LodeFox Privacy Policy
How we handle personal data, the rights you have, and how to contact us.
Version 1.1 · Effective date: 14.7.2026 · Classification: Public
LodeFox Oy (“LodeFox”, “we”, “us”) provides an AI-native product analytics platform. This Privacy Policy explains how we handle personal data, the rights you have and how to contact us.
We handle personal data in two different roles and this Policy is organized around that distinction:
- As a controller — when we decide why and how personal data is processed. This covers visitors to our website; the people who contact us for sales, support, or marketing; the account and relationship data we hold to run our customer relationships; and the account and usage data we process for our own purposes such as authenticating users, securing and improving the Service, and billing.
- As a processor — when we process personal data on behalf of a customer, on their instructions. This covers the end-user interaction data captured through the LodeFox snippet on our customers’ own products, and the personal data of the customer’s own appointed users that we process on their behalf as they use the Service.
If you are an end user of a product or service that uses LodeFox, the business operating that product is the controller of your data and their privacy policy governs. Section 4 explains our limited role, but you should direct requests about that data to the business whose product you were using.
Quick summary
- We process personal data within the EU/EEA.
- We do not sell personal data.
- We are designed around data minimization: we don’t capture what people type and we obfuscate recognizable on-screen text in the browser before anything leaves.
- We use our own AI models and do not send personal data to third-party LLM or inference APIs.
- We do not make automated decisions that produce legal or similarly significant effects on individuals.
- You have rights over your personal data, including access, correction, and deletion — see Section 12.
- Questions: privacy@lodefox.com.
This summary is for convenience only; the full Policy below governs.
1. Who we are
LodeFox Oy is a company registered in Finland (Business ID: 3637857-4), with its registered address at Huvilakatu 12, 33960 Pirkkala. LodeFox is the controller for the processing described in Section 3 and a processor for the processing described in Section 4.
For any privacy matter, our contact point is our Privacy Contact at privacy@lodefox.com.
2. Scope of this Policy
This Policy applies to:
- our website(s), including lodefox.com and related pages (the “Site”);
- the LodeFox application and hosted service, including any application subdomains (the “Service”); and
- our sales, marketing, support, and business operations.
It also describes, in Section 4, the personal data we process on behalf of our customers when their products use LodeFox.
3. Personal data we process as a controller
This Section covers data for which LodeFox decides the purposes and means — i.e. we are the controller.
3.1 Visitors, prospects, and marketing contacts
When you visit our Site, contact us, or interact with our sales and marketing, we may process:
- Contact and inquiry data — for example when you submit a contact form, request a demo, start a chat, or email us such as: your name, business email, company, role and the content of your message.
- Subscription data — if you subscribe to a newsletter or blog updates such as: your email address and preferences.
- Site usage and analytics data — pages viewed, interactions, approximate location derived from network information, device and browser information, and similar, collected via cookies and similar technologies (see Section 6).
Purposes and legal bases:
- Responding to inquiries, demos, and sales discussions — Legitimate interests (to respond and pursue a potential business relationship); steps prior to entering a contract
- Sending newsletters and marketing to subscribers — Consent (withdrawable at any time)
- Direct B2B marketing to business contacts — Legitimate interests (with opt-out)
- Operating, securing, and improving the Site — Legitimate interests
- Analytics and non-essential cookies — Consent
3.2 Account holders and users of the Service
When you or your organization creates an account and uses the Service, we process:
- Account and identity data — such as name, profile picture, business email and the credentials you set.
- Authentication and security data — such as sign-in events, session information and security logs.
- Service usage data — how your users navigate and use the LodeFox application, including data we capture by using our own analytics on the Service.
- Billing and transaction data — where applicable, the information needed to administer a paid subscription.
Purposes and legal bases:
- Providing, maintaining, and administering the Service — Performance of a contract
- Authenticating users and securing the Service — Legitimate interests; legal obligation
- Improving and developing the Service — Legitimate interests
- Billing, invoicing, and record-keeping — Performance of a contract; legal obligation (e.g. accounting law)
- Service-related communications — Performance of a contract; legitimate interests
3.3 Roles for account and user data
When an organization becomes our customer, its people interact with the Service in different ways, and responsibility for their personal data is allocated as follows:
- The customer’s appointed users. A customer’s authorized representative sets up the account and may invite colleagues (such as employees, contractors, or partners) to access the Service. For the personal data of these users that we process on the customer’s behalf as they use the Service — such as setting up and managing their access, and the profile information, references to other users, report configurations, assignments, and similar data they generate through their use of the Service — the customer is the controller and LodeFox acts as processor on the customer’s instructions.
- LodeFox’s own operational purposes. Separately, LodeFox acts as an independent controller of the account and usage data it processes for its own purposes — authenticating users, securing the Service, billing and administering the customer relationship, providing service-related communications, and analyzing and improving the Service (including through analytics on how the Service is used).
- Customer relationship and tenant data. LodeFox is the controller of the account-level details we hold to manage our relationship with the customer — such as billing, administrative, and security contacts.
Where LodeFox and a customer each process the same account data for their own purposes, they act as independent controllers, each responsible for the processing it determines.
4. Personal data we process as a processor (on behalf of customers)
When a customer installs the LodeFox snippet on their website or application, LodeFox processes end-user interaction data on that customer’s behalf and on their documented instructions. For this data:
- the customer is the controller and LodeFox is the processor;
- the customer is responsible for establishing a lawful basis and for providing any required notice or consent to its own end users; and
- the processing is governed by a Data Processing Agreement (DPA) between LodeFox and the customer.
