In short: we collect only what we need to respond to you and run this website securely, we never sell personal data, we keep it no longer than necessary, and you can ask us at any time to access, correct or delete it.
Who we are
LoopStack (“LoopStack”, “we”, “us” or “our”) is a cloud operations company headquartered in Al-Yasmin, King Abdulaziz Road, Riyadh, Kingdom of Saudi Arabia.
For the purposes of the Personal Data Protection Law issued by Royal Decree No. M/19 dated 9/2/1443H, as amended, and its Implementing Regulations (together, the “PDPL”), LoopStack is the controller of the personal data described in this policy.
You can contact us about anything in this policy at info@loopsstack.com or on +966 55 292 0220.
Scope of this policy
This policy applies to personal data we process when you visit loopsstack.com (the “website”), contact us, attend our events, or interact with us as a prospective client, client contact, supplier or partner.
When we process personal data on behalf of our clients as part of the services we deliver (for example, data stored in systems we operate), we act as a processor under the client’s instructions and the terms of our contract. In that case, the client’s own privacy notice applies, and you should contact the client directly.
Personal data we collect
Information you give us
- Contact and enquiry details: your name, company, job title, work email address, phone number and the content of your message when you contact us by email, phone or through the website.
- Business relationship details: work contact details, role and correspondence for client, supplier and partner contacts.
- Event and meeting details: registration details and any accessibility or dietary requirements you choose to tell us.
Information collected automatically
- Server logs: when you visit the website, our web server records your IP address, the date and time of the request, the page requested, the referring page, your browser and device type (user agent) and the response status. We use these logs only to keep the website secure, diagnose faults and prevent abuse.
- Preferences stored on your device: your theme choice (light or dark) and your cookie choices. See our Cookie Policy for details.
We do not use advertising trackers, we do not build profiles of website visitors, and we do not intentionally collect sensitive personal data. Please do not send us sensitive data (such as health, biometric or financial account information) through the website or by email.
How we use personal data and our legal bases
We process personal data only for specified, clear and legitimate purposes, and only to the extent necessary for those purposes. Our legal bases under the PDPL are set out below.
| Purpose | Personal data | Legal basis |
|---|---|---|
| Responding to your enquiry and arranging meetings or resilience reviews | Contact and enquiry details | Your consent, and our legitimate interest in responding to business enquiries |
| Preparing proposals and entering into a contract with you or your organisation | Contact and business relationship details | Steps taken at your request before entering into a contract, and performance of the contract |
| Delivering and supporting our services | Business relationship details | Performance of a contract |
| Keeping the website and our systems secure and preventing misuse | Server logs | Our legitimate interest in protecting our website, systems and users |
| Remembering your theme and cookie choices | Preferences stored on your device | Strictly necessary to provide the function you request |
| Sending service updates, insights or event invitations | Name and work email | Your consent, which you can withdraw at any time |
| Complying with legal obligations, court orders and requests from competent authorities | Any relevant data | Compliance with a legal or regulatory obligation |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and interests. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing carried out before you withdrew.
Transfers outside the Kingdom
We aim to store and process personal data within the Kingdom of Saudi Arabia. Where a transfer or disclosure outside the Kingdom is necessary, for example when a service provider operates infrastructure abroad, we carry it out only in accordance with the PDPL and the Regulation on Personal Data Transfer Outside the Kingdom.
This means relying on an adequacy decision by the competent authority or, where none exists, on appropriate safeguards such as the standard contractual clauses issued by the Saudi Data & AI Authority (SDAIA), together with a risk assessment where required, and limiting the data transferred to what is necessary.
How long we keep personal data
We keep personal data only for as long as needed for the purpose it was collected for, or as required by law. Typical retention periods are:
| Data | Retention period |
|---|---|
| Enquiries that do not lead to a business relationship | Up to 24 months after our last contact |
| Client, supplier and partner records | For the duration of the relationship, then for the period required by applicable law (for example, commercial and tax record-keeping) |
| Web server logs | Up to 14 days, unless needed longer to investigate a specific security incident |
| Cookie choice | 180 days in your browser, after which we ask again |
| Theme preference | Until you clear it from your browser |
| Marketing preferences | Until you withdraw consent, plus a short suppression record so we respect your choice |
When the retention period ends, we securely destroy the data or anonymise it so that it can no longer identify you.
How we protect personal data
As a cloud operations company, security is central to what we do. We apply organisational, administrative and technical measures appropriate to the nature of the data, including:
- Encryption of data in transit using TLS, and encryption at rest where personal data is stored.
- Role-based access with least privilege and multi-factor authentication for staff and operators.
- Hardened, regularly patched servers with security monitoring and logging.
- Confidentiality obligations and privacy training for everyone who handles personal data.
- Regular review and testing of our controls.
If a personal data breach occurs, we will notify the Saudi Data & AI Authority (SDAIA) within 72 hours of becoming aware of it where the PDPL requires, and we will notify affected individuals without undue delay where the breach may cause them harm, together with practical steps they can take.
Your rights
Under the PDPL, and subject to the conditions it sets, you have the right to:
- Be informed about how and why your personal data is collected and processed, as set out in this policy.
- Access the personal data we hold about you and obtain a copy of it in a clear and readable format.
- Request correction of personal data that is inaccurate, incomplete or out of date.
- Request destruction of personal data that we no longer need for its purpose, subject to any legal obligation to retain it.
- Withdraw your consent at any time where we rely on consent.
- Object to direct marketing and opt out of marketing communications at any time.
- Lodge a complaint with the competent authority, the Saudi Data & AI Authority (SDAIA).
To exercise any of these rights, email info@loopsstack.com with the subject line “Privacy request”. We may ask you to verify your identity before acting on your request. We will respond within 30 days; where a request is complex or you have made several requests, we may extend this by up to a further 30 days and will tell you why. Exercising your rights is free of charge.
We would appreciate the chance to resolve any concern with you first, but you may contact SDAIA at any time.
Visitors from outside Saudi Arabia
If you are located in the European Economic Area, the United Kingdom or another jurisdiction with its own data protection law, you may have additional rights, such as the right to restrict processing, to object to processing based on legitimate interests and to data portability. We will honour these rights where the applicable law gives them to you. Contact us using the details below.
Children
Our website and services are intended for businesses and professionals. They are not directed at individuals under 18, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it.
Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects.
Links to other websites
Our website may link to other websites, such as the sources we cite or a map service for directions. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy policies.
Changes to this policy
We review this policy regularly and may update it to reflect changes in law, our services or how we process personal data. The “Last updated” date at the top shows when it was last changed. If we make material changes, we will highlight them on the website and, where appropriate, notify you directly.
Contact us
For any question about this policy or to exercise your rights, contact us:
LoopStack
Al-Yasmin, King Abdulaziz Rd, Riyadh, Kingdom of Saudi ArabiaPhone
+966 55 292 0220