1. Who we are
Loymi SRL, trading as LOYMI, provides the LOYMI business software service and operates loymi.app.
- Controller and service provider
- Loymi SRL
- Business address
- Linin 24, Tiraspol, 3300, Moldova
- Representative
- Valentin Braico
- Privacy contact
- admin@loymi.md · +37369925036
2. When LOYMI is controller or processor
LOYMI as controller
We determine why and how personal data is processed for our website, business registration, business accounts, subscription administration, product security, support and our own analytics. For this processing, Loymi SRL is the data controller.
LOYMI as processor
A business Customer determines the purposes and rules for data about its loyalty members, customers, staff, bookings, orders and communications. For that Customer Personal Data, the Customer is the controller and LOYMI processes the data on its documented instructions. The Data Processing Addendum governs this processing.
If your question concerns a loyalty program, booking, purchase, reward or message from a particular business, contact that business first. We will assist it with a valid privacy request where required.
3. Data we process
Business account and staff data
- name, business name, email, telephone number and business address;
- account role, workspace membership and assigned locations;
- authentication information, password hash, Google account identifier and session data;
- login, security, audit and account activity records;
- support requests, messages and communications with us.
Subscription and billing data
- selected plan, price, currency, trial and subscription status;
- Lemon Squeezy customer, order and subscription references;
- billing dates, payment status, refund status and customer portal links.
Payment card details are entered directly in Lemon Squeezy’s checkout. LOYMI does not receive or store the full card number or security code.
Customer Personal Data processed for a business
- names, telephone numbers, Telegram identifiers and Telegram usernames;
- loyalty membership, points, tiers, rewards and consent records;
- purchase, accrual, redemption, adjustment and refund history;
- bookings, appointments, attendance, services, staff assignments and notes entered by the business;
- orders, fulfilment choices and delivery addresses;
- messages, campaign delivery status and communication preferences;
- technical identifiers needed for authentication, fraud prevention and support.
Website and device data
- IP address, browser, device, operating system and approximate region;
- requested pages, timestamps, referral source and security events;
- analytics consent choice and, after consent, GA4 usage events.
4. Why we use personal data
| Purpose | Typical legal basis |
|---|---|
| Create and operate business accounts, provide purchased features and support | Contract and steps requested before entering a contract |
| Administer trials, subscriptions, cancellations and refunds | Contract and legal obligations |
| Secure the Service, prevent abuse, investigate failures and keep audit records | Legitimate interests in security, reliability and fraud prevention |
| Send necessary account, verification, security and service messages | Contract and legitimate interests |
| Comply with tax, accounting, court and regulatory requirements | Legal obligation |
| Measure public website usage with Google Analytics 4 | Consent |
| Process loyalty, booking, order and communication data for a Customer | The Customer’s documented instructions under the DPA |
Where legitimate interests are used, we assess the need for processing and its effect on individual rights. We do not use consent where the processing is necessary to perform the business contract or meet a legal obligation.
5. Service providers and disclosures
We disclose personal data only where needed to provide, protect and administer the Service, follow a Customer’s instructions, complete a payment, comply with law, or protect legal rights. The current providers are listed on our Subprocessors page.
Relevant categories include:
- OVHcloud for production hosting and infrastructure;
- Cloudflare for object storage and related infrastructure services;
- Resend for transactional email delivery;
- Lemon Squeezy as Merchant of Record and subscription platform;
- Google for account sign-in and consent-based analytics;
- Telegram when a Customer connects its own bot and customer-facing Mini App.
We may also disclose information to professional advisers, regulators, courts or law enforcement where legally required, and in connection with a corporate transaction subject to appropriate confidentiality and data protection safeguards. We do not sell personal data.
6. International data transfers
LOYMI is operated from Moldova and uses providers that may process data in more than one country. Where data protection law requires a transfer mechanism, we use applicable contractual safeguards, including Standard Contractual Clauses where appropriate, and assess the providers and security measures relevant to the transfer.
Business Customers can obtain the applicable processing terms through the DPA and may contact us for information about safeguards relevant to their data.
7. Data retention
We keep personal data only for as long as reasonably necessary for its purpose:
- business account data is kept while the account is active and afterwards where needed for legal claims, security, accounting or contract administration;
- Customer Personal Data is kept for the subscription and then returned or deleted according to the Customer’s instructions, the DPA, legal obligations and protected backup cycles;
- billing references and transaction records are kept for contract, accounting, fraud-prevention and legal requirements;
- security and audit records are retained according to their operational risk and investigation purpose;
- support communications are retained while the request is handled and where reasonably needed to document the resolution;
- the LOYMI analytics-consent preference is stored for 180 days; GA4 data follows the configured analytics retention controls and Google’s applicable terms.
When data is no longer needed, we delete or anonymise it. Backup copies are isolated from ordinary use and expire through the normal backup cycle unless retention is legally required.
8. Security
We use technical and organisational measures appropriate to the nature of the Service, including encrypted transport, role-based access, tenant separation, credential hashing or encryption, audit logging, rate limits, protected backups and restricted administrative access.
No system can guarantee absolute security. Customers must use strong unique credentials, protect recovery information, assign the minimum necessary roles and promptly report suspected compromise to admin@loymi.md.
9. Your rights
Depending on applicable law and our role, an individual may have rights to information, access, correction, deletion, restriction, objection, data portability and withdrawal of consent. A person may also have the right to complain to a competent data protection authority.
Send a request concerning LOYMI-controlled data to admin@loymi.md. We may need to verify the requester’s identity. For Customer Personal Data, we normally forward the request to or act on instructions from the relevant business Customer.
Individuals in Moldova may contact the National Center for Personal Data Protection at datepersonale.md. Individuals elsewhere may contact the authority competent for their location.
10. Cookies and Google Analytics 4
Necessary cookies support sign-in, security and essential preferences. They are used because the requested Service cannot operate securely without them. Public-site analytics is optional.
GA4 is not loaded until the visitor selects Allow analytics. After permission, it may receive the page path without search parameters, device and browser information, approximate region, referral source, page views and interactions with selected calls to action. We exclude private workspace, payment and customer-program paths from public-site analytics.
We do not intentionally send names, emails, telephone numbers, passwords, Telegram data, purchase contents, loyalty balances or text entered in forms to GA4. Analytics consent can be withdrawn below; withdrawing it removes LOYMI analytics cookies from the current browser.
YOUR CHOICE
Analytics settings
Allow anonymized analytics to help us improve LOYMI, or leave it only cookies necessary for the operation of the site.
The decision can be changed at any time.
11. Automated processing
LOYMI provides configurable segments, loyalty rules and message automations controlled by the Customer. LOYMI does not use account or analytics data to make solely automated decisions that produce legal or similarly significant effects for an individual. A Customer is responsible for assessing its own configured rules and communications.
12. Children
Business accounts are not intended for persons under 18. Customer loyalty programs are controlled by the relevant business. A Customer must not knowingly use LOYMI to process a child’s data without the notices, permissions and safeguards required by applicable law.
13. Changes and contact
We may update this Policy when the Service, providers or legal requirements change. The effective date and version identify the current text. Material changes will be communicated through an appropriate website, workspace or email notice.
Privacy and data protection questions can be sent to admin@loymi.md or addressed to Loymi SRL, Linin 24, Tiraspol, 3300, Moldova.