Where the data actually comes from.
It is the first question a careful buyer asks a lead-generation vendor, and most of them answer it vaguely. Here is the full answer.
What we use.
Every lead in your queue records where it came from, so you can check any of this yourself rather than take our word for it.
Public business directories and registries
Trade bodies, industry associations, chambers of commerce, government supplier and tender portals, and statutory company registers. Information businesses publish, or are required to publish, so that other businesses can find and transact with them.
Company websites
The pages a company publishes about itself: what it does, where it operates, and — where the company chooses to publish them — the people who hold particular roles. We read the same pages a prospective customer would.
Open mapping and place data
OpenStreetMap and similar open datasets, for finding businesses of a given type in a given area. Used to build the list of companies, not to identify individuals.
Professional profiles, as published
Where someone has published their current employer and job title professionally, we use it to confirm we have the right person in the right role. We record the profile URL so you can check it yourself.
Our own inference
Where a company publishes an email pattern for its staff, we may infer a likely address for the person we've identified — and then verify it before it is ever used. A likely address that fails verification is discarded, not sent to.
What we never do.
These are commitments, not preferences. They are how the system is built, and they are what an external client's DPA holds us to.
We never buy or resell lists
Nothing in your queue came from a data broker, and nothing we assemble for you is ever sold, shared or reused for another client.
We never scrape behind a login
No credential-gated sources, no automated access to platforms in breach of their terms, no private profile data. If reading it requires an account, we don't take it.
We never collect personal life data
Business role, business contact details, employer, company information. Not home addresses, not personal social accounts, not anything about someone's private life. If a field isn't relevant to a business conversation, we don't store it.
We never send to an unverified address
Verification runs before anything is queued for email. This protects the recipient from a misdirected message as much as it protects your domain.
We never auto-send on WhatsApp or LinkedIn
Those messages are drafted and queued. A person on your team reads each one and sends it from their own account, or discards it.
We never contact someone who has opted out
One opt-out, on any channel, and that person is suppressed permanently — across every future run, for every client. Suppression records are the one thing we keep forever.
How we operate where you sell.
Electronic-marketing rules differ by country. Rather than run one approach everywhere and hope, we operate to the stricter reading in each market we serve.
India
We process business-contact information published by companies for business purposes. Individuals can ask what we hold and require its erasure, and we action that regardless of whether they are a client. Cold email carries sender identification and a working unsubscribe.
Australia & New Zealand
Commercial electronic messages carry accurate sender identification and a functional unsubscribe that we honour promptly, and we only approach a work address that the business has published in connection with that person's role. Where the position on a channel is unsettled, we take the more conservative reading.
South Africa
We treat direct electronic marketing as requiring an explicit, honoured opt-out, we identify the sender on every message, and we act on objections and access requests on receipt.
This page describes how we work. It is not legal advice, and it does not replace your own obligations as the party deciding who to contact — you remain the data controller for the outreach we prepare on your behalf. The Data Processing Addendum sets out the split formally.
If you’d rather not hear from us
If you received a message prepared by loopwyn and want to be removed, write to privacy@loopwyn.com and you will be suppressed permanently — not just for the client who contacted you, but across every client and every future run. You can also ask what we hold about you and require its deletion. We don’t ask for a reason and we don’t make you argue for it.
Want to see it applied to your market?
Tell us who you sell to and we'll show you the leads it produces, with the source recorded on each one.
Free trial available · Cancel anytime, no notice period · External clients sign a DPA before we begin