Skip to content
LoglunedebugContact sales

Privacy Notice

Effective date: 2026-07-17

Navigation

Part Clauses Purpose
A. Controller and processing map 1–4 identify the controller and processor roles, data, sources, purposes, and legal bases
B. Disclosure, transfers, retention, and security 5–9 explain payment processing, recipients, advertising position, transfers, retention, and safeguards
C. Rights and special contexts 10–13 state rights, US disclosures, legal requests, and controller contacts
D. Providers and regional procedures 14–21 identify providers and explain EEA/UK, US-state, deletion, incident, corrections, complaints, Japan APPI, and Brazil LGPD procedures

Part A — Controller and processing map

1. Scope, controller, and processor roles

This Privacy Notice explains how Loglune collects, uses, discloses, retains, and protects personal data when a business customer and its authorized users use the Service. Loglune is a business tool and is not directed to children. If we learn that a child provided personal data, we will take reasonable steps to delete it. Contact support@loglune.com with a privacy question. Loglune is the controller for the account, authentication, billing, support, usage, and security data described in this Notice. Contact: support@loglune.com. Privacy request form: /privacy#privacy-request. Where the flag definitions, configuration, and targeting rules you create and manage in Loglune contain personal data of your end users (for example, user identifiers or segment keys embedded in targeting rules), you are the controller for that data and Loglune acts as your processor, handling it only to operate the platform, retain the change history, and reconstruct a past version to deliver a reproduction on your instructions. Stripe acts as an independent controller for the payment data it processes, and Cloudflare processes authentication data on our instructions through Cloudflare Access, with the identity provider you sign in through acting as an independent controller for its own authentication.

2. Personal data we collect

Category Examples Role
Account data business email, authorized-user name, display name, locale, timezone, workspace controller
Flag and configuration data feature-flag and configuration definitions, targeting rules, segment keys, user identifiers processor for the customer
Flag change history and version metadata change events, author reference, version identifier, change time, customer reference controller / processor
Subscription and seat data plan, seat count, status, renewal date, reproduction usage, Stripe customer and subscription identifiers controller
Device and network data IP address, browser, device, request, security, and error information controller
Usage data pages or features used, referral and campaign information where enabled controller
Support data messages, attachments, and content you choose to share with support controller
Rights and compliance data request, identity-verification result, response, appeal, incident, and legal-request records controller

Your flag definitions and targeting rules may contain personal data of your end users. We do not ask you to include personal data in them and do not analyze their contents to infer traits about any person; we process them only to operate the platform and reconstruct a past version to deliver a reproduction on your instructions. Account and authentication data are necessary to create and operate a Loglune account. If you do not provide them, we cannot create or maintain your account. Payment and billing data are required to activate and renew a paid subscription. Flag and configuration data, optional support attachments, optional analytics choices, and optional marketing preferences are not statutory requirements, although declining data needed for a feature may prevent that feature from working.

3. Sources

We receive personal data:

  • directly from you and your authorized users;
  • from your browser or device;
  • from Cloudflare Access and the identity provider you sign in through when you authenticate;
  • from the flag definitions, configuration, and targeting rules you create and manage directly in Loglune;
  • from Stripe for subscription and transaction status;
  • from security, hosting, monitoring, and analytics providers; and
  • from support communications and lawful requests.

We limit collection to data reasonably relevant to the stated purposes. We do not obtain ownership of personal data, use your flag or configuration contents to create advertising profiles, or intentionally collect data from data brokers. If data is later needed for a materially incompatible purpose, we provide additional notice and obtain consent where required before that use.

4. Why we use personal data

Purpose Data Primary legal basis where GDPR or UK GDPR applies
Create and secure an account and its seats account, device, security data performance of a contract
Store, version, evaluate, reproduce, and export flag definitions and configuration flag and configuration data, change history performance of a contract; processor acting on the customer’s instructions
Provide and manage the subscription and metering account, subscription and seat data performance of a contract
Prevent abuse and investigate errors device, network, security, error data legitimate interests in operating a secure service
Provide support account, support data contract and legitimate interests
Send account, security, legal, and service communications account, subscription, security data contract, legal obligation, and legitimate interests
Measure reliability and improve non-content features usage, error, device data legitimate interests or consent where required
Operate optional analytics usage data consent where required; otherwise legitimate interests where permitted
Send optional marketing email and preference consent or another locally permitted basis
Meet legal obligations and defend claims relevant account, transaction, rights, and incident data legal obligation and legitimate interests

