Privacy and cookies policy
Table of Contents
- Who is the administrator of your personal data?
- Who can you contact about the processing of your personal data?
- What personal data we collect and process
- Purposes and Legal Bases of Data Processing as well as Categories of Recipients
- International Data Transfers
- Storage Period and Deletion
- Rights as Data Subject
- Exercising Your Data Subject Rights and Managing Your Settings
- Cookies and Similar Technologies
- Additional important information about privacy
Privacy Policy
In our Privacy Policy, we've compiled all the essential information about how we handle your personal data and your related rights.
This Privacy Policy is effective from March 15, 2024.
Scope and Updating of this Privacy Policy
This Privacy Policy applies to the use of this website and all applications, services, products, and tools provided by LUDILO (referred to collectively as "Services"), regardless of how you access or use these Services, including access via mobile devices and apps.
We may change this Privacy Policy at any time by publishing the amended version here and indicating the effective date of the amended version. All material changes to this Privacy Policy will be communicated to you via email if you have registered with us.
# 1: Who is the administrator of your personal data?
LUDILO, located at [insert address of LUDILO], is the operator of our services and responsible according to the provisions of the General Data Protection Regulation (GDPR). When this privacy policy refers to 'us', 'we', or 'our', it always refers to LUDILO as the responsible party
# 2: Who can you contact about the processing of your personal data?
We have appointed a Data Protection Officer responsible for overseeing the protection of your personal data. If you have any questions about this Privacy Policy or about data protection at LUDILO in general, you can contact our Data Protection Officer at
# 3: What personal data we collect and process
We collect your personal data when you use our services, create a new LUDILO account, provide us with information via a web form, add or update information to your LUDILO account, or engage with us in any other way. We also collect personal data from other sources (such as other members of our Adevinta group of companies, credit agencies, and other data providers).
Overall, we collect the following personal data:
4.1 Personal data provided by you when using our services or setting up a LUDILO account
Data that identifies you, such as name, title, address, telephone number, and email address, your username, your date of birth, or your VAT identification number, which you provide when opening the LUDILO account or at a later date, with certain data such as your telephone number being mandatory to verify, for example, in preventing and investigating illegal activities. Data about ads and information you provide during a transaction (e.g., delivery address), as well as other transaction-related content you generate (e.g., ads and other content you generate or relate to your LUDILO account, use of the contact function in ads, and saved searches (including favorites)). Other content you generate or relate to your account (e.g., user reviews). Content exchanged with other users via our messaging tools (further information below under Review of messages sent via our messaging tools). Financial information (e.g., credit card and account numbers, payment data) related to the use of a paid service offered by us or a payment service provided by a payment service provider as part of our services. In some cases, optional: marital status, employment status, net income, household size, interests. Data we need to collect for tax purposes when you, as a seller, use our 'Secure Pay' or 'Buy Now' function, including e.g., the tax identification number and the member state of the European Union that issued it, your date of birth, the identifier of the financial account, the name of the holder of the financial account (if different from the name provided in the LUDILO account), and any other information necessary to identify the account holder, as well as any member state of the European Union where you are considered resident. If you submit a report regarding illegal content or a complaint to us: data that identifies you, such as your name and email address, as well as additional information you provide with your report or complaint. You can provide us with additional information via a web form or by updating or adding data to your LUDILO account, inquiries, by calling our customer service, which may be recorded with your consent, or if you contact us for other reasons regarding our services. Additional data that we are legally obliged or entitled to collect and process and that we need for your authentication, identification, or to verify the data we have collected.
4.2 Personal data we automatically collect when you use our services or create a LUDILO account
Data that arises during your use of our services and is associated with your LUDILO account, such as saving searches or ads. Data about your interaction with our services (such as search queries or views of ads), your ad preferences, and your communication with us; this also includes information pseudonymously collected by us that the phone number displayed individually in an ad was called. Location data, including approximate location (e.g., region derived from IP address) and exact location of your mobile device. Please note that with most mobile devices, you can set or deactivate the use of location services for all applications in the settings menu of your mobile device. Computer and connection information, such as statistics about your visits to the services, information about traffic to and from the websites, referral URL, information about advertisements, your IP address, your access times, your access times including the pages accessed within our services, your language settings, and your weblog information.
