Privacy
Privacy Notice
Effective from:
At a glance
This notice explains the information Louhen needs to provide this website and the features you use in the Louhen App. You can reach us with privacy questions using the contact details below.
An account lets you return to information about the children in your care. A reported current shoe size, foot measurements you enter and fit guidance based on those measurements serve different purposes. Reading this notice does not give consent.
Who is responsible
Louhen GmbH is the controller for the website and App processing purposes described here that Louhen determines.
Louhen GmbHRosenstrasse 6
35096 Weimar (Lahn)
Germany
Where this notice applies
This notice covers Louhen’s public website, voluntary email contact and the App features described here for adults in Germany. The website sections apply when you visit the site. The App sections apply when you use the relevant feature once it is available.
The child-related App features are for adults managing information about children aged 0–3 years. The service is not offered directly to these children, and they do not have their own accounts. The adult must be entitled to act for the child. Purchasing and order processing are outside the App processing described in this revision.
Louhen App: your account
When you use an available account feature, we use your email address, the credentials needed to sign in and a technical account identifier. Firebase Authentication is the intended sign-in service; see “App service providers” for the limits on its use before activation. The identifier links saved information to the correct account and helps protect access to it.
Your account is linked to the child profiles you manage. We may also save the language you choose. These details support the account features you request. The legal basis is Article 6(1)(b) GDPR to the extent that the processing is objectively necessary to provide those features.
Information about your children
When you create a child profile, you provide a display name and the month and year of birth. The current child profile does not require the exact day of birth. Month and year are used only for the intended age-related context of the relevant child feature. Technical links connect the profile to your account and help keep each child’s information together. The use described here does not require a weight or additional personal details.
Only provide a child’s information if you are entitled to do so. A technical link to an account does not establish that entitlement. The information supports the management you request and the age-related interpretation of information entered for your child.
For information about the represented child, we rely on Article 6(1)(f) GDPR: Louhen’s and the caring adult’s interest in assigning requested features to the correct child and using the child’s information responsibly. The child’s interests and rights require particular consideration.
Current shoe size
You can record your child’s current shoe size. We save the size, its sizing system, the link to the child and information about the source and time. This lets you return to the reported size and distinguish it from measured foot dimensions.
A reported shoe size is neither a foot measurement nor a conclusion that a particular shoe fits. It is not automatically converted into foot geometry or a fit assessment. Saving it is optional. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in reliably retrieving the current size you report for the correct child and avoiding mix-ups. The child’s interests and rights require particular consideration. This does not replace consent to Measurement or Fit guidance.
Measurements you enter
If you enter foot measurements, we process the details you provide for the left and right foot, the method used, the time and the link to the child. We derive standardized values and an interpretation. Source details and the version of the interpretation help make the result traceable.
A new measurement may replace the one currently selected for use. This does not automatically erase every earlier input or related record. Retention must remain tied to each record’s purpose; see the section on keeping App information.
Entering and using a manual measurement requires separate, purpose-specific consent under Article 6(1)(a) GDPR. This also covers standardizing and interpreting the measurements where those steps are inherent to the requested Measurement function. Fit guidance for a particular shoe is a separate consent purpose. Reading this notice or merely signing in does not replace consent.
Fit guidance
If you use fit guidance for a particular shoe, suitable current foot measurements are considered alongside that shoe’s exact size and width. We process the necessary inputs, the result and details of the evaluation and its source. Incomplete or unsuitable information may mean that no fit conclusion can be offered.
This guidance supports shoe selection; it is not a medical assessment. A fit result does not automatically permit later use of your information for advertising, general model training or an evaluation for another purpose. Using your measurements for this fit guidance requires its own purpose-specific consent under Article 6(1)(a) GDPR, separate from Measurement consent. If you decline Fit consent, unrelated Louhen features remain available.
Privacy choices and requests
Where a feature requires separate consent or another privacy-related declaration, its purpose, version, time and relevant account or subject link may be recorded. This supports respecting and documenting that declaration. It does not amount to blanket agreement to all processing. Where these records or records of privacy requests are necessary to meet our legal data-protection obligations, their processing is based on Article 6(1)(c) GDPR.
Recording a request does not prove that access, correction or erasure has been completed. You can use the privacy contact below to make a request. This notice does not promise instant data delivery or complete erasure at the tap of a button.
Security and reliable operation
To protect features actually in use, we may process necessary technical events, times and limited details of failed or refused operations. Permitted technical request identifiers may be used where necessary to diagnose a failure. Child details, foot measurements, fit results, passwords and access codes do not belong in these diagnostic logs.
We rely on Article 6(1)(f) GDPR for necessary security and troubleshooting. Our legitimate interest is a secure, reliable service. The purpose and scope must be limited to protecting and operating the feature actually used. This does not authorize general behavioral analytics or advertising.