We do not use your flag or configuration contents for advertising, general-purpose AI training, or decisions that produce legal or similarly significant effects on any person. You may stop optional marketing at any time through the unsubscribe link in the message or support@loglune.com. Opting out of marketing does not stop contractual, billing, security, account, legal, or service communications needed to operate Loglune. Where we rely on legitimate interests, the interests are operating and securing the Service, preventing fraud, supporting customers, understanding aggregate performance, establishing or defending legal claims, and improving non-content functionality. We consider necessity, reasonable expectations, minimization, opt-outs, and potential effects on people. You may object, and we will stop unless we demonstrate compelling grounds or need the processing for legal claims.

Part B — Disclosure, transfers, retention, and security

5. Disclosure, payment data, and advertising position

Stripe processes checkout and transaction information as our payment processor and as an independent controller for its own transaction, fraud, and compliance purposes. Loglune does not receive full card numbers. We receive only the information needed to provide the subscription, such as customer, subscription, status, renewal, refund, and transaction references. Stripe may use device, identity, transaction, payment-method, fraud, dispute, tax-location, and support information for its independent purposes and may retain payment and tax records to meet its legal obligations. Its privacy notice governs that independent processing.

We disclose personal data only:

  • to processors that operate the Service on our instructions;
  • to independent providers such as Stripe;
  • when you direct us to disclose it;
  • when reasonably necessary to respond to valid legal process, protect rights, or address a security threat; or
  • to a successor in a merger, reorganization, or transfer of the Service, subject to this Notice and applicable law.

The Third-party Services List identifies the main providers and their roles. Processors may access data only to provide contracted functions, protect the Service, comply with documented instructions and law, or perform another disclosed purpose. Independent controllers determine their own purposes and legal bases. Loglune does not sell personal data. Loglune does not share personal data for cross-context behavioral advertising and does not use personal data for targeted advertising. Loglune does not use personal data to make solely automated decisions that produce legal or similarly significant effects. Because we do not sell or share personal data for targeted advertising, an opt-out signal such as Global Privacy Control or Do Not Track does not change those practices. We will treat a legally valid signal as an opt-out if those practices ever change. Stripe, Cloudflare, the identity provider you sign in through, and other providers may collect data when you interact directly with their services under their own notices.

6. International transfers, retention, and deletion

Our providers may process data outside your country. Where EU, EEA, or UK personal data is transferred to a country without an applicable adequacy decision, we use a legally recognized transfer mechanism, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Agreement or Addendum, when confirmed for the relevant provider and transfer. You may contact support@loglune.com for information about the transfer mechanism applicable to your data. Transfer safeguards do not guarantee that another country’s law is identical to your local law. We assess the provider, data, destination, government-access risk, contractual commitments, and supplementary measures. We suspend or change a transfer when required by applicable law and technically feasible.

Data Retention
Account data while the account is active; deletion from active systems within 30 days after a valid account-deletion request
Flag definitions, change history, and metadata retained under the customer agreement and the customer’s instructions; deleted from active systems within 30 days after a valid deletion request
Backups removed or rendered unavailable through the normal backup cycle, generally within 30 days; deletion records prevent intentional restoration
Subscription and seat data while needed to provide the subscription and resolve transaction issues
Stripe records retained independently by Stripe under its legal obligations and policies
Cloudflare operational logs generally 7 days in the primary logging service; longer security archives follow the configured retention schedule
Google Analytics data user-level and event-level data for 2 months without resetting user-data expiry on new activity; this control does not affect standard aggregated reports
Support records only as long as necessary to resolve the request and establish or defend legal claims
Rights and incident records for the applicable legal limitation, audit, and incident-response period

We may retain a limited record for fraud prevention, legal claims, or a legal hold. When an exception applies, we restrict the retained data to the relevant purpose and period. Account deletion and subscription cancellation are separate. Deleting an account triggers cancellation efforts, but a billing cancellation failure does not stop deletion of Loglune-controlled account data. Retention periods are determined by purpose, account status, the customer agreement, backup cycle, dispute and limitation periods, and legal obligations. Deletion from active systems does not require immediate physical erasure from every backup fragment; backups expire through the stated cycle and are subject to deletion-suppression controls. We may retain a minimal suppression record to prevent accidental restoration or re-creation.

