Privacy Policy
1. Who we are
This website (served at ccg-analytics.de) and the “Get-IT-Done” platform are operated by LB TEC (PTY) LTD (“we”, “us”, the responsible party / data controller). Smart AI Solutions (smartaisolutions.co.za) provides e-mail infrastructure to the platform and acts as an operator / processor on our instructions.
Our two roles
We act in two different capacities, and which one applies depends on whose information it is:
- As responsible party (controller) — for information about visitors to this website and about the people who hold accounts with us: booking, enquiry and intake submissions, account registration details, and server logs. We decide why and how that information is processed, and this policy governs it.
- As operator (processor) — for the information a customer puts into, or receives through, the Get-IT-Done platform: their contacts, their tasks, and the content of messages they send and receive. That information belongs to the customer. They are the responsible party for it; we process it only on their documented instructions, and their own privacy notice — not this one — governs how they may use it. This mirrors §5 of our Terms of Service.
Where this policy says “your information” without qualification, it means information we hold as responsible party. If you are an employee or contact of one of our customers and want to know how they use your information, please contact them directly; we will help route the request if you are unsure who to ask.
- Registered name: LB TEC (PTY) LTD
- Registration / Tax no.: 2020/138701/07
- Physical / registered address: 53 Olinia Crescent, Kuils River, Cape Town, Western Cape 7550, South Africa
- Information Officer (POPIA): Loxly Atkinson
- Privacy contact e-mail: loxly@lbtec.co.za
2. Scope
This policy explains how we collect, use, share, and protect personal information across both of the following, and how we comply with the Protection of Personal Information Act, 2013 (POPIA) of South Africa, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act / CPRA (CCPA).
- This website (ccg-analytics.de) — including our booking form, our client-intake questionnaire, and any enquiry/lead forms. We are the responsible party for this.
- The Get-IT-Done platform — the CRM application itself: user accounts, contacts and pipelines, boards and tasks, connected mailboxes, and the WhatsApp messaging the platform sends and receives. For customer content within the platform we act as operator, per §1.
3. Information we collect
We collect what you give us, the minimum the website needs to function, and — within the platform — the content our customers choose to process through it.
Information you provide directly
- Booking a call/demo — your name, e-mail address, phone number (optional), the topic you select, any notes you write, and your chosen appointment time.
- Client-intake questionnaire — your e-mail address, a client reference from your invitation link, and the answers you provide (which may include your name, role, or company where you type them in).
- Enquiry / lead forms — the contact details a given form requests, typically your name, e-mail address, and phone number.
Information collected automatically
- Strictly-necessary cookies — a session cookie and a security (CSRF) token. These are required for the site and its forms to work; no analytics, advertising, or tracking cookies are set.
- Server logs — standard web-server records such as your IP address, browser/user-agent, and request timestamps, kept for security and diagnostics.
- Web fonts — fonts are served from our own server (self-hosted); no font-related data (such as your IP address) is sent to Google or any other third party.
Information processed inside the Get-IT-Done platform
Where a customer uses the platform, the following is processed on their instructions. We hold it as operator, not as responsible party (§1):
- Account data — the name, e-mail address, role/permissions and password hash of each user the customer creates, plus sign-in timestamps.
- Contacts and pipeline records — the people and organisations the customer stores: names, e-mail addresses, phone numbers, and any notes or custom fields they add.
- Boards, cards and tasks — the work items the customer tracks, including due dates, assignees and free-text descriptions.
- WhatsApp message content and metadata — for reminders the platform sends to the customer's staff, and for inbound replies those staff send back, which the platform reads and converts into task records. This includes the message body, the sender's WhatsApp phone number, the message identifier, and delivery/read status.
- Connected mailboxes — where a user connects their own mailbox, the e-mail headers and body content the platform displays, and the mailbox credentials, which are encrypted at rest.
We do not intentionally collect special-category / sensitive information (e.g. health, biometric, or financial account data) through this website, and the platform is not intended for it. Please do not enter such information in free-text fields.
Artificial intelligence: we do not currently send personal information, message content, or customer data to any third-party AI or large-language-model provider — no such provider is connected to the platform. If we introduce an AI-assisted feature that does so, we will name the provider in the table in §6 and update this policy before that feature is switched on.
4. How and why we use your information (and our legal basis)
| Purpose | Legal basis (GDPR) / lawful processing (POPIA) |
|---|---|
| Schedule and confirm your booking; contact you about it | Consent, and steps to enter/perform a contract at your request (GDPR Art. 6(1)(a)/(b); POPIA s11(1)(a)/(b)) |
| Process your intake answers and prepare a proposal | Consent / pre-contract steps (GDPR Art. 6(1)(a)/(b); POPIA s11) |
| Respond to enquiries and manage the sales relationship | Legitimate interests / consent (GDPR Art. 6(1)(a)/(f); POPIA s11(1)(a)/(f)) |
| Keep the site secure and prevent abuse | Legitimate interests / legal obligation (GDPR Art. 6(1)(c)/(f); POPIA s11(1)(c)/(f)) |
| Provide the platform to a customer: host their contacts, boards and tasks, and operate their user accounts | Performance of our contract with the customer (GDPR Art. 6(1)(b); POPIA s11(1)(b)) — and, for the customer's own contacts, on the customer's instructions as operator |
| Send task and reminder messages over WhatsApp and e-mail on a customer's behalf, and receive replies back into their tasks | On the customer's documented instructions as operator (POPIA s20–21; GDPR Art. 28). The customer is responsible for having a lawful basis and opt-in for the people they message — see §5 of our Terms of Service |
We do not use your information for automated decision-making that produces legal effects, and we do not sell your personal information (relevant to CCPA — see §9).
