← LoomDeck

POPIA & GDPR

Privacy policy.

Effective 16 July 2026 · Version 2.2

This policy explains how NexBDM (Pty) Ltd (“NexBDM,” “we,” “our”), the company behind LoomDeck, collects, uses, shares, and protects personal information, in compliance with South Africa's Protection of Personal Information Act (POPIA) and, where applicable, the General Data Protection Regulation (GDPR).

Download as PDF

Who we are

NexBDM (Pty) Ltd, Registration No. 2026/250171/07, 37 Montery Place, 140 Griffiths Road, Pretoria 0184, South Africa. NexBDM is the “responsible party” under POPIA and the “data controller” under GDPR for the personal information described in this policy.

Information Officer (POPIA) / Data Protection Contact (GDPR): Heinoux Roux, [email protected]

Products this policy covers

This policy covers personal information processed by NexBDM in connection with:

  • NexBDM's consulting, strategy, and business development services;
  • LoomDeck, NexBDM's SaaS operating platform for marketing agencies (loomdeck.io), including its public website, free tools such as the margin calculator, the early-access waitlist, the live demo, and, once launched, paid subscription accounts; and
  • NexBDM's other software products and services.

An “Agency” is an organisation that creates a LoomDeck account. A “Connected Tool” is a third-party platform, such as Meta, HubSpot, or Google, that an Agency authorises LoomDeck to access, via that provider's own sign-in.

What personal information we collect

Collected directly from you

  • Name, email address, phone number, and company name (consulting clients)
  • Business process and systems information shared during discovery (consulting clients)
  • Agency name, email address, and password (LoomDeck account holders: passwords are hashed by our authentication provider and are never visible to NexBDM in plain text)
  • Email address only (LoomDeck early-access waitlist)
  • Payment information, processed by third-party payment providers; NexBDM does not store full card details

Collected via Connected Tools (LoomDeck only, and only with your authorisation)

When an Agency connects a third-party tool to LoomDeck, we receive and store, at that Agency's instruction: an encrypted access token (and, where issued, an encrypted refresh token), the scopes/permissions the Agency granted, and identifying account information such as connected Meta ad account IDs, a HubSpot portal ID, or a Google account email. Depending on which features an Agency uses, LoomDeck may also read operational data from the Connected Tool (for example, HubSpot deal records, or Meta ad account names and spend) solely to display it back to that Agency inside its own deck. When an Agency connects Google Analytics, LoomDeck reads report data via the Analytics Data API, including sessions, engagement, conversions, and source/medium counts, solely to display them in that Agency's own deck. When an Agency connects Google Workspace, LoomDeck reads Google Calendar event metadata (event title, attendee count, start and end time) to display meeting cadence; only events with two or more attendees are counted, and event bodies, attachments, and per-attendee identity are never surfaced. NexBDM does not use Connected Tool data for any purpose other than operating LoomDeck for the Agency that authorised the connection, and does not sell it.

Collected automatically

  • Usage data from our SaaS platforms, including LoomDeck
  • Website analytics on the public marketing pages of loomdeck.io, via two tools: Umami, a self-hosted, cookie-free analytics tool that records aggregate page views without tracking cookies or identifiable IP addresses; and Google Analytics 4 (GA4), which sets first-party cookies to distinguish repeat visitors and measure how the public site is used. Neither tool runs inside the logged-in LoomDeck application.
  • An advertising and conversion measurement pixel on the public marketing pages of loomdeck.io, provided by Meta Platforms, Inc. (“Meta Pixel”). The pixel sets a first-party cookie (_fbp) and sends page-view and event data to Meta so we can measure the effectiveness of our own advertising, build custom audiences of loomdeck.io visitors, and show retargeted ads to those audiences on Facebook and Instagram. The pixel is not loaded inside the logged-in LoomDeck application (/app and /deck). See “Cookies and analytics” below for how to opt out.

How we use personal information

  • To deliver contracted services and operate LoomDeck accounts
  • To connect and display data from Connected Tools solely for the Agency that authorised the connection
  • To communicate with you about your engagement, account, or waitlist status
  • To comply with legal obligations
  • To improve our services, using anonymised or aggregated data wherever practicable

Cookies and analytics

The public marketing pages of loomdeck.io use two analytics tools. Umami is self-hosted, privacy-first, and sets no cookies. Google Analytics 4 (GA4) sets first-party cookies (such as _ga) to distinguish repeat visitors; the data is processed by Google LLC on our behalf. GA4 does not log or store visitor IP addresses, we have not enabled Google Signals or ads personalisation, and GA4 is not loaded inside the logged-in LoomDeck application.