4.3 Personal data we collect in connection with the use of cookies and similar technologies
We use cookies, web beacons, and similar technologies to collect data as part of your use of our services. We collect this data from the end devices (including mobile devices) you use to access our services. The collected data includes the following usage- and device-related information:
Data about the pages you visit, the time, frequency, and duration of visits, the links you click on, and other actions you take as part of your use of our services and in advertising and email content. Data about your activities and interactions with our advertising partners, including data on which ads were shown to you, how often they were shown, when and where they were shown, and whether you took any action, such as clicking on an ad or performing a transaction. Your membership in one or more user segments or categories, such as male, 20-49 years old, interested in cars. Model or device type, operating system and version, browser type and settings, device ID or individual device identifier, ad ID, individual device token, and data regarding cookies (e.g., cookie ID). The IP address from which your device accesses the services. Location data, including approximate location (e.g., region derived from IP address) and exact location of your mobile device. Please note that with most mobile devices, you can set or deactivate the use of location services for all applications in the settings menu of your mobile device.
For more information about our use of these technologies and your choices, please see Cookies and similar technologies.
4.4 Personal data from other sources
We also collect personal data about you from other sources and from third parties to the extent permitted by applicable law. This includes, in particular, the following data:
Data from public sources (e.g., demographic information). Data from credit agencies (e.g., credit check data and identity confirmations). Data from data providers (e.g., demographic information, data related to interest-based and online advertising).
We combine the data you provide with data from these other sources. When third parties provide us with personal data, we take measures to ensure that these third parties are authorized to disclose your personal data to us. We also have access to personal data about you from other members of our Adevinta group of companies.
4.5 Data you share with us on social networks
We may allow you to share data with social networks or use social networks or similar service providers where you already have an account to create a LUDILO account or link your LUDILO account to your account with the respective social network or similar service provider (e.g., Meta and Google). These social networks and similar service providers may automatically grant us access to certain personal data stored about you there (e.g., content you viewed or liked, information about the ads shown to you or clicked on by you, etc.). You can determine the personal data to which we can access via the privacy settings of the respective social network or similar service provider. We use social media links to various social networks. With the help of these links, you can share content or recommend products, among other things. The social media links are integrated in such a way that no personal data can be collected by the social networks simply by accessing the page. Only when a user clicks on a social media link is a connection made to the respective social network. For the purpose and scope of data collection and further processing and use of the data by social networks, as well as your rights and options for protecting your privacy, please refer to the privacy policies of the respective networks or websites. The links to these can be found below. On our websites, we have integrated social media links to the following social networks:
• to Meta (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland). You can find Meta's privacy policy here: https://www.facebook.com/about/privacy/
# 4: Purposes and Legal Bases of Data Processing as well as Categories of Recipients
We process your personal data for various purposes and based on various legal grounds that allow such processing. We process your personal data, among other things, to provide and improve our services, offer you a personalized user experience on this website, contact you regarding your LUDILO account and our services, provide customer service, offer you personalized advertising and marketing communications, and detect, prevent, mitigate, and investigate fraudulent or unlawful activities. For these purposes, we also share your data with third parties (including our processors) as described in Section 5.6 of this Privacy Policy.
Below is a summary, organized by legal basis, of the purposes for which we process your personal data, including the categories of recipients to whom we transmit personal data for each purpose mentioned:
• We process your personal data to fulfill the contract with you and to provide our services (Art. 6 para. 1 lit. b) GDPR). This includes the following purposes:
Processing data about you or your company for the purpose of concluding and performing the contract with you (including conducting two-factor authentication using the phone number stored in your LUDILO account if there is an increased risk of unauthorized access to your LUDILO account). Providing our services and their use (including billing), especially for posting ads and other user content, facilitating contact with other users with relevant offers, measuring and improving the quality and success of our services, keeping our services safe and operational, and adapting the content of the website and services based on your actions to what you might like. Facilitating and conducting transactions/contacting other users (including transmitting your necessary personal data to other LUDILO users), providing and improving features such as ratings and LUDILO account management, providing other services requested by you (as described in connection with such services), and ensuring the functionality of our services. Resolving issues with your LUDILO account, enforcing fee claims, and providing other customer service. For these purposes, we may contact you via notification in your LUDILO account, email, phone, SMS, push notification on your mobile device, or mail. Processing general location data (such as IP