Information on your device
The App stores your chosen language and whether you have completed the introduction on your device. Sign-in may persist across App restarts. Durable Firestore caching is disabled in the current local test environment. Whether a later available App keeps additional local copies, and which ones, must be checked against its actual configuration and explained here before use.
Signing out ends the relevant sign-in. It does not erase your chosen language or introduction status, and it does not erase all local data. It also does not replace deletion of server-side information or backups. Each copy that actually exists is handled according to its purpose and applicable deletion rules; this notice does not claim that all historical copies have already been removed.
App service providers
Firebase Authentication is the intended sign-in service, and Cloud Firestore is intended to store account, child and measurement information. These are Google services. Local development and testing of these App functions continue to use emulators. Separate company test infrastructure already exists; this does not mean these services have been made available for App customer data. Production use for App customer data remains unestablished. Email contact uses Microsoft 365 as described below.
Before any later production use, the services actually used, recipients, processing locations and applicable transfer safeguards must be established and this notice reviewed accordingly. A planned European storage region does not establish exclusively European processing. The Vercel information concerns the website.
How long App information is kept
Account information remains available for the active account relationship; child-profile information for the respective managed profile. A correction replaces the previous information. Deleting the profile or account ends ordinary use of the associated information. Separately required evidence is limited to what that purpose needs.
For the current reported size, a new or corrected entry replaces the previous current value; clearing it removes that value. The previous entry is not kept as an ordinary size history. A separate evidential duty does not permit continued use as a size history.
Measurement information serves only the separately permitted Measurement purpose. Its ordinary retention ends when it is refreshed, the child profile is deleted or that purpose ends. Fit information depends on the separately permitted Fit purpose; ordinary use ends when that purpose ends or the account relationship is deleted. After withdrawal, no further Measurement or Fit processing relies on that consent. Any need to retain limited information on another legal basis is assessed separately. Withdrawal does not mean instant deletion of every copy; possible future usefulness does not justify continued retention.
Once your account deletion takes effect, your active account relationship with Louhen ends. Ordinary account, child and product information is deleted or disassociated from the ended relationship through the applicable deletion process. This does not mean instant physical erasure of every record and copy. Removing a link is not always equivalent to complete erasure or anonymization.
Limited consent records may remain necessary to demonstrate the grant, scope and withdrawal of consent. Privacy requests are documented until handling and any necessary review are complete. Afterwards, only information needed for a specific applicable legal duty or a particular justified evidential purpose remains, such as an unresolved legal dispute. When that duty ends or the particular evidential purpose is complete, unnecessary information is deleted or identifying links are removed. Any exception must be limited in scope, access and review or end point. These records do not restore account access, consent or active product information.
Our App diagnostics policy provides a retention period of 30 days for redacted diagnostic logs limited to technical metadata. This period does not apply to Vercel Runtime Logs, service data generated under a provider’s own responsibility, consent evidence or backups. It describes the intended App retention policy and does not claim that a customer service is already operating.
Local copies and backups must not make deleted information available again for ordinary use. When their specific recovery or evidential purpose ends, the affected information must be removed or expire through the respective backup process. Deletions and withdrawals since the backup was taken must be respected before restoration. Necessary exceptions cover only the specific information required. No uniform period has been established for all backup copies; immediate complete backup erasure is not promised.
Visiting this website
When you visit this website, technically necessary connection and request data are processed. These may include your IP address, date and time, requested path, hostname, HTTP method and status code, referrer, browser and device information, and technical request and security identifiers.
This processing supports secure, reliable and efficient delivery of this public website, troubleshooting and protection against abusive or harmful access. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are reliable, secure delivery and protection of our systems.
Website hosting and recipients
We use Vercel Inc., 440 N Barranca Ave, #4133, Covina, CA 91723, USA, for hosting and delivery. Where Vercel processes data on our instructions, it acts as a processor.
Vercel may engage further processors for infrastructure, storage, monitoring and security. Its current list of their functions and locations is published in the Trust Center. Where Vercel processes service-generated data as an independent controller, Vercel’s privacy notice also applies.
Website processing outside the EEA
Vercel’s primary processing facilities are in the United States; processing may also occur at other Vercel or subprocessor locations. For transfers from the European Economic Area, Vercel provides for adequacy decisions, including the EU–U.S. Data Privacy Framework, or the European Commission’s standard contractual clauses, as applicable. The relevant arrangements and safeguards are available in Vercel’s data processing agreement.
Website retention
Ordinary use of website access and diagnostic data ends when delivery or the particular investigation of a fault or security concern is complete and the information is no longer needed for it. Longer retention is limited to specific necessary legal duties or resolving a particular incident or legal claim. Service data processed by Vercel as an independent controller are subject to the purposes and retention criteria described in Vercel’s privacy notice.
