Privacy Policy

Last updated: May 2026. Lojycal is GDPR-aligned and architected for Privacy-by-Design. All data flows are processed lojycally utilizing Row-Level Security (RLS), hardware-gated MFA (AAL2), and tamper-proof WORM audit logs to ensure that your organization's data remains isolated, immutable, and under your absolute control.

1. Controller

Lojycal, Katbachstraße 24, 10965 Berlin, Germany. Contact: privacy@lojycal.com.

2. Data we process

Account data (name, email, role), workspace telemetry (assets, contracts, governance events), and security logs required to operate the IT operations console.

3. Legal basis

Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (legitimate interest in security).

4. Storage & transfers

Data is stored within the EU. Sub-processors are listed in your workspace under Admin → Regional Compliance.

5. Your rights

Access, rectification, erasure, restriction, portability, and objection per Art. 15–22 GDPR. Contact privacy@lojycal.com to exercise them.

6. Security

TLS in transit, encryption at rest, MFA, RBAC, and continuous audit logging. See the Audit Evidence Center for current posture.