Privacy Policy

Last updated: October 5, 2026

This policy explains what personal data the Loop MDM service (the management console at panel.loop.net.tr and the Loop MDM agent installed on devices) processes, why, and your rights.

1. The service and who we are

Loop MDM is developed and operated by independent developer Ahmet ÖZDİNÇ (“we”). It lets organizations manage their own Android work devices.

For data collected from managed devices, the organization managing the devices (our customer) is the data controller and we act as its processor. For console user account data, we are the controller.

Loop MDM is only for work devices owned or managed by organizations. It must not be used to monitor or spy on people’s personal phones, or to lock devices based on payment status.

2. Data we process

Console users:

  • Name, email address, role and permissions
  • Password (stored as a one-way hash), two-factor authentication secret (encrypted)
  • Session and audit logs: sign-in time, IP address, browser, actions taken

3. Data collected from managed devices

  • Device info: brand, model, serial number, Android and agent version
  • Status: battery, storage, network connection, local and public IP address, last check-in, USB debugging state
  • List of installed apps and their versions
  • Location: only if the organization enables it in policy, at set intervals; location records are deleted after 30 days
  • Management records: applied policy, commands sent and their results, errors
  • Information the organization enters (e.g. device name, assigned employee name)
  • Screenshots during remote support: only with the device user’s permission (on unattended kiosk devices, at the organization’s choice without a prompt) and always with a visible warning banner on the device; not stored permanently — kept in server memory only during the session and briefly after

4. Data we do not collect

  • Messages, call logs, emails, contacts
  • Photos, files, passwords
  • In-app activity and web browsing history
  • Notification contents: shown only on the device itself in kiosk mode, never sent to our servers

5. Purposes and legal bases

  • Providing the device management service (policies, app distribution, kiosk, Wi‑Fi, lost mode, remote support) — performance of a contract
  • Security of the service and devices, preventing abuse, audit logs — legitimate interests and legal obligations
  • Account notifications and reports the organization requests by email — performance of a contract
  • For device data processed on behalf of an organization, the legal basis is the organization’s own (e.g. employment contract, legitimate interests)

6. Sharing and service providers

We do not sell personal data or use it for advertising. We rely on these providers to run the service:

  • Hosting: Oracle Cloud Infrastructure, Frankfurt (Germany). Data is stored in the European Union.
  • Google Firebase Cloud Messaging: a content-free signal wakes a sleeping device; only the device’s messaging token is shared
  • Email delivery: the service’s mail (SMTP) server; used only for account notifications and reports the organization requests
  • Maps: when the console shows a location, map tiles are loaded into your browser from OpenStreetMap servers

7. Retention

  • Location records: 30 days
  • Screenshots and remote support images: not stored permanently
  • Other device and account data: for the duration of the organization’s use of the service; deleted when the organization deletes the device or account
  • Audit logs: as long as needed for security and legal obligations

8. Security

  • All connections are encrypted with HTTPS
  • Each organization’s data is isolated; one organization cannot see another’s devices
  • Secrets such as Wi‑Fi passwords are stored encrypted; console users have two-factor authentication
  • After enrollment the device shows a “This device is managed” notice listing what is collected

9. Your rights

You may ask whether we process your personal data, request access, correction or deletion, object to processing and seek redress, as provided by applicable law (including Turkish Law No. 6698, KVKK, and where applicable the GDPR).

If you use a managed device, please contact the organization that manages it first; we will assist them. You can also write to ahmet@ozdinc.net; we respond within 30 days.

10. Changes and contact

We may update this policy; the current version is always published on this page with its date above. Questions: ahmet@ozdinc.net