Privacy Notice
Effective September 1, 2026 · Version 1.0. This notice explains in practical terms what personal data Loyal Pet processes, why it does so, and the choices and rights available to you.
1. Controller and contact
The controller is JiDo Data UG (haftungsbeschränkt), trading as Loyal Pet, Allerstraße 3, 12049 Berlin, Germany, represented by managing director Young Jin Kim. Company register: Amtsgericht Charlottenburg, HRB 221920 B.
Privacy and data-rights requests: hello@loyalpet.artGeneral contact: info@jidodata.com
We have not appointed a data protection officer. Please use the contact above for every privacy question or request.
2. Scope
This notice applies to loyalpet.art, Loyal Pet accounts, guest portrait sessions, photo uploads, AI-assisted portrait generation, orders and gift cards, waitlists, partnership bookings, support, and service emails. It does not govern a third-party site you choose to visit through an external link.
3. Data we process and where it comes from
- Account and identity data: name, email address, language, sign-in-provider identifiers, account roles, memberships, and consent history. We receive these from you and, if you choose Google sign-in, from Google.
- Guest and technical data: signed guest and session identifiers, timestamps, shortened cryptographic hashes derived from a device signature and IP prefix, request and error data, and security/audit events. These are observed when you use the service.
- Pet and portrait data: pet name, species, optional breed, gender and age category, style choices, instructions, uploaded photographs, sanitized copies, visible likeness facts, generation status, watermarked previews, final portraits, and download records. We receive the inputs from you and create the derived data and portraits for you.
- Order and payment data: order, product, amount, currency, payment or subscription status, Stripe checkout identifiers, and invoice or accounting records. Stripe receives payment-card details directly; Loyal Pet does not store complete card numbers or CVCs.
- Withdrawal data: name, order or contract reference, optional identified contract part, receipt email, declaration, request identifier, receipt time, and confirmation-delivery status. We receive these directly from the person exercising the right of withdrawal.
- Waitlist and email data: email address, audience or campaign, language, page and consent version, consent time, unsubscribe status, send identifier, and coarse first-party open or click signals. We receive signup data from you and observe the limited engagement signals when an email is fetched or a tracked Loyal Pet link is used.
- Partnership-booking data: name, email, optional phone number, organisation note, selected time and time zone, booking status, and security records. We receive these from the person making the booking.
- Support data: topic, correspondence, order context, and any attachment you choose to send. We receive these from you and add only the status and audit data needed to handle the request.
A photograph containing only a pet can still be personal data when it is linked to an identifiable customer, account, order, filename, or embedded metadata. Accepted images are decoded and re-encoded; this strips EXIF data, including embedded GPS data, before a sanitized reference is used for portrait generation. The quarantine copy is deleted after successful sanitization.
Please upload photographs only if you are entitled to use them. If an image identifies another person, we receive that person's data from you rather than from that person. You should give them this notice before uploading where reasonably possible. Do not upload identity documents, medical information, or other sensitive information. We do not use face recognition, biometric identification, or sensitive-trait inference.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide requested website, guest-session, account, family and business features | Art. 6(1)(b) GDPR; Art. 6(1)(f) for service integrity and access control |
| Sanitize uploads, build the pet reference, generate, refine and deliver portraits | Art. 6(1)(b) GDPR |
| Create orders, take payment, deliver purchases, administer subscriptions and handle refunds | Art. 6(1)(b) GDPR; Art. 6(1)(c) for tax and accounting duties |
| Receive, confirm and process contract withdrawals | Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR for our duties under German consumer law |
| Answer support requests and manage partnership bookings | Art. 6(1)(b) for contractual or pre-contractual requests; otherwise Art. 6(1)(f), our interest in answering enquiries |
| Send waitlist, research and launch emails | Your consent, Art. 6(1)(a) GDPR; you may withdraw at any time |
| Record first-party email open/click signals for consented campaigns | Your consent, Art. 6(1)(a) GDPR and, where applicable, section 25(1) TDDDG |
| Keep an unsubscribe record so that we do not contact you again | Art. 6(1)(f) GDPR, our and your interest in reliably honouring the opt-out |
| Prevent abuse and fraud, secure the service, investigate faults, and establish or defend legal claims | Art. 6(1)(f) GDPR, our interest in a reliable and secure service and in protecting users |
| Store or read optional analytics information on your device | Your consent under section 25(1) TDDDG and Art. 6(1)(a) GDPR |
Where we rely on legitimate interests, we minimise the data, restrict access, and balance those interests against your rights. You may object as described in section 11. We do not use consent to justify processing that is necessary to fulfil your order.