7. Security

We use measures designed to protect personal data, including encrypted transport, encryption at rest through our infrastructure providers, access controls, authentication, secret management, private per-customer storage, monitoring, and backups. Flag definitions, configuration, and their change history are stored as private objects separated by customer, with metadata held in a separate database. Access is limited to the authorized delivery of an evaluation or reproduction to the customer that owns it; cross-customer access is not authorized. No service can guarantee absolute security. If a personal-data breach occurs, we assess the affected data, risk, people, and jurisdictions and make notifications required by applicable law. Security also depends on you. Protect your account credentials, your authorized users, active sessions, and exported files; use supported software; and notify us promptly of suspected compromise. Do not send an access token, full card number, or unnecessary flag or configuration data to support. Support communications are processed as plaintext support data for the request and should be limited to what is necessary. We use cookies and similar technologies for authentication, language, security, checkout, and user preferences. The Cookie Notice describes the technologies, purposes, providers, and controls. Non-essential storage or access technologies are not activated before consent where consent is required.

Part C — Rights and special contexts

8. Your privacy rights

Depending on where you live, you may have the right to:

  • confirm whether we process your personal data;
  • access and obtain a copy of it;
  • correct inaccurate data;
  • delete data;
  • restrict or object to processing;
  • receive portable data;
  • withdraw consent;
  • opt out of sale, sharing, targeted advertising, or qualifying profiling;
  • use an authorized agent;
  • appeal a refusal; and
  • complain to a data-protection authority or state attorney general.

Where Loglune acts as a processor for personal data contained in a customer’s flag definitions or targeting rules, a request from an end user is directed to the customer that controls that data; Loglune assists the customer as required by law and the customer agreement. Submit a request about Loglune-controlled data through /privacy#privacy-request or email support@loglune.com. We may verify a request using the existing account session, email, or other information proportionate to the risk. We do not require an access token or credential export as identity evidence. For EU, EEA, and UK requests, we normally respond within one month, subject to a lawful extension. For applicable US state requests, we normally respond within 45 days, subject to the relevant law. We will explain any denial and available appeal. Rights may be limited by lawful exceptions, including inability to identify the requester, another person’s rights, legal privilege, security, fraud prevention, legal obligations, or establishment and defense of claims. We disclose the applicable reason and challenge route when permitted. Requests are normally free. Where permitted, we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive, repetitive, or abusive, after considering the circumstances and explaining the decision. Authorized agents must provide legally sufficient authority, and we may verify the requester directly where permitted. Withdrawing consent does not affect processing already lawfully completed. Objection to or restriction of one purpose does not require deletion of data still needed for a different lawful purpose. Portability covers data within the applicable legal scope and does not require disclosure of another person’s data, security secrets, or proprietary inference.

9. United States notice at collection and category disclosures

During the preceding 12 months, Loglune may have collected the categories listed in Section 2 for the purposes in Section 4 and disclosed them to the providers listed in the Third-party Services List. Loglune has not sold personal data or shared it for cross-context behavioral advertising. California and other applicable state residents may exercise access, correction, deletion, portability, opt-out, non-discrimination, agent, and appeal rights as provided by their law. For California notice-at-collection purposes, the following summarizes the categories Loglune may collect, their sources, purposes, and disclosures during the preceding 12 months:

California category Representative Loglune data Sources Business or commercial purposes Disclosed to
Identifiers business email, account and transaction IDs, IP address user, provider, device, Stripe account, security, support, subscription authentication, hosting, security, payment providers
Customer-record information contact and limited billing information user, Stripe subscription, support, compliance Stripe, hosting and support providers
Commercial information plan, seat count, reproduction usage, renewal, cancellation, refund, dispute status Stripe, user provide the subscription, accounting, fraud, support Stripe, hosting and compliance providers
Internet or electronic activity requests, pages, referrals, feature events, browser and error data browser, device, service providers operate, secure, measure and debug Loglune hosting, analytics, error and security providers
Approximate geolocation coarse location inferred from IP or transaction country network, Stripe security, localization, tax and fraud hosting, security and payment providers
User content and communications flag and configuration data, change history, support messages user store flag definitions, deliver reproductions, and provide support hosting processors; support providers where used
Inferences limited service, fraud, and preference signals activity and account data security, feature preferences, service operation processors supporting those purposes

Loglune does not use or disclose sensitive personal information to infer characteristics or for purposes that trigger a right to limit under California law. Loglune does not offer a financial incentive or price difference in exchange for personal data. We do not discriminate because a person exercises a privacy right, although deleting or withholding data necessary for a feature can make that feature unavailable. California’s “Shine the Light” law permits certain requests about disclosure for third parties’ direct-marketing purposes. Loglune does not disclose personal data to third parties for their own direct marketing. Contact support@loglune.com with a qualifying request.