The public marketing pages also load the Meta Pixel, a first-party pixel provided by Meta Platforms, Inc. that sets the _fbp cookie and reports page views and events to Meta so we can measure the effectiveness of our own advertising, build custom audiences of loomdeck.io visitors, and show retargeted ads on Facebook and Instagram. The Meta Pixel is not loaded inside the logged-in LoomDeck application.

You can block or delete these cookies in your browser settings, opt out of Google Analytics across all sites with Google's opt-out browser add-on, and control Meta's use of your data for ads (including the loomdeck.io pixel) in your Facebook ad preferences or via your device-level tracking controls. The logged-in application uses only the session cookies required to keep you signed in. If our use of cookies changes, this policy will be updated first, and, where required, we will ask for your consent.

Limited Use of Google user data

LoomDeck's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. LoomDeck does not transfer this data to third parties except as necessary to provide or improve user-facing features. LoomDeck does not use this data for advertising. LoomDeck does not use raw or aggregated Google user data received from Workspace APIs to develop, improve, or train generalised AI or machine-learning models.

Sharing of personal information

We do not sell personal information. We share it only with service providers necessary to deliver our services, under contract, including:

  • Supabase: authentication, database, and file storage for LoomDeck accounts
  • Resend: transactional email delivery (welcome emails, sign-in links, notifications)
  • Cloudflare: hosting, content delivery, and DNS for loomdeck.io
  • Google (Google Analytics 4): aggregate usage analytics for the public marketing pages only (see Cookies and analytics above)
  • Meta Platforms, Inc. (Meta Pixel): advertising and conversion measurement for our own campaigns, on the public marketing pages only (see Cookies and analytics above)

For LoomDeck's Connected Tools (Meta, HubSpot, Google), NexBDM is not disclosing your data to these providers. You are authorising LoomDeck to retrieve data you already hold with them, at your direction, and you can revoke that authorisation at any time from Integrations inside your LoomDeck account.

International data transfers

NexBDM is based in South Africa. Some of the service providers listed above may store or process personal information outside South Africa, including in the European Economic Area, the United Kingdom, and the United States. Where personal information is transferred internationally, NexBDM takes steps intended to keep it protected consistently with this policy, including data processing agreements with service providers and, where required, Standard Contractual Clauses or an equivalent safeguard.

Your rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct or update inaccurate or incomplete personal information
  • Request deletion of your personal information (the “right to be forgotten” / erasure)
  • Object to processing, including for direct marketing
  • Restrict processing in certain circumstances
  • Request a copy of your personal information in a portable, machine-readable format (data portability, under GDPR)
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. LoomDeck does not currently make any such automated decisions about individuals

Submit requests to [email protected]. We will respond within 30 days, or such shorter period as required by applicable law.

Right to lodge a complaint

South Africa: the Information Regulator, [email protected], JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001. EEA / UK: you may also lodge a complaint with the data protection supervisory authority in your country of residence, or with the UK Information Commissioner's Office (ICO).

Retention

  • Client/consulting engagement data: retained for 5 years post-engagement.
  • LoomDeck waitlist entries: retained until you unsubscribe or request deletion, or for a maximum of 24 months of inactivity.
  • LoomDeck account data: retained for the life of the account, then deleted or anonymised within 90 days of account closure, except where a longer period is required by law.
  • Connected Tool tokens: deleted immediately on disconnection.

Security

We implement reasonable technical and organisational measures to protect personal information against loss, unauthorised access, and misuse, including encryption of Connected Tool access and refresh tokens using AES-256-GCM before storage, access controls restricting who within NexBDM can view personal information, and secure, encrypted storage of client data on approved platforms only.

Children's personal information

LoomDeck and NexBDM's services are directed at businesses and are not intended for use by children. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected a child's personal information without appropriate consent, we will delete it.

Data breach notification

In the event of a security compromise affecting personal information, NexBDM will notify the Information Regulator and affected data subjects as soon as reasonably possible under POPIA, and, where GDPR applies and the breach is likely to result in a risk to individuals' rights and freedoms, notify the relevant supervisory authority without undue delay (and where feasible within 72 hours) and affected individuals without undue delay where the breach is likely to result in a high risk to them.

Changes to this policy

We may update this policy from time to time. Material changes will be posted at loomdeck.io/privacy with an updated effective date.

Contact us

Heinoux Roux, Information Officer / Data Protection Contact

Email: [email protected]

Website: nexbdm.co.za · loomdeck.io