5. AI-assisted portrait generation
Loyal Pet sends sanitized reference images, portrait instructions, and relevant visible pet characteristics to the Google Gemini API. The API returns a generated image and technical response data. We use inline API requests; we do not use Google's File API, search grounding, model tuning, or your uploads to train or fine-tune our own model. Images rejected before sanitization are not sent to Gemini.
For Gemini API use made available in the EEA, Google's paid-service data terms apply. Under those terms, Google does not use prompts, files, or responses to improve its products, but may log them for a limited period to detect prohibited use and may process them in countries where Google or its agents operate. See theGemini API terms andretention explanation.
AI output may be inaccurate or unexpected. The service uses automated safety checks and may route a problem to authorised support staff. This processing creates artwork; it is not used to make a decision that has legal or similarly significant effects on you.
6. Who receives data
- Authorised Loyal Pet staff and contractors, only where their work requires access, such as support, security, or accounting.
- Self-hosted service components, including identity, application database, object storage, scanning, generation, delivery, and audit services operated under Loyal Pet's control.
- Google, for the Gemini API; and, only when you use the relevant feature, Google sign-in, Google Calendar, email invitations, and video-meeting links. Booking notes are not sent to Google Calendar.
- Stripe, for checkout, payment, subscription, fraud-prevention, and payment compliance. Stripe acts as a processor for some services and as an independent controller for purposes it determines under financial law. See Stripe's privacy policy.
- Professional advisers and public authorities, such as tax advisers, counsel, courts, regulators, or law-enforcement bodies, where necessary and legally permitted.
We do not sell personal data. Customer portraits are private to the account, guest, gift recipient, or invited account members with access. We do not place a customer portrait in a public gallery or use it in marketing without a separate, explicit agreement.
7. International transfers
Core application data is stored in systems operated under Loyal Pet's control. Google and Stripe may nevertheless process data outside the EEA. Where an EEA adequacy decision does not apply, we use the European Commission's Standard Contractual Clauses and the provider's data-processing terms, plus supplementary safeguards where required. A copy of the relevant safeguards can be requested at the privacy contact above; commercial details may be redacted.
8. Retention and deletion
- Uploads and portraits: accepted quarantine copies are deleted after sanitization. Sanitized references, derived pet facts, previews, and final portraits remain while needed to provide the account, order, download, support, or sharing feature. After a valid deletion request they are removed or irreversibly de-linked from active systems unless a legal retention duty or claim requires a restricted copy.
- Failed or rejected uploads: kept only for the short diagnostic or security review needed to resolve the failure, then deleted.
- Account and guest data: kept while the account or requested guest flow is active. A guest browser cookie expires after 30 days. Account-deletion requests enter a 30-day review window so subscriptions, shared access, payments, and retention duties can be handled safely.
- Privacy exports: export access expires after 7 days.
- Waitlists: kept until you withdraw, the relevant campaign purpose ends, or the record is no longer needed. A minimal suppression record is kept for as long as needed to honour an unsubscribe.
- Email engagement signals: deleted after 90 days.
- Partnership bookings: free-text notes are kept for 30 days after the appointment, booking and contact records for 24 months, and scheduler security logs for 12 months.
- Support: ordinarily kept for up to 24 months after a ticket closes, unless the record forms part of a transaction, dispute, or legal claim.
- Withdrawal records: ordinarily kept until the end of the third calendar year after receipt so that the declaration, confirmation and resulting reimbursement can be demonstrated; a longer statutory transaction or legal-claim period may apply.