address or postal code) to provide you with location-based services (such as proximity search and other content personalized based on your general location data). Enforcing our terms of use and this privacy policy and other principles. Granting access to your ads and their content to cooperating external providers of websites, applications, services, and tools with whom we collaborate according to our terms of use, so that they can publish or advertise your ads and their content on their websites or in their applications, services, and tools. When we disclose the content of your ads and related personal data to such external providers, we do so only based on an agreement that restricts the use of this personal data by the external provider to the purposes necessary to fulfill the contractual obligations towards us. The external provider is contractually obligated to take appropriate security measures regarding this data. External providers are in no way authorized to disclose personal data contained in your ads to third parties. As necessary, we transmit your personal data to one or more of the aforementioned purposes to processors and the following additional recipients:
Other LUDILO users External operators of websites, applications, services, and tools
• We process your personal data to fulfill our legal obligations (Art. 6 para. 1 lit. c) GDPR). This includes the following purposes:
Participation in proceedings (including legal proceedings) conducted by governmental authorities, especially for the investigation and prosecution of unlawful acts. Prevention, detection, and mitigation (including compliance with reporting obligations) of unlawful acts (e.g., fraud, money laundering, and terrorism financing). Responding to requests to exercise your data subject rights under the GDPR, including sending passwords for corresponding files via SMS to your phone number. Responding to third-party requests for information based on legal disclosure claims that third parties have against us (e.g., in the case of intellectual property infringements or other legal infringements). Processing reports of illegal content and complaints, including reviewing whether such reports or complaints are frequently obviously unfounded by the same user. Meeting additional legal requirements in the areas of consumer protection, online platforms, and taxes. Ensuring the information security of our services. Retention and storage of your personal data to fulfill specific legal retention obligations (further information on the storage of your data by LUDILO can be found under Storage Duration and Deletion).
As necessary, we transmit your personal data to one or more of the aforementioned purposes to processors and the following additional recipients:
Law enforcement authorities, courts, or other governmental authorities (subject to an examination of whether the transmission of your personal data, which we have collected for other purposes, constitutes a permissible change of purpose, including the weighing of whether your interests in excluding the transmission of data prevail). Third parties based on legal disclosure claims against us and in connection with legal proceedings, provided that we are presented with a legal order, court order, or equivalent legal order (subject to an examination of whether the transmission of your personal data, which we have collected for other purposes, constitutes a permissible change of purpose, including the weighing of whether your interests in excluding the transmission of data prevail). Tax authorities within the framework of the reporting process for platform operators. External service providers Credit reporting agencies, if legally allowed or mandatory (e.g., information on payment delays, payment defaults, or other irregularities that may be relevant to your credit report). Other LUDILO users, to the extent that the disclosure of your identity as the reporting user is absolutely necessary within the framework of the procedure for reporting illegal content.
• We process your personal data to protect your vital interests or the vital interests of another natural person (Art. 6 para. 1 lit. d) GDPR). This includes the following purposes:
Prevention, detection, mitigation, and investigation of unlawful acts that may affect your vital interests or the vital interests of another natural person, unless there is already a legal obligation to do so.
As necessary, we transmit your personal data to one or more of the aforementioned purposes to processors and the following additional recipients:
Law enforcement authorities, courts, or other governmental authorities, as well as third parties involved in legal proceedings (subject to an examination of whether the transmission of your personal data, which we have collected for other purposes, constitutes a permissible change of purpose, including the weighing of whether your interests in excluding the transmission of data prevail). External service providers
• We process your personal data to pursue our legitimate interests (Art. 6 para. 1 lit. f) GDPR), provided that your interests or fundamental rights and freedoms do not outweigh. To reconcile our interests with your rights, we have introduced appropriate control mechanisms. On this basis, we process your data for the following purposes:
Participation in proceedings (including legal proceedings) conducted by courts, law enforcement authorities, or other governmental authorities, especially for the investigation and prosecution of unlawful acts, unless there is already a legal obligation to do so and we may reasonably believe that the disclosure of the data is necessary to avert impending disadvantages or report suspicion of unlawful activity. In such cases, we will only disclose the data we deem necessary, such as name, location, postal code, phone number, email address, previous usernames, IP address, fraud complaints, and ad content. Safeguarding the legitimate interests of third parties in civil disputes, unless there is already a legal obligation to do so and we may reasonably believe that disclosing the data to such third parties is necessary
# 5: International Data Transfers
Some of the recipients of your personal data are located outside of your country or have branches in countries where data protection laws may offer a different level of protection than the laws in your country. When transferring data to such recipients, we ensure appropriate safeguards.