10. Legal requests and business transfers

We review government and civil requests for validity, jurisdiction, and scope. We disclose only responsive data we possess. Where a request concerns personal data we process on a customer’s instructions, we notify and coordinate with that customer unless prohibited. Unless prohibited, we may notify the affected user. We may challenge an overbroad, defective, disproportionate, or unlawful request. Emergency disclosure is considered only where permitted by law and where we reasonably believe disclosure is necessary to address an imminent risk of death or serious physical injury. We document the request and response to the extent lawful. If Loglune is reorganized, acquired, or transferred, personal data may transfer to a successor that assumes the obligations in this Notice. A materially different use requires advance notice and any consent required by law.

11. Controller contacts, representatives, and versioning

We may update this Notice when our Service or practices change. We will publish the new effective date and retain prior versions. We will provide advance notice of a material reduction in privacy rights where required. Questions and requests:

Loglune
support@loglune.com
/privacy#privacy-request

EU representative, if required: not appointed unless required by applicable law; contact support@loglune.com
UK representative, if required: not appointed unless required by applicable law; contact support@loglune.com

Personal information protection manager (Japan APPI): Loglune privacy contact, support@loglune.com
Data protection officer, if required: not appointed unless required by applicable law; contact support@loglune.com

Part D — Providers and regional procedures

12. Third-party Services List | /privacy#third-party-services | Provider disclosure

Last updated: 2026-08-28. Loglune uses the following principal third parties. A provider may be a processor acting on Loglune’s instructions or an independent controller depending on the activity.

Provider Legal role and purpose Main data Processing locations Provider information
Cloudflare processor for customer personal data; hosting, CDN, Workers, D1 metadata, R2 flag and ruleset storage, Cloudflare Access session verification, and network security account references, flag and configuration data and metadata, session and authentication tokens, IP, requests, logs global network; Cloudflare, Inc. in the United States and subprocessors in their disclosed locations Cloudflare Privacy
Identity provider (GitHub, GitLab) independent controller; authenticates the user and passes a verified identity to Cloudflare Access when you sign in business email, account identifier, authentication result locations described by each identity provider notices published by each identity provider
Google Analytics 4 processor under the applicable Analytics terms; consent-gated website analytics delivered through Cloudflare Zaraz pseudonymous client and session identifiers, page URL and title, referral and campaign data, website events, web vitals, long tasks, coarse location, and basic browser or device data; no flag or configuration data, account email, User-ID, or user-provided data regional collection; EU, Switzerland, and UK data is collected on regional servers before forwarding to Google processing systems; IP addresses are discarded before logging Google Analytics data safeguards
Stripe payment processor and independent controller for its transaction activities; checkout, payments, indirect tax, receipts, fraud, disputes, and transaction support contact, billing, payment, transaction, tax, refund, subscription data global processing, including Stripe entities and providers in Japan, Ireland, and the United States Stripe Privacy
Zoho Mail processor for mailbox service data and controller for Zoho account data; support mailbox support messages, attachments, sender and recipient addresses, delivery metadata primary storage in the Japan data center; other Zoho entities and subprocessors may access data for support and disaster recovery Zoho Privacy
Provider safeguards

Before sending personal data to a provider, Loglune confirms the provider’s role, purpose, data categories, retention, security terms, processing locations, deletion process, and applicable transfer mechanism. Loglune does not publicly claim that a data-processing agreement, Standard Contractual Clauses, certification, or specific storage region applies until the relevant contract or configuration is confirmed. The public list identifies principal providers and is not a representation that every provider receives every listed field. Access is limited by the enabled feature, configuration, request path, and provider role. Loglune does not connect to or send flag or configuration data to any third-party feature-flag provider; the flag definitions and configuration you manage are held first party within Loglune's own infrastructure. We assess a new provider before production use and require contractual, security, confidentiality, deletion, incident, and transfer terms appropriate to the processing. Where law requires advance subprocessor notice or an objection mechanism, we provide it through the registered email address or Service.