- Commercial and tax records: booking vouchers, including invoices where they are booking vouchers, are kept for 8 years; books, accounting records, inventories and annual accounts for 10 years; commercial correspondence and other tax-relevant documents for 6 years. The period starts at the end of the relevant calendar year under section 147 AO and section 257 HGB.
- Security and legal claims: kept only as long as needed for investigation, defence, or the applicable limitation period.
Deletion from active systems does not necessarily remove a protected backup immediately. Backup copies remain unavailable for ordinary use and disappear through the regular overwrite cycle. Data retained by law is restricted to that purpose. We also instruct processors to delete data where the law and our contracts require it.
9. Cookies and similar technologies
| Name or category | Purpose | Maximum life | Basis |
|---|---|---|---|
np_session | Signed account session and access control | 14 days | Strictly necessary, section 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR |
np_guest | Continue a requested guest upload or checkout | 30 days | Strictly necessary, section 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR |
np_oidc and sign-in cookies | Secure the login redirect and identity session | 10 minutes for the redirect state; identity-session cookies follow the login session | Strictly necessary, section 25(2) no. 2 TDDDG |
np_locale | Remember the language you selected | 1 year | Strictly necessary for the expressly requested preference, section 25(2) no. 2 TDDDG |
np_analytics_consent | Remember whether analytics was allowed or refused and prevent repeated prompts | 1 year | Your choice; Art. 6(1)(c) and (f) GDPR for proof and respect of that choice |
The current application does not load advertising cookies or a third-party analytics provider. Analytics remains blocked unless you actively tick the optional box and accept it; the box is off by default. You can change or withdraw that choice at any time byreviewing the privacy choices. Refusing or withdrawing analytics has no effect on your order or account. Necessary cookies cannot be disabled through the consent control because the requested service would not work.
10. What is required
An email address and sign-in credentials are required for an account. The checkout needs the product, order and payment information required to complete a purchase. Portrait generation needs at least one usable reference image, a pet name and species, and a style choice; breed, gender, age category, free-text notes, phone number, marketing consent, and analytics consent are optional unless a form clearly explains why a field is needed. If required data is not provided, the relevant account, order, portrait, or booking cannot be completed, but optional refusals do not reduce the paid service.
11. Your rights
Subject to the GDPR's conditions and exceptions, you may request access, rectification, erasure, restriction, data portability, and information about recipients. If data is corrected, erased, or restricted, you may ask us to notify recipients unless that is impossible or disproportionate. You may object to processing based on legitimate interests; an objection to direct marketing is always effective. You may withdraw consent at any time for the future without affecting earlier lawful processing.
Use Account → Settings for the available export and deletion controls, use the unsubscribe link in a marketing email, or emailhello@loyalpet.art. We normally verify a signed-in request through the account. For an email request, we may reply to the address already associated with the data or ask for limited additional information if reasonably necessary. We do not routinely require a copy of an identity document.
We answer without undue delay and normally within one month. For a complex request, the GDPR permits an extension of up to two further months; if so, we will explain this within the first month. Rights may be limited where another person's rights or a statutory retention duty applies.
12. Complaints
You may complain to any competent data-protection authority, particularly in the EU country of your habitual residence, workplace, or the alleged infringement. The authority for a Berlin-based controller is theBerliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany, telephone +49 30 13889-0,mailbox@datenschutz-berlin.de.
13. Security and incidents
We use measures appropriate to the risk, including TLS, signed HTTP-only account and guest cookies, role- and account-scoped access controls, private data tables, upload quarantine and image validation, EXIF stripping, access-restricted object storage, hashed network indicators, short-lived delivery grants, audit records, and restricted support/admin access. No internet service can promise absolute security. If a personal-data breach triggers GDPR notification duties, we will notify the competent authority and affected people within the legally required periods.
14. Children
Loyal Pet is not directed to children under 16. A parent or guardian should place an order or provide any consent for a younger person. Contact us if you believe a child supplied data without appropriate authority.
15. Changes and language
We will update the date and version when this notice changes. Material changes will be shown prominently in the service and, where appropriate, sent to the account email before they take effect. Earlier versions are available on request. The German text is the controlling version for the Germany-based service; this English version is provided for accessibility.