We only transfer your personal data from the European Economic Area (EEA) to third countries, meaning countries outside the EEA, based on appropriate safeguards. Currently, third countries offering an adequate level of data protection include Andorra, Argentina, Canada (for businesses subject to the Personal Information Protection and Electronic Documents Act), Switzerland, the Faroe Islands, Guernsey, the State of Israel, the Isle of Man, Japan, Jersey, South Korea, New Zealand, Uruguay, the United Kingdom, and South Korea. In other cases, LUDILO ensures the necessary safeguards, for example, by concluding data protection agreements issued by the European Commission (such as standard data protection clauses (2010/87/EU, 2001/497/EC, or 2004/915/EC)) with the recipients or through other legally prescribed measures. A copy of the documentation of the measures we have taken is available upon request
# 6: Storage Period and Deletion
Your personal data is stored by us and our service providers in accordance with applicable data protection law, as long as necessary for the processing purposes mentioned in this privacy policy (for more information on processing purposes, see Purposes and Legal Basis of Data Processing and Categories of Recipients). Subsequently, we delete your personal data in accordance with our data retention and deletion policies or take measures to properly anonymize the data. However, there may be exceptions if we are legally obligated to retain your personal data for a longer period (e.g., for compliance with legal obligations or for tax, accounting, and auditing purposes). In Europe, retention periods typically range from 6 to 10 years (e.g., for contracts, communications, and business letters). Where legally permissible or required, we may restrict the processing of your data instead of deleting it (e.g., by blocking). This applies especially in cases where we may still need the relevant data for further contract processing or for legal proceedings or defense, or where their retention is otherwise legally required or permitted. The relevant criterion for the duration of the processing restriction is then the statutory limitation or retention periods. After the relevant limitation or retention periods expire, the relevant data will be deleted
# 7: Rights as Data Subject
Subject to possible restrictions under national law, you, as the data subject, have the right to access, rectify, erase, restrict processing, and transfer your personal data. Additionally, you can revoke your consent once given and object to our processing based on legitimate interests. Furthermore, you have the right to lodge a complaint with a supervisory authority
You can withdraw your consent to the processing of your personal data by us at any time. This means that we may no longer process your personal data based on your consent in the future. The lawfulness of the processing carried out based on the consent before the withdrawal shall not be affected by the withdrawal. You can request information about your personal data processed by us. In particular, you can request information about the purposes of processing, the categories of personal data processed, the categories of recipients to whom your data has been or will be disclosed, the planned duration of storage, the existence of a right to rectification, erasure, restriction of processing, or objection, the existence of a right to lodge a complaint, the origin of your data if it has not been collected directly from you, as well as the existence of automated decision-making, including profiling, and, if applicable, meaningful information about its details, whereby the right to information may be restricted by national law. You can request the immediate correction of inaccurate or completion of your personal data stored by us, taking into account the purposes of processing. You also have the right to request the completion of incomplete personal data, including by means of a supplementary statement. You can request the deletion of your personal data stored by us, provided that the processing is not necessary to exercise the right to freedom of expression and information, to fulfil a legal obligation, for reasons of public interest, or to assert, exercise, or defend legal claims, whereby the right to deletion may be restricted by national law. You can request the restriction of the processing of your personal data, to the extent that the accuracy of the data is disputed by you, the processing is unlawful, but you refuse its deletion, and we no longer need the data, but you need it to assert, exercise, or defend legal claims, or you have objected to the processing. You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format and to transmit it to another controller ("right to data portability").
If your personal data are processed on the basis of legitimate interests, you have the right to object to the processing of your personal data for reasons arising from your particular situation. This also applies to any related profiling. If your personal data are processed by us for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes; this also applies to profiling related to such direct marketing.
The processing of your request for the granting of data subject rights (e.g. information or deletion) is generally free of charge. For obviously unfounded or excessive requests, we reserve the right, in individual cases, to demand an appropriate fee (up to the amount of our actual costs) in accordance with applicable legal regulations or to refuse to process the request
# 8:Exercising Your Data Subject Rights and Managing Your Settings
To exercise your data subject rights (including any requests for information or deletion), please contact us using the contact information provided above.
If you wish to change your preferences regarding marketing communications from LUDILO, you can do so at any time in your LUDILO account under "Settings." If you do not wish to receive marketing communications from us, you can also unsubscribe using the link in the email you received from us. Please note that it may take a few days for the changes to take effect due to technical reasons. Information on how to manage your settings regarding cookies and similar technologies can be found in the next section on Cookies and Similar Technologies.