Provider-list changes

We may replace or add a provider when reasonably necessary to operate the Service. We will update this list before or when a new provider begins processing personal data and provide notice of a material change where required. Contact questions to support@loglune.com.

13. EEA, UK, and United States supplemental procedures

For users in the EEA or United Kingdom, Loglune is the controller for Loglune account and service processing described in this Notice and is a processor for personal data contained in a customer’s flag definitions and targeting rules, acting on the customer’s instructions. Stripe and other providers may separately act as independent controllers for their own purposes. Loglune identifies a legal basis for each processing purpose before processing begins. Contract is used only where processing is objectively necessary to provide the requested contract, not merely because processing is mentioned in these documents. Legitimate interests are used only after identifying the interest, necessity, user impact, safeguards, and right to object. Consent is specific, informed, affirmative, and withdrawable where relied upon. If a customer’s flag definitions or targeting rules contain special-category data, the customer is responsible for identifying a valid condition for that processing as the controller; Loglune processes them only to operate the platform and deliver a reproduction and does not use them for a new purpose. You may request access, correction, erasure, restriction, portability, or objection and may withdraw consent without affecting earlier lawful processing. You may also complain to the supervisory authority where you live, work, or believe an infringement occurred. Loglune does not require you to contact it before complaining to an authority, although direct contact may allow faster resolution. Contact details for EEA authorities are available through the European Data Protection Board, and the UK authority is the Information Commissioner’s Office. Where Loglune is legally required to appoint an EEA or UK representative, the confirmed representative is listed in Section 11. A placeholder or “not applicable” entry must not be published until the underlying applicability assessment is documented. Transfers from the EEA or UK use a legally recognized mechanism where required, together with a documented assessment and supplementary measures appropriate to the data and recipient. This section also applies where a comprehensive US state privacy law grants the relevant right and Loglune is subject to that law. It does not reduce a right available under a more protective law. Depending on state and applicability, a resident may have rights to know or confirm processing, access, correct, delete, obtain a portable copy, opt out of sale, targeted advertising, or certain profiling, limit certain sensitive-data uses, and appeal a denied request. Loglune does not sell personal data for money, share it for cross-context behavioral advertising, or use it for targeted advertising as those terms are described in this Notice. If those practices change, Loglune will update the Notice and provide required opt-out methods before beginning them. A privacy request may be submitted through /privacy#privacy-request or support@loglune.com. The request should identify the state of residence and the right requested. Loglune uses only proportionate verification and will not require account creation solely to submit a request where law prohibits that condition. An authorized agent may submit a request where state law permits. Loglune may ask for proof of the agent’s authority and may verify the requester directly unless law provides another procedure. An agent must protect information received through the request and use it only for the authorized purpose. If Loglune denies a request, the response states the basis and, where required, provides an appeal method. An appeal is reviewed by a person or process different from the initial decision where practicable and includes the regulator contact information required by applicable law. Loglune will not discriminate against a person for exercising a privacy right. A lawful difference that is reasonably related to the value or necessity of data or a feature the user asks us to provide would be separately disclosed before use; Loglune currently describes no such program here. Global Privacy Control or another legally recognized universal opt-out signal is honored for a practice to which the signal legally applies. Because Loglune currently does not sell data or use targeted advertising, receipt of the signal does not delete the account, withdraw necessary processing, or create a fictitious opt-out record for an absent practice.

14. Account deletion procedure

Account deletion is distinct from subscription cancellation. Cancelling the subscription stops future renewal but leaves the account and stored flag definitions intact. Deleting an account does not automatically resolve an already completed payment transaction or dispute handled by Stripe. To request deletion, use the in-product deletion control when available or /privacy#privacy-request. Loglune may require a recent sign-in or proportionate proof of account control before carrying out an irreversible deletion. The process ordinarily includes:

  1. receiving and timestamping the request;
  2. confirming the affected account and warning about irreversible loss;
  3. giving the customer an opportunity to export content where appropriate;
  4. cancelling or identifying the status of an active subscription;
  5. removing active account access and scheduling production data, including flag definitions, change history, and metadata, for deletion;
  6. transmitting deletion instructions to processors where required;
  7. retaining only information subject to a documented legal, security, dispute, fraud, or accounting exception;
  8. allowing protected backup copies to expire under the applicable cycle; and
  9. providing completion or exception information where legally required.

