Loop[Cite]
How it worksLanguagesPricingCompareFAQAboutArticles
Free scanSign in
Legal

Privacy Policy

Effective Date: 12 August 2026

1. Introduction

This Privacy Policy explains how personal information is collected, used, disclosed, and protected under the Protection of Personal Information Act 4 of 2013 & 2021 (POPIA) in South Africa, with secondary compliance to GDPR (EU) 2016/679. The organization acts as the responsible party under POPIA or data controller under GDPR.

2. Information We Collect

  • Automatically Collected Information: IP addresses, browser type, device information, operating system, access times, pages viewed.
  • Information Provided by You: Name, email, telephone, postal address, identification details, payment information.
  • Sensitive or Special Personal Information: Not routinely collected unless necessary with explicit consent.
  • Information Published on a Scanned Website: Business name, email addresses, telephone numbers, social profiles and physical address, as published on the publicly accessible pages of a website submitted to us for scanning — see section 5.

3. How We Collect Information

Information is collected through direct submissions, automated technologies (cookies, web beacons, OAuth logins, tracking pixels), and publicly available sources — including the publicly accessible pages of any website submitted to us for scanning, as set out in section 5.

4. Purposes and Legal Basis for Processing

Processing occurs to provide services, respond to inquiries, communicate with users, conduct internal operations, comply with legal obligations, and support application functionalities. Legal bases include consent, contractual necessity, legal obligations, and legitimate interests. Where we analyse a website’s publicly accessible pages in order to produce a report, we rely on legitimate interests. Where we then make contact with that business, we rely on our legitimate interest in letting them know that a result about their own website exists and offering it to them. We do not rely on any assumed consent, we keep that contact limited as described in section 5, and we do not enrol anyone in marketing communications without their separate agreement.

5. Websites Submitted for Scanning

Our service works by analysing a website. When any person submits a website address to us, we fetch and analyse that site’s publicly accessible pages and record the contact details the site itself publishes — typically the business name, email addresses, telephone numbers, social profiles and physical address — alongside the technical result of the scan. We do not attempt to access anything behind a login, a paywall, or any page a site asks us not to fetch.

We use this to produce the report, to identify the business the report is about, and to be able to tell that business the result exists.

The person who requests a scan is not always the owner of the website. A consultant, a competitor or a member of the public may submit an address. For that reason we do not treat a scan request as permission given on the site owner’s behalf, and we do not claim that the owner has consented to anything by virtue of someone else scanning their site.

If we contact a business whose website was scanned, that contact is:

  • Focused and purposeful — sent to a contact channel that the business publishes itself, telling them that a result about their site exists and asking whether they would like it.
  • Not a newsletter and not a list. We do not add a scanned business to a newsletter, mailing list, drip sequence or any other recurring or automated marketing communication.
  • Brief and finite. If we do not hear back, we may follow up a small number of times — which may include another of the contact channels the business publishes, or a short question to clarify an unclear reply. We do not run open-ended or automated campaigns, and we stop as soon as the business asks us to.
  • A clear refusal is final. If a business tells us it is not interested, we stop immediately and permanently, and we record that so it is honoured even if the site is scanned again later.
  • Never sold or shared. We do not sell contact details captured from a scanned site, and we do not share them with third parties for their own marketing.

If your website was scanned and you would rather we did not hold or use those details, you may object or ask us to delete them at any time via our contact page. We will delete the contact details, and the scan record on request, and add you to our suppression list. You do not need to give a reason, and you do not need to be a customer.

6. If You Request a Scan

  • Your email address. If you give us your email to receive a report, we use it to send you that report. That is a transactional message, not marketing.
  • Marketing. We only send you marketing if you have separately and explicitly agreed to it. You can withdraw that agreement at any time, and every such message carries a way to opt out.
  • Your responsibility. By submitting a website address you confirm that you are entitled to request an analysis of it and that doing so does not infringe anyone else’s rights.
  • Prohibited use. You may not use our service to harvest contact details for bulk, unsolicited or automated marketing. We may refuse or withdraw access where we believe it is being used that way.

7. Sharing and Disclosure of Information

Personal information may be shared with service providers, affiliates, regulatory authorities, and in merger/acquisition scenarios. The organization does not sell personal information.

8. International Transfers

Data is primarily processed in South Africa; transfers to other countries use safeguards like binding corporate rules or standard data protection clauses. EU user data is stored on EU servers only.

9. Data Security

Technical, organizational, and administrative measures protect information. No system guarantees absolute security. Data breaches trigger notification requirements under POPIA and GDPR.

10. Data Retention

Information is retained only as long as necessary; transaction data is kept for 7 years per South African tax laws.

11. Your Rights

These rights belong both to people who use our service and to businesses whose websites were scanned (see section 5). You may access, rectify, request erasure, restrict processing, object, obtain data portability, withdraw consent, or lodge complaints with the Information Regulator () or GDPR supervisory authorities.

12. Children's Information

Services are not directed at minors under 16; personal information from children is deleted promptly if collected unknowingly.

13. Changes to This Policy

Updates are posted on the website with effective dates; continued use indicates acceptance.

14. Contact Us

Information Officer / Data Protection Officer: Loopworks PTY Ltd. For any privacy-related questions or requests, please get in touch via our website at loopworks.io.

© 2026 LOOPWORKS PTY (Ltd) — All Rights Reserved

Loop[Cite]

AI visibility for South African businesses — get cited by AI, and recommended to your customers.

HomeContactPrivacy Policy
© 2026 Loop[Cite] · loopcite.comPowered by{L}oopworks