What is captured. By design, this processing is minimized. We capture user-interaction events (such as clicks, navigation, and interaction context) and the visible labels and on-screen text needed to make those events meaningful. We do not capture the values users type into fields, individual keystrokes, or screen recordings, and we do not store end-user IP addresses. Where geographic analytics are available from time to time, we derive approximate location (for example, city or region) from the IP address, which is not itself stored. Recognizable on-screen text is obfuscated in the end user’s browser before any data is transmitted, and customers can additionally tag elements to exclude them. To distinguish sessions, either a pseudonymous, LodeFox-generated identifier (not linked to the customer’s own user records) or an identifier the customer supplies from its own systems is used, at the customer’s choice.
End-user rights. Because the customer is the controller of this data, end users should exercise their rights (Section 12) with the business whose product they were using. We assist our customers in responding to such requests as set out in the DPA, and end-user personal data can be anonymized or deleted at any time on the customer’s instruction.
5. AI and automated processing
LodeFox is an AI-native platform. We use our own AI models throughout our processing pipeline — not only to generate insights, but to automatically detect the structure, features, and user flows of the products we analyze. We do not send personal data to third-party large language model or inference APIs.
No decisions with legal or significant effects. Our AI produces analytical insights to support our customers’ product decisions. It is not used to make automated decisions that produce legal effects concerning individual end users or that similarly significantly affect them within the meaning of Article 22 GDPR.
Model training. We improve our models only on de-identified data. Raw, customer-identifiable event data is not used for model training.
Benchmarking. We may provide comparative benchmarks derived only from aggregated, de-identified data, and only where the contributing sample is large enough to preserve the anonymity of the underlying parties.
6. Cookies and similar technologies
We and our Service use cookies and similar technologies in three distinct contexts. Detailed information and controls are provided in our Cookie Policy.
- On our Site (lodefox.com). We use essential cookies to operate the Site and website-analytics cookies to understand how the Site is used.
- In our Service (including application subdomains). We use essential/session cookies required to authenticate you and operate the application, and analytics cookies to understand and improve how the Service is used.
- On our customers’ products or services via the LodeFox snippet. By default, the snippet sets a cookie in the end user’s browser to store a pseudonymous identifier that distinguishes sessions; alternatively, the customer may supply its own identifier. In this context the customer is the controller and is responsible for providing cookie notice and obtaining any required consent from its end users.
Where consent is required for non-essential cookies, we obtain it and you can withdraw it at any time.
7. Aggregated and de-identified data
We may create aggregated or de-identified data that does not identify any individual, and use it to operate, analyze, improve, and develop our products and services. Because such data cannot be linked to an individual, it is not personal data, and this Policy does not restrict our use of it.
8. How we share personal data
We do not sell personal data. We share personal data only with the following categories of recipients, and only as necessary:
- Sub-processors and service providers that process personal data on our behalf — for example providers of cloud hosting and infrastructure, AI compute, communications and email, customer support, analytics, and payment processing. We enter into data-protection terms with these providers and keep our sub-processor footprint deliberately small. The current list of sub-processors that process personal data on behalf of our customers is maintained under, and made available in accordance with, the DPA.
- Professional advisers and authorities — where necessary to comply with the law, enforce our agreements, or protect rights, safety, and security.
- Corporate transactions — in connection with a merger, acquisition, or reorganization, subject to appropriate confidentiality protections.
9. International data transfers
We process and store personal data within the EU/EEA. Both our application and data infrastructure and our AI inference infrastructure are located within the EU/EEA.
Some of our infrastructure providers are part of corporate groups headquartered outside the EU/EEA, and may in limited circumstances — for example for support, security, or administration purposes — access personal data from outside the EU/EEA. Where any such processing occurs, it is carried out under an appropriate transfer mechanism required by law, being the EU Standard Contractual Clauses, an applicable adequacy decision, or both, together with supplementary safeguards.
The fact that our Site or Service can be accessed by users located outside the EU/EEA does not by itself mean personal data is processed outside the EU/EEA; we serve results to users wherever they are, while the processing itself remains in the EU/EEA. We also limit our operational access to personal data to the EU/EEA.
10. How we keep personal data secure
We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls on a least-privilege basis, environment separation, logging, and monitoring.
11. How long we keep personal data
We keep personal data only for as long as necessary for the purposes described in this Policy:
- Inquiry and marketing data — until you unsubscribe or object, and thereafter only as needed to evidence your preferences.
- Account and Service data — for the duration of the customer relationship, and thereafter as needed to meet legal, accounting, and security obligations.
- Data processed on behalf of customers (Section 4) — retained and deleted in accordance with the customer’s instructions and the DPA.
When personal data is no longer needed, we delete or anonymize it.
12. Your rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate data;
- request erasure of your data;
- request restriction of, or object to, certain processing;
- request portability of data you provided to us;
- withdraw consent at any time, where processing is based on consent; and
- lodge a complaint with a supervisory authority.
To exercise these rights in relation to data for which we are the controller, contact privacy@lodefox.com. We may need to verify your identity. Where the data concerns your use of a customer’s product or service (Section 4), please contact that business, as they are the controller.
You can lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman, or with the authority in your EU/EEA country of residence.
13. Changes to this Policy
We may update this Policy from time to time. Material changes are reflected by a new version number and effective date. Where required, we will provide additional notice. Prior versions are identified by their version number and effective date so you can see which version applied at a given time.
14. Contact
- Privacy Contact: privacy@lodefox.com
- Post: LodeFox Oy, Huvilakatu 12, 33960 Pirkkala, Finland
© 2026 LodeFox Oy.