Deletion may be delayed for a legally permitted period where necessary to verify the request, prevent fraud, complete a transaction requested by the customer, preserve evidence of a dispute, comply with law, protect another person, or maintain security. The retained information is isolated from ordinary product use and deleted when the exception ends unless a further lawful basis applies. A request cannot force Loglune to disclose or delete data controlled solely by Stripe, an identity provider, or another independent controller. Loglune will identify the relevant provider where reasonably possible.

15. Security-incident and breach response

Loglune maintains an incident process appropriate to the nature of the Service. The process covers reporting, triage, containment, preservation of evidence, scope assessment, credential or token protection, provider coordination, recovery, notification assessment, remediation, and closure. An incident is evaluated based on the systems, people, accounts, data categories, duration, likelihood of misuse, potential consequences, and protective measures involved. Where flag definitions or configuration processed on a customer’s instructions are affected, Loglune notifies the customer as required so the customer can meet its own controller obligations. Where law requires notice to a user, regulator, or other person, Loglune provides it within the applicable period and includes the information required by that law. The applicable periods include:

  • GDPR and UK GDPR: notification to the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach likely to result in a risk to rights and freedoms; notification to affected individuals without undue delay where the breach is likely to result in a high risk;
  • Japan APPI: notification to the Personal Information Protection Commission and the affected individual promptly after becoming aware of a qualifying incident, and a formal report within 30 days (or 60 days for unauthorized purpose of use);
  • Brazil LGPD: notification to the Autoridade Nacional de Proteção de Dados and affected individuals within 3 business days of becoming aware of a security incident that may create risk or relevant harm; and
  • US state laws: notification within the period specified by the applicable state statute, typically 30 to 60 days after discovery.

Notice may be delayed or limited where a competent authority lawfully requires it. Incident communications may be delivered to the registered email, within the Service, or through another legally valid channel. A public status notice does not replace individual notice where individual notice is required. Security measures reduce risk but cannot guarantee that an account, network, device, provider, or transmission will never be compromised. Users should protect account credentials, access tokens, devices, exported files, and browser sessions.

16. Corrections, complaints, and appeals

You can correct certain account information directly in the Service. Information controlled by Stripe, an identity provider, or another independent controller may need to be corrected through that provider. If you contest the accuracy of data that cannot be edited directly, identify the field, reason, and supporting evidence. Loglune will correct, complete, annotate, restrict, or decline the request as required by applicable law and will explain a denial where required. Loglune is not required to replace an accurate historical event, security record, transaction record, or support communication with a preferred account of that event. Where appropriate, the record may instead be supplemented with the user’s dispute and the resolution. Correction of account data does not rewrite the contents of your flag definitions or their change history. You control your flag definitions, configuration, and targeting through the Service, subject to version and backup behavior described in the product. A privacy complaint may concern collection, purpose, legal basis, disclosure, transfer, retention, security, consent, a rights response, or another practice described here. Submit it through /privacy#privacy-request or support@loglune.com. Loglune records the complaint, confirms the issue, gathers relevant evidence, limits internal access, identifies the applicable law and provider roles, and provides a reasoned response. We may ask a focused question needed to identify the account or practice but will not request unnecessary flag or configuration data. If an appeal right applies, the denial notice explains how and when to appeal. The appeal should identify the original request and why the decision should change. Loglune will review the record, any new evidence, and the stated legal basis and will provide the regulator information required by applicable law. A complaint, objection, withdrawal of consent, or rights request does not waive any other remedy. Loglune will not retaliate against a person for making a good-faith privacy complaint or contacting a regulator.

17. Japan — Act on the Protection of Personal Information (APPI)

This section supplements the Privacy Notice for users in Japan and for processing governed by the Act on the Protection of Personal Information (個人情報の保護に関する法律). Loglune is a business operator handling personal information (個人情報取扱事業者) under APPI. Privacy requests and complaints may be sent to support@loglune.com.

