Privacy Policy
What we collect, why we collect it, and what you can ask us to do with it.
Last updated: 22 August 2026
Who we are
Vestanam Solutions Private Limited (CIN U72900MH2019PTC320223) operates loopwyn (loopwyn.com). Our place of business is Prabhavee Tech Park, 4th Floor, Regus, Baner, Pune, Maharashtra 411045, India. For any question about this policy or about your data, write to privacy@loopwyn.com. We reply within one working day.
Two different roles
We handle personal data in two distinct capacities, and your rights differ between them.
- As controller — for people who contact us, request a demo, or use the loopwyn application. We decide why and how that data is used.
- As processor — for the business-contact data we discover and prepare on a client’s behalf. The client decides who is contacted and why; we act on their documented instructions under a Data Processing Addendum. If you were contacted through loopwyn and want your details removed, we will action it and tell the client, whichever of us you write to.
What we collect
- Information you give us — name, work email, company website, a description of your ideal customer, and an optional phone number, submitted through our contact or waitlist forms.
- Account data — if you use the application: your email, a hashed password, and the configuration you create.
- Business-contact data processed for clients — name, job title, employer, business email address, business phone where published, and public professional profile links. This is gathered from publicly accessible sources: company websites, public search results, and public professional profiles. We do not buy contact lists, and we do not process special-category data.
- No website analytics. This site loads no analytics script, no advertising pixel, and sets no tracking cookie. If that changes, this page changes first.
Why we use it, and on what basis
Data you submit is used to reply to you, prepare sample leads, and contact you about loopwyn — on the basis of your consent, and our legitimate interest in responding to a business enquiry. Account data is processed to perform our contract with you.
For business-contact data processed on a client’s behalf, the client determines the lawful basis and generally relies on legitimate interests in B2B outreach. We support that with three concrete measures rather than an assertion: we record the source of every contact, we act only on the client’s instructions, and we apply an opt-out permanently and automatically at the moment it is received.
Who we share it with
Service providers only, and only what each needs to do its job. We do not sell personal data, and we do not resell or license the contact data we process for clients. Our sub-processors are:
- Hetzner Online GmbH (Germany) — hosting and database storage.
- OpenAI, Anthropic and Groq (United States) — extracting company details from public pages, summarising a company, and drafting the message text. Sent under API terms that exclude use of the content for training.
- Exa Labs (United States) — public web and professional-profile search.
- MillionVerifier — confirming whether an email address exists, so that we do not send to invalid addresses.
- Telegram — internal operational notifications to our team, which include lead names.
Transfers outside India and the EEA rely on the recipient’s standard contractual clauses. The current list is maintained on the DPA page; clients are notified before a sub-processor is added.
How long we keep it
- Enquiries — while the conversation is live and for 24 months afterwards, so we can pick up where we left off.
- Account data — for the life of the account, and deleted within 90 days of closure.
- Client-processed contact data — for the life of the client’s engagement, deleted within 30 days of termination, except where we must keep records to meet a legal obligation.
- Opt-out records — kept indefinitely, deliberately. A suppression entry is the only reliable way to guarantee someone is never contacted again, and deleting it would defeat the request that created it.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to processing, to receive it in a portable form, and to withdraw consent at any time. Anyone contacted through the platform can opt out; opt-outs are recorded on a suppression list and are never contacted again by that client.
Write to privacy@loopwyn.com. We respond within 30 days. Where we act as processor we will pass the request to the client without delay and assist them in answering it. If you are in the EEA or the UK you may also complain to your local supervisory authority; in India, to the Data Protection Board.
Security
Each account’s data is isolated at the database level by row-level security keyed on the account, enforced by the database itself rather than by application code — a query that forgets to filter returns nothing rather than someone else’s data. Traffic is encrypted in transit. Application access is limited to named personnel who need it, and every server-side fetch of a user-supplied address is filtered to prevent it reaching internal systems.
No system is perfect. If we discover a breach affecting personal data we will notify affected clients without undue delay and within 72 hours of becoming aware.
Changes
If we change this policy we will update the date above, and for material changes we will tell clients directly rather than relying on you to re-read the page.