5. Cookies and tracking
We use only strictly-necessary first-party cookies (session and CSRF token). Because these are essential to provide the service you request, they do not require prior consent under GDPR/POPIA. We do not use analytics or advertising cookies and do not track you across other sites. If we add non-essential cookies in future, we will show a consent banner first.
6. Who we share information with
We share personal information with the service providers (“operators”/“processors”) needed to run the site and the platform, and we never sell it. Each provider is bound to process data only on our instructions. The table below is the complete list.
| Provider | What they receive | Where |
|---|---|---|
| Supabase (booking database) | Booking details: name, e-mail, phone, topic, notes, appointment time | European Union (Supabase on AWS) |
| Smart AI Solutions (e-mail / SMTP) | Recipient address + message content for booking confirmations and intake reports | South Africa |
| Hostinger (web hosting) | Anything processed on the server (site + CRM); server logs | European Union |
| Meta Platforms, Inc. and its affiliates — the WhatsApp Business Platform, which carries every WhatsApp message the platform sends or receives | Recipient and sender WhatsApp phone numbers, the content of each message, and message metadata (identifiers, timestamps, delivery and read status) | Meta’s global processing infrastructure, including the United States |
| Unipile (WhatsApp connectivity provider — currently in use, being retired) | The same WhatsApp phone numbers, message content and metadata, while it remains the transport | European Union |
About WhatsApp: WhatsApp is operated by Meta. Any message the platform sends to, or receives from, a WhatsApp number necessarily passes through Meta’s systems and is subject to Meta’s own terms and privacy practices in addition to this policy. We cannot deliver a WhatsApp message without Meta receiving it. Meta is an independent controller for its own purposes as described in its terms; we do not control what it does with the data it holds about a WhatsApp user.
We may also disclose information where required by law, or to protect our rights, safety, or property.
7. International transfers
Our hosting and booking database are located in the European Union, and our e-mail infrastructure is in South Africa. Because we are a South African responsible party using EU-based processors, personal information is transferred out of South Africa to the EU/EEA. We rely on lawful transfer mechanisms for this — your consent, contractual necessity, and appropriate safeguards under POPIA section 72, supported by GDPR Standard Contractual Clauses in our processors’ terms.
WhatsApp messages travel further than the EU. Every WhatsApp message the platform sends or receives passes through Meta’s global infrastructure, which includes the United States — a destination without a South African adequacy finding and, for EU data subjects, outside the EEA. This transfer is unavoidable if WhatsApp is used at all: it is how the network works. We rely on the Standard Contractual Clauses and data-transfer terms incorporated into the Meta Platform Terms and the WhatsApp Business Terms, together with contractual necessity under POPIA section 72(1)(b), for this leg. While Unipile remains the transport, the same message data also passes through Unipile in the European Union. If you do not want your information sent through WhatsApp, ask us or your employer to use e-mail reminders instead — the platform supports e-mail and in-app reminders that do not involve Meta.
8. How long we keep your information
We keep personal information only as long as necessary for the purpose it was collected, then delete or anonymise it. Our retention periods are:
- Booking and enquiry details: 12 months from your last contact with us, unless the enquiry becomes an engagement.
- Client-intake answers: for the duration of the proposal or engagement, then 5 years — the period South African tax and company legislation requires business records to be retained.
- Server logs: 90 days.
- WhatsApp and e-mail reminder messages we send as responsible party: for the life of the related task, then deleted with it.
- Customer Data held as operator (a customer's contacts, boards, tasks, and the WhatsApp and mailbox content flowing through their account): for as long as their account is active, then deleted or anonymised within 90 days of termination, except where the law requires us to keep a record. This is the same 90-day commitment given in §10 of our Terms of Service. A customer may ask us to delete their data sooner, and may export it at any time.
You can ask us to delete your information sooner — see §9.
9. Your rights
Depending on where you are, you have the following rights. To exercise any of them, contact our Information Officer (§1). We respond within the timeframes required by law and will not discriminate against you for exercising them.
Under POPIA (South Africa)
- Access the personal information we hold about you, and know who it has been shared with.
- Request correction or deletion of information that is inaccurate, irrelevant, or excessive.
- Object to processing, and withdraw consent, on reasonable grounds.
- Lodge a complaint with the Information Regulator (South Africa) — inforegulator.org.za.
Under GDPR (EU/EEA)
- Access, rectification, erasure (“right to be forgotten”), restriction, data portability, and objection.
- Withdraw consent at any time (without affecting prior processing).
- Lodge a complaint with your local supervisory authority.
Under CCPA/CPRA (California)
- Know what personal information we collect and how it is used; access and delete it; correct inaccuracies.
- Opt out of the “sale” or “sharing” of personal information — note we do not sell or share your information.
- Exercise these rights without discrimination.
10. How we protect your information
- Encryption in transit over HTTPS/TLS.
- Access controls and role-based permissions in the CRM; connected-mailbox credentials are encrypted at rest.
- The booking database enforces row-level security (deny-by-default), so records are only reachable server-side.
No method of transmission or storage is completely secure; while we use appropriate safeguards, we cannot guarantee absolute security.
11. Children’s privacy
This website is intended for businesses and is not directed at children. We do not knowingly collect personal information from children (under 18 under POPIA; under 16 under GDPR unless a lower national age applies). If you believe a child has provided us information, contact us and we will delete it.
12. Contact us
For any privacy question or to exercise your rights, contact our Information Officer:
- Information Officer: Loxly Atkinson
- E-mail: loxly@lbtec.co.za
- Address: LB TEC (PTY) LTD, 53 Olinia Crescent, Kuils River, Cape Town, Western Cape 7550, South Africa
13. Changes to this policy
We may update this policy from time to time. We will post the revised version here with a new “Last updated” date and, for material changes, take reasonable steps to notify you.