Purpose of use

Loglune uses personal information for the purposes stated in Section 4. Under APPI, Loglune specifies these purposes to the extent that the individual can reasonably foresee how the information will be handled, and does not use personal information beyond those purposes without prior consent except where APPI permits.

Provision to third parties

Loglune does not provide personal data to a third party without prior consent except where APPI permits, including provision to processors (委託先) acting under Loglune's supervision, joint use as disclosed, or business succession. The providers listed in the Third-party Services List receive personal data as processors under Loglune's instructions or as independent controllers. Where personal data is provided to a provider located outside Japan, Loglune confirms the receiving country's personal information protection system or the provider's equivalent measures as required by APPI and provides the information required before obtaining consent or relying on an exception.

Cross-border transfer

Where personal data is transferred to a provider in a country that has not been recognized by the Personal Information Protection Commission as having an equivalent level of protection, Loglune takes measures required by APPI, including confirming the provider's data-protection system, implementing contractual safeguards, and providing information about the receiving country's regime upon request.

Individual rights under APPI

You may request disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of provision of retained personal data (保有個人データ) by contacting support@loglune.com or using /privacy#privacy-request. Loglune responds without delay and within the period required by APPI. If Loglune denies a request, it provides the reason and information about available remedies. Where a purpose of use is no longer necessary and a large volume of personal data is no longer needed, Loglune takes measures to delete or cease use of the data without delay where feasible.

Qualifying incidents

If a qualifying incident occurs under APPI, Loglune provides a preliminary report to the Personal Information Protection Commission promptly and a detailed report within 30 days (or 60 days for unauthorized purpose of use), and notifies affected individuals promptly.

Complaint resolution

Complaints related to the handling of personal information may be submitted to support@loglune.com. Loglune endeavors to resolve complaints appropriately and promptly. You may also contact the Personal Information Protection Commission (個人情報保護委員会) or a certified personal information protection organization where applicable.

18. Brazil — Lei Geral de Proteção de Dados (LGPD)

This section supplements the Privacy Notice for users in Brazil and for processing governed by the Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13,709/2018).

Controller and legal bases

Loglune is the controller (controlador) for the account and service processing described in this Notice and acts as operator (operador) for personal data it processes on a customer’s instructions. Loglune identifies the applicable legal basis under Article 7 or Article 11 of the LGPD for each processing activity. The legal bases include: performance of a contract, legitimate interests, consent, compliance with a legal obligation, and other bases permitted by LGPD. Where Loglune relies on legitimate interests, the balancing assessment considers the data subject's reasonable expectations, the data minimization measures, and opt-out mechanisms available.

Data subject rights under LGPD

Under Article 18 of the LGPD, you have the right to:

  • confirm the existence of processing;
  • access your personal data;
  • correct incomplete, inaccurate, or outdated data;
  • anonymize, block, or delete unnecessary or excessive data;
  • request portability to another provider;
  • delete personal data processed with consent;
  • obtain information about public and private entities with which data has been shared;
  • obtain information about the possibility of denying consent and the consequences;
  • withdraw consent; and
  • petition the Autoridade Nacional de Proteção de Dados (ANPD).

Submit a request through /privacy#privacy-request or support@loglune.com. Loglune responds within 15 days for simplified format requests and within the period required by LGPD for complete declarations.

International transfer

Where personal data of Brazilian users is transferred internationally, Loglune relies on a mechanism recognized under LGPD, such as Standard Contractual Clauses approved by the ANPD, an adequacy determination, or specific and prominent consent where no other mechanism is available and the transfer is necessary for contract performance. Loglune assesses the receiving country's data-protection level and implements supplementary measures where required.

Data protection officer

The data protection officer (encarregado) for LGPD purposes may be contacted at support@loglune.com. The confirmed identity of the encarregado is listed in Section 13 when appointed.

Sensitive personal data

A customer’s flag definitions or targeting rules may contain personal data within the meaning of Article 11 of the LGPD where the customer includes it. Loglune does not request sensitive data and does not process their contents to infer sensitive categories. Loglune relies on the limited purposes stated in Section 4 to handle them only for storage, evaluation, and reproduction delivery on the customer’s instructions.

Security incidents

In the event of a security incident that may create relevant risk or harm to data subjects, Loglune notifies the ANPD and affected individuals within 3 business days of becoming aware of the incident, providing the information required by ANPD Resolution CD/ANPD No. 15/2024.