# 9: Cookies and Similar Technologies
When you use our services, we and selected third parties may use cookies and similar technologies to provide you with a better, faster, and more secure user experience or to show you personalized advertising. Cookies are small text files that your browser automatically creates and stores on your device when you use the services. Detailed information about our use of cookies and similar technologies and your choices can also be found in our Cookie, Web Beacon, and Similar Technologies Statement.
Our cookies and similar technologies serve different functions:
- They may be technically necessary for providing our services.
- They help us optimize our services technically (e.g., monitoring error messages and loading times).
- They enhance your user experience (e.g., storing font size and form data entered).
- They allow us to display more relevant advertisements to you.
We use cookies and similar technologies that only remain on your device as long as your browser is active (session cookies), as well as cookies and similar technologies that remain on your device for a longer period (persistent cookies). Where possible, we take appropriate security measures to prevent unauthorized access to our cookies and similar technologies. A unique ID ensures that only we and/or selected third parties have access to cookie data.
# 10: Additional important information about privacy
This section contains additional important information regarding privacy in connection with the use of our services, including information about whether you are required to provide personal data.
What happens if you make your personal data public on our websites or in our applications? Other users have access to the information you disclose on Ludilo or share with other users. Other users may, for example, view your ads and reviews.
When you post ads, the username you provided will be displayed and thus visible to the public. It is associated with all your public Ludilo activities. Notices of suspicious activities and violations of the principles on our websites that are sent to other Ludilo users may contain your public username and specific details about items. So, if you use a username that allows for inferences about your identity, third parties may associate your Ludilo activities with you.
To ensure the protection of your personal data, we only allow other users limited access to your information, meaning only to the extent necessary for facilitating transactions.
Responsibility for personal data of other users received through Ludilo If you communicate with another user (e.g., a prospective buyer) and receive their personal data (such as name, email address, or other contact details and shipping information), you are independently responsible for this personal data and its processing after we have transmitted it to you.
Unless you are acting purely for personal purposes, we recommend that you explain your data processing in a privacy notice and respect the privacy of other users. As a seller, you must comply with applicable data protection laws and, in particular, respect the rights of other users as data subjects, for example, by allowing them to access the personal data collected by you and to request its deletion.
You may only use the personal data of other users to which you have access for the purpose of conducting contact with the other user and otherwise only for purposes for which these users have expressly consented. Using the personal data of other users to which you have access for any other purposes, such as adding them to mailing lists without explicit consent, constitutes a violation of our terms of use.
Personal data of third parties If you provide us with personal data of another person, you must obtain the consent of that person, or this must be legally permissible. You must inform these individuals about how we process personal data in accordance with our Privacy Policy.
Review of messages sent via our messaging tools All messages sent via our messaging tools are initially received by us and then forwarded to the recipient. All messages are automatically filtered based on certain criteria. Suspicious messages may be manually reviewed by our customer service. In the event of a violation of our terms of use, we reserve the right to block the transmission of the message and, if necessary, to suspend your Ludilo account.
This serves the legitimate interests such as protecting against fraudulent or suspicious activities (e.g., spam, viruses, phishing, or other illegal activities) or enforcing our terms of use and other principles (e.g., regarding illegal and other prohibited content).
Are you obliged to provide us with your personal data? Some of the personal data you provide to us (e.g., those by which we can identify you) are necessary for concluding the contract for the use of our services. The provision of all other personal data is voluntary but may be necessary for using our services, such as the offer or contact information required for placing an ad.
Privacy of children Our services are not directed at minors. We do not knowingly collect personal data from minors. The use of our services by minors is not permitted under our terms of use without the consent of their legal guardians.
Stay logged in When you log in with your Ludilo account, you remain logged in for a certain period until you log out. If you use our app, you will remain logged in after signing in. If you are using a public computer or sharing your computer with others, we recommend that you do not choose to stay logged in but log out instead. You and any other user of the computer/browser through which you logged in can view, access, and perform certain actions on most areas of your Ludilo account during the period you are logged in without further authorization. You and any other user of this computer/browser can, among other actions, perform the following actions and account activities:
Post an ad or contact a seller View your activities View your Ludilo account View or edit your saved watchlist and searches View your profile page Send messages to other users Perform post-purchase activities (e.g., leave feedback or submit complaints)
You normally end the session for which you are logged in by logging out and/or deleting your cookies. If you have certain privacy settings enabled in your browser, you can also end the session for which you are logged in by simply closing the browser. If you are using a public computer or sharing your computer with others, you should log out and/or delete your cookies as soon as you stop using our services to protect your Ludilo account and personal data.