Privacy Policy
Last updated: September 27, 2026
- 1. Controller
- 2. Overview of processing
- 3. Public demo
- 4. Registration and customer account
- 5. Chat and switch queries
- 6. MAC addresses (switch data)
- 7. Hosting and infrastructure
- 8. Consent and proof
- 9. Cookies and local storage
- 10. Storage periods (retention)
- 11. Your rights as a data subject
- 12. Right to lodge a complaint
1. Controller
Tobias HeerFriedrichshafener Str. 5
70329 Stuttgart
Germany
Email: human@netloop.ai · Legal: legal@netloop.ai
2. Overview of processing
netloop.ai is a platform for CLI-based network switch management with AI-assisted querying. Where personal data is processed under this policy, it is processed on behalf of our customers (Art. 28 GDPR). Data subjects include in particular our customers' employees and users of the platform.
Categories of processing:
- contact details and access credentials of users (on registration),
- chat history and queries to the AI system,
- switch data (e.g. IP addresses, MAC addresses, hostnames),
- pseudonymous audit records.
3. Public demo
The public demo is a free test environment for professional users. Using the demo does not conclude a contract and creates no payment obligation. For the public demo we provide throwaway accounts. These accounts and their chats and files are deleted immediately after creation, at the latest after one hour. Demo sessions cannot be linked to individuals; we do not store IP addresses for this purpose. Replies in the demo are generated by an AI system (transparency pursuant to Art. 50 of Regulation (EU) 2024/1689).
4. Registration and customer account
On registration we process the data you provide (name, email address, password, optional company details and onboarding token). Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (service security). Access security is additionally protected by two-factor authentication (TOTP).
5. Chat and switch queries
Your queries and the associated responses are processed through our platform. For natural-language processing and command generation we use AI models provided by Mistral AI (France, EU). Transmission takes place exclusively to servers within the European Union; no third-country transfer to LLM providers occurs. Processing is carried out on behalf of the customer (Art. 28 GDPR).
Before transmission to the AI provider, personal values (in particular IP and MAC addresses, email addresses, phone numbers, hostnames) are pseudonymised (masked) by our platform unless they are technically required for the requested operation.
For SSH access to switches, login credentials (username and password) may be required. These are either stored locally in the customer client's configuration file or optionally queried via a browser overlay and transmitted end-to-end encrypted directly to the client. The server has no means to decrypt or view this data. Credentials are not stored permanently.
To ensure IT security and for compliance evidence (Art. 6(1)(f) GDPR; legitimate interest in secure operation), when logging in to a network device we record the username of the device account used — not the password — in our security-relevant audit logs (90 days). Recording of the username can be disabled per customer.
6. MAC addresses (switch data)
Managing network switches may involve processing data relating to individual devices (e.g. ARP/MAC tables, IP addresses). In individual cases such data may relate to a person (e.g. employees' devices). We process this data exclusively on behalf of and under the instructions of the customer (Art. 28 GDPR). For matching MAC addresses with device manufacturers, only hashed values are recorded.
7. Hosting and infrastructure
The platform is operated on servers of Amazon Web Services (AWS) in region eu-central-1 (Frankfurt). AWS is engaged as a processor; the AWS Data Processing Agreement including Standard Contractual Clauses (SCC) applies. No content delivery networks (CDN) are used.
Server logs (access logs) contain the IP address of the accessing device as well as time, requested path (without query parameters), status code and response time. This data is processed solely for IT security and attack detection as well as error analysis (Art. 6(1)(f) GDPR; legitimate interest in secure operation of the platform). No complete URLs (in particular no query parameters) and no user-agent information are stored. The logs are automatically deleted after at most 14 days. The delivered server version is not disclosed in the HTTP header.
8. Consent and proof
In the public demo, you must explicitly consent to the storage and processing of the chats and queries you enter by an AI system (Art. 6(1)(a) GDPR). To prove consent (Art. 7(1) GDPR) we store only a pseudonymous record: timestamp, version of the consent text, language and a hash of the session. This record contains neither your inputs nor your IP address and is automatically deleted after 90 days.
When registering, you must (1) accept the Terms and this Privacy Policy and (2) explicitly consent to the storage and processing of the chats and queries you enter by an AI system (Art. 6(1)(a) GDPR). Both declarations are mandatory; without active consent, registration is not possible. To prove consent (Art. 7(1) GDPR) we store a record with timestamp, version of the consent text (2026-08-09-signup-consent-v1), language and the email address provided at registration. This record contains neither chat content nor your IP address and is automatically deleted after 90 days.
9. Cookies and local storage
We use only technically necessary cookies and browser local storage required for sign-in and operation of the platform (Art. 6(1)(f) GDPR; § 25(2) TDDDG), as well as a functional cookie for the language selection (default: German). No tracking or audience measurement takes place. A cookie banner is therefore not required.
10. Storage periods (retention)
| Data category | Storage period |
|---|---|
| Chats and uploaded files | 90 days after last activity, then automatic deletion |
| Audit records (incl. device account username, no password) | 90 days |
| Demo sessions | max. one hour |
| Registered user accounts | until the account is deleted |
| Lead data | until withdrawal or once the purpose is fulfilled |
Automatic deletion is performed by a daily cleanup job on our servers.
11. Your rights as a data subject
Within the scope of the statutory provisions you have the right to:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection (Art. 21 GDPR).
Please send your request by email to legal@netloop.ai. We respond within one month (Art. 12(3) GDPR). Where we act as a processor for a customer, we will forward your request to the responsible controller.
12. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. The authority of your place of residence or the place of the alleged infringement is competent. In Germany, the authority responsible for the controller's seat is the Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg.