KVKK basis |
|---|---|---|
| Provide the Service, run your subscription and API keys | Contract | Contract necessity |
| Bill and issue receipts (via Creem) | Contract & legal obligation | Contract & legal obligation |
| Keep records for tax, accounting and audit | Legal obligation | Legal obligation |
| Prevent fraud, protect the Service, investigate abuse | Legitimate interests | Legitimate interests |
| Provide support and handle complaints | Contract & legitimate interests | Contract & legitimate interests |
| Optional analytics cookies | Consent | Explicit consent |
| Marketing emails | Consent | Explicit consent |
| Legal claims and defence | Legitimate interests / legal obligation | Legal obligation |
Where we rely on legitimate interests we balance them against your rights and describe the interest clearly.
4. Who we share it with (processors and recipients)
- Creem (Armitage Labs OÜ) – payments, invoicing, tax compliance, chargebacks and refunds. Creem is a separate controller for the payment transaction.
- Hosting, database and infrastructure providers we use to run the Service.
- Email delivery provider for transactional messages.
- Analytics providers — only if you consent to analytics cookies.
- Professional advisers (accountants, lawyers) when required by law or to defend legal claims.
- Public authorities where we are legally obliged to disclose.
We do not sell personal data. We do not name vendors that are not actually configured. Where a vendor changes, we update this list.
5. International transfers
The Service is delivered from the United Kingdom. Depending on the provider, data may be processed outside your country, including outside the UK, EEA and Turkey. Where transfers happen, we rely on lawful transfer mechanisms:
- UK: adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
- EEA: European Commission adequacy decisions or Standard Contractual Clauses (SCCs) with supplementary measures where appropriate.
- Turkey: transfer mechanisms permitted under the KVKK, including explicit consent where required and, once formally in force, the KVKK cross-border transfer regime and any KVKK-approved undertakings.
6. How long we keep it (retention)
- Account and contract data: while your account is active and for 6 years after closure, to comply with UK tax and accounting record-keeping rules and defend legal claims.
- Invoices and financial records: 6 years (UK statutory retention).
- API keys: hashed values are deleted when the key is revoked or the account is closed.
- API and security logs: normally 12 months, longer if reasonably needed for an active incident.
- Support tickets: 3 years from closure of the ticket.
- Consent evidence: for as long as we rely on the consent plus the applicable limitation period.
- Marketing preferences: until you withdraw.
- Backups: rolling short-term retention on a strict schedule; deleted data is overwritten on the next cycle.
Where the admin configures a shorter retention for logs, the shorter setting applies.
7. Your rights
Subject to legal limits and time bars, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data deleted where the legal basis for keeping it no longer applies;
- restrict or object to processing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time (this does not affect prior lawful processing).
To exercise a right, write to support@loftpress.shop with enough information to verify your identity. We respond within the legal time limits.
UK / EEA complaints. You can complain to the UK Information Commissioner’s Office (ICO) or your local EU supervisory authority.
Türkiye / KVKK. KVKK Madde 11 kapsamındaki haklarınızı, Veri Sorumlusuna Başvuru Usul ve Esasları hakkında Tebliğ’e uygun şekilde support@loftpress.shop adresi üzerinden kullanabilirsiniz. Yanıtımız yasal süreler içinde verilir; ayrıca KVKK’ya şikâyet hakkınız saklıdır.
8. Cookies and analytics
We use strictly necessary cookies to run the site (session, CSRF, language, consent banner state). These do not require consent. Optional analytics cookies run only after you opt in through the cookie banner. You can change your choice at any time from the Cookie Preferences link in the footer.
9. Automated decision-making
We do not use solely automated decisions that produce legal or similarly significant effects on you. Rate-limiting and fraud-scoring are decision-support tools reviewed by humans before any account is suspended.
10. Security
We hash API keys and passwords, encrypt admin-managed secrets at rest, isolate environments, enforce role-based access, and maintain audit logs for security-sensitive actions. No online service is perfectly secure; we cannot guarantee absolute security but we work continuously to protect your data.
11. Children
The Service is not directed to individuals under 18 and we do not knowingly collect personal data from them. If you believe a child has provided personal data, contact us and we will delete it.
12. Creem as a separate controller
Creem processes payment data as a separate controller under its own privacy notice available at creem.io/legal/privacy. LOFT PRESS LTD does not control Creem’s processing.
13. Changes to this policy
We may update this policy. Material changes are notified by email and in-app and shown on this page with a new effective date and version number. Older versions are archived and available on request.
14. Contact
- LOFT PRESS LTD, Unit 501 Leroy House, 434-436 Essex Road, London, England, N1 3FY
- Privacy contact: support@loftpress.shop
- Response window: within 3 business days during Monday to Friday, 09:00–17:00 UK time