Delivery of photographic media
We use Cloudflare, Inc., USA, to deliver photographic media. This involves processing, in particular, the requesting connection’s IP address, the requested media file and technical routing data. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is reliable delivery of these media.
Cloudflare processes delivery data on our behalf for as long as needed for that purpose, subject to legally required retention. Cloudflare is independently responsible for its own network and service data; their retention follows the purposes and criteria in its privacy notice.
Processing outside the EEA is possible. Covered transfers to the United States rely on the EU–U.S. Data Privacy Framework; the relevant arrangements provide, in particular, for standard contractual clauses where other transfer safeguards are required. Further information is available in Cloudflare’s data processing agreement.
A data-minimal website
The informational pages described here do not offer sign-in or forms. We do not use analytics, marketing, tracking or personalization services on these pages. Separately provided privacy functions are distinct from these informational pages.
If an explicitly available privacy function needs technically necessary, short-lived state or cookies, they serve only that function, not advertising or behavioral analytics. This does not promise that an automated deletion form is already available; you can send privacy requests to our privacy contact.
Louhen may use automated processing for product features. The Stage 1 features described here do not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
Contact by email
If you choose to contact us by email, we process your email address, your name if you provide it, your message, any attachments and communication metadata. We use this information to receive, assess and answer your request and, where necessary, document it.
We handle enquiries about a service or contractual relationship you request under Article 6(1)(b) GDPR, to the extent necessary for that service, contract or pre-contract steps you request.
We handle privacy requests and the documentation legally required for them under Article 6(1)(c) GDPR, to the extent necessary to meet our legal data-protection obligations.
We answer and document other legitimate enquiries to the extent necessary under Article 6(1)(f) GDPR. Our legitimate interest is handling those enquiries appropriately and maintaining secure, orderly business communications.
We use Microsoft Exchange Online for business email, including privacy@louhen.eu, and SharePoint to keep privacy-case documents. Recipients are Microsoft and the subprocessors used for these services. Microsoft processes the communication and case content we store there on our instructions as a processor. For certain business and service data of its own, Microsoft also processes data as an independent controller.
Processing outside the European Economic Area is possible. Microsoft describes safeguards including the European Commission’s standard contractual clauses and, where applicable, adequacy arrangements such as the EU–U.S. Data Privacy Framework. Information about these safeguards and the services covered is available in the Microsoft Products and Services Data Protection Addendum. You can request a copy of the relevant safeguards through our privacy contact.
We delete the information when the enquiry is complete and further storage is unnecessary. We keep it longer only where legal retention duties, the establishment, exercise or defence of legal claims, evidential needs or other documented obligations require it. We do not make solely automated decisions about your rights with legal or similarly significant effects within the meaning of Article 22 GDPR.
Your privacy rights
Subject to the relevant legal conditions, you have rights including access, correction, erasure, restriction of processing and, where applicable, data portability. You can contact privacy@louhen.eu to exercise these rights.
Where processing relies on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
Making a complaint
You have the right to complain to a data protection supervisory authority. The authority responsible for Louhen GmbH is the Hessian Commissioner for Data Protection and Freedom of Information, Wilhelmstraße 7, 65185 Wiesbaden. Information on complaints is available from the HBDI.
Your right to complain is not limited to this authority. In particular, you may also contact the supervisory authority where you habitually reside, where you work or where the alleged infringement occurred.
Information necessary to deliver the website
The technically necessary connection data are transmitted automatically when you visit the site. Providing them is not a statutory or contractual requirement; without them, however, the website cannot be delivered technically.
Only information objectively necessary for an account feature you request is required for that feature. You do not have to save a child profile or current shoe size to use unrelated features. Without the necessary child-related information, the relevant child feature cannot be provided. Measurement and Fit guidance each require their separate consent; declining does not affect unrelated features.
Contact us about your privacy rights
You can contact our privacy address about your own information or information about a child you represent. Please explain what you need and provide only the information necessary for the request. Do not send passwords or secret access codes.
Where processing is based on consent, you can withdraw it for the future using the privacy contact below. After effective withdrawal, we stop future processing that depends on that consent. Withdrawal does not affect the lawfulness of processing before that point. Handling a request may require checking the requester’s identity and entitlement to represent the child. Your statutory rights apply whether we handle requests manually or automatically; this notice does not promise instant or automated fulfillment.
We do not routinely collect identity documents, custody papers or family-status evidence for ordinary child profiles. If a privacy request requires additional evidence of identity or entitlement to represent a child, we assess that individually and limit it to what is necessary.
AI-generated imagery
The photographic imagery on this website was created using generative artificial intelligence. The people and situations shown are fictional and do not depict actual customers or documented real-world events. Louhen uses these images for the visual presentation of its editorial content.