POPIA & GDPR
Privacy policy.
Effective 16 July 2026 · Version 2.2
This policy explains how NexBDM (Pty) Ltd (“NexBDM,” “we,” “our”), the company behind LoomDeck, collects, uses, shares, and protects personal information, in compliance with South Africa's Protection of Personal Information Act (POPIA) and, where applicable, the General Data Protection Regulation (GDPR).
Download as PDFWho we are
NexBDM (Pty) Ltd, Registration No. 2026/250171/07, 37 Montery Place, 140 Griffiths Road, Pretoria 0184, South Africa. NexBDM is the “responsible party” under POPIA and the “data controller” under GDPR for the personal information described in this policy.
Information Officer (POPIA) / Data Protection Contact (GDPR): Heinoux Roux, [email protected]
Products this policy covers
This policy covers personal information processed by NexBDM in connection with:
- NexBDM's consulting, strategy, and business development services;
- LoomDeck, NexBDM's SaaS operating platform for marketing agencies (loomdeck.io), including its public website, free tools such as the margin calculator, the early-access waitlist, the live demo, and, once launched, paid subscription accounts; and
- NexBDM's other software products and services.
An “Agency” is an organisation that creates a LoomDeck account. A “Connected Tool” is a third-party platform, such as Meta, HubSpot, or Google, that an Agency authorises LoomDeck to access, via that provider's own sign-in.
What personal information we collect
Collected directly from you
- Name, email address, phone number, and company name (consulting clients)
- Business process and systems information shared during discovery (consulting clients)
- Agency name, email address, and password (LoomDeck account holders: passwords are hashed by our authentication provider and are never visible to NexBDM in plain text)
- Email address only (LoomDeck early-access waitlist)
- Payment information, processed by third-party payment providers; NexBDM does not store full card details
Collected via Connected Tools (LoomDeck only, and only with your authorisation)
When an Agency connects a third-party tool to LoomDeck, we receive and store, at that Agency's instruction: an encrypted access token (and, where issued, an encrypted refresh token), the scopes/permissions the Agency granted, and identifying account information such as connected Meta ad account IDs, a HubSpot portal ID, or a Google account email. Depending on which features an Agency uses, LoomDeck may also read operational data from the Connected Tool (for example, HubSpot deal records, or Meta ad account names and spend) solely to display it back to that Agency inside its own deck. When an Agency connects Google Analytics, LoomDeck reads report data via the Analytics Data API, including sessions, engagement, conversions, and source/medium counts, solely to display them in that Agency's own deck. When an Agency connects Google Workspace, LoomDeck reads Google Calendar event metadata (event title, attendee count, start and end time) to display meeting cadence; only events with two or more attendees are counted, and event bodies, attachments, and per-attendee identity are never surfaced. NexBDM does not use Connected Tool data for any purpose other than operating LoomDeck for the Agency that authorised the connection, and does not sell it.
Collected automatically
- Usage data from our SaaS platforms, including LoomDeck
- Website analytics on the public marketing pages of loomdeck.io, via two tools: Umami, a self-hosted, cookie-free analytics tool that records aggregate page views without tracking cookies or identifiable IP addresses; and Google Analytics 4 (GA4), which sets first-party cookies to distinguish repeat visitors and measure how the public site is used. Neither tool runs inside the logged-in LoomDeck application.
- An advertising and conversion measurement pixel on the public marketing pages of loomdeck.io, provided by Meta Platforms, Inc. (“Meta Pixel”). The pixel sets a first-party cookie (_fbp) and sends page-view and event data to Meta so we can measure the effectiveness of our own advertising, build custom audiences of loomdeck.io visitors, and show retargeted ads to those audiences on Facebook and Instagram. The pixel is not loaded inside the logged-in LoomDeck application (/app and /deck). See “Cookies and analytics” below for how to opt out.
Legal basis for processing
We only process personal information where we have a lawful basis to do so:
| Purpose | GDPR lawful basis | POPIA condition |
|---|---|---|
| Providing LoomDeck or consulting services to you | Performance of a contract | s11(1)(b): necessary to perform a contract |
| Waitlist and marketing communications | Consent (withdrawable any time) | s11(1)(a): consent |
| Security, fraud prevention, service integrity | Legitimate interests | s11(1)(d): legitimate interest |
| Compliance with law, tax, or regulatory requests | Legal obligation | s11(1)(c): legal obligation |
| Aggregate, non-identifying product analytics | Legitimate interests | s11(1)(f): legitimate interest |
| Measuring and improving our own advertising (Meta Pixel) | Legitimate interests | s11(1)(f): legitimate interest |
How we use personal information
- To deliver contracted services and operate LoomDeck accounts
- To connect and display data from Connected Tools solely for the Agency that authorised the connection
- To communicate with you about your engagement, account, or waitlist status
- To comply with legal obligations
- To improve our services, using anonymised or aggregated data wherever practicable
Limited Use of Google user data
LoomDeck's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. LoomDeck does not transfer this data to third parties except as necessary to provide or improve user-facing features. LoomDeck does not use this data for advertising. LoomDeck does not use raw or aggregated Google user data received from Workspace APIs to develop, improve, or train generalised AI or machine-learning models.
International data transfers
NexBDM is based in South Africa. Some of the service providers listed above may store or process personal information outside South Africa, including in the European Economic Area, the United Kingdom, and the United States. Where personal information is transferred internationally, NexBDM takes steps intended to keep it protected consistently with this policy, including data processing agreements with service providers and, where required, Standard Contractual Clauses or an equivalent safeguard.
Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you
- Correct or update inaccurate or incomplete personal information
- Request deletion of your personal information (the “right to be forgotten” / erasure)
- Object to processing, including for direct marketing
- Restrict processing in certain circumstances
- Request a copy of your personal information in a portable, machine-readable format (data portability, under GDPR)
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. LoomDeck does not currently make any such automated decisions about individuals
Submit requests to [email protected]. We will respond within 30 days, or such shorter period as required by applicable law.
Right to lodge a complaint
South Africa: the Information Regulator, [email protected], JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. EEA / UK: you may also lodge a complaint with the data protection supervisory authority in your country of residence, or with the UK Information Commissioner's Office (ICO).
Retention
- Client/consulting engagement data: retained for 5 years post-engagement.
- LoomDeck waitlist entries: retained until you unsubscribe or request deletion, or for a maximum of 24 months of inactivity.
- LoomDeck account data: retained for the life of the account, then deleted or anonymised within 90 days of account closure, except where a longer period is required by law.
- Connected Tool tokens: deleted immediately on disconnection.
Security
We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, and misuse, including encryption of Connected Tool access and refresh tokens using AES-256-GCM before storage, access controls restricting who within NexBDM can view personal information, and secure, encrypted storage of client data on approved platforms only.
Children's personal information
LoomDeck and NexBDM's services are directed at businesses and are not intended for use by children. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected a child's personal information without appropriate consent, we will delete it.
Data breach notification
In the event of a security compromise affecting personal information, NexBDM will notify the Information Regulator and affected data subjects as soon as reasonably possible under POPIA, and, where GDPR applies and the breach is likely to result in a risk to individuals' rights and freedoms, notify the relevant supervisory authority without undue delay (and where feasible within 72 hours) and affected individuals without undue delay where the breach is likely to result in a high risk to them.
Changes to this policy
We may update this policy from time to time. Material changes will be posted at loomdeck.io/privacy with an updated effective date.
Contact us
Heinoux Roux, Information Officer / Data Protection Contact
Email: [email protected]
Website: nexbdm.co.za · loomdeck.io